Clarity Management logo Clarity Management
  • Features
  • How it works
  • Terms
Sign In

Privacy Policy

Effective date: [DATE] Last updated: 1 August 2026 Version: 1.0

Contents

  1. Scope and our role
  2. Information Officer
  3. Information we collect
  4. Patient information
  5. Why we process it
  6. Health and special information
  7. Who we share it with
  8. Cross-border transfers
  9. How we protect it
  10. How long we keep it
  11. Cookies and local storage
  12. Your rights
  13. Complaints
  14. Security compromises
  15. Children and minors
  16. Changes to this policy
  17. Contact us

Scope and our role

This policy explains how [LEGAL ENTITY NAME] (registration number [REG NO]) — trading as Clarity Management — handles personal information. It applies to our website and to the Clarity Management practice management application.

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). Two different relationships matter, and the difference decides who you should approach about your information:

Practice staff and website visitors

For the accounts and contact details of the practices we serve, their staff, and visitors to our website, we are the responsible party. This policy governs that information and you can exercise your rights directly with us.

Patients of a practice

For patient records held in the application, the practice is the responsible party and we are its operator. We process patient information only on that practice's instructions. If you are a patient, please direct requests about your records to your clinic — its own privacy notice governs them, and we will refer you there.

Information Officer

POPIA requires us to appoint an Information Officer registered with the Information Regulator. Ours is:

Name
[FULL NAME]
Position
[POSITION]
Email
[privacy@yourdomain.co.za]
Telephone
[+27 …]
Postal address
[POSTAL ADDRESS]

Information we collect

As responsible party, we collect the following about practice staff and website visitors:

Category Examples Source
Account information Name, work email address, password (stored only as a cryptographic hash), role and permissions, profile colour and avatar You, at registration or when an admin invites you
Practice information Practice name, practice number, billing and contact details, logo, consulting rooms and staff list Your practice administrator
Authentication data Session tokens, sign-in timestamps, password-reset and one-time-PIN records Generated when you use the Service
Technical and log data IP address, browser and device type, pages and features accessed, error reports and timestamps Collected automatically
Audit records A log of actions taken in the application, including who viewed or changed a patient record and when Generated by the Service
Support and enquiries Messages you send us, and the correspondence that follows You
Anti-abuse signals A reCAPTCHA risk score and related signals collected by Google when you submit the registration form Google reCAPTCHA v3 — see section 7

Patient information

Practices use the application to record information about their patients. Depending on how a practice configures it, this may include names and contact details, identity or medical-aid numbers, date of birth, address, appointment history, clinical notes and diagnoses, audiological findings, hearing-aid fittings and serial numbers, procedures performed, uploaded documents and files, tasks, quotes and invoices.

We hold this information on behalf of the practice. We do not decide what is collected or why. We do not use it for our own purposes, we do not sell it, we do not use it for advertising, and we do not use it to train machine learning models. Our access is limited to what is necessary to operate, support and secure the Service — for example, a support engineer investigating a fault you have reported.

Why we process it

POPIA requires a lawful justification for each processing purpose. Ours are:

Purpose Justification under POPIA
Creating and administering accounts; providing the Service Necessary to perform the contract with your practice (s11(1)(b))
Billing, collections and accounting Contractual necessity and compliance with tax and company law (s11(1)(b), s11(1)(c))
Securing the Service, preventing fraud and abuse, maintaining audit logs Our legitimate interests and our duty to secure personal information (s11(1)(f), s19)
Support, troubleshooting and service communications Contractual necessity (s11(1)(b))
Improving reliability and usability using aggregated, non-identifying usage data Legitimate interests (s11(1)(f))
Marketing emails to business contacts Consent, or an existing customer relationship — you can opt out at any time (s11(1)(a), s69)
Processing patient records On the documented instruction of the practice, as its operator (s20, s21)

Health and special information

Information about a person's health is special personal information under section 26 of POPIA and may only be processed in limited circumstances. Section 32 permits medical professionals and healthcare institutions to process health information where it is necessary for proper treatment and care, or for the administration of the institution.

Practices rely on that authorisation as responsible party. We process the same information solely as their operator, and we are bound by the confidentiality duty in section 32(4) — anyone who processes health information must treat it as confidential unless a legal duty requires disclosure. Our personnel are bound by written confidentiality undertakings that survive the end of their engagement.

Who we share it with

We do not sell personal information. We share it only as set out below.

Sub-operators

We use the following service providers, each under a written contract requiring them to protect the information and process it only on our instructions:

Provider Purpose Location
[HOSTING PROVIDER] Application and database hosting, backups [REGION]
Google (reCAPTCHA v3) Bot and abuse protection on the registration form. Google receives your IP address and interaction signals. United States and other Google regions
Google Fonts Serving the typefaces used on our pages. Your browser requests font files directly from Google, which receives your IP address. United States and other Google regions
[EMAIL PROVIDER] Sending transactional email such as password resets, one-time PINs and appointment communications [REGION]
[PAYMENT PROCESSOR] Subscription payments. We do not store full card numbers. [REGION]

Others

  • Your practice. Administrators at your practice can see the account and audit information of their Authorised Users.
  • Professional advisers. Auditors, lawyers and accountants under duties of confidentiality.
  • Law enforcement and regulators. Where we are legally compelled. We will tell the affected practice unless we are prohibited from doing so.
  • A successor. If our business is merged or sold, information may transfer to the acquirer, subject to this policy. We will give notice before that happens.

Cross-border transfers

Practice and patient data is hosted in [REGION]. Some of our sub-operators — such as Google's reCAPTCHA and Fonts services — process limited technical data outside South Africa.

Section 72 of POPIA permits transfers outside the Republic only where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, or where the transfer is necessary to perform a contract with or for the benefit of the data subject. We rely on contractual safeguards with each such provider.

How we protect it

Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. Ours include:

  • encryption of all traffic in transit using TLS, and encryption of data at rest, including backups;
  • authentication by signed access tokens, with passwords stored only as salted hashes and never in readable form;
  • role-based access control so Authorised Users see only what their role requires, and strict separation of each practice's data;
  • audit logging of access to patient records, so a practice can see who viewed or changed what;
  • access to production systems limited to named personnel on a need-to-know basis, under confidentiality undertakings;
  • regular backups, patching of dependencies, and [periodic penetration testing].

No system is completely secure. You also play a part: use a strong unique password, do not share accounts, and sign out on shared devices.

How long we keep it

  • Account information — for as long as the account is active, and then for [12] months.
  • Patient records — for as long as the practice instructs. After a subscription ends, records remain available for export for [30] days and are then deleted or anonymised within [90] days.
  • Audit and security logs — [12] months.
  • Billing and tax records — five years, as required by South African tax law.
  • Backups — rolling backups are overwritten within [35] days.

Note for practices

The National Health Act and HPCSA guidelines require health records to be kept for defined minimum periods — generally at least six years from when a record became dormant, and longer for minors. That duty rests with the practice. Export and archive your records before ending a subscription.

Cookies and local storage

We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics on the application.

The application stores the following in your browser:

  • Authentication token — a signed token kept in localStorage so you stay signed in between page loads. Removed when you sign out.
  • Interface preferences — such as your theme, sidebar state and preferred calendar view.

Google reCAPTCHA sets its own cookies on the registration page for abuse detection; that processing is governed by Google's privacy policy. Clearing your browser storage will sign you out and reset your preferences.

Your rights

Under POPIA you have the right to:

  • Be told whether we hold information about you, and to request access to it (s23);
  • Correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully (s24);
  • Object to processing based on legitimate interests, on reasonable grounds (s11(3));
  • Withdraw consent where processing relies on it, without affecting processing already carried out;
  • Opt out of direct marketing at any time (s69);
  • Not be subject to a decision based solely on automated processing that has legal consequences for you (s71). We do not make such decisions.

To exercise these rights, email [privacy@yourdomain.co.za]. Access requests are made on Form 2 under the Promotion of Access to Information Act 2 of 2000, and a prescribed fee may apply. We may ask for proof of identity, and we will respond within the period the law allows.

If you are a patient

Contact your clinic, not us. Your clinic is the responsible party for your records and is best placed to answer. If you approach us, we will pass the request to the clinic and let you know we have done so.

Complaints

Please raise concerns with our Information Officer first — we would like the chance to put things right. You also have the right to complain to the regulator:

Regulator
Information Regulator (South Africa)
Website
inforegulator.org.za
Complaints email
[verify current address on their site]

Security compromises

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA requires notification. We will notify the Information Regulator and the affected practice as soon as reasonably possible after discovering and containing the compromise. Where we act as operator, we will notify the practice so that it can fulfil its own duty to notify affected patients, and we will give it the information it reasonably needs to do so.

Children and minors

Our website and application are not directed at children, and accounts may only be held by adults. Practices do record information about paediatric patients. Under section 35 of POPIA, processing a child's personal information generally requires the consent of a competent person such as a parent or guardian, and obtaining that consent is the practice's responsibility as responsible party.

Changes to this policy

We may update this policy as the Service or the law changes. The “Last updated” date above reflects the current version. For material changes we will give notice by email to account administrators or by in-app notice before the change takes effect.

Contact us

  • Privacy enquiries: [privacy@yourdomain.co.za]
  • Security reports: [security@yourdomain.co.za]
  • Post: [POSTAL ADDRESS]

For the terms governing use of the Service, see our Terms of Service.

Clarity Management
  • Home
  • Terms of Service
  • Privacy Policy

© Clarity Management. All rights reserved.