
PRIVACY POLICY
ZI.CARE PRIVACY NOTICE
ZI.CARE PRIVACY NOTICE
Last updated on: September 27, 2024
Welcome to the Zi.Care Platform!
Please read this Privacy Notice carefully to ensure that you understand the terms regarding the Processing of Your Personal Data conducted by Zi.Care.
Please read this Privacy Notice carefully to ensure that you understand the terms regarding the Processing of Your Personal Data conducted by Zi.Care.
A. Introduction
We have prepared this privacy notice (formerly known as the Privacy Policy) (hereinafter referred to as the “Privacy Notice”) to inform and explain to you how we, PT Jejaring Tiga Artha, a company established in Indonesia with its principal office at Office 8 Building, 11th Floor Unit D, Jl. Senopati No.8, RT.8/RW.3, Senayan, Jakarta 12190, Indonesia, together with our wholly-owned subsidiaries and affiliates (collectively referred to as “Zi.Care”, “We”, “Us”, or “Our”), obtain, collect, store, control, use, process, analyze, amend, update, display, disclose, transfer, reveal, and protect your Personal Data (collectively referred to as “Processing of Personal Data” or “Processing Personal Data”).
This Privacy Notice explains how we manage the Personal Data you provide to Us through the Zi.Care mobile application, website, and/or other platforms managed by Us (collectively referred to as the "Platform"), whether requested directly or during your use of the Platform.
This Privacy Notice applies to all users, healthcare service provider partners (such as general practitioners, specialists, psychologists, and midwives) (“Healthcare Providers”), agents, vendors, suppliers, Our partners (such as pharmacies, laboratories, insurance companies, and hospitals), as well as contractors (collectively referred to as “You”), except as governed by a separate privacy notice.
This Privacy Notice forms an integral part of the Zi.Care Terms and Conditions of Use (“Terms of Use”). We encourage you to read this Privacy Notice in conjunction with the terms and conditions of our products or services, as those documents may contain specific information regarding how We Process Your Personal Data. By using the Platform and any features or services that We operate (“Services”), you agree to the Terms of Use and this Privacy Notice. Therefore, it is important that you read and fully understand this Privacy Notice before registering, accessing, or using Our Platform (including related Services).
This Privacy Notice carries the same meaning as the Privacy Policy referred to in the Terms of Use and any Services on Our Platform.
This Privacy Notice explains how we manage the Personal Data you provide to Us through the Zi.Care mobile application, website, and/or other platforms managed by Us (collectively referred to as the "Platform"), whether requested directly or during your use of the Platform.
This Privacy Notice applies to all users, healthcare service provider partners (such as general practitioners, specialists, psychologists, and midwives) (“Healthcare Providers”), agents, vendors, suppliers, Our partners (such as pharmacies, laboratories, insurance companies, and hospitals), as well as contractors (collectively referred to as “You”), except as governed by a separate privacy notice.
This Privacy Notice forms an integral part of the Zi.Care Terms and Conditions of Use (“Terms of Use”). We encourage you to read this Privacy Notice in conjunction with the terms and conditions of our products or services, as those documents may contain specific information regarding how We Process Your Personal Data. By using the Platform and any features or services that We operate (“Services”), you agree to the Terms of Use and this Privacy Notice. Therefore, it is important that you read and fully understand this Privacy Notice before registering, accessing, or using Our Platform (including related Services).
This Privacy Notice carries the same meaning as the Privacy Policy referred to in the Terms of Use and any Services on Our Platform.
Acknowledgment and Consent
| 1. | By clicking the button or taking any action indicating consent under this Privacy Notice (whether electronically or non-electronically), you expressly declare that you have read, understood, and accepted all the terms in this Privacy Notice. You also explicitly give your clear consent to Us to Process your Personal Data in accordance with the provisions set forth in this Privacy Notice. |
| 2. | We require your Personal Data, among other reasons, to process transactions on the Platform. Therefore, you declare that the Personal Data provided to Us during account registration or data updates is accurate and up-to-date. You are obligated to update and notify Us of any changes to such Personal Data. By this, you release Us from any claims, lawsuits, compensation, and/or demands arising from transaction processing failures on the Platform or Service usage due to inaccurate Personal Data you have provided to Us. You also guarantee that all data provided, whether in writing or any other form for using the Platform, is your own and not the personal data of third parties obtained without lawful authorization. As such, you take full responsibility for any consequences arising from the provision and validity of such data. |
| 3. | You may voluntarily request to input or claim the Personal Data of third parties, such as parents, children, friends, and others, in accordance with certain features on the Platform. We reserve the right to validate such Personal Data and request additional information related to your request. By entering or claiming third-party Personal Data, you declare that the third party has granted you consent to (i) incorporate their Personal Data as part of your Personal Data and (ii) allow Us to process their Personal Data. Any consequences arising from the combination of such Personal Data will be your responsibility in accordance with this Privacy Notice and applicable laws. We are released from any claims related to the unauthorized use of third-party Personal Data. Furthermore, We reserve the right to request proof of consent from the third party at any time. |
| 4. | We will safeguard Personal Data in accordance with the provisions of this Privacy Notice. We are not responsible for any Personal Data disclosed and disseminated by you, whether intentionally or unintentionally. Therefore, you are deemed to have waived your right to the confidentiality of the Personal Data disclosed through such actions. |
| 5. | If you are below the established age threshold (under 18 years old), classified as a minor, unmarried, or under guardianship in accordance with applicable laws, you are required to review this Privacy Notice together with your parent or legal guardian. Ensure that your parent or legal guardian understands and agrees to the terms in this Privacy Notice before you use Our Platform and Services. By disclosing Personal Data to Us, you declare and warrant that your parent or legal guardian has provided consent for the processing of your Personal Data in accordance with applicable laws. Your parent or legal guardian also agrees to be bound by this Privacy Notice and will be responsible for all your actions taken within Our Platform. |
B. Personal Data
“Personal Data” refers to any information, data, and/or details in any form that can be used to identify you. This includes information you provide to Us, whether directly or indirectly, through the Platform or related to your personal information, over time.
Personal Data includes, but is not limited to, information such as your full name, identification numbers (including passport numbers, national identity documents, or other government-issued IDs), nationality, address, date of birth, gender, mobile phone number, and IP address. Additionally, Personal Data also encompasses location information, device data (including IMEI numbers), bank account and credit card details, email addresses, images/photos, and biometric data (including fingerprint and facial recognition). It also includes marital status, personal health information (including health conditions, treatments, allergies, vaccinations, immunizations, medical procedures, medical history, prescriptions, reports, recommendations, and other health records), insurance information, financial information, and other data classified as Personal Data under applicable laws.
For legal clarity, the term "Applicable Laws" includes all binding legal instruments, including but not limited to:
This scope applies comprehensively and dynamically, following legal developments during the validity of this Privacy Notice.
Furthermore, the definition of Personal Data is not limited to explicitly private information. Any form of data, including but not limited to user profiles, unique identifiers, or other information that can be linked or combined with Personal Data, is legally classified and treated as Personal Data.
Note that Personal Data does not include any personal information available in the public domain.
Personal Data includes, but is not limited to, information such as your full name, identification numbers (including passport numbers, national identity documents, or other government-issued IDs), nationality, address, date of birth, gender, mobile phone number, and IP address. Additionally, Personal Data also encompasses location information, device data (including IMEI numbers), bank account and credit card details, email addresses, images/photos, and biometric data (including fingerprint and facial recognition). It also includes marital status, personal health information (including health conditions, treatments, allergies, vaccinations, immunizations, medical procedures, medical history, prescriptions, reports, recommendations, and other health records), insurance information, financial information, and other data classified as Personal Data under applicable laws.
For legal clarity, the term "Applicable Laws" includes all binding legal instruments, including but not limited to:
| a. | Laws; |
| b. | Government regulations; |
| c. | Regional regulations; |
| d. | Presidential decrees; |
| e. | Ministerial instructions; |
| f. | Organizational bylaws; |
| g. | Industry Codes of Ethics; |
| h. | Licenses and official permits; |
| i. | Final and binding court decisions; and |
| j. | Policies and regulations from authorizedregulatory bodies. |
This scope applies comprehensively and dynamically, following legal developments during the validity of this Privacy Notice.
Furthermore, the definition of Personal Data is not limited to explicitly private information. Any form of data, including but not limited to user profiles, unique identifiers, or other information that can be linked or combined with Personal Data, is legally classified and treated as Personal Data.
Note that Personal Data does not include any personal information available in the public domain.
C. Legal Basis for Processing Personal Data
In accordance with applicable laws and regulations, Zi.Care processes your Personal Data based on the following:
| 1. | To fulfill contractual or pre-contractual obligations where you are or will become a party, and to respond to your requests for Services, we are authorized to process your Personal Data. This includes, but is not limited to, medical history, symptoms experienced, and other relevant information disclosed during video teleconsultations with Healthcare Providers, with the purpose of facilitating health consultations, ensuring the accuracy of medical advice, delivering products or services you obtain through the Platform, and processing payments and insurance claims related to the Services you use, all in accordance with applicable legal provisions. |
| 2. | Zi.Care is authorized to process Personal Data to serve legitimate and measured business interests, such as ensuring the security of information technology infrastructure, optimizing the quality of healthcare services through usage analysis, and conducting direct marketing of products and services deemed relevant to your needs. These actions are carried out proportionally, without infringing upon your fundamental rights as a data subject, and are applied only to the extent necessary to achieve legitimate purposes. Zi.Care is committed to balancing its business interests with your rights and freedoms, ensuring transparency through the maintenance of processing records that you may access upon request, and respecting your right to object to such processing as outlined in the 'Your Rights' section of this Privacy Notice. |
| 3. | Zi.Care is obliged to process Personal Data to comply with binding legal obligations, including but not limited to the management of medical records, reporting to relevant authorities, and the implementation of strict data security protocols. Such processing is conducted in accordance with applicable laws, including compliance with tax obligations, social security, or lawful court orders, as well as fulfilling the obligation to report suspicious transactions in accordance with anti-money laundering regulations. This ensures Zi.Care’s compliance with applicable legal and ethical standards in the healthcare industry and related financial transactions. |
| 4. | Zi.Care is authorized to process Personal Data in the context of health and epidemiological research, including but not limited to contributions to clinical studies, monitoring and preventing disease outbreaks, and addressing public health emergencies. The goal is to generate crucial information that can serve as a basis for public health policy decisions and disease prevention initiatives. Such processing is carried out with due regard for proportionality, confidentiality, and strict data protection measures, and is subject to oversight by relevant health authorities. |
| 5. | Zi.Care may process Personal Data based on explicit consent voluntarily provided by you in situations where other legal bases do not apply. This consent can be withdrawn at any time, such as in the case of receiving marketing communications or health promotion notifications through the Platform. You will be provided with comprehensive information on how to modify your consent and your rights as outlined in the 'Your Rights' section of this Privacy Notice. Additionally, the withdrawal of consent will not affect the legality of processing carried out prior to the withdrawal based on that consent. |
D. Personal Data We Collect
The Personal Data collected when you use the Platform, receive, or provide Services includes:
| 1. | Personal Data collected from you as a user of the Platform is as follows:
|
||||||||||||||||||||||||||||||||||||||||
| 2. | Personal Data Collected from You as a Healthcare Provider on the Platform is as follows:
Note: By using the Platform, you, as a Healthcare Provider, warrant that the information you provide is accurate and correct. You acknowledge and agree that we have the right to directly verify the information regarding your personal data that you have submitted through the Platform. If the information you provide is found to be incorrect, we shall not be liable for any consequences that may arise in connection with the provision and use of such incorrect information. |
||||||||||||||||||||||||||||||||||||||||
| 3. | Operational Data: Zi.Care utilizes cookies, server logs, and similar technologies to enhance the functionality and user experience on the Platform, as well as for monitoring and marketing purposes both within and outside the Platform. These technologies are useful for storing user preferences, maintaining sessions, facilitating automatic authentication for frequently used services according to your settings, and enabling similar functions. You have the option to disable cookies through your browser settings while using the Platform; however, this may result in limited access or functionality on the Platform. Additionally, our third-party partners may also automatically receive and store non-personal information or anonymous data regarding your online activities. | ||||||||||||||||||||||||||||||||||||||||
| 4. | Personal Data obtained from other sources, including but not limited to:
|
E. Use of Personal Data We Collect
| 1. | We may use the Personal Data collected for the following purposes, as well as for other purposes permitted by applicable laws and regulations:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2. | Your Personal Data submitted through the Platform or during the use of the Services, which is not intended for public access, will only be shared with you and the Healthcare Provider you choose for consultation through our Platform. This data will be used by the Healthcare Provider to deliver the Services you request. They will have access to update information by adding review notes, health targets, monitoring feedback, or comments as part of the requested services. Healthcare Providers also have the right to terminate services to customers at any time according to their policies, and after such termination, they will no longer have access to your Personal Data. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3. | You have the right to share your Personal Data with others at your own risk. Zi.Care is not responsible for the actions of third parties who receive and use the information you disclose, and their compliance with this Privacy Notice is not guaranteed by Zi.Care. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 4. | We may use your Personal Data without requiring your consent, based on legitimate interests or other legal grounds recognized by applicable laws, for purposes such as: (i) complying with applicable laws and regulations; (ii) investigating potential fraud or illegal activities; or (iii) protecting our brand, reputation, or ownership. Additionally, the use of your Personal Data may be necessary when we are required, advised, recommended, expected, or requested to do so by our legal advisors or local or foreign legal advisors, regulators, government, or other authorities. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5. | We may use your Personal Data to send you information, which may include but is not limited to important messages regarding the Services or marketing and non-marketing materials related to specific Services or products that we believe may be of interest to you. This communication may be conducted through various methods, such as email or Short Message Service (SMS) to your phone number. By using the Platform, you agree to receive such messages. If you choose not to receive marketing communications from us in the future, you may follow the unsubscribe instructions available in the communications we send, or you can contact us through the channels available in the "Contact Us" section of our Privacy Notice. |
F. Disclosure of Your Personal Data That We Collect
| 1. | We may disclose, provide access to, or share your Personal Data with our affiliates and/or third parties for the specified purposes and for other purposes permitted by applicable laws and regulations:
|
||||||||||||||||||||||||||||||||
| 2. | By using the Platform, you are deemed to have agreed to allow certain third parties to use your Personal Data to provide you with information regarding goods and services that you require. Such third parties include, but are not limited to:
|
||||||||||||||||||||||||||||||||
| 3. | When Personal Data does not need to be linked to you, we will make reasonable efforts to remove the association of such Personal Data with you as an individual before disclosing or sharing that information. | ||||||||||||||||||||||||||||||||
| 4. | We will not sell or rent your Personal Data. | ||||||||||||||||||||||||||||||||
| 5. | In addition to what is provided in this Privacy Notice, we may disclose and share your Personal Data if we inform you and have obtained your consent for such disclosure or sharing. |
G. International Data Transfer
Your Personal Data that we collect may be stored, transferred, or processed outside of Indonesia by our personnel or by third-party service providers, vendors, suppliers, partners, contractors, or affiliates of Zi.Care. We are committed to complying with applicable regulations and to using our best efforts to ensure that such parties provide a level of protection for Personal Data that is equivalent to or higher than that imposed in Indonesia, or have obtained your consent.
H. Cookies
| 1. | Cookies are small files that automatically store your preferences and configurations on your device when visiting a site, and are not used to access other data on your device beyond what you have consented to share. |
| 2. | Although your computer device will automatically receive cookies, you have the option to modify your browser settings to reject cookies, which may hinder the optimal performance of Zi.Care's services when you access the platform. |
| 3. | We use Google Analytics features to collect data such as your age, gender, interests, and other information that may identify you, which we will use to develop features, facilities, and content on the Platform. If you do not wish for your Personal Data to be tracked by Google Analytics, you can install the Google Analytics Opt-Out Add-On in your browser. |
| 4. | Zi.Care may use third-party features to enhance our services and content, including ratings, adjustments, and presentation of offers based on your interests or visit history on our Platform. If you do not wish to receive personalized offers, you can set your preferences through your browser settings. |
I. Storage of Personal Data
| 1. | To the extent permitted by applicable laws and regulations, we will retain all Personal Data you provide in accordance with the original purpose of collection: (i) as long as you remain a user of our Platform, and (ii) from the date you cease using our Platform and/or since your request for the deletion of your account and Personal Data. |
| 2. | Zi.Care will delete and/or anonymize your Personal Data under our control when (i) such Personal Data is no longer necessary to fulfill the purpose of collection, and (ii) retention is no longer necessary for compliance with applicable laws and regulations. |
| 3. | Please note that it is possible that some of your Personal Data may still be retained by third parties, including government institutions in certain ways. In the event that we share your Personal Data with authorized government institutions and/or other agencies designated by the relevant government or in cooperation with us, you agree and acknowledge that the retention of your Personal Data by the relevant agencies will follow their respective data retention and/or processing policies. |
| 4. | Data communicated between you as a user and our partners (such as Healthcare Providers, pharmacy partners, laboratories, insurance partners, hospitals, and/or delivery partners) conducted outside of our Platform (e.g., through phone calls, SMS, mobile messaging, or other communication methods, as well as the collection of your Personal Data by our partners) may also be stored in various ways. We do not permit the processing of Personal Data between you as a user of the Platform and our partners occurring outside of our Platform because such activities are beyond our control, and therefore we cannot be held liable for such matters. To the extent permitted by applicable laws and regulations, you release us from any and all claims, losses, liabilities, costs, damages, and expenses (including but not limited to legal fees and full indemnity expenses) arising directly or indirectly from any Personal Data processing activities conducted outside of our Platform. |
J. Your Rights as a Data Subject
| 1. | As stipulated in applicable laws and regulations, you as a Data Subject have the following rights concerning your Personal Data:
|
||||||||||||||||||
| 2. | You have the right to access, correct, or obtain copies of your Personal Data under the control of Zi.Care by contacting us through the chat feature with our customer service team within the Zi.Care application. Please note that all requests will undergo a thorough screening and verification process and will only be processed by Zi.Care once you have provided adequate proof of identity to access, correct, or request copies of such data. Zi.Care reserves the right to deny requests to access or correct part or all of your Personal Data if permitted or required under applicable laws and regulations, including situations where the Personal Data may contain references to other individuals or where the request for access or correction is deemed irrelevant, frivolous, or burdensome. To the extent permitted by applicable laws and regulations, Zi.Care reserves the right to impose a reasonable administrative fee on you to handle your requests for accessing, correcting, or requesting copies of your Personal Data, and if so, we will inform you of such fees before processing your request. Zi.Care will respond to your requests regarding access, correction, or requests for copies of your Personal Data in accordance with the time limits specified by applicable laws and regulations. | ||||||||||||||||||
| 3. | If you wish to exercise any other rights as a data subject in accordance with applicable laws and regulations, you may contact us through the chat feature with our customer service team within the Zi.Care application. | ||||||||||||||||||
| 4. | Please note that if you request the deletion or destruction of your Personal Data, we may still process your Personal Data as necessary for our legitimate business interests, such as detecting and preventing fraud and enhancing security. For example, if we suspend an account due to fraud or security reasons, we may retain certain information from that account to prevent that member from creating a new account on the Platform in the future. We may also continue to process your Personal Data as necessary to comply with our legal obligations. For instance, we may retain some of your information for tax, legal reporting, and audit obligations. |
K. Security of Your Personal Data
| 1. | The confidentiality of your Personal Data is a top priority for Zi.Care. We will implement reasonable and appropriate security measures, both technical and operational, to protect and safeguard your Personal Data from unauthorized access, collection, use, or disclosure, through appropriate physical, electronic, and managerial security procedures. To ensure optimal protection, you are required to periodically update our Platform to maintain the security of your Personal Data. | ||||||
| 2. | Although Zi.Care has made optimal efforts to secure and protect your Personal Data, it should be understood that data transmission over the Internet is never completely free of risk. In the event of a data protection failure involving your Personal Data, to the extent required by applicable laws and regulations, we will notify you through our official communication channels, either directly or indirectly, to provide adequate information regarding the incident and take necessary steps to prevent further misuse of your Personal Data. | ||||||
| 3. | The security of your Zi.Care account largely depends on your efforts to maintain the confidentiality of your password and other access information. You are fully responsible for the confidentiality and security of your account, including your phone number, email, password, and one-time password (OTP), as well as the security of the device you use. If you neglect to maintain that confidentiality or security, you release Zi.Care from any losses or claims arising therefrom. Zi.Care is also not responsible for the misuse of access to the Platform caused by the loss or transfer of control over your device to unauthorized parties. | ||||||
| 4. | We make verification efforts concerning you and your Personal Data to ensure optimal data accuracy, completeness, and consistency. By agreeing to this Privacy Notice, you release us from any claims related to data accuracy, completeness, and/or consistency, without diminishing our obligation to continue efforts for correction in accordance with our responsibilities. | ||||||
| 5. | The obligation to maintain the confidentiality of Personal Data does not apply or is no longer applicable to Personal Data that:
|
L. Links to Third-Party Platforms
| 1. | Please note that when you use the Platform, Zi.Care may include links or hyperlinks to third-party platforms, websites, or applications, including the content contained therein ("Third-Party Platforms") provided for your convenience. Zi.Care has no control over and is not responsible for such Third-Party Platforms; thus, your use of Third-Party Platforms is entirely at your own risk. |
| 2. | This Privacy Notice is solely directed at and enforced regarding the Services through the Platform. |
| 3. | Zi.Care strongly recommends that you always review and thoroughly understand the personal data management policies applicable on Third-Party Platforms before you submit your personal data. |
M. Governing Law
This Privacy Notice is prepared and governed by the laws applicable in the Republic of Indonesia, and you are required to comply with and be fully subject to all applicable laws and regulations in the territory of the Republic of Indonesia.
N. Updates to the Privacy Notice
This Privacy Notice may be amended and/or updated at any time to ensure its compliance with business developments or changes in applicable laws. We will keep previous versions of this Privacy Notice on file for your reference. Zi.Care reserves the right to notify you of any such changes and/or updates in accordance with applicable laws. However, you are advised to periodically review this Privacy Notice page to stay informed of the latest information.
You agree to be fully responsible for the obligation to periodically check this Privacy Notice page to know the latest information regarding the Processing of Personal Data that we undertake. By continuing to access or use the Platform, communicate with us, or purchase Services after changes to this Privacy Notice, you are deemed to have accepted the applicable Privacy Notice along with all its changes.
You agree to be fully responsible for the obligation to periodically check this Privacy Notice page to know the latest information regarding the Processing of Personal Data that we undertake. By continuing to access or use the Platform, communicate with us, or purchase Services after changes to this Privacy Notice, you are deemed to have accepted the applicable Privacy Notice along with all its changes.
O. Contact Us
If you have questions, comments, complaints, or claims regarding this Privacy Notice or wish to exercise your rights as a data subject concerning your Personal Data on the Platform, please send an email to us at info@zicare.id. We will treat your complaint confidentially and will contact you within a reasonable time after receiving your complaint to discuss it and detail the available resolution options.
I HAVE READ AND UNDERSTAND ALL THE PROVISIONS OF THIS PRIVACY NOTICE AND ITS CONSEQUENCES. HEREBY, I ACCEPT ALL RIGHTS, OBLIGATIONS, AND TERMS SET FORTH IN THIS PRIVACY NOTICE. THIS STATEMENT IS CONSIDERED AS MY CONSENT AS THE OWNER AND/OR GUARDIAN OF THE PERSONAL DATA.