1. Who is responsible for your personal data
Locum.my, operated as a sole proprietorship in Malaysia, is the data controller for the personal data described in this notice. This notice is issued under the Personal Data Protection Act 2010.
Contact for anything in this notice: admin@locum.my.
2. What personal data we process
For practitioners: your full name as registered, your Malaysian Medical Council registration number, your Annual Practising Certificate and its expiry date, your phone number, your email address, your bank name and account number, and — if you choose to add them — an alternative contact email address and a LinkedIn profile.
For clinics: the facility name, its licence or registration number, its address and coordinates, and the contact name, phone number and email address of the person registering.
Generated by using the service: the shifts you post or accept, the times recorded when you clock in and out, and the resulting hours and pay figures. Your device’s position is checked at clock-in to confirm you are at the clinic; it is not retained.
Kept as an activity record: the account actions taken on the service, each with who did it and when. These include shifts posted, edited, accepted, released, attended and deleted; account registrations, profile and document changes, and account deletions; decisions an administrator makes to verify or unverify an account, to block or unblock it, or to grant or revoke its Pro status; and the times you sign in and out. Where a change is recorded, the record holds the names of the fields that changed rather than the new contents of those fields. It also holds enough to make an entry readable: the name of the person or clinic an entry concerns, and, for a shift, its status before and after. It does not record your IP address, your device or your location.
If you turn on notifications: a device token issued by your browser, which identifies that browser on that device so a notification can reach it. It does not tell us who you are beyond the account it is stored against, and it holds no message content.
3. Why we process it
To verify that a practitioner is registered and holds a current practising certificate, and that a clinic is licensed, before either can use the service.
To publish shifts, match practitioners to them, and record what was agreed.
To record attendance. Your device’s position is checked at clock-in only to confirm that the practitioner is at the clinic, and the position itself is not stored — it is not used to track anyone at any other time.
To generate the annual tax ledger for practitioners and the KKM Buku Daftar entry for clinics.
To contact you about your account, a shift, or a verification decision.
Where you have opted in, to send you shift alerts and service updates.
To keep an activity record. It is what lets a disputed shift or an administrative decision be reconstructed, and it is readable only by administrators of the service.
4. Where the data comes from
Almost all of it comes directly from you, at registration or through your profile.
The rest is generated by your use of the service — shift, attendance and payment records — and, if you sign in with Google, your name and email address as supplied by Google.
5. Who we disclose it to
Clinics whose shifts you accept, and practitioners who accept your shifts. When a practitioner accepts a shift, their name, registration number, practising certificate expiry, phone number, email address and LinkedIn profile — where they have given one — are attached to that shift and can be read by the clinic that posted it. The same name, registration number and expiry appear on that clinic’s KKM Buku Daftar, and a clinic’s name and licence number appear on the practitioner’s tax ledger. This exchange is the purpose of the service and cannot be opted out of while using it.
Google, where you choose to sign in with a Google account.
Google Cloud Platform and Firebase, which host the service and store its data on our behalf.
Firebase Cloud Messaging, a Google service, where you turn on notifications. The title and text of a notification pass through Google’s delivery network to reach your device. We send only what is described in section 2 — an account status change — and never the contents of a shift, a document or a message.
Google Calendar, where you choose to add a shift to your calendar. Tapping the button to add a shift to Google Calendar opens a Google window in which you pick the account and grant permission; we then create a single event in that account’s primary calendar, carrying the clinic’s name, its address, the shift’s start and end time, the hourly rate, the expected pay and a link back to the shift. We write that one event and nothing else. We do not read your calendar, we do not see any other event in it, and we do not keep a copy of what we wrote. The access token is held in memory for that browser session only and is never written to disk; you can withdraw it at any time at myaccount.google.com/permissions.
Locum.my’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Telegram, which operates the public channel and the other groups where we post open shift summaries. The summary reaches Telegram because we publish it on its platform, not because Telegram processes data on our behalf, and anyone can read those posts without an account. Section 11 sets out what that summary contains, where it is posted, and what we do when a shift is taken.
Any authority, regulator or court where we are required to disclose by law.
We do not sell personal data, and we do not disclose it to advertisers.
6. Where your data is stored
The database, file storage and server functions are hosted in Google Cloud’s asia-southeast1 region, which is in Singapore. Your personal data is therefore transferred outside Malaysia.
It is held under Google Cloud’s contractual and security commitments, and this notice serves as disclosure of that transfer.
Open shift summaries posted to our public Telegram channel, and to the other Telegram groups described in section 11, are also held outside Malaysia, on infrastructure Telegram operates and we do not. Those copies are not covered by the contractual and security commitments above; they are public posts, held by Telegram on its own terms. Section 11 describes those destinations and the limits of removing a post from them.
Notification delivery is not confined to that region. Where you turn notifications on, the device token and the text of the notification pass through Google’s global messaging infrastructure to reach your device.
7. Whether providing it is obligatory
Your name, registration or licence number, phone number, email address and practising certificate are obligatory. Without any of them we cannot verify the account, and it cannot be approved or used. Your phone number in particular is what a clinic uses to contact you directly about a shift, so without one there is no way for a clinic to reach you.
Your bank details and marketing consent are voluntary. Without bank details a clinic cannot pay you through the details on file; declining marketing has no effect on your account.
Location at clock-in is obligatory for that action alone. Declining it means you cannot clock in through the app, and the shift cannot be recorded as attended.
8. How long we keep it
Account and profile data is kept while the account is open, and deleted on request after it is closed.
Shift, attendance and payment records are kept for seven years after the shift, because they underpin the tax and KKM records both parties may be required to produce. These are not deleted on request while that period runs.
The activity record is kept for seven years, for the same reason. It cannot be edited or deleted by anyone, including us — that is what makes it usable as evidence — so entries about a closed account, including the name it was registered under, remain in it after the account itself is deleted.
A notification device token is kept until you turn notifications off, which deletes it, or until your browser reports it as no longer valid, at which point we delete it automatically.
9. Your rights
You may request access to the personal data we hold about you, and ask us to correct anything inaccurate or out of date. Most of it can be corrected yourself on your profile screen.
You may ask us to limit how we process your data, and you may withdraw your consent. Withdrawing consent for the processing described in section 3 means the account can no longer operate, and we will close it.
You may ask us to transmit your personal data to another service provider, where that is technically feasible.
To exercise any of these, email admin@locum.my. We may ask you to confirm your identity first. If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner, Malaysia.
10. Direct marketing
We do not send shift alerts or service updates today. If we begin to, we will send them by WhatsApp or email only to people who ticked the optional box at registration. That tick is separate from your agreement to the terms, and refusing it does not affect your account.
You can withdraw it at any time by emailing admin@locum.my. This does not stop messages we must send about your account, a shift you accepted, or a verification decision.
11. Security and data breaches
Access to records is restricted by server-side rules: an account can read its own profile and the shift records it is party to. It cannot read another account’s profile. Uploaded documents are scoped to the account that owns them. Traffic is encrypted in transit.
A summary of each shift that is currently open is published so that anyone can browse open slots without an account. That summary carries the clinic’s name, the town and state, the start and end time, the number of hours, the hourly rate, the total pay, any tags the clinic added to describe the shift, any extra benefits the clinic chose to describe, and whether the shift is marked as surge. It carries nothing else. It contains no practitioner details, and no street address, coordinates or contact details for the clinic. The benefits text is written by the clinic in its own words; we block phone numbers, links and email addresses in it, but do not otherwise review it before it appears. A shift stops being published in that public listing the moment it is accepted or closed.
That same summary is also posted automatically to our public Telegram channel at t.me/LocumMy1, which is operated by Telegram outside Malaysia. When a shift is taken or closed we edit that post so it no longer shows the shift. Removal from Telegram is best effort: a message that someone has already forwarded, screenshotted or cached is outside our control.
We also post that summary to other Telegram groups whose organisers have asked for it. Those posts are not edited when a shift is taken. Each one carries a note that it is not kept up to date, together with a link to the shift, and that link always shows whether the shift is still open. What remains in such a group is the clinic’s own advertisement of a slot it once offered — the summary carries no practitioner details at any point.
If a breach occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner and you, as required by the Personal Data Protection Act.
12. Changes to this notice
We may update this notice. The date at the top shows when it last changed, and material changes will be notified to the email address on your account.
13. Contact
Email admin@locum.my for any access request, correction, complaint or question about this notice.