This notice explains what personal information GetLean collects through this website, its clinical systems, appointment and online-consultation services and WhatsApp support, why we collect it, where it is kept, and the choices you have.
GetLean is a doctor-led telehealth service for GLP-1 weight-loss care in Singapore. The registered legal entity operating this service is COMPOSED MEDICAL GROUP PTE. LTD. (UEN 202632916G). In this notice, "we", "us", and "GetLean" refer to that entity.
What we collect
We collect information through the eligibility questionnaire and, if you proceed, through appointment booking, payment, your booking confirmation and WhatsApp. That includes the email, WhatsApp and online-consultation records described below. Nothing you enter in the questionnaire is saved until you tick the consent box at the final step and submit.
When you complete and submit the questionnaire, we collect:
- Health information you provide — your height and weight (from which a body mass index is calculated), your waist circumference if you choose to give it, which is optional, your age, your sex, your goal weight, any medical conditions you select, whether you are currently taking a GLP-1 medication and which one, and your answers to a short safety screen.
- A body mass index (BMI) calculated from your height and weight.
- Contact details — your name, email address, and mobile number.
- Your NRIC or FIN number — collected at the final step, to verify your identity for a medical consultation and for any prescription issued to you.
- Your residential address — collected at the final step, so that medication can be delivered to you if it is prescribed.
- A consent record — the exact wording of the consent notice you agreed to, its version, and the time you agreed.
- Booking and consultation details — your selected appointment date and time, booking and payment status, and the operational references used to keep the appointment, payment and patient record correctly linked.
- Communication records — your WhatsApp booking-permission record, its exact wording and version, provider message identifiers, timestamps and delivery, bounce, complaint, failure or suppression status.
- Online-consultation details — the private clinic calendar-event identifier and the unique Google Meet joining link for your consultation.
We do not ask for, and this website does not collect, a photograph or scan of your identity card, or any payment card details. Your NRIC or FIN number is not shown in our day-to-day patient list or website analytics. On submission, the Singapore GetLean server sends full identity, contact details, current residential address and the complete clinical questionnaire to Plato Medical before Firestore receives any submission record. An unpaid submitted Plato record may exist.
Firestore retains the exact consent wording, version and timestamps; opaque joins; booking, payment and WhatsApp-choice evidence; and operational care, adherence, retention, courier, message, watcher and approval evidence. It retains only age, sex, height, weight, goal weight, computed BMI, eligibility outcome and a category-level safety flag from the questionnaire. It does not retain NRIC or FIN, any address part, raw conditions, medication answers or names, raw safety answers, waist measurement, the full clinical intake or Plato note body.
Why we collect it
We use this information to:
- Let a Singapore-registered doctor review your answers and assess whether the programme may be suitable before a consultation.
- Verify your identity, create and maintain your patient record in Plato, book the appointment you select, and record the related invoice and payment status.
- Arrange and document consultations, prescriptions and medication delivery where applicable.
- Send the operational booking confirmation and joining details, receive corrections you send us, and identify a failed or undelivered confirmation so the clinic team can follow up.
- Contact you about your booking and, if you become a patient, coordinate your care and provide the adherence support described in this notice.
We do not sell your information. We do not use your health information, your identity details, your contact details or the content of your messages for advertising. We do use information about how the public pages of this website are used, together with the campaign identifiers an advertisement carries, to measure our advertising and to show advertising to people who have visited this website, as described under Cookies, analytics and advertising below.
Consent and required records
We collect the questionnaire information on the basis of the consent you give when you submit it. If you proceed, we also use and retain information as needed to provide and document the care and services you request, operate the clinic, and meet applicable medical-record, accounting, regulatory and legal obligations. We store the exact consent text, version and acceptance time alongside your submission.
Where it is stored
Your submission is stored in Google Firestore, in Google Cloud's Singapore region (asia-southeast1). That Firestore copy stays in that region. It retains the exact consent wording and timestamps, opaque joins, booking, payment, WhatsApp-choice and operational care, adherence, retention, courier, message, watcher and approval evidence. It may retain your name, email address and mobile number only where the existing booking, payment or WhatsApp workflows need those contact fields. It does not retain your NRIC or FIN, any address part, raw clinical answers, the Plato intake note or a note hash.
Your browser never writes to the database directly. When you submit, your answers are sent to a secure server-side function, also running in the Singapore region, which is the only thing that writes to the database.
After you explicitly consent and submit, the Singapore GetLean server creates or matches the Plato Medical clinic-management and electronic-medical-record system patient record first. It sends Plato your name, email, mobile number, NRIC or FIN, current residential address, sex and the complete health questionnaire as a readable clinical intake note, then verifies the patient and note before it writes Firestore's minimum operational projection. If one existing Plato patient is matched, the submitted standard patient fields are deliberately written as the source of truth for this initial intake and then read back exactly; ambiguous matches stop for a human review. An unpaid submitted Plato record can therefore exist. Booking, invoice and payment records follow only if you continue through those steps.
GetLean has confirmed Plato's data-residency, international-transfer and subprocessor arrangements, including export and service-exit treatment, for this clinical-record and delivery-address process.
The booking-confirmation workflow is live: after a confirmed consultation payment it sends a booking email, sends a WhatsApp confirmation where you have given that permission, and creates a private clinic calendar event with a Google Meet joining link. Limited information is therefore processed outside Singapore through Resend's configured Tokyo sending region, Google Meet and WhatsApp, as described below. Vertex AI also processes limited information outside Singapore if you later choose automated WhatsApp support. Health answers, your NRIC or FIN number and your residential address are not included in a booking-confirmation email or private Google Calendar event.
The Plato-embedded clinical workflow is also live. After verified payment, the information needed to identify and care for you is recorded in the matching Plato clinical record. When the doctor uses the GetLean consultation form embedded inside Plato, the structured care plan is saved in GetLean's Singapore Firestore record and a readable consultation summary is written to Plato. Plato receives and processes this information under the clinic's arrangement with Plato Medical. We do not claim that information held or processed by every service provider remains in Singapore; the specific processing locations we know are described in this notice.
Plato identity and delivery fields
Plato is the first persistent clinical destination for a new submission and is the source of truth for the submitted initial patient identity, contact and residential-address fields. Our courier workflow retrieves the current delivery address from Plato Medical only when an authorised team member needs it for delivery, and does not save that retrieved address back into Firestore. Removing fields from an active database does not by itself remove historical backup or point-in-time recovery copies. GetLean has an approved backup and restoration treatment for this process, and Plato Medical's data-residency, export arrangements and service-exit treatment have been confirmed before activation.
Who can access it
Access to submissions is restricted to the authorised team at COMPOSED MEDICAL GROUP PTE. LTD. and the reviewing Singapore-registered doctor, for the purposes described above. The reviewing doctor is referred to here by role, not by name.
Cookies, analytics and advertising
Analytics
We use Google Analytics on public website pages only to understand how people move through the website. It is not loaded in the embedded Plato consultation app or other internal clinical pages.
What we send it: the page address and, where present, approved campaign-attribution parameters such as utm_*, gclid, gbraid, wbraid, fbclid and msclkid; whether you opened and completed the eligibility questionnaire; the questionnaire result; and, if you pay the consultation fee, that a payment of S$20 was completed.
What we never send it: your name, email address, mobile number, NRIC or FIN, residential address, height, weight, BMI, questionnaire answers, submission reference or Stripe session reference. Query parameters other than the approved campaign-attribution parameters are removed before the page address is sent.
Advertising cookies and pixels
We advertise on platforms such as Meta (Facebook and Instagram) and Google, and we use those platforms' cookies, pixels and similar identifiers on the public marketing pages of this website only — the home page, its Chinese version, and the about, articles, contact, how-it-works and pricing pages. They are not loaded on the booking or payment pages, in the embedded Plato consultation app, or on any internal clinical page. We use them to:
- Measure our advertising — learn which advertisements bring people to the website.
- Show advertising to people who have visited this website (often called retargeting or remarketing), including on Facebook, Instagram, Google and the websites and apps in those platforms' advertising networks.
- Reach people whose browsing is similar to that of visitors to this website, using audiences the platform builds from its own data.
What these tools receive: that a browser loaded one of the public marketing pages named above, the page address with any approved campaign-attribution parameters, and the technical information a browser ordinarily sends, such as the browser type, device type and IP address. The platform may set or read its own cookies or identifiers on your browser and may link that visit to an account you hold with it, under that platform's own privacy policy.
What they never receive: your name, email address, mobile number, NRIC or FIN, residential address, height, weight, BMI, questionnaire answers or result, submission reference, booking details, payment details or any of the health information you give us. These tools are not loaded on the pages where that information is entered or shown.
Your choices. You can stop these tools setting cookies by rejecting third-party cookies in your browser. You can also manage ad personalisation directly with the platforms: Meta's Ad preferences and Off-Facebook activity settings, and Google's My Ad Center. Doing any of these does not affect your care, the questionnaire or a booking.
Our page fonts are served from this website itself rather than by a third party, so loading a page makes no font request to Google or anyone else.
Third parties
We share your information only with the service providers that operate our systems, and only to the extent needed to run the service:
- Vercel — hosts this website and serves it to your browser.
- Google Cloud / Firebase — provides the Singapore-region database that stores your submission and the server functions that operate the service. Google Cloud Vertex AI processes limited WhatsApp message content through its global service location when the automated assistant interprets a message or provides the requested assistant function; that processing is outside Singapore and is described in more detail below.
- Google Workspace / Google Calendar / Google Meet — hosts the clinic's monitored email mailbox, and creates the private clinic calendar event and joining link for an online consultation. For your consultation booking, that calendar event contains a pseudonymous booking key, its date and time and the Meet link; it does not contain your name or email address, and you are not added as a calendar attendee. When you join a consultation, Google handles the live connection, audio and video. GetLean does not currently enable recording, transcription or AI meeting notes for these consultations.
- Resend — sends the transactional booking-confirmation email, and receives the email address and first name used for the message, the appointment date and time, Google Meet link, calendar attachment, a pseudonymous submission reference and the resulting delivery-event data. Resend is configured to send through its Tokyo region, outside Singapore. It does not receive your questionnaire health answers, NRIC or FIN number, residential address or payment-card details.
- Plato Medical Pte. Ltd. (clinic management, electronic medical records, appointments and invoicing) — after explicit v0.4 consent, the Singapore GetLean server creates or matches the patient in Plato before any Firestore submission. Plato receives the full identity, name, email, mobile number, current residential address, sex and complete clinical questionnaire as an intake note. For one unambiguous existing match, GetLean deliberately writes the submitted standard patient fields as the source of truth for this initial intake, accepting successful patient and questionnaire save responses without separate post-write content read-backs; ambiguous matches stop for human review. Firestore retains only its minimal operational projection, including name, email and mobile where booking, payment or WhatsApp operations require them, not the NRIC or FIN, address, raw intake or note body. The doctor also uses Plato for clinical notes, prescriptions and invoicing. Plato's confirmed data-residency, international-transfer, subprocessor, export and service-exit arrangements are described under Where it is stored.
- Stripe (payments) — receives your email address, the payment amount and an opaque submission reference. Payment card details are entered directly with Stripe and never touch our systems. Stripe is currently operating in test mode on this pre-launch site, so no real payment is taken.
- Google Analytics — receives the usage data described under Cookies, analytics and advertising above. No health answers, no name, no email.
- Advertising platforms (Meta, Google) — receive the public-page visit information described under Advertising cookies and pixels above, for advertising measurement and retargeting. No health answers, no name, no email, no booking or payment details.
- Meta Platforms / WhatsApp Business Platform — carries messages to and from our active WhatsApp Business number. Where you give the explicit permission described below, it also carries the operational booking confirmation and joining details. It is described in more detail below.
The following social-media integration is not active and receives no data today:
- Meta (Facebook and Instagram) — this integration is not active. If it is enabled, we will receive the public comments people leave on our posts, any direct messages they send those accounts, and the display name Meta shows against them. We do not receive an email address, a phone number, or a friends list, and we do not match a commenter against our patient records. See Deleting data we hold from Facebook or Instagram below.
Booking confirmations and online consultations
This workflow is live. It sends the booking email, sends the WhatsApp confirmation where you have given that permission, and creates the private clinic calendar event and Google Meet joining link.
After your consultation payment is confirmed and the appointment record has been independently checked, GetLean sends one transactional email confirming the appointment, unless that booking has since been cancelled. It contains your first name, the appointment date and time, a unique Google Meet joining link and a calendar attachment. If any detail is wrong, you can reply to that email; replies reach the clinic's monitored Google Workspace mailbox.
WhatsApp is a required operational channel for this workflow, so you actively tick a separate unticked box agreeing to receive GetLean's consultation booking confirmation and joining details on WhatsApp. If you do not agree, you cannot complete the booking. This permission does not cover marketing and does not by itself switch on automated adherence support, which has its own later consent. You can reply STOP at any time to stop future WhatsApp messages.
The Google Calendar event is private and belongs to the clinic host. It contains a pseudonymous booking reference, the appointment time and the Meet link. It does not include your name or email address, you are not added as an attendee, and Google Calendar is instructed not to send you an invitation. Resend is the only service used by this workflow to send the confirmation email.
When you join the Google Meet consultation, Google necessarily handles the live connection, audio and video. GetLean does not currently record or transcribe consultations and does not enable AI meeting notes. We will update this notice and obtain the required approval and consent before enabling any such feature in future.
How long we keep it
We distinguish your electronic patient health record from operational records. The operational records listed below have separate expiry periods; automated deletion may take place after their expiry date.
- Your electronic patient health record — your lifetime plus six years. This covers your clinical record and care information, including the clinic’s patient WhatsApp conversation, care logs, doctor’s recaps, voice notes and transcripts, and supporting care records. For this purpose, lifetime means your actual lifetime, or 110 years where the time of death is unknown. We do not delete your patient health record because six years have passed since your last visit or message. GetLean does not automatically delete these records; any disposal requires a documented review of the applicable retention period and any legal, complaint or regulatory hold. This policy follows MOH Circular 84/2022, Annex A, for electronic medical records.
- A questionnaire that never became a booking — twelve months. If you complete the eligibility questionnaire and do not go on to book and pay for a consultation, the operational submission copy in GetLean’s booking database expires twelve months after you sent it. This does not delete the clinical intake already recorded in Plato; that is retained under the electronic patient health record policy above.
- A message from a number we have no patient record for — ninety days. If you message our WhatsApp number and you are not a patient, your message is deleted automatically ninety days after you sent it. If you later become a patient, your record from that point is kept as a patient record, above.
- Delivery and read receipts — twelve months. The technical records of whether a message we sent reached your phone and whether it was opened are operational, not clinical. They are deleted automatically twelve months after the event.
If the law requires us to keep something for longer — for example while a complaint, claim or regulatory matter is open — we will keep that record for as long as that requires and no longer.
Messaging you on WhatsApp
GetLean operates a WhatsApp Business number. The booking flow sends an operational WhatsApp confirmation, and requires the separate booking permission described above before that confirmation is sent. Ongoing WhatsApp support is offered to patients to support their care between consultations. You do not have to continue with ongoing support or automated adherence messages, and you can stop them at any time.
What we collect when you message us
When you send a message to our WhatsApp Business number, we receive and store:
- The content of your message — whatever you write or send.
- The mobile number you send it from.
- Timestamps — when the message was sent, and when we received it.
- Delivery and read status for messages we send you — whether a message reached your device, and whether it was read.
- Weekly recap voice notes sent by our doctor — the final recording and an automatic transcript are attached to the relevant patient and week. The transcript may contain errors because it is produced automatically; you may ask us to correct it. A discarded recording exists only temporarily in the doctor's browser, is cleared there, and is not uploaded.
Please assume your messages to us may contain health information. People naturally describe symptoms, side effects, doses, and how they are feeling in a chat message. We therefore treat this messaging history as health information and protect it the same way as the rest of your record.
What we use it for
We use WhatsApp messaging for two purposes: care coordination — arranging, confirming, and following up on consultations and on medication — and adherence support — check-ins and reminders that help you stay on the programme as your doctor intends. We do not use WhatsApp messaging for advertising, and we do not sell your messages or share them for marketing.
Automated assistant
An automated assistant answers messages on this number for patients enrolled in the programme. An automated system reads your message in order to respond to it. It sends check-ins and reminders, records what you tell it about your meals, your walking and your training, and answers common questions about the programme from a set of answers written and approved by our doctor.
Ordinary clinic WhatsApp support is available without activating AI food tracking and coaching. This includes clinic-team replies and operational messages about your consultation, payment and delivery. Before we switch on AI food tracking and coaching, we explain its features and processing and offer a WhatsApp Yes/No choice linked to this policy. We record the choice, the policy and consent-text versions, the message that carried the choice and the time of the response. If you choose No, AI food tracking and coaching stays off and you can still message the clinic team. Food and activity information sent before activation is not added to your tracking log; after activation, please send it again if you want it logged.
Clinical questions are not answered by the assistant. Anything describing a symptom, a side effect, a dose or how you are feeling is passed to the clinical team, and the assistant tells you that it has done so. The assistant is not there to give you medical advice, and a Singapore-registered doctor remains responsible for clinical decisions about your care. If at any point you would rather speak to a person, say so in the chat and we will pass it on.
If your number is not on a patient record, the assistant does not reply to you; you receive a single acknowledgement instead.
Where it is stored, and who can access it
Your messages and voice-note transcripts are stored in Google Firestore, and final clinic voice recordings are stored in a private Google Cloud Storage bucket, all in Google Cloud's Singapore region (asia-southeast1) — the same region as the rest of your record. The recording has no public or signed link. Access is restricted to the authorised team at COMPOSED MEDICAL GROUP PTE. LTD. and the reviewing Singapore-registered doctor, for the purposes described above.
Some of what you send is processed outside Singapore, and we want to be plain about which. To interpret a message or provide the requested assistant function, we send the message content to Google Cloud Vertex AI. Some assistant functions also send a limited amount of context needed for that function, such as current-day nutritional totals or confirmed food-allergy information. Meal photographs may also be sent for a meal estimate. This processing occurs through Vertex AI's global service location, outside Singapore. The model cannot clear a clinical flag set by our code and cannot directly write or delete your records; our service validates its output and makes any record changes in Singapore.
Google states that, where it identifies a prompt as involving potential abuse, it may retain that prompt for up to 90 days for abuse monitoring and allow authorised Google personnel to review it. Google states that this material is not used to train or fine-tune its models without permission.
Voice notes are transcribed inside Singapore. If you send a voice note, or our doctor records a short note with your weekly recap, we convert it to text using Google's speech-to-text service pinned to the same Singapore region, so the audio itself does not leave Singapore for transcription.
Messages sent over WhatsApp also pass through Meta Platforms, which operates WhatsApp and the WhatsApp Business Platform, and are handled by Meta under its own terms. That is inherent in using WhatsApp rather than something we add to it.
If you would prefer that your messages were not processed this way, tell us in the chat or email care@getleanclinic.sg. We will turn off automated processing and continue WhatsApp support manually.
How long we keep it
Your WhatsApp conversation with the clinic is part of your patient record and is kept under the lifetime plus six years electronic patient health record policy, along with the recap voice notes and transcripts. Delivery and read receipts are kept twelve months. A message from a number that is not on any patient record is kept ninety days. The full explanation, including what happens if you later become a patient, is under How long we keep it above.
Your choices
There are three separate things here, and they are often confused.
1. You can turn off automated processing but keep manual WhatsApp support. Tell us in the chat, or email care@getleanclinic.sg, and the automated assistant will stop processing your messages. The clinic team can continue to handle later WhatsApp messages manually.
2. You can stop daily check-ins. Send STOP or tell us to stop the messages, and daily check-ins will stop. You can message us again later to restart them. This does not turn off manual WhatsApp support or delete messages already exchanged.
3. You can ask to access or correct your information. Under the PDPA you may ask for a copy of the personal information we hold about you, including your messaging history, and you may ask us to correct it if it is inaccurate or incomplete. Make either request through our Data Protection Officer, below. Where the information forms part of your health record, we correct an inaccuracy by amending or annotating the record rather than by erasing it, so that the record remains a truthful account of your care.
Your rights
Under the PDPA you may:
- Access the personal information we hold about you.
- Correct it if it is inaccurate or incomplete.
- Withdraw your consent for uses that rely on consent. This may affect our ability to continue providing the service. We may continue to retain or use information where permitted or required by applicable law, including applicable medical-record obligations.
- Complain to us, and to the Personal Data Protection Commission of Singapore, if you believe we have mishandled your information.
To make any of these requests, contact our Data Protection Officer.
Deleting data we hold from Facebook or Instagram
If you have commented on one of our Facebook or Instagram posts, or sent those accounts a message, you can ask us to delete what we hold about that.
How to ask. Email care@getleanclinic.sg from the account you would like us to act on, or send us a message on the same Facebook or Instagram account, and say that you want your comment or message data deleted. You do not need to give a reason.
What we delete. The copy we hold of your comment or message, and the display name stored alongside it.
What we cannot delete, and why. Two things, said plainly because people are often surprised by both:
- The comment as it appears on Facebook or Instagram is yours, not ours. It sits on Meta's platform, and only you can remove it there. Deleting our copy does not take it off the post.
- If you are one of our patients, this does not delete your health record. Your consultation, your submission and your WhatsApp messages with us are a medical record, and we are required to keep those — see How long we keep it and Messaging you on WhatsApp in this notice. A request under this section covers social media comments and messages only.
How long it takes. We will acknowledge your request and respond in accordance with applicable requirements.
If you are not satisfied, you can complain to us and to the Personal Data Protection Commission of Singapore — see Your rights.
Data Protection Officer
Our Data Protection Officer is Lester, Director, who can be reached at care@getleanclinic.sg.
Changes to this notice
If we change this notice we will update the version and the date shown at the top of the page. Material changes will be brought to your attention before they take effect. Before applying a materially new use to information collected under an earlier notice, we will notify affected patients and obtain any consent that is required.
Contact
For privacy enquiries, contact Lester, Director, at care@getleanclinic.sg.