JOBURNENTER TERMINAL

LEGAL // DOC-PP-001

Privacy Policy

Version 1.0|Effective: 7 April 2026|Jurisdiction: Singapore (PDPA 2012)
SEC-01

Who We Are

This website and associated platforms are operated by Joburn Pte. Ltd., a company registered in Singapore, trading as “Funnel Futurist.”

Data Protection Officer:John Coburn
Contact:john@joburn.com
Registered Office:Singapore

References to “we,” “us,” or “our” in this policy refer to Joburn Pte. Ltd.

SEC-02

Scope

This policy applies to all personal data collected through our websites, applications, quizzes, assessments, roadmap tools, booking forms, chat interfaces, and any other digital surfaces operated by Joburn Pte. Ltd., including but not limited to:

  • joburn.com
  • funnelfuturist.com
  • quiz.funnelfuturist.com
  • audits.funnelfuturist.com
  • portal.funnelfuturist.com
SEC-03

Personal Data We Collect

When you interact with our platforms, we may collect the following categories of personal data:

CategoryDetailsBasis / Action
Identity dataFirst name, last name, email address, phone numberTo deliver services and communicate with you
Assessment responsesQuiz answers, self-assessment scores, diagnostic inputsTo generate personalized results, roadmaps, or recommendations
Technical dataIP address, device type, browser, timezone, operating systemPlatform functionality, security, and fraud prevention
Usage dataPages viewed, time on page, scroll depth, click patternsTo improve platform experience
Communication dataChat messages, form submissions, email correspondenceTo respond to inquiries and deliver requested services
Advertising dataAd click identifiers, UTM parameters, conversion eventsTo measure advertising effectiveness
Payment dataTransaction records, subscription status (card details handled by Stripe)Payment processing and invoicing
Meeting dataCall recordings, transcripts (with notice at time of recording)Quality assurance and record-keeping
Communication preferencesMarketing consent status, opt-in/opt-out choicesTo respect your communication choices

We do not collect NRIC, FIN, passport numbers, or sensitive personal data (health, race, religion) unless directly relevant to a service you have requested.

SEC-04

How We Use Your Data

We use your personal data only for the purposes consented to at the point of collection:

CategoryDetailsBasis / Action
Service deliveryDeliver quiz results, personalized roadmaps, audits, and consulting servicesConsent (provided at submission)
CommunicationsRespond to inquiries, send requested information, appointment confirmationsConsent (explicit opt-in)
MarketingNewsletters, product updates, promotional offersConsent (separate explicit opt-in — never pre-ticked)
AnalyticsPlatform performance, user experience optimizationLegitimate business purpose (anonymized/aggregated)
Advertising measurementConversion tracking, audience insights, campaign optimizationConsent (cookie/pixel consent)
Legal complianceTax records, regulatory obligations, dispute resolutionLegal requirement
SecurityFraud detection, abuse prevention, access controlLegitimate business purpose

We will never use your data for a purpose you did not consent to without first obtaining your additional consent.

SEC-05

How We Share Your Data

We share personal data only with trusted service providers who assist in delivering our services:

CategoryDetailsBasis / Action
Supabase (AWS US)Database hostingDPA in place; encryption at rest (AES-256) and in transit (TLS 1.3)
Vercel (US/EU edge)Platform hosting and deliveryDPA in place; SOC 2 Type II certified
Stripe (US)Payment processingPCI DSS Level 1 certified; we do not store card numbers
GoHighLevel (US)CRM and communication deliveryData processed per our service agreements
Meta Platforms (US)Conversion event data (hashed identifiers via CAPI)Data Processing Terms accepted; PII hashed with SHA-256 before transmission
Google Workspace (US)Email, calendar, document collaborationDPA in place; SOC 2 Type II certified
Fireflies.ai (US)Meeting transcription (with prior notice and consent)Data processed per service terms
Analytics providersAggregated, anonymized usage data onlyNo personal data shared with analytics providers

We do not sell personal data. We do not share personal data with third-party advertisers beyond the hashed conversion events described above.

When data is shared with a client of ours through our CRM platform (e.g., when you submit a form on a client’s behalf), that client becomes a joint controller of the data within their isolated account. Client accounts are segregated at the database level using row-level security.

SEC-05A

Our Role: Controller vs. Processor

Depending on the context, Joburn Pte. Ltd. operates in different data protection roles:

CategoryDetailsBasis / Action
Data ControllerWhen you interact directly with joburn.com, our quizzes, roadmaps, terminal chat, or booking formsWe determine the purposes and means of processing your data
Data ProcessorWhen we access Meta Marketing API data, CRM data, or advertising platform data on behalf of our clientsOur client is the controller; we process data per their instructions and our service agreement
Joint ControllerWhen a prospect submits data via a client-branded form that feeds into our shared infrastructureBoth Joburn and the client determine purposes; governed by our Master Services Agreement (Section 8)

When acting as a data processor on behalf of clients, our processing activities are governed by Data Processing Agreements and our Master Services Agreement. We do not use client data for our own purposes beyond the services contracted.

SEC-05B

Meta Platform Data

We use Meta (Facebook/Instagram) APIs to provide advertising performance reporting, audience insights, and campaign management services to our clients. This includes access to:

  • Ad performance metrics (impressions, clicks, conversions, spend)
  • Campaign and ad set configuration data
  • Audience insights (aggregated, non-personally-identifiable)
  • Conversion event data via the Conversions API (CAPI)

Our use of Meta Platform data is subject to Meta Platform Terms and Meta Developer Policies. All personally identifiable information transmitted to Meta via CAPI is hashed using SHA-256 before transmission. We do not store raw Facebook user IDs or access tokens beyond what is necessary for authorized API operations.

To request deletion of data associated with your Facebook or Instagram interactions with our services, see Section 11: Data Deletion Requests.

SEC-06

International Data Transfers

Your data is stored on servers in the United States (AWS US-East-1 via Supabase) and may be processed in the United States and European Union (Vercel edge network).

Under Section 26 of the PDPA, we ensure comparable protection through:

  • Contractual safeguards — Data Processing Agreements with all cloud providers imposing PDPA-comparable obligations
  • Encryption — All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access controls — Role-based, least-privilege access across all systems
SEC-07

Data Retention

We retain personal data only as long as necessary for the stated purpose:

CategoryDetailsBasis / Action
Client engagement dataDuration of engagement + 7 yearsContractual and tax/legal obligations (IRAS)
Lead/prospect data24 months from last interactionPermanently deleted or anonymized after period
Quiz/assessment responses24 months from last interactionPermanently deleted or anonymized after period
Payment records7 yearsIRAS compliance requirements
Meeting recordings12 monthsDeleted after quality assurance review
Technical/usage data12 monthsAnonymized and aggregated after period
Consent records7 yearsArchived securely, then deleted
Cold outreach data6 months from last contactPermanently deleted after period

“Last interaction” means any of: submitting a form, viewing a roadmap, clicking a link in our emails, booking a call, or contacting us.

SEC-08

Cookies and Tracking Technologies

Our platforms may use the following tracking technologies:

CategoryDetailsBasis / Action
Essential cookiesSession management, preferencesRequired for platform functionality (cannot opt out)
AnalyticsAggregated usage patternsOpt-out available via cookie settings or DPO contact
Meta Pixel / CAPIConversion events, page viewsOpt-out available; data hashed before transmission to Meta
URL parametersUTM tags, tracking tokensSession-based identifiers, not stored as cookies
SEC-09

Your Rights

Under the Personal Data Protection Act (PDPA), you have the right to:

CategoryDetailsBasis / Action
AccessRequest a copy of your personal dataEmail john@joburn.com
CorrectionRequest correction of inaccurate dataEmail john@joburn.com
Withdrawal of consentWithdraw consent for marketing or data processingClick "Unsubscribe" in any email, or email john@joburn.com
DisclosureKnow how your data has been used or disclosed in the past yearEmail john@joburn.com
Data deletionRequest deletion of your personal dataEmail john@joburn.com

We will respond to access and correction requests within 30 calendar days. If we cannot comply (e.g., legal obligation to retain), we will explain why.

Withdrawing consent for marketing will not affect the delivery of services you have already requested.

SEC-10

Additional Rights for EU/EEA Residents

If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) provides you with additional rights:

  • Right to erasure ("right to be forgotten") — Request complete deletion of your data
  • Right to data portability — Receive your data in a machine-readable format
  • Right to restrict processing — Request limitation of data processing in certain circumstances
  • Right to object — Object to processing based on legitimate interests, including profiling
  • Right to lodge a complaint — Contact your local EU supervisory authority

For GDPR-specific requests, contact john@joburn.com. We will respond within 30 days.

SEC-11

Data Deletion Requests

You may request the deletion of your personal data at any time by emailing john@joburn.com with the subject line “Data Deletion Request.”

We will confirm receipt within 5 business days, complete the deletion within 30 calendar days, and provide written confirmation once complete. Where data must be retained for legal obligations (e.g., tax records), we will explain which data is retained and why.

If you have interacted with our services through Facebook or Instagram, you may also submit a deletion request through your Facebook Settings under “Apps and Websites.”

SEC-12

Data Security

We implement reasonable technical and organizational measures to protect your personal data:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Row-level security on databases (client data isolation)
  • Role-based access controls (least-privilege principle)
  • Regular security reviews and vulnerability assessments
  • Incident response plan with breach notification procedures

No system is 100% secure. If we discover a data breach that may affect you, we will notify you and the Personal Data Protection Commission (PDPC) within 3 calendar days of assessment, in accordance with the PDPA’s mandatory breach notification requirements.

SEC-13

Do Not Call Registry

We comply with Singapore’s Do Not Call (DNC) Registry provisions. We will check the DNC Registry before sending telemarketing messages via voice calls, SMS, or fax to Singapore telephone numbers. You may register your number on the DNC Registry at www.dnc.gov.sg.

SEC-14

Children

Our platforms are not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has submitted data through our platforms, contact us immediately and we will delete the data.

SEC-15

Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email (if we have your contact information) or a prominent notice on our platforms.

The effective date at the top of this page indicates when this policy was last revised.

SEC-16

Contact Us

For any questions about this privacy policy or your personal data:

Data Protection Officer:John Coburn
Entity:Joburn Pte. Ltd.

You may also contact the Personal Data Protection Commission (PDPC) if you believe we have not adequately addressed your concern:

Phone:+65 6377 3131