Legal

Privacy policy.

How Reylo Labs Pte. Ltd. collects, uses, shares and protects personal data — for people who visit this site, for clinic staff who use Reylo, and for the patient data a clinic entrusts to us.

Last updated: 24 September 2026·UEN 202642579R · Singapore
REYLO / LEGAL · PRIVACY

This is the policy in force, not a template. It describes what Reylo Labs Pte. Ltd. actually does with personal data today. Where something is not yet built or not yet contracted, we say so rather than claim it. If a practice changes, this page changes with it and the date above moves.

1. Who we are

Reylo Labs Pte. Ltd. (UEN 202642579R), registered at 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914, SG (“Reylo”, “we”, “us”) operates the Reylo platform and the website at reylo.ai. Reylo is an AI patient-coordination system used by aesthetic and medical-tourism clinics.

Our governing framework is Singapore’s Personal Data Protection Act 2012 (“PDPA”). Where a clinic operates in Indonesia, Indonesia’s Personal Data Protection Law (UU PDP, Law No. 27 of 2022) also applies to that clinic’s patient data. Where we handle the personal data of people in the European Union or the United Kingdom, we apply the GDPR standard to that data.

We have appointed a Data Protection Officer as the PDPA requires. Reach the DPO at privacy@reylo.ai, or by post at the registered address above.

2. Whose data this covers, and our role

Reylo wears two different hats, and which one applies decides who you deal with.

  • Website visitors, clinic accounts and clinic staff — Reylo is the controller. We decide why and how this data is processed, and this policy governs it end to end.
  • Patient and customer data inside a clinic’s workspace — the clinic is the controller and Reylo is a data intermediary (a processor). Conversations, contacts, bookings, proposals and payment status belong to the clinic. We process them on the clinic’s documented instructions under our data processing terms, and we do not use them for our own purposes. Patients should also read the privacy notice of the clinic they are dealing with, and should send requests about their own data to that clinic.

3. What we collect, and why

From this website

  • What you type into a form. The demo and early-access forms collect your name, email, and optionally your clinic name, location, WhatsApp number, monthly lead volume and message. We use it to reply to you and to arrange a demo. That is the only reason we ask.
  • Technical data that comes with any web request — IP address, browser and device information, and the page you requested — logged by our hosting provider to serve the site and keep it secure. We store the browser user-agent string alongside a form submission as a spam and abuse signal.

From clinic staff using the Reylo platform

  • Account data: name, work email, phone number, role, clinic and workspace details, and login credentials.
  • Billing data: plan, invoices and payment-method metadata. Full card numbers are handled by the payment processor, never stored by us.
  • Usage and security data: log data, IP address, device and browser information, feature usage, and audit records of actions taken in a workspace.

Customer data we process for a clinic, as its intermediary

  • Messages and media exchanged with patients over the channels a clinic connects, principally WhatsApp.
  • Contact identifiers such as phone number, name and messaging handle.
  • Lead, booking, treatment-proposal, invoice and payment-status records, and the stage a patient has reached in the clinic’s pipeline.
  • Whatever else a clinic’s staff chooses to record about a patient in their workspace. Some of this is health-related data, and we treat all of it as sensitive.

We use this data only to run the service the clinic asked for: to route and answer patient messages, book and remind, follow up, raise and settle invoices, and give the clinic its own operational analytics. We do not sell personal data, and we do not use a clinic’s patient data to advertise to anyone.

4. Legal bases and consent

Under the PDPA we collect, use and disclose personal data for purposes a reasonable person would consider appropriate in the circumstances, and which we have notified. We rely on your consent, and on the other bases the PDPA permits, including performance of a contract you are party to and our legitimate interests in operating and securing the service. Where the GDPR applies, the equivalent bases are consent, contract, legal obligation and legitimate interests.

You may withdraw consent at any time by writing to privacy@reylo.ai. We will act on it within a reasonable period. Withdrawing consent may mean we can no longer provide part or all of the service to you, and we will tell you if that is the case.

5. Who we share data with

We disclose personal data only to service providers who need it to run the service, under contracts that require them to protect it to a standard comparable to the PDPA. We do not sell personal data and we do not share it with data brokers.

  • Cloud hosting and infrastructure. The Reylo platform runs on Amazon Web Services in the Singapore region (ap-southeast-1). This website runs on our own server infrastructure.
  • Messaging channels a clinic connects. Principally WhatsApp (Meta Platforms). Messages to and from a patient necessarily pass through the channel that patient chose, on that provider’s own terms.
  • AI providers. Where a clinic enables AI assistance, message content needed to produce a reply is sent to a large-language-model provider — currently OpenAI and Anthropic, depending on the model configured. AI features are off by default and are enabled per clinic.
  • Payment processors chosen by the clinic for patient payments — Xendit is the provider integrated today; others may be added and this list will be updated when they are.
  • A payment processor for our own subscription billing, which handles card details directly so that we do not hold them.
  • Transactional email and calendaring providers, to deliver one-time codes, intake forms, proposals, invoices and video-consultation links.
  • Professional advisers, and authorities where we are legally required to disclose, or where disclosure is necessary to investigate abuse or protect someone from harm.

Where we describe a category rather than name a company, it is because the specific vendor is still being selected or varies by clinic. We will name it here once it is fixed.

6. International transfers

We are based in Singapore; our clinics and their patients are in Indonesia, Korea, the Gulf, Brazil and elsewhere. Personal data therefore crosses borders. Where we transfer personal data out of Singapore, we take reasonable steps to ensure the recipient is bound to a standard of protection comparable to the PDPA, ordinarily through contractual data-protection clauses. Where Indonesia’s PDP Law governs a clinic’s patient data, the clinic and Reylo apply the transfer safeguards it requires. Where GDPR data is transferred outside the EEA or the UK, we use Standard Contractual Clauses or an equivalent approved mechanism.

7. How long we keep data

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires, and then delete or anonymise it.

  • Website enquiries: kept while we are in contact with you and for a reasonable period afterwards, then deleted on request.
  • Clinic account and billing records: kept for the life of the account, and afterwards only for the period Singapore accounting and tax law requires.
  • Customer data held as an intermediary: kept according to the clinic’s instructions, and deleted or returned when the clinic’s agreement with us ends.

8. How we protect it

We use reasonable technical and organisational measures appropriate to the sensitivity of the data: encryption in transit, per-clinic tenant isolation enforced in the database itself and not only in application code, role-based access control, scoped credentials, audit logging, and limits on which staff can access production systems. Access is granted on a need-to-know basis and reviewed.

No system is perfectly secure, and we will not pretend otherwise. If something goes wrong, section 9 says what we do.

9. Data breach notification

If a data breach occurs that is likely to result in significant harm to affected individuals, or that affects a number of individuals at or above the threshold prescribed by the PDPA, we will notify the Personal Data Protection Commission and the affected individuals within the timeframes the PDPA sets. Acting as a data intermediary, we will notify the clinic concerned without undue delay after becoming aware of a breach affecting its customer data, so the clinic can meet its own obligations as controller.

10. Your rights, and how to use them

Under the PDPA you may:

  • Access the personal data we hold about you and be told how it has been used or disclosed in the past year.
  • Correct personal data that is inaccurate or incomplete.
  • Withdraw consent to our continued collection, use or disclosure of it.

Where the GDPR applies, you additionally have rights to erasure, restriction, portability and objection, and the right to complain to your local supervisory authority.

To exercise any of these, email privacy@reylo.ai with enough detail for us to identify your records. We will acknowledge your request and respond within the period the law requires, and we will tell you in advance if a fee applies to an access request, as the PDPA permits. We may need to verify your identity first.

If you are a patient of a clinic that uses Reylo, send your request to that clinic. The clinic is the controller of your data and decides these requests. We will assist it as its intermediary, and we will forward a request to the right clinic if you send it to us by mistake.

11. Cookies and analytics

This marketing website sets no cookies of its own and runs no advertising or cross-site tracking pixels. Where site analytics are enabled, we use a cookieless, aggregate measurement tool that does not build a profile of you or follow you across other sites.

The Reylo application, which clinic staff sign in to, uses strictly necessary cookies and browser storage to keep you signed in and to remember preferences such as language, theme and which workspace you were last in. They are required for the application to work, and they do not hold patient content. You can clear them in your browser at any time, but you will be signed out.

12. Children

Reylo is a tool for businesses and their authorised staff. It is not directed to children and we do not knowingly collect personal data directly from children through it. Where a clinic records data about a minor who is its patient, the clinic is the controller of that data and is responsible for obtaining any consent the law requires from a parent or guardian.

13. Changes to this policy

We may update this policy as the product and our vendors change. The current version is always the one on this page, with its date at the top. If a change materially affects how we handle your personal data, we will tell account holders directly rather than rely on you noticing the date.

14. Contact us, and how to complain

Privacy questions, requests and complaints go to our Data Protection Officer at privacy@reylo.ai, or by post to Reylo Labs Pte. Ltd., 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914. For anything else you can reach us at jasper@reylo.ai or ramon@reylo.ai.

We would like the chance to put a problem right first. If we do not resolve it to your satisfaction, you may complain to Singapore’s Personal Data Protection Commission at www.pdpc.gov.sg. If you are in the EU or UK, you may also complain to your local data protection authority.