Legal
Privacy Policy
Effective date: 26 September 2026 ยท Version 1
01
Who we are
Mutarai is provided by ASA Advisory Services Pte Ltd. This policy explains what personal data we collect from programme participants, why, and what rights participants have over it.
02
What we collect
- Account information: your name and email address.
- Programme and cohort data: which organisation, programme, and cohort you're enrolled in, and your enrolment/completion status.
- Onboarding goal: the development goal you name at the start of the programme.
- Session conversation content: text of your conversations with the coach, including anything typed or spoken.
- Voice recordings: if you use voice input, sent for transcription; we do not keep the audio file itself after transcription.
- Captured evidence and insights: the specific information confirmed with you at each step, and the summaries/closing narrative generated from them.
- Usage data: session timestamps, used for progress tracking and aggregate cohort reporting.
We do not collect payment information, government ID numbers, or health data through this product.
03
How we use it
- To run the coaching conversation, confirm what you've said, and carry confirmed evidence forward across sessions.
- To generate your session summaries, Insights page, and closing programme record.
- To report cohort-level progress (completion rates, timing) to your sponsoring organisation at an aggregate level, not by sharing individual conversation content, unless your programme's consent terms say otherwise.
- We do not use your data for advertising and do not sell it.
04
Who processes it (subprocessors)
- Supabase - our database, authentication, and file storage provider.
- Lovable AI Gateway - routes conversation and voice data to the models below.
- OpenAI - powers coaching conversations. By default, OpenAI does not use API data (including via gateways like Lovable's) to train or improve its models; this is opt-in only. Qualifying customers can also configure zero data retention.
- Google (Gemini) - powers voice transcription. Google states that prompts and responses are not used to improve its products for paid API services. Brief abuse-monitoring logging may still occur; we do not use Google's Search or Maps grounding features, so their extended retention windows don't apply here.
If this list changes, we'll update this policy and, for a material change, ask you to acknowledge it again.
05
Your rights
- Access and export: download a full export of everything we hold about you at any time, from Settings.
- Correction: you confirm every piece of captured evidence before it's saved, and can correct it in the moment; contact us for anything wrong after the fact.
- Deletion: permanently delete your account and all associated data at any time, from Settings - immediate and irreversible.
- If you are in Singapore, these reflect your access and correction rights under PDPA. Equivalent rights apply elsewhere under local law where applicable.
06
Research consent (programme-specific)
Where your programme is run in partnership with an academic or research institution, you'll be asked for a separate, explicit research-consent step at onboarding before any data is used for research or evaluation purposes beyond delivering the programme itself.
07
Data Retention & Deletion
While you're enrolled: your session conversations, captured evidence, and generated insights are kept for the duration of your programme, including the 30- and 60-day follow-up sessions after the core programme closes.
After the programme ends: data is kept for up to 6 months after programme close, to allow your closing report and any sponsor-level programme evaluation, then deleted or anonymised unless you delete it sooner yourself.
If your organisation's contract with us ends: typically, an exported copy of the organisation's aggregate, anonymised programme data is provided on request, and identifiable participant data is deleted within 30 days, unless we're legally required to keep it longer.
Self-service deletion: you can permanently delete your account and everything associated with it at any time, from Settings - an immediate, hard delete that removes your profile, enrolment, captures, insights, and conversation history, and cannot be undone.
Backups: deleted data may persist in encrypted daily backups for up to approximately 14 days before being fully purged, in line with our hosting provider's backup cycle.
Third-party AI processing: per their current API terms, OpenAI does not use this data for training by default and offers zero data retention to qualifying customers; Google does not use paid-API prompts/responses to improve its products and retains data only briefly for abuse monitoring.
08
Security
Access to your data is restricted at the database level so only you (and, for limited administrative purposes, your programme's administrators) can read it; all traffic is encrypted in transit, and data at rest is encrypted by our hosting provider. See also Breach Notification below.
09
International data transfer
Your data is hosted in AWS's Canada (Central) region (Montreal, Canada), and is also processed by our AI subprocessors (OpenAI, Google) as described above, which may process data outside Singapore. This is disclosed here per PDPA's transfer-limitation obligation.
10
Breach Notification Commitment
As of this version, monitoring relies on our hosting provider's platform-level logging; a dedicated, lightweight incident-detection process is being built ahead of the pilot, and this line will be updated once it's live.
If a breach occurs: we will assess its scope and severity within 24 hours of becoming aware of it. If it involves your organisation's participant data, we will notify your designated contact without undue delay, and in any case within 48 hours of confirming it's reportable. We'll tell you the nature of the breach, what data categories were affected, likely consequences, and what we're doing about it. Where required by law or where there's real risk to individuals, we'll notify affected participants directly too.
Escalation contact: Eric Saint-Andre, eric@asaadvisory.com.
11
Data Protection Officer
Eric Saint-Andre (eric@asaadvisory.com) is Mutarai's Data Protection Officer.
12
Children
This service is designed for working professionals participating in an organisational programme and is not directed at, or intended for use by, anyone under 18.
13
Changes to this policy
We'll post the effective date at the top of this page when it changes. For a material change, we'll ask you to re-acknowledge it.
14
Contact
For any question about this policy or your data, including deletion or correction requests: Eric Saint-Andre, Data Protection Officer, eric@asaadvisory.com.