EYS TCM Clinic

Data Protection Policy

heart

We at Eu Yan Sang Integrative Health Pte Ltd (“EYSIH”) take our responsibilities under Singapore’s Personal Data Protection Act 2012 (the “PDPA”) seriously. We also recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data.

This Data Protection Policy is designed to assist you in understanding how we collect, use, disclose and/or process the personal data you have provided to us, as well as to assist you in making an informed decision before providing us with any of your personal data.

If you, at any time, have any queries on this policy or any other queries in relation to how we may manage, protect and/or process your personal data, please do not hesitate to contact our Personal Data Protection Officer (the “PDPO”) at: pdpo-clinic@euyansang.com

Personal Data Protection

1. INTRODUCTION TO THE PDPA

1.1 “Personal Data” is defined under the PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. Common examples of personal data could include names, identification numbers, contact information, medical records, photographs and video images.

1.2 We will collect your personal data in accordance with the PDPA. We will notify you of the purposes for which your personal data may be collected, used, disclosed and/or processed, as well as obtain your consent for the collection, use, disclosure and/or processing of your personal data for the intended purposes, unless an exception under the law permits us to collect and process your personal data without your consent.

2. PURPOSES FOR COLLECTION, USE, DISCLOSURE AND PROCESSING OF PERSONAL DATA

2.1 The personal data which we collect from you may be collected, used, disclosed and/or processed for various purposes, including one or more of the following purposes, depending on the circumstances for which we may/will need to process your personal data, as the case may be:

(a) rendering medical and consultancy services to you;

(b) considering and/or processing your transaction with us, as the case may be;

(c) facilitating, processing, dealing with, administering, managing and/or maintaining your transaction, as the case may be;

(d) carrying out your instructions or responding to any enquiry given by (or purported to be given by) you or on your behalf;

(e) contacting you or communicating with you via phone/voice call, text message and/or fax message, email and/or postal mail for the purposes of administering and/or managing your transaction with us. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of any medicine or medical supplies as well as on the external cover of envelopes/mail packages;

(f) to prevent or investigate any fraud, unlawful activity or omission or misconduct, whether relating to your transaction with us or any other matter arising from your transaction with us, and whether or not there is any suspicion of the aforementioned;

(g) complying with or as required by any applicable law, governmental or regulatory requirements of any relevant jurisdiction, including meeting the requirements to make disclosure under the requirements of any law binding on us and/or for the purposes of any guidelines issued by regulatory or other authorities, whether in Singapore or elsewhere, with which we are expected to comply;

(h) complying with or as required by any request or direction of any governmental authority; or responding to requests for information from public agencies, ministries, statutory boards or other similar authorities. For the avoidance of doubt, this means that we may/will disclosure your personal data to the aforementioned parties upon their request or direction;

(i) conducting research, analysis and development activities (including but not limited to data analytics, surveys and/or profiling) to improve our services and facilities in order to enhance your relationship with us or for your benefit, or to improve any of our products or services for your benefit;

(j) storing, hosting, backing up (whether for disaster recovery or otherwise) of your personal data, whether within or outside Singapore;

(k) any other purposes which we notify you of at the time of obtaining your consent.

(collectively, the “Purposes”)

As the purposes for which we may/will collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of your personal data without your consent is permitted by the PDPA or by law.

2.2 In order to conduct our business operations more smoothly, we may also be disclosing the personal data you have provided to us to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties, whether sited in Singapore or outside of Singapore, for one or more of the above-stated Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes.

3. SPECIFIC ISSUES FOR THE DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

3.1 We respect the confidentiality of the personal data you have provided to us.

3.2 In that regard, we will not disclose your personal data to third parties without first obtaining your consent permitting us to do so, with such consent being either express or deemed, as permitted by law. However, please note that we may disclose your personal data to third parties without first obtaining your consent in certain situations, including, without limitation, the following:

(a) cases in which the disclosure is required or authorized based on the applicable laws and/or regulations;

(b) cases in which the purpose of such disclosure is clearly in your interests, and if consent cannot be obtained in a timely way;

(c) cases in which the disclosure is necessary to respond to an emergency that threatens the life, health or safety of yourself or another individual;

(d) cases in which the disclosure is necessary for any investigation or proceedings;

(e) cases in which the personal data is disclosed to any officer of a prescribed law enforcement agency, upon production of written authorisation signed by the head or director of that law enforcement agency or a person of a similar rank, certifying that the personal data is necessary for the purposes of the functions or duties of the officer;

(f) cases in which the disclosure is to a public agency and such disclosure is necessary in the public interest; and/or

(g) where such disclosure without your consent is permitted by the PDPA or by law.

3.3 The instances listed above at paragraph 3.2 are not intended to be exhaustive. For more information on the exceptions, you are encouraged to peruse the Second, Third and Fourth Schedules of the PDPA which is publicly available at statutes.agc.gov.sg.

3.4 Where we disclose your personal data to third parties with your consent, we will employ our best efforts to require such third parties to protect your personal data.

4. REQUEST FOR ACCESS AND/OR CORRECTION OF PERSONAL DATA

4.1 You may request to access and/or correct the personal data currently in our possession or control by submitting a written request to us, by writing to our PDPO. Alternatively, you may request for a hard copy from any of our clinics. We will need enough information from you in order to ascertain your identity as well as the nature of your request, so as to be able to deal with your request.

4.2 For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days. Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested. Note that the PDPA exempts certain types of personal data from being subject to your access request.

4.3 For a request to correct personal data, once we have sufficient information from you to deal with the request, we will:

(a) correct your personal data within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within which we can make the correction. Note that the PDPA exempts certain types of personal data from being subject to your correction request; and

(b) subject to paragraph 4.4, we will send the corrected personal data to every other organisation to which the personal data was disclosed by EYSIH within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.

4.4 Notwithstanding paragraph 4.3 (b), we may, if you so consent, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.

4.5 We will also be charging you a reasonable fee for the handling and processing of your requests to access your personal data. We will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.

5. REQUEST TO WITHDRAW CONSENT

5.1 You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by submitting your request by sending an e-mail to our PDPO. Alternatively, you may request for a hard copy from any of our clinics.

5.2 We will process your request within a reasonable time from such a request for withdrawal of consent being made, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request.

5.3 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue with your existing relationship with us.

6. ADMINISTRATION AND MANAGEMENT OF PERSONAL DATA

6.1 We will take reasonable efforts to ensure that your personal data is accurate and complete, if your personal data is likely to be used by EYSIH to make a decision that affects you, or disclosed to another organisation. However, this means that you must also update us of any changes in your personal data that you had initially provided us with. We will not be responsible for relying on inaccurate or incomplete personal data arising from you not updating us of any changes in your personal data that you had initially provided us with.

6.2 We will also put in place reasonable security arrangements to ensure that your personal data is adequately protected and secured. Appropriate security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your personal data. However, we cannot assume responsibility for any unauthorized use of your personal data by third parties which are wholly attributable to factors beyond our control.

6.3 We will also put in place measures such that your personal data in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable to assume that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any other legal or business purposes.

6.4 Where your personal data is to be transferred out of Singapore, we will comply with the PDPA in doing so. In this regard, this includes us obtaining your consent unless an exception under the PDPA or law applies, and taking appropriate steps to ascertain that the foreign recipient organisation of the personal data is bound by legally enforceable obligations to provide to the transferred personal data a standard of protection that is at least comparable to the protection under the Act. This may include us entering into an appropriate contract with the foreign recipient organisation dealing with the personal data transfer or permitting the personal data transfer without such a contract if the PDPA or law permits us to.

7. COMPLAINT PROCESS

7.1 If you have any complaint or grievance regarding about how we are handling your personal data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance.

7.2 Please contact us through one of the following methods with your complaint or grievance:

(a) Singapore telephone number: +65 1800 225 1887.

(b) E-mail: pdpo-clinic@euyansang.com. Attention to: ‘Personal Data Protection Officer’

(c) Office address: Eu Yan Sang Integrative Health Pte Ltd Eu Yan Sang Centre, No. 21, Tai Seng Drive, Singapore 535223 Attention to: ‘Personal Data Protection Officer’

7.3 Where it is an email or a letter through which you are submitting a complaint, your indication at the subject header that it is a PDPA complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “PDPA Complaint”.

7.4 We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.

8. UPDATES ON DATA PROTECTION POLICY

8.1 As part of our efforts to ensure that we properly manage, protect and process your personal data, we will be reviewing our policies, procedures and processes from time to time.

8.2 We reserve the right to amend the terms of this Data Protection Policy at our absolute discretion. Any amended Data Protection Policy will be posted on our website and can be viewed at euyansangclinic.com/privacy-policy.

8.3 You are encouraged to visit the above website from time to time to ensure that you are well informed of our latest policies in relation to personal data protection.

Our Website

9. PERSONAL DATA AND OUR WEBSITE

9.1 In your use of the onewellnessmedical.com (“website”), we may collect, use, disclose and/or process certain personal information or data about you. Such personal information or data comprises, but is not limited to:

(a) Name;

(b) Email address;

(c) Date of birth;

(d) Billing address;

(e) Shipping address;

(f) Telephone number; and

(g) Gender.

9.2 Such personal data may/will be collected, used, disclosed and/or processed by EYSIH for various purposes, including one or more of the following purposes, depending on the circumstances for which we may/will need to process your personal data, as the case may be:

(a) Managing and/or administering your use and/or access of the Website;

(b) Managing, operating, administering and providing you the services offered on the Website;

(c) For identification and/or verification;

(d) For contacting you on matters relating to your transactions on the Website and your requested services on the Website, and any enquiries and/or requests submitted by you through the Website or otherwise;

(e) Social Media marketing using direct and open graph techniques (if you have consented to the same);

(f) For digital and conventional marketing purposes such as sending you direct mailers and post about new products, special offers or other information which we think you may find interesting (if you have consented to the same);

(g) Publishing customers review in digital and print format to open public (if you have consented to the same); and/or

(h) any other purposes which we notify you of at the time of obtaining your consent.

(collectively the “Website Management or Transaction Purposes”)

9.3 Paragraph 2.2 above will also apply to your personal data for the Website Management or Transaction Purposes.

9.4 By browsing and using this Website, or by registering for or using the services on the Website, you:

(a) consent to EYSIH and/or EYSIH’ affiliates or related corporations, collecting, using, disclosing and/or processing your personal data for one or more of the Website Management or Transaction Purposes; and

(b) consent to EYSIH and/or EYSIH’ affiliates or related corporations disclosing your personal data to third party service providers, agents and/or EYSIH’ affiliates or related corporations, and/or other third parties, whether sited in Singapore or outside of Singapore, for one or more of the Website Management or Transaction Purposes.

9.5 If you believe that any information we are holding of you is incorrect or incomplete, please contact us at 1800 225 1887.

10. LINKS TO OTHER WEBSITES

Our Website may contain links to other websites of interest. However, once you have used these links to leave our Website, you should note that we do not have any control over that other website. Please note that we are not responsible for the privacy practices of such other websites and advise you to read the privacy statements of each website you visit which collects personal information. We are also not responsible for the content of any such websites nor do we make any representations whatsoever of the content of any such websites.

11. USE OF COOKIES

Please note that we use cookies on our website. Cookies are text files that we put on your computer and they store/record information about your visit to and use of the Website. It enables our own system to recognise you when you visit our Website again and improve our service to you. Overall, cookies help us provide you with a better Website by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify the browser setting to decline cookies if you prefer. However, note that this may prevent you from taking full advantage of the Website. For more information on our use of cookies, please refer to our cookie policy at euyansangclinic.com/cookie-policy.