Privacy Policy
Last updated: 2 October 2026
This Privacy Policy explains how AIVA Health SDN. BHD. (Registration No. 202601038081 (1700176-T)) ("AIVA Health", "we", "us") collects, uses, discloses and protects personal data when you visit our website or use the AIVA Health clinic management platform (the "Service"). We process personal data in accordance with the Personal Data Protection Act 2010 of Malaysia ("PDPA").
Who is responsible for your data
AIVA Health provides software to clinics. Two different situations apply:
- Clinic customers and their staff. For account, billing and contact data of the clinics that subscribe to the Service and of their staff, AIVA Health is the data user (controller).
- Patients of our clinic customers. Patient records, appointments, bills, claims and messages are entered and controlled by the clinic. For that data the clinic is the data user and AIVA Health processes it on the clinic's behalf and on its instructions. If you are a patient, please contact your clinic first about your data; we will assist the clinic in responding to you.
Personal data we collect
Data you or your clinic provide
- Account data: name, email address, phone number, role, branch and login credentials of clinic staff.
- Clinic data: business name, registration and tax numbers, addresses and billing details.
- Patient data entered by a clinic: identity details (such as name, NRIC or passport number, date of birth), contact details, medical and visit records, diagnoses, prescriptions, bills, panel and insurance claims.
- Messages: content of WhatsApp messages exchanged between a clinic and its patients through the Service, together with phone numbers, timestamps and delivery status.
- Communications you send us, such as support requests and contact form submissions.
Data collected automatically
- Log and device data: IP address, browser type, pages viewed, access times and error reports.
- Cookies and similar technologies, as described in our Cookie Policy.
How we use personal data
- To provide, operate, secure and support the Service.
- To create and manage accounts and authenticate users.
- To send and receive WhatsApp messages on behalf of a clinic, such as appointment reminders and replies to patients.
- To bill clinic customers and process payments.
- To send service notices, such as invitations, password resets and changes to these terms.
- To monitor, troubleshoot and improve the Service, and to prevent fraud and abuse.
- To comply with legal obligations.
We do not sell personal data, and we do not use patient data for advertising.
WhatsApp messaging
Clinics may connect their WhatsApp Business account to the Service through the WhatsApp Business Platform operated by Meta Platforms, Inc. and its affiliates ("Meta"). When a clinic does so:
- Messages between the clinic and its patients are transmitted through Meta's WhatsApp Business Platform, and Meta processes them under its own terms and the WhatsApp Privacy Policy.
- We store message content, phone numbers and delivery status so the clinic can see the conversation in the Service.
- The clinic is responsible for obtaining a patient's opt-in before messaging them on WhatsApp. A patient can opt out at any time by replying "STOP" or by telling the clinic.
- We access a clinic's WhatsApp Business account only to provide the features the clinic has enabled, and we stop when the clinic disconnects it.
Sign in with Google
If you choose to sign in with Google, we receive your name, email address and profile picture from your Google account. We use them only to create and sign in to your account. AIVA Health's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not access any other data in your Google account.
Disclosure of personal data
We share personal data only with:
- Service providers who host and operate the Service for us, under contracts that require them to protect the data. These include cloud hosting (Amazon Web Services), email delivery, error monitoring, payment processing and, where a clinic enables AI-assisted features, an AI model provider that receives only the data needed for the request.
- Meta, for WhatsApp messaging enabled by a clinic.
- Panels, insurers and government systems (such as LHDN MyInvois) where a clinic submits a claim or an e-invoice through the Service.
- Authorities, where required by law, or to protect our rights or the safety of others.
- A successor, in the event of a merger, acquisition or sale of our business, subject to this Policy.
Transfer outside Malaysia
The Service is hosted in Singapore, and some of our service providers process data in other countries. Where personal data is transferred outside Malaysia, we take steps to ensure it receives a level of protection comparable to that under the PDPA.
Retention
We keep personal data only as long as needed for the purposes above or as required by law. Clinic records are kept for as long as the clinic remains a customer, and for the period the clinic or applicable medical record and tax laws require afterwards. When data is no longer needed, we delete or anonymise it. See Data Deletion for how to ask us to delete data.
Security
We protect personal data with access controls, role-based permissions, encryption in transit, audit logs and regular backups. No system is perfectly secure, and we will notify affected clinics and the authorities of a breach where the law requires.
Your rights
Subject to the PDPA, you may:
- request access to and a copy of your personal data;
- request correction of personal data that is inaccurate, incomplete or out of date;
- withdraw consent to, or limit, the processing of your personal data;
- ask us to stop direct marketing.
To make a request, write to the contact below. We may need to verify your identity, and we will respond within the time the PDPA allows. If the data was entered by your clinic, we will forward your request to the clinic.
If you do not provide the personal data we need, we or your clinic may be unable to provide the Service to you.
Children
The Service is used by clinics and is not directed at children. Data about minor patients is entered by clinics under the consent of a parent or guardian.
Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy on this page and change the date above, and we will notify clinic customers of material changes.
Contact us
For questions, requests or complaints about personal data:
AIVA Health SDN. BHD. (Registration No. 202601038081 (1700176-T))
Business address: 22A, Jalan SS 22A/4, Damansara Jaya, 47400 Petaling Jaya, Selangor, Malaysia
Registered office: No. 25, Wisma SCMS, Jalan BP 7/12, Bandar Bukit Puchong, 47120 Puchong, Selangor, Malaysia
Email: hello@aivahealth.ai
Phone: +60 11-1755 0637
In the event of any inconsistency between the English and Bahasa Malaysia versions of this Policy, the English version prevails.