Privacy Policy
Last updated: May 13, 2025
This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of your information when you use our Service, particularly when booking appointments, and tells you about your privacy rights and how the law protects you.
We use your Personal Data to provide and improve our Service, including facilitating your appointment bookings. By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to ZORA Behavioural Intervention Sdn Bhd.
- Cookies are small files that are placed on your computer, mobile device, or any other device by a website, containing the details of your browsing history on that website among its many uses.
- Country refers to: Malaysia
- Device means any device that can access the Service such as a computer, a cellphone, or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service refers to the Website.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Website refers to Zora Behavioural, accessible from [https://dev.zorabehavioural.com/](https://dev.zorabehavioural.com/)
- ‘You’ means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using your Personal Data
Types of Data Collected
Personal Data
While using Our Service, particularly when you request an appointment, We may ask you to provide Us with certain personally identifiable information that can be used to contact or identify you, as well as to facilitate your appointment. Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Address, State, Province, ZIP/Postal code, City
- Reason for seeking therapy (brief description)
- Preferred appointment times or days
- Any specific requests or needs mentioned during booking
- Information about how you found our centre
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on your Device. You can instruct your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if you do not accept Cookies, you may not be able to use some parts of our Service. Unless you have adjusted your browser setting so that it will refuse Cookies, our Service may use Cookies.
- Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on your personal computer or mobile device when you go offline, while Session Cookies are deleted as soon as you close your web browser.
We use both Session and Persistent Cookies for the purposes set out below:
- Necessary / Essential Cookies
- Type: Session Cookies
- Administered by: Us
- Purpose: These Cookies are essential to provide you with services available through the Website and to enable you to use some of its features, such as remembering items in a booking form. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that you have asked for cannot be provided, and We only use these Cookies to provide you with those services.
- Cookies Policy / Notice Acceptance Cookies
- Type: Persistent Cookies
- Administered by: Us
- Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
- Functionality Cookies
- Type: Persistent Cookies
- Administered by: Us
- Purpose: These Cookies allow us to remember choices you make when you use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you use the Website.
For more information about the cookies we use and your choices regarding cookies, please visit our Cookies Policy (if you have a separate one) or the Cookies section of our Privacy Policy.
Use of your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service.
- For appointment-related purposes:
- Scheduling and confirming your appointments.
- Sending you reminders about your upcoming appointments.
- Contacting you regarding any changes or cancellations to your appointments.
- For initial contact or follow-up related to your appointment request.
- To contact you: To contact you by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products, or contracted services, including security updates, when necessary or reasonable for their implementation.
- To provide you with news, special offers, and general information about other goods, services, and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information.
- To manage your requests: To attend to and manage your requests to Us.
We may share your personal information in the following situations:
- With Service Providers: We may share your personal information with Service Providers to monitor and analyze the use of our Service, and to contact you. This may include third-party platforms used for appointment scheduling, and we ensure these providers have their own adequate privacy and security measures in place.
- With Affiliates: We may share your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners, or other companies that We control or that are under common control with Us.
- With business partners: We may share your information with Our business partners to offer you certain products, services, or promotions.
- With your consent: We may disclose your personal information for any other purpose with your consent.
Retention of your Personal Data
The Company will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Specifically regarding appointment data, we will typically retain this information for 6 months after your last appointment for administrative purposes, record-keeping, and to manage any potential follow-up inquiries. After this period, the data will be securely anonymized or deleted, unless we are legally required to retain it for a longer period.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Transfer of your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place, including the security of your data and other personal information. If we transfer your data outside of Malaysia, we will ensure that appropriate safeguards are in place to protect your personal data in accordance with applicable data protection laws.
Delete your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about you.
Our Service may give you the ability to delete certain information about you from within the Service.
You may update, amend, or delete your information at any time by signing in to your Account, if you have one, and visiting the account settings section that allows you to manage your personal information. You may also contact Us to request access to, correct, or delete any personal information that you have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Your Rights Regarding your Personal Data
You have certain rights regarding your personal data under the Personal Data Protection Act (PDPA) of Malaysia and potentially other applicable laws. These rights may include:
- The right to access the personal data We hold about you.
- The right to rectify any inaccurate or incomplete personal data We hold about you.
- The right to request the erasure of your personal data when it is no longer necessary for the purposes for which it was collected, or where there is no other legal basis for processing.
- The right to restrict the processing of your personal data in certain circumstances.
- The right to object to the processing of your personal data in certain circumstances.
- The right to data portability (to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller), where applicable.
- The right to withdraw your consent at any time where We are relying on consent to process your personal data.
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We may require you to verify your identity before responding to your request.
Disclosure of your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
Other legal requirements
The Company may disclose your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of your Personal Data
The security of your Personal Data is important to Us. We strive to use commercially acceptable means to protect your Personal Data, including:
- Secure Socket Layer (SSL) or Transport Layer Security (TLS) encryption for data transmitted between your browser and our website.
- Secure storage of data with access controls to limit who can access your personal information.
- Regular security assessments and updates to our systems.
- Implementation of strong password policies for internal access.
However, remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect your Personal Data, We cannot guarantee its absolute security.
Children's Privacy
Our Commitment to Protecting Children's Privacy
At Zora Behavioural, we are committed to protecting the privacy of the children who use our services. We understand the sensitive nature of the information we collect and handle when providing psychological support to minors, and we adhere to strict guidelines to ensure their personal data is treated with the utmost care and in compliance with applicable laws, including the Personal Data Protection Act (PDPA) of Malaysia.
Information We Collect from Children
In the course of providing our services, we may collect the following types of personal data from children:
- Name and age.
- Contact information (e.g., phone number, email address, where appropriate and with parental/guardian consent).
- Information about their well-being, development, and presenting issues relevant to their therapy.
- Session notes and progress reports.
- Information provided by parents or guardians on the child's behalf.
We only collect personal data that is reasonably necessary to provide our psychological services to the child.
How We Collect Children's Information
We typically collect personal data from children through:
- Information provided by their parents or legal guardians during the intake process and ongoing communication.
- Direct communication with the child during therapy sessions, in a manner appropriate to their age and understanding.
- Forms or questionnaires completed by parents/guardians and, where appropriate, by the child with parental/guardian guidance.
Parental/Guardian Consent
We require verifiable consent from a parent or legal guardian before collecting, using, or disclosing the personal data of children under the age of [Specify the age of consent according to Malaysian law or your internal policy, e.g., 18]. We take reasonable steps to verify the identity of the consenting parent or guardian.
How We Use Children's Personal Data
We use the personal data of children for the following purposes:
- To provide psychological assessment, therapy, and support services tailored to their individual needs.
- To communicate with parents or legal guardians regarding the child's progress and treatment plan.
- To maintain confidential records of therapy sessions and progress.
- To comply with legal and ethical obligations.
- For internal quality improvement and training purposes (with appropriate anonymization or pseudonymization where possible).
Disclosure of Children's Personal Data
We will only disclose a child's personal data in limited circumstances, such as:
- With the explicit consent of the parent or legal guardian.
- To other professionals involved in the child's care, with parental/guardian consent.
- When required by law, such as in response to a court order or to protect the child's safety or the safety of others.
- To our trusted service providers who assist us in delivering our services (e.g., secure data storage), under strict confidentiality agreements.
Data Retention for Children's Information
We will retain children's personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law or professional ethical guidelines. The retention periods for children's records may differ from those of adult clients due to specific legal and professional requirements. We will securely dispose of or anonymize children's personal data when it is no longer needed.
Parents'/Guardians' Rights Regarding Their Children's Data
Parents or legal guardians have the right to:
- Access the personal data We hold about their child.
- Rectify any inaccurate or incomplete personal data of their child.
- Request the erasure of their child's personal data in certain circumstances.
- Withdraw their consent to the collection, use, or disclosure of their child's personal data at any time (this may impact our ability to continue providing services).
- Object to the processing of their child's personal data in certain circumstances.
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section of this website. We may require you to provide proof of your identity and legal guardianship.
Contact Us Regarding Children's Privacy
If you have any questions or concerns regarding the privacy of your child's personal data, please do not hesitate to contact us using the information provided in the "Contact Us" section of this website.
Changes to this Privacy Policy
We reserve the rights to update our Privacy Policy from time to time without prior notice. Kindly refer to the changes in this page from time to time for the relevant updates.
