DRMed Clinic and Laboratory

Legal

Data Privacy Notice

How DRMed Clinic and Laboratory handles your personal data under the Philippine Data Privacy Act of 2012 (RA 10173).

Last updated: July 26, 2026

This notice explains how DRMed Clinic and Laboratory collects, uses, stores, and protects personal data in compliance with the Data Privacy Act of 2012 (RA 10173) and applicable NPC issuances.

1. Personal Information Controller

DRMed Clinic and Laboratory
4/F DRMed Clinic and Laboratory, Northridge Plaza, Congressional Avenue, Quezon City
Mobile: 0916 604 3208
Telephone: (02) 8 355 3517

2. Personal Data We Process

  • Patient identification details (for example: name, DRM-ID, and portal login details).
  • Laboratory transaction information (for example: test names, dates, status, and released reports).
  • Security metadata (for example: timestamp, hashed IP and hashed user-agent for consent and access logging).
  • Public-website activity (for example: pages viewed, whether a booking or inquiry form was completed, and the advertising campaign you arrived from). Collected on our public pages only — never in the Patient Portal or Staff Portal. See Section 6.

3. Purpose of Processing

  • Verify patient identity for secure release of test results.
  • Provide laboratory report access and test status tracking.
  • Maintain service security, fraud prevention, and audit trail records.
  • Comply with legal, regulatory, and medical record obligations.
  • Measure how our public website and advertising perform, so we can improve them. This uses website-activity data only — never your health information. See Section 6.

4. Legal Basis

Processing is based on consent, fulfillment of healthcare service obligations, legitimate interests in securing systems, and compliance with legal obligations under Philippine law.

5. Data Sharing

Data may be processed by authorized service providers used for operations (such as secured cloud hosting, document storage, and anti-bot protection) under confidentiality and data protection controls. Data is not sold to third parties.

We also use the advertising and analytics providers described in Section 6. These providers receive only website-activity data — they are never given your medical records, laboratory results, DRM-ID, or any other health information.

6. Cookies, Analytics and Advertising

Our public website only uses cookies and measurement tools to understand how visitors find us and to measure the effectiveness of our advertising. These tools are never active inside the Patient Portal or the Staff Portal, and they never have access to laboratory results, medical records, or any health information.

What we use

  • Website analytics — aggregated page-visit statistics that tell us which pages are useful, without identifying you personally.
  • Meta (Facebook) Pixel and Conversions API — used only on our public pages to measure the results of our Facebook and Instagram advertising. It records that an action happened (for example: a page was viewed, a booking form was completed, or a phone number was tapped) together with a randomly generated reference used solely to avoid counting the same action twice.
  • Campaign reference cookie — if you arrive from an advertisement, we store the campaign name in a first-party cookie for up to 30 days so we can tell which campaign led to an inquiry.

What is never shared

  • We do not send your name, DRM-ID, contact details, chosen tests, medical conditions, or results to any advertising platform.
  • We do not use these tools to build health-related advertising audiences, and we do not advertise based on any condition or test a person may be interested in.
  • We do not sell personal data.

Your choices

We ask before any of this is switched on. On your first visit we show a short banner, and the measurement tools described above stay completely off — no Meta Pixel, no campaign cookie — unless you press Accept. If you press Decline, or simply ignore the banner, nothing is loaded and nothing is sent.

You can change your mind at any time using the Cookie preferences link at the bottom of any page. Choosing Decline also deletes any measurement cookies already stored on your device. You can additionally block or delete cookies through your browser settings.

Booking, registration, and portal access work exactly the same whichever you choose — we never restrict access to care or to your results based on this decision. You may also object to this processing by contacting us using the details in Section 12.

7. Retention

Data is retained only as long as necessary for medical, legal, and operational purposes, and disposed of securely based on DRMed retention schedules and legal requirements.

8. Your Rights as Data Subject

  • Right to be informed
  • Right to access
  • Right to object
  • Right to rectification
  • Right to erasure or blocking, when legally applicable
  • Right to data portability, when applicable
  • Right to damages and complaint

9. Security Measures

DRMed implements administrative, physical, and technical safeguards including access controls, secure transmission, rate limiting, and audit logging for portal activities.

10. Consent and Portal Access Logs

When you submit portal credentials and accept this notice, we may record consent metadata such as DRM-ID, timestamp, privacy notice version, and hashed client identifiers for compliance and security verification.

11. Updates to This Notice

We may update this notice from time to time. The latest posted version on this page applies.

12. Contact for Privacy Requests

For privacy-related requests (access, correction, or complaints), contact DRMed through the numbers listed above or through our contact form.