Clinic Cloud ← Back to home
Template โ€” not yet legal advice. Replace every [bracketed] placeholder and have a qualified Malaysian solicitor review this before relying on it.

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Company Name] ("Processor", "we") and the Customer clinic ("Controller", "you") and governs the processing of personal data under the Malaysian Personal Data Protection Act 2010 (PDPA).

1. Roles

The Controller is the data user for patient and clinic personal data. The Processor processes such data only on the Controller's documented instructions to provide the Service.

2. Scope of processing

3. Processor obligations

4. Sub-processors

The Controller authorises the Processor to engage sub-processors for hosting, payments, messaging and e-Invoice. Current sub-processors include [cloud host], [payment gateway], [messaging provider], [LHDN/MyInvois]. The Processor imposes data-protection obligations on each and remains responsible for their performance. We will give notice of intended changes and allow reasonable objection.

5. Security measures

6. Personal data breach

The Processor will notify the Controller without undue delay (target: within [72] hours) after becoming aware of a personal data breach affecting the Controller's data, with information reasonably available to support the Controller's own notification obligations.

7. Data subject requests

Where a patient contacts the Processor directly, the Processor will refer them to the Controller and assist the Controller in responding to access, correction or withdrawal requests via the Service's export and editing tools.

8. International transfer

Personal data is hosted in [region โ€” e.g. Singapore (asia-southeast1)]. Any transfer outside Malaysia is subject to safeguards consistent with the PDPA.

9. Return & deletion

On termination, the Controller may export Customer Data for [30] days. Thereafter the Processor will delete or anonymise the data within [90] days, except where retention is required by law (e.g. medical-records or tax retention periods).

10. Audit

The Processor will, on reasonable notice and no more than [once per year] (or after a breach), make available compliance information and allow a reasonable audit, subject to confidentiality.

11. Liability & precedence

Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict on data protection, this DPA prevails. Governed by the laws of Malaysia.

Signed on acceptance of the Terms of Service, or as a separate signed agreement: Controller: [Clinic Name] ยท Processor: [Company Name].