Privacy Policy

Well Counselling & Psychotherapy ("we", "us", or "our") is committed to protecting the personal data of our users, customers, and website visitors in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and how we protect it. It also explains your rights regarding your personal data and how to contact us with questions or concerns.

This policy applies to personal data collected through our website at wellcounselling.sg, our mobile applications, and our offline interactions with you.

Effective date: 01 August 2026

Last updated: 22 August 2026

We may collect the following types of personal data:

Data you provide directly:

  • Name

  • Email address

  • Phone number

  • Mailing address

  • Company name

  • Payment information

  • Billing information

Data collected automatically:

  • IP address

  • Browser type and version

  • Device information

  • Pages visited and time spent on our website

  • Referring website or source

  • Cookies

  • Location data

Data from third parties:

  • Data from social media platforms, business partners, public databases

We collect and use your personal data for the following purposes:

  • Providing our services: To process your orders, manage your account, and deliver the products or services you request

  • Communication: To respond to your enquiries, send order confirmations, and provide customer support

  • Marketing: To send you promotional materials, newsletters, and updates about our products and services (with your consent)

  • Website improvement: To analyse website usage patterns and improve our website's functionality

  • Legal compliance: To comply with applicable laws, regulations, and legal obligations

  • Security: To detect, prevent, and address fraud, security issues, and technical problems

  • [ADD OTHER PURPOSES SPECIFIC TO YOUR BUSINESS]

We process your personal data based on the following legal bases under the PDPA:

  • Consent: Where you have given express consent (e.g., subscribing to our newsletter)

  • Deemed consent: Where you have voluntarily provided personal data for a purpose that is reasonable and apparent (e.g., submitting a contact form)

  • Deemed consent by notification: Where we have notified you of the intended use and you have not opted out within a reasonable period

  • Legal requirement: Where processing is required by Singapore law

  • Contractual necessity: Where processing is necessary to perform a contract with you

We may share your personal data with the following types of third parties:

  • Service providers: Companies that provide services on our behalf, such as payment processing, email delivery, website hosting, and analytics [NAME SPECIFIC PROVIDERS: e.g., Stripe, Mailchimp, Google Analytics, AWS]

  • Professional advisers: Lawyers, accountants, and auditors as necessary

  • Government authorities: Where required by law or in response to valid legal requests

  • Business transfers: In connection with a merger, acquisition, or sale of assets (with notice to you)

  • [ADD OTHER THIRD PARTIES SPECIFIC TO YOUR BUSINESS]

We require all third-party service providers to process your personal data in accordance with the PDPA and to implement appropriate security measures.

[IF APPLICABLE] Some of the third-party services we use may store or process your data outside Singapore. These include:

  • [SERVICE NAME] — data stored in [COUNTRY]

  • [SERVICE NAME] — data stored in [COUNTRY]

Where we transfer personal data outside Singapore, we ensure that the recipient provides a standard of protection comparable to the PDPA through contractual arrangements or other appropriate safeguards, in compliance with Section 26 of the PDPA.

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

  • Customer records: [X years] after the end of the customer relationship

  • Financial records: [5-7 years] as required by IRAS

  • Marketing data: Until you withdraw consent or unsubscribe

  • Website analytics data: [X months/years]

  • [ADD OTHER DATA TYPES AND RETENTION PERIODS]

When personal data is no longer needed, we will securely destroy or anonymise it.

We implement reasonable security measures to protect your personal data from unauthorised access, disclosure, alteration, and destruction. These measures include:

  • Encryption of sensitive data in transit and at rest

  • Access controls limiting data access to authorised personnel only

  • Regular security assessments and software updates

  • Staff training on data protection practices

  • Secure disposal of physical and digital records

While we take reasonable precautions, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security. For guidance on what to do if a breach occurs, see our data breach notification guide.

Under the PDPA, you have the following rights:

Right to access: You may request access to the personal data we hold about you. We will respond within 30 days of receiving your request. A reasonable fee may apply.

Right to correction: You may request that we correct any inaccurate or incomplete personal data. We will make corrections as soon as practicable.

Right to withdraw consent: You may withdraw your consent for any specific purpose at any time by contacting our DPO. We will process your withdrawal within [X business days]. Please note that withdrawal of consent may affect our ability to provide certain services to you, and we will inform you of the likely consequences.

To exercise any of these rights, please contact our Data Protection Officer using the details below.

Our website uses cookies and similar technologies to enhance your browsing experience and collect analytics data.

Essential cookies: Required for the website to function properly Analytics cookies: Help us understand how visitors interact with our website (e.g., Google Analytics) Marketing cookies: Used to deliver relevant advertisements

You can manage your cookie preferences through your browser settings. Disabling cookies may affect the functionality of our website.

Our Data Protection Officer (DPO) is responsible for overseeing our compliance with the PDPA.

DPO Contact:

  • Name/Title: [DPO NAME or "Data Protection Officer"]

  • Email: [dpo@yourcompany.com]

  • Phone: [PHONE NUMBER, if applicable]

  • Address: [BUSINESS ADDRESS]

If you have any questions about this privacy policy, wish to exercise your rights, or have concerns about how we handle your personal data, please contact our DPO.

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by [posting a notice on our website / sending an email notification / other method].

We encourage you to review this policy periodically.