top of page

Privacy Policy

Version 2.0.0

Effective January 1st, 2026

PART A — ABOUT THIS POLICY
1. Who we are

1.1 Scribo Limited (“Scribo”, “we”, “our” or “us”) provides cloud practice-management software to healthcare practices in Hong Kong, comprising the Scribo® Clinic and Scribo® Pharmacy modules and related services. Our registered particulars and contact details are set out in Section 24.


1.2 We respect the privacy of every individual whose personal data we handle, and we comply with the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”).


1.3 This Privacy Policy applies to our website at www.scribo.com.hk, to the Scribo® software application, and to the Scribo Services and Additional Services as those terms are defined in our Terms of Service. It does not apply to any service that has its own privacy policy which does not incorporate this one.

2. The two capacities in which we handle personal data

2.1 Where you visit our website, enquire about our products, register a Scribo User Account, are verified by us, are billed by us, or receive communications from us, we decide why and how your personal data is used. In relation to that data we are the data user under the PDPO. Part B of this Policy explains what we do with it, and the rights you have against us.


2.2 Where a clinic or pharmacy uses our software to record information about its patients or customers, that practice — not Scribo — decides why and how that information is used. The practice is the data user; we act as a data processor on its instructions, and we hold the information on its behalf. Part C of this Policy explains what that means, and, importantly, whom a patient should approach to exercise their rights.


2.3 If you are a patient of a clinic or pharmacy that uses our software and you wish to see or correct your medical record, your request must be made to that clinic or pharmacy. We are not permitted to give you access to it, and we are not in a position to judge whether it is accurate. Section 19 explains this further.

3. Definitions

In this Policy:


Anonymised Data” means information, or any portion of it, which has been anonymised so that it no longer renders an individual identifiable, and with respect to which there is no reasonable basis to believe that it could be used to identify an individual, either directly or together with additional information available through legal means from third parties.


Datasets” means sets of secondary data derived from Anonymised Data.


End User” means a patient, customer or other individual whose personal data is recorded in the Scribo Services by a Subscribed Practice.


Personal Data” has the meaning given in the PDPO: data relating directly or indirectly to a living individual, from which it is practicable for the identity of that individual to be directly or indirectly ascertained, and in a form in which access or processing is practicable.


Practice Data” means the data recorded in the Scribo Services by or for a Subscribed Practice, including patient and customer records, consultation and dispensing records, prescriptions, and transaction records. Practice Data includes “Patient Data”, being Personal Data concerning the health of an individual.


Scribo User” means an individual who uses a Scribo User Account to access the Scribo Services.


Subscribed Practice” means a clinic, pharmacy or similar premises which subscribes to the Scribo Services.


Terms of Service” means Scribo’s terms of service as in force from time to time.


Trust Centre” means our online trust centre at https://scribo.trust.site/.


Terms defined in the Terms of Service and used but not defined in this Policy have the meaning given in the Terms of Service.

PART B — WHERE WE ARE THE DATA USER

This Part applies to Personal Data about you, in your own right, as a visitor to our website, an enquirer, a Scribo User, a person we verify, a billing contact, or a recipient of our communications.

4. What we collect

4.1 Your name, job title or professional role, employer or practice, email address, telephone number, postal address, and the content of enquiries and correspondence.


4.2 The details used to register and operate a Scribo User Account, a Scribo Organisation Account or a Scribo Practice Account, including name, email address, telephone number, occupation and title, authentication credentials, role and permission settings, and account activity. If you choose to authenticate using a third-party account, such as Google, you authorise us to obtain account information from that provider.


4.3 Where we verify an organisation or an individual under the Terms of Service, we collect the information necessary to do so, which may include professional registration particulars, licence and permit details, business registration particulars, and documentary evidence you provide. Section 7 explains this.


4.4 Billing contact details, billing address, invoices, and records of payments. Payment card details are collected and held solely by our payment processor. We do not receive or store your card number, expiry date or security code.


4.5 Records of your contact with our support team, including correspondence, and notes of telephone or messaging conversations.


4.6 When you visit our website or use the Scribo Services we may collect your IP address, browser type and version, operating system, referring page, pages viewed, approximate location, device information, and the dates and times of access.


4.7 Where you choose to take part in a survey or in user research, the information you provide. Participation is always optional.


4.8 We may receive information about you from your employer or practice, from a colleague who invites you to join an account, from public registers when verifying professional or business particulars, and from our service providers.


4.9 We do not directly collect from you information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions or trade union membership, and we do not collect information about criminal convictions or offences. This Section concerns information we collect about you in your own right; it does not concern the clinical information that a practice records about its patients using our software, which is dealt with in Part C.

5. Whether you must provide it

5.1 You are not obliged to provide Personal Data to us. However, if you do not provide the information necessary to register or operate an account, to verify an organisation, or to bill for the Scribo Services, we may be unable to provide those services to you or to the practice you act for.

6. What we use it for

6.1 We use the Personal Data described in Section 4 for the following purposes:

(a) providing, maintaining, supporting and securing the Scribo Services and Additional Services;
(b) creating, administering and authenticating accounts, and managing roles and permissions;
(c) verifying organisations and individuals under Sections 7.6 to 7.10 of the Terms of Service;
(d) processing orders, issuing quotations and invoices, collecting payment, and maintaining accounting records;
(e) responding to enquiries and providing customer support and training;
(f) monitoring, analysing and improving the performance, reliability and security of our services, and developing new features and services;
(g) detecting, investigating and preventing fraud, misuse, unauthorised access and breaches of our Terms of Service;
(h) direct marketing, subject to Section 8;
(i) complying with our legal and regulatory obligations, and establishing, exercising or defending legal claims; and
(j) any other purpose you have consented to, or which is directly related to a purpose above.


6.2 We will not use your Personal Data for a new purpose that is unrelated to those above without first obtaining your consent.

7. Verification

7.1 Because our software can be used to generate prescriptions, dispensing records, medicine labels and other clinical documentation, we may check that an organisation registering with us is genuinely a healthcare practice, and that the individuals concerned are who they say they are and hold the registrations they claim. We may do this by contacting you, by asking for documents, and by searching public registers.


7.2 We carry out verification for our own risk-management and regulatory purposes. We are not obliged to verify anyone, we may verify some organisations and not others, and the fact that we have or have not verified an organisation is not an endorsement of it.


7.3 We keep records of verification for as long as the relationship continues, and for seven (7) years afterwards, so that we are able to show what checks were carried out if a question later arises.

8. Direct marketing

8.1 We may use your name, job title, practice, email address, telephone number and postal address to send you information about the Scribo Services and Additional Services, new modules, add-ons and features, events, training, offers, and news about Scribo.


8.2 We will not use your Personal Data in direct marketing unless you have consented, or have indicated that you do not object. Where we ask for your consent we will tell you the kinds of Personal Data to be used and the classes of goods and services to be marketed, and we will give you a channel through which to respond.


8.3 You may tell us at any time to stop using your Personal Data for direct marketing. We will do so without charge, and we will not require you to give a reason. You may opt out by using the unsubscribe link in any marketing message, or by writing to us at the address in Section 24.


8.4 We do not sell, rent or otherwise provide your Personal Data to any third party for that party’s own direct marketing, whether for gain or otherwise.


8.5 Even if you opt out of direct marketing, we may still contact you about the services you have ordered, requested or enquired about, including service announcements, security notices, billing correspondence, changes to our terms, and support responses. These are not direct marketing and you cannot opt out of them while you hold an account.


8.6 We do not use Practice Data, including Patient Data, for direct marketing of any kind, and we do not market to End Users. Where a Subscribed Practice sends appointment reminders or other messages to its own patients through our software, the practice is the sender and is responsible for that communication.

9. Cookies and analytics

9.1 We use cookies and similar technologies on our website and in the Scribo Services. Our Cookie Policy explains which we use, what they do, and the choices available to you.


9.2 We use analytics to understand how our services are used so that we can improve them. Where analytics data is capable of identifying you, we treat it as Personal Data under this Policy.

10. Who we disclose it to

10.1 We may disclose the Personal Data described in Section 4 to the following classes of person:

(a) our employees, contractors and Affiliates, on a need-to-know basis;
(b) our service providers, including hosting, content delivery, payment, communications, customer support and compliance providers. The service providers which process personal data on our behalf are listed in the Trust Centre;
(c) the Subscribed Practice or Organisation you act for, in relation to your use of its accounts;
(d) our professional advisers, including lawyers, accountants, auditors and insurers;
(e) a purchaser or prospective purchaser of our business or assets, or a party to a financing or reorganisation, subject to appropriate confidentiality obligations;
(f) regulators, law enforcement agencies, courts and tribunals, where required by law or by an order of a court or tribunal of competent jurisdiction; and
(g) any other person with your consent.


10.2 We do not disclose Personal Data to any person for that person’s own purposes except as described above.

11. Transfers outside Hong Kong

11.1 Personal Data is stored and backed up in Hong Kong, and is not accessed by us from outside Hong Kong, except where an order for a bespoke solution provides otherwise.


11.2 Where any Personal Data is nevertheless transferred outside Hong Kong, we ensure that it is subject to protections comparable to those required by the PDPO, and we implement the Privacy Commissioner’s recommended model contractual clauses where appropriate.


11.3 The Scribo Services are offered to practices in Hong Kong. This Policy is written by reference to the PDPO and does not address the requirements of the data protection regimes of other jurisdictions.

12. How long we keep it

12.1 We keep Personal Data only for as long as is necessary for the purposes described in Section 6.


12.2 We keep Personal Data for the following periods:

  • Enquiries which do not become customers: Not more than 24 months from last contact

  • Scribo User Account records: Duration of the account, plus 24 months

  • Verification records: 7 years after the end of the relationship (Section 7.3)

  • Billing and accounting records: 7 years, aligning with record-keeping obligations under the Inland Revenue Ordinance (Cap. 112) and the Companies Ordinance (Cap. 622)

  • Support correspondence: 7 years

  • Website and usage logs: 12 months

  • Marketing preferences and opt-out records: For as long as necessary to give effect to the opt-out

12.3 We may keep Personal Data for longer where we are required to do so by law, or where it is necessary for the establishment, exercise or defence of legal claims.


12.4 Personal Data may persist in routine backups after it has been deleted from our live systems. Backups are retained on a rolling basis for thirty-five (35) days and are then overwritten, so that data deleted from our live systems is removed from backups within that period.

13. How we protect it

13.1 We take practicable steps to protect Personal Data against unauthorised or accidental access, processing, erasure, loss or use. Our information security management system is certified to ISO/IEC 27001, and our control framework is described in the Trust Centre.


13.2 Our measures include access controls, encryption of data in transit and at rest, network and application controls, logging of user actions and of changes made to data, segregation of customer environments, personnel screening and training, secure development practices, and vulnerability and patch management.


13.3 No system can be guaranteed to be completely secure. In the event of a security breach affecting Personal Data, we will notify you within seventy-two (72) hours of Scribo acquiring actual knowledge of the breach, subject to any confidentiality obligation owed to a third party. We will tell you what information is at risk, the steps we have taken to protect it, and what we are doing to rectify the breach. Where the breach affects Practice Data, we will notify the Subscribed Practice rather than the individuals concerned, and the practice is responsible for deciding what to tell them.


13.4 You are responsible for keeping your contact details current so that we can notify you. Notification under Section 13.3 is not an admission of fault or liability.

14. Your rights

14.1 You may ask us whether we hold Personal Data about you, and ask for a copy of it.


14.2 You may ask us to correct Personal Data about you which is inaccurate or incomplete.


14.3 You may ask us to delete Personal Data about you. We will do so unless we are required to retain it by law, unless it is necessary for the establishment, exercise or defence of legal claims, or unless deleting it would prevent us from providing services which you continue to receive. Where we are unable to delete it, we will tell you why.


14.4 You may ask us to provide Personal Data which you have given to us, or to transmit it to another person you nominate, in a structured, commonly used and machine-readable format.


14.5 You may ask us to stop using, or to restrict our use of, Personal Data about you where we have no continuing right to use it, or where it is inaccurate or unlawfully held.


14.6 You may object at any time to the use of your Personal Data for direct marketing, and we will stop without charge and without asking your reasons. Section 8.3 explains how.


14.7 Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect anything done before we receive it.


14.8 Requests should be made in writing to the contact in Section 24. We may ask you to provide proof of identity and, where a request is made on your behalf, proof of authorisation. We will respond within thirty (30) calendar days. We may charge a fee for complying with a data access request, which will not be excessive.


14.9 Exercising the rights in Sections 14.3, 14.5 and 14.7 may limit the functionality available to you and, in some cases, may mean that we are no longer able to provide the Scribo Services to you. We will tell you if that is so when you make your request.


14.10 If your request concerns a record held by a clinic or pharmacy in our software, we will not be able to deal with it, and Section 19 explains what to do instead.

15. Complaints

15.1 If you are concerned about how we have handled your Personal Data, please contact us first, using the details in Section 24, so that we have an opportunity to put it right.


15.2 You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, whose details are published at www.pcpd.org.hk.

PART C — WHERE WE ARE A DATA PROCESSOR

This Part concerns Practice Data, including Patient Data: the records that clinics and pharmacies keep about their patients and customers using our software.

16. Who decides what happens to patient records

16.1 The Subscribed Practice is the data user in respect of the Practice Data it records in the Scribo Services. It decides what information is collected, for what purposes it is used, how long it is kept, and to whom it is disclosed.


16.2 Scribo is a data processor. We hold and process Practice Data on the instructions of the Subscribed Practice and for the purpose of providing the Scribo Services. Our obligations to the Subscribed Practice are set out in Schedule 3 to the Terms of Service, which implements the contractual measures required by Data Protection Principles 2(3) and 4(2) of the PDPO.


16.3 Where a Subscribed Practice sits within an organisation containing other practices, access to Practice Data across those practices is controlled by the organisation, not by us. The Terms of Service address this at Sections 8.4.6 to 8.4.8.


16.4 The Scribo Services are used by healthcare professionals who work for more than one practice, including locums. An individual who has been given access by more than one practice is able to reach the records of each of them. Each practice decides who is given access to its records and on what terms, and each is responsible for that decision. A practice which wishes to confine access to its own premises or network may ask us to apply a control restricting access to specified addresses. Sections 8.4.9 to 8.4.11 of the Terms of Service address this.

17. What we do, and do not do, with Practice Data

17.1 We host, store, transmit, back up, retrieve and display Practice Data in order to provide the Scribo Services; we secure and monitor it; we assist practices with support requests; and, where instructed, we migrate it.


17.2 We do not use Practice Data for our own purposes. We do not sell it. We do not use it for direct marketing. We do not disclose it to any third party except as instructed by the Subscribed Practice, as described in this Policy, or where required by law or by an order of a court or tribunal of competent jurisdiction.


17.3 Our personnel access Practice Data only where necessary to provide, support or secure the Scribo Services, and are bound by confidentiality obligations.


17.4 A Subscribed Practice is responsible for ensuring that its own agreements, privacy policies and collection statements permit Practice Data to be provided to Scribo and processed as described in this Policy; for obtaining and maintaining any consent required; for securing all rights necessary for Scribo to receive and process that data; and for informing Scribo, within fifteen (15) calendar days of receiving it, of any objection, opt-out or withdrawal of consent by an individual which affects Scribo’s processing.

18. Aggregated and anonymised data, and model training

18.1 We create aggregated and anonymised data derived from use of the Scribo Services. Before data is used in this way it is stripped of Personal Data, and it is prepared so that it cannot reasonably be used, alone or together with other information reasonably available to us, to identify any individual, practice or organisation.


18.2 We use that aggregated and anonymised data to operate, secure, benchmark, evaluate and improve the Scribo Services, to develop new features and services, and for the training, validation and improvement of machine learning and artificial intelligence models.


18.3 A Subscribed Practice, or the organisation to which it belongs, may tell us not to use data derived from its use of the Scribo Services for the training, validation or improvement of machine learning or artificial intelligence models. The request must be made in writing to the email address in Section 24, and may be made by the Organisation Administrator for a whole organisation or by the Owner of a single practice account. We will confirm in writing when the opt-out has taken effect, which will be within thirty (30) days of our receiving the request.


18.4 An opt-out operates from the date it takes effect. We are not able to reverse the training of a model that has already taken place, and an opt-out does not require us to retrain or delete an existing model. An opt-out does not affect our use of aggregated and anonymised data for the other purposes in Section 18.2, is free of charge, and does not affect the functionality available to the practice.


18.5 Scribo does not claim ownership of, and does not sell, license or otherwise commercialise, any dataset derived from Practice Data. Scribo does not use aggregated or anonymised data for any purpose other than those stated in Section 18.2. Any wider right contained in an earlier version of this Policy, including any right to own or commercialise derived datasets, is withdrawn.

19. If you are a patient or customer of a practice that uses Scribo

19.1 Your medical or dispensing record belongs to the clinic or pharmacy that treats you, not to Scribo. That practice is responsible for it.


19.2 If you wish to see your record, ask for it to be corrected, ask how long it is kept, withdraw a consent you have given, or complain about how it has been handled, please contact the clinic or pharmacy directly. We are not permitted to give you access to a record held by a practice, and we cannot correct it.


19.3 If you contact us about a record held by a practice, we will tell you to approach the practice, and we may notify the practice that a request has been made. We will not disclose the content of any record to you.


19.4 We may assist a practice, at its request, in locating or extracting information so that the practice can respond to your request.


19.5 If you do contact us, please tell us which clinic or pharmacy holds the record, so that we are able to refer your request to it. Without that information we will not be able to identify the practice concerned, and we will not search our systems in order to find it.

20. Electronic Health Record Sharing System

20.1 Some practices using the Scribo Services connect to the Electronic Health Record Sharing System established under the Electronic Health Record Sharing System Ordinance (Cap. 625), commonly known as eHealth or 醫健通.


20.2 That system is operated by the Government, not by Scribo. Whether your information is shared through it, and on what basis, is a matter between you and your healthcare provider, and is governed by that Ordinance and by the sharing consent you give. We act only as a technical means by which a practice connects to it.

21. Service providers

21.1 We engage service providers to process Practice Data on our behalf, including hosting and infrastructure providers. A current list is published in the Trust Centre.


21.2 We impose on each such provider obligations no less protective than those we owe to Subscribed Practices, and we remain responsible for their performance. We give Subscribed Practices at least thirty (30) days’ notice before adding or replacing a provider.

22. Retention, export and deletion of Practice Data

22.1 We retain Practice Data for as long as the Subscribed Practice’s subscription continues.


22.2 After a subscription is suspended or ends, functionality enabling the practice to export its Practice Data remains available for ninety (90) days. After that period we delete or irreversibly de-identify it, except where we are required by law to retain it, where it is necessary for the establishment, exercise or defence of legal claims, or where it remains in routine backups which are overwritten in the ordinary course.


22.3 A practice is responsible for exporting and retaining the records it is required to keep under the laws and professional obligations applicable to it. Those retention periods are often considerably longer than a subscription, and our retention of Practice Data does not discharge them.

PART D — GENERAL
23. Changes to this Policy

23.1 We may amend this Policy. We will publish the amended version with its version number and effective date, and where an amendment is material we will give at least thirty (30) days’ notice.


23.2 We will not use Personal Data already collected for a materially different purpose without first obtaining consent where the PDPO requires it.

24. How to contact us

24.1 Requests, opt-outs and complaints under this Policy should be addressed to the Privacy Officer, using the details below.

Scribo Limited

  • Registered office: Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong

  • Correspondence address: Mail box no. 1017-4, Unit 1017, 10/F, Building 19W, No. 19 Science Park West Avenue, Hong Kong Science Park, Pak Shek Kok, New Territories, Hong Kong

  • Email: team@scribo.com.hk

  • WhatsApp: +852 6311 2012

25. Related documents

25.1 This Policy should be read with our Terms of Service, our Cookie Policy, and the information published in the Trust Centre. Where we act as a data processor, Schedule 3 to the Terms of Service governs our obligations to the Subscribed Practice.

bottom of page