| 1.1 | This website, [medistore.sg], (“Website”) is operated by AsiaMedic Wellness Assessment Centre Pte Ltd (referred to herein as “AsiaMedic”, “we”, “us” or “our”). We respect the privacy and confidentiality of the personal data of all users of our Website and are committed to implementing policies, practices and processes to safeguard the collection, use and disclosure of the personal data you provide us, in compliance with the Singapore Personal Data Protection Act (PDPA) 2012 (“PDPA”). |
| 1.2 | We have developed this Data Protection Notice (“Notice”) to assist you in understanding how we collect, use, disclose, process, protect and retain your personal data that is in our possession, when you access our Website and/or use services on our Website. |
| 1.3 | This Notice supplements but does not supersede nor replace any other consents which may have been previously provided to us in respect of your personal data, and your consents herein are additional to any rights which we may have under applicable law to collect and handle your personal data. |
| 2.1 | As used in this Notice and in line with the PDPA, personal data refers to data, whether true or not, about an individual who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access to. |
| 2.2 | While the specific types of personal data you submit through our Website may vary depending on the nature of your interaction with us and whether you maintain an account with us, the following are some broad categories of personal data that we may collect about you including, without limitation, your: |
(a) personal information (such as name, NRIC, gender, nationality); (b) contact information (such as phone number and email address); (c) transaction information, which includes your credit card details, bank account details, your billing address, your mailing address or the mailing address of the intended recipient of your order, payments and orders to and from you, and other details of products and services that you have supplied to or purchased from us; (d) usage information, which includes information about how you use our Website (including the time you visit our Website, the duration of your visit, the types of products and/or services you are searching for and/or how you are searching for such products and/or services); and (e) marketing and communications data, which includes your interests, feedback, survey responses, preferences in receiving marketing materials from us and your communication preferences, as well as your preferences for particular products or services. | |
| 2.3 | Other terms used in this Notice shall have the meanings given to them in the PDPA (where the context so permits). |
| 3.1 | We generally do not collect your personal data unless (a) it is provided to us voluntarily by you directly or via a third party who has been duly authorised by you to disclose your personal data to us (your “authorised representative”) after (i) you (or your authorised representative) have been notified of the purposes for which the data is collected, and (ii) you (or your authorised representative) have provided written consent to the collection and usage of your personal data for those purposes, or (b) collection and use of personal data without consent is permitted or required by the PDPA or other laws. We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you (except where permitted or authorised by law). |
| 3.2 | Generally, we may collect your personal data in the following ways: (a) When you browse our Website (you generally do so anonymously but please refer to clause 12 below on the use of cookies); (b) When you create or administer an account on our Website; (c) When you use our services; (d) When you use our Website to make a purchase; (e) When you submit any form or online query; (f) When you contact us – for example, if you get in touch to give us some feedback; (g) When you participate in a promotion, survey, event or other marketing campaign organised by us; (h) When you subscribe to our newsletters or alerts; (i) When we receive your personal data from third parties, including technical data from analytics providers, advertising networks and social media platforms and contact and transaction data from providers of technical, payment and delivery services; and (j) When you submit your personal data to us for any other reason. |
| 4.1 | In general, we may collect, use and/or disclose the personal data you provide to us for one or more of the following purposes: (a) Register you as a new customer; (b) Verify your identity; (c) Process and deliver your order(s); (d) Manage your account, including managing payments and fees and charges; (e) Manage your relationship with us; (f) Process payments or credit transactions; (g) Manage business and administrative operations and processes and comply with our internal procedures and policies; (h) Administer, operate, provide, maintain and protect our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, as well as ensuring that unauthorized users do not access the information on our Website); (i) Deliver relevant content and advertisements to you and measure or understand the effectiveness of the advertising we serve you; (j) Make suggestions and recommendations to you about our products or services that may be of interest to you; (k) Send you relevant information about our events, news announcements or promotions; (l) Enable you to complete a survey or participate in a promotion, survey, event or other marketing campaign organized by us; (m) Carry out our obligations arising from any contracts entered into between you and us and in the course of or in connection with our provision of the products and/or services requested by you; (n) Comply with any applicable laws, regulations, codes of practice, guidelines, or rules, or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authority; (o) Conduct audits and manage commercial risks; (p) Protect and enforce our contractual and legal rights and obligations; (q) Facilitate business asset transactions involving AsiaMedic; (r) Transmit to any unaffiliated third parties including our third-party service providers and agents, and relevant government and/or regulatory authorities, whether in Singapore or abroad, for the aforementioned purposes (provided that we will ensure these third parties (i) are subject to the relevant confidentiality obligations in respect of your personal data, (ii) undertake to comply with the PDPA and (iii) take steps to ensure that your personal data continues to receive a standard of protection that is at least comparable to that provided under the PDPA, if your personal data is transferred to a recipient in a country or territory outside Singapore); and (s) Any other incidental purposes related to or in connection with the above. |
| 4.2 | The above purposes are not intended to be exhaustive. We will notify you of any other purposes for which we may collect, use and/or disclose your personal data at the time of obtaining your consent. |
| 4.3 | If you supply us with your contact information, you may receive periodic mailings or calls from us and/or our affiliates, associated companies and related corporations with information about new products and services or upcoming events offered or organised by us and/or our affiliates, associated companies and related corporations. We will always obtain your consent to direct marketing communications where we are required to do so by law and if we intend to disclose your personal data to any third party for such marketing. If you do not wish to receive such mailings or calls, you may “opt out” by logging into your account on our Website and updating your preferences, or by writing, calling or emailing us at the address/numbers listed below: AsiaMedic Wellness Assessment Centre Pte Ltd 350 Orchard Road #08-00 Shaw House Singapore 238868 Email: enquiry@medistore.sg |
| 4.4 | Subject to the provisions of any applicable law, we may disclose your personal data to third parties set out below, whether they are located in Singapore or overseas: |
(a) Any member of AsiaMedic, our affiliates and associated companies; (b) Our agents, contractors and third-party service providers who provide administrative, financial, operational, or other services; (c) Relevant government agencies and regulatory authorities to comply with any laws, rules, and regulations imposed by any governmental authority; (d) Any business partner, investor, assignee, or transferee (actual or prospective) to facilitate business asset transactions (which may extend to any merger, acquisition, or asset sale) involving AsiaMedic; (e) Providers of professional services such as share registrars, auditors, lawyers, and consultants; (f) Insurance companies; (g) Banks, payment card processing companies, and other financial institutions; (h) Data processing and hosting companies such as IT service providers, web hosting companies, and cloud service providers; (i) Providers of goods or services such as freight and courier services, and warehouse services; and (j) Any other party to whom you consent for us to disclose your personal data. |
Where required to do so by law, we may disclose personal data about you to the relevant authorities or to law enforcement agencies.
| 5.1 | In compliance with the PDPA, we may collect, use or disclose your personal data without your consent for the legitimate interests of AsiaMedic or another person. In relying on the legitimate interests exception of the PDPA, AsiaMedic will assess the likely adverse effects on the individual and determine that the legitimate interests outweigh any adverse effect. |
| 5.2 | In line with the legitimate interests’ exception, we will collect, use, or disclose your personal data for the following purposes: (a) Fraud detection and prevention; (b) Detection and prevention of misuse of services; (c) Network analysis to prevent fraud and financial crime, and perform credit analysis; and (d) Collection and use of personal data on company-issued devices to prevent data loss. |
| 5.3 | The purposes listed in the above clause may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter. |
| 6.1 | The consent that you provide for the collection, use and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop collecting, using and/or disclosing your personal data for any or all of the purposes listed above by submitting your request in writing or via email to our Data Protection Officer at the contact details provided below. |
| 6.2 | Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within thirty (30) business days of receiving it. |
| 6.3 | Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our goods or services to you and this may also impact our ability to proceed with your transactions or interactions with us and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us in writing in the manner described in clause 13 below. |
| 6.4 | Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws. |
| 7.1 | We generally rely on personal data provided by you (or your authorised representative). |
| 7.2 | In order to ensure that your personal data is current, complete and accurate, please update us if there are any changes to your personal data (such as a change in your mailing address) by informing our Data Protection Officer at the contact details provided below. If you are a registered user on our Website, you can update any of the personal data you have provided by logging into your account. |
| 8.1 | We take commercially reasonable precautions to keep all information obtained from our online visitors secure against unauthorised access (e.g. data breach) and use and we periodically review our security measures. Although there is no way that any website can absolutely guarantee the security of personal data, AsiaMedic is committed to employing reasonable security measures and regularly reviewing our security practices. |
| 8.2 | You are responsible for keeping your login information and passwords confidential. AsiaMedic uses [2048bit encryption] for its website security certificates. Please be aware that these protection tools do not protect information that is not collected through our Website, such as information provided to us by email. |
| 9.1 | We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected, or as required by applicable laws. |
| 9.2 | We have a document retention policy that keeps track of the retention schedules of the personal data you provide us, in paper or electronic forms (including via cloud services). |
| 9.3 | We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for business or legal purposes. |
| 9.4 | We will dispose of or destroy such documents containing your personal data in a proper and secure manner when the retention limit is reached. |
| 10.1 | If you are a registered user on our Website, you can access and edit any of the personal data that you have provided by logging into your account. |
| 10.2 | If you wish to make (a) an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, or (b) a correction request to correct or update any of your personal data which we hold about you, you may submit your request in writing or via email to our Data Protection Officer at the contact details provided below. |
| 10.3 | Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request. |
| 10.4 | We will respond to your request as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA). |
| 10.5 | Please note that depending on the request that is being made, we will only need to provide you with access to the personal data contained in the documents requested, and not to the entire documents themselves. In those cases, it may be appropriate for us to simply provide you with confirmation of the personal data that our organisation has on record, if the record of your personal data forms a negligible part of the document. |
If there is a need for us to transfer your personal data to another organisation outside of Singapore, we will comply with the PDPA provisions in respect of the transferred personal data and take steps to ensure that your personal data continues to receive a standard of protection that is at least comparable to that provided under the PDPA. If this is not so, we will enter into a contractual agreement with the receiving party to accord similar levels of data protection as that in Singapore.
| 12.1 | A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server. |
| 12.2 | Cookies may be either “persistent” cookies or “session” cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed. |
| 12.3 | Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies. |
| 12.4 | We use cookies in a range of ways to improve your experience on our Website, including: (a) keeping you signed in; and (b) understanding how you use our Website. |
| 12.5 | There are several different types of cookies which our Website uses: (a) Functionality – We use these cookies so that we recognize you on our Website and remember your previously selected preferences. These could include what language you prefer and location you are in. A mix of first-party and third-party cookies are used. (b) Google Analytics – We use Google Analytics to analyse the use of our Website. Google Analytics gathers information about website use by means of cookies. The information gathered relating to our Website is used to create reports about the use of our Website. Google’s privacy policy is available at: https://policies.google.com/privacy. |
| 12.6 | You can set your browser not to accept cookies by changing the settings of your browser. However, in a few cases, some of the Website features may not function as a result. |
| 12.7 | Our Website may contain links to other websites which are operated by third parties. We are not responsible for the privacy practices of any such linked external websites. We encourage you to check the applicable privacy policies of such third-party websites to learn about their data practices. |
| 13.1 | If you have any query or feedback regarding this Notice, or any complaint you have relating to how we manage your personal data, or if you wish to make a request, you may contact our Data Protection Officer (DPO) at: dpo@asiamedic.com.sg. |
| 13.2 | Any query or complaint should include, at least, the following details: (a) your full name and contact information; and (b) brief description of your query, complaint or request. |
| 13.3 | We treat such queries and feedback seriously and will deal with them confidentially and within reasonable time. |
| 13.4 | Please note that if your personal data has been provided to us by a third party, you should contact such party directly to make any queries, feedback, and requests to AsiaMedic on your behalf. |
| 14.1 | This Notice applies in conjunction with any other notices, contractual clauses and consent clauses that apply in relation to the collection, use and disclosure of your personal data by us. |
| 14.2 | We may update this Notice from time to time without prior notice. Any amended Notice will be posted on our Website and you are encouraged to visit our Website periodically to note any changes. |
| 15.1 | This Notice shall be governed in all respects by the laws of Singapore. Effective date: [06 May 2024] Last updated: [06 May 2024]
|