Privacy Notice
Q10 Pharmacy website, vouchers, member cards, Birthday Club, Telegram services and staff tools
Baca Notis Privasi dalam Bahasa MelayuLast updated: 23 July 2026
Operator: Q10 Pharmacy, Miri, Sarawak
1. Scope and responsibility
This notice explains how Q10 Pharmacy handles personal data in the services named above. It supplements any in-store notice that applies to dispensing, regulated-sales or patient-care records. Some pharmacy, transaction or dispute records may need to be retained even after an optional service is cancelled.
This notice describes the deployed system. We will review it whenever a provider, database field, retention period or customer channel changes. It is not a guarantee of legal compliance or a substitute for professional legal review.
2. Data we handle
| Feature | Data used | Why |
|---|---|---|
| In-store membership / IRS POS | Name, member account, contact details and other information entered in the local pharmacy system. Dispensing or regulated-sale records may contain additional health or identity information. | Membership, customer service, transactions and pharmacy operations. |
| Member directory and digital-card links | Name, member ID, a SHA-256 normalized-phone lookup hash, an HMAC-SHA-256 IC/passport verifier, its version, and record update time. Raw IC/passport is not saved in the cloud member record. Public phone-and-IC web self-verification is disabled. | Let authorised staff locate and verify the correct member, or let the linked Telegram bot revalidate an existing member link, before issuing a 15-minute, provider-specific, one-use Wallet link. |
| New-member staff queue | Name, member ID and one normalized phone for up to eight days. No Wallet bearer token is stored in the sync entry. | Let authorized staff prepare and send a requested member-card link, then remove the temporary queue item. |
| Vouchers and spin | Name, purpose-limited contact phone, phone/identity hashes where used, voucher code and offer, outlet, dates, redemption/void status, eligibility information and minimized anti-abuse signals. | Issue, find, validate and redeem a voucher; prevent repeated or fraudulent claims. |
| Birthday Club | Name, normalized phone, birthday month, privacy-notice version, registration time/source and separate WhatsApp choice. | Create one annual reward and deliver it through WhatsApp if chosen, through a separately opted-in linked Telegram account, or through staff retrieval. |
| Browser notifications | A browser push endpoint and cryptographic subscription keys tied to the voucher that authorized them. | Send the optional reminder for that voucher. An old voucher subscription is not reused as general marketing permission. |
| Google or Samsung Wallet | Name, member ID/barcode, pass identifier and the voucher/member information shown on the selected pass. | Create and update the digital pass you requested. |
| Telegram bot | Telegram user/chat ID, linked member details, preferences, reminder text/times, commands, limited conversation history and—only after you agree—eligible purchase information retrieved for reminder setup. | Link the customer, deliver requested reminders/rewards and answer requested questions. |
| Customer-order tool | Customer name, phone/member ID, requested item, notes, deposit/status and staff activity. | Manage reservations and customer orders. |
| Security and diagnostics | IP address, user agent, timestamps, rate-limit counters, staff access logs and minimized device/browser signals. High-risk voucher attempts may be flagged for staff review. | Protect accounts and vouchers, investigate failures and maintain the service. |
3. Where data comes from
- directly from you through our website, Telegram, WhatsApp or staff;
- from the Q10 membership/POS record created during your in-store dealings;
- from your browser, device, Telegram account or Wallet provider when you use that feature; and
- from Q10 staff when they update an order, voucher or service record.
4. How the services connect
| Flow | Data movement |
|---|---|
| Member sync | Local IRS SQL → read-only sync on a Q10 PC → minimized schema-v3 records in Cloudflare KV. Raw IC, points, city and state are not part of the cloud member schema. |
| Member verification and Wallet-link issue | Public phone-and-IC web self-verification is disabled. After an in-person check, authorised staff use an authenticated dashboard to request a separate Google or Samsung Wallet link. A linked Telegram user may request a link only after the bot revalidates the member link. The Q10 Worker creates an opaque token limited to the selected provider, valid for up to 15 minutes and accepted once. |
| Voucher issue / redemption | Customer or staff browser → Q10 Worker → a per-customer/per-code Cloudflare Durable Object that serializes the operation → the retained voucher record in Cloudflare KV. |
| Birthday Club | Authorised staff create a 15-minute one-use enrollment link after an in-person check. Your browser then sends the link token, birthday month, notice acknowledgement and optional WhatsApp choice to the Q10 Cloudflare Worker/KV. The purpose-limited record contains the normalized phone so Q10 can match the registration to staff retrieval, optional WhatsApp delivery or a separately opted-in linked Telegram account. |
| Wallet | Authorised staff dashboard or linked Telegram bot → Q10 Worker creates a 15-minute, provider-specific token → your browser presents it once to Q10 Worker → Google Wallet or Samsung Wallet receives the pass data when you choose that provider. A Google token cannot be used for Samsung, or vice versa. |
| Telegram automation | Telegram → Q10 Telegram Worker → Q10 storage. For AI-assistant questions, recent conversation context and the question may be sent to Google Gemini. |
| Browser push | Your browser → Q10 Worker → the push service selected by your browser/device → your device. |
| Staff operations | Authorized staff browser → Cloudflare Worker/storage → the relevant outlet or owner Telegram chat for an operational notification where configured. |
5. Purposes and choices
We process data to provide the service you request, operate membership and vouchers, keep appropriate records, secure the systems, respond to enquiries and meet applicable obligations. Birthday and promotional channel choices are separate from ordinary pharmacy service.
- Birthday Club registration requires acknowledgement of this notice because the reward needs a name, phone and birthday month.
- WhatsApp delivery for Birthday Club is optional. Leaving it unticked does not consent to marketing. A linked Q10 Health Bot user may separately send
/birthday onin a private Telegram chat; otherwise ask staff to retrieve the reward. - Browser push is optional and scoped to the voucher used to authorize it.
- A digital Wallet card is optional. Staff or the linked Telegram bot issue separate Google and Samsung links after verification; each link is provider-specific, expires after 15 minutes and is accepted once. Ask staff for a new link if it expires.
- Telegram linking is optional. Use
/unlinkor/privacy delete confirmto remove the Telegram profile and related optional data. - Do not send prescriptions, medical histories or identity documents to the AI assistant unless Q10 specifically asks you to use an approved channel for that purpose.
6. Service providers and disclosures
We do not sell customer data. Depending on the feature you choose, data may be processed by:
- Cloudflare for website delivery, Workers, KV and Durable Object storage, serialized voucher operations and security;
- Telegram for bot messages and account/chat identifiers;
- Google for Google Wallet and Google Gemini when the AI assistant is used;
- Samsung for Samsung Wallet passes;
- your browser/device push provider for optional web notifications; and
- authorized Q10 staff, professional advisers, regulators or authorities where needed for service, security, claims or applicable law.
These providers may process data outside Malaysia. Their own terms and privacy notices also apply. We are responsible for assessing these transfers, keeping the applicable records and putting suitable contractual safeguards in place. See the Malaysian regulator’s cross-border transfer guidance.
7. Retention
We aim to keep personal data only for the service, security, accounting, dispute and regulatory periods that apply. Current application controls include:
| Record | Current application retention |
|---|---|
| New-member staff queue | Up to 8 days. |
| Purpose-specific Google or Samsung Wallet bearer token prepared by staff or the linked Telegram bot | Up to 15 minutes and accepted once. Replaced, consumed or expired tokens are not valid. |
| Birthday Club one-use enrollment token | Up to 15 minutes, and deleted after successful use or replacement. |
| Unused voucher and duplicate-prevention index | Voucher expiry plus approximately 90 days. |
| Redeemed voucher record | Up to 2 years for reconciliation, dispute and accounting/audit purposes. |
| Spin/audit log | Up to 180 days. |
| Minimized device anti-abuse record | Up to 90 days. |
| Voucher-specific push subscription | Until approximately one day after that voucher expires. |
| Telegram purchase hand-off event | Normally 24–48 hours. |
| AI conversation context in Q10 KV | Up to 1 hour. The provider may apply its own processing/retention terms. |
| Telegram pairing code | Up to 15 minutes; the linked profile and reminders remain until unlinked/deleted or no longer needed. |
| Birthday Club | Up to 2 years after the most recent registration or preference update, or sooner when consent is withdrawn, deletion is requested or the program ends. Channel consent is checked before outreach. |
| Customer-order tool | Active records for up to 400 days; completed or archived records for up to 180 days. Staff Telegram links expire after up to 180 days unless renewed or removed sooner. |
| Cloud member index | While membership is active and until the next reconciliation removes an obsolete record. |
| Local pharmacy and transaction records | According to applicable operational, accounting, professional and legal requirements. |
Backups, provider logs and records required for legal claims or regulatory purposes may take longer to remove. We will explain an applicable exception when responding to a request.
8. Security and automated controls
Measures include HTTPS in transit, minimized member-sync fields, a phone lookup hash, a keyed identity verifier, purpose-bound one-use tokens, staff role/outlet checks, request limiting, restricted secrets and audit logging. No internet service can promise absolute security.
Rate limits, duplicate checks and fraud rules can automatically delay or reject a voucher attempt. They do not determine medical treatment. Ask Q10 staff for human review if a legitimate request is blocked. The Telegram AI assistant is not a substitute for a pharmacist, doctor or emergency service.
If Q10 suspects loss, unauthorized access or disclosure, our operational response is to contain the issue, preserve relevant logs, assess the data and people potentially affected, contact the relevant provider, escalate it to Q10 management/privacy contact, and make customer or regulatory notifications where our assessment finds they are required. These steps do not guarantee that an incident will not occur or that every event has the same notification duty.
9. Browser storage and external resources
Some pages use local/session storage for a voucher code, interface preference or short session. Browser push creates a subscription only after permission. Pages may load static assets or libraries from content-delivery providers; those providers can receive ordinary request information such as IP address and user agent. We do not intentionally use advertising pixels for these voucher/member pages.
10. Your requests and choices
Subject to the Personal Data Protection Act 2010 and other applicable requirements, you may ask whether we process your data, request access or correction, withdraw optional consent, object to direct marketing, or ask us to stop a particular use or delete data that is no longer required. Withdrawal may prevent an optional service from continuing but does not undo processing already completed.
The Malaysian Personal Data Protection Commissioner describes data-subject rights on its official rights page. You may also contact or complain to the Commissioner.
When making a request, tell us the phone number/account and feature involved. We may need to verify that the request concerns your data. We will not ask you to send a full IC through an ordinary public chat merely to make a privacy enquiry.
11. Children and family members
A parent or guardian should manage online reward, Wallet, Telegram and reminder choices for a child. Pharmacy records concerning a child may still be processed for care, dispensing, safety and legal requirements. Do not submit another adult’s phone, birthday or identity details without their authority.
12. Changes
We may update this notice when features, providers or legal requirements change. The latest date appears at the top. If a change materially affects an existing optional consent, we will request a new choice rather than treating silence as agreement.
Contact Q10 about personal data
Privacy contact: Q10 Pharmacy Management
- WhatsApp: +60 11-5681 1869 / +60 11-6586 0907 · Landline: +60 85-326 939
You can also visit Q10 Pharmacy Riam. Say “privacy request” and specify whether you want access, correction, channel opt-out, Telegram unlinking or deletion. Reply STOP to a Q10 WhatsApp birthday message to withdraw that channel choice.
To report suspected loss, unauthorized access, disclosure or misuse, say “privacy/security incident” and give the approximate date, affected feature and a safe way to contact you. Do not send a full IC/passport, password, secret or active link token through an ordinary public chat. Q10 management will record and assess the report through the operational response described above.