Privacy Policy
Privacy Policy of the Company and all its subsidiaries and assets including those in different countries. The Company delivers cloud-based software services to its clients on a subscription service basis. It needs access to data to enable delivery of services and also improve its services. Every transaction will entail transferring in the case of a person accessing services, his/her personal data to enable service delivery, responsible for transferring payments or reimbursements and in compliance with law, their credentials and personal data to the service recipient to enable the delivery of services and also to payment processing, better customer care etc. The Company also uses automated algorithms to improve service delivery through zoyel.my and its other subsidiaries. The software and data used is only used to attempt a better service delivery.
This Privacy Policy describes Our policies and procedures on the collection, use, storage, processing, transfer, and disclosure of Your Personal Data when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Definitions
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
This Privacy Policy is an electronic record under applicable laws and the rules made thereunder. This Privacy Policy does not require any physical, electronic, or digital signature by the Company.
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You including but not limited to:
- Email Address
- First name and last name
- Gender
- Age
- Phone Number
- Location
- Device
- Address, State, Province, ZIP/Postal code, City, Country
- Bank account information in order to pay for products and/or services within the Service
- Usage Data
- Any detail relating to the aforesaid as provided to the Company for availing the Services
It is hereby clarified that any information that is freely available or accessible in public domain or furnished under the applicable laws for the time being in force shall not be regarded as "personally identifiable information".
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You including but not limited to:
- Date of Birth
- Passport or National ID card or other form of ID
- Bank card statement
- Other information linking You to an address
You always have the option to not provide the Personal Data or information to Us sought to be collected from You by choosing to not use a particular Service(s) or feature being provided by Us, which requires You to provide such information. However, any refusal to provide certain Personal Data or information could impact provision of services and restrict your access thereto.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Information Collected While Using the Application
While using Our Application, in order to provide features of Our Application, We may collect, with Your prior permission:
- Information regarding Your location
- Pictures, videos and other information from Your or accessing Device's camera and photo library
We use this information to provide features of Our Service, and to improve and customize Our Service. The information may be uploaded to the Company's servers and/or a Service Provider's server or it may be simply stored on Your device.
You can enable or disable access to this information at any time, through Your Device settings.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service: including to monitor the usage of our Service.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
- To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide You: with news, special offers and general information about other goods, services and events which We offer that are similar to those that You have already purchased or enquired about unless You have opted not to receive such information.
- To manage Your requests: To attend and manage Your requests to Us.
- For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
- For Research & Development: We may use Your information for development of better services through Cohort studies, AI, Machine Learning, Analytics to provide continuous improvement of algorithms, to ensure better delivery.
- For other purposes: We may use Your information for other purposes, such as data analysis, audit, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and Your experience.
Sharing Your Personal Data
We may share Your Personal Data in the following situations:
- With Service Providers / Recipients of Service: We may share Your Personal Data with Service Providers / Service Recipients to monitor and analyse the use of our / Your Service, for payment processing, to contact You and to enable you to provide / receive services. All agencies or persons involved in the coordination of care may be provided access to data.
- With Government Authorities: where required by law to comply with the country of origin or jurisdiction.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your information with Our Affiliates, in which case We will require those Affiliates to honour this Privacy Policy. Affiliates may include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
- With business partners: We may share Your information with Our business partners to offer You certain products, services or promotions.
- With other users: when You share Personal Data or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside. If You interact with other users or register through a Third-Party Social Media Service, Your contacts on the Third-Party Social Media Service may see Your name, profile, pictures and description of Your activity. Similarly, other users will be able to view descriptions of Your activity, communicate with You and view Your profile.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy or to meet requirements of law in the relevant jurisdiction. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other Personal Data.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The Company has reasonable security measures and safeguards in place to protect Your privacy and Personal Data from loss, misuse, unauthorized access, disclosure, destruction, and alteration, in compliance with applicable laws. The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security however ensure or guarantee or warrant its absolute security.
It is further clarified that You have and so long as You access the Services (directly or indirectly), the obligation to ensure that You shall at all times, take adequate physical, managerial, and technical safeguards, at Your end, to preserve the integrity and security of Your data which shall include and not be limited to Your Personal Data.
Facial Biometric Data
We gather and process facial biometric data, including facial images and recognition embeddings, to facilitate authentication and verify identity. This biometric data is associated with your personal information to support specific use cases.
How Do We Use the Collected Face Data?
We use facial data for the following purposes:
- Patient Registration & Verification: We link a patient's face with their personal data during registration. On subsequent visits, facial recognition retrieves their stored information.
- Employee Attendance: Facial biometric authentication is employed for attendance tracking and workforce management.
- User Login: Users can log in to their accounts using facial recognition as an alternative to traditional credentials.
Is Face Data Shared with Any Third Parties?
We do not sell or share face data with third-party companies, advertisers, or external organizations. Face data is processed using advanced facial recognition and verification technology, and stored securely in our cloud environment. Personal data linked to facial recognition is encrypted and stored safely in our highly secured cloud systems.
Where Is Face Data Stored?
Face images are stored in a secure cloud storage environment with stringent access restrictions. Personal information associated with face data is safeguarded within our secure internal systems using robust encryption protocols.
How Long Do We Retain Face Data?
- Face data is retained for as long as you maintain an active account with us.
- If you request account deletion, your face data is permanently deleted from our storage.
- For employees, face data used for attendance tracking is retained for compliance and record-keeping purposes in accordance with our retention policies.
- In cases where we provide services to clients (e.g., hospitals, healthcare providers), data retention is governed by the terms of our contract with the client. If a client requests deletion, we follow their specified retention and deletion policies.
How Do We Protect Face Data?
We use advanced encryption, access controls, and secure storage measures to safeguard your face data. Our security standards ensure that biometric data is processed and stored in line with industry-leading protocols.
Payments
We may provide paid products and/or services within the Service. In that case, We may use third-party services for payment processing (e.g., payment processors).
We will not store or collect Your payment card details. That information is provided directly by You to Our third-party payment processors whose use of Your Personal Data is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
Stripe — Their Privacy Policy can be viewed at stripe.com/privacy
When You use Our Service to pay for a product and/or service via bank transfer, We may ask You to provide information to facilitate this transaction and to verify Your identity.
When payment information is being transmitted for availing the Services, it will be protected by encryption technology. By making payments for any Services on Our platform, You expressly consent to the sharing of Your information with third party service providers, including payment gateways, to process payments and manage Your payment-related information. Hence, the Company cannot guarantee that transmissions of Your payment-related information or Personal Data will always be secure or that unauthorized third parties will never be able to defeat the security measures taken by the Company or the Company's third-party service providers. The Company assumes no liability or responsibility for disclosure of Your information due to errors in transmission, unauthorized third-party access, or other causes beyond its control.
You play an important role in keeping Your Personal Data secure. You shall not share Your Personal Data or other security information for Your account with anyone. The Company has undertaken reasonable measures to protect Your rights of privacy with respect to Your access of Our Services. However, We shall not be liable for any unauthorized or unlawful disclosures of Your Personal Data made by any third parties who are not subject to Our control.
Other Service Partners
Other service partners which may have access to some or part of your data to enable services in certain circumstances and these may include the following. Please review their privacy policies.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Your Consent and Changes to This Privacy Policy
Your Acknowledgement
All information disclosed by You shall be deemed to be disclosed willingly and without any coercion. No liability pertaining to the authenticity/genuineness/misrepresentation/fraud/negligence of the information disclosed by You shall lie on the Company nor will the Company be in any way responsible to verify any information obtained from You.
Changes to Our Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the 'Last updated' date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your acceptance of the amended Privacy Policy, including by way of Your continuous access to the Services, shall signify Your consent to such changes and agreement to be legally bound by the same.
Your Rights
Our Company would like to make sure You are fully aware of all of your data protection rights. Every user is entitled to the following:
You have the right to request Our Company for separate copies of your personal data. We may charge you a small fee for this service.
You have the right to request that Our Company correct any information You believe is inaccurate or complete information that is incomplete.
You have the right to request that Our Company erase your personal data, under certain conditions.
You have the right to request that Our Company restrict the processing of your personal data, under certain conditions.
You have the right to object to Our Company's processing of Your personal data, under certain conditions.
You have the right to request that Our Company transfer the data that We have collected to another organization, or directly to you, under certain conditions.
You may choose to withdraw Your consent in writing at any point of time. In such a scenario, the Company may delete Your information or de-identify it so that it is anonymous and not attributable to You.
If You make a request, We have one month to respond to You. If You would like to exercise any of these rights, please contact us at our email: info@zoyel.my
Contact Us
If You have any (i) questions about this Privacy Policy and/or (ii) any grievance with respect to the Services, You can contact us:
Zoya Technologies Malaysia Sdn Bhd
📧 Email: info@zoyel.my
📮 Mail: To customer care,
Zoya Technologies Malaysia Sdn Bhd
15-13A, Wisma UOA 2, Jalan
Pinang 50450 Kuala Lumpur W.P. Kuala Lumpur Malaysia.
If there is a failure to get response or a resolution, You may seek arbitration under applicable laws.