ALEX / Legal
ALEX Privacy Notice - v1.0
How the ALEX platform collects, uses, discloses, transfers, retains, and protects personal data.
Part 1 - About This Notice
1.1 Purpose
This Privacy Notice ("Notice") explains how the ALEX platform ("ALEX", the "Platform") collects, uses, discloses, transfers, retains and protects Personal Data and, where applicable, Protected Health Information ("PHI"), and describes the rights available to individuals in respect of their data.
For simplicity, this Notice uses "ALEX", "we", "us", and "our" to refer to the Platform and the entities that operate it in the roles described in §1.2 and §1.6. Where "we" or "us" is used in reference to the operational Processing of Personal Data or PHI (rather than to the Platform as a product), the operational entity is ALEX Tech Pte. Ltd. and its country subsidiaries, as identified in §1.2. ArcNovo Tech Inc. is the intellectual property owner and licensor of the Platform (see §1.6) and, save for that IP-ownership role, does not itself process Personal Data or PHI, does not act as a Controller, Processor, Business Associate, or Joint Controller for any Processing described in this Notice, and is not a party to Tenant, Partner, or patient contracts in respect of the Platform.
1.2 Who We Are
| Entity | Role | Registered Address | Contact |
|---|---|---|---|
| ArcNovo Tech Inc. | Wyoming corporation, qualified to transact business in California as a foreign corporation; intellectual property owner and licensor of the ALEX Platform to ALEX Tech Pte. Ltd. and its country subsidiaries under an intercompany licence agreement; does not process Personal Data or PHI in the ordinary course of platform operation; is not a Controller, Processor, Business Associate, or Joint Controller for any Processing described in this Notice (see §1.6) | 30 N Gould St, Ste N, Sheridan, WY 82801-9346, USA | No direct privacy-contact channel - see ALEX Tech Pte. Ltd. contacts in Part 18 |
| ALEX Tech Pte. Ltd. | Singapore private limited company (UEN 202308966D); sole global operating entity for the ALEX Platform; contracts with Tenants, Partners, sub-processors, and (where the Patient Application is offered on a direct-to-consumer basis) with patients; acts as Controller and, where applicable, Joint Controller with the patient, or Processor / Business Associate to a Tenant Covered Entity, under HIPAA / HITECH, GDPR / UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH and analogous laws; the entity that carries privacy-law obligations and liabilities in respect of the Processing described in this Notice (see §1.6) | 68 Circular Road, #02-01, Singapore 049422 | privacy-sg@alexcare.tech · privacy@alexcare.tech |
| Future country subsidiaries of ALEX Tech Pte. Ltd. - see the "No country subsidiaries currently incorporated" note immediately below this table | Wholly-owned subsidiaries of ALEX Tech Pte. Ltd. once (and if) incorporated; would act as local Controllers where required by local law | Not applicable - none currently incorporated | See ALEX Tech Pte. Ltd. contact channels in Part 18 |
No country subsidiaries currently incorporated. As at the effective date of this Notice, ALEX Tech Pte. Ltd. has no formally incorporated country subsidiaries. References to "country subsidiaries", to "the relevant ALEX Tech country subsidiary", or to "ALEX Tech Pte. Ltd. or its relevant country subsidiary" - in this §1.2, in §1.6, in the jurisdictional Annexes, and elsewhere in this Notice - describe entities that ALEX Tech Pte. Ltd. may in the future incorporate to meet local data-residency, licensing, regulatory, or business needs. Any illustrative country-subsidiary names that appear in this Notice, in operative contracts, or in related materials (for example, "ALEX Tech (Thailand) Ltd.", "ALEX Tech (Malaysia) Sdn. Bhd.", "ALEX Tech Philippines Inc.") are indicative only and are subject to change; the actual legal name of any future country subsidiary will be confirmed at the time of that subsidiary's incorporation and, where relevant, notified through an update to this Notice. Until a country subsidiary is formally incorporated, all obligations and liabilities of ALEX under this Notice in the relevant country attach to ALEX Tech Pte. Ltd. directly.
Joint Controllership. ALEX Tech Pte. Ltd. is (a) the sole ALEX-side Controller for Tenant Workforce accounts on the Platform, corporate visitor and lead data, and general Platform operations; and (b) a Joint Controller under Article 26 of the GDPR (where GDPR applies) with the patient, in respect of patient identity, credential, and cross-provider record data associated with the ALEX Network - the patient as data subject exercising sovereignty rights, and ALEX Tech as the operator of the identity, portability, and cross-provider linkage functionality. Each connected Tenant remains the Controller for the treatment data it contributes. The essence of the joint-controller arrangement - including the allocation of responsibilities for compliance with data-subject rights and transparency obligations - is available on request at dpo@alexcare.tech. ArcNovo Tech Inc. is not a party to this joint-controller arrangement.
Controller / Processor Roles by Data Flow (Summary):
| Data Flow | Controller | Processor | Notes |
|---|---|---|---|
| Patient data processed on Tenant deployments of the Platform (through the mobile application, web application, and/or authorised and provisioned APIs or interfaces made available to the Tenant) | The Tenant (hospital / clinic / lab / imaging / pharmacy / insurer / other healthcare organisation) | ALEX Tech Pte. Ltd. (or its country subsidiary where local law so requires) | The Tenant is Covered Entity (HIPAA) or Controller (GDPR / PDPA); ALEX Tech is Business Associate / Processor. Governed by the Business Associate Agreement (BAA) and Data Processing Addendum (DPA), entered into by ALEX Tech (not ArcNovo). |
| Patient data processed through patient-facing components of the Platform - accessed by the patient via the ALEX patient mobile application, patient web application, and/or authorised and provisioned APIs or interfaces - including portable identity, cross-provider record consent, and the patient-sovereign timeline | Joint Controllers: the patient (exercising sovereignty rights) and ALEX Tech Pte. Ltd. (as operator of the identity, portability, and cross-provider linkage functionality); each connected Tenant remains Controller of the treatment data it contributes | - | Joint-controller transparency notice available per this §1.2. The patient may withdraw the relevant consents at any time per Part 13. |
| Corporate website and marketing data (leads, prospects, visitors) | ALEX Tech Pte. Ltd. | Marketing sub-processors (see Appendix 1 to this Notice) | Cookies, analytics, CRM. Standard controller processing. |
| Tenant Workforce account data (login, role, activity logs used for platform operations, billing, service continuity, security) | ALEX Tech Pte. Ltd. | - | Platform-operations processing on ALEX Tech's own behalf, with a controller footing. |
| Tenant Workforce activity data used to render the Tenant's own service to its patients | The Tenant | ALEX Tech Pte. Ltd. | Same as Row 1 |
1.3 Scope - Who This Notice Covers
This Notice applies to three principal audiences:
- Patients whose Personal Data or PHI is handled through the Platform - including patients who access the Platform directly through the ALEX patient mobile application, patient web application, or authorised and provisioned APIs or interfaces; patients receiving care from ALEX Tenant providers using the Platform; and patients whose data is routed between ALEX Tenant providers through the ALEX Network.
- Tenant Workforce Users - clinicians, administrators, and other staff of ALEX Tenant organisations who use the Platform in the course of employment, whether through the mobile application, web application, or authorised and provisioned APIs or interfaces.
- Corporate audiences - visitors to
alexcare.techand related properties; prospective customers; partners in our partner ecosystem programme; investors; job applicants.
Not covered by this Notice - but separately notified - are: (i) individuals whose data is controlled by an ALEX Tenant, where the Tenant provides its own patient-facing notice under HIPAA / local law; (ii) ArcNovo employees (covered by internal HR privacy notice); (iii) individuals interacting with third-party services linked from ALEX properties (see Part 16).
1.4 Relationship to Tenant Notices
Where you receive care from an ALEX Tenant, that Tenant is the Covered Entity (HIPAA) or the Controller (GDPR / PDPA) of your PHI / Personal Data - a compliance role, not an ownership title (see §1.5.3). ALEX processes that data only on the Tenant's documented instructions under a Business Associate Agreement (BAA) and / or Data Processing Addendum (DPA). Please consult your Tenant's own notice for rights against the Tenant. Rights you may separately hold against ALEX as Processor, Business Associate, or Joint Controller are described in Part 13.
1.5 Patient Data Sovereignty - Our Fundamental Commitment
ALEX operates on the principle of patient data sovereignty. This principle governs how we describe every relationship, contract, and technical arrangement in this Notice and in every companion legal instrument (DPA, BAA, sub-processor agreement, partner ecosystem terms). It is not merely a marketing statement - it is a binding legal commitment that shapes our contract templates, our engineering, our sub-processor onboarding, and our corporate governance.
1.5.1 The Sovereignty Principle
An individual patient holds the ultimate rights in their own Personal Data and PHI - including the underlying facts that describe the patient's health, identity, contact information, treatment history, biometric characteristics, insurance status, and any inference derived from any of the foregoing. These rights are inalienable in substance: a patient cannot be contractually stripped of them, and no party who processes patient data acquires them through the act of processing. The custody, control, or lawful processing of patient data by ALEX, by any Tenant, by any sub-processor, or by any Partner is a role of stewardship - never an act of appropriation, and never a source of ownership.
1.5.2 No Ownership by ALEX
Neither ALEX Tech Pte. Ltd. (the operating entity), nor ArcNovo Tech Inc. (the IP owner and licensor), nor any subsidiary, affiliate, or successor of either, claims or holds ownership of any patient Personal Data or PHI. The lawful operational roles carried by ALEX Tech Pte. Ltd. - as Controller, Processor, Business Associate, or Joint Controller as identified in §1.2 - do not carry any implied assertion of ownership. The IP-owner and licensor role carried by ArcNovo Tech Inc. is a proprietary interest in the ALEX Platform software and technology - not in any patient's Personal Data or PHI; ArcNovo Tech Inc. does not process such data (see §1.6) and does not, by virtue of its IP ownership of the Platform, acquire any interest in the data that patients or Tenants place into the Platform. Where this Notice or any technical documentation describes ALEX as "holding", "storing", "processing", "routing", "hosting", or "operating on" patient data, those words describe an operational role carried by ALEX Tech Pte. Ltd. and never confer an ownership right on ALEX Tech, ArcNovo, or any other party.
1.5.3 No Ownership by Tenants
An ALEX Tenant that engages the Platform to deliver care to its patients acts as the Covered Entity (HIPAA) or Controller (GDPR / PDPA and equivalents) of patient data. This is a compliance role, not an ownership title.
- HIPAA does not confer "ownership" of PHI in any commercial sense. Older healthcare-vendor contracts sometimes assert that "the provider owns the medical record"; that assertion, insofar as it purports to derogate from patient rights under 45 CFR §§ 164.524, 164.526, 164.528, 164.522, and 164.508, is not enforceable against those rights. State medical-record laws that impose custodial retention obligations run to the patient and to the licensing regulator - not against the patient's underlying substantive rights.
- GDPR, UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH, APPI, AU APP and equivalent frameworks are rights-based, not property-based. They allocate Controller and Processor duties; they do not grant ownership of the personal data to any party.
Every Tenant contract that ALEX enters into includes provisions that: (a) acknowledge Tenant does not own patient Personal Data or PHI processed on the Platform; (b) bind Tenant to honour every patient right that would attach against Tenant under applicable law; (c) prohibit Tenant from asserting ownership in any downstream contract, notice, marketing communication, disclosure to insurers, disclosure to employers, sale to data brokers, or otherwise; (d) prohibit Tenant from selling, licensing, pledging as security, or transferring patient data as a proprietary asset; and (e) require Tenant to return or delete patient data on Tenant termination in accordance with applicable clinical-record retention law and patient instruction, without asserting a residual proprietary claim.
1.5.4 No Ownership by Partners or Sub-processors
Every sub-processor engaged by ALEX (listed in Appendix 1) and every partner in our partner ecosystem programme is contractually bound to: (a) process patient Personal Data and PHI only on ALEX's documented instructions or, where the partner has an independent lawful basis, only within the strict scope of that basis; (b) claim no ownership, licensing right, or proprietary interest in patient data received through ALEX; (c) not use patient data for the partner's or sub-processor's independent business purposes - including AI Model training on identifiable data, product-improvement analytics beyond the strict scope of service, or resale - unless separately consented by the patient and independently lawful; (d) impose the same restrictions on any downstream sub-processor; and (e) return or delete patient data at end of engagement. Partner certification and sub-processor status are revocable for violation of these terms.
1.5.5 Anti-Alienation
Patient Personal Data and PHI is not a saleable, licensable, pledgable, or mortgageable asset of ALEX, of any Tenant, of any Partner, or of any sub-processor. No such party shall sell, license, pledge as security, grant a proprietary interest in, or otherwise treat patient Personal Data or PHI as a commercial asset owned by that party. This restriction survives termination of any commercial arrangement between the parties who processed the data, and it is enforceable by the patient as a matter of stewardship duty owed to the patient - not merely as a contractual covenant between the processing parties.
1.5.6 Corporate Transactions
Where ArcNovo Tech Inc., ALEX Tech Pte. Ltd., any Tenant, any Partner, or any sub-processor undergoes a merger, acquisition, sale of assets, financing, restructuring, spin-off, or similar corporate transaction:
- (a) Patient Personal Data and PHI transfers to the successor in a custodial role only, never as a proprietary asset of the transferring party.
- (b) The successor is bound by the sovereignty commitments in this §1.5 and by every patient-rights obligation that attached to the predecessor - as a condition of the transaction, warranted by the transferring party and enforceable by ALEX and by affected patients.
- (c) Where required by applicable law - including the appointment of a consumer privacy ombudsman under 11 U.S.C. § 332 in a US bankruptcy sale involving personally identifiable information, or the equivalent regime in another jurisdiction - the required protective mechanism shall be honoured, not circumvented.
- (d) Affected patients receive notice with a meaningful opportunity to exercise portability, transfer, or erasure rights before the transfer takes effect, to the extent required by applicable law and in all cases where the transfer would materially change the identity of the party holding custody of the patient's data.
- (e) Any commercial value ascribed to patient data in the transaction shall not diminish patient rights - value derived from data stewardship does not convert stewardship into ownership.
1.5.7 Insolvency and Wind-Down
In the event of ALEX insolvency, Tenant insolvency, or wind-down of any party that holds patient data through the Platform:
- (a) Patient Personal Data and PHI shall not be treated as a "for-sale" asset of the insolvent estate. Consistent with US Bankruptcy Code § 363(b)(1)(A) and § 332 (consumer privacy ombudsman) - and equivalent regimes in Singapore's Insolvency, Restructuring and Dissolution Act 2018, the UK's Insolvency Act 1986, and applicable ASEAN insolvency law - patient data disposition shall be conducted under a protective regime that preserves patient rights.
- (b) Stewardship transfers to a qualified successor operator who assumes the sovereignty commitments in this §1.5 in writing, or to a court-appointed data custodian pending transition.
- (c) Patients receive advance notice and a meaningful window to exercise portability, transfer, and erasure rights before any successor transition takes effect.
- (d) Where no qualified successor exists, patient data shall be exported to the patient (or to the patient's nominated successor provider) and thereafter deleted from ALEX systems in accordance with applicable clinical-record retention law, with certification of deletion to the patient on request.
- (e) ALEX's business-continuity design and Tenant contracts are structured so this commitment is operational under stress - not merely aspirational.
1.5.8 Cross-Border Sovereignty
Patient sovereignty rights follow the patient - not the storage location and not the corporate domicile of the processing party. Where patient data is transferred across borders under Part 9, the patient's substantive rights (access, rectification, erasure, portability, restriction, objection, ADM safeguards, complaint) remain in force notwithstanding the storage jurisdiction. Where a receiving jurisdiction offers materially weaker protection than the patient's home jurisdiction, the higher standard prevails as a matter of contract.
1.5.9 De-identified, Aggregate, and AI-Derived Data
- De-identified and aggregated data derived from patient data (see Part 6.3) is used for legitimate platform-improvement, safety-signal, and permitted research purposes only. We do not sell or license such data to any third party for that party's independent commercial exploitation. Our sub-processors and partners are contractually restricted to the same.
- AI-generated inferences about an identified patient (for example, an automated risk score, a documentation suggestion, a code-capture recommendation, a triage classification) remain within the sovereignty scope described above. Such inferences cannot be transferred to any third party or repurposed outside the scope of the underlying lawful basis without either (i) explicit patient consent or (ii) an independent lawful basis established for the recipient.
1.5.10 Contract Override - Sovereignty Prevails
No term of any contract between ALEX and a Tenant, between ALEX and a Partner, between ALEX and a sub-processor, between any Tenant and its own downstream vendors, between any Partner and its own downstream affiliates, or between any successor to any of the foregoing and any third party, shall be construed to grant ownership of patient Personal Data or PHI to any party or to derogate from the sovereignty commitments in this §1.5. Any provision of any such contract that purports to do so is void and unenforceable to the extent of the derogation, and the commitments in this §1.5 prevail. ALEX will not enter into and will not accept any Tenant amendment, Partner amendment, sub-processor amendment, or successor undertaking that conflicts with this §1.5.
1.5.11 High-Trust Operating Posture
Consistent with these sovereignty commitments, we operate the Platform on a high-trust footing that includes: (a) minimum-necessary data collection; (b) role-based access control and immutable audit logging on every read of identifiable patient data; (c) transparent published sub-processor list with advance notice of change (Appendix 1 and §7.3); (d) transparent AI training data governance (Part 6.3); (e) responsiveness to patient rights requests within the statutory windows (Part 13); (f) independent audit under the certifications listed in Part 11.7; and (g) enforcement of every provision of this §1.5 through the standard-form contract templates ALEX uses for all Tenants, Partners, and sub-processors - with those templates published in redacted form to enterprise Tenants and regulators on reasonable request.
1.6 Corporate Structure and Allocation of Legal Responsibility
ALEX operates through two principal legal entities, each with a defined and non-overlapping role.
1.6.1 ArcNovo Tech Inc. - IP Owner and Licensor Only
ArcNovo Tech Inc. is a Wyoming corporation, qualified to transact business in California as a foreign corporation, with registered office at 30 N Gould St, Ste N, Sheridan, WY 82801-9346, USA. It is the intellectual property owner and licensor of the ALEX Platform - including the software, model weights, technical documentation, trade secrets, and related IP that comprise the Platform. ArcNovo Tech Inc. licenses the ALEX Platform to ALEX Tech Pte. Ltd. and its country subsidiaries under an intercompany licence agreement.
For the avoidance of doubt, and consistent with the actual operating structure of the Platform:
- ArcNovo Tech Inc. does not itself process Personal Data or PHI of patients, Tenant Workforce Users, corporate visitors, or any other data subject in the ordinary course of platform operation;
- ArcNovo Tech Inc. does not determine the purposes or means of Processing conducted through the Platform for the purpose of any applicable data-protection law (including Article 4(7) GDPR, HIPAA 45 CFR § 160.103, PDPA-SG s.2(1), and equivalents);
- ArcNovo Tech Inc. does not contract with Tenants, Partners, sub-processors, or patients as a data-processing counterparty in respect of the Platform;
- ArcNovo Tech Inc. is not a Controller, Processor, Joint Controller, Business Associate, or Business Associate Subcontractor for any Processing described in this Notice; and
- The IP-ownership interest that ArcNovo Tech Inc. holds in the Platform software and technology does not extend to, and does not confer any interest in, any patient's Personal Data or PHI (see §1.5.2).
Where a data subject seeks to exercise rights, register a complaint, or notify a concern in respect of Processing described in this Notice, the correct counterparty is ALEX Tech Pte. Ltd. or its relevant country subsidiary - not ArcNovo Tech Inc.
1.6.2 ALEX Tech Pte. Ltd. - Sole Global Operating Entity
ALEX Tech Pte. Ltd. is a Singapore private limited company incorporated under the Companies Act 1967 and registered with ACRA. It is the sole global operating entity for the ALEX Platform. As at the effective date of this Notice, ALEX Tech Pte. Ltd. has no formally incorporated country subsidiaries (see the "No country subsidiaries currently incorporated" note in §1.2). ALEX Tech Pte. Ltd. - together with any country subsidiaries it may incorporate in the future to meet local data-residency, licensing, regulatory, or business needs - is the party that:
- contracts with Tenants for use of the Platform (including under Business Associate Agreements and Data Processing Addenda);
- contracts with Partners in the partner ecosystem programme;
- contracts with sub-processors;
- contracts directly with patients where the Patient Application is offered on a direct-to-consumer basis;
- acts as Controller (and, where applicable, Joint Controller with the patient for the patient-sovereign functionality of the Platform, or Processor / Business Associate to a Tenant Covered Entity) under HIPAA / HITECH, GDPR / UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH and analogous laws; and
- bears the operational responsibility for the data-protection commitments in this Notice.
1.6.3 Allocation of Legal Responsibility
All privacy-law obligations and legal liabilities in respect of the Processing described in this Notice - including (without limitation) data-subject rights fulfilment, breach detection and notification, regulator complaints handling, cross-border transfer safeguards, retention, security, sub-processor management, and AI-transparency obligations - attach exclusively to ALEX Tech Pte. Ltd. and, where applicable under local law, to the relevant ALEX Tech country subsidiary. ArcNovo Tech Inc. bears no privacy-law obligation and no privacy-law liability in respect of such Processing, save to the extent that a specific statutory provision imposes a duty directly on ArcNovo Tech Inc. as IP owner (which, under the frameworks surveyed in this Notice, does not arise in the ordinary course).
All contracts entered into in respect of the Platform - with Tenants, Partners, sub-processors, patients, and other counterparties - are executed by ALEX Tech Pte. Ltd. or its relevant country subsidiary, and not by ArcNovo Tech Inc. Any recourse for breach of the commitments in this Notice, or for any privacy-law claim arising in respect of the Platform, lies against ALEX Tech Pte. Ltd. (or the relevant ALEX Tech country subsidiary).
1.6.4 Preservation of Statutory Rights
Nothing in this §1.6 or in this Notice derogates from any statutory right that a data subject may hold against any party that in fact processes their Personal Data or PHI, under the law that applies to that Processing. The corporate-structure allocation set out in §1.6 describes which entity is the operational counterparty for privacy-law purposes; it does not waive, restrict, exclude, or defeat any right that a data subject holds by law. Data subjects retain the full suite of statutory rights described in Part 13 and in the jurisdictional Annexes, exercisable against ALEX Tech Pte. Ltd. and, where local law so provides, against the country subsidiary that operates in the data subject's jurisdiction. Nothing in this §1.6 prevents a data subject from lodging a complaint with a supervisory authority (see Part 19).
1.6.5 Contact and Recourse
All contact points for the exercise of data-subject rights, DPO enquiries, breach notification, and regulatory complaint routing are the ALEX Tech Pte. Ltd. channels set out in Part 18. ArcNovo Tech Inc. does not operate a data-protection contact channel and will not intake data-subject requests.
Part 2 - Definitions
For the purposes of this Notice:
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, aligned with GDPR Art. 4(1), PDPA-SG s.2(1), PDPA-TH s.6, PDPA-MY s.4, DPA-PH s.3(g). Includes online identifiers, device identifiers, and inferred data. |
| Sensitive / Special Category Data | Data warranting heightened protection under applicable law - includes health data, genetic data, biometric data, sexual orientation, religious belief, political opinion, criminal history, national ID numbers where restricted (e.g., SG NRIC per PDPC guidance, MY NRIC per PDPA), and children's data. |
| Protected Health Information (PHI) | As defined under 45 CFR § 160.103, individually identifiable health information transmitted or maintained in any form by a Covered Entity or Business Associate. |
| Processing | Any operation performed on Personal Data - collection, recording, storage, use, disclosure, transmission, erasure. |
| Controller | The entity that determines the purposes and means of Processing (GDPR Art. 4(7); PDPA equivalents). |
| Processor | The entity that processes Personal Data on behalf of a Controller (GDPR Art. 4(8)); analogous to Business Associate under HIPAA. |
| Sub-Processor | A Processor engaged by ALEX to process Personal Data. Named list at Appendix 1. |
| Tenant | Any healthcare organisation, provider, insurer, or health-adjacent enterprise that has contracted with ALEX to use the Platform. |
| Platform | The ALEX platform in all its forms - including modules, features, and services accessed by users through the ALEX mobile application(s), the ALEX web application(s), and/or authorised and provisioned application-programming interfaces (APIs) and other interfaces. References to "the Platform" are technology-neutral and cover future access modes we introduce that are consistent with this Notice. |
| Patient Application | Those components of the Platform intended for direct use by patients - including the ALEX patient mobile application, the ALEX patient web application, and any authorised patient-facing APIs or interfaces. |
| Tenant Application | Those components of the Platform intended for use by Tenant Workforce Users - including tenant administration, clinical workflow, and back-office modules accessed via the ALEX mobile application(s), web application(s), and/or authorised and provisioned APIs or interfaces. |
| ALEX Network | The inter-organisational clinical fulfilment functionality that enables Tenant providers to route clinical orders (for example, laboratory, imaging, pharmacy, and referral orders) to other Tenant providers on the Platform, and to receive results back, subject to applicable consent. |
| AI Model | Any machine-learning, deep-learning, foundation, generative, statistical or agentic system used within the Platform to derive inference, generate content, route decisions, or support clinical workflows. |
| Automated Decision-Making (ADM) | Decisions produced without meaningful human involvement having legal or similarly significant effects on the data subject (GDPR Art. 22). |
| Patient Data Sovereignty | The principle set out in §1.5 that individual patients hold ultimate rights in their own Personal Data and PHI, that neither ALEX nor any Tenant, Partner, sub-processor, successor, or affiliate of the foregoing claims or holds ownership of such data, and that custody or lawful processing is a role of stewardship rather than appropriation. |
| Steward / Custodian | A party that holds, processes, transmits, or routes patient Personal Data or PHI in a lawful role - without acquiring any proprietary interest in the underlying data. ALEX operates in a Steward / Custodian role in respect of all patient Personal Data and PHI. Tenants, Partners, and sub-processors likewise operate in Steward / Custodian roles insofar as they touch patient data through the Platform. |
| Qualified Successor Operator | A successor entity that has (i) undertaken in writing to be bound by the sovereignty commitments in §1.5, (ii) demonstrated equivalent or superior technical and organisational safeguards to those set out in Part 11, and (iii) been notified to affected patients with a meaningful window for the patient to exercise portability and erasure rights before the transition takes effect. |
Part 3 - What Information We Collect
3.1 Patient (Direct Patient Application Use and Tenant-Delivered Care)
We collect the following categories of Personal Data and PHI in connection with patient care and patient use of the Platform (whether via the Patient Application or via a Tenant's use of the Platform in delivering care to the patient):
Identity & Contact Data: legal name, preferred name, date of birth, gender identity where volunteered, national identifiers where legally required (SG NRIC/FIN, MY NRIC/passport, TH National ID, PH PhilSys PSN, US SSN under HIPAA-permitted uses), residential and mailing address, contact telephone, email, next-of-kin contact.
Clinical Data (PHI): medical history, current conditions, allergies, medications, immunisations, laboratory results, imaging studies and DICOM objects, clinical notes and encounter summaries, procedure history, diagnoses (ICD-10, ICD-10-TM, ICD-11 as applicable), care team assignments, treatment plans, referral history, admission/discharge/transfer records.
Insurance & Benefits Data: payer identifier, policy number, coverage tier, claim history, government scheme membership (BHYT, NHSO, PhilHealth, BPJS, MediSave / MediShield Life, MEDIBRIDGE panel status, TPA identifiers).
Financial Data: billing charges, receipts, co-payment history, payment instrument tokenised references (we do not store full card PAN; see Part 11.4).
Biometric & Sensitive Identifiers: facial images for identity verification (opt-in), fingerprint or voice patterns where used for patient authentication (opt-in), genetic data where clinically ordered.
Cross-Provider Data (Patient Portability): portable patient identity record, longitudinal health-event timeline, consent grants and revocations recorded in our consent-management system, and cross-provider notifications the patient has enabled through the Platform.
Behavioural / Interaction Data: Patient Application usage logs, appointment booking history, message threads with providers, and feature-engagement events (used to render the service; not sold and not used for third-party advertising).
Device & Technical Data: device ID, OS version, IP address (retained only for security and fraud-prevention windows - see Part 10), approximate geolocation (city-level; precise geolocation only with explicit permission and only for feature-specific use, e.g., nearest-provider search).
3.2 Tenant Workforce (Clinician, Admin, Support)
We collect: name, work email, employee ID (assigned by the Tenant), role assignments, credential and licence numbers where the Tenant configures credential verification, authentication data (password hashes, MFA factors), session logs, feature-access audit trail, IP address of the accessing device, browser/OS metadata, and workflow productivity data used solely for service delivery and security.
3.3 Corporate Visitors, Leads, Applicants, Partners
We collect: name, business email, employer, job title, country, information you submit through contact forms or event registrations, communication history, marketing engagement events (opens, clicks - where consent has been captured for such tracking), résumé and application data (for job applicants - handled under a separate applicant privacy notice on request), and diligence data submitted through our partner ecosystem programme.
3.4 Data We Do NOT Collect / Do NOT Want
- We do not knowingly collect data from children under 13 in the US or under the age of digital consent in the applicable jurisdiction (see Part 14) except where a Tenant configures pediatric care workflows on our platform - in which case the Tenant is Controller and parental consent is administered under the Tenant's care governance.
- We do not collect political opinions, religious belief, trade-union membership, or sexual life data unless expressly and voluntarily provided by a patient in a clinical context and clinically relevant.
- We do not knowingly ingest data from unauthorised scraping, brokered datasets, or third-party sources outside our named data sources.
Part 4 - Legal Bases for Processing
Because ALEX operates across multiple jurisdictions with materially different legal-basis frameworks, we identify the legal basis relied upon for each category of Processing.
4.1 Under the GDPR / UK GDPR (Art. 6 and Art. 9)
| Processing Purpose | Legal Basis (Art. 6) | Art. 9 Special Category Basis (where applicable) |
|---|---|---|
| Provision of care via the Platform in use by a Tenant (ALEX as Processor) | Art. 6(1)(b) contract with Tenant / Art. 6(1)(f) legitimate interest | Art. 9(2)(h) provision of health / social care under professional secrecy |
| Patient identity, portability, and cross-provider record functionality (Patient Application and related APIs) | Art. 6(1)(a) consent | Art. 9(2)(a) explicit consent |
| Emergency access / break-glass to PHI to prevent serious harm | Art. 6(1)(d) vital interests | Art. 9(2)(c) vital interests where data subject cannot consent |
| Billing, tax, accounting records | Art. 6(1)(c) legal obligation | N/A |
| Fraud detection, security, network integrity | Art. 6(1)(f) legitimate interest (balancing test on file) | Art. 9(2)(g) substantial public interest (where PHI touched) |
| Corporate marketing to prospective customers | Art. 6(1)(f) legitimate interest / Art. 6(1)(a) consent (opt-in for email) | N/A |
| AI model training on de-identified aggregated data | Art. 6(1)(f) legitimate interest (with balancing test) - see Part 6 | Not applicable once effectively de-identified per Recital 26 |
| AI model training on identifiable PHI | Art. 6(1)(a) explicit consent, or Art. 6(1)(e) scientific research under Art. 89 safeguards - see Part 6 | Art. 9(2)(a) explicit consent, or Art. 9(2)(j) scientific research |
4.2 Under HIPAA / HITECH (US)
ALEX processes PHI in the capacity of a Business Associate (and, in some flows, Business Associate Subcontractor) of Covered Entity Tenants. Our processing is authorised by:
- The Business Associate Agreement executed with each Covered Entity Tenant, in the form required by 45 CFR § 164.504(e).
- The Covered Entity's underlying Treatment, Payment, or Health Care Operations (TPO) purpose per 45 CFR § 164.506.
- Patient authorisation under 45 CFR § 164.508 for uses beyond TPO (e.g., marketing, most research uses, sale of PHI, psychotherapy notes).
- Permitted disclosures under 45 CFR § 164.512 (required by law, public health, victims of abuse, health oversight, judicial proceedings, law enforcement under conditions, decedents, organ donation, serious threat).
- The Minimum Necessary Standard (45 CFR § 164.502(b)) is applied technically through role-based access control and disclosure-scope-limiting APIs.
4.3 Under PDPA-SG (Singapore Personal Data Protection Act)
We rely on (a) consent obtained under s.13–17 for standard Processing purposes; (b) deemed consent by notification under s.15A for compatible secondary purposes; (c) the legitimate-interests exception under the First Schedule, Part 3 (with the required balancing assessment on file) for security, fraud, and business-improvement Processing; (d) the business-improvement exception under the First Schedule, Part 5 for internal analytics on de-identified data; (e) statutory disclosures under s.17 exceptions where required.
4.4 Under PDPA-TH (Thailand Personal Data Protection Act B.E. 2562)
Health data is Sensitive Personal Data under s.26 and requires explicit consent unless a s.26 exception applies (vital interests; preventive/occupational medicine; public interest in the area of public health; scientific research subject to safeguards). Non-sensitive Personal Data is processed on the legal bases in s.24 (consent, contract, legal obligation, vital interests, public task, legitimate interests).
4.5 Under PDPA-MY (Malaysia Personal Data Protection Act 2010 as amended by the PDPA (Amendment) Act 2024)
We process on the bases in s.6 and s.40 (Sensitive Personal Data) - consent (with the enhanced explicit-consent standard for health data), performance of a contract, compliance with a legal obligation, or protection of vital interests. As required by the 2024 amendments (in force 2025), we operate under Class of Data User registration for the healthcare class, appoint a Data Protection Officer, notify data subjects of material processing changes, and comply with the enhanced breach-notification and data-portability rules.
4.6 Under DPA-PH (Philippines Data Privacy Act of 2012, RA 10173)
Health data is Sensitive Personal Information under s.3(l) and requires the higher-standard bases in s.13 - consent obtained prior to collection or where processing is necessary for medical treatment carried out by a medical practitioner or medical treatment institution and the data subject is not legally capable of giving consent; or as provided by existing laws and regulations for the protection of lawful rights and interests of natural or legal persons in court proceedings; or necessary to fulfill functions of public authority. We are registered with the National Privacy Commission (NPC) and our Data Processing System (DPS) registration is on file.
4.7 Other Jurisdictions
For processing subject to (i) Japan APPI, (ii) Australia Privacy Act 1988 and Australian Privacy Principles, (iii) Hong Kong PDPO, (iv) UAE PDPL, (v) Saudi Arabia PDPL, (vi) other Applicable Data Protection Law, we rely on the equivalent legal bases as summarised in Annex G.
Part 5 - How We Use Personal Data
We use Personal Data only for the following purposes, tied to the legal bases in Part 4:
- To render the Platform service - provisioning Tenants, delivering care workflows, routing clinical orders, storing and retrieving records, generating clinical documentation, delivering results, and rendering the patient-facing components of the Platform (whether through the mobile application, web application, or authorised and provisioned APIs or interfaces).
- To identify patients and prevent misidentification - through biometric matching (where opted in), demographic reconciliation, and our patient identity system.
- To route and fulfil clinical orders across the ALEX Network - only where a valid consent to cross-provider routing has been captured through our consent-management system.
- To bill for services and process payment - including insurer and government-scheme claim submission with claim-adjudication tracking.
- To provide clinical decision support and safety alerts - including drug-interaction, allergy, and clinical-safety alerts under our clinical policy governance framework.
- To detect, investigate, prevent, and respond to security incidents, fraud, abuse and legal liability - including credential-stuffing detection, anomalous access review, and forensic audit-trail preservation.
- To comply with legal, regulatory and audit obligations - including HIPAA, PDPA, GDPR, tax, corporate records, health-authority reporting, and litigation holds.
- To communicate service, safety, and security information - including security bulletins, breach notifications, product-change notices, and service-availability alerts.
- To improve the Platform - through our internal platform improvement and model-development processes, using de-identified and aggregated data unless explicit consent for identifiable-data use has been captured (see Part 6).
- To conduct corporate marketing and sales - to prospective enterprise customers on a legitimate-interest or consent basis (opt-in for email marketing in jurisdictions requiring it).
- To operate our partner ecosystem programme - partner registration, certification, and revenue-share reconciliation.
We do not use Personal Data for: sale to third parties for their independent purposes; behavioural advertising; discriminatory profiling; or any purpose materially inconsistent with the purposes disclosed at collection without either fresh consent or a valid compatible-purpose analysis.
Part 6 - AI, Model Training, and Automated Decision-Making
Because ALEX is an AI-native platform, we make this Part more detailed than a general SaaS notice would.
6.1 Where AI is Used
AI is used within the Platform to:
- Draft clinical documentation from clinician dictation or structured inputs (AI-assisted; the human clinician remains the sign-off author).
- Suggest ICD, procedure, and drug codes to improve billing accuracy.
- Route clinical orders across the ALEX Network.
- Generate patient-facing summaries and translations.
- Support triage and clinical-decision-support alerts under our clinical policy governance framework and clinical safety oversight.
- Detect fraud, credential abuse and security anomalies.
- Improve the Platform through our internal platform improvement and model-development processes.
6.2 Automated Decision-Making
Under GDPR Art. 22 (and analogous provisions in Annex jurisdictions), decisions producing legal or similarly significant effects on you will not be made solely by automated means without a lawful basis and appropriate safeguards. ALEX is designed such that clinically significant decisions require human clinician sign-off - the AI proposes, the licensed clinician disposes. Where ADM is unavoidable (e.g., automated fraud-block on suspicious authentication), you have the right (a) to be informed, (b) to obtain human review, (c) to express your point of view, and (d) to contest the decision. Contact dpo@alexcare.tech.
6.3 Use of Personal Data / PHI for AI Model Training
Default rule: we train and refine AI Models exclusively on de-identified, aggregated, or synthetic data. De-identification follows either the HIPAA Safe Harbor method (45 CFR § 164.514(b)(2)) or the HIPAA Expert Determination method (45 CFR § 164.514(b)(1)), with additional k-anonymity / l-diversity re-identification-risk testing.
Exceptions requiring explicit consent or a lawful research basis:
- Where identifiable data is used for research purposes, we rely on Art. 9(2)(j) GDPR (scientific research) with Art. 89 safeguards, HIPAA IRB or waiver processes, PDPA research exceptions where available, and analogous local-law bases.
- Where a Tenant explicitly authorises identifiable-data training on its patient population under its BAA / DPA, the Tenant is responsible for the underlying patient consent and IRB where required.
AI Transparency Commitments:
- We publish the categories of data used to train our AI Models.
- We do not use patient PHI to train AI Models for third-party foundation-model providers.
- We do not sell or license identifiable Personal Data or PHI to any third party for AI training.
- Our sub-processor list (Appendix 1) identifies any AI / ML infrastructure providers and states whether they process identifiable or de-identified data on our behalf.
6.4 EU AI Act Positioning
Several categories of AI functionality operated by us may fall in-scope of the EU AI Act (Regulation (EU) 2024/1689). Classification is made per system and per intended purpose - AI systems that are medical devices, or safety components of medical devices, may be classified under Article 6(1) and Annex I (conformity-assessment route). Other AI systems - including certain clinical decision support, biometric, and workforce use cases - may be classified as high-risk under Article 6(2) and Annex III. Each ALEX AI system in scope is classified before deployment, and the applicable risk-management, data-governance, technical-documentation, transparency, human-oversight, accuracy, robustness, and cybersecurity regime is operated for the applicable classification. EU AI Act database registration is completed where required. A per-system classification statement will be published together with the AI Transparency Notice referenced above; in the interim, per-system classification information and additional AI-transparency information are available on request via privacy@alexcare.tech.
6.5 Alignment with Frameworks
Our AI governance aligns with the NIST AI Risk Management Framework, Singapore's Model AI Governance Framework 2.0 (including the Generative AI addendum), and the ISO/IEC 42001 AI Management System standard.
Part 7 - Sharing and Disclosure
We share Personal Data only in the following circumstances:
7.1 With Your Tenant
Where you are a patient of an ALEX Tenant, your data is inherently accessed by that Tenant's authorised workforce. This is not a "sharing" for GDPR purposes - the Tenant is the Controller and ALEX is the Processor.
7.2 With Other Providers on the ALEX Network
When you (or your Tenant, acting on your instruction) route a clinical order to a fulfilment provider on the ALEX Network - for example, a standalone laboratory receiving a laboratory order from your referring hospital - the order and clinically necessary Personal Data are transmitted through the Platform to that fulfilment provider only where a valid consent to cross-provider routing has been captured through our consent-management system and where a network-level Data Processing Addendum is in force.
7.3 With Sub-Processors
We use sub-processors listed at Appendix 1 to deliver the service - including cloud hosting, cybersecurity, communications, payments, analytics, and specialist AI infrastructure. Each sub-processor is bound by a written agreement imposing GDPR Art. 28-equivalent, HIPAA BAA-equivalent, and PDPA-equivalent obligations, and by the anti-appropriation and non-ownership flow-down provisions in §1.5.4 and §1.5.5. Sub-processor additions are notified 30 days in advance where Tenant contract terms require, with a right to object. A sub-processor that violates the anti-appropriation or non-ownership provisions is subject to immediate suspension and removal.
7.4 With Payers, Government Health Schemes, Regulators
Where you consent to insurance claim submission, or where the Tenant's care model requires eligibility verification, we transmit claim data to payer systems (BHYT, NHSO, PhilHealth, BPJS, MEDIBRIDGE, HMO/TPA, Medicare/Medicaid, private insurers). We disclose to health authorities where mandated (public health reporting; adverse-event reporting; disease-surveillance obligations).
7.5 Under Legal Compulsion
We disclose Personal Data where required by law, subpoena, court order, or lawful government request, applying (a) narrow scoping to only the data legally compelled, (b) validity checks on the compelling instrument, (c) challenges where legally overbroad, and (d) transparency reporting on aggregate government-request volume (published annually).
7.6 In Corporate Transactions and Insolvency
In a merger, acquisition, sale of assets, financing, insolvency, reorganisation, restructuring, spin-off, or similar corporate transaction, Personal Data may transfer to the successor entity only in a custodial capacity, never as a proprietary asset. The full sovereignty commitments in §1.5.6 (Corporate Transactions) and §1.5.7 (Insolvency and Wind-Down) apply - including successor undertakings to be bound by this Notice, patient-notification rights with a meaningful opportunity to exercise portability or erasure before transition, and, in insolvency, appointment of a consumer privacy ombudsman where required by applicable law. Patient Personal Data and PHI shall not be treated as a "for-sale" asset of any estate. Where no Qualified Successor Operator can be identified, patient data is returned or exported to the patient and thereafter deleted from ALEX systems in accordance with applicable clinical-record retention law.
7.7 With Professional Advisers
Auditors, lawyers, insurers, and accountants where necessary to obtain professional advice, under confidentiality obligations.
7.8 We Do Not Sell Personal Data
We do not "sell" Personal Data as that term is defined under the California Consumer Privacy Act / California Privacy Rights Act (see Annex A) or analogously under other laws.
Part 8 - Sub-Processors
The current list of sub-processors is maintained at Appendix 1 to this Notice. Categories of sub-processor include:
| Category | Purpose |
|---|---|
| Cloud infrastructure (regional hosting) | Compute, storage, database, network |
| Managed database services | Primary and analytics data stores |
| CDN & DDoS protection | Network performance and security |
| Email & transactional messaging | Notifications, receipts, security alerts |
| SMS & WhatsApp/LINE gateways | Patient reminders and OTP delivery |
| Payment processing | PCI DSS Level 1 processors - we do not store card PAN |
| Analytics (product & marketing) | Usage understanding and A/B testing (de-identified) |
| Customer support tooling | Ticketing, in-app messaging |
| Identity verification / KYB / KYC | Onboarding checks for Tenants and, where required, patients |
| AI/ML infrastructure | Model hosting, training compute (de-identified or synthetic data by default) |
| Backup & disaster recovery | Cross-region recovery |
| Security & SIEM | Threat detection, incident response |
| E-signature | Contract execution |
We disclose the specific provider identity, function, and processing location for each sub-processor in Appendix 1. Data subjects may request the current list by emailing dpo@alexcare.tech.
Part 9 - International Data Transfers
9.1 Data Residency Position
Wherever feasible, we host data in the region of the data subject and the Tenant - for example, ASEAN Tenant patient data in Singapore or Malaysia data-region availability zones. Certain global services (identity federation, aggregate telemetry, security threat intelligence) are inherently cross-border.
9.2 Transfer Mechanisms
Where cross-border transfer occurs, we rely on the following mechanisms as applicable to the sending jurisdiction:
| Sending Region | Mechanism(s) |
|---|---|
| EEA / UK | (i) Adequacy Decision where available; (ii) EU Standard Contractual Clauses (2021 modules) with Transfer Impact Assessment; (iii) UK IDTA or UK Addendum to EU SCCs; (iv) Binding Corporate Rules (upon approval - in progress); (v) Art. 49 derogations only in limited circumstances |
| Switzerland | Swiss Federal Data Protection and Information Commissioner-approved SCCs |
| Singapore | Transfer conditions under PDPA s.26 read with the PDP Regulations - comparable-standard contracts; ASEAN Model Contractual Clauses where in use; consent where applicable |
| Thailand | PDPA s.28–29 - adequacy per PDPC list; standard contractual clauses; explicit consent for cross-border transfer of Sensitive Personal Data with material-risk disclosure |
| Malaysia | PDPA s.129 whitelist compliance (under the 2024 amendment framework); consent; adequate safeguards |
| Philippines | NPC Circular 20-03 (or successor) cross-border transfer requirements; contractual safeguards; accountability principle enforcement |
| United States | HIPAA-compliant BAA flow-downs; state-law transfer conditions where applicable |
| Other | Equivalent mechanisms under Applicable Data Protection Law |
9.3 Countries We May Transfer To
Personal Data may be transferred to and processed in: Singapore, Malaysia, Thailand, Philippines, Indonesia, Vietnam, Japan, Australia, Hong Kong, India, the United States, the United Kingdom, Ireland, Germany, the Netherlands, and other countries where our sub-processors operate. The processing-country for each sub-processor is disclosed in Appendix 1.
9.4 Transfer Impact Assessments
For each transfer channel, we maintain a Transfer Impact Assessment addressing (a) the specific transfer, (b) applicable third-country law and practice, (c) contractual, technical and organisational safeguards, and (d) any supplementary measures. Available to competent authorities on request.
Part 10 - Retention
We retain Personal Data only for as long as necessary for the purposes described in Part 5, subject to legal and regulatory minimum-retention requirements. The category-level retention rules set out in the table below constitute our Data Retention Schedule for the purposes of this Notice:
| Category | Retention Rule |
|---|---|
| Patient clinical record / PHI held for a Tenant | Retained per the Tenant's clinical-record retention policy and applicable state, federal, and country medical-record retention law. Note: HIPAA does not prescribe a medical-record retention period; the six-year HIPAA retention period at 45 CFR § 164.530(j) applies to specified compliance documentation - policies, procedures, authorisations, accounting-of-disclosures logs, and BAA records - and not to the underlying medical record. State medical-record laws often require 7–25 years post last encounter; SG Private Hospitals & Medical Clinics Act - 6 years from last consultation, 25 years for minors from age of majority; TH - 5 years from last treatment as a floor, longer for specific record classes; MY - per MOH Circulars; PH - per DOH Administrative Order. |
| Patient identity and consent records held through the Patient Application | For the duration of the active patient account plus 6 years post-closure for legal defensibility, unless a data-subject deletion request is exercised and no legal hold applies |
| Tenant workforce authentication logs | 12 months rolling for operational logs; 6 years for security incident forensic logs |
| Corporate marketing leads | 24 months post last engagement; consent-based email marketing consent refreshed per applicable law |
| Billing & financial records | 7 years (US IRS / SG IRAS / applicable tax authority) - some regions require 10 years |
| Cookies | Per-cookie duration disclosed in the Cookie Policy |
| Backups | Encrypted backups purged on the 35-day rolling window unless subject to legal hold |
| De-identified / aggregated datasets | Indefinite for legitimate research and platform improvement purposes; identifiable data purged per category rule above |
Where a data subject requests erasure, we apply the request across primary systems, backups within the backup rotation window, and sub-processors - subject to (a) legal-hold exceptions, (b) HIPAA record-retention duties held by the Covered-Entity Tenant (a Business Associate cannot delete PHI unilaterally against a Covered Entity's retention obligation), and (c) freedom-of-expression exceptions where applicable.
Part 11 - Security Measures
We implement technical and organisational security measures commensurate with the risk to Personal Data and PHI. Certifications and assessments are listed in Section 11.7. High-level control set:
11.1 Governance
- Named Chief Information Security Officer accountable to the Board.
- ISMS aligned with ISO/IEC 27001 and ISO/IEC 27701.
- HIPAA Security Rule Administrative, Physical, and Technical Safeguards (45 CFR §§ 164.308, 164.310, 164.312) implemented.
- SOC 2 Type II audit programme initiated; independent audit targeted for Q4 2028 (see §11.7). No SOC 2 Type II report is currently available.
11.2 Access Controls
- Role-based access control across primitives and services.
- Multi-factor authentication mandatory for all workforce, admin, and privileged Tenant accounts.
- Just-in-time privileged access with approval workflow and time-bound elevation.
- Zero-trust network architecture; workload identity for service-to-service authentication.
- Minimum-necessary access principle enforced through service-level scope tokens.
11.3 Encryption
- Data-in-transit: TLS 1.3 (TLS 1.2 permitted only for legacy Tenant integrations under a documented exception).
- Data-at-rest: AES-256 with envelope encryption using a customer-controlled Key Management Service for eligible Enterprise Tenants.
- End-to-end encryption available for specified sensitive communications channels.
- Cryptographic modules FIPS 140-2 (transitioning to FIPS 140-3) validated where applicable.
11.4 Payment Data
- PCI DSS scope minimised - no full PAN storage; tokenisation at PCI Level 1 processor; ALEX systems are Merchant / Service Provider scope with SAQ D (or full RoC where required).
11.5 Monitoring, Logging and Response
- Centralised SIEM with 24×7 monitoring.
- Immutable audit logs for PHI/Personal Data access.
- Documented incident-response plan tested at least annually.
- Vulnerability management with defined SLA windows (Critical: 7 days; High: 30 days; Medium: 90 days).
- External penetration test at least annually; targeted testing on material feature launches.
11.6 Personnel
- Background checks for personnel with PHI/Personal Data access (subject to local law).
- Mandatory annual privacy and security training with role-specific modules.
- Contractual confidentiality obligations survive termination.
11.7 Certifications & Attestations
| Framework | Status |
|---|---|
| SOC 2 Type II | Programme initiated; independent audit targeted for Q4 2028. No completed report currently available. |
| ISO/IEC 27001 | ISMS designed to ISO/IEC 27001 controls; certification audit targeted for Q4 2028. Not yet certified. |
| HIPAA Security Rule Attestation | Self-attested compliance; independent third-party assessment targeted for Q4 2028. |
11.8 Limitations
No security system is impenetrable. While we take substantial measures to protect Personal Data, we cannot guarantee absolute security. Where we identify a Personal Data Breach affecting your data, we follow Part 12.
Part 12 - Data Breach Notification
We maintain an incident-response programme that identifies, contains, investigates and notifies Personal Data Breaches consistent with legal requirements across jurisdictions.
| Jurisdiction | Notification Rule |
|---|---|
| GDPR / UK GDPR | Supervisory authority within 72 hours of becoming aware, where the breach is likely to result in risk to rights and freedoms; data subjects "without undue delay" where high risk |
| PDPA-SG | Personal Data Protection Commission notification within 3 calendar days where significant harm or scale threshold met; affected individuals as soon as practicable |
| PDPA-TH | PDPC (Thailand) notification within 72 hours where risk to rights and freedoms; affected data subjects where high risk |
| PDPA-MY | Personal Data Protection Commissioner notification per 2024 Amendment Act - 72 hours; affected data subjects where required |
| DPA-PH | NPC notification within 72 hours of knowledge/reasonable belief; affected data subjects; where 100+ affected, published notice may be required |
| HIPAA / HITECH | Individuals: within 60 days of discovery; HHS Secretary: annually for breaches <500, within 60 days for breaches ≥500; media: for breaches ≥500 in a state/jurisdiction. Business Associate obligation to notify Covered Entity within 60 days of discovery (contractually shorter - see BAA) |
| Others | Per Annex G |
Notification content includes: nature of the breach, categories and approximate numbers of individuals and records concerned, name and contact of the DPO, likely consequences, measures taken or proposed, and recommended protective steps for affected individuals.
Part 13 - Your Rights
The rights available to you depend on the jurisdiction whose law applies to the Processing. Full jurisdictional detail appears in the Annexes. Common core:
Sovereignty framing: the rights described in this Part 13 are the operational expression of the Patient Data Sovereignty commitment in §1.5. They are inalienable in substance - no term of any contract between ALEX and any Tenant, Partner, sub-processor, or successor derogates from them, and no assertion of ownership by any such party defeats them. ALEX supports the exercise of these rights on a good-faith, plain-language, free-of-charge basis (for the first request in any 12-month period), with proportionate identity verification and within the statutory response windows below.
13.1 Right to Be Informed
You have the right to know we are processing your data, why, and how - the purpose of this Notice.
13.2 Right of Access
You may obtain confirmation whether we process your data, a copy of your data, and prescribed metadata.
13.3 Right to Rectification / Correction
You may require inaccurate data to be corrected and incomplete data completed.
13.4 Right to Erasure / Deletion ("Right to be Forgotten")
You may request deletion of your data, subject to exceptions (legal-obligation retention; freedom of expression; public interest in health / research / archiving; establishment, exercise or defence of legal claims; Covered-Entity retention duties over PHI).
13.5 Right to Restrict Processing
You may require Processing to be paused during accuracy disputes, unlawful-processing claims, or when we no longer need data but you require it for legal claims.
13.6 Right to Data Portability
You may receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller. For patient data held through the Platform, this right is supported by FHIR R4 export.
13.7 Right to Object
You may object to Processing based on legitimate interests, including profiling; you have an absolute right to object to direct marketing.
13.8 Rights in Relation to Automated Decision-Making
As described in Part 6.2.
13.9 Right to Withdraw Consent
Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing. In-application controls in the Patient Application provide granular consent management through our consent-management system.
13.10 Right to Lodge a Complaint
You may complain to your supervisory authority. Contact details in Annexes.
13.11 How to Exercise Your Rights
- Free of charge for the first request in any 12-month period (except where manifestly unfounded or excessive, in which case a reasonable fee may apply or the request may be refused).
- Identity verification proportionate to the request - we ask for information reasonably necessary to confirm identity, and no more. We do not require notarised documents unless the sensitivity of the request and the applicable law makes it strictly necessary.
- Response time - one month under GDPR (extendable +2 months for complex requests with notice); 30 days under PDPA-SG and DPA-PH; 30 days under HIPAA (extendable +30 days); shorter statutory windows honoured where applicable.
- Submission channels - email privacy@alexcare.tech; in-application request flow within the Patient Application and the Tenant Application; and postal request to the addresses in §1.2.
- No adverse consequences for exercising your rights.
Part 14 - Children and Minors
We do not knowingly collect Personal Data directly from children under the age of digital consent applicable in the jurisdiction (US COPPA: under 13; EEA: 13–16 as set by member state; UK: 13; SG: 13 per PDPC guidance; TH: 20 as age of majority with parental consent below; MY: 18; PH: 18). Where children's health data is processed by a Tenant configuring paediatric care workflows on the Platform, the Tenant is the Controller and administers parental / guardian consent under its own care governance. Patient Application accounts are subject to age-appropriate design principles and, where opened for minors, are controlled through parent / guardian custodial accounts.
If we learn that we have inadvertently collected Personal Data directly from a child in breach of applicable law, we will delete it promptly. Contact privacy@alexcare.tech.
Part 16 - Third-Party Sites and Integrations
Our services may link to, or integrate with, third-party sites and services - including government health portals, payer systems, insurer portals, e-signature providers, and app-store deep links. Third parties operate under their own privacy notices; we accept no responsibility for third-party privacy practices. However, where we integrate third-party services on your behalf in delivering ALEX, we perform due diligence and, where the third party processes your Personal Data at our instruction, we impose contractual data-protection obligations.
Part 17 - Changes to This Notice
17.1 Cadence
This Notice is reviewed at least annually. Material changes are announced with a minimum of 30 days' advance notice; non-material updates (typographical corrections, clarifications, sub-processor list refreshes) take effect on publication with the updated Effective Date.
17.2 Notice Channels
- Effective Date, Last Updated date, and Version updated in the header metadata block at the top of this Notice.
- Change summary added to Appendix 2 (Change Log).
- Material changes emailed to registered account holders and posted as an in-app notification.
- Machine-readable change log at
/privacy-notice.jsonldwill be provided for automated policy-monitoring tools once implemented.
17.3 Prior Versions
Prior versions will be retained at alexcare.tech/privacy/archive for at least 6 years once the archive page is published; in the interim, prior versions are available on request via dpo@alexcare.tech.
17.4 Translations
As at the Effective Date, this Notice is published in English. Localised versions in the primary language of each operating country will be published as ALEX Tech Pte. Ltd. onboards operations in that country, and will be updated in accordance with §17.1. In the event of conflict between the English original and a localised version, the English original prevails except where local law mandates the local-language version prevail (see Annexes D, E, F). Translation requests may be sent to dpo@alexcare.tech.
Part 18 - Contact Us and Our DPO
| Contact Purpose | Channel |
|---|---|
| Data Protection Officer (Group) | Yakin Patel · dpo@alexcare.tech · postal: ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422 |
| US HIPAA Privacy Officer | hipaa-privacy@alexcare.tech |
| EEA Representative under GDPR Art. 27 | Not currently applicable - ALEX Tech Pte. Ltd. does not, as at the Effective Date, offer the Platform to data subjects in the EEA on a targeted basis, nor monitor their behaviour in the EEA, within the meaning of Art. 3(2) GDPR. An Art. 27 representative will be designated and this Notice updated before any such targeting commences. Data subjects in the EEA may in the interim contact us at eu-rep@alexcare.tech. |
| UK Representative under UK GDPR Art. 27 | Not currently applicable - ALEX Tech Pte. Ltd. does not, as at the Effective Date, offer the Platform to data subjects in the UK on a targeted basis, nor monitor their behaviour in the UK, within the meaning of Art. 3(2) UK GDPR. A UK GDPR Art. 27 representative will be designated and this Notice updated before any such targeting commences. Data subjects in the UK may in the interim contact us at uk-rep@alexcare.tech. |
| Singapore DPO | Yakin Patel (same appointee as Group DPO) · dpo-sg@alexcare.tech · postal: ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422 |
| Thailand DPO | dpo-th@alexcare.tech |
| Malaysia DPO | dpo-my@alexcare.tech |
| Philippines DPO | dpo-ph@alexcare.tech |
| General Privacy Enquiries | privacy@alexcare.tech |
| Security Vulnerability Reports | security@alexcare.tech. A PGP-signed disclosure channel and a security.txt file at alexcare.tech/.well-known/security.txt will be published once available. |
Annex A - United States (HIPAA / HITECH / State Laws / CCPA-CPRA)
A.1 HIPAA / HITECH Framework
ALEX Tech Pte. Ltd. (through its US operating vehicle where established for US market activity) operates as a Business Associate (or Business Associate Subcontractor) of US Covered Entity Tenants. Business Associate Agreements meeting 45 CFR § 164.504(e) are executed by ALEX Tech Pte. Ltd. or the relevant ALEX Tech US operating vehicle, and not by ArcNovo Tech Inc. (which is the IP owner and licensor of the Platform and is not a Business Associate - see §1.6). ALEX Tech complies with the HIPAA Privacy Rule (45 CFR Part 164 Subpart E) to the extent obligated by HIPAA and by contract, and with the Security Rule (Subpart C) in full. HITECH breach notification obligations at 45 CFR § 164.410 apply - see Part 12.
A.2 Notice of Privacy Practices (NPP)
The NPP required under 45 CFR § 164.520 is issued by each Covered Entity Tenant - not by ALEX - because the NPP is the Covered Entity's obligation. Where you receive care from an ALEX Tenant, ask the Tenant for its NPP. Where ALEX operates as a Covered Entity in respect of any direct-to-consumer offering (for example, certain patient-facing healthcare functions of the Platform offered to a patient directly and without a Tenant relationship), the ALEX NPP will be published at alexcare.tech/notice-of-privacy-practices once that page is available; in the interim, a copy of the current NPP is available on request via hipaa-privacy@alexcare.tech.
A.3 State Laws
We recognise the following US state laws as applicable where their preconditions are met:
- California: CCPA/CPRA - see A.4.
- Virginia: Virginia Consumer Data Protection Act (VCDPA).
- Colorado: Colorado Privacy Act (CPA).
- Connecticut: Connecticut Data Privacy Act (CTDPA).
- Utah: Utah Consumer Privacy Act (UCPA).
- Texas: TDPSA; Texas Medical Records Privacy Act.
- Washington: My Health My Data Act (MHMDA).
- New York: SHIELD Act; anticipated NY Health Information Privacy Act.
- Other US state comprehensive privacy laws as they take effect.
A.4 California Notice (CCPA/CPRA)
- Categories of Personal Information collected - see Part 3 mapped to CCPA §1798.140(v) categories.
- Sources - directly from you; from your Tenant; from public records where lawful; from service providers.
- Purposes - Part 5.
- Sharing / "Sharing" for cross-context behavioural advertising - we do not "sell" or "share" PI as those terms are defined under the CPRA. We do not process Sensitive Personal Information for inferences beyond authorised purposes.
- Rights: Right to know / right of access / right to correct / right to delete / right to opt-out of sale-or-sharing (we do not sell or share; the toggle is nonetheless available) / right to limit use of Sensitive PI / right against retaliation.
- How to exercise: privacy@alexcare.tech. A "Your California Privacy Rights" footer link and a CCPA/CPRA sale/share opt-out control will be added to the site once implemented; in the interim, all California rights requests may be submitted to privacy@alexcare.tech.
- Authorised agents - accepted with verification.
- Retention notice - Part 10 satisfies the CCPA disclosure requirement.
A.5 Health-Specific
For Washington MHMDA and analogous consumer-health-data laws, we do not collect or process "consumer health data" outside of a HIPAA-covered relationship without the geolocation-and-consent-and-disclosure regime prescribed. Geofencing around healthcare facilities is not conducted.
A.6 No Ownership of PHI under HIPAA
HIPAA does not confer "ownership" of PHI on Covered Entities or Business Associates in any commercial sense. Older healthcare-vendor and provider contracts sometimes assert that "the provider owns the medical record"; that assertion, insofar as it purports to derogate from patient rights under 45 CFR §§ 164.524 (access), 164.526 (amendment), 164.528 (accounting of disclosures), 164.522 (restriction and confidential communications), and 164.508 (authorisation for uses beyond TPO), is not enforceable against those rights. The custodial and record-integrity obligations of a Covered Entity under HIPAA and state medical-record law run to the patient (and to the licensing regulator) - not against the patient's underlying substantive rights. ALEX Tech Pte. Ltd. (or its US operating vehicle), as Business Associate, does not assert ownership of PHI; every US Tenant BAA includes a mirror non-ownership acknowledgement per §1.5.3.
A.7 Bankruptcy - Consumer Privacy Ombudsman
In any US Chapter 11 sale or § 363 asset disposition by ALEX Tech Pte. Ltd. (or its US operating vehicle) or by any US Tenant that would involve personally identifiable information of patients, ALEX Tech will not oppose (and will affirmatively support) the appointment of a Consumer Privacy Ombudsman under 11 U.S.C. § 332, with the objective that any successor operator inherits the sovereignty commitments in §1.5 as a condition of the sale.
Annex B - European Economic Area & United Kingdom (GDPR / UK GDPR)
B.1 Applicability
This Annex applies where the GDPR or UK GDPR applies to Processing - including under Art. 3(2) extraterritorial jurisdiction where we offer services to, or monitor the behaviour of, individuals in the EEA/UK.
B.2 Controller
As stated in §1.2 and §1.6, ALEX Tech Pte. Ltd. is the operational Controller (and, for the patient-sovereign functionality, Joint Controller under Art. 26 with the patient) in respect of Processing described in this Notice. ArcNovo Tech Inc. is the IP owner and licensor of the Platform and is not a Controller, Processor, or Joint Controller for any such Processing (see §1.6). The essence of the joint-controller arrangement with the patient is available on request.
B.3 Legal Bases
As set out in Part 4.1.
B.4 EEA and UK Representatives
As at the Effective Date, ALEX Tech Pte. Ltd. does not fall within Art. 3(2) GDPR or Art. 3(2) UK GDPR (targeted offering to, or behavioural monitoring of, EEA / UK data subjects) and accordingly has not designated an Art. 27 representative under GDPR or UK GDPR. If ALEX Tech Pte. Ltd. commences activities that trigger Art. 3(2) of either regime, an Art. 27 representative will be designated in the relevant jurisdiction and this Notice updated. Data subjects in the EEA and UK may in the interim contact us at eu-rep@alexcare.tech and uk-rep@alexcare.tech respectively. ArcNovo Tech Inc. does not have and does not require an Art. 27 representative, as it does not process Personal Data of EEA / UK data subjects in the ordinary course (see §1.6).
B.5 International Transfers
As set out in Part 9. EU SCCs (2021), UK IDTA / Addendum, and Transfer Impact Assessments are used.
B.6 Data Subject Rights
The full suite of GDPR rights (Art. 15–22, 77) is honoured - see Part 13. The right to lodge a complaint may be exercised with any EEA supervisory authority. Because ALEX Tech Pte. Ltd. has no establishment in the EU and does not, as at the Effective Date, engage in Processing falling within Art. 3(2) GDPR, the one-stop-shop mechanism (Art. 56 GDPR) does not apply. If and when ALEX Tech Pte. Ltd. establishes an EU main establishment or commences Art. 3(2)-triggering activities, the applicable lead supervisory authority will be identified and this Notice updated. In the interim, data subjects in the EEA may lodge a complaint with the supervisory authority in their Member State of residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
B.7 DPIA
For high-risk processing (large-scale health data processing; systematic monitoring; automated decision-making - GDPR Art. 35), we have completed Data Protection Impact Assessments. Summaries available on request; full DPIAs available to supervisory authorities.
B.8 EU AI Act Positioning
See Part 6.4.
Annex C - Singapore (PDPA)
C.1 Applicability
Applies to Processing subject to the Personal Data Protection Act 2012 (as amended) and the PDP Regulations.
C.2 Organisation
ALEX Tech Pte. Ltd. is the sole "organisation" for PDPA-SG purposes in respect of Personal Data collected, used, or disclosed through the ALEX Platform. ArcNovo Tech Inc. is the IP owner and licensor of the Platform and is not an "organisation" for such Processing (see §1.6).
C.3 Data Protection Officer
Our DPO for Singapore is Yakin Patel (also the Group DPO), contactable at dpo-sg@alexcare.tech or by post at ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422. This satisfies s.11(3) and the Notification Obligation.
C.4 Consent, Notification, Purpose
We provide notification of purposes at or before collection (s.20). We rely on consent (s.13–17), deemed consent by notification (s.15A) for compatible secondary purposes, the legitimate-interests exception (First Schedule Part 3) for security and business improvement, and other statutory exceptions as applicable.
C.5 NRIC / FIN Handling
We follow the PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers - collecting NRIC/FIN only where required by law, permitted under narrow exceptions (e.g., verifying identity for high-risk transactions), or where the individual has given specific consent.
C.6 Do Not Call Registry
For marketing communications via voice, SMS or fax, we check the Do Not Call Registry before contacting and maintain the required records.
C.7 Data Breach Notification
Notification to the PDPC and affected individuals per the Notifiable Data Breach regime - see Part 12.
C.8 Cross-Border Transfer
Governed by s.26 read with Reg 10 of the PDP Regulations - comparable-standard contracts, ASEAN MCCs where used, and additional safeguards for Sensitive Personal Data.
C.9 Rights of Data Subjects
- Access (s.21) - first request free of charge (fee only where request is excessive).
- Correction (s.22).
- Withdrawal of consent (s.16).
- Data portability: the Singapore PDPA data-portability obligation (introduced by the 2020 amendment and codified at Part 6B) will take effect only upon issuance of implementing regulations by the Singapore Government; as at the Effective Date, no such implementing regulations are in force, and no statutory data-portability right is currently exercisable against ALEX Tech Pte. Ltd. under PDPA-SG. As a matter of platform commitment, ALEX Tech Pte. Ltd. voluntarily supports a data-export capability for Personal Data held about a Singapore data subject on request via dpo-sg@alexcare.tech; this voluntary capability is distinct from the statutory right and does not amount to a waiver, admission, or expansion of the statutory position.
C.10 Complaints
PDPC, pdpc.gov.sg.
Annex D - Thailand (PDPA B.E. 2562)
D.1 Applicability
Applies where the PDPA-TH applies, including extraterritorially where we offer services to data subjects in Thailand or monitor their behaviour.
D.2 Local Presence
Under s.37(5) of the Thailand PDPA, ALEX Tech Pte. Ltd. has designated ArcNovo Tech (Thailand) Co. Ltd., acting in its capacity as authorised distributor of the Platform for ALEX Tech Pte. Ltd., as its local representative in Thailand. ArcNovo Tech (Thailand) Co. Ltd. is a Thai-incorporated commercial distributor and is a separate and independent legal entity from ArcNovo Tech Inc. (the Wyoming corporation identified in §1.2 and §1.6); ArcNovo Tech Inc. has no ownership interest, control interest, or corporate relationship with ArcNovo Tech (Thailand) Co. Ltd., and the two entities share no common personal-data Processing role. Data subjects in Thailand and the Thailand Personal Data Protection Committee (PDPC) may contact the local representative through dpo@alexcare.tech, which is the published channel routed to the Group Data Protection Officer, who liaises with the local representative for statutory obligations under s.37(5).
D.3 DPO
Under s.41, appointed given the scale of Sensitive Personal Data processing. Contact dpo-th@alexcare.tech.
D.4 Legal Bases
- Non-sensitive Personal Data: bases in s.24.
- Sensitive Personal Data (health data, biometric, etc.): explicit consent under s.26 unless s.26 exceptions apply.
D.5 Language
As at the Effective Date, this Notice is published in English. A Thai-language version of this Notice, and Thai-language consent forms and rights-exercise workflows, will be published before onboarding of any additional Thai patients or data subjects beyond current customers served through ArcNovo Tech (Thailand) Co. Ltd.'s Platform distribution. Where a Thai translation is subsequently published and conflicts with the English original, the Thai translation prevails to the extent required by Thai law and PDPC guidance. In the interim, Thai-speaking data subjects may contact dpo@alexcare.tech for assistance in Thai.
D.6 Cross-Border Transfer
Per s.28–29 - adequacy assessment, contractual safeguards, or explicit consent with material-risk disclosure.
D.7 Rights
As set out in Part 13, given effect through PDPA-TH Chapter 3.
D.8 Complaints
PDPC Thailand, pdpc.or.th.
Annex E - Malaysia (PDPA 2010 as Amended 2024)
E.1 Applicability
Applies where PDPA-MY applies, including under the 2024 Amendment Act extraterritorial provisions.
E.2 Registration
Where ALEX Tech Pte. Ltd. or a future Malaysian subsidiary falls within a registrable class of data controllers under Malaysian law, that entity will obtain the required registration before commencing the applicable processing.
E.3 DPO
Appointed per the 2024 amendment, contactable at dpo-my@alexcare.tech.
E.4 Consent and Sensitive Data
Explicit consent obtained for Sensitive Personal Data (s.40).
E.5 Language
As at the Effective Date, this Notice is published in English. A Bahasa Malaysia version of this Notice will be published together with English-language operations in Malaysia in compliance with PDPA-MY s.7(3), before onboarding of any Malaysian data subjects. Where the Bahasa Malaysia version is subsequently published and Malaysian law requires the BM version to prevail, the BM version prevails. Translation requests may be sent to dpo@alexcare.tech.
E.6 Cross-Border Transfer
Per s.129 (and the 2024 amendment framework) - whitelist compliance, consent, adequate safeguards.
E.7 Breach Notification
Per 2024 amendment - 72 hours to the Commissioner where required - see Part 12.
E.8 Data Portability
Per the 2024 amendment - supported by FHIR R4 export from the Platform.
E.9 Rights
As Part 13.
E.10 Complaints
JPDP, pdp.gov.my.
Annex F - Philippines (Data Privacy Act 2012, RA 10173)
F.1 Applicability
Applies where DPA-PH applies. As data controllers processing Sensitive Personal Information of Filipino data subjects and operating through Filipino Tenants, we register with the NPC.
F.2 NPC Registration
DPS registration and DPO appointment are on file with NPC.
F.3 DPO
F.4 Legal Bases
Sensitive Personal Information (health) processed only under s.13 bases - consent; medical treatment carried out by a medical practitioner or medical treatment institution where data subject not legally capable of consent; specific laws; or the protection of lawful rights and interests in court proceedings.
F.5 Cross-Border Transfer
Per NPC Circular 20-03 (or successor) with accountability, contractual safeguards, and impact assessment.
F.6 Breach Notification
72 hours to NPC per NPC Circular 16-03 (as amended) - see Part 12.
F.7 PhilSys / PhilHealth Data
Handled under the PhilSys Act (RA 11055) safeguards and PhilHealth data-sharing rules; only used for the specific service purposes disclosed.
F.8 Rights
As Part 13, given effect through DPA-PH Chapter IV.
F.9 Complaints
NPC, privacy.gov.ph.
Annex G - Other Regions (Australia, Japan, Hong Kong, UAE, KSA, and Others)
G.1 Australia (Privacy Act 1988, Australian Privacy Principles, My Health Records Act)
Where APP applies, we comply with the 13 Australian Privacy Principles, notifiable-data-breach obligations to the OAIC, and (where applicable) the additional My Health Records Act safeguards. Cross-border disclosure per APP 8 with accountability. Contact: OAIC, oaic.gov.au.
G.2 Japan (APPI)
Where APPI applies, we comply with purpose specification, use limitation, security control, third-party provision restrictions, and rules for cross-border transfer under Chapter 4 Section 3. Requests: PPC, ppc.go.jp.
G.3 Hong Kong (PDPO)
Compliance with Data Protection Principles under Schedule 1. Contact: PCPD, pcpd.org.hk.
G.4 UAE (Federal Decree-Law No. 45 of 2021 - PDPL)
Where PDPL applies (including DIFC/ADGM equivalents where relevant), we comply with the applicable regime and contact the UAE Data Office where required.
G.5 Saudi Arabia (PDPL)
Where KSA PDPL applies, we comply with the applicable regime including data-residency and cross-border transfer conditions administered by SDAIA.
G.6 Other Regions
Where any other data-protection law applies, we implement the required safeguards and provide the specific rights set out in that law. Contact dpo@alexcare.tech.
Appendix 1 - Sub-Processors
This Appendix lists the sub-processors engaged by ALEX Tech Pte. Ltd. to process Personal Data on our behalf, as at the Effective Date. Data subjects and Tenants may request the current version of this list at any time by emailing dpo@alexcare.tech. Material changes to this list are managed under the sub-processor-change process referenced in Part 8 and in Tenant DPAs.
| Sub-processor | Category | Function | Primary Processing Location |
|---|---|---|---|
DigitalOcean, LLC (digitalocean.com) |
Cloud infrastructure | Compute, storage, managed database, and network services for the Platform | Regionally configured; Southeast Asia region used as primary for Platform data of Southeast Asia Tenants and patients |
Stripe, Inc. (stripe.com) |
Payment processing (PCI DSS Level 1) | Card payment processing for international transactions; tokenised - no PAN storage in ALEX systems | Global card networks; Stripe primary processing in the United States and Ireland |
2C2P Pte. Ltd. (2c2p.com) |
Payment processing (PCI DSS Level 1) | Regional Southeast Asia payment processing including local card, wallet, and bank-transfer methods; tokenised - no PAN storage in ALEX systems | Singapore and Southeast Asia |
Amazon Web Services, Inc. (aws.com) |
Email and transactional messaging | Transactional email, notifications, and messaging infrastructure | Regionally configured; Southeast Asia region used as primary for Platform notifications to Southeast Asia recipients |
GoDaddy.com, LLC (godaddy.com) |
Domain registration and email domain services | Domain registration and email-domain services for the alexcare.tech domain and associated mailboxes |
United States |
Cloudflare, Inc. (cloudflare.com) |
Website security and abuse prevention | Turnstile bot detection for Contact Us and Book Demo forms; processor when protecting the website and independent controller when improving Turnstile | Cloudflare global network; processing governed by the applicable Cloudflare agreement and privacy disclosures |
Category coverage note. The categories of sub-processor engagement that may arise as the Platform scales are set out in Part 8. Where a category listed in Part 8 does not appear in this Appendix as at the Effective Date, no sub-processor in that category is currently engaged. This Appendix will be updated before any additional sub-processor in a listed category is engaged for Processing that touches Personal Data.
Appendix 2 - Change Log
| Version | Effective Date | Change Summary |
|---|---|---|
| 1.0 | 30 July 2026 | Initial published version of the ALEX Privacy Notice. |
Where a subsequent version of this Notice makes material changes, the change summary is recorded here in accordance with §17.
End of ALEX Privacy Notice v1.0