Introduction
Our Commitment
HelloClinic is a clinic-management SaaS platform developed and operated by KAKI TECH LIMITED (the "Company," "we," "us," or "our"). The Company is not a healthcare provider and does not provide diagnosis, treatment, or other medical advice through this website or the Service. This policy explains how we collect, hold, use, disclose, and protect personal data when operating our website, handling demo and sales enquiries, providing the Service, and processing Customer Data on behalf of clinic customers. We apply the laws of Hong Kong, including the Personal Data (Privacy) Ordinance (Cap. 486) (the "Ordinance" or "PDPO") and its Data Protection Principles (DPPs), and take reasonable and practicable data protection measures.
Scope of Policy
This policy applies to website visitors, people who submit demo or sales enquiries, our customers and their authorized users, and other individuals whose data we handle in business or support interactions. Patient data uploaded or managed by a clinic customer is normally controlled by that clinic as the "Data User" under applicable Hong Kong terminology; the Company processes it on the clinic's documented instructions as a data processor. This policy does not replace a clinic's own privacy notice, Personal Information Collection Statement, or legal responsibilities. Patients should normally contact the relevant clinic to access or correct their medical records; where appropriate, we will assist in accordance with the clinic's instructions.
Definitions
To ensure clarity and legal precision, key terms are defined below, consistent with the definitions in the PDPO:
- Personal Data: Any data relating directly or indirectly to a living individual, from which it is practicable for the identity of the individual to be directly or indirectly ascertained, and in a form in which access to or processing of the data is practicable. In the context of the Service, examples include but are not limited to name, Hong Kong Identity Card number, contact details, medical records, diagnostic images, laboratory results, and in some cases, technical data associated with an individual (such as IP address).
- Data Subject: The living individual who is the subject of the personal data.
- Data User: A person or organization who controls the collection, holding, processing, or use of personal data. In this policy, a clinic customer normally acts as the Data User for its patient data and is responsible for collection, notice, consent, accuracy, use, and disclosure.
- Data Processor: A person or organization who processes personal data on behalf of a Data User and not for an independent purpose of its own. The Company may act as a Data Processor for a clinic customer; the actual role depends on the data flow, customer instructions, and applicable law.
- Customer Data: Data uploaded, entered, generated, stored, processed, or transmitted by a clinic customer or its authorized users, including patient data, medical records, appointments, billing data, and other data controlled by the customer.
- Service Data: Technical logs, device and usage information, error records, account administration data, and transaction records generated to provide, protect, maintain, and improve the Service. If such data identifies an individual, we handle it under this policy.
- Prescribed Consent: For the PDPO's direct-marketing requirements, consent or an indication of no objection that is expressly and voluntarily given after the Data Subject has been informed of the relevant circumstances and has not withdrawn it in writing.
Part 1: Principles of Personal Data Collection and Processing
1.1 Collection Principles and Methods
The Company applies Data Protection Principle 1 (DPP1) of the PDPO to the purpose and manner of personal data collection. We collect data for lawful purposes directly related to our functions and activities as a SaaS provider, and seek to keep the data necessary, adequate, and not excessive for those purposes.
We use lawful and fair collection methods and do not knowingly use deceptive or misleading means. Where a Personal Information Collection Statement (PICS) or other just-in-time notice is required, it will supplement this Privacy Policy at the point of collection; this policy remains the broader reference document for our practices.
At or before the time we collect your personal data, the Company will provide you with a clear and understandable PICS in an appropriate form (e.g., on a registration form or website page). The statement will explicitly outline:
- Purpose of Collection: Clearly stating the specific and defined purposes for which your personal data will be used.
- Classes of Transferees: Informing you of the categories of third parties to whom your personal data may be transferred or disclosed.
- Obligation to Provide Data: Stating whether providing the data is mandatory or voluntary, and the consequences of failing to provide such data.
- Rights of Access and Correction: Informing you of your right to request access to and correction of the personal data we hold, and providing contact details for the Data Protection Officer responsible for handling such requests.
1.2 Types of Personal Data We Collect
To operate the website, respond to enquiries, provide the SaaS Service, and follow customer instructions, the Company may collect, hold, and process the following categories of personal data. The actual data collected depends on the feature used, the relationship you have with the relevant party, and how a clinic customer uses the Service.
- Identity and Contact Data: Includes name, job title, company or clinic name, phone number, email address, region, language, and correspondence address. Hong Kong Identity Card numbers or other identifiers will only be handled where clearly necessary and consistent with the PDPO and relevant PCPD practice codes.
- Customer and Health Data: Clinic customers may enter or manage patient names, contact details, appointments, medical records, images, laboratory results, prescriptions, billing data, and other health-related information through the Service. Such data is normally controlled by the clinic, and the Company processes it only under customer instructions and the applicable service agreement.
- Account and Transaction Data: Includes account settings, plans, invoices, payment status, and transaction records. Full card or payment-instrument details are normally handled by a third-party payment processor; unless expressly disclosed otherwise, the Company does not store full card numbers for general use.
- Technical and Usage Data: When you interact with our website or digital platforms, our system automatically collects certain technical information. This may include your Internet Protocol (IP) address, browser type and version, operating system, login data, device information, activity logs regarding how you use our platform (e.g., features used, access times), and data collected through cookies. When such data can directly or indirectly identify you, we treat it as personal data and provide equal protection.
- Communications and Support Data: Includes emails, demo and sales enquiries, support requests, error descriptions, attachments, and other communications with the Company. If a call or remote-support session involves recording or screen sharing, we will provide additional notice and obtain any required authorization where applicable.
1.3 Purposes of Collection, Holding, and Processing
The Company collects, holds, and processes personal data only for clear purposes directly related to the website, SaaS platform, customer support, accounts, and business operations. We apply DPP1 and applicable law to keep data necessary, adequate, and not excessive. The table below summarizes the main purposes; where another jurisdiction's law applies, the relevant legal basis will be assessed according to the actual processing.
Table 1: Summary of Personal Data Processing Activities
| Category of Personal Data | Primary Processing Purpose | Relevant DPP / Legal Basis |
|---|---|---|
| Identity and Contact Data | - Respond to demo, sales, billing, and support enquiries. - Create and manage customer accounts. - Contact you about service, maintenance, and security matters. |
DPP1; providing the Service or responding to your request. |
| Health and Medical Data | - Host, store, transmit, search, back up, and otherwise process data under clinic instructions. - Maintain access controls, auditability, support, and platform security. - The Company does not provide diagnosis, treatment, or clinical judgment. |
DPP1; customer instructions and the service agreement. |
| Account and Transaction Data | - Process subscriptions, invoices, payments, and refunds where applicable. - Prevent fraud, collect overdue amounts, and conduct accounting audits. |
DPP1; transaction and legal administration. |
| Technical and Usage Data | - Maintain website and Service security, availability, and performance. - Detect abuse, errors, and security incidents. - Improve the Service using aggregated or de-identified data where practicable. |
DPP1 and DPP4; security, maintenance, and service operations. |
| Communications Data | - Respond to and follow up on enquiries, complaints, and support requests. - Keep necessary service, transaction, and compliance records. - Fulfill legal and regulatory requirements. |
DPP1; communications, service, and compliance management. |
Part 2: Use, Disclosure, and Transfer of Personal Data
2.1 Restrictions on Use of Personal Data
We apply Data Protection Principle 3 (DPP3) of the PDPO and use personal data for the purposes stated at collection or purposes directly related to them. Where a new purpose is not compatible with the original purpose, or where direct-marketing rules require it, we will obtain the required Prescribed Consent or rely on another lawful basis before proceeding. We may also use or disclose data where necessary to comply with law, protect the Service, prevent abuse, or establish, exercise, or defend legal rights.
"Prescribed Consent" means express and voluntary consent given by you with full knowledge of the circumstances. For example, a phone number collected for sending appointment reminders will not be used for unrelated promotional messages without the separate consent or other legal basis required by applicable law. Where a new notice or PICS is required, we will provide it and seek any required authorization.
2.2 Disclosure and Transfer of Personal Data
The Company keeps personal data we directly hold confidential. We disclose or transfer personal data only where lawful, reasonable, and necessary, applying a need-to-know principle and appropriate contractual restrictions. For Customer Data, disclosure or transfer is normally made under the clinic customer's instructions, the service agreement, and applicable law. Categories may include:
- Third-Party Service Providers and Subcontractors: The Company may engage providers of cloud infrastructure, databases and file storage, email or form delivery, customer support, payment processing, website analytics, bot protection, and information security. They may process data only on our or the clinic customer's instructions and only as necessary to provide the relevant service. We use contractual, confidentiality, security, and oversight measures according to risk.
- Providers of cloud, network, storage, email, support, payment, and security functions.
- Providers of website analytics, bot protection, or error monitoring, such as Google, Microsoft, or Cloudflare; the actual tools depend on the website and Service configuration.
- Other providers connected to or assisting with data under a clinic customer's instructions.
- Clinic Customers and Their Designees: Where a clinic customer controls the data, we may provide or enable access to the clinic, its authorized personnel, or service providers designated by that clinic.
- Disclosure under Legal Requirements: Under laws, regulations, legally binding court orders, or requests from government departments (such as the Department of Health), or to cooperate with lawful investigations by law enforcement agencies to prevent or detect crime, we may be obligated to disclose relevant personal data.
- Emergency Situations: In emergency situations where there is a serious threat to the life or health of you or others, we may disclose personal data when necessary to prevent or mitigate that threat.
2.3 Cross-border Data Transfer
Our operations may involve cloud, analytics, security, email, payment, or other service providers located outside Hong Kong. Personal data may therefore be processed or stored outside Hong Kong. We assess risks according to the data category, service need, and applicable law, and use contractual, confidentiality, security, purpose-limitation, onward-transfer, and deletion measures to require appropriate protection from recipients.
We refer to the PDPO, PCPD guidance on cross-border transfers and cloud computing, and applicable contractual safeguards. Recipients, processing locations, and providers may change because of feature, technology, or operational requirements; where a Personal Information Collection Statement or applicable law requires notice, we will provide it.
To this end, we take the following measures:
- Contractual and Purpose Controls: We require recipients to process data only for the agreed service purposes and restrict unauthorized disclosure and onward transfer.
- Due Diligence: We assess security capabilities, service terms, processing locations, and subcontracting arrangements according to the sensitivity of the data and provider risk.
- Transparent Notice: Applicable Personal Information Collection Statements, service terms, or customer agreements will describe the relevant recipient categories.
2.4 Commitment Against Data Commercialization and Marketing
We do not sell identifiable personal information of patients or consumers to third parties.
We separate service, billing, security, and support communications from marketing. We will not sell identifiable patient or consumer personal data, or provide Customer Data to a third party for that party's own direct marketing. Unless the prescribed consent required by applicable law or another lawful basis applies, we will not use personal data collected directly for unrelated direct marketing.
For direct marketing about new services, events, or offers, we will where applicable provide clear notice, an opt-in or no-objection channel, and a free opt-out method. A clinic customer that uses the Service to message its patients remains responsible for the relevant notices, consents, content, recipients, and opt-out mechanism.
2.5 Case Studies and Use of Customer Company Information
Unless you notify the Company in writing that you do not want this use, the Customer is deemed to grant the Company a non-exclusive, royalty-free, and limited license to use its company name, trademarks, logos, case studies, implementation details, and customer-success stories for marketing. If you do not want the Company to use this information, please provide written notice; the Company will stop new uses within a reasonably practicable period, but is not responsible for immediately withdrawing materials already published, printed, or reproduced by third parties.
This default permission does not include patient data, reasonably identifiable individual data, protected trade secrets, or information whose disclosure is prohibited by law. Any use of such information requires separate written approval and an applicable lawful basis. We will also:
- Strict Privacy Protection: Exclude patient data and reasonably identifiable individual data unless a separate written approval and lawful basis expressly cover the specific use.
- Maintenance of Business Secrets: Exclude contract specifics, pricing plans, proprietary technology, and protected trade secrets unless the approved scope expressly authorizes their disclosure.
- Professional and Compliant Use: Use the relevant information only within the default permission or separate written approval, and in accordance with applicable law and any brand guidelines known to us.
Any approved case study or trademark use does not constitute a guarantee of medical, security, or service outcomes and does not affect either party's rights or obligations under the service agreement.
Part 3: Data Security and Retention
3.1 Data Security Commitment
The Company applies Data Protection Principle 4 (DPP4) of the PDPO and takes practicable steps to protect personal data from unauthorized or accidental access, processing, erasure, loss, or use. We maintain a risk-based security program covering governance, technical, and physical measures, informed by applicable law, PCPD guidance, and relevant industry practice.
Data Governance and Organizational Measures
- Designated Responsibility: We maintain a contact for privacy and data-security matters, including oversight of applicable law and internal policies. Contact details are provided in Part 6 of this policy.
- Limited and Controlled Access: The Company will not access or use Customer Data for an independent purpose of its own. To provide support, maintenance, security, incident investigation, legal compliance, or fulfill customer instructions, authorized personnel may need limited access within a need-to-know and least-privilege scope. Clinic customers should avoid including unnecessary patient identifiers in support requests; remote connections or screen sharing require the customer's express authorization.
- Policies and Procedures: We maintain internal policies and procedures appropriate to the nature and risk of the personal data we handle, covering relevant parts of its lifecycle from collection, use, and storage to deletion.
- Access Control: We use least-privilege and need-to-know controls. The Service supports role-based access management, and clinic customers are responsible for configuring their users and administrator accounts appropriately. Company personnel are permitted to access only the minimum data reasonably required for their duties, subject to applicable support and security processes. Access rights are reviewed and revoked or adjusted as appropriate when roles change or personnel leave.
- Employee Training: We provide privacy and information-security training appropriate to personnel roles and responsibilities, including relevant legal requirements, internal procedures, social-engineering risks, and safe handling of sensitive data.
- Risk Assessment: We conduct security and privacy risk assessments when appropriate to the nature of the processing, including before material changes to technology, systems, or processing activities where warranted.
Technical Measures
We select technical and organizational measures appropriate to the data, processing, threat environment, and Service architecture.
- Transmission and Storage Protection: We use appropriate transmission encryption, storage encryption, key-management, and access-control measures according to data sensitivity and the service environment.
- Infrastructure and Network Protection: We use cloud, network, and security providers that may provide firewall, traffic protection, monitoring, backup, or other security functions; configurations may change according to the environment, provider, and service requirements.
- Secure Configuration and Patching: We apply risk-based hardening, vulnerability handling, code review, log monitoring, and patch-management practices.
- De-identification and Aggregation: For service analysis, statistics, testing, or product improvement, we use aggregated, de-identified, or pseudonymized data where practicable and take reasonable measures to prevent re-identification.
Physical Measures
We provide high protection for personal data existing in physical form.
- If the Company holds physical personal data for business purposes, we use reasonable measures such as access control, locked storage, and secure destruction according to sensitivity.
- Physical security for cloud servers is provided by the relevant cloud service providers under their security measures and contractual commitments.
3.2 Data Breach Incident Response Plan
Despite our rigorous preventive measures, we have developed a detailed response plan to deal with potential data security incidents (i.e., data breaches). The plan aims to quickly contain the situation, assess the impact, and take remedial measures to minimize potential harm to affected individuals.
Our response plan includes the following key steps:
- Immediate Action: Upon discovery or suspicion of a data breach, the response team will take immediate action, including isolating affected systems to stop the continuation of the leak.
- Harm Assessment: We will quickly assess the nature of the incident, the types and volume of personal data involved, and the risk of harm to the data subjects.
- Notification Mechanism: If an incident involves Customer Data, we will notify the relevant customer as soon as practicable after confirming or reasonably suspecting the incident, as required by the applicable service or data-processing terms. Whether to notify the PCPD or affected Data Subjects will be determined by applicable law, regulatory guidance, and incident risk.
- Post-incident Review: After the incident is handled, we will conduct an in-depth review to identify the root cause and take necessary improvement measures to strengthen our security system and prevent similar incidents from recurring.
3.3 Data Retention Policy
The Company applies Data Protection Principle 2 (DPP2) of the PDPO and does not retain personal data longer than reasonably necessary for the purpose for which it is used, subject to customer instructions, contractual commitments, security needs, and legal retention requirements.
Our data retention policy is based on the following principles:
- Purpose-driven: Retention periods depend on the collection purpose, customer instructions, service agreement, billing and legal obligations, security needs, and other applicable law. The relevant clinic normally remains responsible for retaining patient medical records.
- Customer Data: After service termination or a customer instruction, we will restrict access and delete or return Customer Data according to the service agreement, data-processing terms, and any applicable export arrangement. Backups may remain until overwritten in the ordinary backup cycle; unless agreed in writing, we do not guarantee permanent or immediate recovery of deleted data.
- Other Data: Billing, payment, transaction, security-log, incident, and legally required records may be retained for the period necessary for the relevant purpose or legal obligation.
- Secure Destruction: When data is no longer required, we take reasonable steps to delete, anonymize, or securely destroy it according to its category and technical environment.
Part 4: Your Rights and Our Responsibilities
4.1 Transparency of Information
The Company abides by Data Protection Principle 5 (DPP5) of the PDPO, striving to ensure high transparency in our policies and practices regarding personal data. This Privacy Policy Statement is our primary tool for fulfilling this responsibility, aimed at clearly informing you of the types of personal data the Company holds and the primary purposes for which such data is used. We commit to disclosing our data handling practices in clear, easy-to-understand language.
4.2 Rights of Access and Correction
The PDPO gives you rights to access and correct personal data. The Company will handle requests for data we actually hold or control; where a clinic customer controls the data, we will provide reasonable assistance after identity verification and under the customer's instructions, but will not disclose clinic-controlled medical records without lawful authorization.
Data Access Request (DAR)
You have the right to ascertain whether the Company holds your personal data and, if we do, to request a copy under the PDPO. If the data is controlled by a clinic customer, please send the request to that clinic or identify the clinic in your request so that we can refer or assist appropriately.
How to make a Data Access Request:
- In Writing: All DARs must be made in writing (in Chinese or English). For ease of processing, we recommend using the "Data Access Request Form" (Form OPS003) specified by the PCPD.
- Submission: Please mail or email the completed form to the Data Protection Officer listed in Part 6 of this policy.
- Identity Verification: To protect your personal data from unauthorized access, we need to take reasonable steps to verify your identity before processing the request.
- Processing Time: According to PDPO regulations, we will comply with your request or provide a written response within 40 calendar days of receiving your request.
- Fees: We may charge a fee that is not excessive for processing a DAR to cover the direct administrative costs involved in providing copies of the data. If a fee is required, we will notify you in advance.
Data Correction Request (DCR)
If you believe that the personal data the Company holds about you is inaccurate, you have the right to request that we make corrections.
How to make a Data Correction Request:
A DCR should be made after you have exercised your right of access and obtained a copy of the data. The procedure is similar to a DAR, requiring a written request to the actual Data User or the contact listed in Part 6, clearly specifying the data that needs correction and the correct content. We will assist in accordance with the PDPO, customer instructions, and the applicable service agreement.
Grounds for Refusal
While we strive to assist you in exercising your rights, in a few specific circumstances prescribed by the PDPO, we may need to refuse your access or correction request. These circumstances include but are not limited to:
- The request is not made in writing in Chinese or English.
- We are unable to verify the identity of the requester through reasonable steps.
- Complying with the access request would involve disclosing personal data of a third party who cannot be anonymized.
- Other exemptions specified in the PDPO apply.
If we refuse your request, we will notify you in writing of the reasons for refusal within the 40-day statutory period and record the details of the refusal as required by law.
4.3 Use of Website Tracking Technologies
To enhance the performance and user experience of the Company's website and digital platforms, we may use "Cookies" and similar website tracking technologies. We commit to being fully transparent in this regard.
- What are Cookies: Cookies are small text files stored on your computer or mobile device. The website may also use pixels, SDKs, browser storage, and similar technologies to remember preferences, maintain security, understand website use, and prevent abuse.
- Types of Cookies We Use:
- Necessary and Security Technologies: Used for language preferences, form security, bot protection, authentication, or basic website operation.
- Analytics and Experience Technologies: We may use Google Analytics, Microsoft Clarity, or other analytics tools to understand page use, errors, traffic, and interactions and to improve the website and Service. These tools may process technical data through providers outside Hong Kong.
- Your Choice and Control: You may restrict Cookies and similar technologies through browser, device, or relevant third-party settings; refusing some technologies may affect certain website functions. Where a jurisdiction or particular tool requires prior consent, we will follow the applicable process to obtain, record, and respect your choice.
Part 5: Legal Liability
5.1 Responsibility of Service Users
HelloClinic provides a technical SaaS platform. Clinic customers normally act as the Data Users of their patient data and are responsible for collection, notice, consent, accuracy, medical use, professional decisions, and external disclosure; the Company remains responsible for its processing activities as a Data Processor or service provider under applicable law, the service agreement, and data-processing terms. Hosting data through the Service does not transfer the statutory rights of patients, clinics, or other Data Subjects.
5.2 AI-Generated Content Disclaimer
The Service may include features that assist in generating content using Artificial Intelligence (AI). All AI-generated content is for reference only and cannot replace professional medical judgment. Users have the ultimate responsibility to review, modify, and independently confirm the accuracy, completeness, and clinical appropriateness of AI-generated content before making or implementing any clinical decision. To the maximum extent permitted by applicable law, HelloClinic is not responsible for clinical, legal, or other consequences arising from use of or reliance on AI-generated content.
5.3 Clinical Safety Alerts Disclaimer
The Service may provide allergy alerts and drug-interaction alerts as clinical safety support. These alerts are not AI-generated content, medical advice, diagnosis, treatment, or a substitute for professional clinical judgment. An alert may be absent, delayed, incomplete, inaccurate, or generated when no alert is clinically relevant. To the maximum extent permitted by applicable law, HelloClinic is not responsible for any consequence arising from an alert, the absence of an alert, or reliance on either. Users have the ultimate responsibility to review, modify, and independently confirm the accuracy, completeness, and clinical appropriateness of the relevant information before making or implementing any clinical decision.
Part 6: Contact and Policy Review
6.1 Language Version
This policy is provided in Traditional Chinese and English. For a public website notice, we will use reasonable efforts to keep both versions consistent. If a customer agreement or applicable law specifies a language version, that agreement or law will control; if no language version is specified, the Traditional Chinese version shall prevail. This Privacy Policy does not replace a separate service agreement or data-processing terms signed with a customer.
6.2 Governing Law and Jurisdiction
KAKI TECH LIMITED is the Hong Kong legal entity operating HelloClinic. To the extent legally applicable, this Privacy Policy and any non-contractual obligations arising from or relating to it are governed by the laws of the Hong Kong Special Administrative Region. Unless an applicable customer agreement or mandatory law provides otherwise, the parties submit to the exclusive jurisdiction of the courts of Hong Kong for disputes arising from or relating to this Privacy Policy, the website, or the Company's handling of personal data.
6.3 Changes to the Policy
We regularly review and update this Privacy Policy to reflect legal requirements, technology, and our operational practices. Amendments will be published on this website and the "Last Updated" date will identify the latest version. We may notify you of material changes by email, platform notice, or a prominent website notice; changes relating only to website technology, providers, or non-material operations may be reflected by updating this policy and its date.
6.4 Contacting Our Data Protection Officer
Establishing a clear, single point of contact is an important part of our practice of accountability and protection of your rights. This ensures you can communicate directly with personnel dedicated to privacy matters when needed, reflecting our serious attitude toward data governance.
If you have any questions about this Privacy Policy Statement, or wish to make inquiries or complaints regarding personal data matters, or exercise your rights of access and correction, please contact our Data Protection Officer via:
- Title: Data Protection Officer (DPO)
- Email Address: info@helloclinic.io
All correspondence will be handled confidentially, and we will endeavor to respond to your inquiries in a timely manner.
6.4 Complaining to the PCPD
The Company is committed to resolving any concerns you may have regarding personal data privacy in a fair and transparent manner. However, in the spirit of fully protecting your rights and ensuring information transparency, we hereby inform you that if you are dissatisfied with the way we handle your privacy matters or our response, you have the right to lodge a complaint with the independent regulatory body in Hong Kong - the Office of the Privacy Commissioner for Personal Data (PCPD). For complaint procedures and contact information, please refer to the PCPD official website.