Privacy Policy
This Privacy Policy was last updated on 26 February 2025 and applies to all users of Gravity Telehealth.
1. Introduction
Welcome to Gravity Telehealth (“we,” “us,” “our”). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy outlines how we collect, use, store, and share your information when you use our telemedicine services. This Privacy Policy applies to all personal data collected, used, or disclosed in connection with our services, regardless of where data processing occurs.By accessing or using Gravity Telehealth’s services, you acknowledge that you have read, understood, and agreed to be bound by this Privacy Policy. Your continued use of the platform signifies your acceptance of any updates to the policy. If you disagree with any part of this Privacy Policy, you must immediately cease using our services.
Legal Entity: Gravity Telehealth is owned and operated by Clinics Medical Group Pte. Ltd., a Singapore-registered entity. Clinics Medical Group Pte. Ltd. is responsible for collecting and processing personal data under the Personal Data Protection Act (PDPA) of Singapore.
Role of Gravity Telehealth and International Doctors
Clinics Medical Group Pte. Ltd. serves as the “Organisation” under PDPA, determining the purposes and means of processing your personal data. Where doctors based internationally (e.g., the UK) access or process personal data on our behalf, they act as “data intermediaries,” meaning they follow our instructions and the PDPA’s requirements. Clinics Medical Group Pte. Ltd. maintains oversight of data intermediaries through regular audits, contractual obligations, and monitoring to ensure compliance with PDPA requirements. If you have questions, please contact us at support@clinicsmedicalgroup.com
International Doctors and Data Protection Laws
Gravity Telehealth may engage doctors located outside Singapore to provide telemedicine consultations. While these doctors process personal data on our behalf and according to the Personal Data Protection Act (PDPA), they are also independently bound by their respective local data protection and professional regulations. For instance, doctors based in the United Kingdom must comply with the UK General Data Protection Regulation (UK GDPR), in addition to fulfilling their professional confidentiality obligations.
Through our contractual arrangements, we ensure that any international doctors offering services via the Gravity Telehealth platform adhere to standards comparable to the PDPA and to the applicable requirements of their local jurisdictions. If you have any questions about cross-border data handling, please contact us using the details provided in this Privacy Policy.
2. Purpose of Data Collection
We collect, use, and process your personal data to provide secure telemedicine services, including but not limited to:
- Healthcare Services: Conducting consultations, treatment planning, and follow-ups.
- Record Maintenance: Maintaining patient records in compliance with healthcare and regulatory standards.
- Technical Functionality: Supporting platform functionality, enhancing security, and improving our services.
- Legal Compliance: Complying with legal and regulatory obligations under PDPA, and other relevant laws.
- Marketing (with Consent): Sending promotional materials and service updates, where you have opted in to receive such communications.
3. Types of Data Collected
To ensure effective healthcare services, we collect the following types of data:
3(a). Personal Information
Identification Data:
- Full name
- Date of birth
- Gender
- Contact details (email address, phone number, location)
Account Information:
- Username
- Password (securely stored)
3(b). Health Information
Medical History:
- Past medical conditions
- Past medications
- Family medical history
- Any other relevant medical information you choose to provide to facilitate care
Current Health Status:
- Current symptoms and details provided in pre-consultation forms
- Current medications
- Allergies
- Vital signs and measurements
- Ongoing treatments
- Diagnostic images, lab reports, or other medical documents
Consultation Details:
- Consultation notes
- Prescribed medications and treatment recommendations
Emergency Information:
- Emergency contact details
3(c). Technical Data
Device Information:
- Device type (e.g., smartphone, tablet, computer)
- Operating system
Internet Information:
- IP address
- Browser type
Usage Patterns:
- Pages visited
- Time spent on the platform
- Interaction logs (e.g., clicks, navigation paths)
3(d). Sensitive Data
- You may choose to upload genetic test data or other sensitive health information when using our telemedicine services. If you voluntarily provide such genetic data, we will treat it with heightened confidentiality in accordance with applicable data protection laws. Gravity Telehealth processes this information solely to facilitate medical consultations and related healthcare services, ensuring it is accessed only by authorised healthcare professionals.
3(e). Data from Third-Party Sources
- Referral Information: Data from referring healthcare providers
- Insurance Information: Details provided by insurance companies (if applicable)
3(f). Cookies and Tracking Technologies
Types of Technologies That May Be Used:
- Cookies: Small data files stored on your device to enhance user experience and track usage.
- Web Beacons: Transparent images embedded in emails or web pages to monitor user interactions.
- Local Storage: Stores data locally within your browser to remember preferences and settings.
Purposes:
- Essential Cookies: Necessary for the functioning of the platform (e.g., session management).
- Performance Cookies: Collect anonymous data to analyse platform performance and user behaviour.
- Functionality Cookies: Remember your preferences and settings for a personalised experience.
- Advertising Cookies: Track your browsing activities to deliver personalised advertisements (only with your consent).
3(g). User-Uploaded Data
Users may voluntarily upload files, documents, or images (e.g., medical records, prescriptions, or diagnostic reports) to the Gravity Telehealth platform to facilitate consultations or other services. Such data will be securely stored and accessible only to authorised personnel directly involved in providing healthcare services. Gravity Telehealth will not modify or share user-uploaded content with third parties without explicit consent, except as required by law.
4. Legal Basis for Data Processing
We process your personal data based on the following legal grounds:
- Consent:
- For collecting and processing sensitive health information.
- For sending marketing communications (when you have explicitly opted in).
- Contractual Necessity:
- To deliver telemedicine services, including scheduling and conducting consultations.
- Legal Compliance:
- To adhere to obligations under PDPA, and other applicable healthcare regulations.
- Exceptions Permitted by Law: We may process personal data without consent if required for national interest, public security, or legal investigations, as explicitly permitted under the PDPA.
- Legitimate Interests:
- We may process personal data without consent where it is necessary to fulfil legitimate interests, including improving services or ensuring fraud prevention, provided these do not override your rights
- Automated Decision-Making and Profiling (if applicable): :
- Gravity Telehealth does not currently engage in automated decision-making or profiling that significantly affects you. However, we may implement such processes in the future to analyse user interactions, enhance service offerings, and improve user experience. If we adopt automated decision-making or profiling, we will ensure that:
- A valid legal basis (e.g., legitimate interests or explicit consent) applies, and
- Such processing does not override your fundamental rights and freedoms.
- We will update this Privacy Policy accordingly and provide you with information on your rights (such as the right to object) before any automated decision-making processes come into effect.
5. How We Use Your Data
We use your data solely for the following purposes:
- Healthcare Provision:
Facilitating consultations with qualified healthcare providers, including developing and managing treatment plans. - Communication and Marketing Preferences:
- Notifying you about appointments, service updates, and responding to patient inquiries.
- Gravity Telehealth may send you marketing communications, service updates, and promotional materials if you have explicitly opted in to receive such communications.
- Opt-Out Mechanism: You may manage your preferences or withdraw consent for marketing communications at any time through your account settings or by contacting support@clinicsmedicalgroup.com
- No Effect on Core Services: Opting out of marketing communications will not affect your access to core telemedicine services.
- Service Improvement:
Analysing aggregate data (and identifiable data with your consent) for internal analytics, research, and to enhance our services. - Security and Maintenance:
Ensuring platform security and functionality, and conducting regular security audits and vulnerability assessments. - Marketing (with Consent):
Sending promotional materials and service updates based on your preferences. - Customer Support:
Providing user support, responding to inquiries, and troubleshooting technical or service issues. - Automated Decision-Making and Profiling:
Enhancing user experience by personalising content and services based on user behaviour and preferences. - Legal Compliance and Dispute Resolution:
Complying with applicable laws and regulations, cooperating with law enforcement, and handling disputes or legal claims related to our services.
6. Data Sharing and Cross-Border Transfers
6(a). Authorised Professionals
We share your data only with authorised healthcare professionals directly involved in your care. These professionals are bound by strict confidentiality and data protection standards.
6(b). Third-Party Service Providers
We may engage third-party service providers to perform functions on our behalf, including:
- Cloud Storage Providers: For securely storing your medical records.
- Telecommunication Services: To facilitate video consultations.
- Payment Processors: To handle billing and payments. Gravity Telehealth engages trusted third-party payment processors that comply with industry standards, including encryption protocols and secure payment gateways, to protect your financial information. If you have concerns about a payment transaction, contact us at support@clinicsmedicalgroup.com
- Technical Support Services: To maintain and support our platform.
- Marketing Services: To manage and deliver marketing communications (only with your consent).
- Analytics Providers: To analyse platform usage and improve services.
We require these providers to maintain robust data security practices and to:
- Comply with Applicable Data Protection Laws: This includes their local regulations as well as any relevant international requirements, such as Singapore’s Personal Data Protection Act (PDPA).
- Use Data Solely for Agreed Purposes: Third parties may only access and process personal data as necessary to fulfil the services requested by Gravity Telehealth, subject to our instructions.
Where possible, we enter into agreements or impose binding obligations ensuring that these providers implement appropriate technical, administrative, and organisational measures to protect personal data. If you have questions about our third-party service providers or the safeguards we have in place, please contact us using the details provided in this Privacy Policy.
6(c). Cross-Border Data Transfers
Your data may be transferred to and processed in countries outside your jurisdiction, including the United Kingdom and Singapore. These transfers are conducted under appropriate safeguards, including:
- Standard Contractual Clauses (SCCs): Ensuring compliance with GDPR requirements.
- Data Encryption: Encrypting data during transfer to protect against unauthorised access.
- Compliance with PDPA: Verifying that the recipient country maintains a standard of protection comparable to Singapore’s PDPA.
Doctors based outside of Singapore—including in the UK—who access patient data are required to handle it in compliance with their professional licensing obligations and all applicable local data protection laws.
Patient Rights in Cross-Border Transfers:
Patients have the right to:
- Request information about where their data is processed.
- Understand the safeguards in place to protect their data during cross-border transfers.
By using our services, you consent to the international transfer and processing of your personal data under these protective measures.
6(d). Additional International Transfer Mechanisms
- Local Regulations Compliance: Adherence to local data protection laws in jurisdictions where data is processed.
6(e). Disclosures to Legal and Regulatory Bodies
We may disclose your data to government or regulatory bodies when required by law. Such disclosures comply with applicable data protection laws to safeguard your rights and privacy.
7. Data Security Measures
At Gravity Telehealth, we are committed to protecting your personal data through industry-standard security practices and a multi-layered approach to ensure confidentiality, integrity, and availability. Our comprehensive security controls include:
Encryption and Secure Communication
- We use industry-standard encryption to protect all communication between your device and our servers, ensuring that your personal data is transmitted securely and cannot be intercepted or accessed by unauthorised parties.
Access Controls
- Role-based access controls ensure that only authorised personnel with specific permissions can access sensitive personal data. This minimises the risk of unauthorised access and ensures that access is strictly on a need-to-know basis.
Physical Security
- Your data is hosted on AWS servers located in Singapore, which employ stringent physical and network security measures to protect against unauthorised access, breaches, and other risks.
Secure Password Handling
- We take precautions to protect your account. User passwords are never stored in plain text; instead, they are encrypted to ensure that even in the unlikely event of unauthorised access, your actual password remains secure.
Authentication and Account Security
To enhance account security, we have implemented:
- Two-Factor Authentication (2FA): Users are required to verify their identity using a second factor (e.g., an OTP sent via email) during login or sensitive actions.
- One-Time Password (OTP) Verification: OTPs are securely generated and time-limited, reducing the risk of unauthorised access.
Session Management and Mobile App Security
- For additional protection, we enforce screen lock authentication every 5 minutes of inactivity within the mobile app. This requires users to re-authenticate if their session is idle, preventing unauthorised access.
- Secure session management practices are applied to ensure user sessions are properly controlled and monitored.
Regular Security Assessments
- We conduct quarterly audits, penetration testing, and continuous monitoring to identify and mitigate potential security risks. These measures help ensure the ongoing protection and resilience of our systems.
Incident Response Plan
- We have a dedicated team that promptly responds to potential data breaches or security incidents. This team investigates and mitigates risks, ensuring that appropriate measures are taken to protect your personal data.
Ongoing Security Practices
- We continuously monitor and update our systems to stay aligned with evolving security standards and best practices. Our commitment includes regular updates, threat detection, and proactive measures to safeguard your personal data.
8. Data Retention and Deletion
8(a). Data Retention Periods
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this Privacy Policy or as required by law. Gravity Telehealth will delete or anonymise personal data when it is no longer required for business or legal purposes, in compliance with PDPA. The specific retention periods are as follows:
- Health Data and Linked Personal Information:
- Retained for 15 years in compliance with Singapore healthcare regulations. This includes any personal information (e.g., name, contact details, date of birth) that forms part of your medical records.
- Technical Data:
- Retained for 1 year to analyse and improve our services and platform performance. After this period, such data may be anonymised to ensure it no longer identifies you.
- Children’s Data:
- Retained only for as long as necessary to comply with legal requirements, ensure the safety of minors, and provide necessary healthcare services.
8(b). Data Deletion Procedures
- Access Requests:
Patients can request access to their medical records by emailing support@clinicsmedicalgroup.com
We will verify your identity and provide access within 30 days. - Deletion Requests:
To request deletion of your data, contact us at support@clinicsmedicalgroup.com
We will assess your request in line with regulatory retention requirements and inform you of any data that must be retained for legal reasons. - Data Minimisation Commitment:
We are committed to retaining only the data necessary for the specified purposes.
Regular reviews are conducted to ensure compliance with data minimisation principles. - Backup Data:
While primary data is subject to deletion requests, backup data is retained according to our data retention policies and is securely deleted as part of our regular data purging processes.
8(c). Anonymisation of Data
After the legal data retention period or upon user request for deletion, Gravity Telehealth may anonymise personal data for research, statistical analysis, and service improvement. Anonymised data cannot be used to identify any individual and will only be utilised in compliance with applicable laws.
Under Singapore’s Personal Data Protection Act (PDPA), you have the following rights regarding your personal data:
9. Your Data Rights
9(a). Right to Access
You have the right to request access to the personal data we hold about you, including your medical records.
What Can Be Accessed:
You may request access to medical records, such as consultation notes, diagnostic test results, prescriptions, and treatment plans.
Exceptions to Access:
Access may be restricted or certain information may be redacted in the following cases:
- Disclosure could reasonably cause harm to you or others.
- The data includes confidential third-party information.
- The information contains proprietary clinical opinions not directly relevant to your care.
How to Request Access:
- Submit your request to support@clinicsmedicalgroup.com with your full name and contact details.
- We will verify your identity before processing your request and respond within 30 days, or inform you if additional time is required.
9(b). Right to Correction
If any personal data we hold about you is inaccurate or incomplete, you may request that it be corrected.
- How to Request a Correction:
- Contact us at support@clinicsmedicalgroup.com and provide details of the correction required.
- We will update your data as soon as is practical and, if applicable, inform other organisations to which the corrected data was disclosed within the last 12 months.
9(c). Right to Withdraw Consent
You may withdraw your consent for the collection, use, or disclosure of your personal data at any time. Where deemed consent applies (e.g., when you provide personal data for a specified purpose), you will be notified of the purpose and given the option to opt out.
- How to Withdraw Consent:
- Submit your request to support@clinicsmedicalgroup.com with reasonable notice.
- We will inform you of the consequences of withdrawing consent (e.g., reduced access to telemedicine services).
- Upon withdrawal, we will cease to collect, use, or disclose your personal data for the specified purposes, except where required by law (e.g., retaining healthcare records for 15 years as mandated by Singapore regulations).
9(d). Responsibility for Data Accuracy
You are responsible for ensuring that the personal data you provide is accurate and up to date.
- Consequences of Inaccurate Data:
- Providing incorrect or outdated information may affect our ability to deliver telemedicine services effectively.
- Gravity Telehealth reserves the right to suspend or terminate services if inaccuracies are identified.
9(e). Right to Data Breach Notification
In the event of a data breach that is likely to result in significant harm, we will notify you as soon as practicable. We will also provide details about the nature of the breach, the data affected, and the steps you can take to mitigate potential risks.
10. Children's Privacy
Gravity Telehealth does not knowingly collect personal data from children under 18 without parental consent. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@clinicsmedicalgroup.com. We will take steps to delete such information in compliance with legal requirements.
- Parental Consent: Parents or legal guardians must provide verified consent for the collection and processing of data for minors under 18 years old.
- Parental Acknowledgment During Booking: Parents or guardians must acknowledge their consent explicitly during the appointment booking process.
- Parental Control and Access: Parents or guardians are responsible for managing the minor's account and have access to the minor's health information.
- Parental Presence During Consultations: Users under 18 years old must have a parent or legal guardian present during consultations.
- Data Retention: Children’s data will be retained only as long as necessary, in compliance with PDPA regulations.
- Unified Privacy Policy: Updates to this policy apply to all users, including children, and can be reviewed in the app.
11. Cookies and Tracking Technologies
Gravity Telehealth uses cookies to enhance user experience and improve our services. Cookies may collect information such as your browsing preferences and interactions on the platform.
Marketing and Cookies
We require your express consent for cookies that collect personal data for advertising or behavioural tracking purposes. You may adjust your cookie preferences through your browser settings. Please note that disabling certain cookies may affect your experience on our platform.
11(a). Types of Technologies Used
- Cookies: Small data files stored on your device to enhance user experience and track usage.
- Web Beacons: Transparent images embedded in emails or web pages to monitor user interactions.
- Local Storage: Stores data locally within your browser to remember preferences and settings.
11(b). Purposes
- Essential Cookies: Necessary for the functioning of the platform (e.g., session management).
- Performance Cookies: Collect anonymous data to analyse platform performance and user behaviour.
- Functionality Cookies: Remember your preferences and settings for a personalised experience.
- Advertising Cookies: Track your browsing activities to deliver personalised advertisements (only with your consent).
11(c). User Control
- Manage Preferences: You can manage your cookie preferences through your browser settings or via our Cookie Settings page.
12. Storage of Data on Devices
Some data generated by the Gravity Telehealth app may be temporarily stored on your device to enhance performance and user experience. This includes:
- Cached App Data: To improve loading speeds.
- Downloaded Files: Such as consultation summaries or prescriptions, which are stored locally for offline access.
- Temporary Session Data: Used for authentication during active sessions.
Security Measures:
- All locally stored data is encrypted to prevent unauthorised access.
- Temporary data is automatically deleted when no longer needed.
User Responsibility:
- Ensure your device is protected with a passcode or other security measures.
- Avoid accessing your account over unsecured networks.
12. Third-Party Links and Content
Our platform may contain links to third-party websites or services. We do not endorse or assume responsibility for the content or practices of these third parties. Accessing such links is at your own risk, and we recommend reviewing their privacy policies.
- Liability Limitation:
Gravity Telehealth is not liable for any damages or losses resulting from your interactions with third-party content or services. - Third-Party Analytics:
We may use third-party analytics services (e.g., Google Analytics) to monitor platform usage. These services may collect information about your interactions with the platform.
13. Data Breach Response Plan
In the event of a data breach, Gravity Telehealth will take the following steps to mitigate risks and protect your data:
- Immediate Containment:
Identify and contain the breach to prevent further unauthorised access. - Assessment:
Assess the scope and impact of the breach, including the types of data affected and the number of users impacted. - Notification:
Notify affected individuals as soon as practicable following becoming aware of the breach, as required by PDPA.
Provide clear information about the nature of the breach, the data affected, and the steps being taken to address it. - Remediation:
Implement measures to prevent similar breaches in the future.
Review and update security protocols and policies as necessary. - Regulatory Reporting:
Gravity Telehealth will notify the PDPC within three calendar days of assessing a notifiable breach and inform affected individuals as soon as practicable. - Support for Affected Users:
Offer support services to affected users, if necessary.
14. Data Protection Officer (DPO)
Gravity Telehealth has appointed a Data Protection Officer (DPO) responsible for ensuring compliance with the PDPA, addressing queries, and managing data protection measures. If you have any questions, concerns, or inquiries about how Gravity Telehealth handles your personal data, please contact our Data Protection Officer (DPO):
- Email: support@clinicsmedicalgroup.com
For further information about data protection in Singapore, you may visit the website of the Personal Data Protection Commission (PDPC):
- Website: www.pdpc.gov.sg
15. Automated Decision-Making and Profiling
15(a). Information on Automated Processes
If Gravity Telehealth utilises automated decision-making or profiling processes, we ensure transparency and fairness:
- Purpose:
Enhancing user experience by personalising content and services based on user behaviour and preferences. - Nature of Processing:
Analysis of user interactions to tailor recommendations and improve platform functionality. - Impact on Users:
These processes are designed to benefit users by providing a more personalised and efficient service. They do not significantly affect your rights and freedoms.
15(b). User Rights Related to Automated Decision-Making
- Right to Information: You have the right to be informed about any automated decision-making processes that significantly affect you.
- Right to Contest: You can contest any decisions made through automated processes by contacting us at support@clinicsmedicalgroup.com
16. Force Majeure
Gravity Telehealth shall not be liable for any failure or delay in performing its obligations due to circumstances beyond its reasonable control, including but not limited to acts of God, war, pandemics, or governmental actions.
17. Compliance with Export Control and Sanctions
Users represent and warrant that they are not located in, under the control of, or a national or resident of any country subject to economic sanctions or on any denied party listing. Gravity Telehealth reserves the right to restrict services in compliance with international sanctions.
18. Assignment of Terms
- Rights to Assign:
Gravity Telehealth may assign or transfer its rights and obligations under these Terms to any third party without your consent. - User Assignment:
Users may not assign their rights without prior written consent from Gravity Telehealth.
19. Severability and Waiver
- Severability:
If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect. - Waiver:
The failure of Gravity Telehealth to enforce any right or provision of this Privacy Policy shall not constitute a waiver of such right or provision.
20. Entire Agreement
This Privacy Policy constitutes the entire agreement between you and Gravity Telehealth regarding the use of personal data and supersedes all prior agreements.
21. Changes to Services
Gravity Telehealth reserves the right to modify or discontinue the platform or any services at any time, temporarily or permanently, with or without notice.
22. Notices
We may provide notices to users via email or postings on the platform. Users are responsible for maintaining accurate contact information to receive these notices.
23. Governing Language
This Privacy Policy is written in English. If translated into another language, the English version shall prevail in the event of a conflict.
24. Governing Law and Jurisdiction
These Terms are governed by the laws of Singapore, without regard to conflict of law principles. Any disputes shall be resolved exclusively in the courts of Singapore.
25. No Agency Relationship
Nothing in this Privacy Policy shall be construed to create a partnership, joint venture, or agency relationship between you and Gravity Telehealth. Parties are independent contractors.
26. Conflict Resolution Between Documents
In the event of any conflict between this Privacy Policy and any other policies or agreements, this Privacy Policy shall prevail unless expressly stated otherwise.
27. Health Insurance Portability
Gravity Telehealth does not handle insurance claims or communicate with insurance providers on behalf of Patients. Users are responsible for managing their own health insurance matters where relevant.
28. Advertising and Promotions
- Advertising:
Gravity Telehealth may display advertisements on the platform. Users agree that Gravity Telehealth may use certain information for advertising purposes in accordance with our Privacy Policy. - Consent for Communications:
User consent for marketing communications will be obtained separately. Users may opt out at any time.
29. Feedback and Intellectual Property
Any feedback or suggestions provided by users regarding the platform are entirely voluntary. Gravity Telehealth is free to use such feedback without any obligation or compensation to the user.
30. Changes to the Privacy Policy
Gravity Telehealth reserves the right to update or modify this Privacy Policy at any time to reflect changes in legal, technical, or business requirements.
- Notification: Users will be notified of significant changes through in-app notifications.
- Acceptance of Changes: Continued use of the platform after notification constitutes acceptance of the updated Privacy Policy.
- Review Period: Users are encouraged to review the updated policy within 30 days of receiving the notification.
31. Final Notes
By using Gravity Telehealth's services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. Your privacy is important to us, and we are committed to protecting your personal data with the highest standards of security and confidentiality.
Effective Date: 26 February 2025
This Privacy Policy is effective as of 26 February 2025.