PR CompassStart

Privacy policy

Last updated 26 September 2026

PR Compass ("we") is an independent educational tool. This policy explains what we collect, why, and your choices. We designed the product around the principles of Singapore's Personal Data Protection Act 2012 (PDPA): consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation and accountability.

Draft for review. This policy describes how the software is built. Before public launch it should be reviewed by a qualified adviser and completed with the operating entity's name and Data Protection Officer contact.

What we collect

  • Assessment answers — e.g. age, nationality, pass type, years in Singapore, approximate income, qualification level, family ties and application history. These are stored without your name or email.
  • Email address — only if you ask for the full report. Stored in a separate table from your answers, linked by an internal reference that can be removed.
  • Consent choices — whether you agreed to a one-time outcome follow-up and/or product updates, with timestamps.
  • Optional outcome reports — if you later tell us your ICA outcome, it is linked to your anonymous assessment, not to your email.

What we never collect

NRIC or FIN numbers, passport numbers, residential addresses, bank or card details, payslips or any document uploads.

Why we use it

  • To calculate and show your readiness indicator and checklist (the service you requested).
  • To email your report — only with your explicit consent.
  • To produce aggregated, anonymised statistics that improve our benchmarks. We never publish individual records.
  • If — and only if — you opt in: to ask you once, later, about your outcome, and/or to send product updates.

We do not sell personal data and we do not use it for advertising.

Retention

Assessments carry a retention date of 24 months from creation, after which they are scheduled for deletion. Emails that are no longer linked to any assessment are deleted. Aggregated statistics that cannot identify anyone may be kept.

Security

Data is sent over encrypted connections (HTTPS). Access links are protected with secrets that are stored only as one-way hashes. Database credentials and service keys are kept on the server and never exposed to your browser. Administrative access requires authentication, and we rate-limit and validate every submission.

Deleting your data

You can delete your assessment at any time from your results page or with the delete link in your report email. Deleting an assessment also deletes any outcome reports tied to it and your email address, if it is not linked to another assessment. To exercise access or correction rights, or to withdraw consent, contact us (address to be added before launch).

Go to the deletion page →

Cookies and local storage

We set one strictly necessary, httpOnly cookie so you can reopen your own results on this device. Your questionnaire draft and checklist ticks are kept in your browser's local storage only. We do not use advertising or cross-site tracking cookies. If analytics are enabled, we use a privacy-focused, cookieless tool that does not track you across sites.

Service providers

We may use infrastructure providers (hosting, database and email delivery) that process data on our behalf under contract. Some may store data outside Singapore; where they do, we require protection comparable to the PDPA.