1. Introduction
This Privacy Policy explains how Polaris Aura Sdn Bhd (“Company”, “we”, “us”) collects, uses, stores, and shares information when you use SihatOS. For personal data of individuals in Malaysia, we process information in line with the Personal Data Protection Act 2010 (PDPA) where applicable.
2. Roles
- Clinic / business customer: typically the data user/controller of patient, member, and staff data entered into SihatOS.
- Polaris Aura Sdn Bhd: provides the App and acts as a service provider/processor for customer content, and as controller for account, billing, analytics, and support data we collect ourselves.
3. Information we collect
A. Account and business information
Business name, branch details, contact person, phone/email, subscription or demo details, and role/access level.
B. App usage and device information
Device type, OS version, app version, log data, crash diagnostics, IP address, approximate location (if provided by the device/OS), and security events (for example failed PIN attempts).
C. Customer content you enter (processed on your behalf)
Depending on features you use, this may include:
- Member/patient profiles, visits, and appointments
- Clinical notes, body charts, consent records, and MC-related records
- POS transactions, receipts, packages, loyalty, and credit
- Staff attendance, commissions, inventory, reports, and exports
We process this content to operate the Service for your clinic. We do not sell it.
D. Support communications
Messages you send us through email, forms, or other support channels.
4. How we use information
- Provide, secure, maintain, and improve SihatOS
- Authenticate users and enforce access controls (including staff and manager PIN flows)
- Process transactions, receipts, reports, exports, and related features
- Provide customer support and onboarding
- Send service notices (security, downtime, policy updates)
- Comply with law and enforce our Terms
We do not use patient clinical content for advertising.
5. Legal bases / purposes (PDPA-oriented)
We process data where necessary to perform a contract with you, for legitimate business interests (such as security and product improvement), with consent where required, or to comply with legal obligations.
Your clinic is responsible for having a lawful basis to collect patient and staff data and for providing required notices or consents to individuals.
6. Sharing
We may share information with:
- Cloud hosting, storage, email, analytics, or crash-reporting providers under contract
- Payment or messaging providers you choose to use with the App
- Professional advisers or authorities when required by law
- A buyer in a merger or acquisition, with appropriate safeguards
We do not sell personal data.
7. International transfers
Data may be stored or processed on servers in Malaysia and/or other countries used by our hosting providers. Where data is transferred outside Malaysia, we take reasonable steps consistent with PDPA requirements.
8. Retention
- Account and billing data: while your account is active and as needed for legal or accounting retention
- Customer content: retained for the life of your account or per your configuration; deleted or returned within a reasonable period after account closure or request, subject to backups and legal holds
- Logs and security data: kept for a limited period for security and troubleshooting
9. Security
We use reasonable technical and organizational measures (access controls, encryption in transit where applicable, and least-privilege staff access). No method is 100% secure. You must also secure devices, PINs, and staff access.
10. Your rights and choices
Depending on applicable law, individuals may request access, correction, or limitation of their personal data.
- Patients / members: please contact the clinic that holds your record first.
- Clinic admins / staff: contact us via the SihatOS contact form.
You may also request deletion of account data, subject to legal retention needs.
11. Children’s privacy
SihatOS is a business application and is not directed at children. Do not use the App to create accounts for children except as needed for legitimate clinic records under your professional and legal obligations.
12. Health-related data
Some features may involve sensitive personal data (for example clinical notes, consent, or MC). Clinics must restrict access to authorized staff and use these features only for legitimate care and operations purposes.
13. App Store and third-party platforms
Apple App Store and Google Play processing of downloads, payments, and reviews is governed by Apple’s and Google’s policies. We do not control those platforms.
14. Changes
We may update this Policy. We will post the new effective date and, where appropriate, notify you via the App, website, or email.
15. Contact
Polaris Aura Sdn Bhd
Product: SihatOS
Privacy / PDPA contact:
SihatOS contact / demo form
Related: Terms and Conditions