Privacy Policy
Overview
Vincere Aesthetics Clinic (“Vincere”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”) and applicable Ministry of Health (MOH) guidelines for licensed medical practices.
This Privacy Policy explains what personal data we collect from you, how we use and protect it, and the rights you have in relation to that data. It applies to visitors of our website (www.vincereclinic.com.sg) and to patients of our clinic.
By using our website, contacting us via WhatsApp, telephone, or email, or attending our clinic, you acknowledge that you have read and understood this Policy.
Information we collect
We collect personal data only to the extent necessary for legitimate medical, clinical, and business purposes. The categories of data we may collect include:
- Contact details — name, telephone number, email address, and preferred method of communication.
- Identification details — date of birth, NRIC/FIN (where required for medical record keeping), gender, and nationality.
- Medical and health information — medical history, allergies, current medications, previous aesthetic treatments, relevant skin or facial conditions, and treatment preferences.
- Treatment records — consultation notes, assessment findings, treatment plans, procedures performed, products used, and follow-up outcomes.
- Clinical photographs — where you have provided explicit consent, before-and-after photographs taken during consultation or treatment for clinical documentation.
- Payment information — billing address and payment method details (handled via secured payment providers; we do not store full credit card numbers).
- Communications with us — records of messages sent via WhatsApp, email, telephone, or our website.
- Website usage data — technical information such as browser type, device, and pages visited (see Section 9 on Cookies).
How we use your information
We use your personal data for the following purposes:
- Providing medical consultations, assessments, and aesthetic treatments.
- Maintaining your medical records as required by MOH guidelines.
- Scheduling, confirming, and reminding you of appointments.
- Communicating with you regarding your treatment, follow-up care, or responses to your inquiries.
- Managing clinical safety, including monitoring adverse reactions and treatment outcomes.
- Processing payments and managing billing records.
- Complying with legal, regulatory, or medical professional obligations.
- Sending you marketing or service information about Vincere — only where you have opted in (see Section 8).
- Improving our services, website, and patient experience.
We will not use your personal data for purposes unrelated to those listed above without seeking your consent.
Sharing and disclosure
We treat your personal data as confidential. We do not sell, trade, or rent your personal information to third parties. We may share your personal data only in the following limited circumstances:
- With healthcare professionals involved in your care, where a medical referral is made or a specialist consultation is required, with your consent.
- With service providers who assist us in operating our clinic or website (for example, appointment scheduling platforms, IT service providers, or payment processors). Such providers are bound by confidentiality obligations and may only process your data for the purposes we authorise.
- Where required or permitted by law, regulation, court order, or governmental authority — including in response to requests from the Ministry of Health, the Singapore Medical Council, or other regulatory bodies.
- In the event of a sale, merger, or restructuring of our clinic, where we ensure your data remains protected under equivalent privacy standards.
Storage and security
We take reasonable and appropriate measures to protect your personal data from unauthorised access, disclosure, alteration, or loss. These measures include secure electronic medical record systems, restricted staff access on a need-to-know basis, encrypted digital transmission where applicable, and physical security controls for paper records kept at the clinic.
Notwithstanding our efforts, no method of electronic transmission or storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately using the details in Section 12.
Data retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, and to comply with legal and professional obligations:
- Medical records are retained for the minimum periods required under MOH guidelines — generally six (6) years from the date of your last consultation for adult patients, or until the patient reaches the age of 25 (whichever is longer) for patients who were minors at the time of treatment.
- Financial and billing records are retained for seven (7) years as required under the Singapore Income Tax Act.
- Marketing and communication data is retained until you withdraw consent or request deletion.
- Website usage data (analytics) is retained in aggregated form and does not personally identify you after the retention periods of the relevant analytics providers.
After the applicable retention period, your personal data will be securely deleted or anonymised.
Your rights under PDPA
Under the Singapore Personal Data Protection Act, you have the following rights in relation to your personal data:
- Right to access — you may request a copy of the personal data we hold about you, and information about how it has been used and disclosed in the past year.
- Right to correction — you may request corrections to any personal data that is inaccurate or incomplete.
- Right to withdraw consent — you may withdraw your consent to our use of your personal data for specific purposes (such as marketing communications) at any time. We may be required to retain certain medical records even after consent is withdrawn, in accordance with legal or professional obligations.
- Right to data portability — where applicable, you may request that certain of your personal data be transferred to another service provider.
To exercise any of these rights, please contact us using the details in Section 12. We will respond to your request within 30 days. A reasonable administrative fee may apply to access requests, as permitted under PDPA.
Marketing communications
We will only send you marketing communications — such as treatment updates, educational content, or clinic announcements — where you have opted in to receive them. You may opt out at any time by replying “STOP” to a WhatsApp message, clicking the unsubscribe link in any email, or contacting us directly.
Service communications — such as appointment confirmations, reminders, follow-up messages about a treatment you have received, and responses to your enquiries — are not considered marketing and will continue as part of our clinical service to you.
Cookies and analytics
Our website uses cookies and similar technologies to improve your browsing experience and to help us understand how visitors use the site. Cookies are small files placed on your device that enable functionality such as remembering your language preference.
We may use third-party analytics providers (such as Google Analytics) to collect aggregated, non-personally-identifiable information about website usage — including pages visited, time spent, and general geographic region. This helps us improve site content and usability.
You can control or disable cookies through your browser settings. Disabling cookies may affect the functionality of some parts of the website.
Minors
Our services are intended for individuals aged 18 and above. Where a minor seeks consultation or treatment, parental or guardian consent is required, and we handle their information with additional care under PDPA and MOH guidelines.
We do not knowingly collect personal data from minors through our website. If you believe we have, please get in touch so we can remove it.
Policy updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. The effective date at the top of this page indicates when it was last updated.
Material changes will be communicated to you where required by law — for example, by email (if you have opted in) or by prominent notice on our website. Your continued use of our services following an update constitutes acceptance of the revised Policy.
Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact our Data Protection Officer:
111 Somerset Road, #03-20, TripleOne Somerset
Singapore 238164
+65 8238 0700
wecare@vincereclinic.com.sg
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.