Privacy Policy

The Personal Data Protection Act 2010 (the “Act”), which regulates the processing of personal data in commercial transactions, applies to Pharmaniaga Berhad  (“Pharmaniaga”, “our”, “us” or “we”), a public limited company incorporated under the laws of Malaysia with a business address at No. 7, Lorong Keluli 1B, Kawasan Perindustrian Bukit Raja Selatan, Seksyen 7, 40000 Shah Alam, Selangor Darul Ehsan.

For the purpose of this written notice (“Notice”), the terms “personal data” and “processing” shall have the same meaning as prescribed in the Act.

  1. This Notice serves to inform you about how  your personal data is used by us when you use the software and system known as ‘My Private Vaccine’ or the associated Site at https://myprivatevaccine.com/ and any related applications ( the terms “System”, “Site” or “Services” shall be taken to refer to any part of the My Private Vaccine software, system, site or services, as may be appropriate in the context of that part).

Who we are and who we work with:

  1. Pharmaniaga is operating as the dispensing pharmacy for COVID-19 vaccinations for the private sector in Malaysia. Private companies (“the Employers”) are able to purchase vaccines from Pharmaniaga.
  2. The Covid-19 vaccination (“Vaccine”) is carried out by healthcare providers (“Healthcare Providers”) that have been authorised for that purpose and are licensed under the Ministry of Health, Malaysia.
  3. To facilitate the tracking and management of vaccinations Pharmaniaga has procured My Private Vaccine.
  4. Employers will be able to register details of employees they have purchased vaccines for (“Eligible Employees”) by inputting their details on the Site.
  5. Pharmaniaga does not administer any vaccines but provides access for Eligible Employees to make vaccine appointments through the Site. The Healthcare Providers will have access to the System for the purpose of verifying the details of Eligible Employee and facilitating administration of  the vaccine(s) purchased from Pharmaniaga. Once the vaccination has been completed, details will be updated into the System by the Healthcare Provider and the Employer and Eligible Employee can obtain a record of the status.
  6. Any data provided to us by an Employer or Eligible Employee will be made available through the System to the Healthcare Provider to administer the vaccine. The details of the vaccination will be made available by the Healthcare Provider to the Employer and Employee.
  7. The Site will not hold any details of payment.

Notice to Employers

  1. If you are an Employer registering Eligible Employees in the System then you undertake that you have obtained the necessary specific consents from those individuals before disclosing any of their personal details to us. It should be made clear by you, the Employer, to any employee, that sensitive personal data containing information set out below under the heading “Eligible Employee Data” will be stored by us and shared with MySejahtera and the Employer. Furthermore, you, the Employer, undertake to indemnify us in full and hold us harmless from any loss or damages or penalties arising from you or your Company’s breach of or failure to meet the requirements of the Act.

What data will be collected by us:

  • Eligible Employee Data- personal and sensitive personal data – which will comprise the Health Record (set out below) -as well as: Name, Address, Identity Card Number / Passport Number, Employee ID, MySejahtera ID, Nationality, Phone number, Date of birth, Email address and Gender.
  • Health Record Data including vaccination details such as Date of administration, Place of administration, Batch number.
  • If you are an Employer or Healthcare Provider we will collect the following data:

We will also collect other information that you voluntarily choose to provide to us including unique identifiers such as passwords, and personal data in communications and correspondence emails or letters that you send to us; and additional personal or other information that may be relevant.

  1. As an Eligible Employee, by registering in with us you consent to the processing of your personal data for purposes which include but are not limited to the following:
  • The creation of a Health Record containing sensitive personal data about you.
  • To connect you with the Healthcare Provider that you choose;
  • To facilitate our interactions with you;
  • To contact you when necessary or requested, including to remind you of an upcoming appointment;
  • For compliance with legal and regulatory obligations;
  • To perform core operational services (such as hosting, billing, fulfilment, data storage, security, insurance verification, or Site analytics);
  • For internal record keeping;
  • For internal investigations, audit or security purposes;
  • To investigate your complaints;
  • To produce statistical reports, collectively or at individual data level, for corporate reporting, research works and publications;
  • To use statistical information that we collect in any way permitted by law;
  • For analysis for statistical, profiling or other purposes for us to conduct category analysis, financial analysis, investigate service lapses, and to review, develop and improve the quality of our products and services; and
  • Such other purposes directly related to the foregoing (collectively, “Purposes”). Generally, we handle your personal data for the purposes set out in this Notice. Any one or more of the listed purposes may apply to your personal data, depending on the actual situation. The Purposes above do not purport to be an exhaustive listing, although an effort is made to set out as many salient purposes as may be applicable.
  1. Generally, your personal data was, is being or is to be collected:
  • When you use the interactive tools and services, such as searching for available appointments with Healthcare Providers and completing medical history forms prior to Healthcare Provider appointments.
  • When you voluntarily provide information in free-form text boxes and through responses to surveys, questionnaires and the like;
  • Through cookies on the Site, and Site analytics services and other tracking technology; and
  • When you use the “Contact Us” function on the Site, send us an email or otherwise contact us.
  1. You are responsible for ensuring that the information you provide us is accurate, complete, not misleading and is kept up to date. If you fail to supply us any of your personal data which is not stated as being voluntarily provided to us, we may refuse to process your personal data for any of the Purposes and you will not be able to use the Services.
  2. We may require your assistance if the personal data relating to other persons is required for the Purposes and you hereby agree to use your best endeavours to assist us when required.
  3. You have the right to request access to and to request correction of your personal data and to contact us with any inquiries or complaints in respect of your personal data (including the possible choices and means for limiting the processing of your personal data) through the Site as follows:

The Personal Data Protection Officer
Email address:  [email protected]
Telephone no: +603 2782 1999

  1. We may refuse to comply with your request for access or correction to your personal data and if we refuse to comply with such request, we will inform you of our refusal and reason for our refusal.
  2. We will disclose your data to your Employer, the Healthcare Provider and the Ministry of Health, Malaysia through MySejahtera which may use your sample for further study.
  3. Eligible Employees will have already consented to the disclosure of personal data by their employer to us;
  4. We may disclose your personal data for the Purposes to our related companies, your employers (where applicable), our service providers, insurance company, governmental departments and/or agencies including Ministry of Human Resources, SOCSO, the Immigration Department or other government, regulatory and/or statutory bodies and any such third party requested or authorized by you or as may be required in law.
  5. We will store your data securely and with the appropriate level of protection commensurate with the sensitivity of the information. We will only keep your data for such period of time as is necessary to fulfil the Purpose or to comply with any legal or regulatory obligations. We cannot advise you on how long third parties including the Ministry of Health will retain your data for once we disclose it to them.
  6. We may transfer your personal data to a place outside Malaysia for any of the Purposes.
  7. We reserve the right to amend this Notice at any time and will place notice of such amendments on the Site or via any other mode that we view suitable.
  8. Nothing in this Notice shall limit your rights or our rights under the Act.
  9. In the event of any inconsistency between the English version and the Bahasa Malaysia version of this Notice, the English version shall prevail.