Privacy-first handling of retiree wellness data by WellHubAge. Policy last reviewed 05-02-2026. Updates applied to reflect operational and legal changes.

General Privacy Information

At WellHubAge we respect the privacy of retirees and their families. This policy explains what data we collect, why we collect it, how we use it, and the choices available to you. We design our services to support healthier, more independent retirement living while minimizing data collection to what is necessary for service delivery. Our approach focuses on clarity, security, and practical control for users.

05-02-2026
WellHubAge
168, Jalan Raja Permaisuri Bainun, 30250 Ipoh, Perak, Malaysia
01

Key definitions

This section defines terms used throughout the policy to help you understand how we process personal data in connection with WellHubAge services for retirees.

Personal data means any information that can identify an individual directly or indirectly, such as name, contact details, health-related preferences, or device identifiers when linked to a person.
Processing includes any operation performed on personal data, such as collection, storage, use, disclosure, deletion, or transfer necessary to deliver our wellness services.
User refers to a retiree, family member, caregiver, or authorised representative using WellHubAge services or interacting with our platform and communications.
Service refers to the wellness care, educational content, scheduling, assessments, and support features provided by WellHubAge to help retirees manage health and wellbeing.
Cookies are small text files placed on a device to recognise returning users, remember preferences, and help improve the online experience and basic analytics used to optimise our services.
02

Data collection

We collect only the information necessary to provide, personalise, and improve retirement wellness services. Collection is limited to practical details that support safe and effective care and communication.

03

Data you provide

When you sign up or interact with WellHubAge, you may provide personal details to set up an account, access services, or receive support. These details enable appointments, tailored recommendations, and secure communication.

  • Identity details: full name, date of birth, and preferred contact name for correspondence.
  • Contact details: residential address (e.g., 168, Jalan Raja Permaisuri Bainun, 30250 Ipoh, Perak, Malaysia), email address, and telephone number for scheduling and updates.
  • Basic health and wellness information you provide to personalise services: medical conditions, medications, mobility notes, dietary preferences and activity levels.
  • Account and authentication data such as chosen username, password hashes, and device identifiers necessary to secure access.
  • Payment and billing details where applicable for paid wellbeing plans and transparent invoicing.
  • Communications you send to us, including feedback, support requests, and preferences for service delivery.
04

Data collected automatically

Some information is collected automatically to improve the website and services, and to ensure secure and reliable delivery.

  • Usage data: pages visited, session duration, and service features used to optimise content and user flows.
  • Device and browser information used for compatibility and troubleshooting.
  • Location data inferred from IP addresses to provide region-appropriate content and local support options.
  • Performance data and error logs to detect and resolve technical issues in the platform.
  • Basic analytics cookies that help measure which resources and features deliver most value to retirees.
  • Security-related signals such as unusual login activity to protect accounts from unauthorised access.
05

Third-party data sources

We may receive data from trusted partners and third-party services to improve and support the delivery of wellness services and to keep records accurate.

  • Healthcare professionals or care coordinators who provide relevant clinical or care-related information with your consent.
  • Payment processors and business services for billing and transaction validation.
  • Trusted analytics and hosting providers that help us maintain and improve the platform and security.
06

How we use personal data

We use personal data only for specific, limited purposes that benefit users and enable the service to operate reliably and safely.

  • To register and manage user accounts, verify identity, and provide access to personalized wellness features.
  • To coordinate appointments, reminders, and communications that help retirees follow care plans and community programs.
  • To personalise content and recommendations based on health profiles and preferences while avoiding intrusive profiling.
  • To process payments, invoices, and receipts related to subscription or paid wellness packages.
  • To maintain platform security, detect fraud, and protect user accounts and data integrity.
  • To analyse service usage and improve features, content, and accessibility for retiree users.
  • To respond to support requests and manage communications including updates about service changes.
  • To meet legal and regulatory obligations as required under applicable Malaysian law.
07

Legal bases for processing

We rely on appropriate legal bases for processing personal data, including consent, contractual necessity, legitimate interests, and compliance with legal obligations where applicable.

  • Performance of a contract: processing needed to provide and manage your subscription or service agreement with WellHubAge.
  • Consent: where you have given clear consent for specific processing activities, such as marketing emails or sharing with third-party care providers.
  • Legitimate interests: for improving services, preventing fraud, and maintaining platform security while balancing user rights.
  • Legal obligations: to comply with applicable reporting or regulatory requirements in Malaysia.
08

Cookies and tracking

Cookies and similar technologies are used on our website to support core functionality, remember preferences, and deliver basic analytics. You can manage cookie preferences through your browser or our cookie controls.

Types of cookies we use include essential cookies for site operation, preference cookies to remember settings, performance cookies for analytics, and security cookies for protecting accounts.

Essential: required for login and secure sessions. Functional: save language and accessibility settings. Analytical: measure feature usage to improve experiences. Security: detect suspicious activity.

You can manage or disable cookies through your browser settings. Disabling some cookies may reduce functionality or affect personalized features. We provide a consent control on first visit to record your preferences.

Read our full cookie policy for detailed controls and examples.

09

Sharing and disclosure

We only share data when necessary to deliver services, to comply with legal obligations, or with your informed consent. Third-party recipients are carefully selected and bound by data protection requirements.

  • Service partners that support appointment scheduling, care coordination, and delivery of paid services.
  • Payment processors for handling transactions and invoicing.
  • Cloud hosting and analytics providers that help maintain and improve WellHubAge platform performance and reliability.
  • Legal or regulatory authorities when required by law or to respond to lawful requests.
  • Healthcare providers and emergency services when disclosure is necessary for your immediate care and you have authorised the sharing.
  • Acquirers or advisors in the event of a corporate reorganisation or sale, subject to confidentiality protections and user notice.
10

International transfers

WellHubAge may transfer personal data to service providers located outside Malaysia where necessary to operate the platform. Transfers are limited and subject to safeguards to protect your privacy.

When transferring data internationally we use contractual safeguards, careful vendor selection, and, where available, approved transfer mechanisms to ensure appropriate protection of personal information.

11

Data retention

We retain personal data only as long as necessary for the purposes described, to meet legal obligations, or to resolve disputes. Retention periods are determined based on the type of data and operational needs.

Account information is retained while your account is active and for a reasonable period after account closure to meet recordkeeping and legal requirements.

Communications and support messages are kept for the duration necessary to address inquiries and to maintain a record of service interactions.

System and security logs are retained for limited periods to contribute incidents and maintain platform stability.

When data is no longer required, we securely delete or anonymise it. You can request deletion subject to applicable legal and operational exceptions.

12

Security of data

We apply administrative, technical, and physical measures to protect personal data, including encryption in transit, access controls, and regular security reviews. Our focus is on practical protections to reduce risk for retiree users.

  • Encrypted transmission of sensitive data and secure storage of credentials.
  • Role-based access control and routine access reviews for staff and vendors.
  • Regular backups, incident response planning, and vulnerability scanning to detect and address risks.
13

Your rights

You have rights regarding your personal data. Where applicable, you can access, correct, export, restrict processing, withdraw consent, or request deletion of your data. Requests are handled in a timely and transparent manner.

  • Right to access: request a copy of personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete information.
  • Right to erasure: request deletion of personal data where there is no overriding legal reason to retain it.
  • Right to restrict processing: ask us to limit how we use your data in certain situations.
  • Right to data portability: request a structured, machine-readable copy of data for transfer to another provider where technically feasible.
  • Right to object: object to processing based on legitimate interests or direct marketing in certain contexts.
  • Right to withdraw consent: where processing is based on consent, you can withdraw it without affecting processing prior to withdrawal.
  • Right to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
14

GDPR and applicable rights

Although WellHubAge operates in Malaysia, we recognise international data protection standards. This section explains core rights and protections consistent with GDPR principles for users who may be covered.

GDPR-like rights may apply to individuals in certain circumstances. We adopt practices that respect these rights and provide mechanisms to exercise them promptly.

  • Transparency: clear information about processing activities and access to records when applicable.
  • Data subject rights: accessible processes for access, correction, deletion, and export of personal data.
  • You have the right to restrict processing of your personal data in specific circumstances, for example when you contest the accuracy of data or object to processing for direct marketing purposes. WellHubAge will review and respond to such requests in accordance with applicable law and documented verification procedures.
  • You may object to processing based on our legitimate interests, and you can withdraw consent to marketing communications at any time. WellHubAge will assess objections and, where required by law, stop the processing or inform you of any compelling legitimate grounds for continuing.

If you wish to make a complaint about our handling of your personal data, please contact our Data Protection Officer at the address below. We aim to resolve complaints promptly and fairly. You may also lodge a complaint with Malaysia's Personal Data Protection Department if you believe your rights under Malaysian data protection laws have been violated.

15

Your Privacy Rights

WellHubAge recognises your rights to access, correct, erase, restrict, port, and object to processing of your personal data. To make a rights request, please provide enough information to identify yourself and the data involved. We may require verification to protect your privacy and prevent unauthorized disclosures.

[email protected]

We aim to acknowledge rights requests within 7 business days and provide a substantive response within 30 days. If we need more time due to complexity, we will notify you and explain the extension.

16

Marketing Communications

We may send promotional emails, newsletters, and targeted offers about wellness programs, community activities, and retiree services that align with your interests. Marketing messages are sent only to those who have opted in, unless local law permits otherwise. Communications will include clear options to manage preferences or opt out.

To stop receiving marketing messages, use the unsubscribe link in any email or contact us. Unsubscribe requests are processed promptly; you may still receive transactional or service messages necessary to manage your account or bookings.

17

Children's Privacy

WellHubAge is intended for adults and retirees. We do not knowingly collect personal data from individuals under 18. If we learn that we have received information from a minor, we will take steps to delete it. If you believe we have collected data from a child, contact us to request removal.

18

Links to Third Party Sites

Our website may contain links to third-party websites, tools, and service providers. WellHubAge is not responsible for the privacy practices or content of those sites. We recommend reviewing the privacy policies of any third parties before providing personal data.

19

Changes to This Policy

We may update our privacy policy to reflect changes in law, service offerings, or data practices. Material changes will be communicated via our website or direct notice to affected users. Continued use of WellHubAge services after updates constitutes acceptance of the revised policy.

Contact information

For privacy questions or rights requests contact: WellHubAge, 168, Jalan Raja Permaisuri Bainun, 30250 Ipoh, Perak, Malaysia. Email: [email protected]. Business ID: 430880914527.

+60121129952

[email protected]

168, Jalan Raja Permaisuri Bainun, 30250 Ipoh, Perak, Malaysia