Legal
How Reylo Labs Pte. Ltd. collects, uses, shares and protects personal data — for people who visit this site, for clinic staff who use Reylo, and for the patient data a clinic entrusts to us.
This is the policy in force, not a template. It describes what Reylo Labs Pte. Ltd. actually does with personal data today. Where something is not yet built or not yet contracted, we say so rather than claim it. If a practice changes, this page changes with it and the date above moves.
Reylo Labs Pte. Ltd. (UEN 202642579R), registered at 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914, SG (“Reylo”, “we”, “us”) operates the Reylo platform and the website at reylo.ai. Reylo is an AI patient-coordination system used by aesthetic and medical-tourism clinics.
Our governing framework is Singapore’s Personal Data Protection Act 2012 (“PDPA”). Where a clinic operates in Indonesia, Indonesia’s Personal Data Protection Law (UU PDP, Law No. 27 of 2022) also applies to that clinic’s patient data. Where we handle the personal data of people in the European Union or the United Kingdom, we apply the GDPR standard to that data.
We have appointed a Data Protection Officer as the PDPA requires. Reach the DPO at privacy@reylo.ai, or by post at the registered address above.
Reylo wears two different hats, and which one applies decides who you deal with.
We use this data only to run the service the clinic asked for: to route and answer patient messages, book and remind, follow up, raise and settle invoices, and give the clinic its own operational analytics. We do not sell personal data, and we do not use a clinic’s patient data to advertise to anyone.
Under the PDPA we collect, use and disclose personal data for purposes a reasonable person would consider appropriate in the circumstances, and which we have notified. We rely on your consent, and on the other bases the PDPA permits, including performance of a contract you are party to and our legitimate interests in operating and securing the service. Where the GDPR applies, the equivalent bases are consent, contract, legal obligation and legitimate interests.
You may withdraw consent at any time by writing to privacy@reylo.ai. We will act on it within a reasonable period. Withdrawing consent may mean we can no longer provide part or all of the service to you, and we will tell you if that is the case.
We disclose personal data only to service providers who need it to run the service, under contracts that require them to protect it to a standard comparable to the PDPA. We do not sell personal data and we do not share it with data brokers.
Where we describe a category rather than name a company, it is because the specific vendor is still being selected or varies by clinic. We will name it here once it is fixed.
We are based in Singapore; our clinics and their patients are in Indonesia, Korea, the Gulf, Brazil and elsewhere. Personal data therefore crosses borders. Where we transfer personal data out of Singapore, we take reasonable steps to ensure the recipient is bound to a standard of protection comparable to the PDPA, ordinarily through contractual data-protection clauses. Where Indonesia’s PDP Law governs a clinic’s patient data, the clinic and Reylo apply the transfer safeguards it requires. Where GDPR data is transferred outside the EEA or the UK, we use Standard Contractual Clauses or an equivalent approved mechanism.
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires, and then delete or anonymise it.
We use reasonable technical and organisational measures appropriate to the sensitivity of the data: encryption in transit, per-clinic tenant isolation enforced in the database itself and not only in application code, role-based access control, scoped credentials, audit logging, and limits on which staff can access production systems. Access is granted on a need-to-know basis and reviewed.
No system is perfectly secure, and we will not pretend otherwise. If something goes wrong, section 9 says what we do.
If a data breach occurs that is likely to result in significant harm to affected individuals, or that affects a number of individuals at or above the threshold prescribed by the PDPA, we will notify the Personal Data Protection Commission and the affected individuals within the timeframes the PDPA sets. Acting as a data intermediary, we will notify the clinic concerned without undue delay after becoming aware of a breach affecting its customer data, so the clinic can meet its own obligations as controller.
Under the PDPA you may:
Where the GDPR applies, you additionally have rights to erasure, restriction, portability and objection, and the right to complain to your local supervisory authority.
To exercise any of these, email privacy@reylo.ai with enough detail for us to identify your records. We will acknowledge your request and respond within the period the law requires, and we will tell you in advance if a fee applies to an access request, as the PDPA permits. We may need to verify your identity first.
If you are a patient of a clinic that uses Reylo, send your request to that clinic. The clinic is the controller of your data and decides these requests. We will assist it as its intermediary, and we will forward a request to the right clinic if you send it to us by mistake.
This marketing website sets no cookies of its own and runs no advertising or cross-site tracking pixels. Where site analytics are enabled, we use a cookieless, aggregate measurement tool that does not build a profile of you or follow you across other sites.
The Reylo application, which clinic staff sign in to, uses strictly necessary cookies and browser storage to keep you signed in and to remember preferences such as language, theme and which workspace you were last in. They are required for the application to work, and they do not hold patient content. You can clear them in your browser at any time, but you will be signed out.
Reylo is a tool for businesses and their authorised staff. It is not directed to children and we do not knowingly collect personal data directly from children through it. Where a clinic records data about a minor who is its patient, the clinic is the controller of that data and is responsible for obtaining any consent the law requires from a parent or guardian.
We may update this policy as the product and our vendors change. The current version is always the one on this page, with its date at the top. If a change materially affects how we handle your personal data, we will tell account holders directly rather than rely on you noticing the date.
Privacy questions, requests and complaints go to our Data Protection Officer at privacy@reylo.ai, or by post to Reylo Labs Pte. Ltd., 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914. For anything else you can reach us at jasper@reylo.ai or ramon@reylo.ai.
We would like the chance to put a problem right first. If we do not resolve it to your satisfaction, you may complain to Singapore’s Personal Data Protection Commission at www.pdpc.gov.sg. If you are in the EU or UK, you may also complain to your local data protection authority.