This Privacy Policy explains how [Company Name] (Reg. No. [SSM No.]) ("we", "us") collects, uses, discloses and protects personal data in connection with the Clinic Cloud Service, in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
Two roles. For data about our customers and their staff (account holders), we are the data user. For patient data that a clinic enters into the Service, the clinic is the data user/controller and we act as a data processor on the clinic's behalf — see our Data Processing Agreement.
1. Data we collect
- Account data: name, email, phone, clinic name, role, billing details.
- Usage data: log-ins, audit events, device/browser, IP address.
- Patient data (processed for the clinic): identity, contact, clinical, prescription, billing and insurance information that clinic staff enter.
2. Purposes
- To provide, secure, support and improve the Service.
- To process subscription payments and send service, billing and renewal communications.
- To meet legal, regulatory and tax obligations (e.g. e-Invoice/LHDN).
3. Lawful basis & consent
We process account data on the basis of contract and legitimate interest. Patient data is processed only on the clinic's documented instructions; the clinic is responsible for obtaining patient consent and the lawful basis for the data it enters.
4. Disclosure
We do not sell personal data. We disclose it only to: (a) sub-processors who help run the Service (hosting, payments, messaging, e-Invoice) under confidentiality and data-protection obligations; (b) authorities where required by law; and (c) a successor in a corporate transaction, subject to this Policy.
5. Sensitive / health data
Health data is sensitive personal data under the PDPA and is afforded heightened protection. Direct identifiers (e.g. MyKad, contact details) are encrypted at rest, and personal data is redacted before any third-party AI processing.
6. Cross-border transfer & hosting
The Service is hosted on [cloud provider, region — e.g. Google Cloud, asia-southeast1 (Singapore)]. Where data is processed outside Malaysia, we apply safeguards consistent with the PDPA.
7. Security
We use encryption in transit (HTTPS) and at rest for sensitive identifiers, role-based access control, tenant isolation, audit logging, optional two-factor authentication, rate limiting and regular backups.
8. Retention
We retain account data for the life of the account and as required by law. Patient data is retained per the clinic's instructions and applicable medical-records retention requirements; on termination it is exported and then deleted per the Data Processing Agreement.
9. Your rights (PDPA)
- Access and correction of your personal data.
- Withdraw consent, or limit processing, subject to legal/contractual limits.
- Patients should direct access/correction requests to their clinic (the data user); we will assist the clinic in responding.
10. Cookies
We use strictly necessary cookies for authentication and session security. We do not use third-party advertising cookies.
11. Contact / Data Protection Officer
[Company Name], [Address]. Email: [privacy@yourdomain]. We may update this Policy; material changes will be notified.