Legal Document
Privacy Policy
Last updated: 1 August 2026 · Effective immediately upon publication · Supersedes all prior versions
1. INTRODUCTION AND IDENTIFICATION OF DATA CONTROLLER
This Privacy Policy ("Policy") is issued by Smile Creator Sdn Bhd (Company No. [Registration Number]), a private limited company duly incorporated under the laws of Malaysia and having its registered office in Malaysia ("the Company", "we", "us", or "our"), which operates the HexaOS clinic management platform ("Platform"). This Policy governs the collection, processing, storage, use, disclosure, and deletion of Personal Data (as defined herein) in connection with the use of the Platform, and is issued pursuant to the requirements of the Personal Data Protection Act 2010 of Malaysia ("PDPA 2010") and all subsidiary legislation and guidelines issued thereunder.
By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the terms of this Policy. If you do not agree to this Policy, you must immediately cease use of the Platform and notify the Company in writing of your withdrawal of consent.
2. DEFINITIONS
For the purposes of this Policy, the following definitions shall apply: "Personal Data" means any information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information or from that and other information in the possession of a data user, including any sensitive personal data and expression of opinion about the data subject. "Data Subject" means any individual whose Personal Data is processed by or on behalf of the Company. "Processing" means collecting, recording, holding, or storing Personal Data or carrying out any operation or set of operations on Personal Data, including organising, adapting, altering, retrieving, combining, transmitting, erasing, or destroying. "Subscriber" means any clinic, clinic owner, or authorised clinic staff accessing the Platform pursuant to a valid subscription agreement.
3. CATEGORIES OF PERSONAL DATA COLLECTED
The Company collects and processes the following categories of Personal Data in the course of providing the Platform: (a) identification and contact information, including full legal names, electronic mail addresses, telephone numbers, and the designated role of personnel within a Subscriber's clinic (including but not limited to Owner, Doctor, and Front Desk designations); (b) commercial and organisational information pertaining to Subscriber clinics, including clinic names, branch locations, and subscription and billing details; (c) patient-related clinical data entered by authorised clinic staff, including appointment records, medical and clinical notes, treatment histories, billing records, and other clinical documentation input into the Platform by Subscriber personnel; (d) communications data processed through the Meta WhatsApp Business Cloud API, including message content transmitted between Subscriber clinics and their patients via the Platform's integrated messaging functionality; and (e) technical and usage data, including but not limited to server log files, Internet Protocol ("IP") addresses, device identifiers, browser type and version, operating system information, and Platform feature usage data, collected for the purposes of Platform performance monitoring, error detection, and service improvement.
4. PURPOSES OF PROCESSING
The Company processes Personal Data for the following purposes, each of which constitutes a lawful basis for processing under the PDPA 2010: (a) the performance of contractual obligations owed to Subscribers, including the provision and operation of the Platform and its constituent features; (b) enabling appointment scheduling, patient record management, billing administration, and associated clinical workflow functions; (c) facilitating patient communications via the WhatsApp Business API on behalf of Subscribers; (d) processing subscription payments and administering Subscriber accounts; (e) monitoring Platform performance and remediating errors through third-party error monitoring services; (f) communicating product updates, security advisories, and responses to support enquiries; and (g) compliance with all applicable statutory and regulatory obligations under the laws of Malaysia, including but not limited to the PDPA 2010, the Companies Act 2016, and all applicable taxation legislation.
5. WHATSAPP BUSINESS API INTEGRATION
The Platform integrates with the Meta WhatsApp Business Cloud API ("WhatsApp API") for the purpose of enabling Subscriber clinics to communicate with their patients. The Company hereby discloses the following in connection with such integration: all message content transmitted via the WhatsApp API is processed through Meta Platforms, Inc.'s ("Meta") infrastructure and is subject to Meta's applicable Privacy Policy and Terms of Service, as amended from time to time; message data, including transmitted message content and delivery status metadata, is retained by the Company in its database systems for the purpose of providing message history functionality and audit trail records within the Platform; the Company does not sell, transfer, or otherwise disclose WhatsApp message data to any third party other than as set out in Section 7 of this Policy; and Subscribers are solely responsible for obtaining all necessary consents from patients prior to initiating WhatsApp communications and for ensuring ongoing compliance with Meta's WhatsApp Business Policy.
6. DATA DELETION AND SUBJECT ACCESS REQUESTS
Data Subjects and Subscribers who wish to exercise their right to erasure of Personal Data may submit a written request to the Company at hello@hexaos.ai, with the subject line "Data Deletion Request". Such requests must include the Data Subject's full name, registered electronic mail address, and the name of the Subscriber clinic with which the Data Subject is associated. The Company shall acknowledge receipt of all valid requests within seven (7) business days and shall complete processing of the request within thirty (30) calendar days of receipt, provided that such deletion is not precluded by applicable law.
Data Subjects who have connected a Facebook or Meta account to the Platform and wish to request deletion of associated data must submit a separate written request to hello@hexaos.ai with the subject line "Facebook Data Deletion Request", together with their Facebook User ID and registered electronic mail address. The Company shall delete all associated Personal Data from its systems within thirty (30) calendar days of receipt of a valid request and shall provide written confirmation to the Data Subject upon completion.
Notwithstanding the foregoing, the Company reserves the right to retain Personal Data where such retention is required or permitted by applicable law, including but not limited to financial records subject to retention obligations under Malaysian taxation and company law. In such cases, the Company shall inform the Data Subject of the categories of data retained and the legal basis for such retention at the time of responding to the deletion request.
7. DISCLOSURE TO THIRD PARTIES
The Company discloses Personal Data to the following categories of third-party service providers only to the extent necessary for the provision of the Platform: Meta Platforms, Inc. (WhatsApp Business Cloud API), for the purpose of facilitating patient messaging on behalf of Subscriber clinics, pursuant to which message content and patient telephone numbers may be transmitted; Supabase, Inc., which provides the Platform's primary database and backend hosting infrastructure, pursuant to which all Platform data is stored and processed; Sentry, Inc., which provides error monitoring services, pursuant to which anonymised technical error log data may be transmitted; and Amazon Web Services, Inc. (via Supabase), which provides the underlying cloud infrastructure, pursuant to which encrypted at-rest data is stored. The Company does not sell, rent, or otherwise transfer Personal Data to advertisers, data brokers, or other third parties for commercial purposes.
8. DATA SECURITY MEASURES
The Company implements and maintains the following technical and organisational security measures in connection with the processing of Personal Data: all Personal Data is stored on Supabase-managed PostgreSQL database infrastructure with row-level security ("RLS") controls enabled, such that each Subscriber may only access data attributable to its own clinic; all API access tokens, secret credentials, and sensitive authentication materials are processed exclusively server-side and are not exposed to client-side application code; all Personal Data is encrypted at rest using AES-256 encryption and in transit using Transport Layer Security ("TLS") version 1.2 or higher; all write operations performed within the Platform are recorded in audit log systems with timestamping and user attribution; and access to Platform functionality is governed by a role-based access control ("RBAC") system scoped by Subscriber role designation and branch assignment.
9. DATA SUBJECTS' RIGHTS UNDER THE PDPA 2010
Pursuant to the PDPA 2010, Data Subjects have the right to: (a) request access to Personal Data held by the Company in connection with the Data Subject; (b) request correction of any Personal Data that is inaccurate, incomplete, misleading, or not up-to-date; (c) withdraw consent to the processing of Personal Data, subject to the existence of any overriding statutory or contractual obligations; and (d) request the erasure of Personal Data in accordance with the procedures set out in Section 6 of this Policy. All requests to exercise the foregoing rights should be directed in writing to hello@hexaos.ai. The Company shall respond to all valid requests within twenty-one (21) calendar days of receipt.
10. CONTACT AND ENQUIRIES
All enquiries, complaints, and correspondence relating to this Policy or the Company's data processing activities should be directed to the Data Protection Officer of Smile Creator Sdn Bhd by electronic mail at hello@hexaos.ai. The Company shall acknowledge all enquiries within seven (7) business days. This Policy was last reviewed and updated on 1 August 2026 and supersedes all prior privacy notices and policies published by the Company in connection with the Platform.
