Privacy Policy
Last Updated: 14 October 2025
1. Our Commitment to Privacy
Novena Heart Centre is part of Tamarind Health Management Pte Ltd committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 (Singapore).
This Privacy Policy explains how we collect, use, disclose, protect, and manage your personal data across our Group websites, clinics, and healthcare services.
By providing your personal data to Novena Heart Centre, you acknowledge and consent to the collection, use, and disclosure of your personal data as described in this Policy.
2. Scope
This Policy applies to:
- Visitors to our websites and digital platforms
- Patients, caregivers, and family members
- Healthcare professionals, employees, and contractors
- Vendors, suppliers, and service providers
- Corporate and institutional partners
This Policy should be read together with the Tamarind Health Privacy Policy available at https://tamarindhealth.com/privacy-policy/.
3. Personal Data We Collect
We may collect personal data such as:
- Identity and contact information: name, NRIC or passport number, contact details, address, date of birth, nationality.
- Health and medical information: medical history, diagnostic results, clinical notes, prescriptions, and other data relevant to your care.
- Administrative and financial information: billing, insurance, and payment details.
- Digital and technical information: IP address, browser type, cookies, device identifiers, and analytics data.
- Employment and professional information: work history, credentials, and employment data for staff, partners, or applicants.
Data may be collected directly from you or from authorised third parties such as healthcare providers, insurers, or partner hospitals, where permitted by law.
4. Purpose of Collection and Use
We collect, use, and disclose personal data for legitimate business and clinical purposes, including:
- Delivering medical and healthcare services
- Managing appointments, referrals, and follow-ups
- Processing billing, payments, and insurance claims
- Supporting laboratory, pharmacy, and allied health services
- Conducting patient support, survivorship, and wellness programs
- Managing recruitment, HR, and training
- Performing audits, research, and quality improvement (with appropriate approvals)
- Communicating updates or marketing (where consented)
- Meeting legal, regulatory, and reporting obligations
- Ensuring safety, security, and risk management
5. Disclosure of Personal Data
We may share personal data with:
- Tamarind Health entities and affiliated OpCos
- Hospitals, laboratories, and medical specialists involved in care
- Service providers (IT, billing, storage, audit, marketing)
- Regulators, insurers, or authorities as required by law
- Research and educational collaborators under confidentiality safeguards
- Business partners or successors involved in mergers or acquisitions
All third parties are contractually bound to protect data in accordance with applicable laws and this Policy.
6. Cross-Border Data Transfers
Your personal data may be transferred across borders for administrative, clinical, or operational reasons.
We ensure such transfers comply with applicable laws by obtaining consent where required and applying appropriate contractual and technical safeguards.
7. Data Retention
We retain personal data only as long as necessary for its purpose or as required by law and professional standards.
Medical records are retained for up to twenty (20) years, or longer where required by law, clinical necessity, or institutional policy.
When data is no longer needed, it will be securely deleted, anonymised, or destroyed.
8. Data Security
We maintain administrative, technical, and physical safeguards to protect personal data from loss, misuse, or unauthorised access.
Measures include access controls, encryption, secure servers, and periodic audits. While we aim for the highest standards, no system is entirely secure.
9. Access, Correction, and Withdrawal of Consent
You may:
- Request access to personal data held by us
- Request correction of inaccurate or incomplete information
- Withdraw consent for use or disclosure (subject to legal limits)
Requests should be made in writing to our Data Protection Officer (see Section 12).
We will respond within 30 calendar days or as allowed by law. Administrative fees, if any, will be communicated in advance.
10. Use of Cookies and Analytics
Our websites use cookies and analytics tools to improve functionality and user experience.
You may disable cookies in your browser, though this may limit certain features.
11. Third-Party Links
Our websites may link to external sites. We are not responsible for their content or privacy practices and encourage you to review their privacy policies.
12. Contact Us
Data Protection Officer (DPO)
Novena Heart Centre
51 Goldhill Plaza, #21-07
Singapore 308900
Email: [email protected]
13. Policy Updates
This Policy may be updated periodically. The latest version will always be posted on our website, and continued use of our services signifies acceptance of any revisions.