Effective date: 11 August 2026 · Last updated: 11 August 2026
1. Who is responsible for your data
1.1 Vast Dynamic Ltd, a Hong Kong company, registration number 77131343, registered address Level 9, Amtel Building, 144-148 Des Voeux Road Central, Hong Kong, trading as Mesura Health, is the data user (controller) for the programme dataset: your registration, programme, engagement, measurement and outcome data, and your WhatsApp conversation with the programme.
Because we are established outside Malaysia, we want to be clear about what that means for you: we treat ourselves as bound by the Personal Data Protection Act 2010 ("PDPA") in respect of your data and give you the full set of PDPA rights described in §9, whether or not a court would hold the Act to apply to a Hong Kong data user. Your data is also protected by the contractual commitments in this policy, which you can enforce against us, and you may complain to the Personal Data Protection Commissioner in Malaysia.
1.2 Each partner clinic providing your care is a separate data user for your clinical record — consultation notes, prescriptions, and dispensing records — which it keeps under its own statutory medical-record obligations. This policy covers Mesura's processing; the clinic's processing is governed by its own notice, and this policy explains what we exchange with it.
1.3 Data protection contact: our Data Protection Officer, at support@mesura.health, or by post to the registered address in §1.1.
2. What we collect
From you, during assessment and care (sensitive personal data under PDPA s.4 — collected only with your explicit consent):
- Identity and contact: name, WhatsApp number, preferred language.
- Health information you give at intake: height, weight (and computed BMI), and your answers to screening questions (pregnancy/breastfeeding, thyroid cancer/MEN2 history, pancreatitis, current GLP-1 use, gallbladder disease).
- Everything you send on the programme WhatsApp thread, in both directions, including free-text symptom and side-effect reports. Assume anything you send there is recorded.
- Self-reported measurements during care (weight, and where the programme requests them, waist, blood pressure, adherence check-ins).
From your care team and the partner clinic (via the clinical-systems bridge):
- Booking, consultation-completed, prescription-issued, dispensing and doctor-reviewed lab events, limited to the fields the programme needs. The bridge excludes full clinical notes, diagnosis codes beyond programme scope, ID documents, and card data by design.
Payments: order references, amounts, and payment status. Card details are entered on the payment provider's secure page; we never see or store card numbers.
Website — the online assessment. The assessment is scored in your browser, and the result is shown to you before anything is sent to us. Nothing leaves your device unless you choose to submit it.
When you submit it, we record: your name and the email address or phone number you give us, so a person can reply; the market and state you are in; how the assessment came out; and, where our safety rules flagged something in what you wrote, that they flagged it, so a person sees it first rather than third.
Your clinical answers are not written to our database. They travel with your submission and reach a member of our team as a message they read — that message is where they stay. We have not made them queryable, and running a waiting list does not require it.
Permission to contact you is separate and is never assumed. If you ask us to tell you when the programme opens, we record that permission as its own field, unticked unless you tick it, and agreeing to be assessed is not agreeing to be marketed to. You can withdraw it at any time by writing to support@mesura.health.
How long we keep it, and how to have it removed. We keep your entry only as long as we need it to contact you about the programme opening. You can ask us to delete it at any time, by writing to support@mesura.health, and we will — this record is not part of the append-only store described in §6, so deleting it means deleting it.
Analytics: no analytics or tracking are deployed on our website — no usage data is collected there at all. If that ever changes, this policy is updated before it does.
We do not collect your NRIC or passport number, ID documents, or photos as part of the programme record. Your age and your presence in Malaysia are verified by the partner clinic when it registers you, using the identity documents it holds for its own statutory purposes — those documents are the clinic's and are never sent to us.
3. Why we process it, and on what basis
| Purpose | Data | PDPA basis |
|---|---|---|
| Running your programme: assessment, booking, check-ins, reminders, measurement tracking | All programme data | Explicit consent (s.40) + performance of our contract with you (s.6) |
| Clinical safety: routing your messages, detecting red-flag symptoms, escalating to your care team | Message content, health reports | Explicit consent; vital-interest processing in emergencies |
| Sharing with the partner clinic and pharmacy for your care | Programme + health data per §4 | Your explicit dual-entity consent |
| Billing and payment | Payment records | Contract performance; legal obligations |
| Service improvement and quality assurance | De-identified and aggregated data only | Performance of our contract with you. The PDPA has no general "legitimate interest" basis, so we do not rely on one — this processing uses data from which you cannot be identified |
| Research and publication of cohort outcomes | De-identified data only, per §7 | Separate, optional research consent — never assumed |
| Legal and regulatory obligations | As required | Legal obligation |
| Direct marketing | Contact data | Separate, optional consent (s.43) — never a condition of care |
4. Who we share it with
- The partner clinic and its pharmacy — for your care, under the dual-entity consent you give at the start. Data flows both ways over an authenticated, consent-gated bridge: no data flows for a patient whose consent is not currently granted.
- Messaging providers: our WhatsApp Business provider (currently respond.io) and Meta (WhatsApp). WhatsApp business-API traffic is processed by the provider and Meta; it is not end-to-end encrypted to Mesura in the way person-to-person WhatsApp is.
- AI — and where it runs. Software including AI is used to draft routine replies, route your messages, and prepare a summary of your intake for your doctor. This processing runs on a model operated by the partner clinic on its own infrastructure in Malaysia. Your message content is not sent to any external AI company, and is not used to train anyone's models. The AI has no access to our database and cannot take any decision about you — it drafts and prepares; your doctor decides and signs.
- Payment provider: Airwallex. It processes your payment; we receive status and references only, and never your card details.
- Infrastructure: cloud hosting (currently Railway) and Cloudflare, which delivers the website. No analytics warehouse is in use, and no analytics beacon is running. If either is adopted, this policy and the Transfer Impact Assessment are updated first — a warehouse is where a de-identification promise is most easily broken by accident.
- WellTech Health — a separate company, not a parent or affiliate, whose engineers build and operate the service platform under contract as our data processor.
- Authorities and others where the law permits or requires — see the Privacy Practices document §5 for the narrow list.
We never sell your personal data.
5. Cross-border transfers
Your data is held and administered outside Malaysia. Mesura is a Hong Kong company, so your programme data is controlled from Hong Kong, and our service providers process it in our messaging, payment and hosting providers process it outside Malaysia. Two things stay here: your clinical record, held by the partner clinic, and the AI processing described in §4, which runs on the clinic's own infrastructure in Malaysia rather than crossing a border.
Where personal data leaves Malaysia we rely on your explicit consent, given at intake before any health information is collected, and — for the transfers the service cannot operate without, such as messaging, payments and hosting — additionally on the necessity of those transfers to perform our contract with you. We contractually require every recipient to protect your data to the standard set out in this policy.
6. How long we keep it
- Clinical and programme health records: retained per the medical-records retention requirement applicable to the partner clinic and per our retention schedule — 7 years (from the last entry on your clinical record).
- Consent and audit records: kept for the life of the record they evidence, in tamper-evident append-only form.
- Payment records: 7 years per tax and accounting law.
- Marketing data: until you withdraw consent.
What happens at the end of that period, stated plainly. Our records are held in an append-only system: entries can be added but not altered or erased. That is deliberate — it is what makes your care record and our audit trail trustworthy. The consequence is that we quarantine rather than delete: the record is closed to all operational use, nothing is served, messaged, analysed or exported from it, and it can only be reopened through a restricted route that itself records who opened it and when. Marketing contact data is genuinely deleted from our marketing systems when you withdraw. The same applies if you withdraw consent before retention ends: we stop processing and quarantine, keeping only what medical-record, audit and legal obligations require (PDPA Notice §5).
We would rather tell you this than claim a deletion we cannot perform.
7. Research and published outcomes
We aim to publish programme outcomes. Anything published is de-identified: pseudonymous IDs only, age in 5-year bands, no dates finer than enrolment month, small-cell suppression, DPO-reviewed before release. The raw linked dataset never leaves Mesura's store. Inclusion requires your separate research consent, which is optional and does not affect your care.
8. Security
Access controls with per-role authentication; encryption in transit; append-only audit logging of every access-relevant event including every consent decision; signed, replay-protected integration traffic; secrets in a managed secret store; no production patient data in staging. Our AI safety layer runs deterministic checks before and after any AI involvement in your messages.
Breach response: we maintain a breach-response plan (dpo/breach-response-plan.md) — severity model, first hour, assessment and notification routes. Where required under the PDPA as amended we will notify the Personal Data Protection Commissioner within the period the Act requires, and affected patients without undue delay.
9. Your rights
Under the PDPA you have the right to: access your personal data (response within the statutory 21 days, free of charge); correct inaccurate data; withdraw consent at any time; prevent processing likely to cause damage or distress (s.42); and stop direct marketing (s.43). How to exercise each, verification and timelines are in the PDPA Data Protection Notice, which is the operative notice for these rights — and we do not charge a fee for an access request, though the Act permits one. You may complain to us first, and at any time to the Personal Data Protection Commissioner.
10. Children
The service is for adults 18 and over, and the partner clinic verifies age at registration before any prescription. We do not knowingly collect data from minors; if we learn we have, we end the registration and quarantine the data, and we do not require anyone to prove their age to us in order for that to happen — telling us is enough.
11. Changes
Material changes will be notified on the programme channel before they take effect, with the new version and date shown here.

