Clinic Cloud ← Back to home
Template — not yet legal advice. Replace every [bracketed] placeholder and have a qualified Malaysian solicitor review this before relying on it.

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how [Company Name] (Reg. No. [SSM No.]) ("we", "us") collects, uses, discloses and protects personal data in connection with the Clinic Cloud Service, in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

Two roles. For data about our customers and their staff (account holders), we are the data user. For patient data that a clinic enters into the Service, the clinic is the data user/controller and we act as a data processor on the clinic's behalf — see our Data Processing Agreement.

1. Data we collect

2. Purposes

3. Lawful basis & consent

We process account data on the basis of contract and legitimate interest. Patient data is processed only on the clinic's documented instructions; the clinic is responsible for obtaining patient consent and the lawful basis for the data it enters.

4. Disclosure

We do not sell personal data. We disclose it only to: (a) sub-processors who help run the Service (hosting, payments, messaging, e-Invoice) under confidentiality and data-protection obligations; (b) authorities where required by law; and (c) a successor in a corporate transaction, subject to this Policy.

5. Sensitive / health data

Health data is sensitive personal data under the PDPA and is afforded heightened protection. Direct identifiers (e.g. MyKad, contact details) are encrypted at rest, and personal data is redacted before any third-party AI processing.

6. Cross-border transfer & hosting

The Service is hosted on [cloud provider, region — e.g. Google Cloud, asia-southeast1 (Singapore)]. Where data is processed outside Malaysia, we apply safeguards consistent with the PDPA.

7. Security

We use encryption in transit (HTTPS) and at rest for sensitive identifiers, role-based access control, tenant isolation, audit logging, optional two-factor authentication, rate limiting and regular backups.

8. Retention

We retain account data for the life of the account and as required by law. Patient data is retained per the clinic's instructions and applicable medical-records retention requirements; on termination it is exported and then deleted per the Data Processing Agreement.

9. Your rights (PDPA)

10. Cookies

We use strictly necessary cookies for authentication and session security. We do not use third-party advertising cookies.

11. Contact / Data Protection Officer

[Company Name], [Address]. Email: [privacy@yourdomain]. We may update this Policy; material changes will be notified.