Legal

Privacy Policy

How COTechEnterprise (“C&O Tech Enterprise”) collects, uses and protects data for clinics, patients and visitors of our websites and AI chatbot services.

Effective date: 1 January 2025
Last updated: 1 January 2025

1. Who we are

COTechEnterprise is operated by C&O Tech Enterprise, a business registered with the Companies Commission of Malaysia (SSM). We provide AI-powered chatbot and receptionist services for clinics and service businesses through WhatsApp, web chat and related channels.

In this policy, “we”, “us” and “our” refer to COTechEnterprise. “You” refers to clinic customers, their staff, patients and website visitors.

2. Information we collect

We collect and process the following types of information:

  • Clinic account data – clinic name, business registration details, address, contact person, email, phone number and billing information.
  • User account data – staff names, emails, roles and login credentials (passwords are stored in hashed form only).
  • Conversation data – messages sent between patients/users and our chatbot or human agents, including text, attachments and timestamps.
  • Technical data – IP address, browser type, device information, usage logs, error logs and basic analytics events.
  • Integration data – WhatsApp Business IDs, access tokens and configuration settings needed to connect to Meta or other platforms.
For clinics using our AI assistant, patients should avoid sending highly sensitive personal information (e.g. NRIC, full medical history) through chat unless your clinic specifically instructs them to do so and has obtained appropriate consent.

3. How we use your information

We use the data we collect for the following purposes:

  • To create and manage clinic and user accounts.
  • To provide our AI chatbot, live agent and messaging services.
  • To configure and maintain WhatsApp and other channel integrations.
  • To improve our models, prompts and service quality using aggregated and anonymised data where possible.
  • To provide customer support, troubleshooting and service notifications.
  • To handle billing, invoicing and payment-related matters.
  • To comply with legal obligations and respond to lawful requests from authorities.

4. Legal basis (PDPA & other laws)

For Malaysian clinics, we process personal data in line with the Personal Data Protection Act 2010 (PDPA). Depending on the situation, our legal bases include:

  • Performance of a contract – providing our service to your clinic.
  • Legitimate interests – securing our systems, improving the product and preventing abuse.
  • Consent – where clinics obtain consent from patients for use of messaging channels or AI assistants.

5. Data retention

We keep data only for as long as it is reasonably necessary for the purposes described in this policy, or as required by law. As a general guide:

  • Clinic account and billing data – kept while you are a customer and for a reasonable period afterwards for record-keeping.
  • Conversation logs – retention period is configurable by the clinic where technically supported; otherwise we apply a default retention that balances support needs and privacy.
  • Technical and log data – kept for a shorter period for security, troubleshooting and analytics.

6. How we share information

We do not sell your personal data. We may share data with:

  • Service providers and sub-processors – such as hosting providers, email providers and analytics tools, who help us operate the service under data protection agreements.
  • Communication platforms – including Meta/WhatsApp and other messaging providers, for the purpose of delivering messages and integrating your clinic channels.
  • Professional advisers – such as lawyers, accountants or auditors, where reasonably necessary.
  • Authorities – where required by law or to protect our rights, users or the public.

Access to conversation data within your clinic is controlled by user accounts and roles that you manage.

7. International transfers

Our infrastructure and service providers may be located outside of Malaysia. Where data is transferred across borders, we take reasonable steps to ensure an appropriate level of protection, for example using contractual safeguards.

8. Security

We implement technical and organisational measures intended to protect your data, including encrypted connections (HTTPS), access controls, hashed passwords and regular monitoring. However, no system is perfectly secure and we cannot guarantee absolute security.

Clinics are responsible for maintaining the security of their own user accounts, devices and networks, and for deciding which staff have access to patient conversations.

9. Your rights

Depending on your location and applicable laws, you may have rights such as:

  • Accessing the personal data we hold about you.
  • Requesting correction of inaccurate or incomplete data.
  • Requesting deletion of certain data, subject to legal or contractual obligations.
  • Objecting to certain types of processing, or withdrawing consent where processing is based on consent.

For patients, most requests should be directed to the clinic you interacted with, as they are usually the primary data controller for patient records. We will assist clinics in responding to such requests where appropriate.

10. WhatsApp & third-party platforms

Our service integrates with WhatsApp Business and potentially other messaging channels owned by third parties. Your use of those platforms is also governed by their own terms and privacy policies, which we do not control.

When a clinic connects its WhatsApp account, we store necessary identifiers and tokens to send and receive messages on their behalf. These credentials are kept securely and are only used for the agreed service.

11. Cookies and similar technologies

Our websites may use cookies or similar technologies for basic functions such as remembering preferences, improving performance and measuring traffic. You can usually control cookies through your browser settings, but disabling them may affect some features.

12. Children’s data

Our service is designed for clinics and businesses, not for children to use directly. Any information about minors that appears in conversations is provided under the responsibility of the clinic and handled as part of the clinic’s patient records.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our service or applicable laws. The “Last updated” date at the top will indicate the latest version. Where changes are significant, we may provide additional notice through email or within the product.

14. How to contact us

If you have any questions about this Privacy Policy or how we handle personal data, you can contact us at:

  • Business name: C&O Tech Enterprise (COTechEnterprise)
  • Location: Petaling Jaya, Selangor Darul Ehsan, Malaysia
  • Customer support email: cotech.startup@gmail.com
  • Contact number: +60105212333
This Privacy Policy is provided for transparency and general information only and does not constitute legal advice. We recommend that you seek independent legal review to ensure full compliance with the laws applicable to your clinic or business.