Privacy Policy
Mixup Solution Company Limited
Privacy Policy — Hong Kong & Macau
Introduction
Your privacy and the confidentiality of your personal information is important to Mixup Solution Company Limited ("MixCare Health", "we", "our", "us"). This Privacy Policy ("Policy") sets out how we collect, use, disclose, retain, and protect your personal information in connection with all services provided by MixCare Health, including our self-funded outpatient service, Wellness Marketplace, Flexible Spending Account, Flexible Benefit Solution, and Wellness Events.
This Policy is governed by and complies with the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) ("PDPO") and its six Data Protection Principles. For members and users in Macau, this Policy additionally complies with the Macau Personal Data Protection Act (Lei n.º 8/2005). By using our services, you consent to the practices described in this Policy.
Our Privacy Principles
MixCare Health is committed to protecting your personal data in accordance with the six Data Protection Principles ("DPPs") of the PDPO:
DPP 1 – Collection: We collect personal data only for lawful, specified purposes and in a fair manner, limited to what is necessary for those purposes.
DPP 2 – Accuracy: We take reasonable steps to ensure personal data is accurate and kept up-to-date.
DPP 3 – Use: We use personal data only for the purpose it was collected or a directly related purpose, unless consent is obtained.
DPP 4 – Security: We protect personal data against unauthorised or accidental access, processing, erasure, loss, or use.
DPP 5 – Openness: We make our data policies and practices readily available to the public.
DPP 6 – Access and Correction: We respect your right to access and correct your personal data.
Services Covered by This Policy
This Privacy Policy applies to personal data collected through all MixCare Health services, including:
Self-Funded Outpatient Service: data collected during GP/Specialist consultations, appointment bookings, and claim submissions.
Wellness Marketplace: data collected when you browse, book, and transact with third-party Wellness Providers.
Flexible Spending Account (FSA): data collected to administer your employer-funded benefit balance, eligible claims, and transaction history.
Flexible Benefit Solution: data collected to configure and manage personalised employee benefit packages on behalf of corporate clients.
Wellness Events: data collected for event registration, attendance, feedback, and follow-up communications.
Personal Data We Collect
Categories of Data
We may collect the following categories of personal data:
Identity information: full name, date of birth, staff ID, gender
Contact details: email address, phone number, mailing address
Financial information: bank account details, credit/debit card details, payment transaction records
Health and medical information: appointment records, consultation notes, diagnosis and treatment information, claim documents and wellness receipts
Profile information: profile photo, membership status, benefit entitlements
Usage data: platform activity logs, booking and claim history, session data
Technical data: IP address, device identifiers, browser type, cookie data
How We Collect Data
We collect personal data through:
Online registration, membership applications, and account management on our Platform
Completion of forms, surveys, feedback, or wellness event registration
Email, chat, phone, or SMS communications with our team
Appointment booking and claims submission through the MixCare app or website
Website cookies and tracking technologies (see Cookie Policy)
Third parties such as payment gateways, your employer or plan sponsor, social media platforms, or family members acting on your behalf
How We Use Your Personal Data
In accordance with DPP 3 of the PDPO, we use your personal data only for the purposes for which it was collected or directly related purposes. These include:
Providing, operating, and improving our services, platform, and mobile application
Processing membership applications, renewals, and benefit entitlements
Administering FSA balances, claims processing, and benefit allocation under the Flexible Benefit Solution
Verifying your identity and conducting fraud prevention checks
Processing payments and maintaining financial records
Facilitating appointment bookings with GPs, Specialists, and Wellness Providers
Sending service notifications, appointment reminders, and transactional communications
Conducting wellness event management and post-event follow-up
Displaying your profile image and membership information within the app or website
Conducting market research, analytics, and service improvement (using aggregated or anonymised data where possible)
Complying with applicable laws and regulations, including PDPO requirements and court orders
With your separate consent: sending marketing communications about our services and partner offers
Use of Personal Data in Artificial Intelligence (AI)
MixCare Health may use AI and machine learning technologies to enhance and personalise your experience on our platform. This section explains how your personal data may be processed in connection with AI features.
AI Features We Use
AI features on our platform may include:
Personalised health and wellness recommendations based on your usage history, benefit selections, and stated preferences
Wellness Marketplace search ranking and product recommendations tailored to your profile
FSA and Flexible Benefit optimisation suggestions to help you maximise your benefit credits
Automated processing of claim documents and wellness receipts for eligibility checks
Anomaly detection for fraud prevention and account security
Data Used in AI Processing
AI features may process the following categories of your personal data: usage patterns and platform activity, benefit selections and claim history, health and wellness preferences you provide, and anonymised or aggregated usage data for model training and improvement. We do not use AI to make fully automated decisions that have significant legal effects on you without human oversight.
Legal Basis and Your Rights
AI processing of your personal data is conducted on the legal basis of: (a) performance of our contract with you; (b) compliance with legal obligations; and (c) our legitimate interests in improving service quality, subject to your interests and rights. Where AI processing is based on consent, you may withdraw consent at any time by contacting info@mixcarehealth.com. Withdrawal of consent will not affect processing already carried out.
AI Limitations Disclaimer
AI-generated recommendations and outputs are for informational purposes only. They do not constitute medical advice, diagnosis, or treatment. MixCare Health is not liable for any decisions made based solely on AI-generated outputs. Always consult a qualified healthcare professional for medical decisions.
Sharing Your Personal Data
We may share your personal data with the following categories of recipients, subject to appropriate data processing agreements and safeguards:
Wellness Providers on the Marketplace who fulfil your bookings and services
Your employer or plan sponsor for benefit administration purposes under the FSA or Flexible Benefit Solution
Payment gateway providers and financial institutions for processing transactions
IT service providers, cloud hosting providers, and analytics partners who support our platform operations
Regulatory authorities, law enforcement, or courts as required by law, including compliance with PDPO obligations
We do not sell, rent, or license your personal data to third parties for their own marketing purposes.
Cross-border Data Transfers
Your personal data may be transferred to or processed in jurisdictions outside Hong Kong or Macau (for example, where our cloud service providers are based). We take steps to ensure equivalent data protection standards apply to all transfers, in compliance with Schedule 3 of the PDPO and applicable transfer regulations.
Data Security
In accordance with DPP 4 of the PDPO, we implement appropriate technical and organisational measures to protect your personal data against unauthorised or accidental access, collection, use, disclosure, copying, modification, disposal, or similar risks. These measures include:
End-to-end encryption of sensitive data in transit and at rest
Role-based access controls limiting data access to authorised personnel only
Regular security assessments, penetration testing, and vulnerability management
Staff training on data protection obligations and privacy best practices
Incident response procedures for data breaches, including notification to the Privacy Commissioner for Personal Data (PCPD) where required
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
Membership and account records: for the duration of membership plus 7 years
Health and medical records: as required by applicable medical record retention laws or 7 years, whichever is longer
Financial and payment records: 7 years in compliance with Hong Kong tax and commercial regulations
Marketing communications data: until you withdraw consent or opt out
Upon expiry of the retention period, personal data will be securely deleted or anonymised.
Your Rights
Under the PDPO, you have the following rights in relation to your personal data held by us:
Right of Access (DPP 6): You may request access to personal data we hold about you. We will respond within 40 days of receiving a valid Data Access Request (DAR).
Right of Correction (DPP 6): You may request correction of inaccurate personal data. We will respond within 40 days.
Right to Opt Out of Direct Marketing: You may at any time withdraw consent to the use of your personal data for direct marketing.
Right to Complain: If you believe your rights under the PDPO have been infringed, you may lodge a complaint with the Privacy Commissioner for Personal Data (PCPD) at www.pcpd.org.hk.
To exercise your rights, please contact us in writing at info@mixcarehealth.com, clearly stating the nature of your request. We may charge a reasonable fee for processing Data Access Requests, as permitted under the PDPO.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and app to improve functionality, analyse usage, and personalise your experience. You may manage cookie preferences through your browser settings. Disabling cookies may affect the functionality of certain features.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated Policy on our platform and, where appropriate, by direct notification. The date of the most recent revision is indicated at the top of this Policy. Your continued use of our services after any update constitutes acceptance of the revised Policy.
Contact Us
Mixup Solution Company Limited — MixCare Health
Email: info@mixcarehealth.com
Phone: +852 2323 3132
Website: www.mixcarehealth.com
You also have the right to lodge a complaint with the Privacy Commissioner for Personal Data (PCPD) at www.pcpd.org.hk, or the Office for Personal Data Protection (GPDP) of Macau at www.gpdp.gov.mo.