Legal

Privacy Policy

Last updated: 2026-07-21 · how NefraOne Solutions (TR0344472-X) handles personal data.


1. Who we are

NefraOne Solutions (TR0344472-X) ("we", "us") operates the NefraOne platform. This Privacy Policy describes how we collect, use, share, and protect personal data when you use the Service. It applies to administrators, clinical staff (nurses, doctors), sponsor representatives, patients accessing their own records, and visitors who use the public walk-in booking page.

2. PDPA and our role

We comply with the Malaysian Personal Data Protection Act 2010 ("PDPA") and its subsidiary regulations. For clinical and patient data entered into NefraOneby a dialysis centre, the centre is the data user (controller) and NefraOne Solutions (TR0344472-X) acts as the data processor on the centre's behalf. For data we collect directly (administrator accounts, billing contacts, public bookings), we act as the data user.

3. Categories of personal data we process

  • Identity data - full name, IC / passport number, date of birth, gender, contact details
  • Sensitive personal data (health) - diagnoses, dialysis prescriptions, session records, vitals, lab results, medications, comorbidities, allergies
  • Account data - email address, role, last sign-in time, sign-in IP address and user-agent string for security auditing
  • Sponsorship data - sponsor identity, batch records, ledger entries for funds applied to specific patients
  • Operational data - audit logs of actions taken in the Service (create / update / delete events, sign-ins) retained for security and compliance
  • Public-booking data - name, contact number, preferred outlet and slot of walk-in visitors who book a session without an account

4. How we use personal data

We use personal data to:

  • Provide, maintain, and improve the Service
  • Authenticate users and prevent unauthorised access
  • Generate the reports and exports requested by the data user (e.g. National Renal Registry submissions, MyInvois e-Invoices)
  • Communicate with administrators about their account, billing, and material service changes
  • Meet our legal obligations and respond to lawful requests by regulators
  • Investigate and prevent fraud, abuse, or security incidents

5. Legal basis

Under the PDPA we rely on the following bases: (a) consent obtained by the data user (clinic) from each patient prior to entry of their data; (b) performance of contract for administrator and staff accounts under the subscription agreement with the clinic; (c) compliance with legal obligations for retention of audit logs and tax-related records; (d) legitimate interests of the data user, such as monitoring service security, where consistent with PDPA principles and proportionate to the risk.

6. Sharing and disclosure

We share personal data only as follows:

  • With your clinic - clinical data is visible to authorised personnel at your dialysis centre according to their role and scope
  • With regulatory portals - when you trigger a submission (eNRR, MyInvois), the required fields are transmitted to the relevant authority. We do not share data with regulators absent your action or a lawful order
  • With sub-processors - cloud hosting (currently Vercel for compute and Neon Postgres for the database, both within Asia-Pacific regions), transactional email (Resend). Sub-processors are bound by written agreements to PDPA-aligned protections
  • With professional advisers - auditors and legal counsel under confidentiality obligations
  • To comply with law - when required by a competent authority, court order, or to protect rights and safety

We do not sell personal data. We do not use clinical or patient data for advertising or for training AI models.

7. Cross-border transfers

Where Customer Data is processed by sub-processors outside Malaysia, we transfer personal data only to jurisdictions that provide an adequate level of protection or under written agreements containing PDPA-aligned safeguards. We will document the transfer mechanism on request to administrators.

8. Retention

Clinical records are retained while the clinic's subscription is active. On termination, we retain Customer Data for up to ninety (90) days to allow export, after which it is permanently deleted unless a longer retention is required by law (for example, tax records retained for seven (7) years per the Income Tax Act 1967). Audit logs are retained for two (2) years. Walk-in booking records are retained for ninety (90) days after the appointment date.

9. Security

We use industry-standard safeguards including TLS encryption in transit, encryption at rest on managed Postgres, role-based access control, audit logging, passwordless email authentication, session timeouts, and rate-limited access. No system is perfectly secure; we will notify affected data users without undue delay if we become aware of a personal data breach likely to result in significant harm.

10. Your rights under PDPA

Subject to the conditions in the PDPA, you have the right to:

  • Access personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Withdraw consent previously given for the processing of your personal data (this may affect our ability to provide the Service)
  • Limit processing for direct marketing
  • Lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP)

For patient records held by your clinic, please submit access or correction requests to your clinic directly. For data we hold as a data user, contact us using the details below.

11. Children

The Service is not intended for use directly by children. Where a dialysis centre records data on a minor patient, the parent or legal guardian's consent must be obtained by the clinic in accordance with the PDPA.

12. Cookies and similar technologies

The Service uses strictly-necessary cookies and similar technologies to maintain your sign-in session, remember sidebar preferences, and prevent cross-site request forgery. We do not use third-party advertising or tracking cookies. Cookie details are available on request.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to administrators by email and through the Service at least 14 days before taking effect.

14. Contact

To exercise your rights, ask questions, or report a concern, reach our data protection contact via our contact page. You also have the right to lodge a complaint with the Personal Data Protection Department (JPDP) at pdp.gov.my.