Data Protection

Commitment to Data Protection

How PĒRL collects, uses, and safeguards your personal data under the Singapore Personal Data Protection Act 2012 (PDPA).

The Personal Data Protection Act 2012 (PDPA) governs the collection, use, and disclosure of personal data. As a foundational data infrastructure provider for the private healthcare sector, PĒRL takes its compliance obligations and the protection of your personal data strictly. We ensure the security and integrity of your information by:

  • Restricting access strictly to authorised clinic partners, healthcare professionals, and internal personnel on a need-to-know basis to facilitate administrative routing and care delivery.
  • Implementing rigorous technical and organisational measures, including AES-256 end-to-end encryption for qualitative and biometric data, to protect against unauthorised access or data breaches.
  • Anonymising personal data to the fullest extent possible when aggregating marketplace data to develop shared market intelligence and capacity optimisation metrics.

Data Processing for Platform and Healthcare Facilitation

When you utilise our platform to secure medical appointments, we disclose your scheduling intent and basic identifiers to our network of participating clinics strictly for the purpose of facilitating your care. Subject to your explicit, tiered consent, we may further process your personal data to recommend preventive care schedules, grant access to wellness marketplaces, and match your availability with off-peak clinic capacities.

In our capacity as a data layer for the private healthcare sector, we aggregate and irreversibly anonymise data to participate in broader industry efforts. These efforts include:

  • Assessing structural capacity constraints and optimising off-peak yield management for participating healthcare providers.
  • Providing aggregated, non-identifiable metrics to insurance providers to assist in the benchmarking of facility fees and the structuring of premium plans.
  • Conducting statistical anomaly detection to ensure billing accuracy and mitigate operational discrepancies.
  • Collaborating with community organisations, including Active Ageing Centres, to support hyper-local patient onboarding and logistical coordination.

We guarantee that any collection, use, or disclosure of your personal data for the aforementioned purposes is executed in strict adherence to the PDPA. Please note that our partner clinics retain the role of primary data controllers regarding your clinical and medical records. These institutions are independently bound by the Healthcare Services Act and are responsible for statutory obligations, including synchronisation with the National Electronic Health Record (NEHR) system.

To facilitate the continual improvement of our technological infrastructure, your personal data may be processed within the PĒRL ecosystem for internal quality assurance, the refinement of our proprietary artificial intelligence models (Whisk), and the general enhancement of our service offerings.

Full Data Protection Policy

Read the complete PĒRL Data Protection Policy, including tiered consent, proxy access, cross-border transfers, and retention. Last updated 22 June 2026.

Download PDF