Effective date: 31 August 2026
This Privacy Policy explains how Discerning Solutions (S) Pte Ltd ("Discerning Solutions", "DSN", "we", "us" or "our") collects, uses, discloses, protects, retains and otherwise handles personal data in connection with:
thediscerning.one and its webpages;
enquiries and contact forms;
newsletters, briefings and events;
research and diagnostic participation;
accounts, memberships or client portals where offered;
commissioned work carried out through The House of Discernment;
Decision Credit administration where applicable;
partner, supplier and practitioner relationships;
recruitment and professional enquiries; and
other interactions that refer to this Privacy Policy.
TheDiscerning.One is the public institutional brand of The House of Discernment. DSN identifies the family of governed methods, modules, engines, standards and decision systems developed within the House.
This Privacy Policy is intended to operate consistently with Singapore's Personal Data Protection Act 2012 ("PDPA") and other applicable data-protection requirements.
1. What is personal data?
In this Privacy Policy, personal data means data about an individual who can be identified:
from that data; or
from that data together with other information to which the relevant organisation has or is likely to have access,
as understood under applicable law.
Personal data does not have to be highly sensitive to be protected.
Depending on how you interact with us, it may include your name, professional contact details, account information, communications, research responses, transaction information, online identifiers or other information associated with you.
2. Our role
Discerning Solutions may handle personal data in different roles depending on the context.
For example:
when you contact us directly, subscribe to a briefing, register for an event or manage an account, we normally determine why and how the relevant personal data is used;
in some commissioned engagements, a client may provide personal data for DSN to process on the client's behalf and for the client's purposes;
in other engagements, DSN may determine its own legitimate and lawful purposes for selected information required to perform the governed method, maintain a Decision Record, protect method integrity or meet legal and business obligations.
Where a separate written agreement allocates data-protection responsibilities between DSN and a client, partner or service provider, that agreement also applies.
3. Personal data we may collect
The personal data we collect depends on your relationship with us.
3.1 Identity and contact information
This may include:
name;
job title;
organisation;
work email address;
telephone number;
country or market; and
other contact details you choose to provide.
3.2 Professional and organisational information
This may include:
role and responsibilities;
decision authority;
team, function or market;
professional biography;
employer or client relationship;
relevant expertise; and
information needed to understand your role in a DSN engagement.
3.3 Account and access information
Where account or restricted-access features are offered, this may include:
username or account identifier;
authentication and security information;
account permissions;
membership or access level;
login and access logs; and
account-support records.
We should not need your password in readable form.
3.4 Commercial and transaction information
Where paid services, Decision Credits or other commercial arrangements are offered, this may include:
billing contact information;
organisation and invoice information;
order, activation and delivery records;
payment status;
Decision Credit wallet or allocation records;
subscription or membership status; and
related commercial communications.
Payment-card information may be collected directly by an authorised payment provider rather than stored by DSN, depending on the payment arrangement in use.
3.5 Decision, research and engagement information
If you participate in research, a diagnostic, workshop, interview, survey or commissioned DSN engagement, we may collect information such as:
your responses and observations;
professional opinions;
interview or workshop notes;
research answers;
decision roles and authority;
stakeholder positions;
evidence you provide;
assumptions, disputes or unknowns associated with a case;
approvals, exceptions or overrides attributed to responsible individuals; and
records needed to reconstruct the governed decision process.
We seek to collect only the personal data that is reasonably necessary for the relevant purpose.
3.6 Communications and preferences
This may include:
enquiries;
correspondence;
meeting requests;
newsletter preferences;
marketing choices;
feedback;
complaints;
event registrations; and
records of consent or withdrawal.
3.7 Website and technical information
Depending on the Site configuration, we may collect:
IP address;
browser and device information;
operating system;
pages visited;
date and time of access;
referring page;
approximate location derived from technical data;
cookie or similar identifiers;
interaction and performance information; and
security or diagnostic logs.
3.8 Recruitment, practitioner and partner information
If you apply to work with or for DSN, seek accreditation or licensing, or engage as a partner or supplier, we may collect:
CV or professional history;
qualifications;
portfolio or work samples;
references;
accreditation and training records;
conflicts information;
contractual information; and
records of authority or quality review.
4. How we collect personal data
We may collect personal data:
directly from you;
from your organisation or another authorised representative;
through the Site;
through forms, surveys, interviews, workshops or events;
during a commissioned DSN engagement;
through contracts, proposals, invoices or account administration;
from partners or service providers acting under an appropriate arrangement;
from public professional sources where lawful and relevant;
from public records or publicly available sources; and
automatically through website or security technologies.
Where another person provides your personal data to us, we may rely on that person or organisation to have the authority required to provide it, subject to our own obligations under applicable law.
5. Why we collect, use and disclose personal data
We may collect, use or disclose personal data for purposes including:
5.1 Operating the Site
providing pages and features;
responding to enquiries;
maintaining accounts;
securing and troubleshooting the Site;
analysing Site performance; and
improving accessibility and usability.
5.2 Providing DSN services
understanding and scoping a request;
determining whether DSN should accept, decline, refer or route work;
conducting research;
operating the DSN:Game-First Engine;
performing authorised DSN modules;
maintaining appropriate records;
delivering outputs;
monitoring agreed conditions; and
supporting review or institutional learning.
5.3 Decision governance and accountability
Where relevant to a commissioned case, we may use limited personal data to identify:
decision owners;
responsible practitioners;
evidence providers;
approvers;
authorised challengers;
adaptation authorities;
exception or override authorities; and
other accountable participants.
The purpose is not to create personal profiles unrelated to the decision. It is to keep authority, evidence and accountability traceable.
5.4 Commercial administration
preparing proposals;
administering Decision Credits;
maintaining activation and delivery records;
issuing invoices;
reconciling payments;
managing subscriptions or memberships; and
keeping appropriate financial and business records.
5.5 Communications and relationship management
sending requested materials;
managing meetings and events;
providing relevant service information;
sending newsletters or briefings where permitted;
responding to feedback or complaints; and
maintaining professional relationships.
5.6 Research, quality and improvement
evaluating method performance;
quality assurance;
calibration;
audit and traceability;
improving research and service delivery;
developing aggregate or de-identified learning; and
improving the Game-First Decision Architecture.
Where possible and appropriate, we prefer aggregate, de-identified or anonymised information for institutional learning
that does not require individuals to remain identifiable.
5.7 Legal, security and integrity purposes
complying with law or lawful requests;
establishing, exercising or defending legal rights;
detecting and preventing fraud, misuse or security incidents;
investigating suspected unauthorised use of DSN materials;
protecting confidential information;
enforcing agreements; and
maintaining business continuity.
5.8 Minimum-necessary and purpose-bound handling
DSN takes a privacy-first, minimum-necessary approach to personal data and client information. We seek to collect, receive and use only the information reasonably necessary for the authorised purpose of the Site interaction, engagement, research task or governed decision work.
Where aggregated, de-identified, anonymised or less-identifiable information can reasonably serve the same purpose, DSN should prefer that form over collecting or retaining more identifiable information than is needed.
Providing information to DSN does not, by itself, transfer ownership of client information to DSN. Our right to use client information is limited by the applicable purpose, this Privacy Policy, the relevant engagement terms, confidentiality obligations and applicable law.
Our objective is not to collect more data. It is to use the minimum evidence necessary to sharpen the decision while protecting the information entrusted to us.
6. Consent and other permitted bases
Where the PDPA or another applicable law requires consent, we will seek or rely on consent in accordance with the law.
In some circumstances, applicable law permits personal data to be collected, used or disclosed without fresh consent or treats consent as deemed in specified circumstances. We will rely on such grounds only where their legal requirements are satisfied.
We will not treat the existence of a commercial relationship as unlimited permission to use personal data for unrelated purposes.
7. Withdrawal of consent
Where we rely on your consent, you may withdraw that consent by giving reasonable notice.
We will explain the likely consequences of withdrawal where required.
Withdrawal does not require us to erase information that we are legally entitled or required to retain, and it does not affect processing that occurred lawfully before withdrawal.
Depending on the information concerned, withdrawing consent may mean that we cannot continue providing a feature, communication or service that depends on that information.
To withdraw consent, contact our Data Protection Officer using the details in Section 19.
8. Marketing communications and Singapore telephone numbers
Where we send marketing or promotional communications, we will do so in accordance with applicable requirements.
You may unsubscribe from marketing emails using the method provided in the communication or by contacting us.
Where Singapore's Do Not Call requirements apply to specified marketing messages sent to Singapore telephone numbers, we will comply with the applicable consent, registry-checking and identification requirements.
Service, transactional, security and engagement communications may still be sent where they are necessary and legally permitted.
9. Cookies, Google Analytics and similar technologies
The Site is built and hosted using Google Sites. In operating the Site, Google Sites and related Google services may use
cookies and similar technologies to deliver webpages, maintain security, prevent abuse, remember settings, support
functionality and measure how the Site is used.
9.1 Google Analytics
We use Google Analytics to understand how visitors use thediscerning.one and to help us improve the Site's content, usability and performance.
Depending on the Google Analytics configuration in use, Google Analytics may collect information such as:
the number of users and sessions;
pages viewed and interactions with the Site;
session statistics;
browser and device information;
approximate geolocation; and
technical information used for measurement, security and service operation.
Google Analytics uses first-party cookies and similar technologies to distinguish users and sessions. For example, Google identifies _ga as a principal first-party cookie used by Google Analytics to distinguish visitors. Google services may also use other cookies or identifiers depending on the services, features, device and user settings involved.
We do not intentionally send names, email addresses or other directly identifying information to Google Analytics as analytics identifiers.
9.2 How Google collects and processes data
When you visit a site that uses Google services, your browser may send information to Google, including the URL of the page you are visiting and your IP address. Google may also set cookies on your browser or read cookies that are already present. Google uses information received from sites and apps that use its services to provide, maintain, improve and secure those services and, depending on the Google services and settings involved, for measurement and personalisation purposes.
For Google's explanation of how it collects and processes information when you use websites or apps that use Google services, please read:
How Google uses information from sites or apps that use our services
You may also review Google's Privacy Policy for more information about Google's privacy practices.
9.3 Your cookie and analytics choices
You can control or delete cookies through your browser or device settings. Blocking or deleting some cookies may affect Site functionality or the way Google services operate.
Google also provides the Google Analytics Opt-out Browser Add-on, which may be used to prevent Google Analytics from using your activity on websites where the add-on is supported.
Google also provides privacy and data controls for its services. Where required by applicable law, we will provide an appropriate notice or choice mechanism for non-essential cookies or comparable technologies used on the Site.
9.4 Browser Do Not Track and privacy preference signals
Some web browsers and browser extensions allow users to send a Do Not Track ("DNT") signal or other privacy preference signals when visiting websites.
thediscerning.one is hosted using Google Sites. DSN does not currently operate a separate site-level mechanism that interprets a browser DNT signal as an instruction to disable cookies, Google Sites technologies or Google Analytics.
Sending a DNT signal therefore does not, by itself, guarantee that cookies or analytics technologies used through Google services will be disabled on the Site.
DNT should not be confused with privacy preference signals that may have specific legal effect in certain jurisdictions, such as Global Privacy Control ("GPC"). Where applicable law requires DSN to recognise a qualifying opt-out preference signal for processing that is within DSN's control, we will take reasonable steps to honour that requirement.
You can still use the cookie and analytics choices described in Section 9.3, including browser or device settings and any consent or privacy controls made available by Google. DSN does not sell personal data to advertisers.
For information about Global Privacy Control, you may visit globalprivacycontrol.org.
9.5 Embedded and third-party content
The Site may contain embedded Google services or other third-party content. When such content is loaded or used, the relevant provider may place or read its own cookies or similar technologies and process information under its own privacy terms.
This Privacy Policy describes DSN's use of these technologies. Google's independent collection and processing of information is governed by Google's own terms and privacy policies.
10. AI-enabled systems, AI governance and personal data
The House is AI-enabled and human-governed.
Where applicable to the way DSN develops, deploys or materially relies on AI, our governance approach is designed to align with the principles and practices described in Singapore's Model Artificial Intelligence Governance Framework (Second Edition). The Model Framework is voluntary and does not replace our obligations under the PDPA or any other applicable law, regulation, contractual requirement or sector-specific rule.
10.1 Responsible AI principles
When DSN uses AI, we seek to apply it in a manner that is:
human-centric, with the interests, well-being and legitimate expectations of people considered in the design and use of AI-supported processes;
transparent, so that material use of AI is not deliberately concealed from people who reasonably need to understand its role;
explainable, to a level appropriate to the purpose, audience, consequence and technical feasibility of the use case;
fair, with reasonable attention to the risk that data, models or AI-generated outputs may create or amplify inappropriate bias or unjustified differential treatment; and
accountable, with identifiable human responsibility for consequential judgments and appropriate records of material decisions.
Perfect explainability, transparency or fairness may not always be technically achievable. Where limitations exist, they should be considered in deciding how much reliance may reasonably be placed on the AI-supported output and what additional human review or other safeguards are required.
10.2 How AI may support DSN work
Where appropriate and authorised, AI-supported tools may assist with tasks such as:
organising and classifying evidence;
summarising material;
identifying patterns or relationships;
detecting contradictions or possible inconsistencies;
generating or testing hypotheses;
monitoring conditions and possible review triggers;
supporting research and analysis;
maintaining or structuring records;
routing workflow;
drafting or transforming working material; and
surfacing matters for human examination.
AI-generated or AI-assisted output is treated as an input to judgment rather than proof merely because it was produced by an AI system.
Material claims remain subject to the evidence, verification, attribution and human-governance requirements applicable to the relevant DSN method or engagement.
10.3 Human involvement and accountable authority
DSN determines the appropriate level of human involvement according to the purpose and context of the AI use and, where relevant, factors such as:
the probability and severity of potential harm;
the nature of the potential harm;
the reversibility of the consequence;
the ability of an affected person or organisation to obtain review or recourse;
the importance of the decision;
the uncertainty or limitations of the AI-supported output; and
whether human involvement is operationally feasible and meaningful.
For formal DSN judgments and other consequential decisions within the governed DSN architecture, DSN applies a human-in-the-loop approach: AI may provide analysis, recommendations, classifications or other inputs, but an authorised human must review the relevant basis and exercise the final DSN judgment.
An AI system does not independently become the accountable authority for:
determining the material consequences that should be accepted;
deciding how competing human or organisational interests should legitimately be weighted;
determining whether an organisation has permission to proceed;
making an invested commitment on behalf of a client;
approving exceptions or overrides;
issuing a formal PRISM ruling;
representing a CGS strategic posture as a permanent organisational identity; or
accepting organisational accountability for the decision.
Human authority must remain identifiable and appropriate to the consequence involved.
10.4 Data governance and AI operations
Where AI-supported systems process personal data or other information used in DSN work, we seek to apply controls proportionate to the purpose, sensitivity, consequence and technical context.
Depending on the use case, these controls may include:
limiting data to what is reasonably necessary for the authorised purpose;
considering the source, lineage or provenance of material data where relevant;
assessing the accuracy, completeness, relevance, currency, credibility and context of material data;
identifying material evidence gaps and data limitations;
considering whether datasets or inputs may contain inherent or systematic bias;
distinguishing verified evidence from interpretation, assumption and unknowns;
applying access, confidentiality and security controls;
maintaining appropriate records of material AI-assisted processing and human review;
monitoring AI-supported workflows for errors, drift, unexpected behaviour or changing conditions; and
reviewing whether the continued use of an AI-supported process remains appropriate.
For AI features or workflows with greater potential impact, DSN may apply additional risk-based measures where appropriate and technically feasible, such as:
enhanced explainability or documentation;
repeatability or consistency checks;
robustness or scenario testing;
traceability;
periodic review or tuning;
reproducibility testing where meaningful; or
audit-readiness.
The level of control should be proportionate to the impact and risk of the AI-supported activity. Not every measure is
necessary or technically meaningful for every AI system.
10.5 Transparency, explanation, feedback and human review
Where AI is used in a manner that materially affects an individual's interaction with DSN or materially contributes to a decision concerning that individual, we seek, where appropriate, to provide information that is understandable in the relevant context.
This may include information about:
the fact that AI is being used;
the purpose for which it is being used;
the role AI plays in the relevant process;
whether a human makes or reviews the consequential decision;
material limitations that are relevant to the individual's understanding; and
available channels for questions, feedback, correction or review.
Where personal data used in an AI-supported process is inaccurate, an individual may use the access or correction channels described in this Privacy Policy, subject to applicable law.
Where an AI-augmented decision made within DSN's authority materially affects an individual, DSN will consider whether an appropriate human review or other avenue of recourse should be available, having regard to the consequence, reversibility, feasibility and applicable legal requirements.
10.6 Third-party AI providers
DSN may use third-party AI solution providers or technology services.
Where such providers may process personal data, confidential information or information material to a governed decision, DSN seeks to assess and manage the relationship proportionate to risk.
Client-confidential, personal or otherwise restricted information should not be moved into an unapproved AI environment merely because doing so would make the work easier or faster. Where AI processing is contemplated, DSN considers whether the relevant system is approved for that type of information and whether minimisation, redaction, de-identification or another safeguard is appropriate before processing.
Depending on the service and the information reasonably available from the provider, this may include consideration of:
the types of data processed;
relevant data sources and data-handling arrangements;
security and access safeguards;
provider terms concerning retention and use of submitted data;
the role of human involvement;
known limitations of the AI service;
available information about model behaviour, safeguards or bias mitigation;
transfer or hosting locations where relevant; and
the provider's ability to support DSN's accountability, traceability and contractual obligations.
The use of a third-party AI provider does not transfer DSN's accountability for the way DSN chooses to use the provider's output.
We do not intend to use client confidential information or personal data to train a public general-purpose AI model unless that use has an appropriate lawful basis and is expressly authorised where required.
Where appropriate, a specific AI provider or commissioned workflow may also be governed by an applicable engagement agreement, confidentiality arrangement, data-processing agreement, security requirement or other contractual control.
10.7 Review of AI governance
AI governance is not treated as a one-time technical approval.
Where appropriate to the scale and consequence of the AI use, DSN may periodically review:
whether the original purpose for using AI remains valid;
whether the level of human involvement remains appropriate;
whether material risks, limitations or stakeholder impacts have changed;
whether data and outputs remain sufficiently reliable for the intended use;
whether safeguards and communication remain effective;
whether the AI provider or technical configuration has materially changed; and
whether continued use remains consistent with DSN's method, privacy and accountability requirements.
Material changes may require renewed risk assessment, additional safeguards, changes to human oversight, revised communication or discontinuation of the relevant AI-supported process.
The DPO oversees personal-data protection matters arising from AI use. Responsibility for the substantive use of AI, method judgment and organisational accountability remains with the authorised human roles assigned to those functions.
11. Decision Records and personal data
A Decision Record is the governed institutional account of an invested decision.
Where a Decision Record is created, limited personal data may be included where necessary to identify:
decision ownership;
source attribution;
practitioner authority;
approval responsibility;
exception or override authority;
version responsibility; or
another material accountability relationship.
The Decision Record should not become a repository for unrelated personal information.
The Decision Record is intended to preserve accountability, not to operate as a data warehouse. Where reasonably practicable, raw datasets, complete transcripts and source files should remain in their appropriate controlled source
locations, while the Decision Record preserves only the evidence, metadata, attribution or controlled reference necessary to reconstruct the judgment.
Access to Decision Record content should be limited to people, systems and authorised partners whose roles require that access.
Where personal data can be minimised, coded, aggregated or de-identified without weakening the integrity of the decision record, DSN should consider doing so.
A Decision Record may need to be retained longer than ordinary website enquiry data where retention remains necessary for:
contractual performance;
audit and traceability;
legal or regulatory obligations;
dispute management;
method quality; or
legitimate business recordkeeping.
Retention remains subject to Section 15 below.
12. When we disclose personal data
We may disclose personal data where reasonably necessary to:
service providers acting for or with us;
hosting, cloud, security and IT providers;
email, communications and collaboration providers;
research or survey providers;
payment and billing providers;
professional advisers;
authorised DSN practitioners;
approved partners supporting an engagement;
the relevant client or commissioning organisation;
auditors or quality reviewers;
regulators, courts, law-enforcement or public authorities where legally required;
a buyer, investor or successor in connection with a legitimate corporate transaction, subject to appropriate safeguards;
or another party where you have authorised the disclosure or the law permits it.
We do not sell personal data to advertisers.
DSN does not disclose personal data outside the authorised processing chain except where disclosure is reasonably necessary for an authorised purpose described in this Privacy Policy or an applicable engagement, required to operate an approved service, authorised by the relevant individual or organisation where appropriate, or permitted or required by law.
Where a service provider or approved partner is part of that processing chain, access should be limited to the information reasonably necessary for its role and subject to proportionate contractual, confidentiality, security and oversight controls.
Where a service provider processes personal data on our behalf, we seek to use appropriate contractual, security and oversight arrangements according to the nature of the data and service.
13. Third-party links and services
The Site may contain links to third-party sites or use third-party platforms.
Those parties may collect personal data under their own policies and for their own purposes.
This Privacy Policy does not govern a third party's independent handling of personal data merely because its service is linked from or embedded in our Site.
You should review the relevant third-party privacy information where appropriate.
14. Overseas transfers
Some service providers, cloud infrastructure, research tools, collaboration systems or authorised recipients may be located outside Singapore or may process data outside Singapore.
Where the Singapore PDPA's Transfer Limitation Obligation applies, we will take steps required by law to ensure that transferred personal data receives a standard of protection comparable to the protection required under the PDPA.
Depending on the circumstances, those safeguards may include legally enforceable contractual obligations, due diligence, binding arrangements or another transfer mechanism permitted by law.
15. Retention
We do not intend to keep identifiable personal data indefinitely merely because it might be useful later.
We will cease retaining documents containing personal data, or remove the means by which the data can be associated with particular individuals, when it is reasonable to assume that:
the purpose for which the personal data was collected is no longer being served by retention; and
retention is no longer necessary for legal or business purposes,
subject to applicable law and legitimate recordkeeping requirements.
Different categories of records may have different retention periods.
Factors may include:
the purpose of collection;
the duration of an engagement;
contractual requirements;
audit and traceability needs;
legal limitation periods;
financial and tax record requirements;
dispute or investigation needs;
security requirements; and
whether information can be safely anonymised or de-identified.
DSN should maintain an internal retention schedule that reflects the live systems and record categories actually used.
At the end of an engagement, client information may, as appropriate, be returned, deleted, securely disposed of, de-identified or retained as part of a governed record. The treatment will depend on the authorised purpose, applicable law, legitimate business and audit requirements, the Decision Record requirements and the relevant contractual terms.
Working copies and duplicate material should not be retained merely for convenience once they are no longer required for an authorised purpose.
16. Protection and security
We take reasonable steps to protect personal data in our possession or under our control against risks such as:
unauthorised access;
unauthorised collection;
unauthorised use or disclosure;
copying or modification;
improper disposal; and
loss of storage media or devices.
Controls may include, where appropriate:
access restrictions;
authentication;
encryption or secure transmission;
least-privilege access;
vendor due diligence;
security logging;
backups;
environment separation;
staff and practitioner obligations;
incident-response procedures; and
review of access when roles or engagements change.
For client and engagement information, DSN also seeks to apply a need-to-know and least-privilege approach. Where appropriate, client work should be separated by organisation or engagement, and access should be limited to approved people, systems and partners according to their authorised role.
Sensitive or confidential information should be stored, transferred and shared only through systems or channels approved for the relevant type of information. Security measures may include strong authentication, encryption in transit and, where supported and appropriate, encryption at rest, access logging, controlled sharing permissions and secure disposal.
Restricted information should not be transferred into an unapproved system, personal account or uncontrolled communications channel merely for convenience.
No method of electronic storage or transmission is completely risk-free. Security controls reduce risk; they do not create a guarantee that a breach can never occur.
17. Data breaches
If we have reason to believe that a data breach has occurred, we will assess and manage it in accordance with applicable law and our incident-response processes.
Where a breach is notifiable under the Singapore PDPA or another applicable law, we will make the required notifications to the relevant authority and/or affected individuals within the applicable legal requirements.
Where an incident materially affects client information, DSN will also assess whether the affected client or commissioning organisation must be notified under the applicable engagement, confidentiality arrangement, data-processing terms or other contractual requirements, in addition to any notification required by law.
We may also take steps such as:
containing the incident;
preserving evidence;
investigating cause and scope;
resetting or restricting access;
notifying affected clients or partners where appropriate;
correcting control failures; and
documenting lessons and remedial actions.
18. Access and correction
Subject to the PDPA and any applicable exceptions, you may request:
access to personal data about you that is in our possession or under our control, together with information about how it has been used or disclosed within the relevant statutory scope; and
correction of an error or omission in your personal data.
We may need to verify your identity before acting on a request.
Some information may be exempt from access or correction requirements, or may need to be redacted to protect another person's rights or confidential information, as permitted by law.
To make a request, contact our Data Protection Officer using the details below.
19. Complaints and concerns
If you have a concern about our handling of personal data, please contact our Data Protection Officer at ask.us@thediscerning.one; so that we can review the matter.
DSN maintains a Data Protection Complaints Process explaining how to raise a concern, what information to provide, how we investigate and respond, and how unresolved concerns may be escalated.
We encourage individuals to raise concerns with DSN first so that we have a reasonable opportunity to clarify, investigate or resolve the matter. A concern that indicates a possible data breach or active security incident may be escalated immediately through our incident-response process rather than waiting for the ordinary complaint workflow.
Nothing in our complaints process removes any right you may have to raise a matter with the Personal Data Protection Commission of Singapore or another competent authority.
20. Children's personal data
The Site and DSN's commercial decision services are primarily directed at organisations and adult professionals.
We do not intend to collect personal data from children merely for commercial profiling.
If an engagement, research activity or public programme legitimately involves minors, DSN should apply the consent, notice, safeguarding and data-minimisation controls appropriate to the context and applicable law before collecting the relevant personal data.
If you believe a child has provided personal data to us inappropriately, please contact our DPO.
21. Accuracy of personal data
We take reasonable steps to ensure that personal data we use or disclose is sufficiently accurate and complete where inaccurate data could materially affect the individual or the purpose for which the information is used.
You can help by telling us when material contact, account or professional information changes.
In a governed decision process, a correction to factual personal data does not permit the historical decision record to be silently rewritten. Where a historical record must be corrected, the correction should preserve appropriate traceability of what changed and why.
22. De-identification, anonymisation and institutional learning
The House of Discernment separates learning from hindsight rewriting.
Where case information is used for institutional learning, research, calibration, teaching or public case material, DSN should consider whether the purpose can be achieved through:
aggregation;
de-identification;
anonymisation;
masking;
pseudonymisation; or
removal of unnecessary personal details.
Public case material should not disclose confidential client or personal information without appropriate authority.
Anonymised information should not be deliberately re-identified except where lawfully authorised and necessary for a legitimate purpose.
23. Client and third-party responsibilities
If your organisation gives DSN personal data about employees, customers, research participants, agency staff,
suppliers or other individuals, your organisation is responsible for ensuring that it has the authority to provide that
information and has met any notice, consent or other legal requirements that apply to it.
DSN may require:
data minimisation;
removal of unnecessary identifiers;
a data-processing agreement;
approved transfer arrangements;
participant notices or consent wording; or
another control before accepting certain data.
A client's desire to provide data does not require DSN to accept data that is unnecessary, excessively sensitive or outside the authorised scope.
24. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in:
law or regulatory guidance;
our services;
the Site;
our technology and service providers;
the Game-First Decision Architecture;
our internal privacy and security practices; or
the ways in which we handle personal data.
The effective date at the top of the Policy identifies the current public version.
Where appropriate, we may provide additional notice of a material change.
A change to this Privacy Policy does not authorise DSN to use personal data for an unrelated new purpose where applicable law requires a new notification, consent or other lawful basis.
25. Relationship with other agreements
This Privacy Policy provides the general public explanation of DSN's personal-data practices.
A commissioned engagement may also be governed by:
a confidentiality agreement;
a data-processing agreement;
a research participant notice or consent;
a statement of work;
a Decision Credits Operating Standard;
information-security requirements; or
another contract.
Where a separate agreement lawfully allocates more specific privacy or security obligations, those specific terms apply to that engagement.
26. Closing principle
The House of Discernment depends on traceability without turning traceability into unnecessary surveillance.
Our aim is to collect and keep the information reasonably needed to:
understand the work;
preserve evidence and accountability;
protect the decision record;
deliver authorised services;
comply with law; and
learn responsibly,
while limiting personal data that does not serve those purposes.
Good decision governance requires knowing who had authority.
It does not require collecting everything that can be known about a person.