Privacy Policy

Last updated: 9 August 2026

1. What we collect

We collect only what is needed to provide the hospital information system:

  • Facility details (name, address, contact information)
  • User details (name, email, job role)
  • System usage logs

2. Patient health data

Patient health data recorded in the system belongs to the healthcare facility using it. MorLuang acts solely as a data processor on that facility’s behalf, as defined by the PDPA.

3. Why we use data

  • To provide the service under contract
  • To improve and develop the system
  • To provide technical support
  • To comply with the law

4. Security

We apply both technical and organisational safeguards, including data encryption, access control and audit logging.

5. Data subject rights

Under the PDPA, data subjects have the right to access, correct, delete or port their data, and to object to its processing.

6. Payments and third parties

When you place an order we collect only what is needed to issue documents and open your system: facility name, contact name, email, phone number, tax identification number and billing address.

Payment is made by transfer or PromptPay directly to us. We do not store card numbers or any payment card data. If you upload proof of payment, that file is kept solely to confirm receipt and for later audit.

If an external payment processor is offered in future, the details needed to complete the transaction will be collected and processed by that provider under its own privacy policy.

7. Contact

Data Protection Officer (DPO): [email protected]

This English text is provided for convenience only. The Thai version of this document is the legally binding one; if the two differ, the Thai version prevails.