Skip to main content
HSR HSR HealthSync Relationship
Clinics Sign in

Privacy from the foundation

HSR Privacy Notice

Version 2026-08-23

Pre-release notice for the HSR MVP. Malaysian legal and privacy review is required before public launch.

About this notice

HealthSync Relationship (HSR) is a Malaysia-focused platform that helps patients discover participating clinics and request appointments. This notice explains the limited information used by the first HSR release.

Information HSR uses

  • Account information such as your name, normalized email address, password hash, role, and verification status.
  • Minimal patient profile information, currently limited to a display name and optional contact details when that profile feature becomes available.
  • Clinic account and public-directory information, including clinic name, registration number, contact details, address, and listing status.
  • Appointment request time and status. The MVP does not request diagnoses, clinical notes, prescriptions, laboratory results, or detailed medical history.
  • For an accepted remote appointment, the clinic may provide an external Zoom or Google Meet join link. HSR treats the complete link as a credential and stores it using application encryption.
  • Consent evidence including document type, version, acceptance time, limited network information, and a one-way hash of browser information.
  • Security and audit information about important account, appointment, and administrative actions.

Why HSR uses information

HSR uses this information to create and secure accounts, connect patients with the clinic they select, manage appointment-request status, provide protected access to a clinic-managed remote meeting, provide service messages, prevent misuse, and maintain an audit trail.

Access and disclosure

Patients may access only their own account and appointment information. Clinics may access only requests addressed to their clinic. A complete remote-meeting link is shown only to the owning patient and addressed clinic while the remote appointment is accepted. Selecting it opens Zoom or Google Meet, whose own privacy terms and processing apply. HSR does not host, proxy, record, transcribe, or inspect the call. Administrators receive only explicitly granted capabilities. Information may also be processed by approved hosting and email providers where needed to operate HSR.

Security and retention

HSR uses access controls, password hashing, encrypted HTTPS sessions, input validation, audit records, and application encryption for stored meeting links. Complete meeting links are excluded from audit metadata and generic notifications and are removed when the appointment is cancelled or completed. No online service can guarantee absolute security. Final retention, account-closure, export, and deletion procedures must be approved before public launch.

Your choices

You may choose not to create an account. Self-service access, correction, account-closure, and privacy-request processes will be published before public launch. Do not submit real patient or medical information during pre-release testing.

Changes and contact

HSR records the version you acknowledge. A materially changed notice will use a new version and may require a new acknowledgement. A formal privacy contact channel and legally reviewed wording must be published before public launch.