PDPA Notice (Act 709)
Overview
This notice is issued under the Malaysian Personal Data Protection Act 2010 (Act 709) ("PDPA"). It explains how a business, together with Medivis as its technology provider, collects, uses, discloses and protects your personal data when you contact that business on WhatsApp or book an appointment with it. That business may be a clinic, an agency, a professional practice or any other organisation that uses Medivis to talk to the people it serves.
Medivis is a booking CRM: an appointment calendar, a two-way WhatsApp conversation desk, an AI assistant that answers routine questions, and reminder and broadcast messaging. Each business works in its own isolated account on its own subdomain, and within it each workspace is isolated from every other.
The business is the data user (controller). Medivis operates as a data processor acting on the business's instructions. Where that business belongs to a regulated sector — healthcare, financial services or another — the rules of that sector are its own to meet, and it may issue a further notice of its own alongside this one.
Personal Data We Process
- Identity: name, and where the business records them, date of birth and gender. An identity card number, if given, is stored only as a one-way hash used to recognise a returning contact — the number itself is never written to the database in readable form.
- Contact: mobile number (the WhatsApp number), and optionally an email address and address.
- Conversations: the WhatsApp messages exchanged between you and the business, including any media you send.
- Appointments: date, time, workspace, the person or resource booked, the service, and the free-text note staff type against the booking.
- Consent status: whether you have opted out of marketing messages, and when.
What We Do Not Hold
Medivis is a conversation and booking layer, not a system of record for anything else. The following are not processed on this platform at all:
- No prescriptions, diagnoses, consultation notes, laboratory results, medical certificates or clinical images.
- No invoices, payments or payment instrument details. Medivis bills the business, never you.
- No bank account, card or other financial account data, and no payment processing.
- No queue numbers or check-in records — Medivis does not run a queue or a check-in kiosk.
- No integration with any practice management system, so nothing is imported from one.
Where a business keeps any of that information, it keeps it in its own systems, under its own notice.
Purpose of Processing
- To book, reschedule and cancel your appointments.
- To hold a two-way WhatsApp conversation with you about the business's services, prices, opening hours and availability.
- To send appointment reminders, and to accept a cancellation you send by reply.
- To send follow-up or promotional messages, but only where you have not opted out.
- To let the business's AI assistant answer routine questions. Identifiers are removed from your message before it reaches the AI provider — see our AI Disclosure.
Consent
Messaging the business on WhatsApp, or asking it to book an appointment for you, is the point at which you consent to the processing described above. That processing is what the service is; it cannot be declined while still using it.
Marketing is separate and optional. You may stop marketing messages at any time without affecting your bookings or the service you receive — see Withdrawing Consent below.
Disclosure to Third Parties
Your data is disclosed only to the parties needed to deliver the service. It is never sold, and never shared for advertising.
- The business you contacted — its authorised staff, scoped to the workspace they work in.
- WasapFlow (a Meta Tech Provider partner, Malaysia) — the bridge to the WhatsApp Business Platform. It carries messages; it does not store them.
- OpenAI (United States) — the AI assistant, with identifiers scrubbed beforehand and a Data Processing Agreement in place.
- Our cloud hosting provider (Singapore) — the application servers and the database.
- Regulators or authorities, where required by law.
Security Safeguards
Traffic is encrypted in transit (HTTPS, TLS 1.3). Credentials held on a business's behalf are encrypted at rest with AES-256-GCM, staff passwords are hashed with bcrypt, and identity card numbers are stored only as one-way hashes. Each business's data is isolated at the query layer, staff access is role- and workspace-scoped and re-checked on every request, and sensitive actions are written to an audit log. Our Security page sets out the controls in full.
Retention
- Contact and appointment records: for as long as the business subscribes, plus 7 years.
- WhatsApp conversations: 24 months.
- Audit logs: 5 years.
A business that is suspended or behind on payment is locked out, not deleted — its data is preserved so it can be recovered or exported once the account is settled.
Your Rights (Access & Correction)
Under the PDPA you may:
- Request access to the personal data held about you.
- Request correction of inaccurate or incomplete data.
- Limit the processing of your data for direct marketing.
The business is the data user, so a request is usually answered fastest by asking that business directly. You may also contact our Data Protection Officer using the details below.
Cross-Border Transfer
Application servers and the database are hosted in Singapore. Message text sent to the AI assistant is processed in the United States by OpenAI, with identifiers removed first and a Data Processing Agreement in place. Delivery of a WhatsApp message itself also involves Meta's international infrastructure. In each case we require a level of protection consistent with the PDPA.
Withdrawing Consent
Reply STOP (or BERHENTI) to any WhatsApp message from the business and marketing messages stop immediately. The opt-out is recorded against your number and enforced at the moment of sending, so it applies even if you have never been registered as a contact. Replying START opts you back in.
Opting out of marketing does not stop appointment reminders or replies to a question you have asked, and does not affect service you have already received or processing required by law.
Contact / Data Protection
For any PDPA request or question about your personal data, please contact the business directly, or reach the platform operator below.
Contact the Data Protection Officer (DPO)
Company: KOBARAN TEGUH SDN. BHD.
Company Registration No.: 202601001919 (1664016-P)
Business Address: No. 49, Jalan SILC 2/16, Taman Perindustrian SILC, 79200 Iskandar Puteri, Johor, Malaysia
DPO Email: kobaranteguh@gmail.com
Phone: +60 19-273 3732
For privacy-related inquiries, data access requests, corrections, withdrawals of consent, or complaints regarding your personal data under the Personal Data Protection Act 2010 (Act 709), please contact our Data Protection Officer using the details above.