Privacy-first practices for conscious entrepreneurship programs.

General Policy Overview

Kiorava operates programs in conscious entrepreneurship and spiritual growth under the domain vhorizon.digital. We design activities around real cases and scenarios to help founders integrate purpose-driven practices into operations. Our contact information and data handling commitments are listed below.

  • 2026/04/23
  • Kiorava Pte. Ltd. (Business ID S7539413A)
General Policy Overview

We collect data necessary to administer programs, deliver coaching, run events and improve participant experience. Collection is limited to what supports program delivery, community administration and legal compliance. The examples and scenarios below clarify common cases.

01

Key definitions

To make the policy clearer, we define terms used in examples and scenarios below. These definitions help when we describe specific processing activities related to program enrollment, mentorship, events and community interactions.

Personal data means any information that identifies or can reasonably identify an individual, such as name, email address, phone number, billing details, and profiles used in our community platform.
Processing refers to any operation performed on personal data, including collection, storage, use, disclosure, analysis and deletion for the purposes described in this policy.
User describes program participants, prospective participants, alumni, mentors, guest speakers and visitors to vhorizon.digital or in-person events organized by Kiorava.
Service means Kiorava offerings such as online courses, live retreats, group mentorship, workshops and community forums that support conscious entrepreneurship and spiritual growth.
Cookies are small data files stored on a user's device to improve site functionality, remember preferences and gather analytics to optimise the learning experience and event logistics.
02

Data We Collect

We collect data necessary to administer programs, deliver coaching, run events and improve participant experience. Collection is limited to what supports program delivery, community administration and legal compliance. The examples and scenarios below clarify common cases.

03

Information You Provide

Examples of user-provided data: we collect only what is needed for enrollment, program delivery and communication. Below are common items submitted directly by participants.

  • Registration details: full name, email address, phone number (+6589738771), company name and role.
  • Program forms and questionnaires: background, intentions, personal goals, preferred mentoring scenarios and case descriptions used for tailored coaching.
  • Payment and billing data: invoice name, billing address (63A Lengkok Bahru, Singapore, 152063), transaction records and receipts for program fees.
  • Content you share: uploaded documents, submitted case studies, recorded session consent and feedback forms.
  • Communication preferences: opt-in choices for newsletters, event invites, and community notifications.
  • Support correspondence: messages platform with our team when you request assistance or case review.
04

Information Collected Automatically

We also collect information automatically to maintain and improve the platform, measure engagement and secure accounts. These items are generated while you use our website or services.

  • Usage data: pages visited on vhorizon.digital, session times, resource downloads and navigation paths used in scenario-based learning.
  • Technical data: device type, browser version, IP address, and operating system used to access our services.
  • Analytics: aggregated metrics about program engagement, completion rates and community activity to refine case studies and curriculum.
  • Cookies and similar technologies used for remembering preferences and facilitating single sign-on where applicable.
  • Security logs: authentication events, failed sign-in attempts and system alerts to protect your account and data.
  • Error reports and diagnostics that help our technical team resolve issues and improve platform reliability.
05

Third-party Data Sources

We may receive limited personal data from third parties to facilitate program delivery, background checks for certain cohorts, or to enable payment processing. Use is restricted and subject to contract safeguards.

  • Payment processors: transaction confirmations and verification data for billing and refunds.
  • Third-party platforms: profile data from professional networks when you choose to link accounts for community features.
  • Event partners: attendee lists and dietary or accessibility requirements shared with venue partners when you register for in-person retreats.
06

Why We Use Your Data

We process personal data to support program delivery, community operations, legal compliance and to continually improve our content. Below are the main purposes with concrete examples and scenarios.

  • Program administration: enrolling participants, scheduling sessions and tailoring curriculum based on case-study submissions and stated goals.
  • Communication: sending confirmations, updates, mentor assignments and follow-ups related to your chosen program or retreat.
  • Billing and fraud prevention: processing payments, issuing invoices and verifying transactions with payment providers.
  • Platform improvement: analysing anonymised usage patterns and retention of completed exercises to refine scenario-based materials.
  • Safety and security: detecting suspicious activity, protecting participant data and ensuring that community spaces remain respectful and supportive.
  • Legal compliance: retaining records required by tax or regulatory authorities in Singapore and responding to lawful requests.
  • Research and evaluation: with explicit consent, using anonymised data for studies on conscious entrepreneurship practices and program outcomes.
  • Alumni engagement: inviting past participants to contribute new case studies, mentor cohorts, or join community events.
07

Legal Bases for Processing

Where applicable, we rely on legitimate interests, contract performance, consent and legal obligations as the lawful grounds for processing. We assess interests to avoid undue impact on individuals.

  • Contractual necessity: processing required to deliver the program you purchased or enrolled in, including scheduling and mentor assignment.
  • Consent: for optional features such as marketing communications, recording sessions for the library, or participating in research.
  • Legitimate interests: improving course content and platform features through aggregated analytics and case-study reviews.
  • Legal obligation: retaining business records for tax or compliance reasons as required by Singapore law.
08

Cookies and Tracking

Cookies and similar technologies help Kiorava provide functional access, remember settings and collect analytics. We explain types, how we use them and how you can manage preferences in the examples that follow.

We use essential cookies for login and security, performance cookies for analytics, functional cookies for settings and preference management, and optional marketing cookies only with consent.

Categories: essential (required for site functionality), analytics (usage measurement), functional (preferences), marketing (third-party tracking for ads and social features).

You can manage cookie preferences through the banner on vhorizon.digital, adjust browser settings to reject cookies, or visit our cookie settings page to specify choices for analytics and marketing cookies.

View our detailed Cookie Policy

09

When We Share Data

Kiorava shares personal data only as necessary to provide services, comply with law, or with partners engaged to deliver events and program logistics. We describe typical categories of recipients below with scenarios.

  • Service providers: hosting, email delivery, payment processors and CRM providers engaged under contract to support program operations.
  • Event venues and partners: sharing attendee names and dietary or accessibility needs to ensure inclusive in-person experiences.
  • Legal and regulatory bodies: disclosures when required by law or to respond to lawful requests.
  • Research collaborators: only anonymised or consented participant data is shared when collaborating on studies or program evaluations.
  • Acquirers or advisors: in the event of a business transfer, limited data may be shared under strict confidentiality obligations.
  • Community mentors: contact details and shared case materials as needed for mentoring agreements and feedback loops.
10

International Data Transfers

We may transfer data to service providers located outside Singapore for hosting, analytics and payments. Transfers are subject to safeguards such as standard contractual clauses or where the destination ensures adequate protection.

Where data transfers occur, we use contractual protections, assess providers’ security controls, and limit data to what is necessary for service delivery. Examples include encrypted storage and access controls for remote mentoring recordings.

11

Data Retention

Retention periods are defined by the purpose of processing, legal requirements and the need to support participant records. Below are typical retention approaches and examples.

Account information is retained while your account is active and for a period after account closure to address legal obligations and to retain minimal records of program attendance (typically up to 7 years for business records).

Support and correspondence are retained for up to 3 years to ensure consistent service, resolve disputes, and maintain a record of mentorship agreements when relevant to ongoing cohorts.

Security logs and system diagnostics are retained for a rolling period (commonly 12 months) to detect, contribute and mitigate incidents affecting the platform.

When retention periods expire or you request deletion, we remove personal data from active systems. Backups may take additional time to purge, and certain data may be retained to meet legal requirements.

12

Security Measures

We employ physical, technical and organisational measures to protect personal data. Examples include encrypted storage, role-based access controls, two-factor authentication for administrative accounts and regular security reviews tailored to program cases.

  • Encryption: data in transit via HTTPS and encryption at rest for sensitive records and session recordings.
  • Access controls: least-privilege access for staff, regular reviews of permissions and mandatory confidentiality agreements for mentors and partners.
  • Operational safeguards: regular backups, incident response plans, and periodic third-party security assessments specific to the needs of cohort-based programs.
13

Your Rights

Participants have rights regarding their personal data. We outline practical steps and scenarios for exercising these rights, including requests related to enrollment records, case materials, and consent for recordings.

  • Access: request a copy of the personal data we hold about you, including enrollment and billing records.
  • Correction: ask us to correct inaccurate or incomplete information such as contact details or program preferences.
  • Deletion: request removal of personal data where retention is no longer necessary, subject to legal or contractual exceptions.
  • Restriction: ask to limit processing in specific circumstances, for example when disputing accuracy or during an contribute.
  • Portability: request a structured, machine-readable copy of data you provided directly for program registration and case submissions.
  • Objection: object to processing based on legitimate interests where relevant, for example for direct marketing or certain analytics.
  • Withdraw consent: withdraw consent for optional processing such as marketing or recording storage without affecting contractually necessary processing.
  • How to exercise rights: contact our Data Protection Officer using the details below; we respond in line with applicable law and program timelines.
14

GDPR and International Participants

For participants located in the European Economic Area, GDPR may apply. We describe how GDPR rights are respected and the specific steps for European users to submit requests, with case examples for cross-border program participation.

GDPR applies to EU/EEA residents even when they engage in programs hosted by Kiorava in Singapore. We implement appropriate legal bases and safeguards for such participants, including responding to data access and erasure requests.

  • European participants can submit requests for access, correction, restriction, portability or deletion and we will process those requests in accordance with GDPR timelines and exemptions.
  • We collect contact and usage data to perform our services, process registrations, and respond to inquiries in accordance with applicable data protection principles.
  • Where profiling is used for event recommendations or program matches, we limit automated decisions to provide transparent options and manual review in case of significant impact.
  • Data retention schedules are defined by program lifecycle, regulatory requirements, and legitimate business needs; personal data beyond those needs is securely deleted or anonymized.

If you have a concern about how your personal data is processed by Kiorava, you may file a complaint with our data protection team at the contact address below or with the relevant supervisory authority in Singapore.

15

Your Data Rights

Participants and visitors have the right to access, correct, restrict processing, or request deletion of their personal data where applicable. To initiate a request, provide a clear description of the data and the action you seek. We require proof of identity to protect your information.

[email protected]

We endeavor to acknowledge requests within 5 business days and provide a substantive response within 30 calendar days. Complex requests may require an extended period; in such cases we will explain the reasons and an estimated timeframe.

16

Marketing Communications

Kiorava uses email and SMS to share program updates, case studies, and workshop invitations relevant to conscious entrepreneurship and spiritual growth. Communications are based on consent or legitimate interest where permitted. Each message includes clear options to tailor preferences or opt out.

To stop marketing messages, use the unsubscribe link in any email or manage preferences in your account settings. You may also contact our team to adjust the types of communications you receive; processing such requests may take up to 5 business days.

17

Children's Data

Our programs are designed for adults. We do not knowingly collect personal data from children under 16. If we learn that personal data of a minor was collected, we will take steps to delete it and may require parental consent before processing where applicable.

18

Third-Party Links

Content on vhorizon.digital or program materials may link to third-party sites. Kiorava is not responsible for third-party privacy practices. Review their privacy policies before submitting personal information on external sites.

Third-Party Links

Kiorava shares personal data only as necessary to provide services, comply with law, or with partners engaged to deliver events and program logistics. We describe typical categories of recipients below with scenarios.

Cookies and Tracking

View our detailed Cookie Policy

19

Updates to This Policy

We periodically update our privacy practices to reflect new services, legal requirements, or operational changes. Material changes will be posted at vhorizon.digital and notified to registered users where required. Continued use of services after changes indicates acceptance.