QuantumNexis Sdn Bhd / Ziloy
Last Updated: 12 May 2026
This Personal Data Protection Policy & Privacy Notice (“Policy”) is issued pursuant to the Personal Data Protection Act 2010 (“PDPA”) of Malaysia.
QuantumNexis Sdn Bhd (Company No. 202501025798 (1627211-P)) operating under the brand name “ZILOY” (“Company”, “we”, “us”, “our”) is committed to protecting personal data and ensuring that all personal data is processed in accordance with applicable Malaysian laws, including the Personal Data Protection Act 2010.
This Policy explains how personal data is collected, used, processed, disclosed, safeguarded, retained, and managed in connection with:
This Policy also sets out the operational, confidentiality, platform usage, and data protection obligations applicable to all employees, clinicians, consultants, contractors, Care Navigators, vendors, and authorised users who access or process personal data through QuantumNexis Sdn Bhd and the Ziloy platform.
QuantumNexis Sdn Bhd
Unit B-09-06 Plaza Mont Kiara,
No. 2, Jalan Kiara,
Mont Kiara,
50480 Kuala Lumpur,
Malaysia
Email: contact@ziloy.my
Website: https://ziloy.my
This Policy applies to all personal data processed by QuantumNexis Sdn Bhd in connection with its commercial activities, operational processes, healthcare-related services, digital platforms, teleconsultation services, onboarding activities, and internal governance functions.
The scope of this Policy extends to all users of the Ziloy platform, websites, mobile applications, communication channels, digital healthcare systems, and related services operated by the Company.
This Policy further applies to patients, clients, clinicians, healthcare practitioners, Care Navigators, employees, consultants, contractors, outsourced personnel, vendors, third-party service providers, management personnel, and any authorised individual or entity granted access to personal data, Company systems, operational information, or healthcare-related services administered by the Company.
The provisions contained in this Policy apply to all forms of personal data processing conducted by or on behalf of the Company, whether through digital systems, operational activities, healthcare services, administrative processes, customer engagement channels, or authorised third-party service arrangements.
“Personal Data” means any information relating directly or indirectly to an identifiable individual in connection with a commercial transaction as defined under the Personal Data Protection Act 2010.
Depending on the services requested, the Company may collect and process the following categories of personal data:
4.1 Personal Information
4.2 Sensitive Personal Data
Where applicable and with appropriate consent, the Company may process Sensitive Personal Data including:
4.3 Employment & Professional Information
For clinicians, consultants, contractors, and authorised personnel:
4.4 Technical & Operational Information
Where any technical or operational information identifies or is capable of identifying an individual, such information shall be treated as personal data.
Personal data may be collected directly from individuals or through lawful third-party sources in connection with the Company’s operational, healthcare, administrative, compliance, and service-related activities.
Such collection may occur through registration forms, onboarding documentation, healthcare consultations, questionnaires, assessments, communication channels, customer support interactions, mobile applications, websites, teleconsultation services, operational processes, healthcare administration systems, or other authorised digital platforms operated by or on behalf of the Company.
Where permitted under applicable laws or with appropriate consent, personal data may also be obtained from healthcare providers, insurers, diagnostic laboratories, employers, regulatory authorities, authorised service providers, corporate partners, or other relevant third parties for purposes directly related to the provision, administration, coordination, or enhancement of the Company’s services.
The Company shall take reasonable steps to ensure that personal data collected is relevant, accurate, and limited to information necessary for lawful operational and service-related purposes.
Personal data is processed only for lawful purposes directly related to the operation, administration, governance, and provision of the Company’s services, digital platforms, healthcare ecosystem, and business operations.
Such processing may include activities relating to user registration, account administration, healthcare consultations, teleconsultation services, mental health assessments, patient engagement, Care Navigation services, appointment coordination, communication relating to services, healthcare administration, billing and payment processing, customer support, operational management, and service delivery.
Personal data may also be processed for compliance monitoring, audit and governance requirements, cybersecurity management, fraud prevention, incident management, operational analytics, service enhancement, digital platform administration, legal compliance, regulatory obligations, and responding to lawful requests from government authorities, regulators, or law enforcement agencies.
Where permitted under applicable laws, the Company may process personal data for operational improvement initiatives, digital healthcare enhancement, platform optimisation, internal reporting, business continuity, service quality management, and other legitimate operational purposes reasonably connected to the Company’s activities.
The Company shall not process personal data for purposes unrelated to its services, operational requirements, or lawful business activities unless consent has been obtained or such processing is otherwise permitted under applicable laws.
All authorised personnel, clinicians, Care Navigators, consultants, contractors, vendors, and platform users who are granted access to personal data or Company systems shall comply with the following obligations:
Failure to comply with these obligations may result in suspension of access, disciplinary action, termination of engagement, legal action, regulatory reporting, or other actions deemed necessary by the Company.
All authorised users of the Ziloy platform and related systems shall:
The Company reserves the right to suspend or revoke system access where misuse, security concerns, or non-compliance is identified
Where healthcare consultations, assessments, or related services are conducted digitally through the Ziloy platform or other authorised systems:
Certain features, assessments, analytics, or service functionalities may involve automated processing, AI-assisted technologies, or digital healthcare tools to support service delivery, operational efficiency, user experience, or healthcare administration.
Such technologies shall be used only for lawful purposes directly related to the services provided and subject to appropriate safeguards, confidentiality obligations, and applicable Malaysian laws.
Personal data and patient information must not be uploaded into unauthorised public AI platforms or systems.
Personal data may be disclosed by the Company only where such disclosure is lawful, necessary, proportionate, and directly related to the provision, administration, operation, compliance, or enhancement of the Company’s services and business activities.
Such disclosures may be made to healthcare providers, clinicians, healthcare practitioners, insurers, pharmacies, medication fulfilment partners, diagnostic laboratories, authorised healthcare-related parties, IT and cloud hosting providers, payment processors, auditors, legal advisers, compliance consultants, cybersecurity providers, operational service providers, regulatory authorities, government agencies, or other authorised third parties engaged by the Company.
Where personal data is disclosed to third-party service providers or operational partners, the Company shall take reasonable steps to ensure that such parties are contractually or operationally required to safeguard personal data, maintain confidentiality, implement appropriate security measures, and process personal data only in accordance with applicable laws and the Company’s instructions.
The Company shall not sell personal data or disclose personal data for unrelated third-party marketing purposes without appropriate consent or lawful basis.
The Company’s services may contain links to or integrations with third-party platforms or services operated independently of the Company.
Where you choose to interact with such third-party services, the collection, use, and disclosure of personal data shall be governed by the respective policies of those third parties.
The Company is not responsible for the privacy or data protection practices of independent third-party platforms.
The Company does not knowingly process personal data of individuals below eighteen (18) years of age without verifiable consent from a parent or legal guardian.
Where services are provided in relation to a minor:
Where the Company becomes aware that personal data relating to a minor has been collected without the required consent, such information shall be deleted as soon as reasonably practicable.
By providing personal data to the Company, you consent to the collection, use, disclosure, and processing of such personal data for purposes directly related to the Company’s services and operations.
Explicit Consent for Sensitive Personal Data
Sensitive Personal Data including health information, mental health assessments, biometric information, medical records, or other sensitive information shall only be processed with explicit consent or where otherwise permitted under applicable law.
Explicit consent may be obtained through:
The Company implements reasonable administrative, technical, and physical safeguards to protect personal data against:
Access to personal data is restricted to authorised personnel who require such access for legitimate operational or service-related purposes.
While reasonable safeguards are implemented, no transmission or storage system can be guaranteed to be completely secure.
Users are encouraged to notify the Company immediately if they become aware of any unauthorised access or suspicious activity involving personal data.
Any actual or suspected:
must be reported immediately to the Company through designated reporting channels.
The Company reserves the right to investigate, suspend access, implement containment measures, notify affected parties where required, and report incidents to regulatory authorities in accordance with applicable laws.
Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected or as required under applicable laws, regulatory obligations, healthcare requirements, audit requirements, or operational needs.
Upon expiry of the applicable retention period, personal data shall be securely deleted, anonymised, or disposed of appropriately.
Where personal data is transferred outside Malaysia, such transfer shall be carried out only in accordance with applicable Malaysian laws and subject to appropriate safeguards to ensure adequate protection of the personal data.
Upon termination, resignation, cessation of engagement, suspension, or expiry of authorised access:
Subject to the provisions of the Personal Data Protection Act 2010, individuals may:
Requests may be submitted in writing to:
Email: contact@ziloy.my
The Company may take reasonable steps to verify the identity of the requesting individual before responding to any request.
The Company may implement internal policies, standard operating procedures (SOPs), compliance guidelines, information security procedures, onboarding requirements, and operational controls from time to time to support compliance with this Policy and applicable laws.
All authorised personnel are required to comply with such internal requirements.
Any complaint relating to the processing of personal data may be directed to the Company using the contact details below.
Where applicable, complaints may also be lodged with the Department of Personal Data Protection (JPDP), Malaysia.
This Policy shall be governed by and construed in accordance with the laws of Malaysia.
The Company reserves the right to amend or update this Policy from time to time.
Any revised version shall take effect upon publication through the Company’s website, platform, application, or official communication channels.
For any enquiries relating to this Policy or the processing of personal data, please contact:
QuantumNexis Sdn Bhd
Unit B-09-06 Plaza Mont Kiara,
No. 2, Jalan Kiara,
Mont Kiara,
50480 Kuala Lumpur,
Malaysia
Email: contact@ziloy.my
Website: https://ziloy.my
QuantumNexis Sdn Bhd / Ziloy
Kemaskini Terakhir: 12 Mei 2026
Dasar Perlindungan Data Peribadi & Notis Privasi (“Dasar”) ini dikeluarkan menurut Akta Perlindungan Data Peribadi 2010 (“PDPA”) Malaysia.
QuantumNexis Sdn Bhd (No. Syarikat 202501025798 (1627211-P)) yang beroperasi di bawah jenama “ZILOY” (“Syarikat”, “kami”, “kita”, atau “milik kami”) komited dalam melindungi data peribadi dan memastikan semua data peribadi diproses selaras dengan undang-undang Malaysia yang berkuat kuasa termasuk Akta Perlindungan Data Peribadi 2010.
Dasar ini menerangkan bagaimana data peribadi dikumpul, digunakan, diproses, didedahkan, dilindungi, disimpan, dan diuruskan berkaitan dengan:
Dasar ini juga menetapkan kewajipan operasi, kerahsiaan, penggunaan platform, dan perlindungan data yang terpakai kepada semua pekerja, klinikal, perunding, kontraktor, Care Navigator, vendor, dan pengguna yang diberi kuasa yang mengakses atau memproses data peribadi melalui QuantumNexis Sdn Bhd dan platform Ziloy.
QuantumNexis Sdn Bhd
Unit B-09-06 Plaza Mont Kiara,
No. 2, Jalan Kiara,
Mont Kiara,
50480 Kuala Lumpur,
Malaysia
Email: contact@ziloy.my
Website: https://ziloy.my
Dasar ini terpakai kepada semua data peribadi yang diproses oleh QuantumNexis Sdn Bhd berkaitan dengan aktiviti komersial, proses operasi, perkhidmatan berkaitan penjagaan kesihatan, platform digital, perkhidmatan telekonsultasi, aktiviti onboarding, dan fungsi tadbir urus dalaman.
Skop Dasar ini meliputi semua pengguna platform Ziloy, laman web, aplikasi mudah alih, saluran komunikasi, sistem penjagaan kesihatan digital, dan perkhidmatan berkaitan yang dikendalikan oleh Syarikat.
Dasar ini turut terpakai kepada pesakit, pelanggan, klinikal, pengamal penjagaan kesihatan, Care Navigator, pekerja, perunding, kontraktor, kakitangan luar, vendor, penyedia perkhidmatan pihak ketiga, pihak pengurusan, dan mana-mana individu atau entiti yang diberi kuasa untuk mengakses data peribadi, sistem Syarikat, maklumat operasi, atau perkhidmatan berkaitan penjagaan kesihatan yang ditadbir oleh Syarikat.
Peruntukan dalam Dasar ini terpakai kepada semua bentuk pemprosesan data peribadi yang dijalankan oleh atau bagi pihak Syarikat sama ada melalui sistem digital, aktiviti operasi, perkhidmatan penjagaan kesihatan, proses pentadbiran, saluran penglibatan pelanggan, atau pengaturan perkhidmatan pihak ketiga yang dibenarkan.
“Data Peribadi” bermaksud sebarang maklumat yang berkaitan secara langsung atau tidak langsung dengan individu yang boleh dikenal pasti berkaitan transaksi komersial sebagaimana ditakrifkan di bawah Akta Perlindungan Data Peribadi 2010.
Bergantung kepada perkhidmatan yang diminta, Syarikat boleh mengumpul dan memproses kategori data peribadi berikut:
4.1 Maklumat Peribadi
4.2 Data Peribadi Sensitif
Jika berkaitan dan dengan persetujuan sewajarnya, Syarikat boleh memproses Data Peribadi Sensitif termasuk:
4.3 Maklumat Pekerjaan & Profesional
Bagi klinikal, perunding, kontraktor, dan kakitangan yang diberi kuasa:
4.4 Maklumat Teknikal & Operasi
Sekiranya mana-mana maklumat teknikal atau operasi boleh mengenal pasti seseorang individu, maklumat tersebut akan dianggap sebagai data peribadi.
Data peribadi boleh dikumpul secara terus daripada individu atau melalui sumber pihak ketiga yang sah berkaitan dengan aktiviti operasi, penjagaan kesihatan, pentadbiran, pematuhan, dan perkhidmatan Syarikat.
Pengumpulan tersebut boleh berlaku melalui borang pendaftaran, dokumentasi onboarding, konsultasi penjagaan kesihatan, soal selidik, penilaian, saluran komunikasi, interaksi sokongan pelanggan, aplikasi mudah alih, laman web, perkhidmatan telekonsultasi, proses operasi, sistem pentadbiran penjagaan kesihatan, atau platform digital lain yang dikendalikan oleh atau bagi pihak Syarikat.
Jika dibenarkan di bawah undang-undang yang terpakai atau dengan persetujuan sewajarnya, data peribadi juga boleh diperoleh daripada penyedia penjagaan kesihatan, syarikat insurans, makmal diagnostik, majikan, pihak berkuasa kawal selia, penyedia perkhidmatan yang dibenarkan, rakan korporat, atau pihak ketiga lain yang berkaitan.
Syarikat akan mengambil langkah yang munasabah untuk memastikan data peribadi yang dikumpul adalah relevan, tepat, dan terhad kepada maklumat yang diperlukan bagi tujuan operasi dan perkhidmatan yang sah.
Data peribadi diproses hanya bagi tujuan yang sah dan berkaitan secara langsung dengan operasi, pentadbiran, tadbir urus, dan penyediaan perkhidmatan Syarikat, platform digital, ekosistem penjagaan kesihatan, dan operasi perniagaan.
Pemprosesan tersebut boleh merangkumi aktiviti berkaitan pendaftaran pengguna, pentadbiran akaun, konsultasi penjagaan kesihatan, perkhidmatan telekonsultasi, penilaian kesihatan mental, penglibatan pesakit, perkhidmatan Care Navigation, penyelarasan janji temu, komunikasi berkaitan perkhidmatan, pentadbiran penjagaan kesihatan, pemprosesan bil dan pembayaran, sokongan pelanggan, pengurusan operasi, dan penyampaian perkhidmatan.
Data peribadi juga boleh diproses untuk pemantauan pematuhan, keperluan audit dan tadbir urus, pengurusan keselamatan siber, pencegahan penipuan, pengurusan insiden, analitik operasi, penambahbaikan perkhidmatan, pentadbiran platform digital, pematuhan undang-undang, obligasi kawal selia, dan bagi memenuhi permintaan sah daripada pihak berkuasa kerajaan atau penguat kuasa.
Syarikat tidak akan memproses data peribadi bagi tujuan yang tidak berkaitan dengan perkhidmatannya melainkan dengan persetujuan atau sebagaimana dibenarkan oleh undang-undang.
Semua kakitangan yang diberi kuasa, klinikal, Care Navigator, perunding, kontraktor, vendor, dan pengguna platform yang diberikan akses kepada data peribadi atau sistem Syarikat hendaklah mematuhi kewajipan berikut:
Kegagalan mematuhi kewajipan ini boleh mengakibatkan penggantungan akses, tindakan operasi atau undang-undang, penamatan penglibatan, pelaporan kawal selia, atau tindakan lain yang dianggap perlu oleh Syarikat.
Semua pengguna yang diberi kuasa bagi platform Ziloy dan sistem berkaitan hendaklah:
Syarikat berhak menggantung atau membatalkan akses sistem sekiranya terdapat penyalahgunaan, kebimbangan keselamatan, atau ketidakpatuhan.
Sekiranya konsultasi penjagaan kesihatan, penilaian, atau perkhidmatan berkaitan dijalankan secara digital melalui platform Ziloy atau sistem yang dibenarkan:
Ciri-ciri tertentu, penilaian, analitik, atau fungsi perkhidmatan mungkin melibatkan pemprosesan automatik, teknologi bantuan AI, atau alat penjagaan kesihatan digital untuk menyokong penyampaian perkhidmatan, kecekapan operasi, pengalaman pengguna, atau pentadbiran penjagaan kesihatan.
Teknologi tersebut hendaklah digunakan hanya bagi tujuan yang sah dan tertakluk kepada perlindungan yang sewajarnya serta undang-undang Malaysia yang terpakai.
Data peribadi dan maklumat pesakit tidak boleh dimuat naik ke platform AI awam yang tidak dibenarkan.
Data peribadi boleh didedahkan oleh Syarikat hanya apabila pendedahan tersebut sah, perlu, berkadar, dan berkaitan secara langsung dengan penyediaan, pentadbiran, operasi, pematuhan, atau penambahbaikan perkhidmatan dan aktiviti perniagaan Syarikat.
Pendedahan tersebut boleh dibuat kepada penyedia penjagaan kesihatan, klinikal, syarikat insurans, farmasi, rakan berkaitan penjagaan kesihatan, penyedia hosting awan, pemproses pembayaran, juruaudit, penasihat undang-undang, perunding pematuhan, pihak berkuasa kawal selia, agensi kerajaan, dan pihak ketiga lain yang dibenarkan oleh Syarikat.
Syarikat tidak akan menjual data peribadi atau mendedahkan data peribadi bagi tujuan pemasaran pihak ketiga yang tidak berkaitan tanpa persetujuan sewajarnya.
Perkhidmatan Syarikat mungkin mengandungi pautan atau integrasi dengan platform atau perkhidmatan pihak ketiga yang dikendalikan secara bebas daripada Syarikat.
Sekiranya anda memilih untuk berinteraksi dengan perkhidmatan pihak ketiga tersebut, pengumpulan, penggunaan, dan pendedahan data peribadi akan tertakluk kepada dasar pihak ketiga berkenaan.
Syarikat tidak bertanggungjawab terhadap amalan privasi atau perlindungan data pihak ketiga yang bebas.
Syarikat tidak akan memproses data peribadi individu di bawah umur lapan belas (18) tahun tanpa persetujuan yang boleh disahkan daripada ibu bapa atau penjaga sah.
Sekiranya perkhidmatan disediakan kepada individu bawah umur:
Dengan memberikan data peribadi kepada Syarikat, anda bersetuju terhadap pengumpulan, penggunaan, pendedahan, dan pemprosesan data peribadi tersebut bagi tujuan berkaitan dengan perkhidmatan dan operasi Syarikat.
Persetujuan Jelas bagi Data Peribadi Sensitif
Data Peribadi Sensitif termasuk maklumat kesihatan, penilaian kesihatan mental, maklumat biometrik, rekod perubatan, atau maklumat sensitif lain hanya akan diproses dengan persetujuan jelas atau sebagaimana dibenarkan oleh undang-undang.
Syarikat melaksanakan langkah keselamatan pentadbiran, teknikal, dan fizikal yang munasabah untuk melindungi data peribadi daripada akses tanpa kebenaran, pendedahan, penyalahgunaan, kehilangan, kemusnahan, pengubahan, dan ancaman keselamatan siber.
Akses kepada data peribadi adalah terhad kepada kakitangan yang diberi kuasa dan memerlukan akses tersebut bagi tujuan operasi atau perkhidmatan yang sah.
Sebarang pelanggaran data, akses tanpa kebenaran, kebocoran data, insiden keselamatan siber, akaun yang dikompromi, penyalahgunaan maklumat pesakit, atau pelanggaran Dasar ini hendaklah dilaporkan segera kepada Syarikat melalui saluran pelaporan yang ditetapkan.
Syarikat berhak menjalankan siasatan, menggantung akses, melaksanakan langkah pembendungan, memaklumkan pihak terjejas jika diperlukan, dan melaporkan insiden kepada pihak berkuasa kawal selia mengikut undang-undang yang terpakai.
Data peribadi akan disimpan hanya selama yang diperlukan bagi memenuhi tujuan pengumpulannya atau sebagaimana dikehendaki di bawah undang-undang, keperluan kawal selia, audit, atau operasi.
Selepas tamat tempoh penyimpanan yang berkaitan, data peribadi akan dipadam, dinyahpengenalan, atau dilupuskan dengan selamat.
Sekiranya data peribadi dipindahkan ke luar Malaysia, pemindahan tersebut akan dijalankan selaras dengan undang-undang Malaysia yang terpakai dan tertakluk kepada perlindungan yang sewajarnya.
Apabila berlaku penamatan, peletakan jawatan, tamat penglibatan, penggantungan, atau tamat tempoh akses:
Tertakluk kepada Akta Perlindungan Data Peribadi 2010, individu boleh:
Permintaan boleh dikemukakan secara bertulis kepada:
Emel: contact@ziloy.my
Syarikat boleh melaksanakan dasar dalaman, prosedur operasi standard (SOP), garis panduan pematuhan, prosedur keselamatan maklumat, keperluan onboarding, dan kawalan operasi dari semasa ke semasa bagi menyokong pematuhan terhadap Dasar ini dan undang-undang yang terpakai.
Semua kakitangan yang diberi kuasa hendaklah mematuhi keperluan dalaman tersebut.
Sebarang aduan berkaitan pemprosesan data peribadi boleh dikemukakan kepada Syarikat menggunakan maklumat hubungan yang dinyatakan di bawah.
Jika berkaitan, aduan juga boleh dikemukakan kepada Jabatan Perlindungan Data Peribadi (JPDP), Malaysia.
Dasar ini hendaklah ditadbir dan ditafsirkan menurut undang-undang Malaysia.
Syarikat berhak meminda atau mengemaskini Dasar ini dari semasa ke semasa.
Sebarang versi yang dikemaskini akan berkuat kuasa sebaik sahaja diterbitkan melalui laman web, platform, aplikasi, atau saluran komunikasi rasmi Syarikat.
The Company reserves the right to amend or update this Policy from time to time.
Any revised version shall take effect upon publication through the Company’s website, platform, application, or official communication channels.
Untuk sebarang pertanyaan berkaitan Dasar ini atau pemprosesan data peribadi, sila hubungi:
QuantumNexis Sdn Bhd
Unit B-09-06 Plaza Mont Kiara,
No. 2, Jalan Kiara,
Mont Kiara,
50480 Kuala Lumpur,
Malaysia
Emel: contact@ziloy.my
Laman Web: https://ziloy.my