PRIVACY POLICY

Effective date: 22 July 2026

Last updated: 22 July 2026

1. Introduction and Scope

AGH GROUP HOLDINGS SDN. BHD., trading as MediGoMY (“MediGoMY”, “we”, “us” or “our”), is responsible for the MediGoMY healthcare-information, patient-support and medical-coordination service and for determining the purposes for which personal data is processed through that service, except where another party independently determines its own purposes and means of processing.

The MediGoMY website at medigomy.com, its landing pages and related digital channels may be designed, developed, hosted, maintained, secured, promoted, optimised or operationally supported by authorised external service providers and business partners (collectively, “Website Operations Partners”). These functions may include website development, hosting, technical maintenance, cybersecurity support, search-engine optimisation (“SEO”), search-engine marketing (“SEM”), analytics configuration, advertising-campaign administration, content publishing, customer-enquiry routing and other operational support.

Website Operations Partners act only within the scope of their respective appointments and agreed responsibilities. Where a Website Operations Partner processes personal data solely on MediGoMY’s documented instructions, it acts as a data processor or service provider and does not determine the medical or healthcare purposes for which the information is used.

Where a Website Operations Partner independently determines the purposes and means of a particular processing activity, it may instead act as an independent data controller for that activity and will be responsible for providing any additional privacy information required by applicable law.

MediGoMY may assist users with treatment information, overseas-treatment enquiries, medical second opinions, medical-record collection and preliminary administrative review, hospital and specialist matching, treatment quotations, appointment coordination, communications with hospitals and medical teams, travel and treatment coordination, translation, case-management support and post-treatment administrative follow-up.

This Privacy Policy applies to patients, prospective patients, website visitors and users, and their authorised representatives, including family members, guardians and caregivers, whose personal data is handled in connection with the MediGoMY service.

This Privacy Policy covers personal data collected through medigomy.com, online forms, landing pages, social-media enquiries and lead forms, WhatsApp and other messaging services, email, telephone communications and other service channels made available by MediGoMY.

Independent hospitals, clinics, doctors, laboratories, insurers, travel providers, payment providers, social-media platforms, advertising platforms and other third parties have their own legal responsibilities and privacy practices. Their independent activities are governed by their own privacy notices and terms, which MediGoMY and the Website Operations Partners do not control.

 Nothing in this Privacy Policy makes MediGoMY, a Website Operations Partner or any other service provider responsible for an independent third party’s clinical decisions, professional services, systems, security, representations, acts or omissions, except to the extent that such responsibility cannot lawfully be excluded or arises from that party’s own conduct.

2. Roles, Allocation of Responsibility and Service Limitations

2.1 MediGoMY’s Role

Website Operations Partners provide technical, marketing, operational, administrative or maintenance support only within their agreed scope.

Unless expressly stated otherwise, none of the Protected Parties is acting as a hospital, clinic, medical laboratory, pharmacy, insurer or emergency medical service.

MediGoMY may introduce or connect users to independent hospitals, doctors, laboratories, insurers, travel providers and other healthcare-related service providers in Malaysia or overseas, including in China.

Submitting information through the website does not, by itself:

(a) create a doctor-patient, fiduciary, agency, employment, partnership, joint-venture or other professional relationship between you and any Protected Party;

(b) create a doctor-patient relationship between you and MediGoMY or any Website Operations Partner;

(c) authorise a Website Operations Partner to make medical or treatment decisions;

(d) guarantee that any hospital, doctor or service provider will accept, review or proceed with your case;

(e) guarantee the accuracy, completeness or availability of third-party information, quotations, appointment dates, translations, treatment proposals, travel arrangements or related services;

(f) guarantee any diagnosis, treatment, recovery, appointment, service result or medical outcome; or

(g) replace emergency care or consultation with a suitably qualified healthcare professional.

2.2 Role of Website Operations Partners

Website Operations Partners provide technical, marketing, operational, administrative or maintenance support only within their agreed scope.

Unless expressly agreed and lawfully authorised otherwise, Website Operations Partners:

(a) do not provide medical advice, diagnosis, prescriptions or treatment;

(b) do not select or recommend treatment on clinical grounds;

(c) do not make decisions on behalf of hospitals, doctors, insurers, patients or MediGoMY;

(d) do not guarantee website rankings, search-engine results, advertising performance, enquiry volume, sales, conversions, continuous availability, uninterrupted operation or error-free performance;

(e) are not responsible for the accuracy, completeness or legality of medical, corporate, promotional or service information supplied by MediGoMY, healthcare providers, advertisers or other content owners;

(f) are not responsible for clinical decisions, medical outcomes, appointment availability, hospital acceptance, treatment quotations or the performance of independent healthcare providers;

(g) process personal data only to the extent reasonably necessary for their authorised functions and subject to applicable law and contractual controls; and

(h) may rely on information, instructions, materials and approvals supplied by MediGoMY or other authorised parties unless the Website Operations Partner actually knows that the relevant information or instruction is unlawful.

The engagement of a Website Operations Partner does not transfer MediGoMY’s responsibilities as data controller to that partner.

Equally, a Website Operations Partner is responsible only for obligations applying to its own conduct, role and processing activities. No party assumes another party’s independent statutory, professional, medical, clinical or contractual duties merely because it contributes to, develops, maintains, promotes, advertises, optimises or otherwise supports the website.

To the fullest extent permitted by applicable law, no director, officer, employee, consultant, contractor, agent or representative of a Protected Party assumes personal liability solely because that individual performed authorised work for or on behalf of MediGoMY or a Website Operations Partner.

2.3 No Medical Advice

The website, its content and all coordination communications are provided for general information and administrative-coordination purposes only.

They do not constitute medical advice, diagnosis, treatment, a medical opinion, a prescription or a recommendation to undergo or refrain from any particular treatment. They are not a substitute for consultation with a suitably qualified healthcare professional.

All diagnoses, treatment recommendations, prescriptions, clinical decisions and medical outcomes remain the responsibility of the independent hospital, doctor or healthcare professional providing them.

Users are responsible for obtaining appropriate professional medical advice and for independently evaluating any treatment, provider, quotation or arrangement before making a decision.

To the fullest extent permitted by applicable law, the Protected Parties are not liable for any medical decision, diagnosis, treatment, prescription, clinical act or omission, delay, complication, injury, loss or outcome attributable to an independent hospital, doctor or healthcare provider, or arising from a user treating general website content as a substitute for professional medical advice.

2.4 Third-Party Information and Services

Information concerning hospitals, doctors, treatments, costs, appointment availability, travel arrangements or other third-party services may be supplied by independent third parties.
 

Unless expressly stated otherwise, MediGoMY and the Website Operations Partners do not independently verify or guarantee all such information. Information may change without notice and should be confirmed directly with the relevant provider before the user relies upon it.

 

A link, introduction, listing, advertisement, publication or communication concerning a third party does not constitute a guarantee, endorsement, warranty or assumption of responsibility for that party’s conduct, services, systems or outcomes.

 

Each independent third party remains responsible for its own:

(a) professional and clinical services;

(b) licences, registrations and regulatory compliance;

(c) representations, quotations and contractual commitments;

(d) privacy notices and personal-data processing;

(e) information-security systems;

(f) personnel, agents and subcontractors; and

(g) acts, omissions, delays and service outcomes.

2.5 Responsibility That Cannot Be Excluded

Nothing in this Privacy Policy excludes, restricts or transfers any duty or liability that cannot lawfully be excluded.

This includes responsibility arising from a party’s own fraud, wilful misconduct, breach of a mandatory data-protection obligation, or any other liability that applicable law does not permit that party to exclude.

 

Each party remains responsible for its own acts, omissions, personnel, systems and compliance obligations within its actual role.

 

No Protected Party is responsible for another party’s independent conduct merely because the parties cooperate, exchange information, share infrastructure, refer users, contribute content or participate in the same service arrangement.

 

This Privacy Policy principally addresses privacy and personal-data matters. Additional provisions concerning website use, intellectual property, content ownership, service availability, warranties, limitations of liability, indemnities, dispute resolution and governing law should be contained in separate Website Terms of Use and in the written agreements between MediGoMY and its Website Operations Partners.

3. Definitions

In this Privacy Policy, the following terms have the meanings given below. Where a term is defined in the Personal Data Protection Act 2010 [Act 709], as amended (the “PDPA”), the applicable statutory meaning prevails.

 

(a) “Personal data” means information relating directly or indirectly to an identified or identifiable individual, as recognised under the PDPA.

(b) “Sensitive personal data” includes information concerning a person’s physical or mental health or condition, biometric data and any other category treated as sensitive under applicable law. In this Privacy Policy, related health information may also be described as “sensitive medical information”.

(c) “Health and medical information” means information concerning a person’s health, symptoms, medical condition, diagnosis, prognosis, treatment, medical history, medication, allergies, tests, medical images, medical records or related matters.

(d) “Processing” includes collecting, recording, holding, storing, accessing, viewing, organising, adapting, using, disclosing, transmitting, transferring, combining, restricting, deleting or destroying personal data.

(e) “Data subject” means the individual to whom personal data relates.

(f) “Data controller” means a person or organisation that processes personal data, has control over the processing of personal data, or authorises the processing of personal data, consistently with the applicable statutory definition.

(g) “Data processor” means a person or organisation that processes personal data on behalf of a data controller and within the scope of the data controller’s instructions. A data processor remains responsible for obligations that applicable law imposes directly upon data processors, including applicable security obligations.

(h) “Service provider” means an external party engaged to provide services that may involve personal-data processing. Depending on its actual role, a service provider may act as a data processor, an independent data controller or, where the legal requirements are met, a joint data controller.

(i) “Website Operations Partner” has the meaning given in Section 1 and includes an authorised provider of website development, hosting, maintenance, cybersecurity, SEO, SEM, analytics, advertising administration, content management, customer-enquiry routing or related operational services. This description identifies a commercial function and does not, by itself, determine that party’s legal data-protection status.

(j) “Protected Parties” has the meaning given in Section 2.1. The use of this collective term does not exempt any person from an obligation or liability imposed by applicable law for that person’s own conduct.

(k) “Cookies and similar technologies” means cookies, pixels, tags, software development kits, local storage and comparable technologies used to store or access information on a device.

(l) “Independent third party” means a hospital, doctor, clinic, laboratory, insurer, travel provider, payment provider, social-media platform, advertising platform or other organisation that independently determines its services, systems, professional decisions or personal-data processing.

4. Categories of information collected

We collect the categories of information described below, in each case only where actually applicable to the service you request or your use of our website. Not all categories apply to every user.

Identity and contact information

(a) full name;

(b) identification or passport details, where required;

(c) date of birth;

(d) age;

(e) gender, where medically or administratively relevant;

(f) nationality;

(g) residential location;

(h) telephone number;

(i) WhatsApp number, where you contact us via WhatsApp;

(j) email address;

(k) preferred language.

Sensitive health and medical information

This information is sensitive and is handled with heightened care (see Section 9). It may include:

(a) diagnosis;

(b) symptoms;

(c) medical history;

(d) treatment history;

(e) current medications;

(f) allergies;

(g) laboratory reports;

(h) pathology reports;

(i) imaging files;

(j) scans, X-rays, CT, MRI or PET reports;

(k) genetic or genomic information;

(l) biopsy results;

(m) surgical records;

(n) discharge summaries;

(o) doctors’ letters;

(p) treatment plans;

(q) insurance medical information;

(r) disability, or physical and mental health, information;

(s) photographs or videos submitted for medical evaluation;

(t) other information concerning a patient’s condition, prognosis or treatment enquiry.

Representative and family information

(a) next-of-kin details;

(b) emergency-contact information;

(c) caregiver information;

(d) parent or guardian information;

(e) authorised-representative details;

(f) proof of authority to act for another patient.

Financial, insurance and transaction information

(a) insurance provider and policy information;

(b) payment records;

(c) billing details;

(d) treatment-quotation requests;

(e) transaction references;

(f) limited payment information received from payment processors.

Full payment-card details are handled by our external payment processors and are not stored in complete form by MediGoMY. We receive only limited payment information (such as confirmation of payment and masked card references) from those processors.

Travel and coordination information

(a) passport and visa-related information;

(b) travel dates;

(c) flight and accommodation information;

(d) accessibility needs;

(e) companion details;

(f) transportation arrangements;

(g) treatment-location preferences.

Communications

(a) contact-form submissions;

(b) emails;

(c) WhatsApp and other messaging conversations;

(d) telephone-call notes or recordings;

(e) Zoom or other video-consultation records;

(f) customer-service enquiries;

(g) complaints;

(h) survey responses;

(i) event or seminar registrations.

Calls or video sessions are only recorded where there is a valid legal basis and appropriate prior notice or consent, and any such recording is treated as sensitive where it contains health information.

Technical and online information

(a) IP address;

(b) device identifiers;

(c) browser type;

(d) operating system;

(e) approximate location;

(f) pages visited;

(g) referral source;

(h) interaction data;

(i) cookie identifiers;

(j) advertising identifiers;

(k) form-submission data;

(l) website logs;

(m) analytics and conversion information.

Marketing and lead information
We may receive enquiries and leads through advertising and social-media platforms. We include only platforms that are actually used, and we identify the specific platforms in the details completed before publication (see Appendix A).

5. Sources of information

We may obtain information:

(a) directly from the patient;

(b) from a parent, guardian, family member, caregiver or authorised representative;

(c) from doctors, hospitals, clinics, laboratories and other healthcare providers;

(d) from insurers or medical-assistance companies;

(e) from social-media and advertising lead forms.

6. Information about another person

If you provide personal or medical information about another person (for example, a patient for whom you are enquiring), you confirm that you:

(a) are authorised to provide that information;

(b) have given that person the privacy information they are entitled to receive (including by directing them to this Privacy Policy);

(c) have obtained valid consent or otherwise hold lawful authority to provide the information; and

(d) are not unlawfully accessing or disclosing that person’s medical records.

 We may request proof of your authority before acting on such information, and may decline to proceed where adequate authority is not established.

7. Purposes of processing

We may request proof of your authority before acting on such information, and may decline to proceed where adequate authority is not established.

Purposes necessary to provide or support the services

(a) responding to enquiries;

(b) reviewing whether submitted records are administratively complete;

(c) arranging medical-record review or second-opinion requests;

(d) matching patients with hospitals and doctors;

(e) sending records to healthcare providers selected in connection with your enquiry;

(f) obtaining treatment proposals, quotations or appointment availability;

(g) coordinating consultations, admissions and travel;

(h) providing translation and case-management support;

(i) communicating with patients and their representatives;

(j) processing payments and invoices;

(k) insurance and claims-related coordination;

(l) maintaining case and communication records;

(m) providing customer support.

Purposes related to operating and protecting the platform

(n) improving website functionality and user experience;

(o) website security, fraud prevention and misuse detection;

(p) compliance with legal, regulatory and professional obligations;

(q) establishing, exercising or defending legal claims;

(r) internal audits, quality assurance and staff training;

(s) analytics and service improvement;

(t) de-identification or aggregation of data for analytics, where legally permitted.

 

Optional purposes

(u) direct marketing, only with the appropriate legal basis and a functioning opt-out mechanism (see Section 17).

 

Emergency purposes

(v) emergency disclosures where necessary to protect the life, health or safety of an individual.

The purposes in paragraphs (a) to (t) and (v) are, or may be, necessary for the relevant service or for our lawful operation. The purpose in paragraph (u) (marketing) is optional and is treated separately; declining marketing does not affect the provision of services.

8. Legal grounds and consent

We rely on the grounds for processing that are available under the PDPA. Consent is one basis, but not the only basis; other conditions permitted by the PDPA may apply. We map each purpose in Section 7 to a specific lawful basis as follows:

 

(a) Service-delivery and coordination purposes (Section 7(a)—(m)): performance of, or taking steps at your request prior to entering into, the coordination service you have requested; and, so far as these involve sensitive medical information, the specific condition in Section 9 (explicit consent or another PDPA-permitted condition).

(b) Platform operation, security and improvement purposes (Section 7(n)—(o), (s)—(t)): our legitimate interests in operating, securing and improving the platform, balanced against your interests, and, where legally required, your consent (for example for non-essential analytics).

(c) Legal, regulatory and audit purposes (Section 7(p)—(r)): compliance with a legal obligation to which we are subject, and our legitimate interests in maintaining quality and defending legal claims.

(d) Legal-claims purposes (Section 7(q)): the establishment, exercise or defence of legal claims.

(e) Direct-marketing purposes (Section 7(u)): your separate, specific consent for the relevant channel (see Section 17); this is never bundled with service consent.

(f) Emergency purposes (Section 7(v)): protection of the vital interests — the life, health or safety — of you or another person, where consent cannot be obtained in time.

Sensitive personal data (including sensitive medical information) is processed only on the additional specific conditions set out in Section 9. Where a foreign privacy law genuinely applies, we rely only on the corresponding lawful basis available under that law (see the paragraph below on foreign privacy laws and Article 9(2) of the GDPR).

Where foreign privacy laws apply

Foreign privacy laws do not necessarily apply to MediGoMY (see Section 13 and Appendix A). Where a foreign privacy law is genuinely applicable to a particular processing activity, the legal bases available under that law may include: consent or explicit consent; performance of a requested service or contract; compliance with a legal obligation; legitimate interests, where permitted and appropriately balanced; protection of vital interests; the establishment, exercise or defence of legal claims; and the provision or coordination of healthcare, where legally permitted. We would rely only on bases that are actually available and appropriate under the relevant law.

Consent and its withdrawal

(a) We use layered consent rather than a single omnibus consent. This means that, in addition to any general acknowledgement of this Privacy Policy, we obtain separate, specific and explicit consent for each distinct high-impact activity — in particular: (i) the collection and processing of your sensitive medical information; (ii) the sharing of your medical records with selected hospitals and doctors; (iii) the cross-border transfer of your medical information; and (iv) direct marketing. Each such consent is requested at the relevant point (for example, on a form or before an optional activity), is unbundled from the others, and is not pre-ticked.

(b) You may withdraw consent at any time using the contact details in Section 27, or through any opt-out mechanism provided.

(c) Withdrawing consent does not affect the lawfulness of processing already carried out before withdrawal.

(d) Withdrawing consent may prevent us from continuing a requested service, and we will explain the likely consequences where relevant.

(e) Medical records already sent to an independent hospital or doctor may remain subject to that organisation’s own legal and clinical retention obligations, which we do not control.

9. Sensitive medical information

Health and medical information is sensitive personal data and is treated with heightened care.

(a) We process sensitive medical information only where a specific condition applies. Under the PDPA, this is typically: (i) your explicit consent; (ii) where processing is necessary to protect your vital interests (or those of another person) where consent cannot be obtained; (iii) where processing is necessary for medical purposes and is undertaken by, or under the responsibility of, a person subject to an obligation of confidentiality; or (iv) where processing relates to information you have deliberately made public, or is necessary for legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights. Where a foreign privacy law genuinely applies, we rely only on the corresponding condition available under Article 9(2) of the GDPR — in particular Article 9(2)(a) (explicit consent), 9(2)(c) (vital interests), 9(2)(h) (provision of health care or treatment), or 9(2)(f) (legal claims).

(b) Access to sensitive medical information is restricted to personnel and parties who need it for the purposes described in this policy.

(c) Disclosure of sensitive medical information is made on a need-to-know basis and limited to what is reasonably necessary.

(d) Where medical records are to be shared with hospitals or doctors, we seek appropriate medical-record-sharing authorisation.

(e) We apply additional safeguards to sensitive medical information (see Section 19), recognising that no safeguard can be guaranteed to be completely effective.

(f) Hospitals, doctors and other independent organisations may require you to complete their own separate consent or authorisation forms before they will receive, review or act on medical information.

Publishing this Privacy Policy does not, by itself, constitute your consent to process or disclose your medical records. Where consent is required, it is obtained separately and specifically.

10. When providing information is mandatory

Some information may be necessary in order for us to assist you. For example, information may be necessary to:

(a) respond to an enquiry;

(b) identify the correct patient;

(c) obtain a medical opinion or second opinion;

(d) communicate with a hospital or doctor;

(e) arrange travel or treatment; or

(f) meet legal or payment requirements.

Where information is necessary and you choose not to provide it, we may be unable to respond to your enquiry, progress your case, arrange a service, or complete a transaction. We will indicate, where practical, which information is required and which is optional.

11. Disclosure and recipients

We may disclose personal data to the following categories of recipient, where applicable to your enquiry or service. This list is illustrative and not exhaustive:

(a) selected hospitals;

(b) doctors and multidisciplinary medical teams;

(c) clinics, laboratories and diagnostic centres;

(d) translators and medical interpreters;

(e) case coordinators;

(f) insurers and medical-assistance companies;

(g) travel, visa, accommodation and transportation providers;

(h) payment processors and banks;

(i) website-hosting and cloud-storage providers;

(j) email, messaging, CRM and customer-support providers;

(k) IT, cybersecurity and backup providers;

(l) analytics and advertising providers;

(m) professional advisers, auditors, accountants and lawyers;

(n) regulators, courts, law-enforcement agencies and government authorities, where lawfully required or permitted; and

(o) a buyer, investor or successor in connection with a genuine corporate transaction (see Section 25).

Disclosure is limited to what is reasonably necessary for the relevant purpose and, where required, is subject to appropriate confidentiality, security or contractual controls.

MediGoMY does not sell personal data, and does not share health or other sensitive medical information with third parties for their own targeted-advertising purposes. Any disclosure of personal data is made only for the purposes described in this Privacy Policy and, where required, subject to appropriate confidentiality, security or contractual controls.

12. Hospitals and doctors as independent organisations

Hospitals, doctors, laboratories and similar healthcare organisations generally determine independently how they use, store and retain medical information once it is provided to them. In respect of that information, they typically act as independent data controllers.

 Their own privacy notices, consent forms and clinical-record rules may apply separately to their handling of your information, in addition to this Privacy Policy.

Nothing in this section limits or disclaims MediGoMY’s own responsibility for its selection of recipients, its transmission of information, and its own handling of personal data.

13. International and cross-border transfers

Because our services may involve overseas treatment and cross-border referrals, medical records and other personal data may be transferred outside Malaysia.

(a) Possible destination countries include China and other countries selected by, or relevant to, the patient.

(b) Recipients may include overseas hospitals, doctors, cloud providers and other service providers.

(c) Privacy protections in a destination country may differ from, and may be lower than, those in Malaysia. We do not represent that every foreign country provides protection equivalent to Malaysian law.

(d) We seek to make cross-border transfers in accordance with the conditions and safeguards required under the PDPA.

(e) Depending on the circumstances, transfer mechanisms may include your consent, contractual safeguards, due diligence on recipients, and other mechanisms permitted under applicable law.

(f) We apply data minimisation, transferring only what is reasonably necessary.

(g) We seek to use secure transmission methods (see Section 19).

(h) We seek to record the basis on which each cross-border transfer is made.

(i) You may request further information about the safeguards applying to transfers of your personal data using the contact details in Section 27.

Where personal information is transferred to or from organisations in China, additional requirements under the People’s Republic of China Personal Information Protection Law (“PIPL”) may apply to the China-side organisation. In particular, transfers of personal information out of China may require a separate legal basis and transfer mechanism under PIPL, which the relevant China-side partner must assess and confirm. This is a matter for the China-side organisation and cannot be resolved by MediGoMY alone.

14. Cookies and similar technologies

Our website may use the following categories of cookies and similar technologies:

(a) strictly necessary cookies;

(b) security cookies;

(c) functional cookies;

(d) analytics cookies;

(e) advertising cookies;

(f) conversion-tracking technologies;

(g) social-media pixels.

In relation to these technologies:

(h) each category is used for the purpose indicated by its description above;

(i) cookies may be first-party (set by us) or third-party (set by others);

(j) cookies have different duration categories (for example, session cookies that expire when you close your browser, and persistent cookies that remain for a defined period)

(k) optional cookies (such as analytics and advertising cookies) are used only where the applicable legal requirement for consent is met;

(l) you can reject or withdraw consent to optional cookies through our cookie banner or preference centre, where provided;

(m) you can also use browser controls to manage cookies; and

(n) disabling strictly necessary cookies may prevent parts of the website from functioning properly.

Where legally relevant and technically supported, we may recognise Global Privacy Control or similar signals.

Where appropriate, further detail is provided in a separate Cookie Notice. Browser settings alone do not necessarily withdraw consent where affirmative consent mechanisms are legally required.

15. Analytics, advertising and social-media platforms

Analytics and advertising providers may receive identifiers, device information and interaction data when you use our website or interact with our advertising.

(a) Whether MediGoMY uses audience measurement, remarketing or conversion tracking, and which providers.]

(b) These third parties may independently process the data they receive, in accordance with their own privacy notices.

(c) Please do not submit medical details directly into public social-media comments or posts.

(d) Sensitive medical records should only be sent through approved channels that we identify to you, and not through public or unsecured means.

We do not disclose a user’s health condition or other sensitive medical information to advertising platforms for targeted advertising. General analytics and advertising identifiers (which do not reveal your health condition) are used only where the applicable legal requirement for consent is met.

16. Artificial intelligence, automation and profiling

Where used, AI or automated systems may support functions such as:

(a) translation;

(b) document organisation;

(c) enquiry categorisation;

(d) administrative summaries;

(e) hospital matching;

(f) customer support;

(g) marketing analytics.

Any such tools are used for administrative and support purposes. AI is not used to make a medical diagnosis, and we do not describe any AI output as a medical diagnosis, unless a diagnosis is genuinely and lawfully provided by a qualified professional.

Where AI or automated systems are used, we would explain, to the extent applicable:

(h) what data is used;

(i) whether identifiable medical records are submitted to any third-party AI provider.

(j) the extent of human review of any output;

(k) whether any decision produces a material effect, and how that is handled;

(l) your rights in relation to such processing;

(m) the safeguards applied; and

(n) whether any data may be used to train AI models.

17. Direct marketing

Where you have provided the appropriate consent or we otherwise have a lawful basis, we may send you marketing communications through channels such as:

(a) email;

(b) telephone;

(c) SMS;

(d) WhatsApp or similar messaging services;

(e) social-media messaging;

(f) custom advertising audiences.

In relation to direct marketing:

(g) we rely on the applicable consent or lawful basis for the relevant channel;

(h) marketing consent is requested separately from consent for services and medical-data processing;

(i) you can unsubscribe or opt out at any time using the mechanism in the relevant message or the contact details in Section 27;

(j) opting out of marketing does not stop necessary service communications relating to your enquiry or case; and

(k) we may retain a limited suppression record of your opt-out in order to honour your request.

We do not bundle marketing consent with the consent required to receive medical-coordination services.

18. Data retention

We do not apply a single universal retention period. Instead, we retain personal data for as long as reasonably necessary, based on a retention framework that takes into account:

(a) the purpose of collection;

(b) the duration of the patient enquiry or service;

(c) legal and regulatory obligations;

(d) accounting and tax requirements;

(e) limitation periods;

(f) disputes and legal claims;

(g) hospital and insurance requirements;

(h) security-log requirements;

(i) marketing-consent records;

(j) backup cycles;

(k) whether an enquiry was unsuccessful; and

(l) the nature of uploaded medical reports.

The retention periods below are recommended defaults appropriate to a Malaysian medical-coordination platform. The company should confirm each period against its actual legal, accounting and clinical obligations before publication. Where a longer statutory or regulatory period applies, that longer period prevails.

(m) general enquiries: retained for the duration of the enquiry and up to 12 months after the last contact, unless a case is opened (recommended default);

(n) patient case files: retained for the duration of the coordination relationship and thereafter for the statutory limitation period (6 years from the end of the relationship under the Limitation Act 1953) (recommended default);

(o) medical records and uploaded medical documents: retained in line with applicable medical-records retention practice, being not less than 6 years (and, for minors, until the patient reaches the age of majority plus a further period), consistent with recognised medical-records retention standards (recommended default);

(p) financial, tax and accounting records: retained for 7 years to meet accounting and tax obligations (recommended default);

(q) marketing records: retained until you withdraw consent or object, after which a limited suppression record is kept to honour your opt-out (recommended default);

(r) website logs and cookie data: retained for up to 12 months, or the shorter period stated in the Cookie Notice (recommended default);

(s) backups: overwritten on a rolling cycle, with residual backup copies deleted or overwritten within 6 months in the ordinary course (recommended default).

When personal data is no longer required, we seek to delete it securely or to anonymise it. Because of backup and archival cycles, residual copies may persist for a limited period before being overwritten or deleted in the ordinary course.

20. Data breaches

If we become aware of a suspected personal-data breach, we will take steps that may include:

(a) assessing the suspected breach;

(b) taking containment and remediation steps;

(c) documenting the incident;

(d) notifying the Malaysian Personal Data Protection Commissioner where notification is legally required;

(e) notifying affected individuals where notification is legally required; and

(f) coordinating with relevant hospitals and service providers as appropriate.

We do not promise to notify you of every incident; notification is provided where it is legally required or otherwise appropriate.

We do not promise to notify you of every incident; notification is provided where it is legally required or otherwise appropriate.

21. Individual rights

Subject to the PDPA and any other applicable law, you may have rights in relation to your personal data. Depending on the applicable law and circumstances, these may include:

(a) the right to access your personal data;

(b) the right to request correction of inaccurate or incomplete data;

(c) the right to withdraw consent;

(d) the right to prevent processing likely to cause damage or distress, where applicable;

(e) the right to object to direct marketing;

(f) the right to data portability, where applicable;

(g) the right to restriction of, or objection to, processing, where applicable under a relevant law;

(h) the right to deletion, where legally available; and

(i) the right to complain to the relevant regulator (see Section 27).

Some of the rights listed above (for example, data portability, or restriction and objection) may arise under the amended PDPA or under foreign privacy laws where those genuinely apply, and may not be available in every case.

To exercise a right:

(j) submit a request using the contact details in Section 27;

(k) we may need to verify your identity before acting on a request;

(l) authorised-agent or representative requests may require proof of authority;

(m) some requests may be subject to lawful limitations or exemptions;

(n) a fee may apply only where permitted by law;

(o) we will respond within the timeframe required by applicable law. Under the PDPA, we will respond to a data access or correction request within 21 days (which may be extended, with notice to you, where permitted by section 35 of the PDPA). Where a foreign privacy law genuinely applies (for example the GDPR), we will respond without undue delay and in any event within one month of receipt, extendable by up to a further two months for complex or numerous requests, with notice to you (GDPR Article 12(3)); and

(p) some records cannot be deleted because of legal, medical, accounting or dispute-related obligations, including retention obligations of independent hospitals.

22. Children and minors

We recognise that some patients are minors (for example, paediatric cancer patients).

(a) Whether the website is intended for direct use by minors. It is generally intended to be used by adults acting for themselves or on behalf of a patient.]

(b) Where a minor’s personal data is provided, we expect it to be provided by a parent or legal guardian, or with appropriate parent or guardian consent.

(c) We may seek verification of guardianship or authority.

(d) In emergency circumstances, information about a minor may be handled to the extent necessary to protect the minor’s life, health or safety.

(e) The rights of mature minors may apply where recognised by the applicable law.

(f) How a minor patient’s data is handled when the patient reaches the age of majority.]

We do not adopt a single universal age threshold in this policy; the applicable age of majority and any child-consent age must be determined by reference to the applicable law.

23. Emergency situations

Our website, forms and messaging channels are not emergency services and are not monitored for emergencies.

 If you are experiencing a medical emergency, do not rely on our website forms, WhatsApp, email or other channels.

Instead, contact your local emergency services immediately or attend the nearest appropriate healthcare facility.

24. Third-party websites and services

Our website and communications may contain links to, or interactions with, third parties such as hospitals, doctors, social-media platforms, payment providers and others.

Those third parties are governed by their own terms and privacy notices, which we do not control and for which we are not responsible.

This does not remove MediGoMY’s responsibility for its own disclosures of personal data and for its own handling of personal data.

25. Corporate transactions

If MediGoMY is involved in a merger, acquisition, restructuring, investment, sale of assets, insolvency or similar transaction, personal data may be disclosed to, or transferred to, a prospective or actual buyer, investor, successor or their advisers, subject to appropriate confidentiality arrangements and applicable law.

We would seek to ensure that any recipient handles the information consistently with this Privacy Policy and applicable law.

26. Changes to the Privacy Policy

(a) We may update this Privacy Policy from time to time. Updates will be published on our website at [INSERT WEBSITE URL].

(b) We reserve the right to amend this Privacy Policy at any time. Where a change is material, we will take reasonable steps to notify you before it takes effect — for example by posting a prominent notice on our website, updating the effective date, or (where we hold your contact details and it is appropriate) contacting you directly. Where the change materially expands how we use your sensitive medical information and the law requires it, we will seek renewed consent.

(c) Material changes will not be applied retroactively where this is prohibited by applicable law.

(d) The effective date and the “Last updated” date shown at the top of this policy indicate when the policy took effect and when it was last revised.

27. Contact and complaints

If you have questions, requests or complaints about privacy, you can contact us:

(a) Legal company name: AGH GROUP HOLDING SDN. BHD. (trading as MediGoMY)
(b) Registered address: 12A, Jalan 13/4, Seksyen 13, 46200 Petaling Jaya, Selangor

(c) Privacy email: hello@medigomy.com

(d) Telephone: +6016 – 679 3391

(e) Data Protection Officer:NOT YET APPOINTED

To make a privacy complaint, please contact us using the details above, and we will seek to acknowledge and address your complaint.

You also have the right to lodge a complaint with the Malaysian Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi) or another competent regulator.

28. Language

This Privacy Policy is provided in English.

Whether the Malaysian privacy notice is legally required to be provided in Bahasa Malaysia as well as English. The operator should obtain advice on whether a Bahasa Malaysia version is legally required or appropriate, and, if so, arrange a professionally aligned Bahasa Malaysia version that preserves the legal meaning rather than a literal machine translation.]

Any statement as to which language version prevails should be added only after confirming that such a clause is lawful and appropriate.

IMPLEMENTATION MATERIALS

The following materials are for the operator’s internal implementation use only. They are NOT part of the published Privacy Policy and should be removed before, or kept separate from, the version displayed to users. Appendix A consolidates every company-specific detail that must be completed before publication.

Appendix A. Details to be completed before publication

This is the single consolidated list of company-specific facts that must be confirmed and inserted before the policy is published. Each item corresponds to a token that remains in the policy:

(a) legal entity — confirm exact registered company name and status;

(b) company registration number;

(c) registered address;

(d) privacy contact email;

(e) telephone number;

(f) whether a Data Protection Officer is required and, if so, the DPO’s contact details;

(g) whether data-user / data-controller registration with the Malaysian Personal Data Protection Commissioner is required before go-live — this may be a hard prerequisite; the company should obtain legal advice on whether data-user registration under the PDPA is required before go-live;

(h) effective date and last-updated date;

(i) website URL;

(j) actual vendors and service providers;

(k) website-hosting location;

(l) cloud-storage location(s);

(m) the specific countries that will receive medical records (including confirmation of the China arrangements);

(n) actual security controls in place;

(o) actual retention periods for each data category;

(p) cookie tools in use;

(q) analytics and advertising pixels in use;

(r) CRM platform in use;

(s) WhatsApp setup (for example, whether WhatsApp Business is used and how conversations are stored);

(t) call-recording and video-recording practices;

(u) AI tools in use, and whether identifiable medical records are sent to any third-party AI provider or used to train models;

(v) payment processors, and whether MediGoMY stores full card data;

(w) confirm the no-sale / no-health-data-targeted-advertising position stated in Sections 11 and 15 remains accurate for the business (the policy currently states that MediGoMY does not sell personal data and does not share sensitive health data for third-party targeted advertising);

(x) confirm whether users from the EU, UK, China, Singapore or the United States are intentionally targeted (this drives whether the GDPR, Singapore PDPA or US state laws apply, in addition to the Malaysian PDPA);

(y) PIPL note: outbound transfers of personal information FROM China are subject to PIPL and require a separate legal basis and transfer mechanism (for example, a standard contract or certification) that the China-side partner must confirm. This cannot be resolved by placeholders in this policy alone and requires the China-side organisation’s active confirmation.

Residual-risk note (internal). The following company-protective positions have been drafted to the strongest enforceable extent and should be understood with these limits: (i) the limitation-of-liability and security disclaimers (Sections 2 and 19) cannot exclude liability that cannot lawfully be excluded (for example, liability arising from a failure to comply with mandatory PDPA data-protection obligations, fraud, or death or personal injury caused by negligence) — pushing them further would risk the whole clause being held void; (ii) consent for sensitive medical data has been drafted as layered, specific and explicit rather than a single omnibus consent — a broad “one-tick-covers-everything” consent would likely be unenforceable for sensitive data under the PDPA and GDPR Article 9; (iii) the right to amend the policy is subject to a material-change notice mechanism and, where the law requires, renewed consent — a bare right to change terms at will without notice would be unenforceable against data subjects; and (iv) cross-border transfers to China remain dependent on the China-side partner’s PIPL confirmation, which MediGoMY cannot resolve unilaterally.

Appendix B. Website compliance checklist

Practical recommendations for the website and operations:

(a) place a Privacy Policy link in the website footer;

(b) display a short privacy notice beside every form that collects personal data;

(c) include a separate, explicit consent checkbox for the collection and processing of medical data;

(d) include a separate, optional marketing checkbox that is not pre-ticked;

(e) include specific consent wording for cross-border medical-record transfers;

(f) provide a parent or guardian consent mechanism where minors are involved;

(g) provide an authorised-representative declaration for those enquiring on behalf of another person;

(h) implement a cookie banner and a cookie preference centre;

(i) publish a separate Cookie Notice;

(j) maintain a record of consent for each individual and purpose;

(k) implement a documented data-access and deletion request procedure;

(l) ensure medical-record uploads use a secure upload mechanism;

(m) put vendor data-processing agreements in place with processors;

(n) carry out cross-border transfer assessments and documentation;

(o) maintain a data-retention schedule with actual periods;

(p) maintain an incident-response plan;

(q) carry out a DPO assessment (whether appointment is required);

(r) carry out a data-controller / data-user registration assessment;

(s) carry out a Data Protection Impact Assessment (DPIA) where appropriate;

(t) provide staff confidentiality and privacy training.

Appendix C. Form consent clauses

The following are model consent statements for use beside the relevant website forms and checkboxes. Consent to marketing must be kept separate from consent to medical-data processing, and no consent box may be pre-ticked.

1. Medical-data collection and processing

I consent to MediGoMY (AGH GROUP HOLDING SDN. BHD.) collecting and processing my sensitive medical information for the purpose of the healthcare-coordination service I am requesting, as described in the Privacy Policy.

2. Sharing records with hospitals and doctors

I authorise MediGoMY to share my medical records with the hospitals and doctors selected in connection with my enquiry, for the purpose of review, quotation, appointment or treatment coordination.

3. Cross-border transfer

I understand and agree that my medical information may be transferred to hospitals, doctors or service providers outside Malaysia, including in China, where privacy protections may differ from those in Malaysia, as described in the Privacy Policy.

4. Authority to submit another person’s records

I confirm that I am authorised to provide this person’s personal and medical information, that I have provided them with the required privacy information, and that I hold valid consent or other lawful authority to do so.

5. Parent or guardian consent

I confirm that I am the parent or legal guardian of the patient named above, or am otherwise authorised to act for them, and I consent to the processing of their information as described in the Privacy Policy.

6. Optional marketing

(Separate, not pre-ticked)

I would like to receive marketing communications from MediGoMY about services and information. I understand I can opt out at any time.

7. Optional call or video-session recording

(Separate, not pre-ticked)

I consent to MediGoMY recording this call or video session for the purposes described to me. I understand I may decline recording.

Need Help?