Three commitments, in plain language.
We never sell your health or genetic data. We never share it with insurers or employers unless you personally instruct us to. And we never send health, biomarker or genetic data to an advertising or analytics platform.
Everything below explains how we keep to that.
01Scope and who is responsible
This Privacy Policy explains how Protocol Health Pte Ltd, a company incorporated in Singapore (UEN 202349035M), operating a medical clinic licensed by the Ministry of Health under the Healthcare Services Act 2020, licence number R/24M1418/MDS/001/242, at 71 Robinson Road #01-02, Singapore 068895 ("PROTOCOL", "we", "us") collects, uses, discloses and protects your personal data.
It covers our website, our member dashboard, our clinic, our messaging channels and every service we provide. We handle personal data in accordance with the Personal Data Protection Act 2012 (PDPA) and, for medical records, the Healthcare Services Act and its regulations.
We hold health data and, for some members, genetic data. That is among the most sensitive information a person can share. We treat it accordingly.
02Our Data Protection Officer
Our Data Protection Officer is responsible for how we handle your data and is your point of contact for any question, request or complaint.
03What we collect
Identity and contact
Name, date of birth, sex, NRIC or FIN or passport number, nationality, address, email address and phone number. We collect NRIC or FIN because it is required to identify you correctly across laboratory and medical records.
Health data
Medical history, medications, allergies, family history, symptoms, lifestyle information, consultation notes, blood biomarker results, body composition measurements, imaging results, prescriptions and treatment records.
Genetic data
Where you order a genetic test, the genetic results and any counselling records associated with them.
Payment data
Billing details and transaction records. Full card numbers are handled by our payment providers and are not stored on our systems.
Usage and device data
How you use our website and dashboard, including pages viewed, device and browser type, IP address, referral source and advertising identifiers. See section 12.
Communications
Messages you send us by email, WhatsApp, web chat or phone, and our replies.
04How we collect it
We collect personal data:
- Directly from you, when you book, register, complete an intake form, attend a consultation, or message us
- From our laboratory and clinical partners, when they return your results to us
- Automatically from your device when you use our website or dashboard
- From third parties you have authorised, such as another clinic or laboratory whose historical results you ask us to import
- From publicly available sources or referrers, where you were introduced to us through a referral programme
Where consent is required, we ask for it. In some cases the PDPA allows us to rely on deemed consent, for example when you voluntarily provide information for a service you have requested, or on legitimate interests and legal obligations.
05Why we use it
| Purpose | What that means in practice |
|---|---|
| Providing care | Assessing you, ordering and interpreting tests, prescribing, and managing your treatment over time. |
| Your record | Maintaining an accurate medical record and showing your results and trends in your dashboard. |
| Communication | Appointment reminders, result notifications, follow ups and answering your questions. |
| Payment | Processing payments, renewals and refunds, and keeping accounting records. |
| Safety and quality | Clinical governance, internal audit, incident review and improving our protocols. |
| Legal obligations | Meeting our obligations under Singapore healthcare, tax and other laws, including any notifiable disease reporting. |
| Product improvement | Understanding how our services are used so we can improve them. We use aggregated or de identified data for this wherever possible. |
| Marketing | Sending you content and offers, where you have consented. See section 13. |
06Health and genetic data
Health and genetic data receive additional protection at PROTOCOL.
We do not sell your health or genetic data. We do not share it with insurers, employers, or anyone assessing you for coverage, employment or credit, unless you personally and explicitly instruct us in writing to release it to a named recipient.
Access within PROTOCOL is limited to the clinicians and staff who need it to provide your care, and is logged.
Where we use data to improve our services or to study patterns across our members, we use aggregated or de identified data that cannot reasonably be linked back to you.
08Transfers outside Singapore
Some of our service providers process data outside Singapore. Where personal data is transferred overseas, we take steps required under the PDPA to ensure the recipient provides a standard of protection comparable to Singapore law, through contractual commitments or equivalent safeguards.
You may ask our DPO for information about the safeguards applying to a specific transfer.
09How long we keep it
We keep personal data only as long as we need it for the purposes described here, or as required by law.
| Data | Retention |
|---|---|
| Medical records for adults | At least 6 years from the last entry, in line with Singapore healthcare record keeping requirements. |
| Medical records for patients treated as minors | Retained for the longer period required by law after they reach adulthood. |
| Financial and transaction records | At least 5 years, in line with tax and accounting requirements. |
| Marketing preferences | Until you withdraw consent, plus a suppression record so we do not contact you again in error. |
| Website analytics | Typically up to 26 months, depending on the platform. |
When data is no longer needed for a legal or business purpose, we securely delete or anonymise it.
10How we protect it
Our safeguards include:
- Encryption of data in transit and at rest
- Role based access controls, so staff see only what their role requires
- Access logging and periodic review
- Multi factor authentication on administrative systems
- Contractual data protection obligations on every vendor that touches personal data
- Staff training on confidentiality and data handling
- An incident response process, including notifying you and the PDPC where a breach is notifiable
No system is perfectly secure. Please help us by keeping your password unique, not sharing your login, and telling us immediately if you think your account has been accessed by someone else.
11Your rights
Under the PDPA you may:
- Access the personal data we hold about you, and information about how it has been used or disclosed in the past year
- Correct data that is inaccurate or incomplete
- Withdraw consent for any purpose that relies on your consent, including marketing
- Request a copy of your medical record and results, in a readable format
To make a request, contact our DPO using the details in section 2. We will respond as soon as reasonably possible and normally within 30 days. Where we cannot meet that timeline we will tell you when to expect a response.
We may need to verify your identity before releasing data. A reasonable fee may apply to access requests, and we will tell you before any fee is incurred.
Withdrawing consent has consequences. If you withdraw consent for us to process the health data required to provide your care, we may no longer be able to provide that care. We will explain the likely consequences before acting on a withdrawal request. We will still retain records we are legally required to keep.
12Cookies, analytics and advertising
Our website uses cookies and similar technologies to make the site work, remember your preferences, measure performance and measure the effectiveness of our advertising.
| Type | Purpose |
|---|---|
| Strictly necessary | Sign in, checkout, security and site functionality. These cannot be switched off. |
| Analytics | Understanding how people find and use the site so we can improve it. |
| Advertising | Measuring which campaigns lead to enquiries and purchases, and showing relevant ads. |
We use server side tracking for some measurement. Where we share conversion signals with advertising platforms, those signals are limited to commercial events such as a purchase or an enquiry. We never send health, biomarker, genetic or diagnosis data to an analytics or advertising platform.
You can control cookies through your browser settings, and opt out of advertising personalisation through the settings of the platforms concerned. Blocking strictly necessary cookies will stop parts of the site from working.
Our member dashboard is excluded from advertising tracking.
13Marketing and messaging
We send marketing email only where you have consented, and every marketing email carries an unsubscribe link that works immediately.
Service messages are different from marketing. Appointment reminders, result notifications, renewal notices and safety information relate to the care you have bought from us, so we send them regardless of your marketing preferences.
We use WhatsApp for care team conversations. If you message us there, we hold that conversation as part of your record. WhatsApp is convenient but it is a third party platform, so please do not send anything you would not want held there. Our marketing messages respect the Do Not Call Registry.
14Children
Our services are for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact our DPO and we will delete it, subject to any legal retention obligation.
15Changes to this policy
We may update this policy as our services, our partners or the law change. The current version is always published here with its effective date.
Where a change materially affects how we use your personal data, we will notify you by email before it takes effect.
16Contact and complaints
For any question or request about your personal data, contact our Data Protection Officer, Fern Lee, at fern@protocolhealth.sg, or email hello@protocolhealth.sg.
If you are not satisfied with how we have handled your concern, you may complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.
Protocol Health Pte Ltd (UEN 202349035M)
MOH licence no. R/24M1418/MDS/001/242
71 Robinson Road #01-02, Singapore 068895
This policy sits alongside our Terms & Conditions. Where the two conflict on the handling of personal data, this policy governs.
Last updated 28 July 2026. Protocol Health Pte Ltd, 71 Robinson Road #01-02, Singapore 068895.
Back to top ↑