1. PURPOSE
This Policy establishes the requirements of Postura Wellness (“Postura Wellness”) for collecting, using, disclosing, storing, protecting and disposing of personal data in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”).
This Policy applies to employees, chiropractors, physiotherapists, practitioners, management, administrative personnel, contractors, marketing personnel, temporary staff and other persons authorised to handle Postura Wellness personal data.
2. DATA PROTECTION OFFICER
Postura Wellness has designated a Data Protection Officer (“DPO”).
DPO Contact:
Email: hello@posturawellness.com
Telephone: +65 8399 1262
3. PERSONAL DATA CATEGORIES
Postura Wellness may hold:
General personal data:
- Name
- Telephone number
- Address
- Date of birth
- Appointment information
- Payment information
Healthcare information:
- Medical history
- Symptoms
- Diagnoses or suspected conditions
- Treatment information
- Clinical notes
- X-rays
- Assessment results
- Treatment plans
- Rehabilitation information
Digital information:
- IP address
- Cookies
- Device information
- Website interactions
- Advertising identifiers
- Analytics information
- Campaign and conversion information
4. HEALTHCARE DATA
Healthcare information must be treated as confidential.
Employees and practitioners must not:
- Access patient records without a legitimate reason;
- Share patient information with unauthorised persons;
- Photograph patient records for personal use;
- Download patient records unnecessarily;
- Send patient records through unauthorised applications;
- Discuss patients in public areas;
- Use patient information for personal marketing;
- Upload patient healthcare information to personal cloud accounts; or
- Provide patient information to third parties without appropriate authorisation.
5. ACCESS CONTROL
Access to personal data must be granted based on role and legitimate business requirements.
Practitioners may access information reasonably required for patient care.
Front-of-house personnel may access information reasonably required for appointment and administrative purposes.
Finance personnel may access payment and billing information reasonably required for financial administration.
Marketing personnel should not have unrestricted access to clinical records unless specifically authorised and reasonably necessary.
External vendors may only access information necessary to provide their contracted services.
6. MARKETING DATABASES
Patient information must not automatically be treated as marketing information.
A person’s clinical record and marketing profile should be kept appropriately separated.
Marketing personnel must not use medical conditions, diagnoses, treatment records, X-ray information, clinical notes, treatment outcomes or other healthcare information to create advertising audiences unless there is a specific lawful basis and appropriate approval.
7. META, GOOGLE AND TIKTOK ANALYTICS
Postura Wellness may use Meta Pixel, Meta advertising tools, Google Analytics, Google Tag Manager, Google Ads, TikTok Pixel, TikTok advertising tools and similar analytics and advertising technologies.
These tools may collect website and advertising interaction information.
Healthcare information must not be intentionally transmitted through website analytics or advertising pixels.
Staff and website administrators must not configure tracking events to transmit diagnoses, medical conditions, treatment information, X-ray information, clinical notes, patient records, healthcare history or other sensitive health information.
Particular care must be taken with URL parameters, form submissions, custom events, custom dimensions, audience lists, conversion APIs, advanced matching, customer lists and CRM-to-ad-platform integrations.
Website administrators should review tracking implementations periodically.
8. WEBSITE FORMS
Where a website form collects healthcare information, the form should not automatically send the submitted information to advertising or analytics platforms.
Where practical, tracking scripts should be configured to avoid capturing sensitive form information.
9. MARKETING CONSENT
Direct marketing should generally be based on appropriate consent.
Marketing consent should be voluntary, clear, specific and obtained through an appropriate opt-in mechanism where required.
A patient must not be denied healthcare treatment solely because they decline optional marketing consent.
10. DATA DISCLOSURE
Personal data may only be disclosed where necessary for an authorised purpose, the individual has provided appropriate consent, a legal or regulatory requirement applies, or a recognised exception under the PDPA applies.
11. THIRD-PARTY SERVICE PROVIDERS
Where Postura Wellness engages third parties to process personal data, management should assess the provider’s security controls, data processing arrangements, access requirements, data retention, overseas processing, confidentiality obligations and data breach procedures.
Appropriate contractual provisions should be implemented where appropriate.
12. OVERSEAS TRANSFERS
Where personal data is transferred outside Singapore, Postura Wellness will take reasonable steps to ensure appropriate protection consistent with the PDPA’s transfer limitation requirements.
13. DATA RETENTION
Personal data should not be retained indefinitely.
Business and clinical records should be retained according to applicable legal, regulatory, professional and operational requirements.
When retention is no longer required, information should be securely deleted, anonymised or disposed of.
14. PERSONAL DATA BREACHES
Any staff member who becomes aware of a suspected data breach must report it promptly.
Examples include:
- Sending a patient’s information to the wrong person;
- Lost devices;
- Stolen devices;
- Unauthorised account access;
- Hacked systems;
- Accidental disclosure;
- Incorrect email recipient;
- Unauthorised downloading;
- Unauthorised sharing; or
- Lost physical records.
Staff must not attempt to conceal a breach.
Management/DPO will assess the incident and determine whether regulatory or individual notification is required.
15. STAFF CONFIDENTIALITY
All staff must maintain confidentiality regarding patient and business information.
Confidentiality obligations continue after employment or engagement with Postura Wellness ends.
Unauthorised access, disclosure, copying or misuse of personal data may result in disciplinary or contractual action.
16. PERSONAL DEVICES
Staff should not store patient information on personal devices unless specifically authorised and appropriate security controls are in place.
Where personal devices are authorised for business purposes, appropriate security measures must be maintained.
17. SOCIAL MEDIA
Staff must not post identifiable patient information, photographs, treatment records or clinical information on personal social media accounts.
Patient photographs, videos, testimonials and treatment stories may only be used by Postura Wellness where appropriate consent has been obtained.
18. TRAINING
Relevant personnel should receive appropriate data protection awareness and training covering PDPA obligations, patient confidentiality, secure handling of healthcare information, marketing consent, social media, phishing and cybersecurity, data breaches, analytics and tracking technologies and access control.
19. REVIEW
This Policy should be reviewed periodically and whenever there are material changes to services, IT systems, analytics, advertising platforms, data flows, vendors, regulations or PDPC guidance.
20. GOVERNING LAW
This Policy is governed by the laws of Singapore.

