Privacy Policy
This Privacy Policy explains how Kenneth Tan Medical Clinic ("we", "us") handles personal data in the GP Clinic Toolkit ("the Service"), in line with Singapore's Personal Data Protection Act 2012 (PDPA).
The data we handle
For each subscribing clinic we process limited staff personal data on the clinic's behalf:
- Account data — name, work email, role, and a hashed (never plaintext) password.
- Training records — which SOPs a staff member has read and acknowledged, quiz attempts and scores, and any remedial notes.
- Audit logs — a tamper-evident record of training and administrative actions (who did what, when).
- Clinic profile — clinic name, licence number, and the names of the Principal Officer / Clinical Governance Officer, used to personalise documents.
- Billing data — handled by our payment processor (Stripe); we do not store card numbers.
- Technical logs — basic security and diagnostic logs.
We do not collect patient or clinical health records. The Service is not designed to store patient data.
Why we handle it
To provide the Service: managing accounts and access, recording training and competency as compliance evidence, processing subscriptions, securing the platform, and providing support.
Roles under the PDPA
For staff data entered by a clinic, the clinic owns that data (as the employer) and we act as a data intermediary processing it on the clinic's instructions. For our own account and billing records, we are the organisation responsible.
Who we share it with
- Service providers acting on our behalf: Stripe (payments), [CONFIRM: Resend] (transactional email), and our hosting provider ([CONFIRM: DigitalOcean]).
- Legal: where required by law or to protect rights and safety.
We do not sell personal data.
Where data is stored
The Service is hosted in [CONFIRM: Singapore]. Where a provider processes data outside Singapore, we take the steps required by the PDPA to ensure comparable protection.
How long we keep it
We keep account and training / audit records while the subscription is active and for [CONFIRM: period] afterwards to support compliance evidence, then delete or anonymise them. A clinic can request export or deletion of its data.
How we protect it
Encryption in transit (HTTPS), hashed passwords, role-based access controls, a tamper-evident audit trail, regular backups, and security hardening. No system is perfectly secure, but we take reasonable measures appropriate to the data.
Your rights
Subject to the PDPA, individuals may request access to or correction of their personal data, and may ask questions or make a complaint. Staff should contact their clinic administrator first; clinics can contact us at [CONFIRM: DPO email].
Cookies
We use a single essential session cookie to keep you logged in. We do not use advertising or third-party tracking cookies.
Changes
We may update this Policy; material changes will be notified through the Service or by email.
Contact
Data Protection Officer, Kenneth Tan Medical Clinic — [CONFIRM: dpo@…].
Last updated 3 June 2026 · pre-launch draft, pending legal review.