AITB Documentation← Back to app
← All documents

Privacy Policy — AI Training Bot (AITB)

Provider: Tiny Codes Software Pte Ltd (UEN 202405170H) · Deploying agency: Ministry of Social and Family Development (MSF)
Version: 1.0 (Draft for ITQ CDVHQ0ETQ26000013) · Review cycle: Annually, and on any material change to data practices

This Privacy Policy explains how personal data is used in the AI Training Bot. It complements the AI Use Disclosure and the organisation's internal Data Protection Policy (an internal governance document, available to MSF).

1. Who we are

AITB is operated for MSF, which is the data controller. Tiny Codes Software Pte Ltd is the data intermediary / processor, processing personal data only on MSF's instructions.

2. What personal data we process, and why

  • Account data (name, work email, role/division) — to manage access.
  • Session data — the officer's speech (retained as a voice recording), the transcript, emotion signals, and the assessment outputs — to provide training feedback and progress. Treated as sensitive operational data.
  • Voice recordings (session audio) are retained, alongside the transcript, for two purposes: (i) human review of training interactions, and (ii) speech-to-text (STT) accuracy verification (checking transcript accuracy against the source audio). Recordings are encrypted in transit and at rest, access-controlled (RBAC, least privilege), stored in Singapore (AWS ap-southeast-1), PDPA-handled, and retained for a default of 90 days (MSF-configurable per data class via the Retention Policy) before secure deletion / crypto-erasure.
  • Scenarios and personas are synthetic / Official Open and contain no real client personal data.

We do not use this data to train or fine-tune AI models, or for external analytics, without MSF's explicit approval. Our AI providers likewise do not train on it: OpenAI's API does not use submitted data for model training by default, and the ElevenLabs account-level training opt-out is enabled.

3. Third parties we engage (disclosure)

AITB relies on the following service providers. We disclose what each processes:

Provider Role What it processes Where
OpenAI Speech understanding & in-character reasoning; post-session assessment The officer's spoken input and transcript (the officer's personal/operational data) OpenAI API, Southeast Asia data residency
ElevenLabs Avatar voice (text-to-speech) Only the avatar's synthetic reply text — no officer personal data Provider service
Amazon Web Services (AWS) Hosting and encrypted storage of all persistent data All stored data (accounts, voice recordings, transcripts, assessments, reports) Singapore (ap-southeast-1)
Email delivery Sending reports when shared Recipient address and the report Configured service

Provider processing is governed by data-processing terms; none of these providers use AITB data to train their models under our configuration.

4. Data flow and safeguards

  • Flow: the officer's browser captures speech → it is processed by the speech model (OpenAI) for understanding → the avatar's reply text is voiced by ElevenLabs → voice recordings, transcripts, emotion signals and assessments are stored in the Singapore backend → the assessment model evaluates the transcript. A data-flow diagram is maintained in the System Card and proposal architecture.
  • Where data resides: all persistent personal data is stored in Singapore; GenAI inference of the officer's speech/transcript occurs with Southeast Asia data residency.
  • Leakage controls: encryption in transit and at rest, role-based access control with strict per-user separation, audit logging, encrypted and access-controlled retention of voice recordings with a defined retention period (default 90 days) and secure deletion, and no secondary use for model training. Data-flow risks (including any cross-border exposure) are identified and mitigated through a Data Protection Impact Assessment (DPIA) and the Cloud Security Risk Assessment (CSRA), which is a pre-condition to deployment.

5. Data ownership and portability

  • Ownership: MSF owns the system-generated data, configuration artefacts and reports. On expiry or termination of the service, MSF retains access to this data, configuration and reports.
  • Portability: reports and structured outputs can be exported in common formats (at minimum PDF, and CSV for structured scoring). Officers can access their own session history and reports.

6. Standards we align with (assurance)

AITB is designed to comply with, and operated in alignment with:

  • Singapore PDPA and the PDPC's Advisory Guidelines on Key Concepts, Guide to Accountability, and Guide to DPIAs;
  • AI Verify (Generative AI) governance self-assessment;
  • the Cloud Security Risk Assessment (CSRA) and relevant Government ICT requirements (e.g. IM8), as a pre-condition to deployment;
  • WCAG 2.1 AA accessibility (validated in testing).

7. Your rights and contact

Requests relating to personal data are handled in accordance with the PDPA and routed through MSF as controller. Contact points are provided in the system administration documentation.

8. Changes

This policy is version-controlled and reviewed at least annually and on any material change to data practices. The current version is published in the application's documentation.