During our interactions with you, we may obtain Personal Data about you to fulfill a statutory or contractual requirement, or is required to perform or enter into a contract with you. In this case, you are obliged to provide your Personal Data. If you do not provide your Personal Data to us, we may not be able to accomplish some of the purposes outlined in this Notice.
In other cases, decision to provide us your Personal Data may be optional.
We collect Personal Data from you in the following ways:
Personal Data may be collected, used, transferred or otherwise Processed for one or more of the following purposes:
| Types of Personal Data | Examples (Non-exhaustive) |
|---|---|
| Personal identification information (personal particulars, demographic and contact information) | Name, NRIC, travel and permit document (passport, employment pass, VISA details), gender, date of birth, country of birth, country of residence, nationality, citizenship, marital status, Relatives5 , race, ethnicity, religion, contact number(s), email address(es). |
| Health and medical information | Topics of interest, medical history and records including, but not limited to, drug prescriptions, tests and scan results or clinical images, therapies and procedures, consultations, reports and reviews. |
| Account and profile information | Account login information, health and medical information, benefits entitlement, accreditation, appointments, admissions, bills, purchases and/or payments information, insurance claims, transactions records, subscriptions, registrations, applications, enquiries, feedback, comments, ratings, reviews and testimonials via our communication and feedback touchpoints, channels and/or platforms. |
| Network traffic and other related data | Identification numbers, location data, online identifiers, IP address, cookies, web beacons, device identification details, language settings. |
| Images and/or videos from which you may be identified, images captured on security systems, including CCTV and key card entry systems | Pictures uploaded into our accounts, social media or services otherwise provided to us by you, CCTV images, log files. |
| Compensation and payroll | Bank account information, salary, bonus, payroll deductions including insurance. |
| Job, position, and organisation data. | Department, supervisor, office address, work location, permit details, hire date, job title, designation, business unit, part-time or full time position, work history, termination date and reason, retirement eligibility, promotions and disciplinary records, date of transfers, reporting manager(s), other details of employment contract. |
| Performance and benefits data | Performance reviews and ratings, incentives, awards, retirement, benefits data of family members/dependents such as names and date of birth. |
| Tax Data | Tax number, contribution rates, tax preferences. |
| Data resulting from internal or external communications | Contents of email, records of communication through bots, messaging tools, mobile communications. |
| Information that you decide to voluntarily share with us | Feedback, opinions, reviews, comments, and any information you may share with us on our social media platform, internal communication platforms and websites. |
| Purposes for Processing Personal Data | Examples |
|---|---|
| Provision of Medical Services Purpose | Assessment for provision of medical treatment and other related services: If you are referred to our facility by your doctor / medical professional, and you have previously attended any IHH Healthcare Singapore facility6 , we may use the personal data (such as your address and contact details) we hold from your previous registration or admission to streamline the referral process in our system to assess you for your medical treatment. Such previous registration or admission is regardless of whether the assessment is conducted by our or a third party medical professional and entered into our system. i. Processing your Personal Data that is collected by other IHH Healthcare entities in order to deliver shared services (e.g., HR, IT, Finance and internal audit functions) within IHH Healthcare Singapore; ii. Where an IHH Healthcare Singapore entity performs group management function collects and uses the Personal Data collected by other affiliates for its reporting purposes (e.g., Board reporting or to compile statistics for the necessary reporting); iii. Where an IHH Healthcare Singapore entity uses the same IT systems and database to process its data (including your Personal Data) (e.g., SAP system or any applicable medical records systems); and iv. consolidating your Personal Data collected from an IHH Healthcare Singapore facility or entity into one database for use by another IHH Healthcare Singapore facility or entity in order to facilitate the delivery of medical services to you. Contracted services with government agencies: We may provide health services to groups such as individuals under contracts with government. Where you receive services from us under such arrangements, we will provide your Personal Data (which in some cases may include a copy o your medical record for the relevant admission) to those government agencies as required under those contracts. Clinical trial invitation and participation: At times, we may become aware of clinical trials which may be relevant to your medical attention. Any participation in such trials is voluntary and we will seek your consent before enrolling you into such trials. We may use your personal data to assess your suitability for participation in the clinical trial in order to provide you with initial information about such clinical trial. Other common uses: We may also collect, use, disclose or Process your personal data where necessary for: i. Liaising with third party administrators (TPAs), insurance companies or parties authorising the payment of medical services for review and management of your case and claims of medical fees in relation to any medical services recommended or provided to you; ii. Liaising with your medical saving scheme administrator (e.g., Medisave, MediShield) and, where required, provide information to your medical saving scheme administrator to verify treatment provided to you, as applicable and as necessary; iii. The purpose of contacting you or your appointed primary contact person in relation to billing updates, post-discharge updates/follow-ups, emergency contact or other medical related purposes, and readiness of your medical reports or other documents, by call, text message or email to the number or mailing address which you have provided to us; and iv. Communicating important information to you regarding your medical saving scheme and any financial or management implications in relation to your care at our facility. |
| Business Purpose | Processing necessary for the performance of contractual obligations, invoicing, billing and account management of Individuals, customer service and support, finance and accounting, research and development, internal management and control, and any other reasonably related activities. |
| Contractual obligations and necessity | Providing and administering medical care, health and wellness services including, but not limited to, ordering and providing medication, medical tests, scans, reports, reviews, consultations, therapy, procedures; liaising with third-party service providers, vendors, suppliers and business and collaboration partners for the provisions of such, and related, products and services; and maintaining related documentations and records. |
| Account management of Individuals | Creating and maintaining account profiles and information including, but not limited to, health, medical, benefits entitlement, accreditation, transaction (enquiries and feedback, appointments, admissions, bills, purchases and/or payments, insurance claims, etc.) records; to enable the processing of requests including, but not limited to, subscriptions, registrations, applications, execution and conclusion of contracts, and providing customer service and support |
| Customer service and support | Handling enquiries, feedback and complaints; arranging and facilitating bookings, registrations, applications; providing notifications and reminders; and providing support to deliver contractual obligations and other reasonably related account and relationship management requests and matters. |
| Finance and accounting | Facilitate payments to, and receive payments from, Individuals, service providers, vendors, suppliers and business and collaboration partners; administering debt recovery and management; and other reasonably related matters |
| Research and development | Review, study, analyse, perform analytics and/or aggregate information on product and service consumption, patterns and trends; Individual behavioural patterns, preferences; to improve operations, services, product offerings, personalise experiences; and other reasonably related activities and objectives. |
| Internal management and control | Internal communications, scheduling work, recording time, managing and allocating company and employee assets and human resources, ensuring business continuity and crisis management; managing projects and costs, investor relations, alliances, ventures, mergers, acquisitions, divestitures, re-organisations or disposals and integration with purchaser; compilation of audit trails and other reporting tools, maintaining records relating to business activities, budgeting, financial management and reporting; intellectual property and standards management. |
| Human resources and personnel management | Performing workforce analysis and planning including, but not limited to, internal surveys, performance evaluations, talent and career development, courses and trainings; grievances, disciplinary matters and terminations; maintaining internal employee directories and emergency contacts; management and administration of outplacement, eligibility for employment, initial hiring or rehiring; providing and verifying employment references and background checks; management of leave and other absences, compensation and benefits, taxes, loans, grants, business expenses and reimbursements, travel arrangements. |
| Health, safety and security | Deploying and maintaining technical and organisational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests, identifying and authenticating employees, managing network security and preventing data loss using automated technologies to identify malicious data on equipment or networks and to detect confidential information from leaving our perimeters or from unauthorised access to that information. Recording of your Personal Data through video or other digital, electronic, or wireless surveillance system or device to secure and maintain IT infrastructure, office equipment, facilities and other property, and to maintain the safety and security of our staff, patients, visitors and other attendees to our facilities. |
| Compliance with legal and regulatory obligations | Disclosing Personal Data to government institutions or supervisory authorities as required by law or judicial authorisation for complying with tax and national insurance deductions, record-keeping and reporting obligations, conducting audits and investigations to prevent or detect fraud or corruption, compliance with government inspections and other requests from government or other public authorities, responding to legal process conducting investigations including employee reporting of allegations of wrongdoing, policy violations, fraud, or financial reporting concerns, complying with internal policies and procedures. Please also keep in mind that we may also use your data for security reasons and/or to protect our legitimate business interests or to prevent or investigate suspected or actual violations of law, breaches of the terms of employment or non-compliance with our policies. |
| Defence of legal claims | Establishment, exercise or defence of legal claims to which we are subject, such as responding to legal processes such as subpoenas, pursuing legal rights and remedies, defending litigation and managing any internal complaints or claims (including any whistle-blower/ethics hotlines). |
| Enhanced security and further processing for improved services | Creation of de-identified and/or anonymised data from your Personal Data (by removal of identifiable components, obfuscation, anonymisation, or any other means) to enhance security and for further processing, aggregation, analysis for optimisation of patient care and improvement of healthcare services, products, research and development which may include transferring anonymised data to our affiliates and business partners in foreign countries. |