Privacy Policy
Last updated: March 2026
1. Introduction
EazyClinic is a product developed and operated by EazyTech Labs (202503155437). EazyTech Labs (“we”, “us”, or “our”) is committed to protecting the privacy of the clinics and individuals who use EazyClinic. This Privacy Policy explains how we collect, use, store, and protect information in connection with your use of the EazyClinic platform, in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA).
2. Information We Collect
We collect the following categories of information:
- Account Information: Name, email address, phone number, clinic name, and billing details provided during registration.
- Usage Data: Information about how you interact with the platform, including login activity, features used, and session duration.
- Patient Data: Patient records, medical history, appointments, and billing data entered into the platform by clinic staff. This data is controlled by you as the clinic operator.
- Technical Data: IP addresses, browser type, device information, and cookies used to operate and improve the Service.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the EazyClinic platform
- Process payments and manage your subscription
- Send transactional emails and important service updates
- Provide customer support and respond to enquiries
- Analyse usage patterns to improve the platform
- Comply with legal obligations
We do not sell your personal data or patient data to third parties.
4. Patient Data and Your Responsibilities
As a clinic using EazyClinic, you are the data controller for all patient personal data stored on the platform. You are responsible for ensuring that your collection and use of patient data complies with applicable laws, including the PDPA, and that patients have been informed of how their data is used.
EazyTech Labs processes patient data solely on your behalf and in accordance with your instructions as a data processor.
5. Data Storage and Security
All data is stored on secure cloud servers. We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews to protect your data from unauthorised access, loss, or disclosure.
While we take reasonable precautions, no system is completely secure. In the event of a data breach that affects your personal data, we will notify you in accordance with applicable law.
6. Data Retention
We retain your account and clinic data for as long as your subscription is active and for a reasonable period thereafter for legal and accounting purposes. Upon request, we will delete your data following account termination, subject to any legal retention requirements.
7. Payment Card Data and PCI DSS Compliance
EazyClinic accepts payments processed in accordance with the rules and requirements of major card networks, including Visa, Mastercard, and JCB. We are committed to handling cardholder data responsibly and in compliance with the Payment Card Industry Data Security Standard (PCI DSS).
- No storage of cardholder data: EazyClinic does not store, process, or transmit raw cardholder data on its servers. This includes card numbers (PAN), CVV/CVC codes, and full magnetic stripe data. All card payment details are submitted directly and securely to our PCI DSS-compliant third-party payment processor via encrypted channels (TLS).
- PCI DSS compliance: Our payment processor maintains PCI DSS certification and is responsible for the secure handling of cardholder data in accordance with card scheme rules. We work only with processors who meet the required security standards.
- Card scheme rules: Use of payment features within EazyClinic is subject to the applicable rules and regulations of Visa, Mastercard, JCB, and any other relevant card networks. By using these features, you acknowledge and agree to comply with those requirements.
- Billing information: We may retain limited billing-related information (such as the last four digits of a card, card type, and expiry month/year) solely for the purposes of subscription management and payment reconciliation. This information is not sufficient to process transactions independently.
If you have questions about how your payment data is handled, please contact us at support@eazyclinic.io.
8. Third-Party Services
We may use trusted third-party service providers to help operate the platform (e.g., payment processors, cloud hosting, analytics). These providers only access information necessary to perform their functions and are bound by confidentiality obligations. We do not authorise them to use your data for any other purpose.
9. Cookies
EazyClinic uses cookies and similar technologies to maintain session state and improve your experience. You can control cookie settings through your browser, though disabling cookies may affect the functionality of the platform.
10. Your Rights
Under the PDPA, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete personal data
- Withdraw consent for data processing where applicable
- Request deletion of your personal data, subject to legal requirements
To exercise these rights, please contact us at support@eazyclinic.io.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice on the platform. Continued use of the Service after the effective date constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at support@eazyclinic.io or visit our Contact Us page.