Privacy Policy

Last updated12 July 2026

This Privacy Policy explains how Axtra Health Sdn Bhd (Company Registration No. 1646544-K) ("Axtra Health", "we", "us", or "our"), the operator of the Theo & Thea platform (the "Platform"), collects, uses, discloses, and protects your personal data. It should be read alongside our PDPA Notice, which is the formal notice required under the Personal Data Protection Act 2010 ("PDPA").

Registered office: No. 26, Jalan Eko Botani 2E, Persiaran Eko Botani 2, Taman Eko Botani 2, Iskandar Puteri, 79100 Johor Bahru, Johor Darul Ta'zim, Malaysia. Contact: admin@axtrahealth.com.

1. Who this policy covers

This policy applies to anyone who visits theoandthea.com, creates a patient account, submits a health assessment, books a consultation, or otherwise uses the Platform. It also applies to doctors, pharmacists, and staff accounts, though the categories of data collected differ from patient accounts as set out below.

Theo & Thea is a platform, not a pharmacy. Assessment review, prescribing, and compounding are carried out by independent licensed professional partners — currently Amber Pharmacy Sdn Bhd (compounding), with additional pharmacists and doctors joining over time (see Professional partners). Where a partner processes your data as part of delivering your care, they do so as an independent data controller for the clinical decisions they make, and this policy describes what Axtra Health itself collects and shares with them.

2. Personal data we collect

Account and identity data

Full name, date of birth, sex, email address, phone number, and password (stored as a salted hash — we never see or store your plaintext password).

Health data

Answers to health assessment questionnaires, medical history, current medications, allergies, lifestyle information, consultation notes, prescription and protocol records, and any documents you upload (for example blood test results). This is treated as sensitive personal data under the PDPA and is handled with additional access controls, described in Section 5.

Delivery and fulfilment data

Delivery method (self-pickup or courier delivery), and — where you choose delivery — recipient name, phone number, and shipping address.

Payment data

We do not collect or store your bank card, online banking, or DuitNow login credentials. For manual bank transfer, DuitNow, or QR payments, we retain the reference details and proof-of-payment file you upload so a staff member can verify and reconcile your payment.

Communications

Enquiries you submit through contact or partner forms, and any correspondence with our support team.

Technical and usage data

IP address, browser and device information, and basic access logs generated automatically by our hosting and authentication infrastructure for security and troubleshooting purposes. We do not run third-party advertising or analytics trackers on the Platform.

3. Why we collect and use your data

  • To create and administer your account and verify your identity.
  • To route your assessment to a licensed pharmacist and, where needed, a doctor, so they can review it and propose a protocol or prescription.
  • To enable compounding, dispensing, and delivery or pickup of your order by our licensed pharmacy partners.
  • To process and reconcile manual payments, and to keep the financial and clinical records a licensed pharmacy is required to keep.
  • To send you operational emails — for example payment confirmation, protocol updates, refill reminders, and consultation scheduling.
  • To respond to enquiries you submit and to communicate with professional partners about partnership matters.
  • To maintain the security, integrity, and audit trail of the Platform, and to detect and prevent fraud or misuse.
  • To comply with our legal and regulatory obligations.

We do not use your health data for marketing, and we do not sell your personal data to any third party.

4. Who we share your data with

We share your data only where necessary to deliver the Platform and your care:

  • Professional partners. The pharmacist and, where your pathway requires it, the doctor assigned to review your assessment, and the licensed pharmacy that compounds or dispenses your order (currently Amber Pharmacy Sdn Bhd).
  • Courier partners. If you choose delivery rather than self-pickup, your recipient name, phone number, and address are shared with the courier engaged to deliver your order.
  • Infrastructure providers. We use Supabase for database hosting, authentication, and file storage, and Resend for transactional email delivery. These providers process data on our behalf under their own data processing terms and do not use your data for their own purposes.
  • Regulators and legal process. Where required by law, court order, or a lawful request from a Malaysian regulatory authority (for example in connection with a pharmacy or medicines inspection).

We do not share your data with advertisers, data brokers, or for any purpose unrelated to delivering the Platform.

5. International data transfer

Our infrastructure providers may process and store data on servers located outside Malaysia. Where this happens, we take reasonable steps to ensure your data continues to receive a standard of protection comparable to the PDPA, consistent with section 129 of the PDPA.

6. Data security

Health and account data is encrypted in transit and at rest. Access to patient records is restricted by role — for example, a pharmacist can only see assessments and orders assigned to them, and a doctor can only see cases referred to them — enforced at the database level, not just in the application. Every clinically significant action (review, approval, dispensing, release) is logged for audit purposes.

No system is perfectly secure. If we become aware of a data breach that is likely to result in significant harm to you, we will notify you and the Department of Personal Data Protection where required by law.

7. Data retention

We retain account and health data for as long as your account is active, and afterward for the period required by Malaysian pharmacy and health record-keeping obligations, whichever is longer. Where you close your account or request deletion, we retain the minimum records legally required (for example, prescription and dispensing records) and delete or anonymise the rest.

8. Your rights

Under the PDPA, you have the right to:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Withdraw consent to processing, subject to any retention we are legally required to keep (for example, dispensing records).
  • Limit the processing of your personal data in certain circumstances.

To exercise any of these rights, email admin@axtrahealth.com. We will respond within 21 days as required by the PDPA. We may need to verify your identity before actioning a request.

9. Cookies

We use only the strictly necessary session cookie set by our authentication provider to keep you signed in. We do not use advertising cookies, third-party tracking pixels, or analytics cookies.

10. Children

The Platform is intended for individuals aged 18 and above. We do not knowingly collect personal data from anyone under 18.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above, and where the change is significant, we will notify account holders directly.

12. Contact

Questions about this policy or how we handle your data can be sent to admin@axtrahealth.com, or by post to the registered office address above.