Legal
Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains how HCASB handles information in connection with the pavehealth.app website and the PaveHealth Calendar Integration, the calendar integration used by its care-coordination team.
HCASB owns and operates PaveHealth. In this policy, “we”, “us” and “our” refer to HCASB as the operator of the pavehealth.app website and of the PaveHealth service.
Our registered address is Unit 28-02, Level 28 Q Sentral, Jalan Stesen Sentral 2, 50470 Kuala Lumpur, Malaysia.
Google Calendar Data We Access
The PaveHealth Calendar Integration connects to Google Calendar through the Google Calendar API using the https://www.googleapis.com/auth/calendar.events scope, under the Google Cloud project “HCASB Calendar Production”. This scope allows the integration to view and manage calendar events.
We use the integration to create, update and read calendar events that record a case reference and the scheduled date and time of coordination activities. Calendar events created by the integration do not contain patient names, contact details, diagnoses or any other medical information. The case reference is a non-clinical identifier used to match an event to an internal coordination record.
The integration is used by HCASB’s internal coordination team only. It is not offered to patients or specialists, and neither patients nor specialists are asked to authorise a Google account or grant access to their own Google Calendar. Access is limited to a single organiser account used by our own team.
How We Use Calendar Data
Calendar data accessed through the integration is used only to:
- Schedule and coordinate care-related activities for a case
- Keep internal scheduling records consistent between our tools
- Prevent double-booking and track scheduling changes
- Support routine operational reporting on coordination activity
We do not use Google Calendar data for advertising, and we do not sell it or use it to build advertising or profiling audiences.
How Calendar Data Is Stored
Calendar events are stored in Google Calendar under our own organiser account. Information derived from those events may also be stored in our internal coordination systems for scheduling and record-keeping.
Access credentials and API tokens are held server-side only. They are never exposed to browsers, patients or third parties.
How Calendar Data Is Shared
Calendar data is shared only:
- With Google, as the calendar service provider, in order to use the Google Calendar API
- With our own authorised team members and service providers who support hosting, scheduling and administration, and who are bound to protect it
- Where we are required to do so by law, or to establish, exercise or defend legal claims
We do not share Google Calendar data with advertisers, data brokers or any other third party for their own purposes.
Our Use of Google API Services
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide and improve the scheduling features described in this policy; it is not transferred to third parties except as necessary to provide those features, comply with applicable law, or as part of a merger or acquisition; it is not used for advertising; and it is not used to train generalised machine-learning models.
Revoking Access
Access to the linked calendar can be revoked at any time from the Google Account permission settings under “Third-party apps & services” (myaccount.google.com/permissions). Revoking access stops further calendar access. Because the integration is used only by our own team, revocation is managed internally.
Information Submitted Through This Website
The pavehealth.app website is an informational landing site for PaveHealth. It does not set cookies, and it does not run advertising or analytics tracking.
This website does not transmit enquiry forms. The enquiry form on the contact page is a display-only form: it is not connected to a server, nothing is sent when you press submit, and no information you type into it reaches us. You should therefore treat that form as unsubmitted and contact us using the channels below instead.
If you contact us — by email at [email protected], through the WhatsApp link on this site, or through the PaveHealth portal — we receive the information you choose to provide, which may include your name, contact details and details of your enquiry.
Please do not send medical records, identity documents, payment information or other sensitive information through a general website form or messaging channel unless we have asked you to use an approved secure method.
How We Use Enquiry Information
- To respond to your enquiry and coordinate the care pathway you ask about
- To operate, secure and improve the website
- To maintain appropriate administrative records
- To comply with applicable legal and regulatory requirements
Cookies and Local Storage
This website does not set cookies and does not run advertising or analytics tracking. It uses your browser’s local storage for one essential purpose only: remembering whether you chose the light or dark colour theme. That value is stored in your own browser, is not sent to us, and can be cleared at any time through your browser settings.
If we later introduce analytics, advertising or any other non-essential tracking, this policy and any required consent controls will be updated before those technologies are enabled.
Retention
Because this website does not transmit or store enquiry form data, there is no website form data to retain. The only information this website stores is your theme preference, which stays in your own browser until you clear it.
Calendar events and related coordination records are kept only for as long as reasonably necessary for scheduling, operational and record-keeping purposes, and to meet applicable legal and regulatory obligations. When they are no longer needed, they are deleted or anonymised. Correspondence you send us — by email, WhatsApp or through the PaveHealth portal — is kept for as long as needed to handle your enquiry and to meet our record-keeping obligations.
Security
We use reasonable administrative and technical safeguards intended to protect information, including keeping integration credentials server-side. However, no website, email or internet transmission can be guaranteed to be completely secure.
Your Choices and Rights
Subject to applicable law, you may ask to access, correct or delete personal information we hold about you, object to certain processing, or raise a concern about how it is handled. We may need to verify your identity before responding.
Children’s Information
This site is not directed at children. Parents or legal guardians should make enquiries on behalf of a child.
Changes to This Policy
We may update this policy when our features, operational practices or legal requirements change. The revised date will appear at the top of this page.
Contact Us
For privacy questions, including questions about Google Calendar data, contact HCASB at [email protected]. HCASB monitors this mailbox and routes privacy and policy enquiries internally.
You can also write to us at our registered address: Unit 28-02, Level 28 Q Sentral, Jalan Stesen Sentral 2, 50470 Kuala Lumpur, Malaysia.
This policy describes the calendar integration’s current behaviour. If the integration starts storing additional fields in calendar events, this policy must be updated before that change is made.
