Brigid Privacy Policy MY

Brigid Privacy Policy Malaysia

Updated on 21/07/2026.

The Phoenix Partnership (Leeds) Ltd (“TPP”) are committed to protecting and respecting your privacy. TPP provide the healthcare organisation you are employed by (“Your Organisation”) with the electronic healthcare record (EHR) software, SystmOne.

TPP (We) have developed Brigid (the “App”) to provide you and Your Organisation with the additional ability to access and contribute to electronic healthcare records directly from your smartphone or other personal device. To benefit from the App, Your Organisation must have entered into a customer agreement with us and granted you access credentials necessary to access the App and use the Services.

TPP is committed to protecting and respecting privacy.

To provide the App and associated services, we must process information about you and about the individuals you access within the App. Please read the following carefully to understand our practices regarding personal data and how we will treat it.

This policy (together with the Terms and Conditions and End User Licence Agreement for the App) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. By using the App you are accepting and consenting to this policy.

Please note, this policy relates to the data held in the App concerning you – the end user. The security and privacy of patient related data is addressed under separate fair processing and contractual arrangements for TPP and Your Organisation.  

1. How you may use the App

In return for agreeing to the below you may:

  • Log onto the App via your SystmOne username and password, or PIN, to use the App functionality.
  • Use any documentation to support your permitted use of the App functionality and the service.
  • Contact us with queries or log issues about the services. Please check the customer support model relevant to Your Organisation as these queries may need to be directed via first line support staff.
  • Receive and use any free updates of the App functionality and the service incorporating “patches” and corrections of errors as we may provide to you.

2. Collection of Personal information

The following information is used by us in order to provide the App and services:

Information you give us

You may provide us with information through your use of the App, including your Personal Data. This includes:

  • personal information – associated with access credentials used to access the App and associated software, SystmOne (such as your name, gender, date of birth, ID number and phone number/email address);
  • information in or about the content you provide (e.g. metadata), such as the date and time when information is added.

Information we collect about you:

We may collect information from your use of the App and our services, including:

  • Device and Connection information, such as the type of device, operating system, mobile network information and phone number; Connection information such as the name of your mobile operator or ISP, browser type, language and time zone, mobile phone number and IP address;
  • Usage Information and automatic activity tracking, such as how and when you use the service and what content and functionality you access;
  • Location information, including specific geographic locations, such as through GPS, Bluetooth, or WiFi signals, when location services settings are activated;
  • Information from partner apps and apps that use the App/services, such as information collected by us when you visit or use third-party apps and apps that use the App and/or our services;
  • Information about transactions made on the App. If you use the App for purchases or other financial transactions, we may collect information about the purchase or transaction.

3. Uses of Information we collect

We use the personal information that we collect for the following purposes:

  • To provide our services and to suggest products, including to personalise features and content, services or additional functionality that you may find helpful. In order to create an app and services that are relevant to you, we use:
    • Information on how you use and interact with the App and services;
    • Location-related information – such as your current location, and the locations, organisations and people you’re near (location-related information can be based on things such as precise device location (if you’ve allowed us to collect it), IP addresses and information from your use of the App).
  • To improve our services and to ensure that content is presented in the most effective manner for you and for your device. We use the information we have to send you communications and to respond to you when you contact us.
  • To allow you to participate in the interactive features of our services, when you or Your Organisation choose to do so.
  • To help us keep the App safe and secure. We use the information that we have to verify accounts and activity, combat harmful conduct, detect and prevent bad experiences, maintain the integrity of the App and services, and promote safety and security on and off the App. For example, we use data that we have to investigate suspicious activity or breaches the App Terms and Conditions or End User Licence Agreement.

We may also collect anonymised data in a form that does not allow identification of you for the following reason:

  • To monitor usage and collect usage statistics for product research and development including but not limited to how the App services are being used. We use the information to develop, test and improve the App and services, including by means of conducting surveys and research, and testing and troubleshooting for existing and new products and features.

4. How data is shared

The App enables you to view and update information controlled by Your Organisation. The information you enter into the App will be visible in the desktop software, (SystmOne) used by Your Organisation and within the patient’s electronic healthcare record once you press Save.

To allow another organisation that is not Your Organisation to see the data that you record on the App:

Your Organisation or the patient will need to consent to the data that you record being shared to that organisation from within SystmOne. The data will then become part of the shared care record.

The data recorded in Brigid will also be available within patient facing applications, subject to the sharing rules of your organisation.

Because of our responsibilities to you, we will only disclose or share your personal data in the following circumstances:

  • In accordance with our customer agreements with Your Organisation and the data processing provisions contained therein; or
  • If we have a legal obligation to do so; or
  • If it is necessary to comply with a request from a public or governmental organisation.

An example of a legal obligation would be if a court ordered us to disclose information; in a similar way the government can issue orders that require information to be shared.

If our ownership or control of all or part of our services transfers to a new owner, we may transfer your personal information to the new owner. If this happens, the new owner will be obligated to continue to treat such personal data on the terms set out in this Privacy Policy and inform you of their ownership.

5. Our legal basis for processing data

We act as data processor for data that you enter into the App.

We collect, use and share data that we have access to (as described above):

  • To fulfil our Customer Agreement
  • To fulfil our Terms of Use;
  • To comply with our legal obligations;
  • To protect your interest, or those of others;
  • As necessary in the public interest;
  • As necessary for our (or others’) legitimate interests, including our interests in providing an innovative, personalised, safe and profitable service to our users and partners, unless those interests are overridden by your interests or fundamental rights and freedoms that require protection of personal data.

6. Data Retention

We retain data until it is no longer necessary for the provision of the App or delivery of our services. Retention of Data will align to the provisions contained in the relevant Customer Agreement associated with your credentials.

7. Data Deletion Policy

Scope:

This policy applies to all personal data processed by TPP in its capacity as a data processor, including:

  • Electronic medical records;
  • Associated documents and attachments;
  • Metadata relating to records;
  • Audit logs and system-generated records;

Deletion Requests:

TPP shall act only on documented instructions from the relevant Data Controller unless otherwise required by law.

Upon receipt of a valid deletion instruction, TPP will:

  1. Verify the authority of the requesting Data Controller
  2. Identify the relevant records and associated data in scope (including whether data is being actively shared with other health and care organisations).
  3. Perform deletion of the data from active systems in line with ICO guidance.
  4. Record completion of the deletion process.
  5. Notify the Data Controller when deletion has been completed.

TPP will delete all in scope data, with the exclusion of data that is actively shared via TPP’s data sharing tools. This is data shared with other health and care organisations. Data shared in this way cannot be deleted as this forms part of the medical legal audit for other Data Controllers. 

Deletion:

Deletion shall be deemed complete when:

  • The personal data is removed from, or rendered inaccessible within, active production systems;
  • The personal data is no longer available to users, administrators, customers, or routine business processes;
  • The personal data cannot be retrieved through standard application functionality, reporting tools, searches, exports, or interfaces;
  • Any search indexes, caches, replicas, and derivative operational stores have been updated or purged within normal system maintenance cycles.

This will ensure that the deleted data is not readily accessible and is no longer processed for operational purposes, in line with ICO guidance.

Backup Systems:

Deleted data may remain within backup media, disaster recovery systems, archives, or other protected backup environments for the duration of applicable backup retention periods.

Where deleted data remains in backup systems:

  • The backup copies shall not be used to restore deleted records except where necessary for disaster recovery, system recovery, legal compliance, or other legitimate operational purposes;
  • Any restored backup containing previously deleted data shall be subject to reapplication of deletion controls as soon as reasonably practicable;
  • Backup systems shall be subject to appropriate technical and organisational security measures;
  • Backup copies shall expire and be overwritten in accordance with established backup retention schedules.

TPP does not undertake to selectively remove individual records from backup media where doing so would be technically impracticable or would compromise the integrity, security, or reliability of backup systems.

Medico-Legal Audit Trail:

Notwithstanding any deletion request, TPP may retain a limited medico-legal audit trail where necessary to:

  • Demonstrate compliance with legal and regulatory obligations;
  • Establish, exercise, or defend legal claims;
  • Preserve evidence concerning the existence and management of medical records;
  • Maintain system integrity and accountability.

The medico-legal audit trail shall, to the extent reasonably practicable, contain only the minimum information necessary to fulfil these purposes.

The audit trail shall not be available through ordinary application functionality and shall be subject to enhanced access controls.

Access to Audit Trail Information:

Access to retained medico-legal audit trail information shall be strictly restricted to authorised personnel with a legitimate need to know.

Audit trail information shall only be disclosed:

  • Where required by applicable law;
  • Pursuant to a valid court order;
  • In connection with legal proceedings;
  • In line with ICO and other regulatory guidance;
  • To regulatory authorities possessing lawful authority to require disclosure.

All access to retained audit trail information shall itself be logged and auditable.

Security Controls:

Deleted data, retained backup copies, and medico-legal audit trail information shall be protected through appropriate technical and organisational measures, including:

  • Role-based access controls;
  • Encryption where appropriate;
  • Audit logging;
  • Restricted administrative access;
  • Periodic review of access permissions.

Compliance and Review:

This policy shall be reviewed periodically and updated as necessary to reflect legal, regulatory, operational, and technological developments.

All personnel responsible for processing deletion requests shall be trained on the requirements of this policy.

8. Information security and preventing harm

We make it a priority to provide strong security and give you confidence that the information contained and entered within the App is safe and accessible when you need it. The App is built with strong security features that continuously protect your information. We use strict procedures and employ strict security features in accordance with industry best practice and standards. We take all steps reasonably necessary to ensure that we treat your data securely and in accordance with this Privacy Policy.

We restrict access to personal information strictly to TPP employees, contractors, and agents who need access in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.

In addition to this, it is your responsibility to ensure your computer or device, and your connection to the service, is secure. Use of the App and our services is at your own risk. Although we will do our best to protect personal data, we cannot guarantee the security of the data transmitted to us via any device on which you may access the App.

9. Changes to this policy

We may need to change this Privacy Policy to reflect changes in law or best practice, to deal with additional features or changes to features that we introduce or to apply other updates.

When any updates are made to this Privacy Policy, we will notify you when you next start the App. If you do not accept the notified changes, you may not be permitted to continue to use the App.

If you continue to use the App following notice of the changes to the Privacy Policy, it constitutes your acceptance of the updates.

10. How we operate and transfer data as part of our global services

We share information internally within TPP, externally with our partners and with selected organisations for research purposes (subject to you providing consent to do so) and with those you connect and share with around the world in accordance with this Privacy Policy. Information will be transferred or transmitted to, or stored and processed in Malaysia and the United Kingdom or other countries outside where you live for the purposes as described in this Policy but always securely and in accordance with data protection law.

11. How to contact TPP with questions

If you have general questions or comments about the App, you can email us at: AppEnquiries@tpp-uk.com

If you have questions about this Privacy Policy, you can contact TPP’s Data Protection Officer at: dpo@tpp-uk.com