Privacy Policy
Last Updated: August 3, 2026
MINERVA AI TECHNOLOGY (Registration No.: JM0908847-U) ("Company," "we," "us," or "our") operates the software-as-a-service (SaaS) platform FlowingCare hosted at flowingcare.com (the "Platform").
We respect your privacy and are committed to protecting the personal data of our subscribing clinics ("Subscribers" or "Clinics"), their authorized staff, and their patients ("Data Subjects"). This Privacy Policy explains how we collect, use, process, disclose, and safeguard personal data in compliance with the Malaysian Personal Data Protection Act 2010 (PDPA) and applicable data privacy regulations.
1. Roles of the Parties (Data Controller vs. Data Processor)
To ensure clarity regarding medical and patient data privacy:
- The Clinic as Data Controller: The subscribing medical, dental, or general practice clinic ("Subscriber") acts as the Data Controller. The Clinic determines the purpose and means of collecting patient personal data and is solely responsible for obtaining all necessary consent from patients prior to entering their details into FlowingCare.
- Minerva AI Technology as Data Processor: The Company operates solely as a Data Processor. We store and process patient information exclusively under the direction and instruction of the Subscriber for the purpose of generating automated recall schedules and follow-up communications.
2. Information We Collect
We collect information to provide, maintain, and improve our automated patient recall utility. The data collected is strictly categorized as follows:
A. Subscriber Account Data (Clinics & Staff)
When a Clinic registers for a FlowingCare subscription, we collect:
- Clinic Information: Clinic Name, Registration / MMC Number, Official Address, Contact Number, Official Email Address.
- Staff/User Accounts: Usernames, email addresses, and encrypted authentication credentials of staff members authorized to access the Platform.
- Billing Information: Payment transaction history and billing contact details (credit card/banking details are processed securely via third-party PCI-DSS compliant payment gateways and are NOT stored directly on our servers).
B. Patient Recall Data (Minimally Collected)
Subscribers input minimal operational data required to trigger recall reminders. This includes ONLY:
- Patient Name
- Mobile Phone Number (for WhatsApp messaging)
- Recall Item / Category (e.g., "HPV 2nd Dose," "Annual Health Screening," "6-Month Dental Checkup")
- Target Follow-Up Date
C. Strict Disclaimer on Sensitive Medical Records (EMR)
FlowingCare does NOT collect, process, or store full Electronic Medical Records (EMR), detailed clinical diagnosis notes, medical history files, prescription details, or clinical consultation logs. FlowingCare is an operational messaging and communication utility, not an EMR or health record system.
D. Technical & Usage Data
When accessing flowingcare.com, our cloud infrastructure automatically logs standard technical information:
- IP address, browser type, operating system, access timestamps, and page interaction logs.
- Session authentication cookies required to maintain secure user logins.
3. How We Use Your Information
We use the collected personal data strictly for legitimate business and operational purposes:
- Service Delivery: To generate daily recall dashboards, calculate follow-up dates, and enable one-click WhatsApp message routing and email summary notifications.
- Account Management: To manage subscriptions, process invoices, handle customer support inquiries, and verify user authenticity.
- Security & System Maintenance: To monitor system health, prevent fraudulent activity or unauthorized access, and ensure data integrity.
- Legal Compliance: To fulfill statutory accounting, taxation, and legal obligations under Malaysian law.
4. Disclosure & Third-Party Service Providers
We do NOT sell, rent, trade, or monetize any Clinic or Patient data. Personal data may only be disclosed under the following controlled circumstances:
- Essential Infrastructure Providers: We engage trusted third-party cloud service providers to host and run the Platform:
- Cloud Hosting & Database Infrastructure: Cloudflare, Inc. (used for edge network security, API processing, and encrypted serverless database storage).
- Transactional Email Delivery: Third-party transactional email providers (e.g., Resend / Postmark) used exclusively to deliver morning recall summary emails to authorized Clinic staff.
- Payment Processing: Payment gateway providers (e.g., Stripe / FPX Payment Gateways) for processing subscription charges.
- Legal & Regulatory Obligations: We may disclose data if required by Malaysian law, court orders, law enforcement requests, or statutory authorities enforcing the PDPA.
- Business Transfers: In the event of a merger, acquisition, or sale of company assets, subscriber account data may be transferred as part of business assets, subject to the buyer agreeing to honor this Privacy Policy.
5. Data Security & Storage
We implement industry-standard administrative, physical, and technical security safeguards to protect personal data:
- Encryption: Data in transit is encrypted using HTTPS / TLS 1.3 encryption. Data stored within our database infrastructure (Cloudflare D1/KV) is encrypted at rest.
- Access Controls: Strict role-based access controls (RBAC) ensure that authorized Clinic staff can only view and access their own Clinic's patient records.
- Minimalist Data Footprint: By deliberately refraining from storing complex medical history, we minimize privacy risk exposure for both Clinics and Patients.
6. Data Retention & Deletion
- Active Subscriptions: Patient Recall Data is retained for as long as the Subscriber maintains an active paid account with FlowingCare.
- Account Cancellation / Termination: Upon subscription termination or cancellation, Subscriber account data and associated Patient Recall Data will be retained for a grace period of thirty (30) calendar days, after which all patient recall records will be permanently purged from our primary active databases.
- Manual Data Deletion: Subscribers may manually delete individual patient entries from their FlowingCare dashboard at any time.
7. Patient Rights & PDPA Compliance
Under the Malaysian Personal Data Protection Act 2010 (PDPA):
- Data Subject Rights: Patients (Data Subjects) have the right to request access to, correction of, or withdrawal of consent for their personal data.
- Routing of Requests: Because FlowingCare acts as a Data Processor, any patient inquiries or opt-out requests received directly by the Company will be forwarded to the respective Subscriber Clinic (Data Controller) to process.
- Opt-Out Mechanism: Patients who do not wish to receive follow-up messages may inform their Clinic directly, or reply to any WhatsApp message requesting removal, upon which the Clinic staff can remove their profile from the Platform.
8. Cookies and Tracking Technologies
FlowingCare uses essential first-party session cookies and local storage to keep users logged in and store session preferences. We do NOT use third-party cross-site tracking cookies or invasive advertising trackers.
9. International Data Transfers
Our platform leverages global cloud infrastructure (such as Cloudflare) to ensure uptime, speed, and reliability. Where personal data is processed through edge servers located outside of Malaysia, we ensure that the cloud infrastructure provider enforces security and privacy standards at least equivalent to those required under the Malaysian PDPA.
10. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy from time to time to reflect changes in legal requirements, operational workflows, or platform features. Any updates will be published on flowingcare.com/privacy with a revised "Last Updated" date. Continued use of the Platform after such changes constitutes acceptance of the revised policy.
11. Contact Us / Data Protection Enquiries
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Coordinator:
MINERVA AI TECHNOLOGY (Registration No.: JM0908847-U)
Operating Platform: FlowingCare (flowingcare.com)
Email: privacy@flowingcare.com / support@flowingcare.com
Location: Malaysia