EKHAYAMedical Centre← Back to site

Privacy Policy

Last updated: 10 August 2026

This policy explains what personal information Ekhaya Medical Centre collects through this website, why we collect it, who else touches it, and what rights you have over it. It is written to meet our obligations under South Africa's Protection of Personal Information Act, 2013 (POPIA).

If this is an emergency, do not use this website. Call 10177 for an ambulance or go to your nearest emergency department. Nothing on this site is medical advice or a diagnosis, and no form on it is monitored around the clock.

1. Who is responsible for your information

The Responsible Party — the person legally accountable for your information — is:

Ekhaya Medical Centre
Ekhaya Mall, Medical Suites 13C, Embalenhle, 2285, Secunda, Mpumalanga
HPCSA practice number 1440918
Telephone 017 632 9450
Email mehlukomedical@gmail.com

Our Information Officer is [TO BE CONFIRMED — the practice principal]. Any question, request or complaint about your personal information should go to them first.

2. What we collect

We only collect what you actively type into this website. We do not buy information about you, and we do not track you around the internet.

When you…We collect
Request an appointmentYour name, phone number, the service and practitioner you want, your preferred date and time, whether the visit is in person or telehealth, your medical aid details if you give them, and any note you add.
Use the Care FinderThe symptoms and answers you select, so the practice knows why you are coming.
Complete a pre-consultation formYour answers about your symptoms, medical history, medication and related clinical detail, plus your age and sex if given.
Simply browseOur hosting provider keeps short-lived technical logs, including your IP address, for security and reliability. We do not use analytics or advertising trackers.

3. Health information gets extra protection

Information about your health is special personal information under POPIA section 26, and the law treats it more strictly than an ordinary name and phone number. Your symptoms, medical history and medical aid membership all fall into this category.

We process it on two bases: your explicit consent, and POPIA section 32, which permits medical professionals and healthcare institutions to process health information where it is necessary for proper treatment and care.

Consent is not buried in the small print. The pre-consultation form cannot be submitted without it — our server rejects any submission that does not carry it — and we record the date and time you gave it.

4. Why we use it

  • To contact you and confirm the appointment you asked for.
  • To let the treating clinician prepare before you arrive, so your consultation is spent on you rather than on paperwork.
  • To flag urgent symptoms for prompt clinical review.
  • To keep the patient records the HPCSA requires us to keep.
  • To keep the website secure and working.

We do not use your information for marketing, and we do not sell or rent it to anyone.

5. Who else sees it

Inside the practice, access is limited to the clinical and reception staff who need it to treat you or arrange your visit. Outside the practice, we use the following service providers — Operators in POPIA's language — who process information strictly on our instructions:

ProviderWhat they doWhere
SupabaseStores bookings and pre-consultation forms in a PostgreSQL databaseIreland (eu-west-1)
VercelHosts and serves this website, and keeps short-lived server request logsGlobal content delivery network
ResendDelivers booking notification emails to the practiceIreland (eu-west-1)
Google WorkspaceThe practice's email mailboxes, where booking notifications are receivedGlobal

We may also share information where the law requires it, or with your medical scheme when you ask us to submit a claim on your behalf.

6. Where your information is stored

Your information is currently stored on servers located in Ireland (eu-west-1), not in South Africa.

POPIA section 72 permits this where the destination country is subject to a law that provides a level of protection substantially similar to POPIA. Ireland is subject to the EU General Data Protection Regulation, which meets that standard, and our hosting provider is contractually bound to process the information only on our instructions.

We are in the process of moving this database to a South African region so that patient information is stored locally. This page will be updated when that move is complete.

7. How we protect it

POPIA section 19 requires reasonable technical and organisational safeguards. In practice that means:

  • All traffic to this site is encrypted in transit (HTTPS), and the database is encrypted at rest.
  • Patient tables are protected by row-level security and carry no public access policies whatsoever. The website's public credentials cannot read a single patient record — we have tested this directly.
  • Records are reachable only through our own server, never from your browser.
  • Notification emails to the practice deliberately exclude your clinical answers, and mask medical aid numbers.
  • We keep an audit trail of staff access to patient records.

No system is perfectly secure. If a breach ever affects your information, POPIA section 22 requires us to notify both the Information Regulator and you, and we will.

8. How long we keep it

  • Clinical records: 6 years from your last consultation, and for patients under 18, until their 21st birthday, in line with HPCSA guidance.
  • Appointment requests that did not become a consultation: 12 months.
  • Contact details for booking purposes: 24 months.

When a retention period ends we delete the information or de-identify it so it can no longer be linked to you.

9. Your rights

Under POPIA you may:

  • Ask what information we hold about you, and get a copy (section 23).
  • Ask us to correct or delete information that is wrong, misleading, irrelevant, excessive or out of date (section 24).
  • Object to how we are using it, on reasonable grounds (section 11(3)).
  • Withdraw consent at any time. This does not affect processing already carried out, and we may still be required to retain your clinical record.
  • Complain to the Information Regulator.

To exercise any of these, contact our Information Officer using the details in section 1. We may need to verify your identity first — it protects you if we do. We will respond within a reasonable time, and in any event as required by law.

10. Children

We treat information about patients under 18 as belonging to a child, and we rely on the consent of a parent or guardian. A child may be brought to the practice by a parent or guardian who completes these forms on their behalf.

11. Cookies

This website sets no cookies of its own and runs no analytics or advertising trackers. Some third-party content, such as the embedded map, may set its own cookies when it loads. The details are set out in our Cookie Policy.

12. Complaints

Please raise concerns with our Information Officer first — most issues are resolved quickly. If you are not satisfied, you may complain to:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: complaints.IR@justice.gov.za
Enquiries: enquiries.IR@justice.gov.za
https://inforegulator.org.za

13. Changes to this policy

We update this policy when the way we handle information changes — for example when the database moves to a South African region. The date at the top always reflects the current version. Material changes affecting how we use health information will be brought to your attention rather than made quietly.

Questions about anything on this page? Call 017 632 9450 or WhatsApp 069 976 8651, and ask for the Information Officer.