Privacy Policy

Privacy Policy and Personal Data Protection Notice

Last updated: August 11, 2026

This Privacy Policy and Personal Data Protection Notice explains how Chiropractic Specialty Center Sdn. Bhd. (“CSC”, “we”, “us”, or “our”) collects, records, uses, stores, discloses, transfers, protects, and otherwise processes personal data in connection with the website at mychiro.com.my, center inquiries, appointments, services, patient records, telephone calls, website forms, email, SMS, WhatsApp, Facebook or Messenger, post-visit communications, feedback requests, Google review invitations, analytics, and related administrative activities.

We aim to process personal data in accordance with Malaysia’s Personal Data Protection Act 2010 (Act 709), as amended, the applicable Personal Data Protection Principles, and other legal, regulatory, professional, and confidentiality obligations that apply to the particular processing activity. This notice should be read together with our Terms and Conditions, Disclaimer and Health Content Notice, and Professional Information page.

Key Privacy Choices

You may choose whether to receive optional feedback, review, educational, or promotional messages. Withdrawing optional consent will not affect your care. Do not send urgent matters, full medical histories, imaging files, identification numbers, or other highly sensitive information through public reviews, social-media comments, or ordinary website forms. WhatsApp, Facebook, Google, analytics tools, and other external platforms have their own privacy practices.

Data controller and contact details

Controller detail Information
Data controller Chiropractic Specialty Center Sdn. Bhd.
Company number 757008-A (200601037248)
Registered / contact address No. 71, Jalan Medan Setia 1, Plaza Damansara, Bukit Damansara, 50490 Kuala Lumpur, Malaysia
Email [email protected]
Telephone +603 2093 1000
Website https://www.mychiro.com.my/
This notice applies to processing for which Chiropractic Specialty Center Sdn. Bhd. determines the purpose and means. A separately owned or operated CSC-branded location, independent practitioner, payment provider, referral provider, or other organization may be a separate data controller for its own processing and may provide a separate notice.

Who and what this notice covers

This notice may apply to:

  • Visitors to mychiro.com.my and related CSC-controlled pages, forms, landing pages, videos, and digital services.
  • People who call, email, message, request a callback, ask for directions, book an appointment, or make another inquiry.
  • Patients, clients, parents, guardians, representatives, payers, and people involved in appointment or service administration.
  • People who communicate through WhatsApp, the WhatsApp Business Platform, Facebook, Messenger, SMS, email, or another approved third-party communication platform.
  • People who receive post-visit check-ins, feedback requests, optional review invitations, educational updates, or other consented communications.
  • Practitioners, staff members, applicants, suppliers, contractors, and business contacts where their personal data is processed through the website or CSC systems.

A third-party website, messaging service, review platform, social network, map provider, payment service, or external application linked from our website operates under its own terms and privacy practices. CSC does not control those external policies.

Categories of personal data we may collect

Contact and inquiry data

Name, telephone or mobile number, email address, preferred center, preferred language, preferred contact method or time, inquiry date, message content, appointment request, source page, and other information you choose to provide.

Identity, appointment, and administrative data

Identification details where lawfully required, date of birth, guardian or representative details, appointment history, attendance, consent records, communication preferences, billing or payment administration, receipts, invoices, correspondence, and records needed to manage a requested service.

Patient and clinical data

Health history, presenting concerns, symptoms, relevant medical background, medication information, examination findings, assessment results, imaging or reports provided to us, care plans, progress notes, referrals, professional correspondence, and other records created or received in connection with care. Health-related information is sensitive personal data and is processed with explicit consent or another condition permitted by law.

Communication and platform data

The communication channel, recipient number or account, date and time, delivery status, reply status, button selection, opt-in or opt-out record, template identifier, message content, staff notes, language preference, review-invitation history, and technical metadata supplied by the communication platform. Where a person replies with health information, the message may also contain sensitive personal data.

Feedback, reviews, and public content

Feedback submitted privately to CSC, survey responses, complaint or compliment records, and whether an optional review invitation was sent. A Google review, Facebook comment, or other public post is controlled by the platform and may be visible to the public. CSC may view, respond to, or retain a link or screenshot where reasonably necessary for moderation, complaint handling, recordkeeping, or legal purposes.

Website, device, and measurement data

IP address, browser and device information, referral source, approximate location derived from technical data, pages viewed, event timestamps, cookie or device identifiers, security logs, consent choices, and interaction events such as page views, telephone-link clicks, WhatsApp clicks, directions clicks, video plays, and confirmed callback submissions. We do not intentionally send names, telephone numbers, form contents, health information, or other directly identifying data to Google Analytics or Google Ads.

How we collect personal data

We may collect personal data:

  • Directly from you through website forms, telephone calls, email, WhatsApp, Facebook or Messenger, SMS, paper forms, registration forms, feedback forms, or in-person communication.
  • From a parent, guardian, representative, payer, family member, referrer, healthcare provider, employer, insurer, or other person where you have authorized the disclosure or the law otherwise permits it.
  • During consultation, assessment, service delivery, follow-up, recordkeeping, billing, and administration.
  • Automatically through website technologies, server logs, security tools, analytics, advertising measurement, consent-management tools, and messaging-platform metadata.
  • From third-party platforms when you choose to interact with CSC through those platforms or when the platform lawfully provides the data to us.

Why we process personal data

  • To respond to inquiries and provide information you request.
  • To schedule, confirm, reschedule, or manage appointments and communicate location, operating-hour, preparation, parking, payment, and administrative information.
  • To provide chiropractic, physiotherapy, rehabilitation, guided exercise, and related professional or administrative services where appropriate.
  • To maintain accurate professional, clinical, consent, communication, billing, and operational records.
  • To communicate about an inquiry, appointment, requested service, follow-up, safety matter, service interruption, legal notice, or other necessary operational issue.
  • To send optional post-visit check-ins, feedback requests, honest-review invitations, educational updates, or promotional information where the required notice and consent have been provided.
  • To record and honor communication preferences, consent withdrawals, opt-outs, suppression requests, and frequency limits.
  • To monitor service quality, investigate concerns, manage complaints, prevent abuse, and protect patients, staff, systems, premises, and the public.
  • To operate, secure, troubleshoot, measure, and improve the website, forms, communications, and user experience.
  • To measure advertising and website performance without intentionally transmitting personal health information or direct identifiers to analytics or advertising platforms.
  • To comply with legal, regulatory, professional, tax, accounting, insurance, recordkeeping, court, and enforcement obligations.
  • To establish, exercise, or defend legal rights and respond to lawful requests from competent authorities.

Consent and other permitted processing conditions

Depending on the activity, personal data may be processed with your consent; with explicit consent for sensitive personal data; to take steps at your request or provide a requested service; to comply with a legal or professional obligation; to protect vital interests; or under another condition permitted by the PDPA or applicable law.

When you ask CSC to contact you, book an appointment, or respond through a particular channel, we may use that channel to handle the request. Optional feedback, review, educational, or promotional messages are treated separately from necessary appointment, service, safety, or legal communications.

You may withdraw optional consent at any time. Withdrawal does not affect processing already carried out lawfully and does not require CSC to delete records that must be retained for professional, legal, security, consent, complaint, or accounting purposes.

Communication channels and third-party platforms

WhatsApp and the WhatsApp Business Platform

CSC may use the WhatsApp Business app, Meta’s WhatsApp Business Platform or Cloud API, or an approved WhatsApp Business Solution Provider to receive and send messages. Even when the automation and webhook are hosted by CSC, messages still pass through Meta’s systems and may be processed by Meta and its subprocessors. If a third-party provider, customer-management platform, automation service, hosting provider, or integration is used, that provider may process message content or metadata on CSC’s instructions.

Do not use WhatsApp for an emergency or to send a full medical history, identification number, payment-card details, unrequested imaging files, or other highly sensitive information unless CSC has specifically provided an appropriate secure process. WhatsApp and Meta have their own privacy terms, security practices, infrastructure, and international processing arrangements.

Facebook, Messenger, and other social platforms

If you contact CSC through Facebook, Messenger, Instagram, or another social platform, the platform may process your account information, message content, device data, and interaction metadata under its own privacy terms. Public comments are not private communication. Do not post private health information, identification numbers, telephone numbers, reports, or confidential records in a public comment.

Telephone, email, and SMS

CSC may use the telephone number or email address you provide to respond to an inquiry, manage an appointment, provide requested information, or send consented communications. Telephone and email providers may process routing and delivery information. Where call-measurement technology is used, information about the call event may be associated with website or advertising activity for measurement; CSC does not intentionally provide the content of the call to analytics platforms.

Post-visit check-ins, automation, and optional messages

With the appropriate notice and consent, CSC may use automated scheduling or message templates to send a post-visit check-in, ask whether contact is requested, route a reply, or notify the relevant team. Automation may process a button choice, delivery status, reply, and contact preference. It is used for communication and routing—not to diagnose a condition, interpret clinical findings, prescribe care, decide professional suitability, or replace human review.

If a response indicates a concern, a request for contact, or information that may require professional attention, the response should be routed to an appropriate staff member or practitioner. Automated messages are not monitored as an emergency service. For urgent concerns, contact an appropriate emergency service or registered medical facility.

Optional messages must include a practical way to stop or change them. Where supported, you may reply STOP, use an unsubscribe control, change your communication preferences, or contact CSC. We may retain a suppression record so that your opt-out is honored.

Feedback and Google review invitations

CSC may invite an eligible, consented person to provide private feedback or an honest public review. Reviews are voluntary. Declining, ignoring, or posting a critical review will not affect care, appointment availability, fees, or future access to CSC services.

  • CSC does not request a five-star review or a predetermined sentiment.
  • CSC does not offer payment, discounts, gifts, priority access, free services, or other incentives in exchange for a review.
  • CSC does not send review invitations only to people who report a positive outcome or who are expected to post a favorable rating. Neutral eligibility criteria may include consent, a completed visit, no recent duplicate request, and no opt-out.
  • A review should reflect the reviewer’s genuine experience. Do not include private health information, identification numbers, contact details, images of records, or information about another person.

When you open a Google review link, you leave the CSC website and interact directly with Google. Google determines what information is collected, whether a Google account is required, how the review is displayed, and how the review data is retained. Google’s own terms and privacy policy apply.

Website cookies, analytics, and advertising measurement

The website may use essential cookies, local storage, security technologies, and similar tools needed for page delivery, form operation, preference storage, fraud prevention, and website security. It may also use analytics, tag-management, consent-management, and Google Ads measurement tools to understand general performance and measure actions such as page views, telephone clicks, WhatsApp clicks, directions clicks, video plays, and successful callback submissions.

Some measurement tools may use cookies, device identifiers, IP addresses, or similar technical data. Where consent or choice is required, nonessential technologies should be controlled according to the user’s choice and the applicable legal requirements.

CSC does not intentionally send names, telephone numbers, email addresses, form fields, free-text messages, clinical details, imaging information, or other personal health information to Google Analytics or Google Ads. CSC does not use patient clinical data to build advertising audiences or personalize advertising based on a health condition. Technical configuration must be tested to prevent personal data from appearing in event names, URLs, query strings, page titles, or analytics parameters.

Disclosure to staff, practitioners, and service providers

CSC does not sell, rent, or trade personal data. We do not disclose personal data to unrelated third parties for their independent marketing use. Personal data may be disclosed or made accessible only where reasonably necessary and permitted, including to:

  • Authorized CSC practitioners, administrative personnel, management, and staff who need the information for their duties.
  • A separately responsible center operator, practitioner, healthcare provider, referrer, laboratory, imaging provider, payer, insurer, employer, or other party where you have authorized the disclosure or the law permits it.
  • Meta and WhatsApp, a WhatsApp Business Solution Provider, Facebook or Messenger, email or SMS providers, website hosting, cloud storage, CRM, automation, security, analytics, tag-management, payment, accounting, backup, IT support, and other approved processors acting on CSC’s instructions.
  • Professional advisers, auditors, insurers, banks, payment providers, and parties involved in a corporate transaction, subject to confidentiality and legal safeguards where applicable.
  • KKM, the Personal Data Protection Commissioner, courts, law-enforcement bodies, regulators, professional authorities, or other competent authorities where disclosure is required or permitted by law.

CSC remains responsible for selecting appropriate processors, limiting access, giving documented instructions where appropriate, and requiring reasonable confidentiality and security measures. A service provider may also be an independent controller for some of its own legally defined purposes; its privacy policy will apply to that processing.

Cross-border processing and transfers

Some technology, communication, cloud, analytics, review, social-media, or support providers operate regional or global infrastructure. Personal data or message metadata may therefore be processed, accessed, backed up, or supported outside Malaysia, including when Meta, Google, a cloud provider, a BSP, or another international provider is used.

Where personal data is transferred outside Malaysia, CSC will take steps intended to comply with the PDPA requirements applicable at the time, including assessing the transfer, using appropriate contractual or organizational safeguards, limiting the data, and obtaining consent where required. No cross-border method can eliminate all risk.

Security measures

CSC uses reasonable physical, administrative, and technical measures appropriate to the nature of the data and the processing. Depending on the system, these may include access controls, user authentication, role-based permissions, secure connections, device and account controls, staff confidentiality training, backups, logging, vendor review, secure storage, incident response, and secure destruction or deletion.

No website, messaging platform, email service, cloud system, device, transmission method, or storage method is completely secure. You are responsible for using a secure device and for deciding what information to send through a third-party platform. Contact CSC if you believe personal data has been sent to the wrong recipient or a CSC account may have been compromised.

Retention and deletion

Personal data is retained only for as long as reasonably necessary for the stated purpose, professional and clinical recordkeeping, consent and opt-out evidence, communication administration, complaint handling, security, fraud prevention, accounting, tax, insurance, legal claims, regulatory obligations, and other lawful requirements.

  • Clinical and professional records are retained according to applicable legal, professional, and operational requirements.
  • Inquiry and callback data is retained for the time reasonably needed to respond, document the communication, prevent duplicate requests, and meet legal or security needs.
  • Consent, preference, and opt-out records may be retained so that CSC can demonstrate consent and honor a suppression request.
  • Analytics and platform data is retained according to the configured retention period and the provider’s terms, subject to CSC’s settings and legal obligations.

When retention is no longer required, data may be securely deleted, destroyed, anonymized, or made inaccessible. A request to delete data may be limited by clinical, legal, accounting, security, consent, complaint, or recordkeeping obligations.

Personal data breaches

CSC maintains procedures to identify, contain, investigate, document, and respond to a suspected personal data breach. Where the applicable legal threshold is met, CSC will notify the Personal Data Protection Commissioner and affected data subjects in the manner and time required by the law and current official guidance. Affected people should follow the protective steps stated in any breach notice.

Your rights and choices

Subject to the PDPA, applicable exceptions, identity verification, professional obligations, and legal recordkeeping requirements, you may:

  • Ask whether CSC processes your personal data and request access to personal data held about you.
  • Request correction of inaccurate, incomplete, misleading, or outdated personal data.
  • Withdraw consent for processing based on consent, including optional messaging, subject to records that must lawfully be retained.
  • Require CSC to stop or not begin direct-marketing communications and use the available opt-out method.
  • Make a request concerning processing that is likely to cause unwarranted damage or distress, subject to the conditions and exceptions in the PDPA.
  • Request data portability where the amended PDPA applies and the request is technically feasible and compatible with applicable requirements.
  • Request deletion or restriction for consideration where permitted, recognizing that CSC may need to retain clinical, legal, accounting, consent, security, or complaint records.
  • Lodge a complaint with CSC or the Personal Data Protection Commissioner.

CSC may need to verify your identity and authority before acting on a request. A reasonable fee may apply where permitted. We will respond within the period required by applicable law or explain why additional time or information is needed.

Children, minors, and representatives

A parent, guardian, or authorized representative may provide information for a minor or another person only when legally authorized to do so. CSC may request evidence of authority. Optional review invitations or promotional communications should not be directed to a minor without appropriate guardian involvement and a lawful basis.

Public comments, reviews, and third-party links

Public comments, Google reviews, Facebook posts, and similar content may be visible, copied, indexed, or shared by others. Do not post private health information or information about another person. CSC may moderate or report content that contains personal data, abuse, spam, impersonation, unlawful material, or material unrelated to the page, but removal from a third-party platform is controlled by that platform.

Links to Google Maps, Google reviews, WhatsApp, Facebook, Messenger, YouTube, research sources, payment services, or other third-party sites are provided for convenience or functionality. Opening a third-party link subjects you to that provider’s terms and privacy practices.

Contacting CSC about privacy

For a privacy question, access or correction request, consent withdrawal, direct-marketing opt-out, data portability request, or complaint, contact:

Contact fieldDetail
OrganizationChiropractic Specialty Center Sdn. Bhd.
AddressNo. 71, Jalan Medan Setia 1, Plaza Damansara, Bukit Damansara, 50490 Kuala Lumpur, Malaysia
Email[email protected]
Telephone+603 2093 1000
Contact pagehttps://www.mychiro.com.my/contact-us/

If CSC is required to appoint or register a Data Protection Officer, the current DPO contact information will be provided in the manner required by law. You may also contact the Personal Data Protection Commissioner if you believe a privacy concern has not been adequately addressed.

Updates and language versions

CSC may update this notice to reflect changes in law, guidance, technology, services, processors, communications, cookies, analytics, or operational practices. The Last Updated date identifies the latest substantive review. Material changes may be highlighted and, where required, additional notice or consent may be requested.

This notice should be made available in English and Bahasa Malaysia. If the two versions differ, the website should clearly state which version prevails, subject to applicable law. Do not assume that a machine translation is sufficient for legal publication without human review.

Common privacy questions

CSC may use the channel you chose or consented to for an inquiry, appointment, requested service, post-visit communication, or optional message. Meta and any approved platform provider also process data under their own terms.

No. Even when CSC hosts the webhook or automation, the WhatsApp Business Platform is operated by Meta. Meta and its subprocessors process messages and metadata. A BSP or other provider may also process data if used.

No. Review invitations must not be based on expected positivity or a requested star rating. Any invitation is optional, honest, and based on neutral eligibility criteria and consent.

Yes. Use the available unsubscribe method, reply STOP where supported, or contact CSC. Necessary appointment, safety, legal, or requested-service communications may still be sent where permitted.

No. A Google review is public. Do not include private health information, identification numbers, reports, contact details, or information about another person.

CSC does not intentionally send names, telephone numbers, form contents, or health information to those services. Technical event tracking should record only the action, such as a confirmed callback submission, without the submitted values.

You may make a request. CSC will consider it under the PDPA and applicable obligations. Clinical, legal, consent, complaint, security, accounting, and other required records may need to be retained.

Email [email protected], call +603 2093 1000, or use the Contact page. Identity verification may be required before personal data is disclosed or corrected.

Author information

Written and reviewed by Yama Zafer, D.C., founder and director of Chiropractic Specialty Center®, a Doctor of Chiropractic (Cleveland University-Kansas City, United States) trained in chiropractic and physiotherapy, registered in Malaysia as a T&CM practitioner (Chiropractic), with over 30 years of clinical experience. Read Yama Zafer, D.C. professional profile.

This notice is an operational privacy disclosure and is not legal advice to the reader.

Last updated

Last updated: August 11, 2026. This notice received a substantive review of data categories, patient and clinical records, website forms, Meta and WhatsApp processing, Facebook and Messenger, post-visit automation, Google review invitations, analytics, Google Ads measurement, processors, cross-border transfers, consent, opt-out choices, security, retention, breach response, rights, and current internal links.