Privacy Policy
Effective Date: August 25, 2026 | Last Updated: August 25, 2026
1. Data Controller & Legal Entity Identity
This Privacy Policy applies to the services, websites, and applications provided by LamaniHub, a software product owned and operated by Lamanify ("we", "us", or "our").
Legal Entity Name: Lamanify
Registration / SSM Number: 201803157488 (SA0472478-H)
Registered Business Address: Level 23-1, Premier Suite, One Mont Kiara, No. 1, Jalan Kiara, Mont Kiara, 50480 Kuala Lumpur, Malaysia
Privacy Contact Email: admin@lamanify.com
2. Meta & WhatsApp Business Platform (Cloud API) Disclosure
LamaniHub provides clinic scheduling software, automated appointment reminders, and AI receptionist features powered through direct integration with Meta Platforms, Inc. via the WhatsApp Business Platform (Cloud API).
When patients or prospective patients communicate with a participating clinic's official WhatsApp number powered by LamaniHub:
- Transit via Meta's Servers: All incoming and outgoing WhatsApp messages transit through Meta’s secure global infrastructure (WhatsApp Business Platform / Cloud API).
- Data Received from Meta: When a user sends a message to the clinic, we receive webhook event payloads from Meta containing:
- Sender's WhatsApp phone number (MSISDN)
- WhatsApp profile name (as configured by the user on WhatsApp)
- Message content (text, button payload clicks, interactive list replies, media IDs, or location)
- Message metadata and delivery status receipts (sent, delivered, read timestamps)
- Data Sent to Meta: To communicate with patients, we transmit payloads to Meta’s Cloud API containing:
- Automated AI receptionist conversational responses
- Appointment confirmation notices and reminder templates
- Rescheduling links and clinic location/operation details
- Post-visit follow-up messages or review requests
3. Controller / Processor Relationship
Under the Malaysian Personal Data Protection Act 2010 (PDPA) and international data protection standards:
Clinic as Data Controller
The healthcare clinic / practice is the Data Controller for all patient data, appointment records, and patient conversation logs. The clinic determines the legal basis for contacting patients and obtaining patient consent.
LamaniHub as Data Processor
Lamanify (LamaniHub) acts solely as the Data Processor (or Data User) processing patient data on behalf of and strictly under the instructions of the clinic. For clinic staff account information, Lamanify acts as the controller.
Patient inquiries regarding access, rectification, or deletion of medical/booking records should primarily be directed to the respective clinic. Patients may also submit deletion requests to us as outlined in Section 8.
4. Information We Collect
We collect and process two categories of personal information:
A. Clinic Account & Staff Data
- Clinic business name, address, SSM registration, and contact details
- Staff user details: full names, work email addresses, phone numbers, role permissions, and hashed passwords
- Subscription, billing, and payment transaction metadata (processed securely via Stripe)
B. Patient Data Processed on Behalf of Clinics
- Patient Contact Information: Name, phone number, and optional email address.
- Appointment Information: Booked service type, practitioner/doctor requested, preferred date and time slot, appointment status (confirmed, cancelled, rescheduled, attended).
- WhatsApp Communications: Inbound patient queries, conversational messages, structured form inputs, and automated AI receptionist responses.
- Technical & Message Metadata: Message delivery timestamps, message IDs, IP addresses for web booking submissions, and browser user-agent strings.
5. Purposes of Processing
We process data exclusively for legitimate operational purposes:
- Online & WhatsApp Appointment Booking: Enabling patients to self-schedule, select available slots, and confirm appointments 24/7.
- 24/7 AI Receptionist Assistance: Answering frequent clinic inquiries (opening hours, branch locations, doctor roster, service pricing) and triaging complex medical queries to human clinic staff.
- Automated Reminder Workflows: Sending multi-touch WhatsApp notifications (immediate confirmation, 3-day reminder, 1-day reminder, 6-hour reminder, and 1-hour before visit) with self-service reschedule links to reduce clinic no-shows.
- Operational Clinic Management: Providing doctors and front desk staff with a real-time calendar and patient queue dashboard.
- Platform Security & Diagnostics: Monitoring system uptime, detecting spam or malicious abuse, and auditing webhook reliability.
6. Third-Party Sub-Processors
To deliver enterprise-grade performance and reliability, we engage specialized sub-processors under rigorous data processing and confidentiality agreements:
| Sub-Processor | Purpose | Data Handled | Location |
|---|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Platform (Cloud API) message delivery & webhook ingress | WhatsApp phone number, profile name, message body, message status | USA / Global |
| Supabase, Inc. | Encrypted database storage & real-time sync | Clinic account data, appointments, patient contacts, message logs | Singapore / Global |
| Google LLC (Gemini API) | Natural language processing for AI clinic receptionist queries | Transient message text (no patient training storage) | USA / Global |
| Cloudflare, Inc. | Web hosting, edge routing, SSL encryption & DDoS protection | IP address, request headers, web booking traffic | Global Edge Network |
| Langfuse | LLM observability, latency tracking & prompt diagnostics | Anonymized prompt traces, token counts, response latency | EU / USA |
| Sentry (Functional Software, Inc.) | Application error tracking & crash reporting | Error stack traces, anonymized diagnostic headers | USA |
| Stripe, Inc. | Payment processing & subscription billing for clinic accounts | Clinic payment card details, billing address, invoice history | Global / USA |
| Cloudinary Inc. | Clinic media & asset delivery (logos, staff photos) | Clinic public assets, images | Global CDN |
7. International Data Transfers
While our primary operations and customer support are located in Malaysia, our technical infrastructure and third-party sub-processors (including Meta, Google, Cloudflare, and Stripe) maintain data centers located outside Malaysia (including Singapore, the United States, and the European Union).
Whenever personal data is transferred internationally, we ensure adequate protection standards are maintained in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA) through standard contractual clauses, technical encryption, and strict vendor security assessments.
8. Your Rights Under Malaysia PDPA
Pursuant to the Personal Data Protection Act 2010 (PDPA) of Malaysia, individuals possess specific legal rights concerning their personal data:
- Right to Access: You have the right to request access to and obtain a copy of your personal data held in our systems.
- Right to Correction: You have the right to require us or the clinic to correct any inaccurate, incomplete, or misleading data.
- Right to Withdraw Consent: You may withdraw consent for receiving automated reminders or marketing communications at any time.
- Right to Deletion / Erasure: You may request the deletion of your personal records and WhatsApp conversation history as outlined on our Data Deletion Instructions page.
Exercising Your Rights: To exercise any of these rights, please email us at admin@lamanify.com. We will respond to verified requests within 21 business days.
If you believe your personal data has been handled inconsistently with the law, you have the right to lodge an escalation or complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi / JPDP) Malaysia (www.pdp.gov.my).
9. Data Retention Policy
We retain personal information only for as long as necessary to fulfill operational, clinical, and statutory obligations:
- WhatsApp Message Logs & Transcripts: Retained for a maximum of 180 days from receipt to facilitate customer service continuity, after which message contents are permanently purged or aggregated.
- Patient Appointment Records: Retained for the duration of the clinic's active subscription, or up to 7 years where required by healthcare record-keeping guidelines and clinic controller mandates.
- Clinic Account & Billing Records: Retained for 7 years following account termination in compliance with Malaysian tax (LHDN) and statutory accounting requirements.
- Ephemeral AI Traces: Diagnostic logs and transient AI prompt tokens are purged within 30 days.
10. Security Measures
We maintain comprehensive technical and organizational security safeguards:
- Encryption in Transit: All HTTP and webhook communication is enforced via TLS 1.3 encryption.
- Encryption at Rest: Database records, backups, and message storage are encrypted at rest using AES-256 standards.
- Row-Level Security (RLS): Multi-tenant isolation is strictly enforced at the database layer ensuring clinics can only access their own respective data.
- API Key & Credential Encryption: Meta Cloud API tokens, WhatsApp System User credentials, and webhooks are encrypted using industry-standard secret management vaults.
11. Changes to This Privacy Policy
We may revise this Privacy Policy periodically to reflect technological updates, Meta platform policy changes, or legal developments. We will notify active clinic accounts of material updates via email or dashboard announcements. Continued use of LamaniHub after updates constitutes acceptance of the revised policy.
12. Contact Information
For questions, data access requests, or privacy inquiries:
Lamanify (LamaniHub)
Email: admin@lamanify.com
WhatsApp Support: +60 11-5670 6510
Address: Level 23-1, Premier Suite, One Mont Kiara, No. 1, Jalan Kiara, Mont Kiara, 50480 Kuala Lumpur, Malaysia