Privacy policy
This policy covers the personal data Klinira collects through this website and through the product; patient clinical data is held by the clinic on its own premises and is not collected by us.
Who holds this data
The data user is Baloot MY Digital Agency, registration number NS0322595-U, of Lot 8115, Tingkat Bawah, Bandar Satelit Islam Pasir Tumboh, 16150 Kota Bharu, Kelantan, Malaysia. Any request about your own personal data — to see it, correct it, withdraw consent or have it deleted — should be sent to hello@klinira.my and will be answered by a person, not an autoresponder.
Two roles, and the difference matters
| Our role | The data, and who controls it |
|---|---|
| Data controller | Clinic staff accounts, billing details, support records, product usage. Controlled by us |
| Data processor | Encrypted backups of patient records, if a later release adds cloud backup. Version 1 sends us none: backups stay on destinations the clinic names |
Patient medical records are not ours and are never processed for our own purposes. The clinic is their controller and decides everything about them.
What this website collects
If you submit the interest form: your name, clinic name, phone number, email address, clinic type and number of doctors. We use it to contact you about Klinira. We do not sell it, do not share it, and do not add you to anything you did not ask for. Ask us to delete it and we delete it.
This site sets no advertising cookies and runs no cross-site tracking. If that ever changes on a campaign landing page, that page will say so on the page itself, and this section will be updated on the same day.
What we collect as the controller
| Category | What it is |
|---|---|
| Accounts and contact | Name, email, phone and role of each user; clinic name, address, registration number and tax details |
| Payments | Handled by Stripe. We never hold card numbers. We keep transaction records, subscription status and invoices |
| Support | Tickets, conversation content, and remote session records: who gave permission, when, and what was opened |
| Product usage | App version, error type, crash reports and performance metrics |
| Aggregate clinic metrics | Patient counts, revenue totals by payment method, stock alert counts, backup status and app version, for the owner's own dashboard. Version 1 sends none of this: the remote dashboard is a later release, and until it exists no clinic figures leave the premises at all |
Crash reports and diagnostic bundles are stripped of personal data before they are sent, and that stripping is covered by a test rather than by good intentions.
There is no patient identity in the aggregate metrics. No names, no identity card numbers, no diagnoses, no drug names at the level of an individual patient. That restriction is built into the architecture, not written into a policy that could be relaxed later.
What we process for the clinic
In version 1 we receive no backup at all. Backups go to the drives and folders the clinic names, and this section applies from the release that adds cloud backup onwards. When it does: encrypted backups of patient records, and nothing else. They are encrypted at the clinic before they are sent, so what we receive and store is a blob we cannot read.
We cannot decrypt your backups. Not because we promise not to, but because we cannot.
The clinic holds the recovery key in full and we hold no part of it. The same design has a cost, and we state it in the same breath: if a clinic loses the key, those encrypted backups cannot be opened by anyone, including us.
Why we hold it, and on what basis
| Purpose | Basis |
|---|---|
| Providing the software and cloud services | Performance of the contract |
| Backup and recovery | Performance of the contract |
| Licence validation and payment | Performance of the contract |
| Customer support | Performance of the contract |
| Improving the product | Legitimate interest, aggregate data only |
| Security and abuse detection | Legitimate interest |
| Keeping accounting and tax records | Legal obligation |
| Marketing messages | Consent, withdrawable at any time |
Who we share it with
Cloud infrastructure providers, Stripe for payments, and an authority where the law compels us. The current list of sub-processors is available on request, and we give reasonable notice before changing one that handles patient data.
We do not sell data. We do not share data for advertising. We do not use patient data to train any model.
Where it is processed
Cloud services are hosted in Singapore at present, with a move to Malaysian hosting planned, and we give written notice before any change of storage location. Because backups are encrypted before they leave the clinic and the remote summary carries no personal data, the location of our servers does not decide where your patients' data lives. It lives in your clinic.
While data is stored outside Malaysia, the system generates a cross-border transfer record automatically for each clinic, naming the recipient, the destination country, the data category, the purpose and the safeguards, so the clinic can meet its own record-keeping duty under section 129 of the PDPA without doing anything. After the move to Malaysia those historical records are kept, not deleted.
How long we keep it
| Data | Kept for |
|---|---|
| Account and clinic details | While the account is active, then 7 years for tax |
| Encrypted patient backups | While the account is active, then 90 days, then deleted with notice |
| Support records | 3 years |
| Aggregate metrics | 3 years |
| Payment records | 7 years, as the law requires |
Security
- Encryption at rest and in transit
- Role-based access control
- A full audit log that records views, not only changes
- Cloud backups that cannot be altered or deleted inside their retention window, which is what protects a clinic against ransomware
- Two-factor authentication on administrator accounts
- A written incident response procedure that has been rehearsed
Your rights
You can ask what we hold about you, correct it, restrict how we process it, withdraw consent, or ask us to delete it. Email hello@klinira.my and we respond within 21 days. You may also complain to the Personal Data Protection Department (JPDP) in Malaysia.
If there is a breach
We tell the affected clinic promptly and as completely as we can, and we notify the authority within the period set under the PDPA as amended. We give the clinic what it needs to meet its own duty to notify patients. We cannot make that notification decision on a clinic's behalf, because we are not the controller of those records.
Because backups are encrypted before they leave the clinic and we hold no part of the key, a compromise of our storage does not by itself expose readable patient data. That reduces how bad it is. It does not remove anybody's obligation.
If you are a patient
We do not hold your medical record, we cannot look it up, and we cannot correct or delete it. The clinic that treated you is its controller, and it is the clinic you ask. Klinira gives every clinic a template privacy notice, and the clinic decides what it displays and stands behind it.
Changes to this policy
We give 30 days notice before any material change, and we do not make a change quietly and hope nobody reads it.
This page was last updated on 1 September 2026.
Take a place in the first installs
Klinira is being built now. Leave your details and you will hear what is finished, be asked what your clinic actually needs, and get the first install dates when it is ready.