Privacy Policy for SMRP Automator (Dietetics)
Last Updated: July 10, 2026
Version: 2.4 (Post-V2.5.6 Telemetry Realignment)
1. Introduction
The SMRP Automator (Dietetics) ("we", "us", or "the Extension") is a productivity tool designed strictly for authorized use within the Malaysia Ministry of Health (MOH) ecosystem. It automates data entry for Dietetic modules within the SMRP Portal (MyHDW).
We are committed to protecting the sensitive data handled by this tool. This Privacy Policy explains what information is processed, how it is used, and the strict account requirements for operation.
2. Data Collection, Usage, and Sharing
The Extension processes data solely for the purpose of automating form entries, verifying software licenses, and compiling performance diagnostics. We do not collect, store, sell, or transmit any medical or patient data to external servers or third parties. All patient data remains completely local to your device.
A. Types of Data Processed
The Extension accesses and processes the following types of information:
- Account Information: Your authenticated Google account email address (used strictly for access control and licensing tier checks).
- User Configuration Inputs: Dietitian Name, AHP Number, Prefix configurations, Spreadsheet ID, and Sheet Names.
- Google Sheets Data: Clinical and patient metrics (IC Number, Diagnosis, Diet Type, Visit Date, and Nutrition Support parameters) extracted from the Google Sheet you explicitly link.
- SMRP Portal Data: System-generated identifiers (Registration Numbers, active visit parameters) visible on the target
myhdw.moh.gov.my domain.
- Anonymous Performance Telemetry: System runtime durations, single-action execution tallies, multi-row batch summaries (success/failure counts), and manual override kill switch ("Stop Automation") frequencies.
B. How Data is Used
All sensitive medical data processing occurs locally within your specific browser instance.
- Read: The Extension pulls designated rows of data from your Google Sheet using secure Google Sheets API calls.
- Store (Volatile RAM): Patient information is temporarily staged inside your browser’s volatile session memory (
chrome.storage.session). This prevents Protected Health Information (PHI) from ever being written to your local physical storage drive.
- Write: The Extension programmatically injects this text into the corresponding SMRP Portal data-entry inputs on your behalf.
- Clear & Auto-Wipe: Temporary patient data staged in RAM is instantly wiped out upon completion of the row execution. If left unattended during manual validation checks, a 60-second background failsafe timer automatically triggers a complete cleanup cycle.
- Operational Syncing: Performance telemetry aggregates (e.g., total execution time, batch success/failure ratios, manual stop click counts) are cached locally and periodically flushed to a secure database to monitor extension stability and portal performance.
C. Data Sharing and Disclosure
We strictly adhere to the following data sharing policies:
- No Third-Party Sharing: We do not share, transfer, or disclose your Google User Data or spreadsheet records to any third parties, advertisers, data brokers, or external servers.
- No Human Access to PHI: The developer has zero visibility or access to your spreadsheet details or private clinical records.
- No AI Training: Your clinical workflows and text inputs are never used to train or optimize Machine Learning or Artificial Intelligence models.
- Sole Transfer Target: The only transfer of medical data occurs locally on your device, moving text from your Google Sheet directly into the Malaysia Ministry of Health SMRP Portal (
myhdw.moh.gov.my) upon your explicit command.
3. Permissions and Justification
The Extension requests the following permissions to function:
identity: Required to authenticate your Google Account securely using OAuth2, allowing the Extension to read your linked Google Sheet.
identity.email: Required to securely retrieve your account email address to verify your software license tier and ensure compliance with authorized organizational account requirements.
storage: Required to save non-sensitive settings (e.g., Spreadsheet ID, Prefix) on disk, and to hold temporary patient data payloads securely in RAM while moving between windows.
scripting & activeTab: Required to inject the automation script into the SMRP Portal (myhdw.moh.gov.my) to fill forms automatically.
host_permissions:
https://sheets.googleapis.com/*: To fetch rows from your spreadsheet.
https://myhdw.moh.gov.my/*: To navigate and complete form automation on the SMRP portal.
4. Data Retention and Security
- Strict Patient Data Isolation: No patient data, Protected Health Information (PHI), or spreadsheet content is ever transmitted to external databases. The developer has zero access to your medical logs.
- Cloud Telemetry Synchronization: To ensure runtime stability and track portal performance, the extension transmits non-identifiable, operational metrics (user email, execution seconds added, batch success counts, failure counts, and stop button click counts) to a secure Cloudflare D1 SQL database via an encrypted HTTPS POST pipeline. No clinical notes, text parameters, or patient data are ever included in this payload.
- Zero-Trust Storage Architecture: User workspace settings (e.g., historical sequence counters, last processed row dates, spreadsheet settings) are securely retained on your local physical device (
chrome.storage.local) to enable retrospective backlogged entries across browser restarts. All private patient details are isolated strictly to volatile memory and are permanently deleted when Chrome is closed.
- Secure Transmission: All communication between the Extension and external APIs occurs directly via HTTPS using standard OAuth2 protocols.
5. Google API Services User Data Policy
The SMRP Automator (Dietetics) use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Handling of Health / Medical Data
This Extension is designed to process Protected Health Information (PHI).
- No Data Persistency: The Extension acts strictly as a data conduit (copy-paste tool). It does not retain medical records after the automation action is complete.
- Local Processing Only: All processing occurs on the client-side (your local computer). No patient data is sent to the cloud other than the direct, encrypted connection between your browser and your authorized Google Sheet.
7. User Responsibility & Account Governance
STRICT REQUIREMENT: Usage of this extension is restricted to authorized Ministry of Health personnel.
- Authorized Google Workspace Account: You MUST use an official government-issued Google Workspace account (e.g., @moh.gov.my under MyGovUC).
- Prohibition and Enforcement against Personal Accounts: You are strictly prohibited from using personal Gmail accounts (e.g.,
@gmail.com). The extension actively features a programmatic gateway blocker that detects and instantly revokes access tokens for unauthorized personal accounts to maintain data compliance.
- SMRP Portal Authorization: You explicitly warrant that you possess valid, government-authorized credentials to access and enter data into the SMRP Portal (
myhdw.moh.gov.my).
- This extension does not bypass any authentication mechanisms. It is intended solely to assist users who already have legitimate, authorized access to perform data entry.
- Enterprise Management: By using an
@moh.gov.my account, you ensure that the data access remains under the administration, audit, and security policies of the MyGovUC administrators.
- Liability: The developer is not liable for data breaches resulting from the user's failure to adhere to these account security requirements. You are responsible for ensuring you have the legal authorization to access the patient data in the linked Google Sheet and the target SMRP Portal.
8. Changes to This Policy
We may update our Privacy Policy from time to time. You are advised to review this page periodically for any changes. These changes are effective immediately after they are posted on this page.
9. Contact Us
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at:
hooyf@moh.gov.my