Privacy Policy for SMRP Automator (Dietetics)
Last Updated: January 14, 2026
Version: 1.0
1. Introduction
The SMRP Automator (Dietetics) ("we", "us", or "the Extension") is a productivity tool designed strictly for authorized use within the Ministry of Health (MOH) ecosystem. It automates data entry for Dietetic modules within the SMRP Portal (MyHDW).
We are committed to protecting the sensitive data handled by this tool. This Privacy Policy explains what information is processed, how it is used, and the strict account requirements for operation.
2. Data Collection and Usage
The Extension processes data solely for the purpose of automating form entries. We do not collect, store, sell, or transmit your data to any external servers or third parties.
A. Types of Data Processed
The Extension accesses and processes the following types of information:
- User Inputs: Therapist Name, AHP Number, Spreadsheet ID, and Sheet Names.
- Google Sheets Data: Patient information (Name, IC Number, Diagnosis, Diet Type, Visit Date) retrieved from the Google Sheet you explicitly link.
- SMRP Portal Data: Visit information (Registration Numbers, Dates) visible on the
myhdw.moh.gov.my page.
B. How Data is Used
All data processing occurs locally within your browser instance.
- Read: The Extension reads a specific row of data from your Google Sheet using the Google Sheets API.
- Store (Temporarily): Data is temporarily saved in your browser’s local storage (
chrome.storage.local) to facilitate transfer between the extension popup and the SMRP webpage.
- Write: The Extension automatically types this data into the SMRP Portal forms on your behalf.
- Clear: Temporary patient data in storage is overwritten or cleared upon completion of the automation task.
3. Permissions and Justification
The Extension requests the following permissions to function:
identity: Required to authenticate your Google Account securely using OAuth2, allowing the Extension to read the Google Sheet you specified.
storage: Required to save your configuration (e.g., Spreadsheet ID, RN Prefix) and to temporarily hold patient data while the automation moves between tabs.
scripting & activeTab: Required to inject the automation script into the SMRP Portal (myhdw.moh.gov.my) to fill forms automatically.
host_permissions:
https://sheets.googleapis.com/*: To fetch data from your spreadsheet.
https://myhdw.moh.gov.my/*: To perform automation actions on the SMRP portal.
4. Data Retention and Security
- No Remote Storage: The developer has no access to your data. The Extension does not connect to any developer-controlled servers, analytics services, or databases.
- Local Storage: User settings (Spreadsheet ID, RN Sequence) are stored locally on your device. Session-specific data (Therapist Name) is stored in
chrome.storage.session and is cleared when the browser is closed.
- Secure Transmission: All communication between the Extension and Google APIs occurs directly via HTTPS using standard OAuth2 protocols.
5. Google API Services User Data Policy
The SMRP Automator (Dietetics) use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Handling of Health / Medical Data
This Extension is designed to process Protected Health Information (PHI).
- No Data Persistency: The Extension acts strictly as a data conduit (copy-paste tool). It does not retain medical records after the automation action is complete.
- Local Processing Only: All processing occurs on the client-side (your local computer). No patient data is sent to the cloud other than the direct, encrypted connection between your browser and your authorized Google Sheet.
7. User Responsibility & Account Governance
STRICT REQUIREMENT: Usage of this extension is restricted to authorized Ministry of Health personnel.
- Authorized Google Workspace Account: You MUST use an official government-issued Google Workspace account (e.g., @moh.gov.my under MyGovUC).
- Prohibition of Personal Accounts: You are strictly prohibited from using personal Gmail accounts (e.g.,
@gmail.com) with this extension. Using a personal account to store or process patient data is a violation of Ministry of Health data governance policies.
- SMRP Portal Authorization: You explicitly warrant that you possess valid, government-authorized credentials to access and enter data into the SMRP Portal (
myhdw.moh.gov.my).
- This extension does not bypass any authentication mechanisms. It is intended solely to assist users who already have legitimate, authorized access to perform data entry.
- Enterprise Management: By using an
@moh.gov.my account, you ensure that the data access remains under the administration, audit, and security policies of the MyGovUC administrators.
- Liability: The developer is not liable for data breaches resulting from the user's failure to adhere to these account security requirements. You are responsible for ensuring you have the legal authorization to access the patient data in the linked Google Sheet and the target SMRP Portal.
8. Changes to This Policy
We may update our Privacy Policy from time to time. You are advised to review this page periodically for any changes. These changes are effective immediately after they are posted on this page.
9. Contact Us
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at:
hooyf@moh.gov.my