Privacy Policy
Last Updated: January 15, 2026
1. Introduction
At Willowoi, we are committed to protecting the privacy and personal information of our residents, their families, and website visitors. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with Malaysian privacy laws, including the Personal Data Protection Act 2010 (PDPA).
We understand that choosing senior housing arrangements involves sharing sensitive personal information, and we take our responsibility to protect that information seriously. This policy applies to all personal data we collect through our website, during facility visits, through forms and applications, and in the course of providing our services.
2. Information We Collect
We collect different types of information depending on your interaction with us:
Personal Identification Information
- Name, identification numbers (IC/passport)
- Contact details (address, phone number, email)
- Emergency contact information
- Date of birth and age
Health and Care Information
- Medical history and current health conditions
- Medication information
- Dietary requirements and restrictions
- Mobility and functional status
- Healthcare provider information
Financial Information
- Payment information for services
- Bank account details for direct debit (with consent)
- Insurance information if applicable
Website Usage Information
- IP address and browser type
- Pages visited and time spent
- Cookies and similar technologies (see our Cookie Policy)
- Form submissions and inquiries
3. How We Use Your Information
We use personal information for the following purposes:
- Providing residence services and daily care support
- Coordinating with healthcare providers and family members
- Processing payments and maintaining financial records
- Communicating about services, schedules, and updates
- Ensuring resident safety and wellbeing
- Responding to inquiries and scheduling facility tours
- Improving our services based on feedback and needs
- Complying with legal and regulatory requirements
- Maintaining records for operational and legal purposes
4. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary to fulfill our service agreement with you
- Legal Obligation: We need to process data to comply with Malaysian laws and regulations
- Legitimate Interest: Processing is necessary for our legitimate business interests, such as improving services and ensuring resident safety
5. Information Sharing and Disclosure
We do not sell or rent personal information to third parties. We may share information with:
Authorized Family Members
With resident consent, we share relevant information with designated family members or representatives to keep them informed about care and wellbeing.
Healthcare Providers
We coordinate with doctors, therapists, and other healthcare professionals involved in a resident's care, sharing only information necessary for proper treatment.
Service Providers
Third parties who help us operate our facility (such as food suppliers, maintenance services, or IT support) may access limited information necessary to provide their services. These providers are contractually bound to protect data confidentiality.
Legal Requirements
We may disclose information when required by law, court order, or government request, or when necessary to protect safety and rights.
6. Data Security
We implement appropriate technical and organizational measures to protect personal data:
- Secure storage of physical records in locked facilities
- Electronic data encryption and password protection
- Restricted access to personal information (only authorized staff)
- Regular security assessments and updates
- Staff training on data protection responsibilities
- Confidentiality agreements with employees and contractors
While we strive to protect personal data, no security system is completely impenetrable. We encourage you to also take steps to protect your information, such as keeping login credentials confidential.
7. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy and to comply with legal obligations:
- Active resident records: Duration of residence plus 7 years
- Financial records: 7 years as required by Malaysian law
- Health information: 7 years following last service
- General inquiries: 2 years from last contact
- Website analytics: 26 months
After these periods, we securely delete or anonymize personal data unless longer retention is required by law or necessary for legal proceedings.
8. Your Rights
Under Malaysian data protection law, you have the following rights:
- Right to Access: Request copies of your personal data we hold
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Withdraw Consent: Withdraw consent for data processing (where consent is the legal basis)
- Right to Data Portability: Request transfer of your data to another service provider
- Right to Limit Processing: Request restriction of how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Complaint: Lodge a complaint with the Personal Data Protection Commissioner
To exercise these rights, please contact us using the information provided at the end of this policy. We will respond to requests within 21 days as required by Malaysian law.
9. Cookies and Website Technologies
Our website uses cookies and similar technologies to enhance user experience and understand how visitors use our site. For detailed information about our cookie practices, please see our separate Cookie Policy.
10. Third-Party Links
Our website may contain links to external websites operated by third parties. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any website you visit.
11. Children's Privacy
Our services are designed for seniors aged 60 and above. We do not knowingly collect personal information from individuals under 18 years of age. If you believe we have inadvertently collected such information, please contact us so we can delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will post the revised policy on our website with an updated "Last Updated" date. Significant changes will be communicated to residents and their families through our regular communication channels. Continued use of our services after policy changes indicates acceptance of the updated terms.
13. Contact Information
If you have questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle personal information, please contact us:
Willowoi
Jalan Ipoh 234
51200 Kuala Lumpur
Wilayah Persekutuan, Malaysia
Email: [email protected]
Phone: +60 3 4051 9267