Privacy Policy

Last updated: 26 June 2026

This Privacy Policy describes how Organic Raspberry Pte. Ltd. (trading as "Sophia", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use the Sophia platform, websites (sophiawomen.com and sophiawomen.ai), digital courses, AI money coaching application, and related services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not access or use our Services.

1. Who We Are

Organic Raspberry Pte. Ltd. (UEN: 202297027Z) is the data controller responsible for your personal data. We are incorporated in Singapore and provide Services across Singapore, Hong Kong, the United Kingdom, and Australia.

Contact: [email protected] | #02-01, 68 Circular Road, Singapore 049422

UK Representative (UK GDPR Art. 27): DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom. DataRep is Sophia's appointed representative for the purposes of UK GDPR Article 27 and is the point of contact for UK data subjects and the Information Commissioner's Office (ICO) in respect of Sophia's processing of UK personal data. See Section 9 for contact details.

2. Scope and Applicable Laws

This Privacy Policy is designed to comply with the following data protection frameworks, depending on where you are located:

Where the laws of your jurisdiction grant you additional rights, we will honour those rights to the extent required by law.

3. Personal Data We Collect

3.1 Data You Provide Directly

3.2 Data Collected Automatically

3.3 Data from Corporate Partners (B2B Channel)

Where your employer or corporate partner has enrolled you in the Sophia platform as part of an employee benefit or financial wellness programme, we may receive your name, work email address, and enrolment information from that corporate partner. The corporate partner's use of your data is governed by their own privacy policy and any Data Processing Agreement (DPA) entered into with us.

3.4 AI and Human Coaching — Special Notice

Our coaching services include both AI-generated coaching and sessions with human coaches. Both process the financial context data you provide (e.g. life goals, monthly savings amount, savings habits) to deliver personalised educational guidance. In both cases:

We apply heightened care to all coaching data and do not use it for advertising or share it with third parties for marketing purposes. Human coaching session notes and summaries are accessible only to the coach assigned to you and authorised Sophia staff. Where your coach creates a session summary, this is done only with your consent. You may withdraw consent for session summaries at any time without affecting your right to continue using the coaching service.

4. How We Use Your Personal Data

4.1 To Provide and Improve our Services

Legal basis: performance of contract (Singapore PDPA: contractual necessity / legitimate purpose; UK GDPR Art. 6(1)(b); HK PDPO: use directly related to collection purpose).

4.2 Communications

Legal basis: consent (for marketing); legitimate interests / contractual necessity (for transactional communications). You may opt out of marketing communications at any time.

4.3 Analytics and Service Development

Legal basis: consent. You may grant or withdraw analytics consent at any time in your account settings. See Section 7 for further details.

4.4 Legal and Compliance

5. Sharing Your Personal Data

We do not sell your personal data. We may share it in the following circumstances:

5.1 Service Providers

We engage trusted third-party service providers who assist us in operating our Services. These include providers in the following categories:

All service providers are contractually bound to process your personal data only on our instructions, for specified purposes, and in compliance with applicable data protection law. We maintain a register of sub-processors which is available to corporate partners upon request under a signed Data Processing Agreement.

5.2 Corporate Partners

Where you access Sophia through an employer or corporate partner, we may share aggregated, anonymised programme engagement data with that partner (e.g. overall course completion rates). We do not share individual personal data with corporate partners without your consent, except where required under the applicable DPA.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred to the successor entity, subject to equivalent privacy protections.

5.4 Legal Requirements

We may disclose your data to comply with applicable law, court order, or lawful government request, or to protect the safety, rights, or property of Sophia, our users, or the public.

6. International Data Transfers

Your data may be processed in countries other than Singapore, including where our service providers are located. We take steps to ensure that any cross-border transfers comply with applicable law, including:

Details of international transfer safeguards for specific sub-processors are available to corporate partners upon request under a signed Data Processing Agreement.

7. Storage and Analytics Technologies

Sophia uses browser storage (such as localStorage) rather than cookies for its core functionality. This applies across both sophiawomen.com and sophiawomen.ai.

We do not use marketing or advertising cookies. You can manage analytics consent in your account settings, and clear browser storage through your browser. Disabling essential storage will prevent you from staying logged in.

8. Data Retention

You may request deletion of your account and personal data at any time (subject to legal retention obligations).

9. Your Rights

To exercise any of these rights, please contact us at: [email protected]

UK residents — contacting our UK Representative (DataRep)

If you are located in the United Kingdom, you may also exercise your rights under the UK GDPR by contacting our appointed UK representative, DataRep, through any of the following channels:

Email: [email protected] — please include “Sophia, SophiaAI” in the subject line.

Online: www.datarep.com/data-request

Post: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom. Address your letter to “DataRep” (not “Sophia”), and clearly reference “Sophia, SophiaAI” in the correspondence.

We or DataRep may request proof of your identity before processing your request, to protect your personal data. For further information about your rights under the UK GDPR, you may consult the UK Information Commissioner’s Office at ico.org.uk. DataRep’s own privacy notice is available at www.datarep.uk/privacy-policy.

We will respond within 30 days (or such shorter period as required by applicable law). We may ask you to verify your identity before processing your request.

If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the relevant supervisory authority (e.g. PDPC in Singapore, PCPD in Hong Kong, ICO in the UK, OAIC in Australia).

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These include encryption in transit (TLS), encryption at rest, access controls, and regular security reviews.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant regulators as required by applicable law.

11. California Privacy Rights (CCPA / CPRA)

This section applies to residents of California and supplements the rest of this Privacy Policy, pursuant to the CCPA/CPRA.

11.1 Categories of Personal Information Collected

11.2 Sale or Sharing of Personal Information

We do not sell your personal information for monetary consideration. We do not share your personal information with third parties for cross-context behavioural advertising. We therefore do not offer a ‘Do Not Sell or Share’ opt-out as we do not engage in these activities.

11.3 Your California Privacy Rights

11.4 How to Submit a Request

Contact us at [email protected] with subject line ‘California Privacy Request’. We will respond within 45 days (extendable by a further 45 days with notice).

11.5 Shine the Light

We do not share personal information with third parties for their direct marketing purposes.

12. Children

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. Contact us immediately if you believe a minor has provided us with personal data.

13. Changes to This Policy

We will notify you of material changes by email and/or in-app notice at least 14 days before they take effect.

14. Contact Us

Organic Raspberry Pte. Ltd. (trading as “Sophia”) | UEN: 202297027Z

[email protected] | #02-01, 68 Circular Road, Singapore 049422 | sophiawomen.com | sophiawomen.ai