Legal
ALEX Privacy Notice
How the ALEX platform collects, uses, discloses, transfers, retains, and protects personal data.
On this page · 28 sections
Part 1 - About This Notice
1.1 Purpose
This Privacy Notice ("Notice") explains how the ALEX platform ("ALEX", the "Platform") collects, uses, discloses, transfers, retains and protects Personal Data and, where applicable, Protected Health Information ("PHI"), and describes the rights available to individuals in respect of their data.
For simplicity, this Notice uses "ALEX", "we", "us", and "our" to refer to the Platform and to the entity that operates it. That entity is ALEX Tech Pte. Ltd. and its country subsidiaries, as identified in §1.2. ALEX Tech Pte. Ltd. is the sole entity that Processes Personal Data and PHI in connection with the Platform, and the sole entity against which the commitments in this Notice run.
1.2 Who We Are
| Entity | Role | Registered Address | Contact |
|---|---|---|---|
| ALEX Tech Pte. Ltd. | Singapore private limited company (UEN 202308966D); sole global operating entity for the ALEX Platform; contracts with Tenants, Partners, sub-processors, and (where the Patient Application is offered on a direct-to-consumer basis) with patients; acts as Controller and, where applicable, Joint Controller with the patient, or Processor / Business Associate to a Tenant Covered Entity, under HIPAA / HITECH, GDPR / UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH and analogous laws; the entity that carries privacy-law obligations and liabilities in respect of the Processing described in this Notice (see §1.6) | 68 Circular Road, #02-01, Singapore 049422 | privacy@alexcare.tech |
| Future country subsidiaries of ALEX Tech Pte. Ltd. - see the "No country subsidiaries currently incorporated" note immediately below this table | Wholly-owned subsidiaries of ALEX Tech Pte. Ltd. once (and if) incorporated; would act as local Controllers where required by local law | Not applicable - none currently incorporated | See ALEX Tech Pte. Ltd. contact channels in Part 18 |
No country subsidiaries currently incorporated. As at the effective date of this Notice, ALEX Tech Pte. Ltd. has no formally incorporated country subsidiaries. References to "country subsidiaries", to "the relevant ALEX Tech country subsidiary", or to "ALEX Tech Pte. Ltd. or its relevant country subsidiary" - in this §1.2, in §1.6, in the jurisdictional Annexes, and elsewhere in this Notice - describe entities that ALEX Tech Pte. Ltd. may in the future incorporate to meet local data-residency, licensing, regulatory, or business needs. Any illustrative country-subsidiary names that appear in this Notice, in operative contracts, or in related materials (for example, "ALEX Tech (Thailand) Ltd.", "ALEX Tech (Malaysia) Sdn. Bhd.", "ALEX Tech Philippines Inc.") are indicative only and are subject to change; the actual legal name of any future country subsidiary will be confirmed at the time of that subsidiary's incorporation and, where relevant, notified through an update to this Notice. Until a country subsidiary is formally incorporated, all obligations and liabilities of ALEX under this Notice in the relevant country attach to ALEX Tech Pte. Ltd. directly.
Joint Controllership. ALEX Tech Pte. Ltd. is (a) the sole ALEX-side Controller for Tenant Workforce accounts on the Platform, corporate visitor and lead data, and general Platform operations; and (b) a Joint Controller under Article 26 of the GDPR (where GDPR applies) with the patient, in respect of patient identity, credential, and cross-provider record data associated with the ALEX Network - the patient as data subject exercising sovereignty rights, and ALEX Tech as the operator of the identity, portability, and cross-provider linkage functionality. Each connected Tenant remains the Controller for the treatment data it contributes. The essence of the Article 26(2) arrangement between ALEX Tech Pte. Ltd. and the patient is available to any data subject on request via dpo@alexcare.tech, and is published as an appendix to this Notice once settled in final form.
Controller / Processor Roles by Data Flow (Summary):
| Data Flow | Controller | Processor | Notes |
|---|---|---|---|
| Patient data processed on Tenant deployments of the Platform (through the mobile application, web application, and/or authorised and provisioned APIs or interfaces made available to the Tenant) | The Tenant (hospital / clinic / lab / imaging / pharmacy / insurer / other healthcare organisation) | ALEX Tech Pte. Ltd. (or its country subsidiary where local law so requires) | The Tenant is Covered Entity (HIPAA) or Controller (GDPR / PDPA); ALEX Tech is Business Associate / Processor. Governed by the Business Associate Agreement (BAA) and Data Processing Addendum (DPA), entered into by ALEX Tech. |
| Patient data processed through patient-facing components of the Platform - accessed by the patient via the ALEX patient mobile application, patient web application, and/or authorised and provisioned APIs or interfaces - including portable identity, cross-provider record consent, and the patient-sovereign timeline | Joint Controllers: the patient (exercising sovereignty rights) and ALEX Tech Pte. Ltd. (as operator of the identity, portability, and cross-provider linkage functionality); each connected Tenant remains Controller of the treatment data it contributes | - | Joint-controller transparency notice available per this §1.2. The patient may withdraw the relevant consents at any time per Part 13. |
| Corporate website and marketing data (leads, prospects, visitors) | ALEX Tech Pte. Ltd. | Marketing sub-processors (see Appendix 1 to this Notice) | Cookies, analytics, CRM. Standard controller processing. |
| Tenant Workforce account data (login, role, activity logs used for platform operations, billing, service continuity, security) | ALEX Tech Pte. Ltd. | - | Platform-operations processing on ALEX Tech's own behalf, with a controller footing. |
| Tenant Workforce activity data used to render the Tenant's own service to its patients | The Tenant | ALEX Tech Pte. Ltd. | Same as Row 1 |
| Evaluation User content submitted to a sandbox, pilot, beta, or demonstration environment under Terms of Service §5.5 (only synthetic or lawfully de-identified test data is permitted; real Personal Data or PHI must not be submitted to any evaluation environment) | ALEX Tech Pte. Ltd. | - | Evaluation User accepts the Terms of Service and this Notice as a condition of Evaluation Access. Where an Evaluation User submits data in breach of ToS §5.5(b), the resulting Processing is remediated per Part 12 and Part 13 as if that data had been received in error, and does not create a Controller-Processor relationship between ALEX Tech and the underlying data subject. |
1.3 Scope - Who This Notice Covers
This Notice applies to four principal audiences:
- Patients whose Personal Data or PHI is handled through the Platform - including patients who access the Platform directly through the ALEX patient mobile application, patient web application, or authorised and provisioned APIs or interfaces; patients receiving care from ALEX Tenant providers using the Platform; and patients whose data is routed between ALEX Tenant providers through the ALEX Network.
- Tenant Workforce Users - clinicians, administrators, and other staff of ALEX Tenant organisations who use the Platform in the course of employment, whether through the mobile application, web application, or authorised and provisioned APIs or interfaces.
- Evaluation Users - prospective customers, related parties, and other persons granted time-limited access to the Platform (or to a sandbox, pilot, beta, or demonstration environment) for evaluation, demonstration, or trial purposes, whether or not a fee is paid and whether or not a separate written evaluation agreement is in place, in each case under Terms of Service §5.5. Evaluation Users are subject to the restrictions in Terms of Service §5.5(b) prohibiting submission of real Personal Data or PHI to any evaluation environment; where an Evaluation User provides any Personal Data of their own (for example, business-contact data of the Evaluation User's own personnel accessing the evaluation environment), that data is Processed by ALEX Tech Pte. Ltd. as Controller for the limited purposes of granting, administering, securing, and terminating Evaluation Access.
- Corporate audiences - visitors to
alexcare.techand related properties; prospective customers; partners in our partner ecosystem programme; investors; job applicants.
Not covered by this Notice - but separately notified - are: (i) individuals whose data is controlled by an ALEX Tenant, where the Tenant provides its own patient-facing notice under HIPAA / local law; (ii) our own personnel (covered by an internal HR privacy notice); (iii) individuals interacting with third-party services linked from ALEX properties (see Part 16).
1.4 Relationship to Tenant Notices
Where you receive care from an ALEX Tenant, that Tenant is the Covered Entity (HIPAA) or the Controller (GDPR / PDPA) of your PHI / Personal Data - a compliance role, not an ownership title (see §1.5.3). ALEX processes that data only on the Tenant's documented instructions under a Business Associate Agreement (BAA) and / or Data Processing Addendum (DPA). Please consult your Tenant's own notice for rights against the Tenant. Rights you may separately hold against ALEX as Processor, Business Associate, or Joint Controller are described in Part 13.
1.5 Patient Data Sovereignty - Our Fundamental Commitment
ALEX operates on the principle of patient data sovereignty. This principle governs how we describe every relationship, contract, and technical arrangement in this Notice and in every companion legal instrument (DPA, BAA, sub-processor agreement, partner ecosystem terms). It is not merely a marketing statement - it is a binding legal commitment that shapes our contract templates, our engineering, our sub-processor onboarding, and our corporate governance.
1.5.1 The Sovereignty Principle
An individual patient holds the ultimate rights in their own Personal Data and PHI - including the underlying facts that describe the patient's health, identity, contact information, treatment history, biometric characteristics, insurance status, and any inference derived from any of the foregoing. These rights are inalienable in substance: a patient cannot be contractually stripped of them, and no party who processes patient data acquires them through the act of processing. The custody, control, or lawful processing of patient data by ALEX, by any Tenant, by any sub-processor, or by any Partner is a role of stewardship - never an act of appropriation, and never a source of ownership.
1.5.2 No Ownership by ALEX
Neither ALEX Tech Pte. Ltd., nor any subsidiary, affiliate, licensor, or successor of it, claims or holds ownership of any patient Personal Data or PHI. The lawful operational roles carried by ALEX Tech Pte. Ltd. - as Controller, Processor, Business Associate, or Joint Controller as identified in §1.2 - do not carry any implied assertion of ownership. Intellectual-property rights in the Platform software and technology are proprietary interests in that software and technology, and not in any patient's Personal Data or PHI; no such right confers any interest in the data that patients or Tenants place into the Platform. Where this Notice or any technical documentation describes ALEX as "holding", "storing", "processing", "routing", "hosting", or "operating on" patient data, those words describe an operational role carried by ALEX Tech Pte. Ltd. and never confer an ownership right on ALEX Tech or on any other party.
1.5.3 No Ownership by Tenants
An ALEX Tenant that engages the Platform to deliver care to its patients acts as the Covered Entity (HIPAA) or Controller (GDPR / PDPA and equivalents) of patient data. This is a compliance role, not an ownership title.
- HIPAA does not confer "ownership" of PHI in any commercial sense. Older healthcare-vendor contracts sometimes assert that "the provider owns the medical record"; that assertion, insofar as it purports to derogate from patient rights under 45 CFR §§ 164.524, 164.526, 164.528, 164.522, and 164.508, is not enforceable against those rights. State medical-record laws that impose custodial retention obligations run to the patient and to the licensing regulator - not against the patient's underlying substantive rights.
- GDPR, UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH, APPI, AU APP and equivalent frameworks are rights-based, not property-based. They allocate Controller and Processor duties; they do not grant ownership of the personal data to any party.
Every Tenant contract that ALEX enters into includes provisions that: (a) acknowledge Tenant does not own patient Personal Data or PHI processed on the Platform; (b) bind Tenant to honour every patient right that would attach against Tenant under applicable law; (c) prohibit Tenant from asserting ownership in any downstream contract, notice, marketing communication, disclosure to insurers, disclosure to employers, sale to data brokers, or otherwise; (d) prohibit Tenant from selling, licensing, pledging as security, or transferring patient data as a proprietary asset; and (e) require Tenant to return or delete patient data on Tenant termination in accordance with applicable clinical-record retention law and patient instruction, without asserting a residual proprietary claim.
1.5.4 No Ownership by Partners or Sub-processors
Every sub-processor engaged by ALEX (listed in Appendix 1) and every partner in our partner ecosystem programme is contractually bound to: (a) process patient Personal Data and PHI only on ALEX's documented instructions or, where the partner has an independent lawful basis, only within the strict scope of that basis; (b) claim no ownership, licensing right, or proprietary interest in patient data received through ALEX; (c) not use patient data for the partner's or sub-processor's independent business purposes - including AI Model training on identifiable data, product-improvement analytics beyond the strict scope of service, or resale - unless separately consented by the patient and independently lawful; (d) impose the same restrictions on any downstream sub-processor; and (e) return or delete patient data at end of engagement. Partner certification and sub-processor status are revocable for violation of these terms.
1.5.5 Anti-Alienation
Patient Personal Data and PHI is not a saleable, licensable, pledgable, or mortgageable asset of ALEX, of any Tenant, of any Partner, or of any sub-processor. No such party shall sell, license, pledge as security, grant a proprietary interest in, or otherwise treat patient Personal Data or PHI as a commercial asset owned by that party. This restriction survives termination of any commercial arrangement between the parties who processed the data, and it is enforceable by the patient as a matter of stewardship duty owed to the patient - not merely as a contractual covenant between the processing parties.
1.5.6 Corporate Transactions
Where ALEX Tech Pte. Ltd., any Tenant, any Partner, or any sub-processor undergoes a merger, acquisition, sale of assets, financing, restructuring, spin-off, or similar corporate transaction:
- (a) Patient Personal Data and PHI transfers to the successor in a custodial role only, never as a proprietary asset of the transferring party.
- (b) The successor is bound by the sovereignty commitments in this §1.5 and by every patient-rights obligation that attached to the predecessor - as a condition of the transaction, warranted by the transferring party and enforceable by ALEX and by affected patients.
- (c) Where required by applicable law - including the appointment of a consumer privacy ombudsman under 11 U.S.C. § 332 in a US bankruptcy sale involving personally identifiable information, or the equivalent regime in another jurisdiction - the required protective mechanism shall be honoured, not circumvented.
- (d) Affected patients receive notice with a meaningful opportunity to exercise portability, transfer, or erasure rights before the transfer takes effect, to the extent required by applicable law and in all cases where the transfer would materially change the identity of the party holding custody of the patient's data.
- (e) Any commercial value ascribed to patient data in the transaction shall not diminish patient rights - value derived from data stewardship does not convert stewardship into ownership.
1.5.7 Insolvency and Wind-Down
In the event of ALEX insolvency, Tenant insolvency, or wind-down of any party that holds patient data through the Platform:
- (a) Patient Personal Data and PHI shall not be treated as a "for-sale" asset of the insolvent estate. Consistent with US Bankruptcy Code § 363(b)(1)(A) and § 332 (consumer privacy ombudsman) - and equivalent regimes in Singapore's Insolvency, Restructuring and Dissolution Act 2018, the UK's Insolvency Act 1986, and applicable ASEAN insolvency law - patient data disposition shall be conducted under a protective regime that preserves patient rights.
- (b) Stewardship transfers to a qualified successor operator who assumes the sovereignty commitments in this §1.5 in writing, or to a court-appointed data custodian pending transition.
- (c) Patients receive advance notice and a meaningful window to exercise portability, transfer, and erasure rights before any successor transition takes effect.
- (d) Where no qualified successor exists, patient data shall be exported to the patient (or to the patient's nominated successor provider) and thereafter deleted from ALEX systems in accordance with applicable clinical-record retention law, with certification of deletion to the patient on request.
- (e) ALEX's business-continuity design and Tenant contracts are structured so this commitment is operational under stress - not merely aspirational.
1.5.8 Cross-Border Sovereignty
Patient sovereignty rights follow the patient - not the storage location and not the corporate domicile of the processing party. Where patient data is transferred across borders under Part 9, the patient's substantive rights (access, rectification, erasure, portability, restriction, objection, ADM safeguards, complaint) remain in force notwithstanding the storage jurisdiction. Where a receiving jurisdiction offers materially weaker protection than the patient's home jurisdiction, the higher standard prevails as a matter of contract.
1.5.9 De-identified, Aggregate, and AI-Derived Data
- De-identified and aggregated data derived from patient data (see Part 6.3) is used for legitimate platform-improvement, safety-signal, and permitted research purposes only. We do not sell or license such data to any third party for that party's independent commercial exploitation. Our sub-processors and partners are contractually restricted to the same.
- AI-generated inferences about an identified patient (for example, an automated risk score, a documentation suggestion, a code-capture recommendation, a triage classification) remain within the sovereignty scope described above. Such inferences cannot be transferred to any third party or repurposed outside the scope of the underlying lawful basis without either (i) explicit patient consent or (ii) an independent lawful basis established for the recipient.
1.5.10 Contract Override - Sovereignty Prevails
No term of any contract between ALEX and a Tenant, between ALEX and a Partner, between ALEX and a sub-processor, between any Tenant and its own downstream vendors, between any Partner and its own downstream affiliates, or between any successor to any of the foregoing and any third party, shall be construed to grant ownership of patient Personal Data or PHI to any party or to derogate from the sovereignty commitments in this §1.5. Any provision of any such contract that purports to do so is void and unenforceable to the extent of the derogation, and the commitments in this §1.5 prevail. ALEX will not enter into and will not accept any Tenant amendment, Partner amendment, sub-processor amendment, or successor undertaking that conflicts with this §1.5.
1.5.11 High-Trust Operating Posture
Consistent with these sovereignty commitments, we operate the Platform on a high-trust footing that includes: (a) minimum-necessary data collection; (b) role-based access control and immutable audit logging on every read of identifiable patient data; (c) transparent published sub-processor list with advance notice of change (Appendix 1 and §7.3); (d) transparent AI training data governance (Part 6.3); (e) responsiveness to patient rights requests within the statutory windows (Part 13); (f) independent audit under the certifications we are progressively pursuing as listed in Part 11.7 (noting that, as at the Effective Date, no such certifications have been issued); and (g) enforcement of every provision of this §1.5 through the standard-form contract templates ALEX uses for all Tenants, Partners, and sub-processors - with those templates to be published in redacted form to enterprise Tenants and regulators on reasonable request once the redacted-template library is established.
1.6 Allocation of Legal Responsibility
ALEX Tech Pte. Ltd. is the only entity with any operational or legal role in the Processing described in this Notice. This §1.6 records where responsibility sits and against whom it is enforceable.
1.6.1 ALEX Tech Pte. Ltd. - Sole Global Operating Entity
ALEX Tech Pte. Ltd. is a Singapore private limited company incorporated under the Companies Act 1967 and registered with ACRA. It is the sole global operating entity for the ALEX Platform. As at the effective date of this Notice, ALEX Tech Pte. Ltd. has no formally incorporated country subsidiaries (see the "No country subsidiaries currently incorporated" note in §1.2). ALEX Tech Pte. Ltd. - together with any country subsidiaries it may incorporate in the future to meet local data-residency, licensing, regulatory, or business needs - is the party that:
- contracts with Tenants for use of the Platform (including under Business Associate Agreements and Data Processing Addenda);
- contracts with Partners in the partner ecosystem programme;
- contracts with sub-processors;
- contracts directly with patients where the Patient Application is offered on a direct-to-consumer basis;
- acts as Controller (and, where applicable, Joint Controller with the patient for the patient-sovereign functionality of the Platform, or Processor / Business Associate to a Tenant Covered Entity) under HIPAA / HITECH, GDPR / UK GDPR, PDPA-SG, PDPA-TH, PDPA-MY, DPA-PH and analogous laws; and
- bears the operational responsibility for the data-protection commitments in this Notice.
1.6.2 Allocation of Legal Responsibility
All privacy-law obligations and legal liabilities in respect of the Processing described in this Notice - including (without limitation) data-subject rights fulfilment, breach detection and notification, regulator complaints handling, cross-border transfer safeguards, retention, security, sub-processor management, and AI-transparency obligations - attach exclusively to ALEX Tech Pte. Ltd. and, where applicable under local law, to the relevant ALEX Tech country subsidiary.
All contracts entered into in respect of the Platform - with Tenants, Partners, sub-processors, patients, and other counterparties - are executed by ALEX Tech Pte. Ltd. or its relevant country subsidiary. Any recourse for breach of the commitments in this Notice, or for any privacy-law claim arising in respect of the Platform, lies against ALEX Tech Pte. Ltd. (or the relevant ALEX Tech country subsidiary).
1.6.3 Preservation of Statutory Rights
Nothing in this §1.6 or in this Notice derogates from any statutory right that a data subject may hold against any party that in fact processes their Personal Data or PHI, under the law that applies to that Processing. The allocation set out in §1.6 describes which entity is the operational counterparty for privacy-law purposes; it does not waive, restrict, exclude, or defeat any right that a data subject holds by law. Data subjects retain the full suite of statutory rights described in Part 13 and in the jurisdictional Annexes, exercisable against ALEX Tech Pte. Ltd. and, where local law so provides, against the country subsidiary that operates in the data subject's jurisdiction. Nothing in this §1.6 prevents a data subject from lodging a complaint with a supervisory authority (see Part 19).
1.6.4 Contact and Recourse
All contact points for the exercise of data-subject rights, DPO enquiries, breach notification, and regulatory complaint routing are the ALEX Tech Pte. Ltd. channels set out in Part 18.
Part 2 - Definitions
For the purposes of this Notice:
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, aligned with GDPR Art. 4(1), PDPA-SG s.2(1), PDPA-TH s.6, PDPA-MY s.4, DPA-PH s.3(g). Includes online identifiers, device identifiers, and inferred data. |
| Sensitive / Special Category Data | Data warranting heightened protection under applicable law - includes health data, genetic data, biometric data, sexual orientation, religious belief, political opinion, criminal history, national ID numbers where restricted (e.g., SG NRIC per PDPC guidance, MY NRIC per PDPA), and children's data. |
| Protected Health Information (PHI) | As defined under 45 CFR § 160.103, individually identifiable health information transmitted or maintained in any form by a Covered Entity or Business Associate. |
| Processing | Any operation performed on Personal Data - collection, recording, storage, use, disclosure, transmission, erasure. |
| Controller | The entity that determines the purposes and means of Processing (GDPR Art. 4(7); PDPA equivalents). |
| Processor | The entity that processes Personal Data on behalf of a Controller (GDPR Art. 4(8)); analogous to Business Associate under HIPAA. |
| Sub-Processor | A Processor engaged by ALEX to process Personal Data. Named list at Appendix 1. |
| Tenant | Any healthcare organisation, provider, insurer, or health-adjacent enterprise that has contracted with ALEX to use the Platform. |
| Platform | The ALEX platform in all its forms - including modules, features, and services accessed by users through the ALEX mobile application(s), the ALEX web application(s), and/or authorised and provisioned application-programming interfaces (APIs) and other interfaces. References to "the Platform" are technology-neutral and cover future access modes we introduce that are consistent with this Notice. |
| Patient Application | Those components of the Platform intended for direct use by patients - including the ALEX patient mobile application, the ALEX patient web application, and any authorised patient-facing APIs or interfaces. |
| Tenant Application | Those components of the Platform intended for use by Tenant Workforce Users - including tenant administration, clinical workflow, and back-office modules accessed via the ALEX mobile application(s), web application(s), and/or authorised and provisioned APIs or interfaces. |
| Evaluation User | A prospective customer, related party, or other person granted Evaluation Access under Terms of Service §5.5 - that is, time-limited access to the Platform (or to a sandbox, pilot, beta, or demonstration environment) for evaluation, demonstration, or trial purposes, whether or not a fee is paid and whether or not a separate written evaluation agreement is in place. Evaluation Users are prohibited from submitting real Personal Data or PHI to any evaluation environment under Terms of Service §5.5(b); only synthetic or lawfully de-identified test data may be submitted. |
| ALEX Network | The inter-organisational clinical fulfilment functionality that enables Tenant providers to route clinical orders (for example, laboratory, imaging, pharmacy, and referral orders) to other Tenant providers on the Platform, and to receive results back, subject to applicable consent. |
| AI Model | Any machine-learning, deep-learning, foundation, generative, statistical or agentic system used within the Platform to derive inference, generate content, route decisions, or support clinical workflows. |
| Automated Decision-Making (ADM) | Decisions produced without meaningful human involvement having legal or similarly significant effects on the data subject (GDPR Art. 22). |
| Patient Data Sovereignty | The principle set out in §1.5 that individual patients hold ultimate rights in their own Personal Data and PHI, that neither ALEX nor any Tenant, Partner, sub-processor, successor, or affiliate of the foregoing claims or holds ownership of such data, and that custody or lawful processing is a role of stewardship rather than appropriation. |
| Steward / Custodian | A party that holds, processes, transmits, or routes patient Personal Data or PHI in a lawful role - without acquiring any proprietary interest in the underlying data. ALEX operates in a Steward / Custodian role in respect of all patient Personal Data and PHI. Tenants, Partners, and sub-processors likewise operate in Steward / Custodian roles insofar as they touch patient data through the Platform. |
| Qualified Successor Operator | A successor entity that has (i) undertaken in writing to be bound by the sovereignty commitments in §1.5, (ii) demonstrated equivalent or superior technical and organisational safeguards to those set out in Part 11, and (iii) been notified to affected patients with a meaningful window for the patient to exercise portability and erasure rights before the transition takes effect. |
Part 3 - What Information We Collect
3.1 Patient (Direct Patient Application Use and Tenant-Delivered Care)
We collect the following categories of Personal Data and PHI in connection with patient care and patient use of the Platform (whether via the Patient Application or via a Tenant's use of the Platform in delivering care to the patient):
Identity & Contact Data: legal name, preferred name, date of birth, gender identity where volunteered, national identifiers where legally required (SG NRIC/FIN, MY NRIC/passport, TH National ID, PH PhilSys PSN, US SSN under HIPAA-permitted uses), residential and mailing address, contact telephone, email, next-of-kin contact.
Clinical Data (PHI): medical history, current conditions, allergies, medications, immunisations, laboratory results, imaging studies and DICOM objects, clinical notes and encounter summaries, procedure history, diagnoses (ICD-10, ICD-10-TM, ICD-11 as applicable), care team assignments, treatment plans, referral history, admission/discharge/transfer records.
Insurance & Benefits Data: payer identifier, policy number, coverage tier, claim history, government scheme membership (BHYT, NHSO, PhilHealth, BPJS, MediSave / MediShield Life, MEDIBRIDGE panel status, TPA identifiers).
Financial Data: billing charges, receipts, co-payment history, payment instrument tokenised references (we do not store full card PAN; see Part 11.4).
Biometric & Sensitive Identifiers: facial images for identity verification (opt-in), fingerprint or voice patterns where used for patient authentication (opt-in), genetic data where clinically ordered.
Cross-Provider Data (Patient Portability): portable patient identity record, longitudinal health-event timeline, consent grants and revocations recorded in our consent-management system, and cross-provider notifications the patient has enabled through the Platform.
Behavioural / Interaction Data: Patient Application usage logs, appointment booking history, message threads with providers, and feature-engagement events (used to render the service; not sold and not used for third-party advertising).
Device & Technical Data: device ID, OS version, IP address (retained only for security and fraud-prevention windows - see Part 10), approximate geolocation (city-level; precise geolocation only with explicit permission and only for feature-specific use, e.g., nearest-provider search).
3.2 Tenant Workforce (Clinician, Admin, Support)
We collect: name, work email, employee ID (assigned by the Tenant), role assignments, credential and licence numbers where the Tenant configures credential verification, authentication data (password hashes, MFA factors), session logs, feature-access audit trail, IP address of the accessing device, browser/OS metadata, and workflow productivity data used solely for service delivery and security.
3.3 Evaluation Users
For each Evaluation User granted Evaluation Access under Terms of Service §5.5, we collect: name, business email, employer, job title, country, information submitted through the Evaluation Access intake or request channel, communication history relating to the Evaluation Access, authentication data (password hashes, MFA factors), session logs and feature-access telemetry within the evaluation environment, IP address of the accessing device, browser/OS metadata, and content, prompts, inputs, outputs, telemetry, session data, and configuration submitted by or generated in connection with Evaluation User's use of the Platform (in each case subject to the prohibition in Terms of Service §5.5(b) on submitting real Personal Data or PHI). Evaluation-environment usage telemetry may be inspected, retained, and used by ALEX Tech under Terms of Service §5.5(e) for the purposes of operating, securing, and improving the Platform and evaluating the Evaluation User's use.
3.4 Corporate Visitors, Leads, Applicants, Partners
We collect: name, business email, employer, job title, country, information you submit through contact forms or event registrations, communication history, marketing engagement events (opens, clicks - where consent has been captured for such tracking), résumé and application data (for job applicants - handled under a separate applicant privacy notice on request), and diligence data submitted through our partner ecosystem programme.
Website contact and demo requests. When you send a contact or demo request through our website, we also record technical details that accompany the request: your IP address and the country it approximately indicates (looked up on our own servers from a locally held database, without sending your IP address to a third party for that purpose), the time zone reported by your device, the country indicated by the telephone number you give, the browser and operating system your device reports, the page from which you sent the request, and the time you sent it. We use these details to route and follow up your request and to detect and prevent spam and abuse, and we keep them with your request under the retention rule for corporate marketing leads in Part 10.
Security check on our website forms. Our website forms use Cloudflare Turnstile to tell people apart from automated programs. When you begin filling in a form, Turnstile runs in your browser and processes signals such as your IP address, your browser's TLS fingerprint and user-agent, and the key that identifies our form; it returns to us the result of the check, not the signals themselves. Cloudflare, Inc. processes these signals on our behalf as our sub-processor (Appendix 1) and, to improve its bot detection, as an independent controller, as described in its Turnstile Privacy Addendum (cloudflare.com/turnstile-privacy-policy).
3.5 Data We Do NOT Collect / Do NOT Want
- We do not knowingly collect data from children under 13 in the US or under the age of digital consent in the applicable jurisdiction (see Part 14; and see Annex G §G.7 for the India-specific under-18 posture and s.9 DPDPA 2023 prohibitions on tracking, behavioural monitoring, and targeted advertising directed at children) except where a Tenant configures pediatric care workflows on our platform - in which case the Tenant is Controller and parental consent is administered under the Tenant's care governance.
- We do not collect political opinions, religious belief, trade-union membership, or sexual life data unless expressly and voluntarily provided by a patient in a clinical context and clinically relevant.
- We do not knowingly ingest data from unauthorised scraping, brokered datasets, or third-party sources outside our named data sources.
- We do not want, and Evaluation Users are prohibited from submitting to any evaluation environment, real Personal Data or PHI of any identified or identifiable natural person; only synthetic or lawfully de-identified test data may be submitted by Evaluation Users (Terms of Service §5.5(b)).
Part 4 - Legal Bases for Processing
Because ALEX operates across multiple jurisdictions with materially different legal-basis frameworks, we identify the legal basis relied upon for each category of Processing.
4.1 Under the GDPR / UK GDPR (Art. 6 and Art. 9)
| Processing Purpose | Legal Basis (Art. 6) | Art. 9 Special Category Basis (where applicable) |
|---|---|---|
| Provision of care via the Platform in use by a Tenant (ALEX as Processor) | Art. 6(1)(b) contract with Tenant / Art. 6(1)(f) legitimate interest | Art. 9(2)(h) provision of health / social care under professional secrecy |
| Patient identity, portability, and cross-provider record functionality (Patient Application and related APIs) | Art. 6(1)(a) consent | Art. 9(2)(a) explicit consent |
| Emergency access / break-glass to PHI to prevent serious harm | Art. 6(1)(d) vital interests | Art. 9(2)(c) vital interests where data subject cannot consent |
| Billing, tax, accounting records | Art. 6(1)(c) legal obligation | N/A |
| Fraud detection, security, network integrity | Art. 6(1)(f) legitimate interest (balancing test on file) | Art. 9(2)(g) substantial public interest (where PHI touched) |
| Corporate marketing to prospective customers | Art. 6(1)(f) legitimate interest / Art. 6(1)(a) consent (opt-in for email) | N/A |
| AI model training on de-identified aggregated data | Art. 6(1)(f) legitimate interest (with balancing test) - see Part 6 | Not applicable once effectively de-identified per Recital 26 |
| AI model training on identifiable PHI | Art. 6(1)(a) explicit consent, or Art. 6(1)(e) scientific research under Art. 89 safeguards - see Part 6 | Art. 9(2)(a) explicit consent, or Art. 9(2)(j) scientific research |
4.2 Under HIPAA / HITECH (US)
ALEX processes PHI in the capacity of a Business Associate (and, in some flows, Business Associate Subcontractor) of Covered Entity Tenants. Our processing is authorised by:
- The Business Associate Agreement executed with each Covered Entity Tenant, in the form required by 45 CFR § 164.504(e).
- The Covered Entity's underlying Treatment, Payment, or Health Care Operations (TPO) purpose per 45 CFR § 164.506.
- Patient authorisation under 45 CFR § 164.508 for uses beyond TPO (e.g., marketing, most research uses, sale of PHI, psychotherapy notes).
- Permitted disclosures under 45 CFR § 164.512 (required by law, public health, victims of abuse, health oversight, judicial proceedings, law enforcement under conditions, decedents, organ donation, serious threat).
- The Minimum Necessary Standard (45 CFR § 164.502(b)) is applied technically through role-based access control and disclosure-scope-limiting APIs.
4.3 Under PDPA-SG (Singapore Personal Data Protection Act)
We rely on (a) consent obtained under s.13 to s.17 for standard Processing purposes; (b) deemed consent by notification under s.15A for compatible secondary purposes; (c) the legitimate-interests exception under the First Schedule, Part 3 (with the required balancing assessment on file) for security, fraud, and business-improvement Processing; (d) the business-improvement exception under the First Schedule, Part 5 for internal analytics on de-identified data; (e) statutory disclosures under s.17 exceptions where required.
4.4 Under PDPA-TH (Thailand Personal Data Protection Act B.E. 2562)
Health data is Sensitive Personal Data under s.26 and requires explicit consent unless a s.26 exception applies (vital interests; preventive/occupational medicine; public interest in the area of public health; scientific research subject to safeguards). Non-sensitive Personal Data is processed on the legal bases in s.24 (consent, contract, legal obligation, vital interests, public task, legitimate interests).
4.5 Under PDPA-MY (Malaysia Personal Data Protection Act 2010 as amended by the PDPA (Amendment) Act 2024)
We process on the bases in s.6 and s.40 (Sensitive Personal Data) - consent (with the enhanced explicit-consent standard for health data), performance of a contract, compliance with a legal obligation, or protection of vital interests. As required by the 2024 amendments (in force 2025), we operate under Class of Data User registration for the healthcare class, appoint a Data Protection Officer, notify data subjects of material processing changes, and comply with the enhanced breach-notification and data-portability rules.
4.6 Under DPA-PH (Philippines Data Privacy Act of 2012, RA 10173)
Health data is Sensitive Personal Information under s.3(l) and requires the higher-standard bases in s.13 - consent obtained prior to collection or where processing is necessary for medical treatment carried out by a medical practitioner or medical treatment institution and the data subject is not legally capable of giving consent; or as provided by existing laws and regulations for the protection of lawful rights and interests of natural or legal persons in court proceedings; or necessary to fulfill functions of public authority. NPC Data Processing System (DPS) registration and DPO notification status is described in Annex F.2.
4.7 Under DPDPA-IN (India Digital Personal Data Protection Act 2023)
We process personal data of Data Principals within India on the basis of consent obtained in accordance with s.6 (free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action; limited to what is necessary for the specified purpose; withdrawable at any time), and, where applicable, on the "Certain Legitimate Uses" grounds under s.7 (in particular s.7(a) where the Data Principal has voluntarily provided personal data for the specified purpose, s.7(g) in a medical emergency, and s.7(i) in the employment context). We do not rely on s.7 grounds that are not available to a private-sector Data Fiduciary in the delivery of the Platform. The full India-specific posture, including the notice, grievance-redressal, cross-border-transfer, and Significant Data Fiduciary elements, is set out in Annex G.
4.8 Other Jurisdictions
For processing subject to (i) Japan APPI, (ii) Australia Privacy Act 1988 and Australian Privacy Principles, (iii) Hong Kong PDPO, (iv) UAE PDPL, (v) Saudi Arabia PDPL, (vi) other Applicable Data Protection Law, we rely on the equivalent legal bases as summarised in Annex H.
Part 5 - How We Use Personal Data
We use Personal Data only for the following purposes, tied to the legal bases in Part 4:
- To render the Platform service - provisioning Tenants, delivering care workflows, routing clinical orders, storing and retrieving records, generating clinical documentation, delivering results, and rendering the patient-facing components of the Platform (whether through the mobile application, web application, or authorised and provisioned APIs or interfaces).
- To identify patients and prevent misidentification - through biometric matching (where opted in), demographic reconciliation, and our patient identity system.
- To route and fulfil clinical orders across the ALEX Network - only where a valid consent to cross-provider routing has been captured through our consent-management system.
- To bill for services and process payment - including insurer and government-scheme claim submission with claim-adjudication tracking.
- To provide clinical decision support and safety alerts - including drug-interaction, allergy, and clinical-safety alerts under our clinical policy governance framework.
- To detect, investigate, prevent, and respond to security incidents, fraud, abuse and legal liability - including credential-stuffing detection, anomalous access review, forensic audit-trail preservation, and protection of our website forms against automated abuse.
- To comply with legal, regulatory and audit obligations - including HIPAA, PDPA, GDPR, tax, corporate records, health-authority reporting, and litigation holds.
- To communicate service, safety, and security information - including security bulletins, breach notifications, product-change notices, and service-availability alerts.
- To improve the Platform - through our internal platform improvement and model-development processes, using de-identified and aggregated data unless explicit consent for identifiable-data use has been captured (see Part 6).
- To conduct corporate marketing and sales - to prospective enterprise customers on a legitimate-interest or consent basis (opt-in for email marketing in jurisdictions requiring it), including responding to contact and demo requests made through our website.
- To operate our partner ecosystem programme - partner registration, certification, and revenue-share reconciliation.
- To grant, administer, secure, and terminate Evaluation Access under Terms of Service §5.5 - including intake, identity verification, environment provisioning, session monitoring, telemetry collection, evaluation-outcome assessment, and post-termination content-deletion action.
We do not use Personal Data for: sale to third parties for their independent purposes; behavioural advertising; discriminatory profiling; or any purpose materially inconsistent with the purposes disclosed at collection without either fresh consent or a valid compatible-purpose analysis.
Part 6 - AI, Model Training, and Automated Decision-Making
Because ALEX is an AI-native platform, we make this Part more detailed than a general SaaS notice would.
6.1 Where AI is Used
The Platform is designed to provide, and progressively delivers as each AI-assisted feature is released to a Tenant's environment or made generally available in the Patient Application, AI functionality that may include:
- Drafting clinical documentation from clinician dictation or structured inputs (AI-assisted; the human clinician remains the sign-off author).
- Suggesting ICD, procedure, and drug codes to improve billing accuracy.
- Routing clinical orders across the ALEX Network.
- Generating patient-facing summaries and translations.
- Supporting triage and clinical-decision-support alerts under our clinical policy governance framework and clinical safety oversight.
- Detecting fraud, credential abuse and security anomalies.
- Improving the Platform through our internal platform improvement and model-development processes.
Not every feature described in this section is generally available as of the Effective Date; individual features are released to Tenants under separate release notices and, where applicable, product-specific supplementary terms. Where a specific AI-assisted feature has been released to your deployment, this Notice applies to that feature.
6.2 Automated Decision-Making
Under GDPR Art. 22 (and analogous provisions in Annex jurisdictions), decisions producing legal or similarly significant effects on you will not be made solely by automated means without a lawful basis and appropriate safeguards. ALEX is designed such that clinically significant decisions require human clinician sign-off - the AI proposes, the licensed clinician disposes. Where ADM is unavoidable (e.g., automated fraud-block on suspicious authentication), you have the right (a) to be informed, (b) to obtain human review, (c) to express your point of view, and (d) to contest the decision. Contact dpo@alexcare.tech.
6.3 Use of Personal Data / PHI for AI Model Training
Default rule: we train and refine AI Models exclusively on de-identified, aggregated, or synthetic data. Where de-identified data is used for the purposes described in this Part, the Platform applies de-identification techniques appropriate to the intended use and risk, including techniques designed to align with the HIPAA Privacy Rule de-identification standard at 45 C.F.R. § 164.514. Specific technique selection (including whether Safe Harbor at 45 C.F.R. § 164.514(b)(2), Expert Determination at 45 C.F.R. § 164.514(b)(1), or additional statistical re-identification-risk methods are applied to a given dataset), and any applicable expert-determination or Safe Harbor evidence, is available to Tenants on request via dpo@alexcare.tech.
Exceptions requiring explicit consent or a lawful research basis:
- Where identifiable data is used for research purposes, we rely on Art. 9(2)(j) GDPR (scientific research) with Art. 89 safeguards, HIPAA IRB or waiver processes, PDPA research exceptions where available, and analogous local-law bases.
- Where a Tenant explicitly authorises identifiable-data training on its patient population under its BAA / DPA, the Tenant is responsible for the underlying patient consent and IRB where required.
AI Transparency Commitments:
- We publish the categories of data used to train our AI Models as each AI Model is released.
- We do not use patient PHI to train AI Models for third-party foundation-model providers.
- We do not sell or license identifiable Personal Data or PHI to any third party for AI training.
- Our sub-processor list (Appendix 1) identifies any AI / ML infrastructure providers and states whether they process identifiable or de-identified data on our behalf.
6.4 EU AI Act Positioning
ALEX Tech Pte. Ltd. is undertaking, and will complete before offering any regulated AI functionality in the EU market, per-system classification under Articles 6(1)/Annex I and 6(2)/Annex III of Regulation (EU) 2024/1689 (the "EU AI Act"), and any registration required under Article 71. For each AI system in scope, the applicable risk-management, data-governance, technical-documentation, transparency, human-oversight, accuracy, robustness, and cybersecurity regime will be operated as required by the classification determined for that system before that system is placed on the market or put into service in the EU. Where classification, registration, or the applicable risk regime has not yet been completed for a given AI system, that AI system will not be made available to EU users. A per-system classification statement will be published together with the AI Transparency Notice; in the interim, per-system classification status and additional AI-transparency information are available on request via privacy@alexcare.tech.
Synthetic-content labelling under EU AI Act Article 50. Article 50 of Regulation (EU) 2024/1689 imposes transparency obligations on providers and deployers of AI systems that generate or manipulate synthetic content, including a machine-readable labelling obligation on providers of generative AI systems (Art. 50(2)) and a disclosure obligation on deployers who generate or manipulate text, image, audio, or video content constituting a deep fake or, in specified conditions, published text on matters of public interest (Art. 50(4)). Article 50 enters into application on 2 August 2026. Where the Platform is offered to users in the EU, and in respect of AI-generated content produced by the Platform (including AI-drafted clinical documentation, AI-generated patient-facing summaries, AI-generated translations, and other synthetic outputs), ALEX Tech Pte. Ltd. will (a) mark AI-generated outputs with a machine-readable identifier consistent with Art. 50(2) and applicable technical standards, and (b) where the Platform is used by a Tenant or by a patient to generate or publish synthetic content that falls within Art. 50(4), surface the disclosures required to enable the deployer to satisfy Art. 50(4) in respect of that content. Article 50 compliance status per AI system will be published together with the per-system EU AI Act classification statement referenced above; in the interim, current status is available on request via privacy@alexcare.tech.
6.5 Alignment with Frameworks
Our AI governance is designed to align with the NIST AI Risk Management Framework, Singapore's Model AI Governance Framework 2.0 (including the Generative AI addendum), and the ISO/IEC 42001 AI Management System standard. The current status of the internal mapping documents evidencing alignment with each of these frameworks is available to Tenants on request via dpo@alexcare.tech.
Part 7 - Sharing and Disclosure
We share Personal Data only in the following circumstances:
7.1 With Your Tenant
Where you are a patient of an ALEX Tenant, your data is inherently accessed by that Tenant's authorised workforce. This is not a "sharing" for GDPR purposes - the Tenant is the Controller and ALEX is the Processor.
7.2 With Other Providers on the ALEX Network
When you (or your Tenant, acting on your instruction) route a clinical order to a fulfilment provider on the ALEX Network - for example, a standalone laboratory receiving a laboratory order from your referring hospital - the order and clinically necessary Personal Data are transmitted through the Platform to that fulfilment provider only where a valid consent to cross-provider routing has been captured through our consent-management system and where a network-level Data Processing Addendum is in force.
7.3 With Sub-Processors
We use sub-processors listed at Appendix 1 to deliver the service - including cloud hosting, cybersecurity, communications, payments, analytics, and specialist AI infrastructure. ALEX Tech Pte. Ltd. is in the process of executing GDPR Article 28-equivalent processing agreements (and, where applicable, HIPAA §164.502(e) Business Associate Agreements) with each sub-processor listed in Appendix 1, and imposing the anti-appropriation and non-ownership flow-down provisions in §1.5.4 and §1.5.5. The current execution status of each is available to Tenants on request via dpo@alexcare.tech. Sub-processor additions are notified in advance per the terms of the applicable Tenant DPA, with a right to object where the DPA so provides. A sub-processor that violates the anti-appropriation or non-ownership provisions is subject to immediate suspension and removal.
7.4 With Payers, Government Health Schemes, Regulators
Where you consent to insurance claim submission, or where the Tenant's care model requires eligibility verification, we transmit claim data to payer systems (BHYT, NHSO, PhilHealth, BPJS, MEDIBRIDGE, HMO/TPA, Medicare/Medicaid, private insurers). We disclose to health authorities where mandated (public health reporting; adverse-event reporting; disease-surveillance obligations).
7.5 Under Legal Compulsion
We disclose Personal Data where required by law, subpoena, court order, or lawful government request, applying (a) narrow scoping to only the data legally compelled, (b) validity checks on the compelling instrument, (c) challenges where legally overbroad, and (d) transparency reporting on aggregate government-request volume (we intend to publish an annual government-request transparency report; the first publication cadence will be confirmed once the first reporting cycle completes).
7.6 In Corporate Transactions and Insolvency
In a merger, acquisition, sale of assets, financing, insolvency, reorganisation, restructuring, spin-off, or similar corporate transaction, Personal Data may transfer to the successor entity only in a custodial capacity, never as a proprietary asset. The full sovereignty commitments in §1.5.6 (Corporate Transactions) and §1.5.7 (Insolvency and Wind-Down) apply - including successor undertakings to be bound by this Notice, patient-notification rights with a meaningful opportunity to exercise portability or erasure before transition, and, in insolvency, appointment of a consumer privacy ombudsman where required by applicable law. Patient Personal Data and PHI shall not be treated as a "for-sale" asset of any estate. Where no Qualified Successor Operator can be identified, patient data is returned or exported to the patient and thereafter deleted from ALEX systems in accordance with applicable clinical-record retention law.
7.7 With Professional Advisers
Auditors, lawyers, insurers, and accountants where necessary to obtain professional advice, under confidentiality obligations.
7.8 We Do Not Sell Personal Data
We do not "sell" Personal Data as that term is defined under the California Consumer Privacy Act / California Privacy Rights Act (see Annex A) or analogously under other laws.
Part 8 - Sub-Processors
The current list of sub-processors is maintained at Appendix 1 to this Notice. Categories of sub-processor include:
| Category | Purpose |
|---|---|
| Cloud infrastructure (regional hosting) | Compute, storage, database, network |
| Managed database services | Primary and analytics data stores |
| CDN & DDoS protection | Network performance and security |
| Email & transactional messaging | Notifications, receipts, security alerts |
| SMS & WhatsApp/LINE gateways | Patient reminders and OTP delivery |
| Payment processing | PCI DSS Level 1 processors - we do not store card PAN |
| Analytics (product & marketing) | Usage understanding and A/B testing (de-identified) |
| Customer support tooling | Ticketing, in-app messaging |
| Identity verification / KYB / KYC | Onboarding checks for Tenants and, where required, patients |
| AI/ML infrastructure | Model hosting, training compute (de-identified or synthetic data by default) |
| Backup & disaster recovery | Cross-region recovery |
| Security & SIEM | Threat detection, incident response |
| Bot protection | Distinguishing people from automated programs on website forms |
| E-signature | Contract execution |
| Domain registration and email domain services | Administration of ALEX domains and mailboxes |
We disclose the specific provider identity, function, and processing location for each sub-processor in Appendix 1. Data subjects may request the current list by emailing dpo@alexcare.tech.
Part 9 - International Data Transfers
9.1 Data Residency Position
Wherever feasible, we host data in the region of the data subject and the Tenant - for example, ASEAN Tenant patient data in Singapore or Malaysia data-region availability zones. Certain global services (identity federation, aggregate telemetry, security threat intelligence) are inherently cross-border.
9.2 Transfer Mechanisms
Where cross-border transfer occurs, we rely on the following mechanisms as applicable to the sending jurisdiction:
| Sending Region | Mechanism(s) |
|---|---|
| EEA / UK | ALEX Tech Pte. Ltd. relies on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, with a Transfer Impact Assessment for each transfer channel, for transfers of Personal Information from the EEA and UK to Singapore. Adequacy decisions are relied on where available. Binding Corporate Rules are not currently in place. Art. 49 derogations are used only in limited circumstances. |
| Switzerland | Swiss Federal Data Protection and Information Commissioner-approved SCCs |
| Singapore | Transfer conditions under PDPA s.26 read with the PDP Regulations - comparable-standard contracts; ASEAN Model Contractual Clauses where in use; consent where applicable |
| Thailand | PDPA s.28 to s.29 - adequacy per PDPC list; standard contractual clauses; explicit consent for cross-border transfer of Sensitive Personal Data with material-risk disclosure |
| Malaysia | PDPA s.129 whitelist compliance (under the 2024 amendment framework); consent; adequate safeguards |
| Philippines | NPC Circular 20-03 (or successor) cross-border transfer requirements; contractual safeguards; accountability principle enforcement |
| United States | HIPAA-compliant BAA flow-downs; state-law transfer conditions where applicable |
| Other | Equivalent mechanisms under Applicable Data Protection Law |
9.3 Countries We May Transfer To
Personal Data may be transferred to and processed in: Singapore, Malaysia, Thailand, Philippines, Indonesia, Vietnam, Japan, Australia, Hong Kong, India, the United States, the United Kingdom, Ireland, Germany, the Netherlands, and other countries where our sub-processors operate. The processing-country for each sub-processor is disclosed in Appendix 1.
9.4 Transfer Impact Assessments
For each transfer channel, we maintain a Transfer Impact Assessment addressing (a) the specific transfer, (b) applicable third-country law and practice, (c) contractual, technical and organisational safeguards, and (d) any supplementary measures. Available to competent authorities on request.
Part 10 - Retention
We retain Personal Data only for as long as necessary for the purposes described in Part 5, subject to legal and regulatory minimum-retention requirements. The category-level retention rules set out in the table below constitute our Data Retention Schedule for the purposes of this Notice:
| Category | Retention Rule |
|---|---|
| Patient clinical record / PHI held for a Tenant | Retained per the Tenant's clinical-record retention policy and applicable state, federal, and country medical-record retention law. Note: HIPAA does not prescribe a medical-record retention period; the six-year HIPAA retention period at 45 CFR § 164.530(j) applies to specified compliance documentation - policies, procedures, authorisations, accounting-of-disclosures logs, and BAA records - and not to the underlying medical record. State medical-record laws often require 7 to 25 years post last encounter; SG Private Hospitals & Medical Clinics Act - 6 years from last consultation, 25 years for minors from age of majority; TH - 5 years from last treatment as a floor, longer for specific record classes; MY - per MOH Circulars; PH - per DOH Administrative Order. |
| Patient identity and consent records held through the Patient Application | For the duration of the active patient account plus 6 years post-closure for legal defensibility, unless a data-subject deletion request is exercised and no legal hold applies |
| Tenant workforce authentication logs | 12 months rolling for operational logs; 6 years for security incident forensic logs |
| Evaluation User content, telemetry, and session data | Retained during Evaluation Access and, on termination or expiry of Evaluation Access, subject to deletion by ALEX Tech in accordance with Terms of Service §5.5(f); ALEX Tech may retain aggregate or de-identified evaluation-usage telemetry for platform-improvement purposes consistent with the de-identified/aggregated retention rule below and with Terms of Service §5.5(e) |
| Corporate marketing leads | 24 months post last engagement, including the technical details recorded with a website request (§3.4); consent-based email marketing consent refreshed per applicable law |
| Billing & financial records | 7 years (US IRS / SG IRAS / applicable tax authority) - some regions require 10 years |
| Cookies and similar technologies | Strictly necessary cookies: session, or up to 30 days for fraud and security signals. Consent-preference record: 12 months, renewed on any change of choice. Functional and preference cookies: up to 12 months, except remembered interface state at up to 6 months. First-party analytics on the corporate site: up to 13 months. Error and performance telemetry: up to 30 days. Consent records: duration of the associated processing plus 3 years. Per-cookie detail is set out in the ALEX Cookie Policy, available on request. |
| Backups | Encrypted backups purged on the 35-day rolling window unless subject to legal hold |
| De-identified / aggregated datasets | Indefinite for legitimate research and platform improvement purposes; identifiable data purged per category rule above |
Where a data subject requests erasure, we apply the request across primary systems, backups within the backup rotation window, and sub-processors - subject to (a) legal-hold exceptions, (b) HIPAA record-retention duties held by the Covered-Entity Tenant (a Business Associate cannot delete PHI unilaterally against a Covered Entity's retention obligation), and (c) freedom-of-expression exceptions where applicable.
Part 11 - Security Measures
Programme statement. ALEX Tech Pte. Ltd. is progressively implementing, and targets completion by 31 December 2026 unless an individual control below states otherwise, the technical and organisational security programme described in this Part 11. Certifications and independent assessments are listed in Part 11.7 and are separately gated on the external audit timelines stated there. Independent third-party audit or certification against any control listed in this Part has not yet been performed; the current programme status and evidence for each control is described in Part 11.7 and, at a per-control level of detail, in the control register available on request to Tenants and to competent authorities via dpo@alexcare.tech.
11.1 Governance
- We are appointing a named Chief Information Security Officer accountable to the Board.
- Our ISMS is designed to align with ISO/IEC 27001 and ISO/IEC 27701 and is being progressively implemented.
- HIPAA Security Rule Administrative, Physical, and Technical Safeguards (45 CFR §§ 164.308, 164.310, 164.312) are being implemented per the roadmap.
- SOC 2 Type II audit programme initiated; independent audit targeted for Q4 2028 (see §11.7). No SOC 2 Type II report is currently available.
11.2 Access Controls
- Role-based access control across primitives and services is being progressively implemented.
- Multi-factor authentication will be mandatory for all workforce, admin, and privileged Tenant accounts as the programme completes.
- Just-in-time privileged access with approval workflow and time-bound elevation is being implemented.
- Zero-trust network architecture and workload identity for service-to-service authentication are being implemented.
- Minimum-necessary access principle is being enforced through service-level scope tokens.
11.3 Encryption
- Data-in-transit: TLS 1.3 is targeted; TLS 1.2 permitted only for legacy Tenant integrations under a documented exception during transition.
- Data-at-rest: AES-256 with envelope encryption is being implemented; a customer-controlled Key Management Service (BYOK) for eligible Enterprise Tenants is on the roadmap.
- End-to-end encryption is planned for specified sensitive communications channels; the channel list will be published as each channel is enabled.
- Cryptographic modules FIPS 140-2 (transitioning to FIPS 140-3) validated modules will be used where applicable as the programme completes.
11.4 Payment Data
- PCI DSS scope is minimised - no full PAN storage; tokenisation at PCI Level 1 processor; ALEX systems are within Merchant / Service Provider scope. The applicable Self-Assessment Questionnaire (or full Report on Compliance where required) is maintained and made available to Tenants on request via dpo@alexcare.tech.
11.5 Monitoring, Logging and Response
- Centralised SIEM with 24/7 monitoring is being progressively stood up.
- Immutable audit logs for PHI/Personal Data access are being implemented.
- Documented incident-response plan is being finalised; annual testing is planned once the plan is finalised.
- Vulnerability management: Critical 7 days, High 30 days, Medium 90 days are internal remediation targets, to become operational SLA commitments on completion of the security programme in Q4 2026. Until that completion, ALEX Tech operates against these targets as programme objectives and reports cycle-time metrics to Tenants on request via dpo@alexcare.tech; no external SLA commitment for these windows is currently in force.
- External penetration testing at least annually is targeted; targeted testing on material feature launches will be conducted as those launches occur.
11.6 Personnel
- Background checks are planned for personnel with PHI/Personal Data access (subject to local law).
- Mandatory annual privacy and security training with role-specific modules is being implemented.
- Contractual confidentiality obligations survive termination.
11.7 Certifications & Attestations
| Framework | Status |
|---|---|
| SOC 2 Type II | Programme initiated; independent audit targeted for Q4 2028. No completed report currently available. |
| ISO/IEC 27001 | ISMS designed to ISO/IEC 27001 controls; certification audit targeted for Q4 2028. Not yet certified. |
| HIPAA Security Rule Attestation | Self-attested compliance in progress; independent third-party assessment targeted for Q4 2028. |
11.8 Limitations
No security system is impenetrable. While we take substantial measures to protect Personal Data, we cannot guarantee absolute security. Where we identify a Personal Data Breach affecting your data, we follow Part 12.
Part 12 - Data Breach Notification
We maintain an incident-response programme that identifies, contains, investigates and notifies Personal Data Breaches consistent with legal requirements across jurisdictions.
| Jurisdiction | Notification Rule |
|---|---|
| GDPR / UK GDPR | Supervisory authority within 72 hours of becoming aware, where the breach is likely to result in risk to rights and freedoms; data subjects "without undue delay" where high risk |
| PDPA-SG | Personal Data Protection Commission notification within 3 calendar days where significant harm or scale threshold met; affected individuals as soon as practicable |
| PDPA-TH | PDPC (Thailand) notification within 72 hours where risk to rights and freedoms; affected data subjects where high risk |
| PDPA-MY | Personal Data Protection Commissioner notification per 2024 Amendment Act - 72 hours; affected data subjects where required |
| DPA-PH | NPC notification within 72 hours of knowledge/reasonable belief; affected data subjects; where 100+ affected, published notice may be required |
| HIPAA / HITECH | Individuals: within 60 days of discovery; HHS Secretary: annually for breaches <500, within 60 days for breaches ≥500; media: for breaches ≥500 in a state/jurisdiction. Business Associate obligation to notify Covered Entity within 60 days of discovery (contractually shorter - see BAA) |
| DPDPA-IN (India) | Intimation to the Data Protection Board of India and to each affected Data Principal in the form and manner prescribed under s.8(6) of the DPDPA 2023 and any Rules made thereunder - see Annex G §G.9 |
| Others | Per Annex H |
Notification content includes: nature of the breach, categories and approximate numbers of individuals and records concerned, name and contact of the DPO, likely consequences, measures taken or proposed, and recommended protective steps for affected individuals.
Part 13 - Your Rights
The rights available to you depend on the jurisdiction whose law applies to the Processing. Full jurisdictional detail appears in the Annexes. Common core:
Sovereignty framing: the rights described in this Part 13 are the operational expression of the Patient Data Sovereignty commitment in §1.5. They are inalienable in substance - no term of any contract between ALEX and any Tenant, Partner, sub-processor, or successor derogates from them, and no assertion of ownership by any such party defeats them. ALEX supports the exercise of these rights on a good-faith, plain-language, free-of-charge basis (for the first request in any 12-month period), with proportionate identity verification and within the statutory response windows below.
Application to Evaluation Users. Where an Evaluation User is a natural person, the rights in this Part 13 apply to Personal Data of the Evaluation User Processed by ALEX Tech Pte. Ltd. as Controller under §1.3 (audience 3) - including intake data, account credentials, and evaluation-environment session and telemetry data. The Evaluation User is prohibited under Terms of Service §5.5(b) from submitting real Personal Data or PHI of third-party natural persons to any evaluation environment; where such submission nevertheless occurs, the affected third-party data subject retains all rights under this Part 13 exercisable against ALEX Tech Pte. Ltd., and ALEX Tech Pte. Ltd. handles the resulting Personal Data as data received in error and takes remediation action under Part 12 (breach handling where the breach threshold is met) and this Part 13. Terms of Service §5.5(i) provides for Evaluation User indemnity in respect of such improper submission.
13.1 Right to Be Informed
You have the right to know we are processing your data, why, and how - the purpose of this Notice.
13.2 Right of Access
You may obtain confirmation whether we process your data, a copy of your data, and prescribed metadata.
13.3 Right to Rectification / Correction
You may require inaccurate data to be corrected and incomplete data completed.
13.4 Right to Erasure / Deletion ("Right to be Forgotten")
You may request deletion of your data, subject to exceptions (legal-obligation retention; freedom of expression; public interest in health / research / archiving; establishment, exercise or defence of legal claims; Covered-Entity retention duties over PHI).
13.5 Right to Restrict Processing
You may require Processing to be paused during accuracy disputes, unlawful-processing claims, or when we no longer need data but you require it for legal claims.
13.6 Right to Data Portability
You may receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller. For patient data held through the Platform, this right is supported to the extent of the export capability generally available at the time of the request.
13.7 Right to Object
You may object to Processing based on legitimate interests, including profiling; you have an absolute right to object to direct marketing.
13.8 Rights in Relation to Automated Decision-Making
As described in Part 6.2.
13.9 Right to Withdraw Consent
Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing. Granular consent management is provided through the in-application controls of the Patient Application and through our consent-management system, feature by feature as each consent-bearing feature is released to your deployment.
13.10 Right to Lodge a Complaint
You may complain to your supervisory authority. Contact details in Annexes.
13.11 How to Exercise Your Rights
- Free of charge for the first request in any 12-month period (except where manifestly unfounded or excessive, in which case a reasonable fee may apply or the request may be refused).
- Identity verification proportionate to the request - we ask for information reasonably necessary to confirm identity, and no more. We do not require notarised documents unless the sensitivity of the request and the applicable law makes it strictly necessary.
- Response time - one month under GDPR (extendable +2 months for complex requests with notice); 30 days under PDPA-SG and DPA-PH; 30 days under HIPAA (extendable +30 days); 45 days under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), extendable by a further 45 days on written notice to the requesting consumer under Cal. Civ. Code §1798.130(a)(2); 45 days under the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and the Texas Data Privacy and Security Act (each extendable in accordance with the applicable statute); shorter statutory windows honoured where applicable.
- Submission channels - email privacy@alexcare.tech; postal request to the addresses in §1.2. An in-application request flow is provided within the Patient Application and the Tenant Application feature by feature as each flow is released to your deployment; the email and postal channels above are available in all cases.
- No adverse consequences for exercising your rights.
13.12 Right to Appeal Denial of Rights Requests (US State Comprehensive Privacy Laws)
Where a rights request submitted to ALEX Tech Pte. Ltd. under the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, or the Texas Data Privacy and Security Act is denied in whole or in part, you have the right to appeal that denial. Appeals are administered as follows:
- Appeal window: 45 days from receipt of the appeal for VCDPA, CPA, CTDPA, and TDPSA. UCPA does not codify a statutory appeal right; where you nevertheless wish to escalate a UCPA-based denial, ALEX Tech Pte. Ltd. will treat the escalation as an appeal on the same 45-day cycle as a matter of practice.
- Submission channel: appeals may be submitted to privacy@alexcare.tech with the subject line "Rights Request Appeal - [Statute] - [Original Request Reference]".
- Response content: ALEX Tech Pte. Ltd. will inform you in writing of any action taken or not taken in response to the appeal, together with a written explanation of the reasons for the decision.
- Onward escalation: where the appeal is denied, ALEX Tech Pte. Ltd. will provide you with an online mechanism, if available, or other method through which you may contact the attorney general of the relevant State to submit a complaint. Attorney-general contact information is set out in Annex A.4.
Part 14 - Children and Minors
We do not knowingly collect Personal Data directly from children under the age of digital consent applicable in the jurisdiction (US COPPA: under 13; EEA: 13 to 16 as set by member state; UK: 13; SG: 13 per PDPC guidance; TH: 20 as age of majority with parental consent below; MY: 18; PH: 18). Where children's health data is processed by a Tenant configuring paediatric care workflows on the Platform, the Tenant is the Controller and administers parental / guardian consent under its own care governance. Patient Application accounts are subject to age-appropriate design principles and, where opened for minors, are controlled through parent / guardian custodial accounts.
If we learn that we have inadvertently collected Personal Data directly from a child in breach of applicable law, we will delete it promptly. Contact privacy@alexcare.tech.
Part 16 - Third-Party Sites and Integrations
Our services may link to, or integrate with, third-party sites and services - including government health portals, payer systems, insurer portals, e-signature providers, and app-store deep links. Third parties operate under their own privacy notices; we accept no responsibility for third-party privacy practices. However, where we integrate third-party services on your behalf in delivering ALEX, we perform due diligence and, where the third party processes your Personal Data at our instruction, we impose contractual data-protection obligations.
Part 17 - Changes to This Notice
17.1 Cadence
This Notice is reviewed at least annually. Material changes are announced with a minimum of 30 days' advance notice; non-material updates (typographical corrections, clarifications, sub-processor list refreshes) take effect on publication with the updated Effective Date.
17.2 Notice Channels
- Effective Date, Last Updated date, and Version updated in the header metadata block at the top of this Notice.
- Material changes emailed to registered account holders and posted as an in-app notification.
17.3 Prior Versions
Superseded issues are retained for at least 6 years from the date each ceases to be current, and are available at any time on request via dpo@alexcare.tech.
17.4 Translations
As at the Effective Date, this Notice is published in English. Localised versions in the primary language of each operating country will be published as ALEX Tech Pte. Ltd. onboards operations in that country, and will be updated in accordance with §17.1. In the event of conflict between the English original and a localised version, the English original prevails except where local law mandates the local-language version prevail (see Annexes D, E, F). Translation requests may be sent to dpo@alexcare.tech.
Part 18 - Contact Us and Our DPO
Each channel listed below is monitored by an accountable owner within ALEX Tech Pte. Ltd.; response times are governed by the applicable statutory response window under the relevant law described in Part 13 and the jurisdictional Annexes.
| Contact Purpose | Channel |
|---|---|
| Data Protection Officer (Group) | Yakin Patel · dpo@alexcare.tech · postal: ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422 |
| US HIPAA Privacy Officer | Yakin Patel (same appointee as Group DPO) · dpo@alexcare.tech |
| EEA Representative under GDPR Art. 27 | Not currently applicable - ALEX Tech Pte. Ltd. does not, as at the Effective Date, offer the Platform to data subjects in the EEA on a targeted basis, nor monitor their behaviour in the EEA, within the meaning of Art. 3(2) GDPR. An Art. 27 representative will be designated and this Notice updated before any such targeting commences. Data subjects in the EEA may in the interim contact us at dpo@alexcare.tech. |
| UK Representative under UK GDPR Art. 27 | Not currently applicable - ALEX Tech Pte. Ltd. does not, as at the Effective Date, offer the Platform to data subjects in the UK on a targeted basis, nor monitor their behaviour in the UK, within the meaning of Art. 3(2) UK GDPR. A UK GDPR Art. 27 representative will be designated and this Notice updated before any such targeting commences. Data subjects in the UK may in the interim contact us at dpo@alexcare.tech. |
| Singapore DPO | Yakin Patel (same appointee as Group DPO) · dpo@alexcare.tech · postal: ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422 |
| Thailand DPO | Yakin Patel (same appointee as Group DPO) · dpo@alexcare.tech |
| Malaysia DPO | Yakin Patel (same appointee as Group DPO) · dpo@alexcare.tech |
| Philippines DPO | Yakin Patel (same appointee as Group DPO) · dpo@alexcare.tech |
| India Grievance Officer under DPDPA 2023 s.8(10) | Yakin Patel (interim, discharging the Grievance Officer function on a company-officer basis pending threshold triggers for local appointment as described in Annex G §G.3) · dpo-in@alexcare.tech |
| General Privacy Enquiries | privacy@alexcare.tech |
| Security Vulnerability Reports | security@alexcare.tech |
Annex A - United States (HIPAA / HITECH / State Laws / CCPA-CPRA)
A.1 HIPAA / HITECH Framework
ALEX Tech Pte. Ltd. is the Business Associate counterparty (and, in some flows, Business Associate Subcontractor) for US Covered Entity Tenants. ALEX Tech Pte. Ltd. does not currently operate a US operating vehicle. If and when a US operating vehicle is established, this Notice will be amended and republished before that vehicle Processes any Personal Information. Business Associate Agreements meeting 45 CFR § 164.504(e) are executed by ALEX Tech Pte. Ltd. (and, if and when a US operating vehicle is established and this Notice is republished, by that US operating vehicle in addition to or in substitution for the Singapore parent). ALEX Tech complies with the HIPAA Privacy Rule (45 CFR Part 164 Subpart E) to the extent obligated by HIPAA and by contract, and with the Security Rule (Subpart C) per the security programme described in Part 11. HITECH breach notification obligations at 45 CFR § 164.410 apply - see Part 12.
A.2 Notice of Privacy Practices (NPP)
The NPP required under 45 CFR § 164.520 is issued by each Covered Entity Tenant - not by ALEX - because the NPP is the Covered Entity's obligation. Where you receive care from an ALEX Tenant, ask the Tenant for its NPP. Where ALEX operates as a Covered Entity in respect of any direct-to-consumer offering (for example, certain patient-facing healthcare functions of the Platform offered to a patient directly and without a Tenant relationship), the ALEX NPP is published at alexcare.tech/notice-of-privacy-practices and is available on request via dpo@alexcare.tech.
A.3 State Laws
We recognise the following US state laws as applicable where their preconditions are met:
- California: CCPA/CPRA - see A.4.
- Virginia: Virginia Consumer Data Protection Act (VCDPA).
- Colorado: Colorado Privacy Act (CPA). ALEX Tech Pte. Ltd. does not sell Personal Information and does not process Personal Information for targeted advertising, and as at the Effective Date sets no cookie for either purpose (see Part 15). We will recognise and honour universal opt-out mechanisms recognised by the Colorado Attorney General under 4 CCR 904-3 Rule 5.05, including the Global Privacy Control, from the date the consent mechanism described in Part 15 is deployed and in any event before any such processing begins. Additional universal opt-out mechanisms recognised by the Colorado Attorney General from time to time will be honoured on the same basis.
- Connecticut: Connecticut Data Privacy Act (CTDPA).
- Utah: Utah Consumer Privacy Act (UCPA).
- Texas: TDPSA; Texas Medical Records Privacy Act.
- Washington: My Health My Data Act (MHMDA).
- New York: SHIELD Act. ALEX Tech Pte. Ltd. monitors pending state health-privacy legislation including the New York Health Information Privacy Act (S929) and will update this Notice on enactment.
- Other US state comprehensive privacy laws as they take effect.
A.4 California Notice (CCPA/CPRA)
- Categories of Personal Information collected - see Part 3 mapped to CCPA §1798.140(v) categories.
- Sources - directly from you; from your Tenant; from public records where lawful; from service providers.
- Purposes - Part 5.
- Sharing / "Sharing" for cross-context behavioural advertising - we do not "sell" or "share" PI as those terms are defined under the CPRA. We do not process Sensitive Personal Information for inferences beyond authorised purposes.
- Rights: Right to know / right of access / right to correct / right to delete / right to opt-out of sale-or-sharing (we do not sell or share; the toggle is nonetheless available) / right to limit use of Sensitive PI / right against retaliation.
- Response window: ALEX Tech Pte. Ltd. will respond to a verifiable consumer request within 45 days of receipt as required by Cal. Civ. Code §1798.130(a)(2). Where reasonably necessary, ALEX Tech Pte. Ltd. may extend the response period by an additional 45 days on written notice to the requesting consumer within the initial 45-day period, stating the reason for the extension.
- How to exercise: privacy@alexcare.tech. We do not sell or share Personal Information and, as at the Effective Date, set no cookie that would constitute a sale or sharing. A "Your California Privacy Rights" footer link and a sale-and-share opt-out control will be provided together with the consent mechanism described in Part 15; until then all California rights requests are handled through the email channel above.
- Authorised agents - accepted with verification.
- Retention notice - Part 10 satisfies the CCPA disclosure requirement.
- Right of appeal for other US state privacy-law denials - Part 13.12 sets out the appeal mechanism for denials of rights requests under the VCDPA, CPA, CTDPA, UCPA, and TDPSA. The CCPA/CPRA does not codify a consumer-appeal right; consumers denied under CCPA/CPRA may lodge a complaint with the California Privacy Protection Agency at cppa.ca.gov or with the California Attorney General at oag.ca.gov.
- Attorney-general contacts for appeal-denial escalation (Part 13.12). Virginia: Office of the Attorney General, oag.state.va.us. Colorado: Colorado Attorney General, coag.gov. Connecticut: Office of the Attorney General, portal.ct.gov/AG. Utah: Utah Attorney General, attorneygeneral.utah.gov. Texas: Office of the Attorney General, texasattorneygeneral.gov.
A.5 Health-Specific
For Washington MHMDA and analogous consumer-health-data laws, we do not collect or process "consumer health data" outside of a HIPAA-covered relationship without the geolocation-and-consent-and-disclosure regime prescribed. Geofencing around healthcare facilities is not conducted.
A.6 No Ownership of PHI under HIPAA
HIPAA does not confer "ownership" of PHI on Covered Entities or Business Associates in any commercial sense. Older healthcare-vendor and provider contracts sometimes assert that "the provider owns the medical record"; that assertion, insofar as it purports to derogate from patient rights under 45 CFR §§ 164.524 (access), 164.526 (amendment), 164.528 (accounting of disclosures), 164.522 (restriction and confidential communications), and 164.508 (authorisation for uses beyond TPO), is not enforceable against those rights. The custodial and record-integrity obligations of a Covered Entity under HIPAA and state medical-record law run to the patient (and to the licensing regulator) - not against the patient's underlying substantive rights. ALEX Tech Pte. Ltd., as Business Associate, does not assert ownership of PHI; every US Tenant BAA includes a mirror non-ownership acknowledgement per §1.5.3.
A.7 Bankruptcy - Consumer Privacy Ombudsman
In any US Chapter 11 sale or § 363 asset disposition by ALEX Tech Pte. Ltd. or by any US Tenant that would involve personally identifiable information of patients, ALEX Tech will not oppose (and will affirmatively support) the appointment of a Consumer Privacy Ombudsman under 11 U.S.C. § 332, with the objective that any successor operator inherits the sovereignty commitments in §1.5 as a condition of the sale.
Annex B - European Economic Area & United Kingdom (GDPR / UK GDPR)
B.1 Applicability
This Annex applies where the GDPR or UK GDPR applies to Processing - including under Art. 3(2) extraterritorial jurisdiction where we offer services to, or monitor the behaviour of, individuals in the EEA/UK.
B.2 Controller
As stated in §1.2 and §1.6, ALEX Tech Pte. Ltd. is the operational Controller (and, for the patient-sovereign functionality, Joint Controller under Art. 26 with the patient) in respect of Processing described in this Notice. The essence of the Article 26(2) arrangement with respect to the Patient joint-controller construction is available on request via dpo@alexcare.tech, and is published as an appendix to this Notice once settled in final form.
B.3 Legal Bases
As set out in Part 4.1.
B.4 EEA and UK Representatives
As at the Effective Date, ALEX Tech Pte. Ltd. does not fall within Art. 3(2) GDPR or Art. 3(2) UK GDPR (targeted offering to, or behavioural monitoring of, EEA / UK data subjects) and accordingly has not designated an Art. 27 representative under GDPR or UK GDPR. If ALEX Tech Pte. Ltd. commences activities that trigger Art. 3(2) of either regime, an Art. 27 representative will be designated in the relevant jurisdiction and this Notice updated. Data subjects in the EEA and UK may in the interim contact us at dpo@alexcare.tech.
B.5 International Transfers
As set out in Part 9. EU SCCs (2021), UK IDTA / Addendum, and Transfer Impact Assessments are used. Binding Corporate Rules are not currently in place.
B.6 Data Subject Rights
The full suite of GDPR rights (Art. 15 to 22 and Art. 77) is honoured - see Part 13. The right to lodge a complaint may be exercised with any EEA supervisory authority. Because ALEX Tech Pte. Ltd. has no establishment in the EU and does not, as at the Effective Date, engage in Processing falling within Art. 3(2) GDPR, the one-stop-shop mechanism (Art. 56 GDPR) does not apply. If and when ALEX Tech Pte. Ltd. establishes an EU main establishment or commences Art. 3(2)-triggering activities, the applicable lead supervisory authority will be identified and this Notice updated. In the interim, data subjects in the EEA may lodge a complaint with the supervisory authority in their Member State of residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
B.7 DPIA
For high-risk processing (large-scale health data processing; systematic monitoring; automated decision-making - GDPR Art. 35), Data Protection Impact Assessments are being progressively completed as each high-risk Processing operation is launched. DPIA status per Processing operation is available to competent authorities on request.
B.8 EU AI Act Positioning
See Part 6.4, including the Article 50 synthetic-content-labelling commitment applicable to AI-generated content produced by the Platform where offered to users in the EU.
Annex C - Singapore (PDPA)
C.1 Applicability
Applies to Processing subject to the Personal Data Protection Act 2012 (as amended) and the PDP Regulations.
C.2 Organisation
ALEX Tech Pte. Ltd. is the sole "organisation" for PDPA-SG purposes in respect of Personal Data collected, used, or disclosed through the ALEX Platform.
C.3 Data Protection Officer
Our DPO for Singapore is Yakin Patel (also the Group DPO), contactable at dpo@alexcare.tech or by post at ALEX Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422. This satisfies s.11(3) and the Notification Obligation.
C.4 Consent, Notification, Purpose
We provide notification of purposes at or before collection (s.20). We rely on consent (s.13 to s.17), deemed consent by notification (s.15A) for compatible secondary purposes, the legitimate-interests exception (First Schedule Part 3) for security and business improvement, and other statutory exceptions as applicable.
C.5 NRIC / FIN Handling
We follow the PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers - collecting NRIC/FIN only where required by law, permitted under narrow exceptions (e.g., verifying identity for high-risk transactions), or where the individual has given specific consent.
C.6 Do Not Call Registry
For marketing communications via voice, SMS or fax, we check the Do Not Call Registry before contacting and maintain the required records.
C.7 Data Breach Notification
Notification to the PDPC and affected individuals per the Notifiable Data Breach regime - see Part 12.
C.8 Cross-Border Transfer
Governed by s.26 read with Reg 10 of the PDP Regulations - comparable-standard contracts, ASEAN MCCs where used, and additional safeguards for Sensitive Personal Data.
C.9 Rights of Data Subjects
- Access (s.21) - first request free of charge (fee only where request is excessive).
- Correction (s.22).
- Withdrawal of consent (s.16).
- Data portability: the Singapore PDPA data-portability obligation (introduced by the 2020 amendment and codified at Part 6B) will take effect only upon issuance of implementing regulations by the Singapore Government; as at the Effective Date, no such implementing regulations are in force, and no statutory data-portability right is currently exercisable against ALEX Tech Pte. Ltd. under PDPA-SG. As a matter of platform commitment, ALEX Tech Pte. Ltd. voluntarily supports a data-export capability for Personal Data held about a Singapore data subject on request via dpo@alexcare.tech; this voluntary capability is distinct from the statutory right and does not amount to a waiver, admission, or expansion of the statutory position.
C.10 Complaints
PDPC, pdpc.gov.sg.
Annex D - Thailand (PDPA B.E. 2562)
D.1 Applicability
Applies where the PDPA-TH applies, including extraterritorially where we offer services to data subjects in Thailand or monitor their behaviour.
D.2 Local Presence
Under s.37(5) of the Thailand PDPA, ALEX Tech Pte. Ltd. has designated ArcNovo Tech (Thailand) Co. Ltd., acting in its capacity as authorised distributor of the Platform for ALEX Tech Pte. Ltd., as its local representative in Thailand. ArcNovo Tech (Thailand) Co. Ltd. is a Thai-incorporated commercial distributor. It acts as local representative only, and is not a Controller or Processor of Personal Data Processed through the Platform. Data subjects in Thailand and the Thailand Personal Data Protection Committee (PDPC) may contact the local representative through dpo@alexcare.tech, which is the published channel routed to the Group Data Protection Officer, who liaises with the local representative for statutory obligations under s.37(5).
D.3 DPO
Under s.41 of the Thailand PDPA, ALEX Tech Pte. Ltd. is required to appoint a Data Protection Officer given the scale of its Sensitive Personal Data Processing. The Group DPO is Yakin Patel (dpo@alexcare.tech), who discharges the s.41 DPO function in respect of Thailand-related Processing pending designation of a Thailand-country-specific DPO. Local liaison for Thai-language enquiries and for coordination with ArcNovo Tech (Thailand) Co. Ltd. as local representative under §D.2 is available through dpo@alexcare.tech. A Thailand-country-specific DPO will be designated, and this Annex updated, at the incorporation of an ALEX Tech country subsidiary in Thailand or at the point at which Thailand-specific operating conditions require country-based appointment, whichever occurs earlier. The Thailand PDPC and data subjects in Thailand may in the interim rely on the Group DPO designation set out in this §D.3 as satisfying the s.41 identification requirement.
D.4 Legal Bases
- Non-sensitive Personal Data: bases in s.24.
- Sensitive Personal Data (health data, biometric, etc.): explicit consent under s.26 unless s.26 exceptions apply.
D.5 Language
As at the Effective Date, this Notice is published in English. A Thai-language version of this Notice, and Thai-language consent forms and rights-exercise workflows, will be published before onboarding of any additional Thai patients or data subjects beyond current customers served through ArcNovo Tech (Thailand) Co. Ltd.'s Platform distribution. Where a Thai translation is subsequently published and conflicts with the English original, the Thai translation prevails to the extent required by Thai law and PDPC guidance. In the interim, Thai-speaking data subjects may contact dpo@alexcare.tech for assistance in Thai.
D.6 Cross-Border Transfer
Per s.28 to s.29 - adequacy assessment, contractual safeguards, or explicit consent with material-risk disclosure.
D.7 Rights
As set out in Part 13, given effect through PDPA-TH Chapter 3.
D.8 Complaints
PDPC Thailand, pdpc.or.th.
Annex E - Malaysia (PDPA 2010 as Amended 2024)
E.1 Applicability
Applies where PDPA-MY applies, including under the 2024 Amendment Act extraterritorial provisions.
E.2 Registration
ALEX Tech Pte. Ltd. is completing PDPA-MY Class of Data User registration under the Healthcare Class where required under the 2024 amendment framework, and the applicable ALEX Tech country subsidiary (once and if incorporated in Malaysia) will assume that registration where local law so requires. Until any Malaysian subsidiary is incorporated, ALEX Tech Pte. Ltd. files as the extraterritorial Data User under the 2024 amendment framework.
E.3 DPO
Under the PDPA (Amendment) Act 2024 (Malaysia), ALEX Tech Pte. Ltd. is required to appoint a Data Protection Officer for its Processing subject to PDPA-MY. The Group DPO is Yakin Patel (dpo@alexcare.tech), who discharges the DPO function in respect of Malaysia-related Processing pending designation of a Malaysia-country-specific DPO. Local liaison for Bahasa Malaysia enquiries is available through dpo@alexcare.tech. A Malaysia-country-specific DPO will be designated, and this Annex updated, at the incorporation of an ALEX Tech country subsidiary in Malaysia or at the point at which Malaysian operating conditions require country-based appointment, whichever occurs earlier. The Malaysian Personal Data Protection Commissioner and data subjects in Malaysia may in the interim rely on the Group DPO designation set out in this §E.3 as satisfying the PDPA-MY DPO identification requirement introduced by the 2024 amendment framework.
E.4 Consent and Sensitive Data
Explicit consent obtained for Sensitive Personal Data (s.40).
E.5 Language
As at the Effective Date, this Notice is published in English. A Bahasa Malaysia version of this Notice will be published together with English-language operations in Malaysia in compliance with PDPA-MY s.7(3), before onboarding of any Malaysian data subjects. Where the Bahasa Malaysia version is subsequently published and Malaysian law requires the BM version to prevail, the BM version prevails. Translation requests may be sent to dpo@alexcare.tech.
E.6 Cross-Border Transfer
Per s.129 (and the 2024 amendment framework) - whitelist compliance, consent, adequate safeguards.
E.7 Breach Notification
Per 2024 amendment - 72 hours to the Commissioner where required - see Part 12.
E.8 Data Portability
Per the 2024 amendment - supported to the extent of the export capability generally available at the time of the request.
E.9 Rights
As Part 13.
E.10 Complaints
JPDP, pdp.gov.my.
Annex F - Philippines (Data Privacy Act 2012, RA 10173)
F.1 Applicability
Applies where DPA-PH applies. As data controllers processing Sensitive Personal Information of Filipino data subjects and operating through Filipino Tenants, ALEX Tech Pte. Ltd. is subject to NPC registration and notification requirements as described in F.2.
F.2 NPC Registration
ALEX Tech Pte. Ltd. is completing NPC Data Protection System registration and DPO notification; the certificate of registration will be maintained on file and referenced here once issued.
F.3 DPO
Under s.14 of the Data Privacy Act 2012 (RA 10173) and NPC Circular 16-01, ALEX Tech Pte. Ltd. is required to designate a Data Protection Officer. The Group DPO is Yakin Patel (dpo@alexcare.tech), who discharges the s.14 DPO function in respect of Philippines-related Processing pending designation of a Philippines-country-specific DPO. Local liaison for Philippines-based enquiries and coordination with the NPC is available through dpo@alexcare.tech. A Philippines-country-specific DPO will be designated, and this Annex updated, at the incorporation of an ALEX Tech country subsidiary in the Philippines or at the point at which Philippines operating conditions require country-based appointment, whichever occurs earlier. The NPC and data subjects in the Philippines may in the interim rely on the Group DPO designation set out in this §F.3 as satisfying the s.14 DPO identification requirement, and the Group DPO designation is reflected in the NPC registration referenced in §F.2.
F.4 Legal Bases
Sensitive Personal Information (health) processed only under s.13 bases - consent; medical treatment carried out by a medical practitioner or medical treatment institution where data subject not legally capable of consent; specific laws; or the protection of lawful rights and interests in court proceedings.
F.5 Cross-Border Transfer
Per NPC Circular 20-03 (or successor) with accountability, contractual safeguards, and impact assessment.
F.6 Breach Notification
72 hours to NPC per NPC Circular 16-03 (as amended) - see Part 12.
F.7 PhilSys / PhilHealth Data
Handled under the PhilSys Act (RA 11055) safeguards and PhilHealth data-sharing rules; only used for the specific service purposes disclosed.
F.8 Rights
As Part 13, given effect through DPA-PH Chapter IV.
F.9 Complaints
NPC, privacy.gov.ph.
Annex G - India (Digital Personal Data Protection Act 2023)
G.1 Applicability
The Digital Personal Data Protection Act 2023 (India) ("DPDPA-IN", the "Act") applies to the processing of digital personal data (a) within the territory of India under s.3(a), and (b) outside India where the processing is in connection with the offering of goods or services to Data Principals within India under s.3(b). ALEX Tech Pte. Ltd. acts as Data Fiduciary within the meaning of s.2(i) in respect of personal data of Data Principals within India processed in connection with the Platform. Any entity engaged by ALEX Tech Pte. Ltd. to process such personal data on its behalf acts as Data Processor within the meaning of s.2(k); the identity of any such Data Processor is disclosed through the sub-processor register at Appendix 1 as applicable.
G.2 Data Fiduciary Identification and Notice Contact
The Data Fiduciary is ALEX Tech Pte. Ltd. (UEN 202308966D), 68 Circular Road, #02-01, Singapore 049422. Data Principals within India, and any authorised representative acting on their behalf, may contact the Data Fiduciary through dpo-in@alexcare.tech, which is routed to the Grievance Officer designated under §G.3. This satisfies the identification-of-Data-Fiduciary requirement in s.5(i).
G.3 Grievance Officer under s.8(10)
Under s.8(10), the Data Fiduciary is required to publish the business contact information of a person able to answer questions raised by the Data Principal about the processing of her personal data. The Grievance Officer is Yakin Patel (dpo-in@alexcare.tech), who discharges the function on a company-officer basis pending threshold triggers for a locally-appointed Grievance Officer, mirroring the country-DPO interim posture in Annexes D, E, and F. ALEX Tech Pte. Ltd. will acknowledge any grievance promptly and provide a substantive response within 30 days of receipt, or such shorter period as may be prescribed by Rules made under the Act. Where a Data Principal is not satisfied with the response or does not receive a response within the applicable period, the Data Principal may complain to the Data Protection Board of India per §G.12.
G.4 Notice at Collection (s.5)
The notice provided to a Data Principal at or before the time consent is sought under s.6 satisfies s.5. It sets out (a) the personal data proposed to be processed and the purpose, in itemised form; (b) the manner in which the Data Principal may exercise her rights under ss.11 to 14, including the mechanism for withdrawal of consent as set out in §G.5; and (c) the manner in which the Data Principal may make a complaint to the Data Protection Board of India. Where personal data was collected before commencement of the Act and consent under the Act has not been obtained, the transitional notice required under s.5(2) is provided at the earliest practicable opportunity and in any event before further processing in reliance on prior consent.
G.5 Consent Architecture (s.6)
Consent under s.6 will be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, and will signify agreement to processing for the specified purpose (s.6(1)). Consent will be limited to the personal data necessary for the specified purpose (s.6(2)); any part of the consent that seeks agreement beyond that necessity is to that extent invalid, and processing under that invalid part will not be undertaken. The consent request will be in clear and plain language, with an option to access in English or any language listed in the Eighth Schedule to the Constitution of India (s.6(3)); interim language availability will be extended in line with the India operating footprint, and the current list is available on request via §G.3. Consent is withdrawable at any time, and the mechanism for withdrawal will be as easy as the mechanism by which consent was given (s.6(4) and (5)). On withdrawal, ALEX Tech Pte. Ltd. and its Data Processors will cease processing based on that consent within a reasonable time (s.6(6)); lawful pre-withdrawal processing is unaffected, and consequences arising from the cessation of the specified service are borne by the Data Principal.
G.6 Grounds Other than Consent - Certain Legitimate Uses (s.7)
Where a s.7 ground is available and materially applicable to a specific processing purpose, ALEX Tech Pte. Ltd. may rely on that ground in the alternative to, or in addition to, consent. The s.7 grounds relied on where materially applicable are: (a) s.7(a) - where the Data Principal has voluntarily provided her personal data for the specified purpose and has not indicated non-consent; (b) s.7(g) - processing necessary for responding to a medical emergency involving a threat to life or immediate threat to health of the Data Principal or any other individual; and (c) s.7(i) - processing necessary for the purposes of employment or safeguarding the employer from loss or liability. ALEX Tech Pte. Ltd. does not rely on s.7 grounds relating to State functions (s.7(b) and (c)) or disaster response (s.7(f) and (h), except incidentally through s.7(g) medical-emergency processing), and does not rely on grounds unavailable to a private-sector Data Fiduciary in the ordinary delivery of the Platform.
G.7 Children and Persons with Disability (s.9)
"Child" under s.2(f) means an individual who has not completed eighteen years. Before processing any personal data of a child, ALEX Tech Pte. Ltd. will obtain verifiable consent of the parent or lawful guardian, in the manner prescribed by Rules (s.9(1)). Before processing personal data of a person with disability who has a lawful guardian, verifiable consent of the lawful guardian will be obtained in the same manner (s.9(2)). ALEX Tech Pte. Ltd. will not undertake (a) processing likely to cause any detrimental effect on the well-being of a child, (b) tracking or behavioural monitoring of children, or (c) targeted advertising directed at children (s.9(3) and any Rules made thereunder). This §G.7 operates together with Part 14; where there is any inconsistency in respect of India, this §G.7 prevails.
G.8 Data Principal Rights (ss.11 to 14)
Data Principals within India have (a) right to access information about personal data processed, the processing activities undertaken, and the identities of Data Fiduciaries and Data Processors with whom personal data has been shared (s.11); (b) right to correction, completion, updating, and erasure (s.12); (c) right of grievance redressal through the readily-available means provided by the Data Fiduciary (s.13); and (d) right to nominate any other individual to exercise the Data Principal's rights in the event of death or incapacity (s.14). Rights are exercised through §13.11 of this Notice and the Grievance Officer channel in §G.3. ALEX Tech Pte. Ltd. will act on a request within the period prescribed under the Act and Rules, and will notify the Data Principal of the outcome; where a request is declined or partially declined, the Data Principal will be informed of the reasons and of the right to escalate under §G.12.
G.9 Data Fiduciary Obligations (s.8)
ALEX Tech Pte. Ltd. discharges the s.8 obligations as follows: (a) processing personal data only for the purpose for which consent has been given or a s.7 legitimate use applies (s.8(1) and (2)); (b) making reasonable efforts to ensure personal data is complete, accurate, and consistent where it is used to make a decision that affects the Data Principal or is disclosed to another Data Fiduciary (s.8(3)); (c) implementing appropriate technical and organisational measures to ensure effective observance of the Act and Rules (s.8(4)); (d) taking reasonable security safeguards to prevent personal data breach (s.8(5)), consistent with the security programme in Part 11; (e) intimating the Data Protection Board of India and each affected Data Principal in the event of a personal data breach, in the form and manner prescribed under s.8(6), consistent with Part 12; (f) erasing personal data on withdrawal of consent, or as soon as it is reasonable to assume the specified purpose is no longer served by its retention, and causing Data Processors to do the same (s.8(7) and (8)), subject to retention required by law; and (g) publishing Grievance Officer contact information and maintaining an effective grievance-redressal mechanism under s.8(9) and (10), discharged through §G.3.
G.10 Cross-Border Transfer (s.16)
Section 16 permits transfer of personal data for processing to any country outside India, except a country or territory that the Central Government of India has, by notification, restricted. As at the effective date of this Notice, no such restriction affects the processing described in this Annex G. ALEX Tech Pte. Ltd. will comply with any restriction notified by the Central Government from time to time, and will update this Notice and Appendix 1 as necessary. Where any other Indian law prescribes a higher standard than s.16, the higher standard applies. Personal data of Data Principals within India is processed primarily in Singapore; sub-processor jurisdictions are set out in Appendix 1.
G.11 Significant Data Fiduciary Posture (s.10)
As at the effective date of this Notice, ALEX Tech Pte. Ltd. has not been notified as a Significant Data Fiduciary under s.10(1). If so notified, ALEX Tech Pte. Ltd. will comply with the additional s.10(2) obligations within any timeline set by the notification, including (a) appointment of a Data Protection Officer based in India representing the Significant Data Fiduciary and serving as point of contact for grievance redressal, (b) appointment of an independent data auditor to evaluate compliance with the Act, and (c) undertaking periodic Data Protection Impact Assessments, periodic audits, and such other measures as may be prescribed. This §G.11 will be updated on any change in status.
G.12 Data Protection Board of India and Complaints
The Data Protection Board of India ("DPB"), constituted under Chapter V, is the supervisory authority under the Act. A Data Principal within India who is not satisfied with the Grievance Officer response under §G.3, or who does not receive a response within the applicable period, may complain to the DPB. The current contact route is as published by the Data Protection Board of India from time to time. ALEX Tech Pte. Ltd. will cooperate with any inquiry, direction, or proceeding initiated by the DPB and will act on any direction in accordance with the Act.
G.13 Rules and Notifications
The Act operates in conjunction with Rules and Notifications issued by the Central Government from time to time, including the Digital Personal Data Protection Rules and any subordinate instrument thereunder. ALEX Tech Pte. Ltd. will comply with such Rules and Notifications as they come into force and will update this Notice to reflect any material change to the compliance posture in this Annex G. The current state of subordinate legislation is available on request through §G.3.
Annex H - Other Regions (Australia, Japan, Hong Kong, UAE, KSA, and Others)
H.1 Australia (Privacy Act 1988, Australian Privacy Principles, My Health Records Act)
Where APP applies, we comply with the 13 Australian Privacy Principles, notifiable-data-breach obligations to the OAIC, and (where applicable) the additional My Health Records Act safeguards. Cross-border disclosure per APP 8 with accountability. Contact: OAIC, oaic.gov.au.
H.2 Japan (APPI)
Where APPI applies, we comply with purpose specification, use limitation, security control, third-party provision restrictions, and rules for cross-border transfer under Chapter 4 Section 3. Requests: PPC, ppc.go.jp.
H.3 Hong Kong (PDPO)
Compliance with Data Protection Principles under Schedule 1. Contact: PCPD, pcpd.org.hk.
H.4 UAE (Federal Decree-Law No. 45 of 2021 - PDPL)
Where PDPL applies (including DIFC/ADGM equivalents where relevant), we comply with the applicable regime and contact the UAE Data Office where required.
H.5 Saudi Arabia (PDPL)
Where KSA PDPL applies, we comply with the applicable regime including data-residency and cross-border transfer conditions administered by SDAIA.
H.6 Other Regions
Where any other data-protection law applies, we implement the required safeguards and provide the specific rights set out in that law. Contact dpo@alexcare.tech.
Appendix 1 - Sub-Processors
This Appendix lists the sub-processors engaged by ALEX Tech Pte. Ltd. to process Personal Data on our behalf, as at the Effective Date. Data subjects and Tenants may request the current version of this list at any time by emailing dpo@alexcare.tech. Material changes to this list are managed under the sub-processor-change process referenced in Part 8 and in Tenant DPAs.
| Sub-processor | Category | Function | Primary Processing Location |
|---|---|---|---|
DigitalOcean, LLC (digitalocean.com) |
Cloud infrastructure | Compute, storage, managed database, and network services for the Platform | Regionally configured; Southeast Asia region used as primary for Platform data of Southeast Asia Tenants and patients |
Stripe, Inc. (stripe.com) |
Payment processing (PCI DSS Level 1) | Card payment processing for international transactions; tokenised - no PAN storage in ALEX systems | Global card networks; Stripe primary processing in the United States and Ireland |
2C2P Pte. Ltd. (2c2p.com) |
Payment processing (PCI DSS Level 1) | Regional Southeast Asia payment processing including local card, wallet, and bank-transfer methods; tokenised - no PAN storage in ALEX systems | Singapore and Southeast Asia |
Amazon Web Services, Inc. (aws.com) |
Email and transactional messaging | Transactional email, notifications, and messaging infrastructure | Regionally configured; Southeast Asia region used as primary for Platform notifications to Southeast Asia recipients |
Cloudflare, Inc. (cloudflare.com) |
Bot protection | Security check (Turnstile) on the contact and demo forms of alexcare.tech; also an independent controller of those signals to improve its bot detection, as described in its Turnstile Privacy Addendum |
Cloudflare's global network; Cloudflare, Inc. is established in the United States |
GoDaddy.com, LLC (godaddy.com) |
Domain registration and email domain services | Domain registration and email-domain services for the alexcare.tech domain and associated mailboxes |
United States |
Category coverage note. The categories of sub-processor engagement that may arise as the Platform scales are set out in Part 8. Where a category listed in Part 8 does not appear in this Appendix as at the Effective Date, no sub-processor in that category is currently engaged. This Appendix will be updated before any additional sub-processor in a listed category is engaged for Processing that touches Personal Data.
Processing-agreement status. ALEX Tech Pte. Ltd. is in the process of executing GDPR Article 28-equivalent processing agreements (and, where applicable, HIPAA §164.502(e) Business Associate Agreements) with each of the sub-processors listed above. The current execution status of each is available to Tenants on request via dpo@alexcare.tech.
End of ALEX Privacy Notice