If you are a corporate entity/an organisation, references to the term “you” and “your” shall also include your employees, representatives and agents.
The PDPA requires us to inform you of your rights in respect of your personal data that is being processed or that is to be collected and further processed by us and the purposes for the data processing. The PDPA also requires us to obtain your consent to the processing of your personal data. In light of the PDPA, we are committed to protecting and safeguarding your personal data.
2.0 Collection of personal data
The term “personal data” means any information in our possession or control that relates directly or indirectly to an individual to the extent that the individual can be identified or are identifiable from that and other information in our possession such as name, phone number, identity card number or passport number, etc. The types of personal data collected depend on the purpose of collection. We may “process” your personal data by way of collecting, recording, holding, storing, using and/or disclosing it.
Your personal data may be collected from you during your course of dealings with us in any way or manner including pursuant to any transactions and/or communications made from/with us, for e.g. we collect information about our users on the “Sign Up” and “Registration” pages of the Websites. We may also collect your personal data from a variety of sources, including without limitation, at any meetings, events, seminars, conferences, talks, customer satisfaction surveys organised and/or sponsored by us, as well as from publicly available sources.
In addition, we may also receive, store and process your personal data which are provided or made available by any third parties, credit reference bodies, regulatory and law enforcement authorities, for reasons including delivery of our services, performance of conditions of agreements and/or to comply with our legal and regulatory obligations.
Pursuant to registration as a doctor or a health care provider on the Website, you may provide additional information in your personal profile page describing your credentials, professional experiences, academic background, biography and the like. Your personal profile page shall be available for viewing by other registered users of QueueMed and will be considered nonconfidential and non-proprietary. Providing additional information in your personal profile beyond what is required at registration is entirely optional and can be altered or removed by you at any time.
During the collection of personal data on the Profile Pages as a doctor or healthcare provider on the Websites, you are required to provide your applicable contact information (such as name, physician license information, email address and the like). In the case of professional information, professional information provided by you to us will be authenticated against a third party provider. Professional information shall include but not limited to physician license number, details regarding qualifications and specialties and the like.
QueueMed reserves the rights to collect, disseminate, sell or otherwise disclose nonpersonal data provided by you.
3.0 Purpose of Acquiring and Processing your personal data
The personal data as provided/furnished by you to us or collected by us from you or through such other sources as may be necessary for the fulfilment of the purposes at the time it was sought or collected, may be processed for the following purposes (collectively referred to as the “Purposes”):
- To assess, process and provide products, services and/or medical appointment facilities to you, including membership/loyalty programmes that we offer (if any);
- To facilitate, process, deal with, administer, manage and/or maintain your relationship with us;
- To consider and/or process your application/transaction with us;
- To respond to your enquiries or complaints or resolve any issues and disputes which may arise in connection with any dealings with us;
- To administer and process any payments related to products, services and/or facilities requested by you;
- To facilitate your participation in, and our administration of, any events including meetings, seminars, conferences, talks, contests, promotions or campaigns;
- To carry out due diligence or other monitoring or screening activities (including background checks) in accordance with legal or regulatory obligations or risk management procedures that may be required by law in accordance with PDPA or put in place by us;
- To administer, give effect to and process any payment related to your commercial transactions with us;
- To provide you with information and/or updates on our products, services, upcoming promotions offered by us and/or events, conferences, talks and seminars organised by us and selected third parties which may be of interest to you from time to time by WhatsApp, phone call, email, mail, social media and/or any other appropriate communication channels;
- To send you invitation to join our membership program, events and promotions and product launch events as well as conferences, talks and seminars;
- To monitor, review and improve our events and promotions, products and/or services;
- To process and analyse your personal data either individually or collectively with other individuals;
- To conduct collective market research or surveys, internal marketing analysis, customer profiling activities, analysis of customer patterns and choices, planning and statistical and trend analysis in relation to our products and/or services;
- To share any of your personal data with the auditor for our internal audit and reporting purposes;
- To share any of your personal data pursuant to any agreement or document which you have duly entered with us for purposes of seeking legal and/or financial advice and/or for purposes of commencing legal action;
- To share any of your personal data with a third party necessary for the preparation of legal documents or contract to be entered by you;
- To communicate with you and to maintain and improve customer relationship;
- To maintain and update internal record keeping, files and contact lists;
- To detect, investigate and prevent any fraudulent, prohibited or illegal activity or omission or misconduct;
- To enable us to perform our obligations and enforce our rights under any agreements or documents that we are a party to;
- To meet any applicable legal or regulatory requirements and making disclosure under the requirements of any applicable law, regulation, direction, court order, bylaw, guideline, circular or code applicable to us;
- To comply with or as required by any request or direction of any governmental authority; or responding to requests for information from public agencies, ministries, statutory bodies or other similar authorities;
We will seek your separate consent for any other purposes which do not fall within the categories stated above.
We may also be collecting from sources other than yourself, personal data about you, for one or more of the above Purposes, and thereafter using, disclosing and/or processing such personal data for one or more of the above Purposes.
5.0 Disclosure of personal data
We will not sell, rent, transfer or disclose any of your personal data to any third party without your consent. However, we may disclose your personal data to the following third parties, for one or more of the above Purposes:
- Your immediate family members, caregivers, and/or emergency contact person as may be notified to us from time to time;
- Any person under a duty of confidentiality to which has undertaken to keep your personal data confidential which we have engaged to discharge our obligations to you;
- Any party in relation to legal proceedings or prospective legal proceedings;
- Our auditors, consultants, lawyers, accountants or other financial or professional advisers appointed in connection with our business on a strictly confidential basis, appointed by us to provide services to us;
- Any party nominated or appointed by us either solely or jointly with other service providers, for purpose of establishing and maintaining a common database where we have a legitimate common interest;
- Government agencies, law enforcement agencies, courts, tribunals, regulatory/professional bodies, industry regulators, ministries, and/or statutory agencies or bodies, offices or municipality in any jurisdiction, if required or authorised to do so, to satisfy any applicable law, regulation, order or judgment of a court or tribunal or queries from the relevant authorities;
- Our business partners, third party product and/or service providers, suppliers, vendors, distributors, contractors or agents, on a need to know basis, that provide related products and/or services in connection with our business, or discharge or perform one or more of the above Purposes and other purposes required to operate and maintain our business;
- The general public when you become a winner in a contest, participate in our events, conferences, talks and seminars without compensation for advertising and publicity purposes;
- Any third party in connection with any proposed or actual reorganisation, merger, sale, joint venture, assignment, transfer or other disposition or all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings); and/or
- Any other person reasonably requiring the same in order for us to operate and maintain our business or carry out the activities set out in the Purposes or as instructed by you.
6.0 Accuracy of your personal data
Please ensure that you provide personal data that is true, accurate, complete and reliable and keep us updated on any changes to such personal data. Kindly note that if you do not provide complete and accurate personal information to us as and when it is required, it may have adverse consequences for you as we would be relying on such personal data to provide you with the Services. You will promptly update us in the event of any change to your personal data.
7.0 Your Rights
To the extent that the applicable law allows, you have the right to request for access to, request for a copy of, request to update or correct, your personal data held by us.
We may charge a small fee (such amount as permitted by the PDPA) to cover the administration costs involved in processing your request to access your personal data. Notwithstanding the foregoing, we reserve our rights to rely on any statutory exemptions and/or exceptions to collect, use and disclose your personal data.
You have the right at any time to request us to limit the processing and use of your personal data (for example, requesting us to stop sending you any marketing and promotional materials or contacting you for marketing purposes).
In addition, you also have the right, by notice in writing, to inform us on your withdrawal (in full or in part) of your consent given previously to us subject to any applicable legal restrictions, contractual conditions and a reasonable duration of time for the withdrawal of consent to be effected. However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue with your existing relationship with us or the contract that you have with us will have to be terminated.
8.0 Retention of your personal data
Any of your personal data provided to us is retained for as long as the purposes for which the personal data was collected continues; your personal data is then destroyed or anonymised from our records and system in accordance with our retention policy in the event your personal data is no longer required for the said purposes unless its further retention is required to satisfy a longer retention period to meet our operational, legal, regulatory, tax or accounting requirements.
9.0 Security of your personal data
We are committed to ensuring that your personal data is stored securely. In order to prevent unauthorised access, disclosure or other similar risks, we endeavour, where practicable, to implement appropriate technical, physical, electronic and procedural security measures in accordance with the applicable laws and regulations and industry standard to safeguard against and prevent the unauthorised or unlawful processing of your personal data, and the destruction of, or accidental loss, damage to, alteration of, unauthorised disclosure of or access to your personal data
The Internet is not a secure medium. However, we will put in place various security procedures with regard to the Websites and your electronic communications with us.
All our employees and data processors, who have access to, and are associated with the processing of your personal data, are obliged to respect the confidentiality of your personal data.
Please be aware that communications over the Internet, such as emails/ webmails are not secure unless they have been encrypted. Your communications may be routed through a number of countries before being delivered, this is the nature of the World Wide Web/Internet.
We cannot and do not accept responsibility for any unauthorised access or interception or loss of personal data that is beyond our reasonable control.
10.0 Personal data from minors and other individuals
This Website provides links to and include links to websites operated by third parties. Where you access third party websites using links from our Website or access our Website from third party websites, it does not mean that we endorse or approve that third party website’s policy and we cannot be responsible for the privacy policies and practices of such third party websites. QueueMed has no control over the content of such third-party websites, and is not responsible for it, or for the effect of your accessing a Website through a link on our Website or linking from a third party website to our Website. You should assume that any information that does not bear the QueueMed logo is operated by a third party.
We recommend you read and understand the privacy/personal data protection statement/policy posted on those other websites in order to understand their procedures for collecting, processing, using and disclosing personal data and before submitting your personal data to those websites.
We employ an industry standard technology called “cookies”. The cookie is a small piece of information stored on the hard drive of your computer or device for recordkeeping purposes, and is used by us to track your visits to the Websites. Cookies may be used to save your preferences for your ease and convenience when using the Websites. Third party advertising networks may issue their separate cookies to your hard drive when serving advertisements.
The type of anonymous click stream data collected by us through the cookies may include your Internet Protocol address, web browser software, date and time of visit to the Websites, and whether your requests (including search requests and clicking on links to parts of the Websites) were met with successfully. All such information collected through cookies are not personal data and you cannot be identified from this information. Such information is only used for the purpose of managing and creating a better user experience, analysing the traffic on the Websites and to identify areas for improvement on the Websites.
QueueMed may use IP addresses to analyse trends, administer the Websites, track your movement, and gather broad demographic information for aggregate use.
12.0 Contact details
QueueMed Healthtech Sdn Bhd
D-19-05, Menara SuezCap 1, No. 2, Jalan Kerinchi Kiri, Pantai Dalam, 59200 Kuala Lumpur.
Email : firstname.lastname@example.org (For business/partnership use only)
Phone : 010-3765162