Logo

Privacy Policy

Last updated: 25 September 2026.

Identity and Role of the Data Controller

journozenly operates as the data controller for the purposes of the Personal Data Protection Act 2012 of Singapore. We determine the purposes and means of processing personal data collected through our corporate health services platform.

Scope of This Notice

This policy applies to all individuals whose personal data we process in connection with our corporate health offerings, including employees of client organisations, visitors to our website, and participants in health programmes. It covers data collected via our site, contact forms, and related services.

Categories of Personal Data and Sources

We collect personal data such as names, contact details, employment information, health metrics from wellness assessments, and usage data from the website. Sources include direct submissions through forms, interactions with our blog content, and third-party referrals from corporate clients.

Purposes of Processing and Legal Bases

Data is processed to deliver corporate health programmes, respond to enquiries via the contact form, personalise wellness recommendations, maintain site security, and comply with legal obligations. Each purpose relies on consent, contractual necessity, or legitimate interests under the PDPA.

Requirement to Provide Data and Consequences

Providing certain data is necessary to access services or submit enquiries. Failure to supply required information may prevent us from delivering health programmes or responding to requests.

Cookies and Similar Technologies

We use cookies for functionality, analytics, and performance. Details are set out in our separate Cookie Policy, which is accessible from the site-wide cookie banner.

Processors, Recipients and Legal Disclosures

Service providers such as hosting platforms, analytics tools, and health programme partners may receive data under contract. We may disclose information when required by law or to protect rights.

International Transfers

Where data is transferred outside Singapore, we apply appropriate safeguards including contractual clauses to ensure protection consistent with the PDPA.

Retention Periods

Personal data is retained only as long as necessary for the stated purposes, typically up to seven years for contractual records or as required by law, after which it is securely deleted.

Security and Data Minimisation

We implement reasonable technical and organisational measures to protect data and collect only what is needed for each purpose.

Data Subject Rights

Individuals may request access, correction, or withdrawal of consent by contacting us through the details on our Contacts page. Requests are handled within the timeframes set by the PDPA.

Withdrawal of Consent and Objection to Marketing

Consent can be withdrawn at any time. You may also object to direct marketing by using unsubscribe links or contacting us directly.

Right to Complain

Complaints may be lodged with the Personal Data Protection Commission of Singapore at their official channels.

Children and Age Restrictions

Our services target corporate clients and are not directed at individuals under 18. We do not knowingly collect data from minors.

Automated Decision-Making and Profiling

We do not engage in solely automated decision-making that produces legal effects, though limited profiling may occur for wellness recommendations with human oversight.

Policy Changes

We may update this policy periodically. Continued use of the site after changes constitutes acceptance of the revised terms.