Scope and our role
This policy explains how [LEGAL ENTITY NAME] (registration number [REG NO]) — trading as Clarity Management — handles personal information. It applies to our website and to the Clarity Management practice management application.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). Two different relationships matter, and the difference decides who you should approach about your information:
Practice staff and website visitors
For the accounts and contact details of the practices we serve, their staff, and visitors to our website, we are the responsible party. This policy governs that information and you can exercise your rights directly with us.
Patients of a practice
For patient records held in the application, the practice is the responsible party and we are its operator. We process patient information only on that practice's instructions. If you are a patient, please direct requests about your records to your clinic — its own privacy notice governs them, and we will refer you there.
Information Officer
POPIA requires us to appoint an Information Officer registered with the Information Regulator. Ours is:
- Name
- [FULL NAME]
- Position
- [POSITION]
- [privacy@yourdomain.co.za]
- Telephone
- [+27 …]
- Postal address
- [POSTAL ADDRESS]
Information we collect
As responsible party, we collect the following about practice staff and website visitors:
| Category | Examples | Source |
|---|---|---|
| Account information | Name, work email address, password (stored only as a cryptographic hash), role and permissions, profile colour and avatar | You, at registration or when an admin invites you |
| Practice information | Practice name, practice number, billing and contact details, logo, consulting rooms and staff list | Your practice administrator |
| Authentication data | Session tokens, sign-in timestamps, password-reset and one-time-PIN records | Generated when you use the Service |
| Technical and log data | IP address, browser and device type, pages and features accessed, error reports and timestamps | Collected automatically |
| Audit records | A log of actions taken in the application, including who viewed or changed a patient record and when | Generated by the Service |
| Support and enquiries | Messages you send us, and the correspondence that follows | You |
| Anti-abuse signals | A reCAPTCHA risk score and related signals collected by Google when you submit the registration form | Google reCAPTCHA v3 — see section 7 |
Patient information
Practices use the application to record information about their patients. Depending on how a practice configures it, this may include names and contact details, identity or medical-aid numbers, date of birth, address, appointment history, clinical notes and diagnoses, audiological findings, hearing-aid fittings and serial numbers, procedures performed, uploaded documents and files, tasks, quotes and invoices.
We hold this information on behalf of the practice. We do not decide what is collected or why. We do not use it for our own purposes, we do not sell it, we do not use it for advertising, and we do not use it to train machine learning models. Our access is limited to what is necessary to operate, support and secure the Service — for example, a support engineer investigating a fault you have reported.
Why we process it
POPIA requires a lawful justification for each processing purpose. Ours are:
| Purpose | Justification under POPIA |
|---|---|
| Creating and administering accounts; providing the Service | Necessary to perform the contract with your practice (s11(1)(b)) |
| Billing, collections and accounting | Contractual necessity and compliance with tax and company law (s11(1)(b), s11(1)(c)) |
| Securing the Service, preventing fraud and abuse, maintaining audit logs | Our legitimate interests and our duty to secure personal information (s11(1)(f), s19) |
| Support, troubleshooting and service communications | Contractual necessity (s11(1)(b)) |
| Improving reliability and usability using aggregated, non-identifying usage data | Legitimate interests (s11(1)(f)) |
| Marketing emails to business contacts | Consent, or an existing customer relationship — you can opt out at any time (s11(1)(a), s69) |
| Processing patient records | On the documented instruction of the practice, as its operator (s20, s21) |
Health and special information
Information about a person's health is special personal information under section 26 of POPIA and may only be processed in limited circumstances. Section 32 permits medical professionals and healthcare institutions to process health information where it is necessary for proper treatment and care, or for the administration of the institution.
Practices rely on that authorisation as responsible party. We process the same information solely as their operator, and we are bound by the confidentiality duty in section 32(4) — anyone who processes health information must treat it as confidential unless a legal duty requires disclosure. Our personnel are bound by written confidentiality undertakings that survive the end of their engagement.
Cross-border transfers
Practice and patient data is hosted in [REGION]. Some of our sub-operators — such as Google's reCAPTCHA and Fonts services — process limited technical data outside South Africa.
Section 72 of POPIA permits transfers outside the Republic only where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, or where the transfer is necessary to perform a contract with or for the benefit of the data subject. We rely on contractual safeguards with each such provider.
How we protect it
Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. Ours include:
- encryption of all traffic in transit using TLS, and encryption of data at rest, including backups;
- authentication by signed access tokens, with passwords stored only as salted hashes and never in readable form;
- role-based access control so Authorised Users see only what their role requires, and strict separation of each practice's data;
- audit logging of access to patient records, so a practice can see who viewed or changed what;
- access to production systems limited to named personnel on a need-to-know basis, under confidentiality undertakings;
- regular backups, patching of dependencies, and [periodic penetration testing].
No system is completely secure. You also play a part: use a strong unique password, do not share accounts, and sign out on shared devices.
How long we keep it
- Account information — for as long as the account is active, and then for [12] months.
- Patient records — for as long as the practice instructs. After a subscription ends, records remain available for export for [30] days and are then deleted or anonymised within [90] days.
- Audit and security logs — [12] months.
- Billing and tax records — five years, as required by South African tax law.
- Backups — rolling backups are overwritten within [35] days.
Note for practices
The National Health Act and HPCSA guidelines require health records to be kept for defined minimum periods — generally at least six years from when a record became dormant, and longer for minors. That duty rests with the practice. Export and archive your records before ending a subscription.
Cookies and local storage
We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics on the application.
The application stores the following in your browser:
-
Authentication token — a signed token kept in
localStorageso you stay signed in between page loads. Removed when you sign out. - Interface preferences — such as your theme, sidebar state and preferred calendar view.
Google reCAPTCHA sets its own cookies on the registration page for abuse detection; that processing is governed by Google's privacy policy. Clearing your browser storage will sign you out and reset your preferences.
Your rights
Under POPIA you have the right to:
- Be told whether we hold information about you, and to request access to it (s23);
- Correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully (s24);
- Object to processing based on legitimate interests, on reasonable grounds (s11(3));
- Withdraw consent where processing relies on it, without affecting processing already carried out;
- Opt out of direct marketing at any time (s69);
- Not be subject to a decision based solely on automated processing that has legal consequences for you (s71). We do not make such decisions.
To exercise these rights, email [privacy@yourdomain.co.za]. Access requests are made on Form 2 under the Promotion of Access to Information Act 2 of 2000, and a prescribed fee may apply. We may ask for proof of identity, and we will respond within the period the law allows.
If you are a patient
Contact your clinic, not us. Your clinic is the responsible party for your records and is best placed to answer. If you approach us, we will pass the request to the clinic and let you know we have done so.
Complaints
Please raise concerns with our Information Officer first — we would like the chance to put things right. You also have the right to complain to the regulator:
- Regulator
- Information Regulator (South Africa)
- Website
- inforegulator.org.za
- Complaints email
- [verify current address on their site]
Security compromises
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA requires notification. We will notify the Information Regulator and the affected practice as soon as reasonably possible after discovering and containing the compromise. Where we act as operator, we will notify the practice so that it can fulfil its own duty to notify affected patients, and we will give it the information it reasonably needs to do so.
Children and minors
Our website and application are not directed at children, and accounts may only be held by adults. Practices do record information about paediatric patients. Under section 35 of POPIA, processing a child's personal information generally requires the consent of a competent person such as a parent or guardian, and obtaining that consent is the practice's responsibility as responsible party.
Changes to this policy
We may update this policy as the Service or the law changes. The “Last updated” date above reflects the current version. For material changes we will give notice by email to account administrators or by in-app notice before the change takes effect.
Contact us
- Privacy enquiries: [privacy@yourdomain.co.za]
- Security reports: [security@yourdomain.co.za]
- Post: [POSTAL ADDRESS]
For the terms governing use of the Service, see our Terms of Service.