Privacy Policy

Last revised: 19 August 2025

5 Health Pte Ltd (“5 Health,” “we,” “our,” or “us”) partners with hospitals, clinics, institutions, and healthcare organizations (“Customers”) to provide access to Bot MD, a suite of AI-powered agents integrated into popular messaging platforms such as WhatsApp, Facebook Messenger, Viber, SMS and other interfaces (together, the “Bot MD Services”).

This Privacy Policy explains how we collect, use, disclose, and protect personal data of individuals who use Bot MD Services, whether as Clinician Users (e.g., doctors, nurses, hospital staff) or Patient Users (patients, caregivers, or the public who interact with Bot MD Care).

By accessing or using the Bot MD Services, you agree to the terms of this Privacy Policy and our Terms of Use. If you do not agree, please do not use the Bot MD Services.

In Plain English

Bot MD is a healthcare technology company that is focused on empowering doctors, nurses and healthcare workers around the world.

Our product platform helps hospitals and clinics automate workflows through AI agents integrated into chat platforms. We do not believe in showing you paid pharmaceutical advertising. Neither do we believe in monetizing your personal data.

Your hospital, institution or organization is paying for you to use the Bot MD Services. You are required to register for an account in order to access and use the Bot MD platform. This account registration is based on the contact information and work-registered mobile number that your hospital, institution or organization provides to us.

All content within Bot MD is provided to us by your institution. Patient-facing data (appointments, reminder logic) is always handled under the hospital’s authorization and with required patient consent.

We know how important it is to maintain data privacy and to protect your user information. Within the contract that we signed with your hospital, we have specific clauses on data privacy and confidentiality.

All query information is anonymized and aggregated into usage statistics that helps us to improve our AI agents’ understanding of workflows and queries. It is also analyzed for us to help you determine which new content to add that is relevant to address unanswered questions

Should you have any further questions about how data is used, please feel free to write to us at support@botmd.io and we can put you in touch with your hospital representative.

Thank you for all that you do for your patients.

Purpose and Scope of this Privacy Policy

1.1 This Privacy Policy sets out the basis on which the Company may collect, use, disclose or otherwise process Personal Data either provided by you and/or our Customers through the use of the Bot MD Services and/or via the Bot MD Interface.

1.2 We may revise this Privacy Policy from time to time without any prior notice to you. You may determine if any such revision has taken place by referring to the date on which this Privacy Policy was last updated. Your continued use of our Bot MD Services constitutes your acknowledgement and acceptance of such changes.

Definitions

2.1 In this Privacy Policy:

“Authorized Representative” has the meaning ascribed to it in Clause 4.1(a).

“Bot MD SaaS Agreement” means the software as a service agreement entered into between the Company and a Customer.

“Customer” means a hospital, institution, or organisation who has entered into an agreement(s) with the Company for the provision of Bot MD Services including the Bot MD SaaS Agreement.

“Individual User Terms” means the terms of use for the Bot MD Services as may be agreed to between the individual user and the Company from time to time.

“PDPA” means the Personal Data Protection Act 2012, as may be amended from time to time.

“Personal Data” refers to any data, whether true or not, about an individual who can be identified (i) from that data; or (ii) from that data and other information to which we have or is likely to have access, including data in our records as may be updated from time to time. Some examples of the Personal Data that we may collect from you include:

(a) Your name, identification numbers such as NRIC, Passport Number, FIN, residential address, email address, telephone number, nationality, gender and date of birth; (b) Information about the computer or mobile device you are using; (c) Geographical location or address; or (d) Other information which you may provide for the Bot MD Services or input into the Bot MD Interface.

“Purposes” has the meaning ascribed to it in Clause 6.1.

2.2 Other terms used in this Privacy Policy shall have the meanings given to them in the PDPA, our Individual User Terms and our Bot MD SaaS Agreement (where the context so permits).

Consent

3.1 You hereby consent to the collection, use, disclosure, transfer and processing of your Personal Data in accordance with and subject to the terms and conditions of this Privacy Policy.

3.2 You may, at any time, withdraw your consent to the collection, use, disclosure, transfer and/or processing of your Personal Data in accordance with the procedure set out in Clause 9.

Collection of Personal Data

4.1 We generally do not collect Personal Data unless: -

(a) it is provided to us voluntarily by you directly or via a third party who has been duly authorised by you to disclose Personal Data to us (the “Authorised Representative”) for the specific purposes which have been notified to you or the Authorised Representative. We do not collect any Personal Data which is not reasonably necessary for the purpose for which it is collected. Some examples of the Personal Data which we may collect include the queries we received from you, the responses returned by or through the Bot MD Services, as well as aggregated and statistical data derived from the use of the Bot MD Services; or

(b) the collection and use of Personal Data is permitted or required under the PDPA or other laws. We shall seek your consent before collecting any additional Personal Data and before using your Personal Data for a purpose which has not been notified to you (except where permitted or authorised by law).

4.2 If you provide us with any Personal Data relating to a third party, by submitting such information to us, you represent to us that:

(a) you are authorised to act on his/her behalf; and

(b) he/she accepts that his/her Personal Data will be subject to this Privacy Policy (as amended from time to time).

4.3 You must ensure that all Personal Data submitted to us, including those relating to third parties, is complete, accurate and up to date. Please update us as soon as reasonably practicable, if there are any changes to your Personal Data by informing the Data Protection Officer named in this Privacy Policy below.

Third Party Messaging Platforms

5.1 Bot MD Services integrate with third-party messaging platforms (e.g. WhatsApp, Facebook Messenger, Viber, SMS etc.). By using Bot MD, you acknowledge that Data transmitted through these platforms is also subject to their terms and privacy policies 5 Health does not control and is not responsible for the data handling We strongly recommend that patients and clinical users avoid sharing sensitive or personally identifiable health data through these platforms

Purposes for the Collection, Use and Disclosure of Personal Data

6.1 We may collect and use Personal Data for any or all of the following purposes (“Purposes”) and you hereby consent to the use of Personal Data for the Purposes:

(a) performing obligations in the course of or in connection with the provision of Bot MD Services or use of Bot MD Interface;

(b) marketing and promoting Bot MD Services and/or Bot MD Interface;

(c) responding to, handling, and processing enquiries, requests, complaints, and feedback;

(d) for audit, accounting, administration, risk management and record keeping purposes;

(e) for emergency contact;

(f) conducting investigations and proceedings in the event of any disputes, possible fraud, misconduct, unlawful action or omission;

(g) responding to requests for information from government or public agencies, ministries, statutory boards or other similar authorities or non-government agencies authorised to carry out specific government or regulatory services or duties;

(h) meeting or complying with any applicable rules, laws, regulations, codes of practice or guidelines issued by any legal or regulatory bodies (including but not limited to responding to regulatory complaints, disclosing to regulatory bodies and conducting audit checks, due diligence and investigations);

(i) managing your relationship with us;

(j) processing payment transactions;

(k) understanding your needs and preferences;

(l) conducting surveys, research, and evaluations to obtain feedback;

(m) verifying your identity and ensuring that you are eligible to access and use the Bot MD Services provided on our Bot MD Interface;

(n) evaluating whether to, temporarily or permanently, suspend, revoke, or terminate your account;

(o) verifying and approving the materials you post or transmit through Bot MD Services or Bot MD Interface;

(p) maintaining or improving the quality of the Bot MD Services through the performance of quality reviews and similar activities;

(q) maintaining or improving Bot MD Interface, its content, appearance, design and/or utility;

(r) converting your Personal Data to anonymised data for the purposes of analytics, business intelligence and statistical research;

(s) creating anonymised information which is information which is not used or intended to be used to personally identify an individual (e.g., aggregate statistics relating to the use of the Bot MD Services);

(t) notifying you when Bot MD Interface updates and upgrades are available;

(u) facilitating business asset transactions (which may extend to any mergers, acquisitions or asset sales);

(v) any other incidental business purposes related to or in connection with the above;

(w) any other specific purposes which we may inform you of in writing from time to time, but for which we will seek your separate consent;

(x) transmitting to any unaffiliated third parties including our third-party service providers and agents, whether in Singapore or abroad, for the aforementioned purposes.

6.2 As you use our Bot MD Services, certain non-personally identifiable information about yourself may be passively collected:

(a) Site Activity Information: We may keep track of some of the actions that you take on our Bot MD Interface, such as the content of searches you perform on our Bot MD Interface;

(b) Access Device and Browser Information: When you access our Bot MD Services through a website from a computer or other device, we may collect anonymous information from that device, such as your Internet protocol address, browser type, connection speed and access times;

(c) Cookies (i.e., small pieces of information that a site sends to your browser while you are viewing a website): We may use both session Cookies (which expire once you close your web browser) and persistent Cookies to make our Bot MD Services easier to use, to make our advertising better, and to protect both you and the Company. You may instruct your browser, by changing its options, to stop accepting Cookies or to prompt them before accepting a Cookie from the websites they visit. If you do not accept Cookies, however, you will not be able to stay logged in to our Bot MD Interfaces.

(d) Real-Time Location: Certain features of our Bot MD Interface use technology to collect real-time information about the location of your device. This is because many of our clinical users may practice in more than one hospital location. We use your device location to present you with relevant information from your hospital, institution or organisation (depending on your physical location). You can choose at any time to disallow access to your device location or to notifications simply by turning these off within your settings page.

(e) Device information: We may also collect non-personal information from your mobile device or computer. This information is generally used to help us deliver the most relevant information to you. Examples of information that may be collected and used include how you use the application(s) and information about the type of device or computer that you use. In addition, in the event our application(s) crashes on your mobile device, we will receive information about your mobile device model software version and device carrier, which allows us to identify and fix bugs and otherwise improve the performance of our application(s).

6.3 Personal Data that you provide will be provided to affiliate partners and third parties service provider, in connection with any services provided by these parties, which may be sited locally or outside of Singapore, and who are bound by contractual obligations to keep your Personal Data confidential and use it only for the purposes for which we disclose it to. Such services would include the maintenance of Bot MD Interface, monitoring Bot MD Interface’s activity, provisions of third-party professional resources such as drug information, clinical calculator and guidelines or membership database, and storage of Users’ information.

6.4 Whilst care would be taken to require that some of these affiliate partners and third parties (to the extent possible, with relevant authorities exempted) provide an undertaking on compliance with the PDPA and applicable personal data protection regulations, we will not be able to provide any warranties on the manner or care in which these third parties maintain, protect or utilise your Personal Data.

6.5 The purposes listed in Clause 6.1 may continue to apply even in situations where your relationship with us has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under any contract with you).

6.6 This Privacy Policy applies only to information we collect through our Bot MD Interface and in email, text and other electronic communications set through or in connection with our Bot MD Services. This Privacy Policy does not apply to information collected by any third party. When you click on links on our Bot MD Interface, you may leave our interface. We are not responsible for the privacy practices of other interfaces, and we encourage you to read their privacy statements carefully.

Disclosure of Personal Data to Third Parties

7.1 Without prejudice to the foregoing, we may also disclose your Personal Data to third parties without first obtaining your consent in certain situations, including, without limitation, the following:

(a) the disclosure is required based on the applicable laws and/or regulations, which can include providing information as required by a court order;

(b) the purpose of such disclosure is clearly in your interests and consent cannot be obtained in a timely way;

(c) the disclosure is necessary to respond to an emergency that threatens the life, health or safety of yourself or another individual;

(d) there are reasonable grounds to believe that the health or safety of yourself or another individual will be seriously affected and consent for the disclosure of the data cannot be obtained in a timely way, provided that we shall, as soon as may be practical, notify you of the disclosure and the purposes of the disclosure;

(e) the disclosure is necessary for any investigation or proceedings;

(f) the Personal Data is disclosed to any officer of a prescribed law enforcement agency, upon production of written authorisation signed by the head or director of that law enforcement agency or a person of a similar rank, certifying that the Personal Data is necessary for the purposes of the functions or duties of the office; and/or

(g) the disclosure is to a public agency and such disclosure is necessary in the public interest; and

(h) to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of the Company’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal Data maintained on our Bot MD Interface is among the assets transferred.

7.2 The instances listed above at Clause 7.1 are not exhaustive. For an exhaustive list of exceptions, you are encouraged to refer to the PDPA.

7.3 In all other instances of the disclosure of Personal Data to third parties with your express consent, we will provide use reasonable endeavours to provide for security in the handling and administration of your Personal Data by such third parties in compliance with the PDPA.

Withdrawal of Consent and/or Request for Access, Correction of your Personal Data

Withdrawal of Consent

8.1 The consent that you provide for collection, use and disclosure of your Personal Data will remain valid until such time it is being withdrawn by you in writing. You may at any time withdraw any consent already given, or deemed to have been given under the PDPA, in respect of the collection, use or disclosure by us of Personal Data about you for any purpose on giving reasonable notice (depending on the complexity of the request and its impact on our relationship with you) to us by contacting our Data Protection Officer at the contact details provided in Clause 11. In general, we shall seek to process your request within fourteen (14) business days of receiving it.

8.2 We do not prohibit an individual from withdrawing his consent to the collection, use or disclosure of Personal Data about the individual but this shall not affect any legal consequences arising from such withdrawal.

8.3 On withdrawal of consent, we shall cease (and cause our data intermediaries and agents to cease) collecting, using or disclosing your Personal Data, as the case may be, unless such collection, use or disclosure, as the case may be, without the consent of the individual is required or authorised under the PDPA or other written law.

8.4 Whilst we respect your decision to withdraw your consent, please note that we may not be able to continue to provide you with the Bot MD Services or allow access to the Bot MD Interface. Should you decide to cancel your withdrawal of consent, please inform us in writing in the manner described in Clause 8.1 above.

Request to Access or Correct Personal Data

8.5 Please contact our Data Protection Officer (at the contact details provided in Clause 11 below) if you wish to make:

(a) an access request for access to your Personal Data or information about the ways in which we use or disclose your Personal Data; or

(b) a correction request to correct any of your Personal Data. Such request shall include the details of the requestor, description of the Personal Data being requested and the date and time range the Personal Data was believed to be collected.

8.6 Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request. We will respond to your access request as soon as reasonably possible. If we are unable to respond to your access request within 30 days after receiving the request, we shall inform you in writing of the time by which we will be able to respond to your access request.

8.7 We will respond to your correction request as soon as practicable from the time the correction request is made. If we are unable to respond to your correction request within 30 days after receiving the request, we shall inform you in writing of the time by which we will be able to correct the Personal Data.

Management and Care of Personal Data

Protection of Personal Data

9.1 We shall protect Personal Data in possession or under our control by making reasonable appropriate administrative, physical and technical measures to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks. You should be aware, however, that no method of transmission over the internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your Personal Data and are constantly reviewing and enhancing our information security measures.

9.2 We do not represent or warrant that our Bot MD Interfaces are free of errors, infection by computer viruses, and/or other harmful or corrupting code, program, macro and such other unauthorized software. We do not assume responsibility for any unauthorised use of your Personal Data by third parties, which are wholly attributable to factors beyond our control.

Retention of Personal Data

9.3 We will retain your Personal Data for the period necessary to fulfil the Purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law, as described in further detail below. After such time, we shall take reasonable effort to destroy or anonymise documents containing your Personal Data, or remove the means by which your Personal Data can be associated with particular individuals.

(a) Account information: We retain your account information for as long as your account is active and a reasonable period thereafter in case you decide to re-activate the Bot MD Services. We also retain some of your information as necessary to comply with our legal, regulatory, tax accounting, reporting or business purposes.

(b) Information you share on the Bot MD Services: If your account is deleted, some of your information and the content you have provided will remain in order to allow other Users to make full use of the Bot MD Services.

(c) Managed accounts: If the Bot MD Services are made available to you through our Customer, we will retain your information for as long as may be required by the administrator of your account under our agreement with the Customer.

(d) Marketing information: If you have elected to receive marketing emails from us, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our Bot Services, such as when you last opened an email from us or ceased using your Bot MD account. We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.

Accuracy of Personal Data

9.4 We generally rely on personal data provided by you or any Authorised Representative. In order to ensure that your Personal Data is current, complete and accurate, please update us if there are changes to your personal data by informing our Data Protection Officer in writing or via email at the contact details provided below at Clause 11 below.

Transfer of Personal Data outside of Singapore

10.1 Please note that the third parties to whom we may provide your Personal Data in accordance with this Privacy Policy may be located in jurisdictions other than Singapore. These jurisdictions may have varying legal protections applicable to Personal Data.

10.2 Where your Personal Data is to be transferred out of Singapore, we will comply with the PDPA in doing so. This includes taking appropriate steps to ascertain that the overseas recipient of the Personal Data is bound by legally enforceable obligations such that the transferred Personal Data is accorded a standard of protection that is at least comparable to the protection accorded under the PDPA.

Data Protection Officer

You may contact our Data Protection Officer if you have any questions or feedback relating to this Privacy Policy, or if you wish to make any request at the details below:

Name: Yan Chuan Sim Email: privacy@botmd.io

Governing Law

This Privacy Policy is governed by the laws of Singapore. You agree to submit to the exclusive jurisdiction of the Singapore courts in any dispute relating to this Privacy Policy.