Back to Sign In

Privacy Policy

SJAM Pahang — Last updated: 20 August 2026

1. About This Policy

This Privacy Policy describes how SJAM Pahang (“the System”) collects, uses, retains, and discloses personal data in connection with the Identity & Access Management (IAM) portal operated by HTTP Studio (“we”, “us”, “our”).

This policy is issued in compliance with the Personal Data Protection Act 2010 (PDPA 2010) of Malaysia. If you are based in the European Economic Area, the General Data Protection Regulation (GDPR) may also apply to your data.

2. Personal Data We Collect

We collect only the data necessary to manage staff identity and access to healthcare systems:

  • Identity data: full name, email address, national identity card (IC) number (stored encrypted at rest).
  • Employment data: facility, department, position level, employment type.
  • Authentication data: hashed password, TOTP secret (encrypted), Google account ID (if Google login is used), device records for mobile login.
  • Usage data: login timestamps, IP addresses, browser/device information, actions performed in the system (audit log).
  • Avatar: optional profile photo uploaded by the user.

3. Purpose of Collection and Use

We collect and process personal data for the following purposes:

  • Verifying and managing staff identity and employment status.
  • Controlling access to healthcare information systems on a need-to-know basis.
  • Maintaining an audit trail of system access for security and regulatory compliance.
  • Sending system notifications and approval requests via email and push notification (if enabled).
  • Complying with applicable laws and regulations including PDPA 2010.

We do not use your personal data for marketing, profiling, or any purpose beyond staff IAM.

4. Legal Basis for Processing

Under PDPA 2010, processing is necessary for the performance of your employment contract and for compliance with legal obligations applicable to your employer. Under GDPR Article 6(b) and 6(c), the legal bases are performance of a contract and compliance with a legal obligation.

5. Disclosure to Third Parties

We share personal data only to operate the system:

  • Google LLC — if you use Google Sign-In, your Google account email is shared with Google's OAuth 2.0 service to verify your identity. Google's Privacy Policy applies.
  • Firebase / Google Cloud (FCM) — if push notifications are enabled, your device token is shared with Firebase Cloud Messaging to deliver in-app alerts.
  • MyDigital ID (JPN / MAMPU) — if you use MyDigital ID login, your IC number is used to verify your identity via the government's OIDC service.

We do not sell, rent, or trade your personal data to any third party.

6. Data Retention

  • Account data is retained while your account is active and for a reasonable period after deactivation, unless you submit a data erasure request.
  • Audit logs (activity logs and field-change records) are retained for 7 years as required for healthcare audit compliance. These records are retained even after account erasure to ensure audit trail continuity.
  • After 7 years, audit records are automatically deleted.

7. Your Rights

Under PDPA 2010 and GDPR, you have the following rights:

  • Right of access (Section 12 PDPA / Art. 15 GDPR): you may request a copy of your personal data. Log in and visit Settings to view your data, or request a JSON export.
  • Right of correction (Section 12 PDPA / Art. 16 GDPR): you may correct inaccurate data via Settings → Profile.
  • Right of erasure (Section 35 PDPA / Art. 17 GDPR): you may request deletion of your personal data via Settings → Data & Privacy → Request Data Erasure. Requests are reviewed within 14 days. Audit logs are retained as legally required.
  • Right of portability (Art. 20 GDPR): you may download your data in JSON format from Settings → Data & Privacy → Export My Data.

8. Security Measures

  • Passwords are hashed using bcrypt and never stored in plain text.
  • IC numbers are encrypted at rest using AES-256-CBC.
  • All data in transit is protected by HTTPS / TLS.
  • Session fixation and brute-force protections are in place.
  • A full audit trail records every significant action in the system.

8a. Location Data — Mana Provider & Mana Team Apps

The Mana Provider (office dispatch) and Mana Team (ambulance crew) mobile apps are part of the Ambulance Booking module and collect additional data beyond the core IAM account data described above:

  • Precise GPS location: Mana Team collects the ambulance crew's real-time GPS position, including while the app is in the background, for the duration of an active trip — from being assigned a case until the vehicle returns to base. This is used to show dispatchers and patients the ambulance's live position and estimated arrival, and to record the route actually driven.
  • Patient and case data: patient name, contact details, pickup/dropoff addresses, and clinical needs entered for a booking, visible to the assigned provider and crew only.
  • Trip and route history: the GPS track, timestamps of each stage (dispatched, arrived, completed, etc.), and driving speed data, retained for operational and billing records.

Location data is collected only while a crew member is signed in and only for the purpose of operating an ambulance dispatch — never sold, and never used for advertising or profiling. It is transmitted over encrypted (HTTPS/TLS) connections and stored on the same infrastructure described in Section 8. Location tracking stops once a trip is completed or the crew signs out. A crew member's own trip history can be reviewed, and their account deleted, using the same rights described in Section 7.

9. Contact / Data Protection Officer

If you have questions about this policy or wish to exercise your rights, contact the System Administrator of your facility. For escalation or formal data protection enquiries, contact the Data Protection Officer (DPO) at:

HTTP Studio
Data Protection Officer
Email: http.studio.dev@gmail.com

10. Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the system after any changes constitutes acceptance of the updated policy.

© 2026 SJAM Pahang. All rights reserved.