1. Our approach
Easy Claim recognises that medical, claims and identity information can be sensitive. We aim to handle personal data consistently with Malaysia's Personal Data Protection Act 2010, as amended, applicable regulatory requirements, contractual commitments and documented client instructions.
This page describes our general approach. It is not a technical security specification, certification, service-level commitment or replacement for the terms governing a specific client engagement.
2. Data-handling principles
Our controls and procedures are guided by the following principles:
- Purpose limitation: use information for defined, authorised and lawful purposes.
- Data minimisation: request and retain only information reasonably needed for the relevant task.
- Accuracy: support appropriate correction and validation of information used in workflows.
- Access control: restrict information to authorised personnel and service providers with a legitimate need.
- Retention control: retain information only for justified business, contractual and legal periods.
- Accountability: assign responsibilities and maintain appropriate records for sensitive processing.
3. Organisational safeguards
Depending on the service, risk and client requirements, safeguards may include:
- confidentiality obligations and role-based access procedures;
- staff awareness and appropriate handling instructions;
- supplier assessment and contractual data-protection requirements;
- documented retention, deletion and incident-management procedures;
- review of material changes to systems or processing activities; and
- escalation and response processes for suspected personal-data incidents.
4. Technical safeguards
Technical measures are selected according to the system and risk. They may include encrypted network transport, authentication, access restrictions, logging, backups, environment separation, vulnerability management and protective monitoring. Specific client controls are confirmed through the relevant agreement or security documentation.
To reduce avoidable exposure, sensitive case files should be exchanged only through channels approved for the relevant engagement, not through public website forms or unsolicited ordinary email.
5. Service providers and cross-border processing
We may use vetted service providers to support hosting, communications, security and business operations. Access is limited to the service being provided and is subject to appropriate contractual and operational controls. Where information is processed outside Malaysia, we take steps required by applicable law and the relevant client arrangements.
6. Incident response
Suspected data incidents are assessed, contained, investigated and documented according to their nature and risk. Where required, Easy Claim will coordinate notifications to affected clients, individuals or authorities within applicable legal and contractual timeframes.
7. Individual rights and enquiries
Information about individual privacy rights and website-related personal data is provided in our Privacy Policy. Questions about data protection, security due diligence or a suspected privacy issue may be sent to enquiries@easyclaim.tech.
