MedBook 醫約 Privacy Policy and Personal Information Collection Statement
MedBook 醫約 (“MedBook”, “we”, “us” or the “Platform”) is operated by MedBook HealthTech Limited(醫約健康科技有限公司). We value your personal data privacy and are committed to handling personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the “Ordinance”) and other applicable laws.
This Privacy Policy and Personal Information Collection Statement explains how we collect, use, disclose, retain and protect your personal data when you browse or use MedBook’s website, application, appointment booking, teleconsultation, medication delivery, customer service or other related services, and how you may exercise your rights to access and correct your data.
Using the Platform does not mean that you consent to our use of personal data for a new purpose unrelated to the original purpose of collection. Where the Ordinance or other applicable law requires your consent, we will provide a clear separate notice and obtain the required consent. We may also provide a shorter collection notice on a relevant page when collecting personal data. If that notice is inconsistent with this document, the more specific notice will prevail to the extent of the inconsistency.
Personal Information Collection Statement (for registration, appointments and service applications)
This section constitutes the Personal Information Collection Statement that we provide under the Ordinance to individuals who supply personal data directly to us. You should read it before submitting any registration, appointment, teleconsultation, payment, delivery, customer-service or other related form.
Unless otherwise indicated in the relevant field or collection page, providing personal data is generally voluntary. However, information marked as mandatory, and information required to verify identity, establish or protect an account, process an appointment, enable a Healthcare Provider to assess a condition safely, process a payment or refund, issue a prescription or medical document, complete delivery, or comply with legal and professional requirements, is necessary for the relevant service. If you do not provide accurate and complete required information, we or the relevant Healthcare Provider may be unable to process your application, appointment or payment, or may need to delay, restrict, cancel or end all or part of the service.
We will use the personal data collected for the purposes described in section 3, including account administration and identity verification, appointment and teleconsultation processing, support for clinical services and medical-record management, payment and refund processing, medication or document delivery, necessary service communications, customer support, complaint or incident handling, protection of the Platform and Patient safety, compliance with legal and regulatory requirements, and service analysis and improvement. Depending on the service used, data may be transferred as described in section 5 to doctors, clinics, hospitals, pharmacies, laboratories or other Healthcare Providers; payment and banking service providers; logistics providers; cloud and technology service providers; professional advisers or insurers subject to confidentiality obligations; authorities legally entitled to request the data; and participants in a business transaction subject to appropriate confidentiality and data-protection arrangements.
Under the Ordinance, you have the right to ask whether we hold your personal data and to request access to and correction of that data. Requests should be made in writing to the Privacy Officer identified in section 14. Direct marketing is not a condition of receiving medical or Platform services. We will not use your personal data for direct marketing unless we have separately given the legally required notice and obtained your consent or indication of no objection.
1. Scope of this document and the roles of the parties
This document applies to personal data whose collection, holding, processing or use is controlled by us.
Doctors, clinics, hospitals, pharmacies, laboratories and other Healthcare Providers providing services through the Platform may act as independent “data users” when providing clinical or professional services and may retain and process medical records under their own legal and professional obligations. They may provide you with a separate privacy notice. Third-party websites, payment platforms, communication tools and other external services may also be governed by their own privacy policies.
2. Personal data we may collect
We collect only personal data that is necessary, appropriate and not excessive for providing services or achieving a directly related purpose. Depending on the functions you use, this may include the following.
2.1 Identity, account and contact information
Name, date of birth, sex, email address, telephone number, correspondence address, account and identity-verification information. Where genuinely required for medical registration, prescribing, statutory or insurance purposes, this may also include a Hong Kong identity-card or travel-document number. We will not request a copy of an identity document without a reasonable need.
2.2 Medical and health information
Symptoms, medical history, allergies, medication history, health conditions, care preferences, photographs or documents you upload, and consultation records, diagnoses, prescriptions, referrals, medical certificates, laboratory or examination results and follow-up information produced or supplied by the professionals responsible for your care.
2.3 Appointment, consultation and delivery information
Appointment time, allocated doctor or Healthcare Provider, consultation status, service records, communications, and, where medication or related items need to be delivered, the recipient’s name, telephone number, delivery address and delivery status.
2.4 Health measurements and connected-device data
If you choose to enter data or connect a compatible device or third-party service, we may collect height, weight, body temperature, blood pressure, heart rate and other health measurements. We will not obtain such data automatically unless you actively enable the relevant function or the service clearly states otherwise.
2.5 Payment and transaction information
Service description, amount, payment status, transaction reference, refund and billing records. Full payment-card or other payment-instrument details are usually collected and processed directly by a third-party payment service provider. We generally receive only the limited information needed to complete and reconcile a transaction.
2.6 Technical, device and usage information
IP address, device type, operating system, browser type, login and access times, use of functions, error and security logs, and information generated through cookies or similar technologies.
2.7 Representative and guardianship information
If you use the service for a minor, a person who cannot manage the service independently or another Patient, we may collect your name, contact details, relationship to the Patient and evidence of authority or guardianship.
We may collect data directly from you or your lawful representative, and may also receive it from the healthcare professionals or organisations responsible for providing services, payment and delivery service providers, devices or systems you authorise us to connect to, and technical logs generated through your use of the Platform.
Unless clear prior notice has been given and any required consent obtained before a consultation begins, the Platform will not generally make an audio or video recording of a teleconsultation.
3. Purposes for which we use personal data
We may use personal data for one or more of the following purposes:
We do not currently use a fully automated process to make a final medical diagnosis, and automated tools do not replace the clinical judgment of a registered doctor. Automated functions may be used for appointment allocation, notifications, administrative support, security and service analysis. If we later intend to use identifiable health information to develop, test or train an artificial-intelligence system, or to make an automated decision that has a significant effect on you, we will first carry out an appropriate assessment, provide clear notice and obtain consent where required by law.
- to establish, verify and administer accounts and Patient profiles;
- to receive and process appointments, allocate a doctor or other Healthcare Provider for the selected time slot, and support teleconsultations and follow-up services;
- to enable Healthcare Providers to verify identity, conduct clinical assessments, diagnose, prescribe, refer, issue medical documents and maintain medical records;
- to arrange dispensing, payment, refunds, reconciliation and delivery;
- to send confirmations, reminders, status updates, security notices and other communications directly related to the service;
- to respond to enquiries and handle complaints, clinical incidents, refunds, claims, disputes and customer-service cases;
- to conduct clinical governance, quality assurance, audits, professional training, Patient-safety work and service monitoring;
- to maintain, test, analyse and improve Platform functionality, reliability, accessibility and user experience, using anonymised or aggregated data where reasonably practicable;
- to detect, investigate and prevent fraud, misuse, cyberattacks, unauthorised access or other security incidents;
- to comply with laws, court orders, regulatory requirements and healthcare professional obligations, or, where permitted by law, to protect any person’s life, health, safety or lawful interests; and
- for another purpose to which you separately consent or which is directly related to a purpose notified at the time of collection.
4. Whether providing data is voluntary or mandatory
Unless otherwise stated at the point of collection, providing personal data is generally voluntary. However, some information is required to verify identity, arrange a consultation, enable a doctor to assess a condition safely, issue a prescription, process payment or complete delivery. If you do not provide accurate and complete required information, we or the relevant Healthcare Provider may be unable to process an appointment or provide all or part of the service, or may need to delay, cancel or end the relevant service.
If you provide another person’s personal data, you confirm that you have appropriate authority to do so and have explained this document to that person where necessary.
5. Disclosure and transfer of personal data
We will disclose or transfer only the personal data reasonably required to achieve the purposes above, where permitted or required by law, or where the required consent has been obtained, to the following classes of persons:
We will use contractual or other reasonable means, as applicable, to require service providers processing personal data on our behalf to process it only in accordance with our instructions, adopt appropriate security measures, and return or delete it as required after the service ends.
We do not sell your personal data.
- doctors, clinics, hospitals, pharmacies, laboratories, allied health professionals and other Healthcare Providers allocated to, responsible for or involved in your service;
- payment processors, banks, accounting or billing service providers;
- delivery and logistics providers, to whom we will provide only the minimum information necessary to complete delivery and will not disclose your diagnosis or full medical record without a need to do so;
- service providers supplying cloud hosting, video communications, SMS or email delivery, identity verification, customer support, system maintenance, cybersecurity, data analytics or other technology services;
- auditors, lawyers, insurers and other professional advisers subject to confidentiality obligations;
- courts, law-enforcement agencies, regulators, government departments or other persons legally entitled to request the data; and
- actual or potential participants in a merger, restructuring, financing, asset transfer or business transfer, subject to appropriate confidentiality and data-protection arrangements.
6. Electronic Health Record Sharing System (eHealth)
Relevant health information will be uploaded to or accessed through the Government’s Electronic Health Record Sharing System only where the relevant Healthcare Provider participates in the system, you have completed the necessary registration or authorisation procedures, and applicable law and system rules permit this. Only personnel who need and are authorised to access the information for the purpose of providing healthcare to you may do so.
You may withdraw participation or revoke sharing consent given to a particular Healthcare Provider in accordance with the procedures of the Electronic Health Record Sharing System. Doing so may affect a Healthcare Provider’s ability to obtain complete information and provide continuity of care. Information in the Electronic Health Record Sharing System will not be used for direct marketing.
7. Direct marketing
We will not use your name, telephone number, email address or other contact information to directly market MedBook, medical, health or related services unless we have provided the notice required by the Ordinance and obtained your consent or indication of no objection.
We will not use medical records or data in the Electronic Health Record Sharing System for direct marketing. We will not provide your personal data to a third party for direct marketing unless we have separately given the legally required notice and obtained the required consent.
You may at any time ask us, free of charge, to stop using your data for direct marketing by using the unsubscribe method in a promotional message or the contact details in section 14. We will stop the relevant use after receiving your request. This will not affect appointment confirmations, consultation reminders, payment, delivery, security or other necessary service communications.
8. Cloud services, overseas processing and third-party services
We may engage cloud and other technology service providers to store or process personal data in Hong Kong or another jurisdiction. Where data is processed outside Hong Kong, we will take reasonably practicable steps to require the recipient to provide protection comparable to applicable Hong Kong requirements and to process the data only for specified purposes.
If you choose to communicate with us or use a related function through a third-party website, video platform, instant-messaging tool or other external service, that third party may process information under its own terms and privacy policy. You should review the relevant policy before using the service.
9. Data security and incident response
We will adopt reasonably practicable administrative, physical and technical measures appropriate to the sensitivity and risk of the data to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Measures may include access and authentication controls, confidentiality obligations for staff and contractors, encryption in transit or at rest, logging and monitoring, backups, vulnerability management, supplier review and incident-response procedures.
No internet transmission or electronic storage method can guarantee absolute security. You should protect login credentials and one-time verification codes and notify us immediately if you suspect unauthorised use of your account or data.
If a personal data breach or security incident occurs, we will assess its impact promptly, contain the risk and take remedial action. Where required by applicable law or appropriate having regard to the risk, we will notify affected individuals, the Privacy Commissioner for Personal Data, the Commissioner for the Electronic Health Record or another relevant authority.
10. Data retention
We retain personal data only for as long as needed to fulfil the purpose of collection, taking into account the data category, medical and professional record requirements, statutory and accounting obligations, Patient safety, the possibility of disputes or claims, and system-security needs.
Different data categories may have different retention periods. Medical records controlled by a doctor or medical institution will be retained by that party in accordance with the individual case, professional guidance and applicable law. When personal data is no longer required, we will, where reasonably practicable, securely erase, destroy or irreversibly anonymise it. Data in backups will be removed under established rotation and deletion procedures unless the law requires continued retention.
11. Cookies and similar technologies
The Platform may use cookies, pixels, software development kits or similar technologies to:
You may manage non-essential cookies through the Platform’s cookie settings, where available, or your browser settings. Refusing or deleting essential cookies may prevent some functions from operating correctly. Cookies set by third-party analytics or content providers may also be governed by their own policies.
- provide login, security, payment and other necessary functions;
- remember language and display preferences;
- understand Platform traffic, errors and functional performance; and
- measure promotional activity or provide more relevant content where the required consent has been obtained.
12. Minors and represented persons
Where a Patient is under 18, cannot sufficiently understand the relevant data processing, or cannot manage an account independently, a parent, guardian or other lawfully authorised person should assist in using the service. We may verify the representative’s identity and authority where appropriate and will consider the Patient’s age, capacity to understand, best interests and applicable law.
A representative should access and handle only the accounts or Patient information that the representative is authorised to manage. Please notify us promptly if that authority ends or changes.
13. Access to and correction of personal data
Under the Ordinance, you have the right to:
Please contact the Privacy Officer identified in section 14 in writing and provide sufficient details to verify your identity and identify the relevant data. We will generally respond within 40 days after receiving a valid data-access request. If we cannot fully comply within that period, we will inform you of the reason and the expected completion time.
We may charge a fee for a data-access request that is not excessive and may refuse all or part of a request where permitted or required by the Ordinance. If you request correction of a medical record controlled by an independent doctor or medical institution, we may need to refer the request to that Healthcare Provider. To preserve the integrity of a medical record, the original clinical entry may be retained and supplemented, corrected or annotated rather than deleted.
Where processing is based on your consent, you may withdraw that consent. Withdrawal does not affect processing carried out before withdrawal, but may prevent us or a Healthcare Provider from continuing to provide part of a service.
- ascertain whether we hold your personal data;
- request a copy of personal data that we hold about you; and
- request correction of inaccurate personal data.
14. Contact us
For questions, complaints or comments concerning this document, our handling of personal data, or a request to access or correct personal data, please contact:
Privacy Officer Company: MedBook HealthTech Limited(醫約健康科技有限公司) Email: info@medbook.now Address: 10/F SYNLOC TOWER 223 NATHAN RD, YAU MA TEI, HONG KONG
You may also make an enquiry or complaint to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
15. Changes to this document
We may update this document in response to changes in law, regulatory requirements, technology or services. The updated version will be published on the Platform and will state its last-updated date. If a change may materially affect your rights or the way we use personal data, we will give prominent notice by reasonable means and obtain fresh consent where required by law.
Unless otherwise stated, a revision applies from its published effective date. A revision does not automatically authorise us to use personal data already collected for a new purpose inconsistent with the original purpose of collection.
Last updated: 3 August 2026 · Effective date: 15 July 2026 · Version: 1.0