Privacy and data protection at EldoriaNCare

EldoriaNCare collects minimal personal data necessary to provide care and coordinate services. We describe purposes, lawful bases and retention periods so residents and families can make informed decisions. Practical steps for access, correction and deletion requests are provided, with contact details for local queries.

2026-04-12 EldoriaNCare (Business ID: 061883433281), 18, Jalan Bistari 1, Parit Botak, 83200 Batu Pahat, Johor, Malaysia 18, Jalan Bistari 1, Parit Botak, 83200 Batu Pahat, Johor, Malaysia [email protected]

Definitions used in this policy

This section clarifies terminology used across the privacy policy so readers understand how terms are applied to care delivery and administrative processes.

Personal data means any information that identifies or can reasonably identify an individual, including contact details, health-related information collected for care planning and administrative identifiers.
Processing refers to any operation performed on personal data, such as collection, storage, use, adaptation, sharing and deletion conducted to provide services or manage administrative needs.
User refers to residents, family members, caregivers and other individuals whose personal data is collected by EldoriaNCare for the purposes described in this policy.
EldoriaNCare operates a recovery and relaxation center for pensioners that provides on-site wellness programs, physiotherapy support, structured day activities, and digital booking and communication tools through the website EldoriaNCare.digital. The service encompasses in-person care, remotely accessible scheduling and billing features, and educational resources aimed at promoting independent living and measured recovery outcomes in a community setting.
Cookies are small text files placed on devices to store session identifiers, language preferences, and basic usage metrics that enable EldoriaNCare.digital to maintain secure logins, remember user preferences, and analyze site performance. Cookies used by EldoriaNCare do not directly reveal sensitive health details unless a user intentionally submits such data through forms or client portals.
The data controller for personal data collected via EldoriaNCare.digital and on-site registration is EldoriaNCare, Business ID 061883433281, located at 18, Jalan Bistari 1, Parit Botak, 83200 Batu Pahat, Johor, Malaysia. Contact for privacy matters: +60122320034 and the designated privacy contact via the website contact form. This policy explains how EldoriaNCare processes personal data in relation to center services and digital interactions, effective 12-04-2026.
Processors engaged by EldoriaNCare include third-party IT hosting providers, payment processors, and certain outsourced therapy scheduling platforms. These processors act on behalf of EldoriaNCare under written agreements that limit use of personal data to specified processing activities and require appropriate technical and organizational measures to protect data.

What personal data we collect

EldoriaNCare collects personal data necessary to manage recovery programs and provide a safe, comfortable stay for pensioners. Data collection is driven by practical needs—enrollment, medical support coordination, billing, staff scheduling, and effective communication with family or designated representatives. Below we describe categories of data collected through online forms, intake interviews, monitoring systems, and third-party partners, illustrated with examples from typical resident scenarios.

Data you provide directly

We collect information you or your authorized representative supply when registering for services, completing intake forms, requesting bookings, or communicating with our care team. Practical examples: when a family member schedules a 4-week rest-and-rehab program or when a resident updates emergency contact details.

  • Identity details: full name, date of birth, national identification number (if provided), and photos used for identification badges.
  • Contact information: postal address, email address, and telephone number for residents, next of kin, or legal representatives.
  • Health and care details: medical history summaries, medication lists, mobility assessments, dietary requirements and physician notes submitted to plan appropriate therapy and meal services.
  • Booking and service preferences: program selections, preferred therapy schedules, dietary meal choices, and consent forms for specific treatments or group activities.
  • Business information: billing details required for invoicing, such as payment card vouchers processed by our payment partner and invoice records; full card numbers are handled only by certified payment processors.
  • Communications: messages you send via contact forms, email, or the resident portal, including feedback, incident reports, and appointment requests.
  • Legal and consent documents: signed agreements, appointed representative documentation, and directives that affect the level of assistance provided.
  • Photos and multimedia: images or video recordings taken with consent for care assessments, progress documentation, or marketing only when explicit permission is given.

Data collected automatically

When you visit EldoriaNCare.digital or interact with our digital services, we collect certain technical and usage data automatically. These data points help us maintain a secure and accessible service, improve site navigation, and understand how residents and families use online resources. Below are typical automatic data items and practical cases where they are relevant.

  • Device and browser information: device type, operating system, browser version to ensure compatibility of resident portals and teleconsultation tools.
  • IP address and approximate location: used for security monitoring and to detect anomalous access patterns to resident accounts.
  • Usage data: pages visited, links clicked, time spent on booking pages to improve the clarity of information for common scenarios like joining a weekly relaxation class.
  • Cookies and similar technologies: persistent identifiers for login sessions, language preferences, and site personalization.
  • Performance metrics: page load times and error logs used by technical staff to troubleshoot issues that might affect booking or billing.
  • Event logs: timestamps of interactions such as appointment confirmations and consent acknowledgements to maintain accurate operational records.
  • Analytics data from third-party services: aggregated reports that inform program planning without exposing individual health details.
  • Security alerts and access records: entries maintained to contribute and respond to suspected unauthorized access attempts.

Data from third parties

EldoriaNCare may receive information about residents from third parties such as hospitals, specialists, family members, or authorized representatives. These data are used to coordinate care, verify identity, and ensure continuity of treatment. Below are common third-party data sources and examples of use.

  • Referring clinicians and hospitals: discharge summaries, medication lists, and therapy recommendations provided to plan the initial rehabilitation schedule.
  • Family members or legal representatives: contact details and consent confirmations submitted to manage appointments and communications.
  • Payment and insurance providers: coverage details and claim authorizations necessary to process invoicing and reimbursement where applicable.
  • Technology providers: data required by hosting and scheduling platforms to enable resident portal access and appointment reminders.

Why we process personal data

Processing personal data at EldoriaNCare supports operational needs, care coordination, resident safety, compliance with legal obligations, and continuous service improvement. The purposes reflect routine scenarios: admitting a new resident, arranging therapies, invoicing services, and responding to clinical events.

  • Provision of services: registering residents, scheduling therapies, managing meals and accommodation.
  • Health and safety: sharing relevant medical information with on-site clinicians to provide appropriate care and respond to emergencies.
  • Communication: sending appointment confirmations, reminders, and informational updates to residents and their contacts.
  • Billing and administration: invoicing, bookkeeping, and tax reporting associated with services rendered at EldoriaNCare.
  • Quality improvement: analyzing aggregated feedback and outcome measures to refine program schedules and activity content.
  • Security and fraud prevention: monitoring access logs and transactions to protect resident accounts and business operations.
  • Legal and regulatory compliance: retaining records required by Malaysian law or contractual obligations with partners.
  • Research and planning: using de-identified data to understand service demand patterns and plan facility needs.
  • Marketing and outreach: sharing general center updates or newsletters with opt-in subscribers; marketing does not include clinical details without explicit consent.

Legal bases for processing

EldoriaNCare bases processing on operational necessity, legitimate interests, performance of contracts, consent where appropriate, and legal obligations applicable in Malaysia. For specific activities such as clinical record-keeping or business processing, the applicable basis is indicated below along with practical examples.

  • Contractual necessity: processing necessary to perform the service contract, for example arranging the agreed rehabilitation program and related bookings.
  • Legal compliance: processing required to meet legal obligations such as tax reporting, health and safety recordkeeping, and statutory inspections.
  • Legitimate interests: limited processing for security, fraud prevention, and improvement of services, balanced against residents’ privacy rights.
  • Consent: where special categories of data (such as sensitive medical images for marketing) are to be used beyond care purposes, explicit consent will be requested.
  • Vital interests: in emergency situations, data may be processed to protect the life or health of a resident when consent cannot be obtained promptly.

Residents in international contexts and GDPR considerations

Although EldoriaNCare is based in Malaysia, we recognize GDPR principles when processing data of EU residents who use our digital services. In such cases we apply enhanced protections around transparency, purpose limitation, and data subject rights. Practical cases include an EU national booking a short recovery stay while travelling through Malaysia; we ensure clear transfer information and lawful processing bases for such scenarios.

  • Transparency: providing clear information on processing activities and contacting our privacy team for inquiries.
  • Data minimization: collecting only data relevant to the requested service, such as essential medical details for care delivery.
  • Purpose limitation: using collected data only for the care and administrative purposes described unless additional consent is obtained.
  • Data subject rights facilitation: responding to requests to access, rectify, or restrict processing in accordance with applicable rules.
  • Cross-border safeguards: implementing contractual and technical measures when transferring data outside the resident’s jurisdiction.
  • Lawful basis mapping: documenting the basis for each processing activity relating to EU residents.
  • Breach notification: procedures to notify affected individuals and authorities where applicable following recognized timelines.

Cookies and similar technologies

EldoriaNCare.digital uses cookies to enable essential site functions, remember preferences, and provide anonymized analytics. We aim for minimal reliance on persistent tracking and offer users control over cookie settings via the website cookie banner and account preferences.

Types of cookies used include essential session cookies, preference cookies (language and display settings), analytics cookies that collect aggregated usage statistics, and minimal advertising cookies for public outreach initiatives. No cookies are set to collect sensitive health information without explicit user submission.

Cookies are categorized as: essential (required for core functionality), performance (site analytics), functional (preferences), and marketing (opt-in outreach). Users can disable non-essential categories; disabling may limit some features like auto-filled booking forms.

You can manage cookie preferences through the cookie banner on EldoriaNCare.digital or by adjusting your browser settings. Instructions and a cookie management interface are available on the website to block or delete cookies, understanding some services may degrade if non-essential cookies are blocked.

Read the full cookie policy on EldoriaNCare.digital for details on each cookie and how to manage your preferences.

When we share data

EldoriaNCare shares personal data only as necessary to deliver services, comply with legal obligations, or with explicit consent. Sharing is limited to parties that require the data to perform a defined role, such as healthcare partners, payment processors, or emergency responders. Below are common sharing scenarios and examples.

  • Healthcare providers: sharing clinical summaries with a resident’s treating physician or external therapist to coordinate care during admissions or referrals.
  • Payment processors and insurers: transmitting billing information required to process payments or settle claims where the resident or their representative has provided payment details or authorization.
  • Technology and hosting partners: sharing account identifiers and encrypted data with platform vendors who support the resident portal under strict processing agreements.
  • Regulatory authorities: disclosure when required by Malaysian law, audits, or lawful requests from public health agencies.
  • Emergency services: contacting emergency responders and sharing critical health information to assist medical interventions when necessary.
  • Legal advisors and auditors: sharing relevant records with lawyers or auditors when required for legal processes or compliance checks.
  • Marketing partners: only with explicit opt-in; aggregated non-identifiable program outcomes may be shared to support community outreach.

International data transfers

Where data are transferred outside Malaysia—for example, to cloud hosting providers or remote specialist consultants—EldoriaNCare implements contractual safeguards and assesses the receiving party’s security practices. Transfers are limited and documented, and personal data are encrypted in transit.

Safeguards include data processing agreements with standard contractual clauses where applicable, encryption of data during transfer, and restricted access controls. Transfers are reviewed on a case-by-case basis with emphasis on minimizing the volume of personal data moved internationally.

How long we keep personal data

Retention periods are determined by the purpose of processing, legal requirements, and operational needs. We retain only the data needed to support ongoing care, billing, or compliance obligations and dispose of records securely when no longer required.

Account and contact information is retained for the duration of an active relationship and for a limited period after service termination to address potential follow-up queries and for statutory recordkeeping; typical retention is up to 7 years for administrative purposes unless a longer period is mandated by law.

Communications (email, portal messages) related to care, consent, or billing are retained as operational records for case management and dispute resolution, typically for up to 5 years, subject to legal obligations or active case needs.

Technical logs and security records are retained to contribute incidents and maintain service integrity; these are typically kept for a shorter period (e.g., 1 year) unless required otherwise for an active contribute.

When data are no longer necessary, we take steps to securely delete or anonymize records. Requests for deletion by residents or authorized representatives are processed in line with legal restrictions, such as obligations to retain certain medical or business records.

Security of personal data

EldoriaNCare applies organizational and technical measures to protect personal data against unauthorized access, loss, or misuse. Measures are selected to be appropriate to the nature of the data and the risks identified, and are reviewed periodically. Practical examples include access controls for clinical records, encryption of resident portal credentials, and staff training on confidentiality.

  • Access controls: role-based permissions limiting who can view or edit resident records and audit logs that track access to sensitive files.
  • Encryption: encrypted transmission (TLS) for data platform online and encryption at rest for stored backups containing personal data.
  • Operational safeguards: physical security at the facility, secure disposal of paper records, and regular vulnerability assessments of IT systems.
  • Staff training and policies: mandatory privacy and data handling training for all staff, incident response plans, and confidentiality agreements for external partners.

Your rights regarding personal data

Residents, their authorized representatives, and visitors have rights to access and control their personal data held by EldoriaNCare. Rights may be exercised using the contact details on EldoriaNCare.digital or via the facility reception. We respond to requests in accordance with applicable law and reasonable verification processes. Examples and typical response steps are described below.

  • Right to access: request a copy of personal data we hold, such as intake forms, care notes, and billing records related to your stay.
  • Right to rectification: request correction of inaccurate or incomplete information, for example updating medication lists or emergency contacts.
  • Right to erasure: request deletion where there is no overriding legal or operational reason to retain the data; certain clinical or business records may be exempt from deletion.
  • Right to restriction of processing: ask us to limit processing in specific circumstances, such as when the accuracy of data is contested during a review.
  • Right to portability: obtain a copy of data provided in a structured, commonly used electronic format where technically feasible.
  • Right to object: object to processing based on legitimate interests, for example marketing communications; opt-out mechanisms are provided.
  • Right to withdraw consent: withdraw consent for data uses that were previously based solely on consent, for example promotional use of photos.
  • Right to lodge a complaint: submit a complaint to EldoriaNCare via our contact channels or to the relevant data protection authority if you consider processing to be improper.
  • Exercise of rights procedure: to exercise any right, provide sufficient identification and details about the request; we will acknowledge requests promptly and aim to respond within applicable statutory timeframes.

Requesting Access to Personal Data

At EldoriaNCare we recognise the importance of individual rights over personal data. Individuals may submit requests to access, correct, delete, or restrict processing of their personal information. Typical scenarios include a family member requesting an update to a care plan or a resident asking for a copy of their service record. To help us process requests efficiently, provide a clear description of the requested action, the relevant account details, and a copy of an identity document if you are acting on behalf of someone else. Requests received by post or email are logged and handled according to the process described below.

[email protected]

We aim to acknowledge receipt of a privacy rights request within 5 business days and to provide a substantive response within 30 business days. In cases requiring verification or coordination with third-party service providers, response time may extend up to 60 business days; you will be informed if additional time is needed. Example case: where a relative requests historic therapy notes, we will verify authorization and then supply the relevant records or explain any lawful reasons for limited disclosure.

Marketing and Promotional Communications

EldoriaNCare sends marketing about services, wellness programmes, and special events only to those who opt in. Communications channels include email newsletters, postal invitations for local events, and, where consent is provided, SMS notifications about booking availability. Practical case: an elder who opted in for email updates receives a monthly newsletter about gentle exercise classes; they retain full control to change preferences. All marketing messages include simple instructions to manage preferences.

To stop receiving marketing, use the unsubscribe link included in emails, the 'unsubscribe' option in SMS messages, or contact our privacy team. Unsubscribe requests are processed promptly; you may continue to receive transactional messages related to an active booking or legal notices. Example scenario: after unsubscribing from newsletters, a resident still receives appointment reminders relevant to an upcoming therapy session.

Children and Minors

Services provided by EldoriaNCare are designed for pensioners and older adults. We do not knowingly collect personal data from children under 18 for the purposes of our recovery and relaxation programmes. If a guardian or family member provides information on behalf of a person under our care, we require proof of authorization. Practical example: a daughter arranging a respite stay for an adult child must confirm her legal authority to act on their behalf before we accept or store personal data.

Links to Third-Party Sites

EldoriaNCare.digital may contain links to partners and external providers, such as local physiotherapists, equipment suppliers, or community resources. These links are provided for convenience and do not imply endorsement. When you follow an external link, the other site’s privacy practices apply. Case example: clicking a partner booking link redirects you to the partner’s site, where you may be asked to create an account and accept their privacy policy.

Updates to This Policy

We review our privacy practices periodically to reflect changes in services, legal requirements, or technology. Material changes will be published on EldoriaNCare.digital with an updated effective date and, where appropriate, an email notification to affected users. Scenario: if we introduce a new digital intake form that captures additional health-related information, we will update this policy and explain the practical impact and opt-out options.

How to Contact Our Privacy Team

For privacy enquiries or to submit a rights request, contact EldoriaNCare at: 18, Jalan Bistari 1, Parit Botak, 83200 Batu Pahat, Johor, Malaysia. Phone: +60122320034. Business ID: 061883433281. Email: [email protected]. Include your name, preferred contact method, and a clear description of your request. We use these details only to respond and to verify identity where required.

  • +60122320034
  • [email protected]
  • 18, Jalan Bistari 1, Parit Botak, 83200 Batu Pahat, Johor, Malaysia