Client Data Protection Notice

Effective Date: 17 August 2026

We at The Red Bit Limited Liability Partnership, doing business as Sofia Wellness (“Sofia Wellness,” “we,” “us,” or “our”) are committed to protecting your personal data and your rights under Singapore’s Personal Data Protection Act 2012 (“PDPA”). If you have any questions or concerns about this Notice or our practices with regard to your personal data, please contact our Data Protection Officer at hello@sofia.com.sg.

This Data Protection Notice describes how we may use your information if you:

  • are a prospective client enquiring about our counselling or psychotherapy services;
  • are a current or former client receiving or having received our services; or
  • engage with us as a client’s authorised representative.

In this Notice, “you” refers to a prospective client, client, or client’s authorised representative, unless the context requires otherwise. If you are simply browsing our website, our separate Website Privacy Policy explains what we collect through cookies, contact forms, and general site analytics.

The purpose of this Notice is to explain, as clearly as possible, what personal data we collect, how we use it, and what rights you have in relation to it. Please read this Notice carefully.

1. What Information We Collect

In Short: We collect personal data you provide to us in the course of receiving our services, including your contact details, clinical information, and payment details.

We collect personal data that you voluntarily provide to us, or that arises in the course of providing you with counselling or psychotherapy services. This may include:

  • Identification and contact information: your name, other identification details, contact information, date of birth, gender, and emergency contact details.
  • Clinical information: presenting concerns, session notes, treatment plans, risk assessments, and other clinical information arising from your care.
  • Billing information: payment and billing details relating to services rendered.
  • Referral and insurance information: where applicable, information relating to referrals to or from other providers, or insurance claims.
  • Recordings: with your specific consent, audio or video recordings of sessions for clinical supervision purposes (see Section 4).

All personal data that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal data.

2. How We Use Your Information

In Short: We use your personal data to provide your care, manage billing, support clinical supervision, and meet our legal obligations.

We may collect and use your personal data for the following purposes:

  • assessing your suitability for our services and processing your application to begin counselling or therapy;
  • providing the counselling, psychotherapy, or related services you have engaged us for;
  • scheduling and administering appointments;
  • billing and processing payment for services rendered;
  • clinical supervision and case consultation, to support the quality and safety of your care — case material is de-identified wherever reasonably practicable;
  • continuing education and service quality review, generally in aggregated or de-identified form;
  • responding to your queries, requests, or feedback;
  • complying with applicable laws, regulations, or requests from government or regulatory authorities, including where there is a risk of harm to you or to others;
  • referring you to another provider, with your consent, where appropriate; and
  • any other purpose we have notified you of and for which you have provided consent.

We generally do not collect your personal data unless it is voluntarily provided by you (or your authorised representative) after you have been notified of the purpose of collection and have given consent — typically through our intake process — or where collection without consent is permitted or required by law. We will seek your consent before using your personal data for a purpose we have not notified you of, except where permitted or required by law.

3. Who We Share Your Information With

In Short: We share your information only where necessary to provide your care, and we never sell it or use it for third-party marketing.

We may disclose your personal data:

  • to your treating clinician and, where relevant, other Sofia Wellness clinicians or administrative staff involved in your care, on a need-to-know basis;
  • to external clinical supervisors, generally on a de-identified basis, for case consultation;
  • to other healthcare or service providers you are referred to, with your consent;
  • to our service providers (for example, our practice management and IT systems providers) who process personal data on our behalf, under contractual confidentiality and security obligations;
  • where required by law, or to assist government or regulatory investigations; and
  • to any other party you have authorised us to disclose your personal data to.

We do not sell your personal data, and we do not disclose it to third parties for their own marketing purposes.

The purposes listed above may continue to apply even after your relationship with us ends — for example, once your care is formally concluded — for a reasonable period, including to meet legal or record-keeping obligations.

4. Recording and CCTV

In Short: Sessions are only recorded with your specific consent, for supervision purposes; our waiting areas have video-only CCTV for safety.

With your specific consent, sessions may be recorded for clinical supervision purposes, to allow your counsellor and their clinical supervisor to review the session and support the quality and safety of your care. Only your counsellor and their supervisor have access to these recordings, which are deleted once the counselling relationship is terminated.

We operate CCTV in our waiting and common areas for the security and safety of clients and staff. CCTV is not installed in counselling/treatment rooms, and does not record audio. Only the Clinical Director has access to CCTV footage, which is retained for a limited period and reviewed only where necessary, for example to investigate an incident.

5. How Long We Keep Your Information

In Short: We keep your information only as long as necessary — generally 15 years for clinical records and for billing records — unless a longer period is required by law.

We retain your personal data only for as long as necessary to fulfil the purposes it was collected for, or as required by applicable law. Clinical records and billing records are generally retained for 15 years from the date your care is formally concluded, in line with the period within which a claim relating to your care could potentially be brought under Singapore law. We securely delete personal data once it is no longer needed.

6. How We Keep Your Information Safe

In Short: We use administrative, technical, and physical safeguards to protect your personal data, though no system can be guaranteed 100% secure.

We protect your personal data through administrative, technical, and physical safeguards, including role-based access controls, encryption of data in transit and at rest, and confidentiality undertakings from all staff with access to client information. No method of transmission or storage is completely secure. While we cannot guarantee absolute security, we regularly review and improve our security practices, including through due diligence on the systems we use to store and process client data.

Some of our service providers may store or process personal data outside Singapore — for example, cloud-based practice management and productivity tools. Where this occurs, we take steps to ensure your personal data continues to receive a standard of protection comparable to that required under the PDPA.

7. Your Rights

In Short: You can withdraw your consent, and request access to or correction of your personal data, at any time.

Withdrawing consent. The consent you provide remains valid until it is withdrawn. You, or your authorised representative, may withdraw consent by writing to our Data Protection Officer. We will acknowledge a withdrawal request within 10 business days and explain any consequences of withdrawal, including where it may affect our ability to continue providing services to you. Withdrawing consent does not affect our right to continue collecting, using, or disclosing personal data where this is permitted or required without consent under applicable law.

Access and correction. You may request (a) access to a copy of the personal data we hold about you, or information on how we have used or disclosed it, or (b) correction of inaccurate personal data, by writing to our Data Protection Officer. A reasonable fee may apply to access requests; we will inform you of any fee before processing your request. We aim to respond within 30 business days. Clinical opinions and assessments are not altered on request, but will be annotated to record your disagreement where relevant.

Keeping your information accurate. We rely on the personal data you provide to us. Please let us know if your details change, so that we can keep your records current and accurate.

8. Changes and Updates

In Short: We may update this Notice from time to time; we will indicate this by updating the effective date.

We may revise this Notice from time to time. The updated version will be indicated by an updated “Effective Date,” and will be effective as soon as it is accessible. If we make material changes to this Notice, we will notify you either by prominently posting a notice of such changes or by directly notifying you.

9. How to Contact Us

If you have questions, feedback, or requests relating to your personal data, please contact our Data Protection Officer:

Data Protection Officer: Sophia Goh

Email: hello@sofia.com.sg

Address: #02-07 Singapore Shopping Centre, 190 Clemenceau Avenue, Singapore 239924

We will evaluate all requests and feedback in a timely manner, and respond with the outcome.