Legal

Privacy Policy

We hold your blood results, your medical history and, for some members, your genome. This explains exactly what we do with it.

Effective 28 July 2026PDPA compliantProtocol Health Pte Ltd

Three commitments, in plain language.

We never sell your health or genetic data. We never share it with insurers or employers unless you personally instruct us to. And we never send health, biomarker or genetic data to an advertising or analytics platform.

Everything below explains how we keep to that.

01Scope and who is responsible

This Privacy Policy explains how Protocol Health Pte Ltd, a company incorporated in Singapore (UEN 202349035M), operating a medical clinic licensed by the Ministry of Health under the Healthcare Services Act 2020, licence number R/24M1418/MDS/001/242, at 71 Robinson Road #01-02, Singapore 068895 ("PROTOCOL", "we", "us") collects, uses, discloses and protects your personal data.

It covers our website, our member dashboard, our clinic, our messaging channels and every service we provide. We handle personal data in accordance with the Personal Data Protection Act 2012 (PDPA) and, for medical records, the Healthcare Services Act and its regulations.

We hold health data and, for some members, genetic data. That is among the most sensitive information a person can share. We treat it accordingly.

02Our Data Protection Officer

Our Data Protection Officer is responsible for how we handle your data and is your point of contact for any question, request or complaint.

NameFern Lee
PostData Protection Officer, Protocol Health Pte Ltd, 71 Robinson Road #01-02, Singapore 068895

03What we collect

Identity and contact

Name, date of birth, sex, NRIC or FIN or passport number, nationality, address, email address and phone number. We collect NRIC or FIN because it is required to identify you correctly across laboratory and medical records.

Health data

Medical history, medications, allergies, family history, symptoms, lifestyle information, consultation notes, blood biomarker results, body composition measurements, imaging results, prescriptions and treatment records.

Genetic data

Where you order a genetic test, the genetic results and any counselling records associated with them.

Payment data

Billing details and transaction records. Full card numbers are handled by our payment providers and are not stored on our systems.

Usage and device data

How you use our website and dashboard, including pages viewed, device and browser type, IP address, referral source and advertising identifiers. See section 12.

Communications

Messages you send us by email, WhatsApp, web chat or phone, and our replies.

04How we collect it

We collect personal data:

  • Directly from you, when you book, register, complete an intake form, attend a consultation, or message us
  • From our laboratory and clinical partners, when they return your results to us
  • Automatically from your device when you use our website or dashboard
  • From third parties you have authorised, such as another clinic or laboratory whose historical results you ask us to import
  • From publicly available sources or referrers, where you were introduced to us through a referral programme

Where consent is required, we ask for it. In some cases the PDPA allows us to rely on deemed consent, for example when you voluntarily provide information for a service you have requested, or on legitimate interests and legal obligations.

05Why we use it

PurposeWhat that means in practice
Providing careAssessing you, ordering and interpreting tests, prescribing, and managing your treatment over time.
Your recordMaintaining an accurate medical record and showing your results and trends in your dashboard.
CommunicationAppointment reminders, result notifications, follow ups and answering your questions.
PaymentProcessing payments, renewals and refunds, and keeping accounting records.
Safety and qualityClinical governance, internal audit, incident review and improving our protocols.
Legal obligationsMeeting our obligations under Singapore healthcare, tax and other laws, including any notifiable disease reporting.
Product improvementUnderstanding how our services are used so we can improve them. We use aggregated or de identified data for this wherever possible.
MarketingSending you content and offers, where you have consented. See section 13.

06Health and genetic data

Health and genetic data receive additional protection at PROTOCOL.

We do not sell your health or genetic data. We do not share it with insurers, employers, or anyone assessing you for coverage, employment or credit, unless you personally and explicitly instruct us in writing to release it to a named recipient.

Access within PROTOCOL is limited to the clinicians and staff who need it to provide your care, and is logged.

Where we use data to improve our services or to study patterns across our members, we use aggregated or de identified data that cannot reasonably be linked back to you.

07Who we share it with

We share personal data only where it is necessary, and only with parties bound by confidentiality and data protection obligations.

CategoryWhy
Diagnostic laboratoriesTo process your samples and return analytical results.
Genetic testing partnersTo process genetic samples, produce reports and provide counselling where required.
Imaging and specialist providersTo perform scans or specialist assessments you have ordered.
Payment providersTo take payment and manage subscriptions and refunds.
Ecommerce and website platformsTo operate our store, checkout and website.
Messaging and CRM providersTo manage WhatsApp and email conversations with our care team.
Email marketing platformTo send newsletters and updates where you have consented.
Analytics and advertising platformsTo measure website and campaign performance. Health and genetic data is never shared with these platforms.
Cloud hosting and IT providersTo host and secure our systems.
Professional advisers and regulatorsWhere required by law, by a court, or by a regulator such as the Ministry of Health.

We may also disclose data where it is necessary to protect your life or safety, or the safety of others, and where we cannot obtain consent in time.

08Transfers outside Singapore

Some of our service providers process data outside Singapore. Where personal data is transferred overseas, we take steps required under the PDPA to ensure the recipient provides a standard of protection comparable to Singapore law, through contractual commitments or equivalent safeguards.

You may ask our DPO for information about the safeguards applying to a specific transfer.

09How long we keep it

We keep personal data only as long as we need it for the purposes described here, or as required by law.

DataRetention
Medical records for adultsAt least 6 years from the last entry, in line with Singapore healthcare record keeping requirements.
Medical records for patients treated as minorsRetained for the longer period required by law after they reach adulthood.
Financial and transaction recordsAt least 5 years, in line with tax and accounting requirements.
Marketing preferencesUntil you withdraw consent, plus a suppression record so we do not contact you again in error.
Website analyticsTypically up to 26 months, depending on the platform.

When data is no longer needed for a legal or business purpose, we securely delete or anonymise it.

10How we protect it

Our safeguards include:

  • Encryption of data in transit and at rest
  • Role based access controls, so staff see only what their role requires
  • Access logging and periodic review
  • Multi factor authentication on administrative systems
  • Contractual data protection obligations on every vendor that touches personal data
  • Staff training on confidentiality and data handling
  • An incident response process, including notifying you and the PDPC where a breach is notifiable

No system is perfectly secure. Please help us by keeping your password unique, not sharing your login, and telling us immediately if you think your account has been accessed by someone else.

11Your rights

Under the PDPA you may:

  • Access the personal data we hold about you, and information about how it has been used or disclosed in the past year
  • Correct data that is inaccurate or incomplete
  • Withdraw consent for any purpose that relies on your consent, including marketing
  • Request a copy of your medical record and results, in a readable format

To make a request, contact our DPO using the details in section 2. We will respond as soon as reasonably possible and normally within 30 days. Where we cannot meet that timeline we will tell you when to expect a response.

We may need to verify your identity before releasing data. A reasonable fee may apply to access requests, and we will tell you before any fee is incurred.

Withdrawing consent has consequences. If you withdraw consent for us to process the health data required to provide your care, we may no longer be able to provide that care. We will explain the likely consequences before acting on a withdrawal request. We will still retain records we are legally required to keep.

12Cookies, analytics and advertising

Our website uses cookies and similar technologies to make the site work, remember your preferences, measure performance and measure the effectiveness of our advertising.

TypePurpose
Strictly necessarySign in, checkout, security and site functionality. These cannot be switched off.
AnalyticsUnderstanding how people find and use the site so we can improve it.
AdvertisingMeasuring which campaigns lead to enquiries and purchases, and showing relevant ads.

We use server side tracking for some measurement. Where we share conversion signals with advertising platforms, those signals are limited to commercial events such as a purchase or an enquiry. We never send health, biomarker, genetic or diagnosis data to an analytics or advertising platform.

You can control cookies through your browser settings, and opt out of advertising personalisation through the settings of the platforms concerned. Blocking strictly necessary cookies will stop parts of the site from working.

Our member dashboard is excluded from advertising tracking.

13Marketing and messaging

We send marketing email only where you have consented, and every marketing email carries an unsubscribe link that works immediately.

Service messages are different from marketing. Appointment reminders, result notifications, renewal notices and safety information relate to the care you have bought from us, so we send them regardless of your marketing preferences.

We use WhatsApp for care team conversations. If you message us there, we hold that conversation as part of your record. WhatsApp is convenient but it is a third party platform, so please do not send anything you would not want held there. Our marketing messages respect the Do Not Call Registry.

14Children

Our services are for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact our DPO and we will delete it, subject to any legal retention obligation.

15Changes to this policy

We may update this policy as our services, our partners or the law change. The current version is always published here with its effective date.

Where a change materially affects how we use your personal data, we will notify you by email before it takes effect.

16Contact and complaints

For any question or request about your personal data, contact our Data Protection Officer, Fern Lee, at fern@protocolhealth.sg, or email hello@protocolhealth.sg.

If you are not satisfied with how we have handled your concern, you may complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.

Protocol Health Pte Ltd (UEN 202349035M)
MOH licence no. R/24M1418/MDS/001/242
71 Robinson Road #01-02, Singapore 068895

This policy sits alongside our Terms & Conditions. Where the two conflict on the handling of personal data, this policy governs.

Last updated 28 July 2026. Protocol Health Pte Ltd, 71 Robinson Road #01-02, Singapore 068895.

Back to top ↑