Home/Legal

Privacy policy

This policy covers the personal data Klinira collects through this website and through the product; patient clinical data is held by the clinic on its own premises and is not collected by us.

If you are a patient, this is not the page you need. Your medical record is held by the clinic that treated you, under that clinic's control, and the clinic is the only party that can show it to you, correct it or delete it. We cannot look it up. See the last section of this page.

Who holds this data

The data user is Baloot MY Digital Agency, registration number NS0322595-U, of Lot 8115, Tingkat Bawah, Bandar Satelit Islam Pasir Tumboh, 16150 Kota Bharu, Kelantan, Malaysia. Any request about your own personal data — to see it, correct it, withdraw consent or have it deleted — should be sent to hello@klinira.my and will be answered by a person, not an autoresponder.

Two roles, and the difference matters

Our roleThe data, and who controls it
Data controllerClinic staff accounts, billing details, support records, product usage. Controlled by us
Data processorEncrypted backups of patient records, if a later release adds cloud backup. Version 1 sends us none: backups stay on destinations the clinic names

Patient medical records are not ours and are never processed for our own purposes. The clinic is their controller and decides everything about them.

What this website collects

If you submit the interest form: your name, clinic name, phone number, email address, clinic type and number of doctors. We use it to contact you about Klinira. We do not sell it, do not share it, and do not add you to anything you did not ask for. Ask us to delete it and we delete it.

This site sets no advertising cookies and runs no cross-site tracking. If that ever changes on a campaign landing page, that page will say so on the page itself, and this section will be updated on the same day.

What we collect as the controller

CategoryWhat it is
Accounts and contactName, email, phone and role of each user; clinic name, address, registration number and tax details
PaymentsHandled by Stripe. We never hold card numbers. We keep transaction records, subscription status and invoices
SupportTickets, conversation content, and remote session records: who gave permission, when, and what was opened
Product usageApp version, error type, crash reports and performance metrics
Aggregate clinic metricsPatient counts, revenue totals by payment method, stock alert counts, backup status and app version, for the owner's own dashboard. Version 1 sends none of this: the remote dashboard is a later release, and until it exists no clinic figures leave the premises at all

Crash reports and diagnostic bundles are stripped of personal data before they are sent, and that stripping is covered by a test rather than by good intentions.

There is no patient identity in the aggregate metrics. No names, no identity card numbers, no diagnoses, no drug names at the level of an individual patient. That restriction is built into the architecture, not written into a policy that could be relaxed later.

What we process for the clinic

In version 1 we receive no backup at all. Backups go to the drives and folders the clinic names, and this section applies from the release that adds cloud backup onwards. When it does: encrypted backups of patient records, and nothing else. They are encrypted at the clinic before they are sent, so what we receive and store is a blob we cannot read.

We cannot decrypt your backups. Not because we promise not to, but because we cannot.

The clinic holds the recovery key in full and we hold no part of it. The same design has a cost, and we state it in the same breath: if a clinic loses the key, those encrypted backups cannot be opened by anyone, including us.

Why we hold it, and on what basis

PurposeBasis
Providing the software and cloud servicesPerformance of the contract
Backup and recoveryPerformance of the contract
Licence validation and paymentPerformance of the contract
Customer supportPerformance of the contract
Improving the productLegitimate interest, aggregate data only
Security and abuse detectionLegitimate interest
Keeping accounting and tax recordsLegal obligation
Marketing messagesConsent, withdrawable at any time

Who we share it with

Cloud infrastructure providers, Stripe for payments, and an authority where the law compels us. The current list of sub-processors is available on request, and we give reasonable notice before changing one that handles patient data.

We do not sell data. We do not share data for advertising. We do not use patient data to train any model.

Where it is processed

Cloud services are hosted in Singapore at present, with a move to Malaysian hosting planned, and we give written notice before any change of storage location. Because backups are encrypted before they leave the clinic and the remote summary carries no personal data, the location of our servers does not decide where your patients' data lives. It lives in your clinic.

While data is stored outside Malaysia, the system generates a cross-border transfer record automatically for each clinic, naming the recipient, the destination country, the data category, the purpose and the safeguards, so the clinic can meet its own record-keeping duty under section 129 of the PDPA without doing anything. After the move to Malaysia those historical records are kept, not deleted.

How long we keep it

DataKept for
Account and clinic detailsWhile the account is active, then 7 years for tax
Encrypted patient backupsWhile the account is active, then 90 days, then deleted with notice
Support records3 years
Aggregate metrics3 years
Payment records7 years, as the law requires

Security

  • Encryption at rest and in transit
  • Role-based access control
  • A full audit log that records views, not only changes
  • Cloud backups that cannot be altered or deleted inside their retention window, which is what protects a clinic against ransomware
  • Two-factor authentication on administrator accounts
  • A written incident response procedure that has been rehearsed

Your rights

You can ask what we hold about you, correct it, restrict how we process it, withdraw consent, or ask us to delete it. Email hello@klinira.my and we respond within 21 days. You may also complain to the Personal Data Protection Department (JPDP) in Malaysia.

If there is a breach

We tell the affected clinic promptly and as completely as we can, and we notify the authority within the period set under the PDPA as amended. We give the clinic what it needs to meet its own duty to notify patients. We cannot make that notification decision on a clinic's behalf, because we are not the controller of those records.

Because backups are encrypted before they leave the clinic and we hold no part of the key, a compromise of our storage does not by itself expose readable patient data. That reduces how bad it is. It does not remove anybody's obligation.

If you are a patient

We do not hold your medical record, we cannot look it up, and we cannot correct or delete it. The clinic that treated you is its controller, and it is the clinic you ask. Klinira gives every clinic a template privacy notice, and the clinic decides what it displays and stands behind it.

Changes to this policy

We give 30 days notice before any material change, and we do not make a change quietly and hope nobody reads it.

This policy describes what we do. It is not legal advice, and it does not tell your clinic what its own duties are under the PDPA. Those are yours, and your adviser is the person to settle them with.

This page was last updated on 1 September 2026.

Take a place in the first installs

Klinira is being built now. Leave your details and you will hear what is finished, be asked what your clinic actually needs, and get the first install dates when it is ready.