§ Legal
This policy applies to people who visit our website, complete the Longevity Baseline, send an enquiry, or otherwise interact with Vivre Labs. The Platform is operated by Vivre Labs, with intended operations in Malaysia, Indonesia, and Thailand. Clinical services, when launched, are delivered by Vivre's clinical partners under their own statutory licenses.
Vivre operates a deliberate separation between two categories of data. This is structural, not cosmetic. Marketing & enquiry data - information you provide when visiting the website, completing the Baseline, sending an enquiry, or communicating with us before clinical care. Vivre Labs is the controller of this data. Clinical & health data - biomarkers, lab results, imaging, consultation notes, prescriptions, and any other information generated in the course of supervised clinical care. This data is held under the custody of the treating physician and clinical facility as required by Malaysia's PHFSA, Indonesia's Health Law 17/2023, and Thailand's Sanitarium Act and Medical Council rules.
Clinical data, when generated, is held in a healthcare-capable managed cloud (AWS, Google Cloud, or Microsoft Azure), with the storage region pinned to the patient's market. Vivre Labs does not use decentralized, distributed, or blockchain-based storage for any form of personal health information. Encryption is AES-256 at rest, TLS 1.2 or higher in transit, with managed key rotation. Access is role-based, with patient identifying information separated from clinical records, and logged on a tamper-evident audit trail.
Your identifying information (name, contact) is held in a separate identity vault and mapped to an internal opaque identifier. Lab results, biomarkers, and clinical records are stored keyed only by that opaque identifier. Resolving the opaque identifier back to a person is a privileged, audit-logged operation restricted to your treating physician in clinical context. When Vivre shares aggregated cohort data for clinical research, that dataset is generated by a further de-identification step that removes direct identifiers AND quasi-identifiers. Removing the name alone is not, and is not treated by us as, de-identification.
Subject to the law of your market, you have rights to access, correct, withdraw consent, request deletion of marketing data, object to processing, and lodge a complaint with the data-protection authority in your market. Malaysia - Department of Personal Data Protection (JPDP), PDPA 2010 (as amended 2024). Indonesia - the authority designated under UU 27/2022 PDP Law. Thailand - Office of the Personal Data Protection Committee (PDPC), PDPA 2019. To exercise any right, contact privacy@vivre.[domain].
We do not sell personal data. We do not run targeted advertising or cross-site tracking. We do not collect health data through unsecured channels (Telegram, WhatsApp, email forms). We do not store personal health information on decentralized or blockchain-based systems. We do not pay affiliates, influencers, or third parties on a per-patient or per-sale basis to refer patients to the Platform.
While Vivre Labs is in a pre-launch / demo state, no actual clinical care is being delivered. Information you provide during the pre-launch period is held under the marketing-data provisions of this policy. The market-specific, counsel-certified versions of this policy will replace this interim document at clinical launch.
For questions about this policy: privacy@vivre.[domain]. The full version of this policy, including detailed sections on lawful basis, cross-border transfers, retention, and children, is available on request and in the project documentation.
Are you 18 years of age or older?