Privacy Policy
Medinex Technology Sdn Bhd ("Medinex", "we", "us", or "our") is committed to protecting the privacy and confidentiality of personal data processed through our clinic management system and healthcare software platform ("Services").
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia and other applicable laws.
By accessing or using our Services, you agree to the terms of this Privacy Policy.
1. WHO THIS POLICY APPLIES TO
This Privacy Policy applies to: Clinic operators and administrators who subscribe to and manage Medinex accounts; healthcare professionals (doctors, nurses, staff) who use the platform; patients whose data is processed through the platform by subscribing clinics; visitors to our website and marketing pages.
Important: Medinex operates as a software platform provider, not a licensed healthcare facility. Subscribing clinics remain the primary data controllers for patient data. Medinex acts as a data processor on their behalf. Clinics are responsible for obtaining appropriate patient consent in accordance with applicable law.
2. INFORMATION WE COLLECT
2a. Information You Provide — Account Information: name, email address, company or clinic name, role, phone number, and password provided during registration. Billing Information: payment details including billing address and payment method, processed securely via our licensed third-party payment partners; Medinex does not store full card numbers. Communications: messages, support requests, or feedback submitted through our platform or via email. Uploaded Clinical Content: patient records, appointment data, prescriptions, diagnoses, billing records, and other clinical information entered by clinic staff into the platform.
2b. Information Automatically Collected — Usage Data: features accessed, session duration, navigation paths, and system interactions. Device and Technical Information: browser type, IP address, operating system, device identifiers, and access timestamps. Cookies and Tracking Technologies: we use cookies, web beacons, and analytics tools to maintain sessions, understand usage patterns, and improve platform performance. See Section 8 for details.
2c. Information From Third Parties — We may receive limited data from integrated third-party systems (e.g., laboratory systems, pharmacy systems, payment gateways) that clinics connect to Medinex, and from identity verification or authentication providers.
3. SENSITIVE PERSONAL DATA
In providing clinic management services, Medinex processes sensitive personal data as defined under the PDPA, including health and medical information, diagnosis and treatment records, prescription data, and medical history. We process such data only on the instructions of subscribing clinics, who are responsible for obtaining valid patient consent. Medinex implements enhanced technical and organisational safeguards for all sensitive personal data.
4. HOW WE USE YOUR INFORMATION
We use collected information to: provide, operate, and maintain our Services; process payments and generate invoices; enable clinic staff to manage appointments, patient records, and billing; respond to support requests and technical inquiries; monitor system performance, security, and reliability; send service-related notifications; send marketing communications where consent is given; comply with applicable legal and regulatory obligations; and enforce our Terms of Service and agreements.
We do not use patient health data for advertising, profiling, or any purpose outside of operating the Services on behalf of the subscribing clinic.
5. HOW WE SHARE YOUR INFORMATION
We do not sell or rent personal data. We may share information only in the following circumstances: Service Providers (trusted vendors who assist us in operating the platform, including cloud hosting providers, analytics services, and payment processors, all bound by data processing agreements); Subscribing Clinics (patient data is accessible to the relevant subscribing clinic and their authorised staff only — Medinex does not share patient data across clinics); Legal and Regulatory Compliance (where required by Malaysian law, court order, or a lawful request from a government authority); Business Transfers (in the event of a merger, acquisition, or sale of assets, with advance notice where required by law); With Your Consent (where explicitly authorised for a specific purpose).
6. DATA RETENTION
We retain personal data for as long as your account remains active, as required to fulfil the purposes described in this policy, or as required by Malaysian law. Clinics may request deletion of patient data by contacting us. Upon termination of a clinic's subscription, data will be retained for a grace period of [90 days] before permanent deletion, unless earlier deletion is requested. We may retain limited records to comply with legal obligations, resolve disputes, and enforce agreements. To request deletion of your data, contact: admin@medinex.com
7. DATA SECURITY
Medinex implements industry-standard technical and organisational security measures, including: encryption in transit (HTTPS/TLS); encryption at rest; role-based access controls with multi-factor authentication; audit logging of access to patient records; secure infrastructure with regular backups; and regular vulnerability assessments and patching. In the event of a data breach affecting personal data, Medinex will notify affected clinics and, where required, the relevant authorities, in accordance with applicable law. While we implement robust safeguards, no system is completely immune from risk.
8. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies to maintain your login session, analyse platform usage and performance, remember user preferences, and improve personalisation and user experience. You can manage or disable cookies through your browser settings; disabling certain cookies may affect platform functionality. We do not use cookies to track patients across third-party websites.
9. YOUR RIGHTS UNDER THE PDPA
As a data subject under the Malaysian Personal Data Protection Act 2010, you have the right to access your personal data held by us, correct inaccurate or incomplete personal data, withdraw consent to the processing of your personal data, limit processing of your personal data in certain circumstances, and request information about how your data is being used. To exercise any of these rights, contact us at admin@medinex.com. We will respond within 21 days of receiving a valid request.
Note for clinic operators: patient data rights requests directed to Medinex will be referred to the relevant subscribing clinic as the primary data controller.
10. INTERNATIONAL DATA TRANSFERS
Medinex's primary infrastructure is located in Malaysia. Where we engage overseas service providers (e.g., cloud infrastructure, analytics), we ensure data transfers comply with applicable Malaysian data protection laws, overseas recipients provide a standard of protection comparable to the PDPA, and appropriate contractual safeguards are in place.
11. CHILDREN'S DATA
Our platform is designed for use by licensed healthcare professionals and clinic operators. We do not knowingly collect personal data directly from individuals under the age of 18 through our platform sign-up process. Patient records for minors may be managed by clinics through the platform; clinics are responsible for ensuring appropriate parental or guardian consent is obtained in accordance with applicable law.
12. AI FEATURES AND AUTOMATED PROCESSING
Where Medinex offers AI-assisted features (e.g., clinical documentation support, billing suggestions): AI features are decision-support tools only and do not replace clinical judgement; no fully automated decisions with legal or significant clinical effect are made without human review; AI outputs are clearly labelled within the platform; and patient data used to power AI features is processed strictly within the scope of the Services and is not used to train external models without explicit agreement.
13. THIRD-PARTY INTEGRATIONS
Medinex may integrate with third-party systems at the request of subscribing clinics (e.g., laboratory systems, pharmacy platforms, insurance portals). We are not responsible for the privacy practices of those third-party systems. Clinics should review the privacy policies of any third-party systems they integrate with.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our Services, applicable law, or security practices. Material changes will be communicated to subscribing clinics via email or in-platform notification at least 14 days before taking effect. Continued use of the Services after the effective date constitutes acceptance of the updated policy. The latest version will always be available at www.medinex.health/privacy.
15. CONTACT US
For any questions, concerns, or requests relating to this Privacy Policy or your personal data: Medinex Technology Sdn Bhd, Kuala Lumpur, Malaysia. Phone: +6 019-8108053. Website: www.medinex.health