Privacy Policy
Last updated: [date]
This policy explains what personal data DolveCRM collects on behalf of the clinics, salons, spas, firms and studios that use it ("our clients"), and how that data is handled. If you're a patient, client or member messaging one of our clients on WhatsApp, this policy covers how your enquiry, booking and feedback data is processed.
1. Who this applies to
DolveCRM is a customer recovery system used by businesses (dental clinics, salons, spas, law and financial advisory firms, gyms and enrichment centres) to manage bookings, reminders, feedback and follow-up over WhatsApp. Our client is the business you're messaging; we process data on their behalf as their service provider.
2. Information we collect
- Contact details: name and phone number, as provided when you message or book
- Booking details: date, time, doctor/staff assigned, and the reason for visit you select or provide
- Message content: messages sent through WhatsApp to the business, and the automated replies sent back
- Booking notes: optional notes you add at booking time (for example, a specific request worth flagging to staff)
- Feedback: ratings and comments submitted after a visit or session
We don't collect payment card details, government ID numbers, or health records beyond what you choose to type into a booking note.
3. How we use your information
- To confirm, remind, and reschedule your appointment
- To follow up if you enquired but didn't book, or missed a visit, so the business can offer to help you rebook
- To route your feedback to staff, especially if you report a problem, so someone can respond
- To give staff a single, searchable record of your visit history at that business
We do not sell, rent, or trade your data, and we do not use it for advertising.
4. How we share your information
Messages are sent and received through the WhatsApp Business Platform, operated by Meta. Meta processes message content as part of delivering it, under its own terms. Beyond what's needed to operate WhatsApp messaging and hosting, we don't share your data with any other third party, and we don't sell it to anyone.
5. Where your data is stored
Data is stored on infrastructure located in Malaysia, in line with the Personal Data Protection Act 2010 (PDPA). It is not transferred outside Malaysia.
6. Data retention
We keep your data for as long as you remain a client of the business you're dealing with, plus a reasonable period afterward for record-keeping, or as required by law. A rejected or cancelled booking is kept temporarily (currently 7 days) before being permanently removed, so a mistaken rejection can still be reversed.
7. Security measures
Access to your data is restricted to authorised staff at the business you're dealing with, protected by encryption, access controls, and audit logging of who accessed what. If a security incident affects your data, we'll notify the affected business so they can inform you, in line with our obligations under the PDPA.
8. Your rights under PDPA
- Ask what data we hold about you
- Ask us to correct inaccurate data
- Withdraw consent to being contacted, by telling the business directly or messaging "stop"
- Ask for your data to be deleted, subject to any legal retention requirements
To exercise any of these, contact the business you're dealing with directly, or reach us at [email protected].
9. Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
10. Contact
[Company legal name]
[Registered address]
[email protected]