Teh Tarik Digital
  • Investors
  • TTD Alliance™

// LEGAL · NURI PLATFORM

NURI - Privacy Notice

Last updated: July 2026  ·  Effective: July 2026

PDPA 2010 (Amended 2024) Sensitive Personal Data On-Premise MOH-Aligned

Introduction & Scope

This NURI Platform Privacy Notice ("Notice") explains how NURI — Teh Tarik Digital's ("TTD", "we", "our", "us") clinical AI platform — processes personal data, including health-related data, when deployed by a healthcare provider or residential care operator ("Facility"). It supplements, and should be read together with, TTD's main Privacy Policy, which governs TTD's practices generally.

Where this Notice and the main Privacy Policy conflict on a matter specific to NURI, this Notice prevails for that matter.

This Notice applies to personal data processed through NURI in the course of clinical documentation, vitals and incident monitoring, early-warning scoring, shift handover generation, and care scheduling, as described in "What Data NURI Processes" below.

This Notice may be made available in Bahasa Malaysia, Simplified Chinese, Tamil, or other languages for your convenience. In the event of any conflict, inconsistency, or ambiguity between the English version and any translated version, the English version shall prevail.

Who Is Responsible for Your Data

NURI is deployed by a Facility — a hospital, clinic, or residential care operator — to support its own clinical and care workflows. TTD's role in relation to the personal data processed through that deployment depends on the arrangement with the Facility:

  • In the general case, the Facility is the Data Controller and TTD is the Data Processor. The Facility instructs TTD on how NURI is configured and used, determines retention and access policies within the bounds of this Notice, and is responsible for responding to individual rights requests from patients, residents, and staff.
  • Some deployments may involve a different arrangement — for example, where TTD provides a hosted service directly to individual practitioners rather than through an institutional Facility. Where this applies, it will be confirmed in the deployment-specific documentation provided to you or your Facility at onboarding.

If you are a patient, resident, family member, or staff member and are unsure who your Data Controller is for a specific NURI deployment, ask your Facility directly, or contact privacy@tehtarik.digital and we will direct you appropriately.

Because TTD typically acts as Data Processor for NURI deployments, TTD cannot independently action requests to access, correct, or delete data processed through NURI without verified instruction from the Facility — see "Your Rights" below.

What Data NURI Processes

NURI functions as a digital twin for frontline healthcare and residential care teams. Depending on which modules a Facility enables, NURI may process:

  • Clinical documentation. Voice-dictated notes from doctors, nurses, and caregivers, which NURI transcribes and structures into clinical records, care notes, and summaries.
  • Vitals and incident data. Bedside monitor feeds, telemetry, and caregiver-logged observations, used to identify anomalies and trends on a per-patient or per-resident basis.
  • Early-warning scores. Automated clinical deterioration scoring (NEWS2) and configured incident flags, used to trigger escalation to designated duty officers and coordinators.
  • Shift handover records. Structured, cross-department handover summaries compiled from the above sources to keep incoming shifts and administrators aligned on care status and outstanding items.
  • Care scheduling data. Rounds, medication administration tracking, and task records tied to specific patients, residents, and staff members.
  • Identifying information. Patient or resident name and identifier, ward or bed assignment, and treating staff, to the extent necessary to attribute the records above correctly.

NURI does not process workforce attendance, payroll, or location-tracking data, and has no facial recognition or other biometric identification functionality.

Sensitive Personal Data & Legal Basis

Health-related data processed by NURI — including vitals, clinical notes, diagnoses, treatment records, and NEWS2 scores — is sensitive personal data under the PDPA (as amended). Under Section 40 of the PDPA, sensitive personal data may not be processed unless the data subject has given explicit consent, or another specific condition set out in that section applies, such as processing that is necessary for medical purposes carried out by an appropriate healthcare professional.

In practice, this means:

  • Where NURI is used for direct patient or resident care, processing is generally necessary for medical purposes and carried out under the professional responsibility of the treating Facility and its clinical staff, consistent with Section 40's medical-purpose condition.
  • Where a Facility relies on patient or resident consent as its legal basis (for example, for uses beyond direct clinical care), obtaining and recording that consent is the Facility's responsibility as Data Controller.
  • Access to health-related data within NURI is restricted to personnel with a defined clinical or operational need, is retained only for the purpose it was collected, and is never used for marketing or profiling.

If you have questions about the specific legal basis relied upon for your data at a particular Facility, please direct them to that Facility, as TTD as Data Processor does not determine this independently.

On-Premise Architecture & Data Residency

No external data dependency

NURI is designed for on-premise within Malaysia. Clinical data processing and AI inference are contained within the deploying Facility's own environment — data is not transmitted to, or processed by, external systems, including TTD's own infrastructure outside the Facility's environment, except as needed for support and maintenance under the applicable service agreement.

NURI integrates with a Facility's existing systems via HL7/FHIR, allowing it to exchange data with hospital information systems and facility hardware without that data leaving the Facility's environment. Where a Facility elects to use a local cloud region rather than a fully on-premise deployment, data still remains within Malaysia.

Because NURI does not routinely transmit health data outside the Facility's environment or Malaysia, the cross-border transfer considerations described in TTD's main Privacy Policy do not typically arise for NURI deployments. Where a specific deployment involves cross-border support arrangements, the Facility will be informed and TTD's international transfer safeguards described in the main Privacy Policy will apply.

How Data Is Shared

Within a Facility's deployment, data processed by NURI is shared only:

  • Within the Facility — with clinical and administrative staff who have a defined operational need, as configured by the Facility's own access controls.
  • With connected facility systems — via HL7/FHIR integrations that the Facility has configured, such as its hospital information system.
  • With TTD support personnel — only to the extent necessary to provide technical support or maintenance, under confidentiality obligations, and, where practicable, on an access-logged basis.
  • Where required by law — including reporting obligations that MOH or other regulators may place directly on the Facility as a healthcare provider.

NURI data is never sold, never used to train TTD's or any third party's AI models, and never shared with other TTD clients or Facilities.

Data Retention

Clinical and care records processed through NURI are retained according to the Facility's own retention policy as Data Controller, which will typically reflect applicable healthcare record-keeping requirements under Malaysian law and MOH guidance, in addition to the PDPA. TTD, as Data Processor, retains data only as instructed by the Facility and does not independently set retention periods for clinical records.

Where TTD provides supporting infrastructure or backups as part of a deployment, these are retained and deleted in line with the Facility's instructions and the applicable service agreement. When a deployment ends, data handling — including export, retention, and deletion of clinical records — is governed by the agreement between TTD and the Facility, not by this Notice alone.

Data Security

NURI applies restricted, role-based access controls, encryption at rest and in transit, and audit logging to health-related data, consistent with the heightened protection required for sensitive personal data under the PDPA.

Following the PDPA Amendment, Section 5(1A) of the PDPA extends the Security Principle (Section 9) directly to Data Processors. TTD, in its capacity as Data Processor for NURI, is directly and independently accountable for securing the data it processes on the Facility's behalf, in addition to the Facility's own security obligations as Data Controller.

Because NURI's clinical processing and inference are contained within the Facility's own environment, the Facility's own network, physical, and access security measures are a critical part of the overall security posture, alongside NURI's own application-level controls.

Data Breach Notification

Where TTD becomes aware of a personal data breach affecting data it processes through NURI, TTD will notify the affected Facility without undue delay, so the Facility can assess the breach and fulfil its own notification obligations as Data Controller, including to:

  • The Personal Data Protection Commissioner of Malaysia, as required under Section 12B of the amended PDPA;
  • Affected patients, residents, or staff, where the breach causes or is likely to cause significant harm; and
  • The Ministry of Health or other relevant regulators, to the extent the Facility is required to do so.

TTD maintains a breach register for not less than two years, documenting the cause, impact, and remedial actions taken for each incident affecting NURI, and supports the Facility's own breach response as needed.

Your Rights

If you are a patient, resident, family member, or staff member whose data is processed through NURI, your Facility is your Data Controller and is responsible for responding to requests to access, correct, restrict, or delete your data, in accordance with the PDPA and, where applicable, its own policies. Please direct such requests to your Facility in the first instance.

TTD supports and cooperates with these requests under its processing agreement with the Facility, but — consistent with its role as Data Processor — cannot alter, export, or delete records processed through NURI without verified instruction from the Facility.

If your Facility is unresponsive, or you believe your data has been mishandled, you may lodge a complaint with the Malaysian Department of Personal Data Protection (www.pdp.gov.my) or the relevant healthcare regulator. You may also contact privacy@tehtarik.digital if you believe TTD itself, rather than the Facility, is responsible for a specific concern.

Children & Minors Under Care

Where a Facility provides paediatric or family care and processes the data of minors through NURI, that processing is carried out by the Facility as part of providing care to the minor, under the Facility's own consent and safeguarding practices as Data Controller. TTD, as Data Processor, applies the same access restrictions and security controls to minors' data as to any other health-related data processed through NURI.

How This Notice Relates to Our Privacy Policy

This Notice is a supplement to, not a replacement for, TTD's main Privacy Policy, which addresses matters common to all TTD products, including TTD's compliance framework, international transfers in general, and how to reach TTD's Data Protection Officer. Where this Notice does not address a topic — for example, TTD's ISO/IEC 27001 and SOC 2 Type II-aligned hosting practices, or TTD's own status regarding statutory DPO appointment thresholds — the main Privacy Policy applies.

Changes to This Notice

We may update this Notice from time to time, including as NURI's capabilities evolve or as MOH guidance and the PDPA develop. Material changes will be notified by posting the updated Notice on this page and updating the effective date above. Facilities will also be notified directly of changes materially affecting their deployment.

Contact Us

If you have questions, concerns, or requests regarding this Notice or NURI's data practices, please contact us:

  • General privacy queries: privacy@tehtarik.digital
  • Data Protection Officer: dpo@tehtarik.digital
  • Legal queries: legal@tehtarik.digital
  • Address: SunTech @ Penang CyberCity, 11950 Bayan Lepas, Pulau Pinang, Malaysia
  • Phone: +604 - 44 20 891
  • Malaysian PDPA Complaints: www.pdp.gov.my
Teh Tarik Digital

PLT. LP0017587 – LGN

ENT. CT0150551 – V

Est. 2016 · Penang Cybercity, Malaysia

Malaysian tech company specialising in AI-powered platforms for SME and government procurement. Builders of IRIS, NURI, JomWork, and SmartPole OS.

Company

  • Business Hub
  • About Us
  • Services
  • The Lab AI
  • Careers

Partnership

  • TTD Alliance Programme

Services

  • Software & Product
  • Cloud & Infrastructure
  • AI Automation
  • Agentic Systems
  • Digital Marketing
  • IT Consultancy
  • Application Security & Code Assurance

Products

  • IRIS v2.1
  • SmartPole OS
  • JomWork
  • NURI

Utilities

  • Get Support
  • Coverage Check

Reach Out

  • SunTech @ Penang CyberCity,
    11950 Bayan Lepas, Penang
  • Kuala Lumpur · Sg. Petani
  • Infinia Park, South Jakarta
  • +604 - 44 20 891
  • ai@tehtarik.digital
cb

© 2026 Teh Tarik Digital. All rights reserved.

  • Privacy
  • Terms
  • Topology