Last updated: 5 August 2026
Privacy Policy
1. Introduction and Who We Are
This Privacy Policy explains how QuiKonsult, Inc. (“QuiKonsult,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects your personal data when you use our website, mobile application, and related services (together, the “Platform”), including our AI-assisted doctor discovery, doctor matching, consultation booking, telemedicine facilitation, and doctor-to-doctor collaboration services.
QuiKonsult, Inc. is the personal information controller (PIC) with respect to the personal data we process through the Platform. We are responsible for complying with the Republic Act No. 10173, also known as the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations (“IRR”), and the issuances, circulars, and advisories of the National Privacy Commission (“NPC”).
We value your privacy. This Policy is written in clear and plain language as required by the DPA, so that you can understand what happens to your personal data before you enter it into the Platform. Where practical, we also make key information available in Filipino. This Policy applies to patients, doctors, and all other users of the Platform, and supplements the QuiKonsult Terms and Conditions, which you agree to when you create an account.
2. Definitions
- “Personal data” refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
- “Sensitive personal information”refers to personal information about an individual's health, education, genetic or sexual life, and previous or current health records; as well as other information that may be used to enable identity fraud, including financial information, usernames and passwords, and government-issued identifiers.
- “Processing” means any operation or any set of operations performed upon personal data, including collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure, or destruction.
- “Consent” means any freely given, specific, informed indication of will that signifies agreement to the processing of personal data, evidenced by written, electronic, or recorded means.
- “Data subject” refers to an individual whose personal data is processed.
- “Data protection officer (DPO)” refers to the individual designated by QuiKonsult to ensure Platform-wide compliance with the DPA.
3. Personal Data We Collect
We collect personal data that you provide directly, that we generate when you use the Platform, and that we receive from authorized sources. We collect only data that is adequate, relevant, and not excessive for the purposes declared in this Policy, in accordance with the data privacy principles of transparency, legitimate purpose, and proportionality.
Account and identity data
- Full name, email address, and password for your account.
- Phone number, birth date, age, and sex, when you choose to provide them or when required for booking.
- Government-issued or professional identifiers for doctors, including professional regulation (PRC) details where applicable.
Health data (sensitive personal information)
Because QuiKonsult facilitates health consultations, we process health information, which the DPA classifies as sensitive personal information (SPI). This may include:
- Symptoms, chief complaints, and medical concerns you describe to Kai (our AI-assisted discovery assistant) or in consultation requests.
- Medical history, current medications, allergies, and other clinical information you share with a doctor through the Platform.
- Consultation records, notes, prescriptions, referral letters, and supporting documents you or your doctor upload, share, or generate through the Platform.
- PhilHealth or other health insurance information, when needed for payment or benefits processing.
Your health data is processed only for declared, specified, and legitimate purposes, and only in ways that are compatible with such purposes. You should not share health data through the Platform unless it is necessary for the service you are using.
Payment and transaction data
- Payment method details and billing information needed to process bookings and payments.
- Booking history, consultation schedules, and transaction records.
Device, usage, and technical data
- Device type, operating system, browser, IP address, and network information.
- Logs of your activity on the Platform, pages visited, features used, and search queries.
- Cookies and similar tracking technologies, as described in our cookie notice within the Platform.
Communications and support data
- Records of messages, requests, and communications you send to us, including customer support inquiries.
- Feedback, ratings, and reviews you submit.
Collaboration and case data (doctors and invited clinicians)
When you use our doctor-to-doctor collaboration features, we process:
- Case titles, descriptions, and Case codes;
- Board content, including notes, annotations, drawings, and links you or other Case Members add;
- Files and medical imaging you or other Case Members upload to Boards or Case Files, including DICOM Studies and their metadata;
- Case File categories and notes assigned by a Room Host;
- Room Chat messages, Poll questions, and anonymous Participant ballots;
- Collaboration Invitations, RSVPs, and Participant details; and
- Host, Presenter, and Case membership assignments, and Preparation Board publishing history.
Collaboration content may include identifiable health information discussed between doctors, including imaging and clinical discussion. We process such content as sensitive personal information under this Policy, and access to it is limited to the authorized Participants and Case Members of the relevant Room or Case.
Call and AI Notes data
- Call metadata, such as timing, duration, and Participants, for consultation and collaboration Calls.
- Video is never recorded on the Platform.
- When a Room Host enables AI Notes and every Participant consents, we record the audio of consenting Participants while AI Notes is active, transcribe it into internal Transcript material, and use it to generate Meeting Summaries, Case Summaries, and Case Primers. A Participant who declines consent is never recorded.
- Deleted Chat Message audit copies: restricted original content and revision history behind a deleted Chat Message, retained only for authorized administrator or developer investigation until the Room is deleted or expires, and never used as AI input.
Calendar connection data
- If you connect a Google or Outlook/Microsoft 365 calendar, we access your external calendar events (read-only) to show them in your QuiKonsult Calendar, use them for scheduling conflict checks, and manage QuiKonsult Room events on your behalf.
- External event details are visible only to you and are never shown to other doctors; other doctors see only Free/Busy availability for conflict checks.
- You may disconnect a connected calendar at any time.
Doctors who use the Platform are independent professionals. When you book a consultation, your health data is also shared with the doctor you select, who acts as a separate personal information controller for the health services they provide. Our role is to facilitate the connection and to support the operation of the Platform.
4. Purposes of Processing
We process your personal data for the following purposes, and for no purpose incompatible with them:
- Providing the service: creating and managing your account; matching you with appropriate doctors, including through our AI-assisted matching; processing consultation requests and bookings; facilitating consultations and their documentation; and maintaining consultation records for continuity of care.
- Payments and billing: processing payments, refunds, and receipts; and resolving payment disputes.
- Communication: sending you service notifications, booking confirmations, reminders, and responses to your inquiries.
- AI-assisted discovery and matching (automated processing): analyzing the information you provide — including health-related details you choose to share — to generate doctor recommendations and facilitate booking. The logic of this automated processing is described further in Section 12 of this Policy.
- Doctor collaboration and case management: enabling invited doctors to collaborate in Rooms, prepare and share Boards, manage Cases and Case Files, conduct Polls and Room Chat, and preserve Case History for Case Members, including hosting, storing, and displaying the content they share.
- AI-assisted meeting intelligence (automated processing): with consent, recording and transcribing Call audio and generating Meeting Summaries, Case Summaries, and Case Primers to help doctors review and verify their discussions, as described further in Section 12 of this Policy.
- Calendar and scheduling: showing your connected calendar events to you, checking scheduling conflicts, and showing only Free/Busy availability to other doctors.
- Security and integrity: verifying identities, preventing fraud, unauthorized access, and abuse; protecting the Platform, our users, and our systems; and investigating incidents.
- Legal compliance: complying with laws and regulations applicable to us, including the DPA, the E-Commerce Act, the Consumer Act, health-sector regulations, and lawful requests from regulators, courts, or law enforcement.
- Analytics and improvement (statistical purposes): improving the Platform, its features, and the quality of doctor discovery and booking, using aggregated and, where possible, de-identified data.
- Direct marketing (only with your consent or a valid lawful basis): sending you promotional communications about QuiKonsult services, with an easy and effective opt-out in every communication. We will not send unsolicited commercial communications in violation of the Cybercrime Prevention Act.
5. Basis of Processing
We process personal data only where at least one lawful basis exists under the DPA and its IRR:
- Your consent (DPA Sections 12(a) and 13(a)): because health data is sensitive personal information, we obtain your specific, informed, freely given consent before processing it, including consent given when you create your account, submit a consultation request, or start a telemedicine consultation. Your consent is time-bound and tied to the declared purpose.
- Contract (DPA Section 12(b)): where processing is necessary for the performance of a contract with you, such as facilitating and managing your bookings.
- Legal obligation (DPA Section 12(c)): where we are required to process data by law, regulation, or a lawful order of a court or government agency.
- Protection of life and health (DPA Sections 12(d) and 13(c)):where processing is necessary to protect your life and health or another data subject's, and you are not legally or physically able to give consent.
- Medical treatment (DPA Section 13(e)): where processing is necessary for medical treatment provided by a medical practitioner or institution, subject to adequate safeguards.
- Legitimate interests (DPA Section 12(f)): for security, fraud prevention, and improvement of the Platform, always weighed against your rights and interests.
6. Scope and Method of Processing
We process personal data through a combination of manual and automated means, including automated systems that match you with doctors and generate recommendations. Processing occurs in secure systems operated by QuiKonsult or by our authorized personal information processors (PIPs), who are bound by contract to process data only on our documented instructions and to protect it with appropriate safeguards.
Access to your personal data within QuiKonsult is limited to personnel who need it to perform their duties, and only to the extent necessary for the declared purposes.
7. Recipients and Disclosure
We do not sell your personal data. We disclose it only to the following recipients or classes of recipients, and only for legitimate purposes:
- Doctors and clinics: the licensed physicians and their facilities whom you select or who are matched with you, solely to enable your consultation, booking, and continuity of care. Doctors act as separate personal information controllers for the health services they provide.
- Collaboration participants and Case Members: the doctors and, where enabled, invited clinicians with whom you choose to collaborate. They access only the Rooms, Cases, Boards, and Case Files shared with them, and they process the content they access under their own professional and legal responsibilities.
- Service providers and processors:cloud infrastructure providers, payment processors, AI and data processing services, analytics providers, and other vendors who support the Platform, bound by data processing agreements and subject to the DPA's requirements on processors.
- Regulators and government agencies: agencies with lawful jurisdiction, such as the Department of Health (DOH), the Professional Regulation Commission (PRC), and PhilHealth, when required by law.
- Law enforcement and courts: in response to a lawful court order, subpoena, or other legal process, or to protect the rights, property, or safety of QuiKonsult, its users, or the public.
- The National Privacy Commission: in connection with data subject requests, complaints, breach notifications, and other lawful exercises of its mandate.
- Business partners: where sharing is necessary to provide a service you requested, under a data sharing agreement that meets the requirements of the NPC, and only where your rights remain protected.
- Connected calendar providers: Google and Microsoft, solely to operate the calendar connections you authorize, as described in Section 3.
Where we share data for commercial purposes, we execute data sharing agreements that comply with NPC requirements and ensure you are informed of the recipients, purposes, categories of data shared, and your rights.
8. Cross-Border Transfers
Some of our service providers store or process data in servers located outside the Philippines. When personal data is transferred abroad, we remain accountable for its protection and take steps to ensure the receiving entity provides a level of protection at least comparable to the DPA, such as through the NPC's Model Contractual Clauses for cross-border transfers or other appropriate safeguards.
9. Data Retention
We keep personal data only as long as necessary to fulfill the declared purposes, to comply with legal obligations, and to resolve disputes or establish, exercise, or defend legal claims. Our retention periods depend on the nature of the data:
- Account data: for as long as your account is active, and for a reasonable period after closure to comply with legal or audit requirements.
- Health and medical records: for a longer period consistent with standards applicable to health records and continuity of care, and in any case no longer than necessary for the declared purposes and legal requirements.
- Transaction and payment records: for the period required by tax, payment, and consumer-protection laws.
- Technical logs: for a period reasonably needed for security, fraud prevention, and troubleshooting.
- Collaboration Rooms and Case content: for the applicable retention period selected for a Case (for example 30, 90, 180, or 365 days) or until the Room expires or is deleted. Room Chat and Room Boards are retained or deleted with their Room; Case History is preserved for Case Members for the Case retention period.
- AI Notes audio and Transcripts:recorded audio is hard-deleted at Room expiry and never retained beyond the Room's retention period. Transcripts are internal source material, are not visible to Participants, and are not included in Room or Case exports.
- Deleted Chat Message audit copies: restricted original content is retained only until the Room is deleted or expires, and only for authorized investigation.
- Connected calendar data: external calendar events are accessed only while the connection is active, and connection data is removed or minimized when you disconnect.
- Records required under the Cybercrime Prevention Act: traffic data and subscriber information are preserved for at least six (6) months, and longer when required by law.
When personal data is no longer needed, we dispose of it securely — by deletion, anonymization, or secure destruction — in a manner that prevents further processing, unauthorized access, or disclosure.
10. Security Measures
We implement reasonable and appropriate organizational, physical, and technical security measures to protect your personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing. These include:
- Encryption of data in transit and at rest, where applicable;
- Access controls and role-based permissions that limit access to those with a legitimate need;
- Secure development and change-management practices;
- Monitoring, logging, and incident-response procedures;
- Confidentiality obligations on employees, contractors, and processors; and
- Regular reviews and, where appropriate, security testing of our systems.
No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee its absolute security. You also have a role to play: keep your password confidential and notify us promptly of any suspected unauthorized use of your account.
11. Your Rights as a Data Subject
Under the DPA, you have the following rights, which you may exercise at any time:
Right to be informed
The right to be informed whether personal data pertaining to you has been, is being, or will be processed, including the existence of automated decision-making and profiling. This Policy is part of that information.
Right to object
The right to object to the processing of your personal data, including processing for direct marketing, automated processing, or profiling. Once you object, we will no longer process your data for that purpose, unless we demonstrate a compelling legitimate ground for continued processing.
Right to access
The right to reasonable access to, upon written request, the personal data we hold about you, the purposes of processing, the recipients, the sources, and the methods of processing, as well as a description of the data involved.
Right to rectification
The right to dispute and correct any incomplete, outdated, false, or unlawfully obtained personal data.
Right to erasure or blocking
The right to suspend, withdraw, or order the removal or destruction of your personal data where it is incomplete, outdated, false, or unlawfully obtained; where it is being used for unauthorized purposes; where it is no longer necessary for the declared purposes; where you have withdrawn consent and no other legal ground exists; or where the processing is prejudicial to you or otherwise unlawful.
Right to damages
The right to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data.
Right to data portability
The right to obtain from us a copy of your data in an electronic, structured, and commonly used format, and to transmit it to another personal information controller, where processing is based on consent or contract and is carried out by electronic means.
Right to complain
The right to lodge a complaint with the National Privacy Commission if you believe your rights under the DPA have been violated. The NPC may be reached at www.privacy.gov.ph or by email at [email protected].
How to exercise your rights
To exercise any of these rights, contact our Data Protection Officer at the details in Section 16. We will respond to your request without undue delay, and in no case later than thirty (30) working days from receipt, unless the request is complex or numerous, in which case we may extend the period by a further fifteen (15) working days and will inform you of the reason. These rights are generally free of charge; reasonable fees may only be charged for copies of the data, and never in an exorbitant amount.
Any waiver of your data privacy rights is void under the rules of the NPC, and nothing in this Policy or elsewhere on the Platform shall be construed as such a waiver.
12. Automated Decision-Making and Artificial Intelligence
QuiKonsult uses AI-assisted technology, including our assistant “Kai,” to help you discover and match with appropriate doctors and to support the booking process. This is automated processing of the information you provide, which may include health-related details you choose to share.
- Existence: AI-assisted matching exists in the discovery and booking flow.
- Logic: the system analyzes the symptoms, concerns, preferences, and other information you provide, along with doctor profiles and availability, to generate ranked doctor recommendations and to help you complete a consultation request.
- Significance and consequences: the recommendations help you choose a doctor; they do not diagnose, treat, or substitute for professional medical judgment. A doctor remains responsible for all clinical decisions.
- Human intervention and contestability: you may disregard recommendations at any time and choose any doctor on the Platform. You may also question, contest, or request human review of any automated decision that produces legal effects or significantly affects you by contacting our DPO.
Where automated processing is the sole basis of a decision that produces legal effects or significantly affects you, we will seek your consent beforehand, and we will provide a mechanism for you to obtain human intervention and contest the decision.
AI Notes and AI-generated summaries
QuiKonsult also uses AI to support doctor collaboration. When a Room Host enables AI Notes and every Participant consents, the Platform records the audio of consenting Participants (never video), transcribes it into internal source material, and generates Meeting Summaries, Case Summaries, and Case Primers:
- Existence and logic: AI Notes transcribes consented Call audio and, together with eligible Room Chat and Poll outcomes, synthesizes summaries organized by Case and Room-wide discussion.
- Significance and consequences: AI-generated summaries are presented as unverified. They are not medical records, medical advice, diagnosis, or treatment recommendations, and a doctor must verify them before any clinical reliance.
- Human intervention and contestability: you may flag an issue with any AI-generated summary, request human review, and edit or verify summaries where the Platform provides those controls. A human — the Room Host or a Case Member — retains authority over verification and edits.
- Consent:consent to AI Notes is specific and time-bound to the Call. Any Participant may decline consent, and a declining Participant's audio is never recorded. Consent may be withdrawn as described in Section 14.
13. Breach Notification
In the event of a personal data breach involving your sensitive personal information or other information that may enable identity fraud, and where the breach is reasonably believed to pose a real risk of serious harm, we will notify the National Privacy Commission and you, the affected data subjects, within seventy-two (72) hours from knowledge of or reasonable belief of the breach, and will submit the required full report within the period prescribed by the NPC.
14. Consent and Withdrawal of Consent
By creating an account and checking the consent box on the sign-up form, and by submitting consultation requests or starting consultations on the Platform, you consent to the processing of your personal data, including your health data, for the purposes described in this Policy. Your consent is freely given, specific, informed, and evidenced by your affirmative act.
You may withdraw your consent at any time, at no cost, by contacting our DPO. Withdrawal of consent will not affect the lawfulness of processing that occurred before the withdrawal. Depending on the purpose withdrawn, withdrawal may limit or prevent us from providing services that depend on that processing, such as booking or facilitating consultations. Where a new purpose, scope, or context differs considerably from what you originally consented to, we will obtain fresh consent from you.
15. Children
The Platform is intended for individuals eighteen (18) years of age or older. We do not knowingly collect personal data from children under eighteen (18) without the consent of their parent or legal guardian. If you are under eighteen (18), you may use the Platform only with the involvement and consent of your parent or legal guardian, and your parent or guardian should review this Policy and the Terms and Conditions with you. If we learn that we have collected personal data from a child without proper parental or guardian consent, we will take steps to delete it.
16. Contact Us and the Data Protection Officer
For any questions, requests, or concerns about this Privacy Policy or your personal data, including requests to exercise your data subject rights or withdraw consent, you may contact:
- Data Protection Officer: [email protected]
- General support: [email protected]
- QuiKonsult, Inc., Philippines.
You may also lodge a complaint directly with the National Privacy Commission at www.privacy.gov.ph.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or legal requirements. If we make material changes, we will provide notice through the Platform (for example, by email or an in-app notice) before the change takes effect, and, where the change involves a new processing purpose or scope, we will obtain fresh consent where required by law. The current version of this Policy, with its “Last updated” date, will always be available on this page, and prior versions will be archived.