Trust Centre

Policies, privacy & certifications.

Full transparency on how we handle data, security and compliance.

Privacy Policy
CareLive collects only the health and account data needed to deliver CKM staging and platform services. Personal data is processed under explicit user consent, never sold to third parties, and handled in line with GDPR, Hong Kong PDPO and China PIPL principles. Users may access, correct, export or delete their data at any time.
Data Security & Encryption Policy
All health data is encrypted with AES-256 at rest and TLS 1.3 in transit. Access is role-based with multi-factor authentication, and every access event is logged in immutable audit trails. Security practices are aligned with ISO/IEC 27001 and SOC 2 frameworks, with regular penetration testing and vendor security review.
Data Processing Agreement (B2B)
For organisational customers, CareLive acts as data processor under a formal DPA. B2B dashboards display only aggregated, de-identified population metrics; individual-level data is visible only where the individual has granted explicit, revocable consent. Data residency options are available for Hong Kong, mainland China and international deployments.
Health Data Interoperability
CareLive's data layer is aligned with HL7 FHIR (Fast Healthcare Interoperability Resources) standards, enabling secure integration with electronic health records, laboratory systems, insurer platforms and national health-data infrastructures where authorised.
Cookie & Analytics Policy
Our website uses only essential cookies and privacy-respecting, anonymised analytics. No advertising trackers. Language preference is stored locally in your browser.
Terms of Service
CareLive is a health-engagement platform, not a medical device and not a substitute for professional medical advice, diagnosis or treatment. CKM staging shown in the platform is an informational screening aid; clinical decisions belong to qualified healthcare professionals.