Privacy

Privacy and data protection

This privacy policy explains how Unit collects, uses, and protects personal data when you use the services available at guidedcoin.tech. The policy describes categories of data collected, the purposes of processing, legal bases where applicable, and the rights available to users. The approach is designed to be consistent with relevant Singapore laws and to provide clarity on how user data supports service delivery and improvement.

04-05-2026 Unit (Business ID S5729433A), 11 Upper Wilkie Road, Singapore, 22 11 Upper Wilkie Road, Singapore, 22. [email protected]
01

Definitions

This section provides concise meanings for terms used in the policy to reduce ambiguity and ensure consistent interpretation across the document.

Personal data means information that identifies or can reasonably identify an individual, such as name, email address, phone number, identification numbers, transaction records, and device identifiers. Processing covers any operation performed on personal data, including collection, storage, use, analysis, sharing, deletion, and transmission. User refers to a person who accesses or interacts with Unit services via guidedcoin.tech, including registered members and visitors who use informational resources. Service refers to the software, interfaces, documentation, and related features offered by Unit at guidedcoin.tech that support values-based personal management activities. Cookies are small text files placed on a device by a website to store preferences, enable basic functions, and collect non-identifying usage data for analytics and performance.
02

Data we collect

We collect data that is necessary to provide and improve services, to communicate with users, and to maintain security and compliance. Collection is limited to what is relevant for these purposes.

Data provided directly by users

Users provide certain information when they register, update their profile, or use interactive features. This information enables account management and personalised features.

  • Contact details: name, email address, and phone number when supplied by the user.
  • Account information: username, password hash, and profile preferences.
  • Values assessment responses and stated priorities for business alignment.
  • Manually entered business data such as budgets, transaction notes, and account nicknames.
  • Communications content when users contact support or participate in feedback surveys.
  • Consent records and settings that reflect user choices about features and sharing.

Automatically collected data

Some information is collected automatically to operate the site, improve services, and protect user accounts. This typically does not include the full content of business transactions unless expressly imported with consent.

  • Usage metrics such as pages visited, feature interactions, and session duration.
  • Technical data including IP address, device type, browser version, and operating system.
  • Cookies and similar identifiers used for functionality and analytics.
  • Aggregated, de-identified usage statistics for service evaluation.
  • Error and performance logs to diagnose issues and improve reliability.
  • Timestamps for account activity such as logins and configuration changes.

Data from third parties

Unit may receive data from third-party service providers or integrated business institutions when users authorise such connections. We limit collection to the data necessary to deliver the requested service.

  • Bank or payment account metadata when user authorises read-only connections for transaction categorisation.
  • Identity verification information from accredited providers where required for compliance.
  • Analytics and performance data provided by third-party monitoring services.
03

Purposes of processing

We process data for specific, documented purposes. Processing is kept proportionate to those purposes and is subject to retention limits.

  • To provide and maintain the Unit service, including account access and feature delivery.
  • To analyse usage trends and improve features, content, and security.
  • To communicate with users about account activity, updates, and support requests.
  • To perform aggregated reporting on values-alignment metrics while protecting individual identities.
  • To comply with legal and regulatory obligations applicable in Singapore and jurisdictions where relevant.
  • To detect, prevent, and respond to fraud, security incidents, or abuse.
  • To enable user-authorised integrations with business providers and third-party tools.
  • To retain records required for business operations and dispute resolution within stated retention schedules.

Legal bases for processing

Where applicable, processing activities are underpinned by an appropriate legal basis such as consent, contract performance, legitimate interests, or legal obligations. The specific basis depends on the nature of the processing and the jurisdiction.

  • Performance of a contract: to provide services requested by a user under the agreed terms.
  • Consent: for optional features or integrations activated by the user.
  • Legitimate interests: for security, fraud prevention, and service improvements, balanced against user rights.
  • Legal obligation: when retention or disclosure is required by applicable law or regulatory process.

GDPR and international data subjects

For users covered by the EU General Data Protection Regulation (GDPR), Unit respects rights established by that framework and will respond to requests in line with applicable procedures and timelines.

  • Right of access: you may request a copy of personal data we hold about you.
  • Right to rectification: you may request correction of inaccurate personal data.
  • Right to erasure: in certain circumstances, you may request deletion of personal data.
  • Right to restriction of processing: you may request limits on how we process your data in specific scenarios.
  • Right to data portability: where applicable, you may request a machine-readable copy of data you provided.
  • Right to object: you may object to certain processing based on legitimate interests or direct marketing.
04

Cookies and tracking technologies

We use cookies and similar technologies to provide basic site functionality, remember preferences, and collect performance information. Users can manage cookie settings through their browser and, where offered, via on-site controls.

Cookies used include strictly necessary cookies for authentication and session management, performance cookies for analytics, and functional cookies for user preferences. No cookies are used for targeted advertising without explicit consent.

Categories include essential (required for site operation), analytics (to measure usage), and preferences (to remember settings). Each cookie type is documented in the detailed cookie notice.

Users can block or delete cookies via browser settings; note that disabling certain cookies may limit functionality. Unit provides a cookie settings control on guidedcoin.tech where users can review and adjust preferences.

Detailed cookie policy and list

Data sharing and disclosure

Unit shares personal data only as necessary to deliver services, comply with law, or with user consent. Third-party recipients are selected to meet service needs and are subject to contractual controls.

  • Service providers that perform hosting, analytics, payment processing, and communication on our behalf.
  • Business institutions or account providers when a user authorises a connection for transaction data or account metadata.
  • Legal or regulatory authorities when disclosure is required by law or to respond to lawful requests.
  • Professional advisors such as auditors or legal counsel when necessary for compliance or dispute resolution.
  • Successors in the event of a merger, acquisition, or sale of assets, subject to contractual protections.
  • Aggregated or anonymised datasets that do not reasonably identify individuals and are used for research or product improvement.

International data transfers

Unit is based in Singapore (11 Upper Wilkie Road, Singapore, 22) and collaborates with service providers in other jurisdictions to deliver platform functionality. Personal data may be accessed, stored or processed outside Singapore when necessary for hosting, analytics, payment processing or customer support. Any such transfers are performed only for legitimate operational reasons and in accordance with applicable data protection requirements.

When personal data is transferred outside Singapore, Unit uses appropriate safeguards such as contractual data processing agreements, evaluated security controls, and technical protections including encryption. Transfers are assessed on a case-by-case basis to ensure a sufficient level of protection consistent with our privacy commitments and any applicable legal obligations.

Data retention

Unit retains personal data only for as long as necessary to provide services, meet legitimate business needs, and comply with legal or regulatory obligations. Retention periods vary by data category and purpose; shorter retention periods apply where feasible.

Account information (registration details, profile data, authentication records) is retained while the account is active and for a period after deactivation when required for fraud prevention, compliance, or dispute resolution. In certain cases we retain account records up to seven years to satisfy business or tax-related obligations.

Communications between users and Unit, including support tickets and in-app messages, are retained for the duration necessary to address requests, maintain service history, and analyze trends to improve the product. Aggregated or anonymised copies may be retained longer for reporting and development.

System logs and diagnostic data (access logs, error reports, security event records) are retained to support operational stability and security contribute. Retention periods are balanced against operational needs and are periodically reviewed to remove obsolete records.

When personal data is no longer required, Unit deletes or anonymises it in a manner intended to prevent reconstruction, except where retention is required by law or legitimate business need. Deletion requests are processed in accordance with applicable law; certain copies may persist in backup systems for a limited time as part of routine disaster recovery procedures.

Security practices

Unit applies technical and organisational measures designed to protect personal data from unauthorised access, disclosure, alteration or destruction. Security controls are selected based on risk assessments and reviewed periodically to align with evolving threats and operational requirements.

  • Encryption in transit (TLS) and where appropriate at rest for stored sensitive data.
  • Role-based access controls, authentication measures and principle of least privilege for internal access.
  • Regular security assessments, patch management, logging and incident response procedures to detect and address vulnerabilities.
05

User rights and choices

Depending on applicable law, individuals may have rights regarding their personal data. Unit facilitates common rights listed below and provides a process to submit requests.

  • Right to access personal data held about you and to obtain a copy in a commonly used format.
  • Right to correct or update inaccurate or incomplete personal data.
  • Right to request deletion or restriction of processing where permitted by law.
  • Right to withdraw consent for processing activities that rely on consent, without affecting prior lawful processing.
  • Right to data portability where applicable, to receive personal data in a structured, machine-readable format.
  • Right to object to processing for direct marketing or other specific grounds where provided by law.
  • Right to lodge a complaint with a supervisory authority if you consider our processing infringes applicable data protection laws.
  • Right to be informed about automated decision-making and profiling where it has a legal or significant effect.

How to submit a rights request

Requests to exercise data rights can be submitted by email to [email protected] or in writing to Unit, 11 Upper Wilkie Road, Singapore, 22. Include your name, contact details, a description of the requested action and any information to verify your identity. We may request additional information to confirm identity and scope of the request.

[email protected]

Unit aims to respond to valid requests within 30 days of receipt. Where complexity or volume requires additional time, we will inform you and provide an estimated timeframe. Response timing may be extended as permitted under applicable law.

Marketing communications

We may send marketing communications about product updates, events or promotions with your consent or other lawful basis. Communications are intended to be relevant and respectful of your preferences.

Marketing messages include an easy unsubscribe option. You may also update your communication preferences by contacting [email protected] or managing settings in your account dashboard.

Children's privacy

Unit services are intended for adults. We do not knowingly collect personal data from persons under 18. If we become aware that we have collected personal data of a minor without appropriate consent, we will take steps to delete that information in accordance with applicable law.

Third-party links

Our website or services may contain links to third-party websites or services. Unit is not responsible for the privacy practices of those sites. We encourage users to review the privacy notices of any third-party services before providing personal data.

Changes to this policy

Unit may update this privacy information to reflect changes in practices, technology, or legal requirements. Material changes will be communicated via the website or direct notice where appropriate. This version is effective as of 10-05-2026.