Privacy Policy
Last updated: 10 August 2026
This policy explains what personal information Ekhaya Medical Centre collects through this website, why we collect it, who else touches it, and what rights you have over it. It is written to meet our obligations under South Africa's Protection of Personal Information Act, 2013 (POPIA).
1. Who is responsible for your information
The Responsible Party — the person legally accountable for your information — is:
Ekhaya Medical Centre
Ekhaya Mall, Medical Suites 13C, Embalenhle, 2285, Secunda, Mpumalanga
HPCSA practice number 1440918
Telephone 017 632 9450
Email mehlukomedical@gmail.com
Our Information Officer is [TO BE CONFIRMED — the practice principal]. Any question, request or complaint about your personal information should go to them first.
2. What we collect
We only collect what you actively type into this website. We do not buy information about you, and we do not track you around the internet.
| When you… | We collect |
|---|---|
| Request an appointment | Your name, phone number, the service and practitioner you want, your preferred date and time, whether the visit is in person or telehealth, your medical aid details if you give them, and any note you add. |
| Use the Care Finder | The symptoms and answers you select, so the practice knows why you are coming. |
| Complete a pre-consultation form | Your answers about your symptoms, medical history, medication and related clinical detail, plus your age and sex if given. |
| Simply browse | Our hosting provider keeps short-lived technical logs, including your IP address, for security and reliability. We do not use analytics or advertising trackers. |
3. Health information gets extra protection
Information about your health is special personal information under POPIA section 26, and the law treats it more strictly than an ordinary name and phone number. Your symptoms, medical history and medical aid membership all fall into this category.
We process it on two bases: your explicit consent, and POPIA section 32, which permits medical professionals and healthcare institutions to process health information where it is necessary for proper treatment and care.
Consent is not buried in the small print. The pre-consultation form cannot be submitted without it — our server rejects any submission that does not carry it — and we record the date and time you gave it.
4. Why we use it
- To contact you and confirm the appointment you asked for.
- To let the treating clinician prepare before you arrive, so your consultation is spent on you rather than on paperwork.
- To flag urgent symptoms for prompt clinical review.
- To keep the patient records the HPCSA requires us to keep.
- To keep the website secure and working.
We do not use your information for marketing, and we do not sell or rent it to anyone.
5. Who else sees it
Inside the practice, access is limited to the clinical and reception staff who need it to treat you or arrange your visit. Outside the practice, we use the following service providers — Operators in POPIA's language — who process information strictly on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Stores bookings and pre-consultation forms in a PostgreSQL database | Ireland (eu-west-1) |
| Vercel | Hosts and serves this website, and keeps short-lived server request logs | Global content delivery network |
| Resend | Delivers booking notification emails to the practice | Ireland (eu-west-1) |
| Google Workspace | The practice's email mailboxes, where booking notifications are received | Global |
We may also share information where the law requires it, or with your medical scheme when you ask us to submit a claim on your behalf.
6. Where your information is stored
Your information is currently stored on servers located in Ireland (eu-west-1), not in South Africa.
POPIA section 72 permits this where the destination country is subject to a law that provides a level of protection substantially similar to POPIA. Ireland is subject to the EU General Data Protection Regulation, which meets that standard, and our hosting provider is contractually bound to process the information only on our instructions.
7. How we protect it
POPIA section 19 requires reasonable technical and organisational safeguards. In practice that means:
- All traffic to this site is encrypted in transit (HTTPS), and the database is encrypted at rest.
- Patient tables are protected by row-level security and carry no public access policies whatsoever. The website's public credentials cannot read a single patient record — we have tested this directly.
- Records are reachable only through our own server, never from your browser.
- Notification emails to the practice deliberately exclude your clinical answers, and mask medical aid numbers.
- We keep an audit trail of staff access to patient records.
No system is perfectly secure. If a breach ever affects your information, POPIA section 22 requires us to notify both the Information Regulator and you, and we will.
8. How long we keep it
- Clinical records: 6 years from your last consultation, and for patients under 18, until their 21st birthday, in line with HPCSA guidance.
- Appointment requests that did not become a consultation: 12 months.
- Contact details for booking purposes: 24 months.
When a retention period ends we delete the information or de-identify it so it can no longer be linked to you.
9. Your rights
Under POPIA you may:
- Ask what information we hold about you, and get a copy (section 23).
- Ask us to correct or delete information that is wrong, misleading, irrelevant, excessive or out of date (section 24).
- Object to how we are using it, on reasonable grounds (section 11(3)).
- Withdraw consent at any time. This does not affect processing already carried out, and we may still be required to retain your clinical record.
- Complain to the Information Regulator.
To exercise any of these, contact our Information Officer using the details in section 1. We may need to verify your identity first — it protects you if we do. We will respond within a reasonable time, and in any event as required by law.
10. Children
We treat information about patients under 18 as belonging to a child, and we rely on the consent of a parent or guardian. A child may be brought to the practice by a parent or guardian who completes these forms on their behalf.
12. Complaints
Please raise concerns with our Information Officer first — most issues are resolved quickly. If you are not satisfied, you may complain to:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: complaints.IR@justice.gov.za
Enquiries: enquiries.IR@justice.gov.za
https://inforegulator.org.za
13. Changes to this policy
We update this policy when the way we handle information changes — for example when the database moves to a South African region. The date at the top always reflects the current version. Material changes affecting how we use health information will be brought to your attention rather than made quietly.