Privacy
DATA PROTECTION POLICY (Also known as ‘PRIVACY POLICY)
Last Updated: 7 Aug 2026
- About this Policy
This Data Protection Policy (“Policy“) explains how Minmed Group Pte Ltd (“we“, “us“, “our“) collects, uses, discloses, processes and protects the Personal Data of our Customers, in accordance with the Personal Data Protection Act (“PDPA“).
It applies to Personal Data in our possession or under our control, including Personal Data held by organisations we have engaged to handle Personal Data on our behalf.
This Policy applies together with any other policies, contractual terms and consent clauses that govern how we handle your Personal Data.
- Definitions
“Services” means any health, wellness, lifestyle, support or care-related services, programmes, facilities, products or digital services that we provide, operate or arrange.
“Customer” means an individual who has contacted us to find out about our Services, or who uses, has used, or may receive any of our Services, whether directly or through another person or organisation.
“Personal Data” means any information, whether true or not, from which you can be identified, either on its own or together with other information we have or are likely to have access to.
“Authorised Representative” means a person or organisation authorised by you, or under applicable law, to provide your Personal Data to us or to act on your behalf. Where a Customer is a minor or otherwise unable to give consent, a parent, legal guardian or other person authorised under applicable law may act as the Authorised Representative. This includes a school or organisation acting with parental authorisation.
- What Personal Data we collect
Depending on how you interact with us, we may collect:
- your name, identification details and contact details;
- demographic and employment information;
- appointment and participation information;
- payment information;
- health, wellness and care-related information;
- medical, counselling, assessment and service records;
- photographs or recordings;
- emergency contact information; and
- other information reasonably required to provide or administer our Services.
We collect your NRIC or FIN where this is required under healthcare regulations, or where it is necessary to identify you accurately for the purposes of your care and records.
- How we collect Personal Data and obtain consent
We generally collect your Personal Data only where:
- you or your Authorised Representative provide it to us voluntarily, after being told what it will be used for and giving consent where consent is required; or
- collection and use without consent is permitted or required under the PDPA or other applicable laws.
If we want to collect additional Personal Data, or use your Personal Data for a purpose we have not told you about, we will seek your consent first, unless the law permits or requires us to proceed without it.
If you provide us with Personal Data about another individual, please make sure you are authorised to do so and that, where required, the individual has been told how their Personal Data will be collected, used and disclosed.
- How we use your Personal Data
We may use your Personal Data for any of the following purposes:
- Providing and improving our Services, such as assessing and responding to your needs, managing appointments or participation, maintaining appropriate records, and supporting your safety, wellbeing and continuity of care.
- Communicating with you and, where appropriate, your Authorised Representative, caregiver or emergency contact, in connection with our Services.
- Coordinating your care with relevant business units, professionals, facilities, service providers, programme partners, and governmental or regulatory authorities.
- Sharing service-related information with a person or organisation arranging, funding or supporting your receipt of the Services (such as an employer or insurer) where you have authorised this, or where it is permitted or required by law.
- Processing payments and claims, including credit transactions, insurance, government healthcare schemes and corporate claims.
- Handling your queries, requests, applications, complaints and feedback.
- Sending you updates about our marketing events, initiatives and Service updates.
- Meeting our legal obligations, including compliance with applicable laws, regulations, codes of practice, guidelines and rules, and assisting law enforcement or investigations by governmental or regulatory authorities.
- Conducting analytics, research and service evaluation to understand how our Services are used, improve operational efficiency and quality, manage risks, and develop or enhance our Services, using anonymised or aggregated data where reasonably practicable.
- Using automated technologies, including artificial intelligence, to support the provision, administration, security, evaluation and improvement of our Services, subject to appropriate safeguards and human oversight where appropriate.
- Any other purpose for which you provided the information, or any related incidental business purpose.
These purposes may continue to apply for a reasonable period after your relationship with us ends or changes, including, where applicable, for as long as we need to enforce our rights under a contract with you.
- Who we share your Personal Data with
We may disclose your Personal Data:
- where it is reasonably necessary to provide, administer or support the Services you use or receive;
- to professionals, service providers, agents, programme partners, facilities and other organisations we have engaged to provide, administer or support the Services, or to carry out the purposes described in this Policy; or
- to a bona fide law enforcement agency, or any governmental or authorised agency responsible for public safety or security, in the performance of their functions as required by law.
Where the Personal Data concerns confidential health, counselling or care information, we limit disclosure to what you have authorised, what is reasonably necessary for the relevant purpose, or what is permitted or required by law.
- Our websites and applications
To help us improve our Services, we use tools that analyse traffic patterns and usage on the Minmed websites and applications. We do not use these tools to identify you by name, but they may collect technical details about your device, such as hardware model, operating system version, browser type and version, IP address, advertising and application identifiers, unique device identifiers, language settings, and wireless or mobile network information.
You can configure your browser to notify you when cookies are received, and choose whether to accept or reject them.
- Marketing communications
From time to time, we may send you news, information and updates about our Services and related activities by post, email or SMS.
To stop receiving these, use the “unsubscribe” function in any message, or email us at ask@minmed.sg.
- Withdrawing your consent
Your consent remains valid until you withdraw it in writing.
To withdraw consent for any or all of the purposes described in this Policy, please write to our Data Protection Officer using the contact details in section 16.
Once we receive your request, we may need reasonable time to process it depending on its complexity and its effect on our relationship with you, and to explain the consequences of acting on it, including any legal consequences affecting your rights and obligations.
Please note that depending on the nature and scope of your request, we may no longer be able to provide our Services to you. We will tell you before we complete the processing of your request.
Withdrawing consent does not affect our right to continue collecting, using and disclosing Personal Data where the law permits or requires us to do so without consent.
- Deleting your account and your records
You can request deletion of your Minmed website or application account by emailing ask@minmed.sg or using the in-app “Account Deletion” function.
Deleting your account does not necessarily delete the associated health, wellness or care records, or other Personal Data that we are required or permitted to retain.
As a licensed healthcare service provider in Singapore, we must retain medical records for periods prescribed under applicable healthcare laws, regulations, licensing requirements and prevailing guidelines. The PDPA does not provide an absolute right to deletion. A request to delete Personal Data, or for us to stop retaining it, may therefore be subject to applicable legal, regulatory, clinical and business retention requirements.
- Accessing and correcting your Personal Data
You may ask us for:
- Access: a copy of the Personal Data we hold about you, or information about how we have used or disclosed it; or
- Correction: an update or correction to Personal Data we hold about you.
Send your request in writing to our Data Protection Officer using the contact details in section 16, and include:
- the requester’s details;
- a description of the Personal Data concerned; and
- the date and time range when you believe the Personal Data was collected.
A reasonable fee may be charged for an access request. If so, we will tell you the fee before we begin processing.
We will respond as soon as reasonably possible. If we cannot respond within 30 days of receiving your request, we will write to you within those 30 days to tell you when we will be able to respond. If we are unable to provide the Personal Data or make the correction you have asked for, we will generally explain why, except where the PDPA does not require us to.
- Keeping your Personal Data accurate
We generally rely on the Personal Data you or your Authorised Representative provide. Please let our Data Protection Officer know in writing if any of your Personal Data changes, so that our records stay current, complete and accurate.
- How we protect your Personal Data
We have put in place reasonable administrative, physical and technical measures to protect your Personal Data against unauthorised access, collection, use, disclosure, copying, modification, disposal and similar risks. These include collecting only the Personal Data we need, restricting access on a need-to-know basis, and reviewing and testing our security measures on a regular basis.
You should be aware that no method of transmission over the internet or method of electronic storage is completely secure. While security cannot be guaranteed, we continually review and strengthen our information security measures.
If you believe your Personal Data has been compromised, or if you have any concerns about how we have handled it, please contact our Data Protection Officer immediately using the details in section 16. We will look into the matter and respond to you.
- How long we keep your Personal Data
Different records are subject to different retention periods, depending on the nature of the record and the legal, regulatory, licensing, professional and business requirements that apply to the relevant Service.
We retain Personal Data for as long as necessary to fulfil the purpose for which it was collected, or as required or permitted by law. We will stop retaining your Personal Data, or remove the means by which it can be associated with you, once it is reasonable to assume that retention no longer serves that purpose and is no longer necessary for legal or business purposes.
- Transfers outside Singapore
We may transfer, store or process Personal Data outside Singapore where this is necessary for the purposes described in this Policy.
Where we do, we take appropriate steps to ensure the recipient is bound by legally enforceable obligations to provide a standard of protection at least comparable to that required under the PDPA.
- Contacting our Data Protection Officer
For any enquiry, feedback or request relating to this Policy or your Personal Data, please contact:
Data Protection Officer
Email: pdpa.dpo@minmed.sg
Address: 8 Kaki Bukit Avenue 1, #02-05/06/07, Singapore 417941
- Changes to this Policy
We may revise this Policy from time to time without prior notice. You can check whether a revision has been made by referring to the “Last updated” date at the beginning of this Policy. You are advised to review this Policy periodically for any changes. Your continued use of our Services means you acknowledge and accept the changes.
