Legal

Privacy Policy

How Klinik Kotaraya collects, uses and protects your personal data, in line with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

Last updated: 6 June 2026

This Privacy Policy is issued by Klinik Kotaraya, operated by Heritage Zefam Sdn. Bhd. ("Klinik Kotaraya", "we", "us" or "our"), and is prepared in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. By providing your personal data to us or using our services, you acknowledge that you have read and understood this Policy.

1. Who we are (Data User)

The party responsible for your personal data is Klinik Kotaraya (Heritage Zefam Sdn. Bhd.), with the following branches:

  • Klinik Kotaraya Batu Kawa — Ch 103, Bandar Baru Batu Kawa, 93250 Kuching, Sarawak. Phone / WhatsApp: 017-857 8106.
  • Klinik Kotaraya Samarahan — Ground Floor Lot 11722, Sublot 2, Aiman Mall Building, Jln Datuk Mohammad Musa, 94300 Kota Samarahan, Sarawak. Phone / WhatsApp: 017-331 7051.

2. Personal data we collect

Depending on your interaction with us, we may collect:

  • Identity & contact details — name, NRIC/passport number, date of birth, gender, address, phone number, email.
  • Health information — medical history, symptoms, diagnoses, treatments, medications, test results and other clinical records.
  • Communications — messages, enquiries and information you share with us via WhatsApp, telephone, email or in person.
  • Payment information — billing details where applicable.
  • Technical data — limited website/usage information (this website does not require an account, login or registration).

3. Sensitive personal data

Information about your physical or mental health is classified as "sensitive personal data" under the PDPA. We process such data only with your explicit consent and for the purpose of providing healthcare services, or where the processing is otherwise permitted or required by law (for example, for medical purposes by a healthcare professional bound by a duty of confidentiality).

4. Purposes of processing

We process your personal data to:

  • provide medical consultation, treatment and clinical services;
  • respond to your enquiries and communicate with you (including via WhatsApp);
  • manage appointments, referrals and follow-up care;
  • create and maintain your medical records;
  • process billing and payments;
  • comply with legal, regulatory and professional obligations (e.g. the Ministry of Health and the Malaysian Medical Council); and
  • maintain the safety, administration and quality of our clinic services.

5. Consent and whether supply is obligatory

By providing your personal data to us (including through WhatsApp or other channels), you consent to our processing of that data as described in this Policy. For sensitive personal data, we rely on your explicit consent or another lawful ground under the PDPA.

Providing your personal data is generally voluntary. However, if you choose not to provide certain information, we may be unable to provide you with proper medical care or services.

6. Disclosure of your personal data

We may disclose your personal data, on a need-to-know basis, to:

  • our doctors, nurses and authorised clinic staff;
  • laboratories, hospitals, specialists and pharmacies for referrals, tests or treatment;
  • service providers and processors acting on our behalf (bound by confidentiality obligations);
  • insurers or panel administrators where you are covered by such arrangements; and
  • regulatory bodies, government authorities or courts where required or permitted by law.

We do not sell your personal data to any third party.

7. Transfer outside Malaysia

Your personal data is generally stored and processed in Malaysia. Should any transfer outside Malaysia be necessary, we will take reasonable steps to ensure your data continues to be protected to a standard consistent with the PDPA.

8. Security of your personal data

We implement reasonable physical, technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, alteration or disclosure, in line with the Security Principle of the PDPA. Access to medical records is restricted to authorised personnel.

9. Retention of your personal data

We retain your personal data only for as long as necessary to fulfil the purposes set out above and to comply with applicable legal, regulatory and medical record-keeping requirements. When no longer required, your data will be securely destroyed or permanently deleted.

10. Your rights

Subject to the PDPA, you have the right to:

  • request access to the personal data we hold about you;
  • request correction of inaccurate, incomplete or outdated data;
  • withdraw your consent or limit the processing of your data (subject to legal and medical limitations); and
  • enquire about how your data has been or may be disclosed.

To exercise any of these rights, please contact us using the details in Section 12. A prescribed fee may apply to data access requests. We may also need to verify your identity before acting on a request.

11. Cookies, website & external links

This website is informational and does not require login, registration or accounts. It may load third-party resources (such as web fonts and styling libraries) and may use limited cookies or analytics to operate and improve the site. Our website contains links and buttons to external services (e.g. WhatsApp and Google Maps); your use of those services is governed by their own privacy policies, over which we have no control.

12. How to contact us

For any questions, requests or complaints regarding your personal data or this Privacy Policy, please contact us:

  • Klinik Kotaraya Batu Kawa — Ch 103, Bandar Baru Batu Kawa, 93250 Kuching, Sarawak. Phone / WhatsApp: 017-857 8106.
  • Klinik Kotaraya Samarahan — Ground Floor Lot 11722, Sublot 2, Aiman Mall Building, Jln Datuk Mohammad Musa, 94300 Kota Samarahan, Sarawak. Phone / WhatsApp: 017-331 7051.

13. Changes to this Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "Last updated" date. Please review it periodically.

14. Language

This notice is provided in both English and Bahasa Malaysia in accordance with section 7(2) of the PDPA. In the event of any inconsistency between the two versions, the Bahasa Malaysia version shall prevail.

Disclaimer: This Privacy Policy is provided as a general template and does not constitute legal advice. Please have the final version reviewed by qualified legal counsel to ensure full compliance with the PDPA and any applicable healthcare regulations.