Personal Data Protection Act 2010
PDPA Notice
Last updated: 1 January 2026
This notice explains how Klinikfy handles personal data under the Malaysian Personal Data Protection Act 2010 ('PDPA'). It complements our Privacy Policy with the specific disclosures required by Section 7 of the PDPA.
1. Data controller
For personal data Klinikfy processes as the operator of the booking platform, Klinikfy acts as the data user (in PDPA terminology) on its own behalf — for example, when we process your account credentials, session data, and technical logs.
For medical data entered by patients for the purpose of being seen by a clinic, the clinic you book with is the data controllerand Klinikfy processes that data on the clinic's documented instructions (the data-processor role under PDPA).
2. Categories of personal data
The personal data we process includes:
- Identity & contact: name, email, phone/WhatsApp number, NRIC (where provided).
- Account & authentication: hashed password, session metadata, role.
- Booking & clinical: appointment dates, chosen services, doctors, and any medical history fields you submit.
- Communications: WhatsApp messages routed through Klinikfy, email notifications.
- Technical: IP address, browser, device, server logs.
3. Purposes of processing
PDPA requires us to state the purposes for which we process your data. We process personal data to:
- Provide, operate, and maintain the Klinikfy service (booking, scheduling, notifications).
- Create and authenticate your account.
- Communicate with you about appointments, reminders, and service updates.
- Detect, prevent, and address fraud, security incidents, and abuse.
- Comply with our legal obligations and respond to lawful requests.
- Improve the service through aggregated, de-identified analytics.
- Where you have given consent, send marketing communications.
4. Disclosure & use limitation
PDPA prohibits us from disclosing or using your personal data for any purpose other than those stated above, except:
- With your express or implied consent.
- Where required or authorised by Malaysian law.
- Where necessary for the performance of a contract with you.
- Where disclosure is necessary to protect your vital interests.
When we use third-party service providers (hosting, email, WhatsApp delivery, error monitoring), we bind them by written contract to process personal data only on our instructions, to maintain confidentiality, and to apply appropriate security measures.
5. Storage, retention, transfer
Personal data is stored on secure servers operated by vetted cloud providers. Primary storage is in Malaysia, with backup replicas in Singapore for disaster recovery.
Retention periods:
- Account data — while the account is active, plus 12 months after deletion.
- Booking records — up to 7 years to support medical-record obligations.
- WhatsApp messages — up to 24 months, then anonymised.
- Server logs — up to 90 days.
We will destroy or permanently de-identify personal data when it is no longer needed for the purposes for which it was collected, except where retention is required by law.
6. Your PDPA rights
Subject to PDPA 2010, you have the right to:
- Request access to your personal data and a copy of it.
- Request correction of inaccurate or incomplete data.
- Withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
- Prevent processing that is causing, or is likely to cause, unwarranted substantial distress or damage.
- Request deletion, subject to our legal retention obligations.
To exercise any of these rights, email privacy@klinikfy.com. We will respond within 21 days of receiving a complete request, as required by the PDPA.
We may need to verify your identity before acting on a request to protect against unauthorised access.
7. Sensitive (medical) data
Medical data is treated as sensitive under PDPA. Klinikfy only processes medical data:
- For the specific medical purpose for which you provided it (the appointment).
- On the documented instructions of the clinic you booked with.
- With your explicit consent captured at booking or sign-up.
- With appropriate additional safeguards (encryption, access logging, role-based access).
We do not sell medical data, do not use it for advertising, and do not allow third-party advertisers access to it.
8. Children's data
Klinikfy does not knowingly process personal data of children under 18 without verifiable parental consent. Parents and legal guardians may create accounts and bookings on behalf of minors in their care.
9. Complaints
If you believe we have not handled your personal data in accordance with PDPA, please contact us first at privacy@klinikfy.com so we can investigate and respond.
If you are not satisfied with our response, you may lodge a complaint with the Jabatan Perlindungan Data Peribadi (JPDP), the Malaysian Department of Personal Data Protection.
10. Updates to this notice
We will review and update this PDPA Notice from time to time to reflect changes in our processing activities or applicable law. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated by email or in-app notice.