1. Who we are
Merpati Healthservices Berhad ("MHSB", "we", "us" or "our") is a company incorporated in Malaysia. We operate the MHSB website at https://www.mhsberhad.com and the Merpati membership application for Android, iPhone and the browser.
For the personal data described in this notice, MHSB is the data user under the Personal Data Protection Act 2010 (“PDPA”). That means we decide what is collected and why, and we are answerable for how it is handled.
Registered office: Unit 12.08, PJ Tower, Amcorp Trade Centre, 18 Persiaran Barat, 46050 Petaling Jaya, Selangor, Malaysia.
Contact for anything in this notice: admin@mhsberhad.com, or +60 19 351 7777 / +60 11 1055 7777.
2. The personal data we collect
We collect only what the membership actually needs. Depending on how you use the platform, that is:
- Identity
- Your full name as it appears on your identity card, your IC number, and your date of birth and gender — the last two are read out of the IC number you enter rather than asked for separately.
- Contact details
- Email address, mobile number, and your address, city, postcode and state.
- Membership record
- Your membership number and tier, application status and dates, your profile photograph if you upload one, and the history of any re-application.
- Professional details
- Whether you are a healthcare professional, your Annual Practising Certificate, your qualifications, speciality and area of practice, the clinics you are affiliated with and the position you hold at each.
- Documents you upload
- Your APC, Borang B or Borang F, signed memoranda of understanding, and clinic or company documents. Superseded uploads are kept rather than overwritten, because a certificate that was current in a given year is still the certificate you held that year.
- Company and clinic records
- Where you register a company or clinic: its name, SSM registration number, addresses, facilities and the people MHSB should deal with.
- Account and security data
- One-time login codes (stored only as hashes, never in readable form), session tokens, a log of administrative actions taken on records, and records of membership-card verifications performed at clinics.
- Website enquiries
- The name, email address, subject and message you send through the enquiry form on our Contact page.
We do not collect patient or clinical records through this platform. It holds membership and professional-registration records, not medical records.
We do not collect payment card numbers. Our website does not run advertising or third-party tracking cookies; the app and the member panel store only what is needed to keep you signed in.
3. Why we collect it, and how we use it
We collect and process personal data relating to members, doctors, healthcare professionals and clinic representatives for the following purposes:
- To create and manage your membership, and to create and maintain a doctor or healthcare-professional profile on our platform.
- To verify and keep accurate the information relating to your professional identity, qualifications, registration, speciality, area of practice, clinic affiliation and professional experience.
- To assess your application, allocate a membership number and issue your digital membership card.
- To let clinics in the network verify a membership card presented to them, and to let authorised users find the clinic and practitioner information they need.
- To administer memoranda of understanding between MHSB and member clinics or companies, including signature and counter-signature.
- To communicate with you about your account, your application, your card, platform services, updates and other relevant matters.
- To provide support and to answer your enquiries and requests.
- To keep our website and application secure, sound and properly operated, including detecting and investigating fraud, misuse or unauthorised access.
- To meet legal, regulatory, professional and reporting requirements that apply to us.
- To improve and develop our services, systems and user experience.
We use your personal data only for the purposes set out in this notice, or for other purposes permitted or required by law. If we ever want to use it for a materially different purpose, we will tell you first and, where the law requires it, ask for your consent.
We do not sell your personal data, and we do not send you direct marketing without your consent.
4. Whether you have to give it to us
The personal data marked as required on our registration forms is obligatory: without it we cannot verify who you are, assess your application, allocate a membership number or issue a card. If you choose not to supply it, we will not be able to process your membership.
Anything else — a profile photograph, for instance — is optional, and leaving it out costs you nothing but the feature it powers.
5. Who we disclose it to
We disclose personal data only where it is necessary for the purposes above. The classes of party we may disclose it to are:
- Clinics and practitioners within the MHSB network, when a membership card is presented for verification — limited to the name, membership number, photograph and status shown on the card.
- MHSB staff and authorised administrators who need access to carry out their responsibilities.
- Our cloud hosting, database and file-storage providers, who hold the platform's data on our behalf.
- Email and one-time-code delivery providers, used to send login codes and account notifications.
- Professional advisers, auditors and insurers, where they need it to advise or act for us.
- Government departments, regulators, courts and law-enforcement agencies, where we are required or permitted by law to disclose it.
- A successor entity, if MHSB reorganises, merges or transfers the business, in which case the data stays subject to a notice no less protective than this one.
Where a third party processes personal data on our behalf, they act on our instructions under a written arrangement and may not use it for their own purposes.
6. Transfers outside Malaysia
Some of the service providers we rely on — cloud hosting and file storage in particular — operate data centres outside Malaysia. Your personal data may therefore be stored or processed outside Malaysia.
Where that happens we take reasonable steps to satisfy ourselves that the receiving jurisdiction and the receiving party provide protection comparable to the PDPA, and that the transfer meets the conditions the Act allows it under.
7. How we protect it
We take reasonable technical, administrative and organisational measures to protect personal data against unauthorised access, disclosure, misuse, alteration, loss or destruction. Those measures include:
- Secure transmission
- Data travelling between your device and our website or application is protected in transit using current encryption.
- Passwordless sign-in
- We do not store passwords. Sign-in uses a one-time code sent to your registered email address, and only a hash of that code is ever stored, with a short expiry and a limit on attempts.
- Access control
- Access is restricted by role to the staff and service providers who need it for their responsibilities.
- Audit logging
- Administrative actions on member and clinic records are logged, so a change can be traced to whoever made it.
- Card verification
- Membership cards are verified through short-lived rotating codes rather than a static number that could be copied and reused.
- Confidentiality
- Personnel with access to personal data are required to keep it confidential and to handle it appropriately.
- Backup and recovery
- Backups are taken so that data can be restored after accidental loss or system failure.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that requires notification under the PDPA, we will assess, contain and investigate it, and make the notifications the law requires within the time it allows.
8. How long we keep it
We keep personal data only for as long as it is needed for the purposes it was collected for, and to meet our legal, regulatory, accounting and other legitimate requirements.
For members and healthcare professionals, that ordinarily means for as long as the membership is active, and for a further period afterwards where we are required or permitted to keep records — for example records relating to a memorandum of understanding, or to a dispute.
If you close or delete your account, we review what is held against it and delete or permanently destroy the personal data that is no longer required, subject to any legal, regulatory, contractual, security or record-keeping requirement that obliges us to keep specific records for longer.
We review the personal data we hold periodically, and securely delete, destroy or anonymise what is no longer needed.
9. Your rights
Subject to the PDPA and any exceptions it allows, you have the following rights over the personal data we hold about you:
- a. Right of access
- You may ask for a copy of the personal data we hold about you and for information about how it is being processed.
- b. Right of correction
- You may ask us to correct, update or complete personal data that is inaccurate, incomplete or out of date. Much of it you can correct yourself: your profile is editable in the app.
- c. Right to withdraw consent
- Where we rely on your consent, you may withdraw it at any time by contacting us. Withdrawing consent may mean we can no longer provide part or all of the service, and it does not affect processing we are permitted or required by law to continue.
- d. Right to prevent processing likely to cause damage or distress
- You may ask us to stop or restrict processing for certain purposes where the PDPA allows it.
- e. Right to prevent processing for direct marketing
- You may tell us to stop using your personal data for direct marketing, at any time and at no cost, either by replying to us or by using the unsubscribe link in any message we send.
- f. Right to request deletion
- You may ask us to delete personal data we no longer need to keep. You can also delete your account yourself from within the app, which removes your account and the data held against it, except anything we are required to retain.
- g. Right to data portability
- Where the Personal Data Protection (Amendment) Act 2024 applies, you may ask us to transmit your personal data to another data user, so far as it is technically feasible and the data format allows.
To exercise any of these rights, write to admin@mhsberhad.com or to Unit 12.08, PJ Tower, Amcorp Trade Centre, 18 Persiaran Barat, 46050 Petaling Jaya, Selangor, Malaysia. We may need to verify your identity before we act on a request — that check protects you, not us. We will respond within the period the PDPA requires. Some requests carry statutory limits or a prescribed fee, and we will tell you if that is the case before doing anything.
If you are not satisfied with how we have handled your personal data or your request, you may complain to us first, and you may also complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Malaysia.
11. Children
The platform is intended for doctors, healthcare professionals, clinic representatives and adult members. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will remove it.
12. Changes to this notice
We may update this notice as our services, or the law, change. Every version carries a version number and a date at the top of this page, and the version you accepted when you registered is recorded against your membership.
Where a change materially affects how we use your personal data, we will bring it to your attention rather than rely on you re-reading this page.



