Privacy Policy

Last updated: 28 August 2026

This policy explains what personal information Ekhaya Medical Centre collects through this website, why we collect it, who else touches it, and what rights you have over it. It is written to meet our obligations under South Africa's Protection of Personal Information Act, 2013 (POPIA).

If this is an emergency, do not use this website. Call 10177 for an ambulance or go to your nearest emergency department. Nothing on this site is medical advice or a diagnosis, and no form on it is monitored around the clock.

1. Who is responsible for your information

The Responsible Party — the person legally accountable for your information — is:

Ekhaya Medical Centre
Ekhaya Mall, Medical Suites 13C, Embalenhle, 2285, Secunda, Mpumalanga
HPCSA practice number 1440918
Telephone 017 632 9450
Email dr.tio@ekhayamedicalcentre.co.za

Our Information Officer is Dr Tio Laosebikan and can be reached at dr.tio@ekhayamedicalcentre.co.za. Any question, request or complaint about your personal information should go to them first.

2. What we collect

We only collect what you actively type into this website. We do not buy information about you, and we do not track you around the internet.

3. Health information gets extra protection

Information about your health is special personal information under POPIA section 26, and the law treats it more strictly than an ordinary name and phone number. Your symptoms, medical history and medical aid membership all fall into this category.

We process it on two bases: your explicit consent, and POPIA section 32, which permits medical professionals and healthcare institutions to process health information where it is necessary for proper treatment and care.

Consent is not buried in the small print. The pre-consultation form cannot be submitted without it — our server rejects any submission that does not carry it — and we record the date and time you gave it.

4. Why we use it

We never sell or rent your information to anyone. We send marketing only to people who have specifically asked for it — see section 5.

5. Newsletters and practice news

We send occasional practice news and general health information by email, but only if you asked us to. The booking form has a tick box for it, and it is unticked by default. Leaving it alone means you get nothing, which is how it should be — the consent you give when you book is consent to be treated, not consent to be marketed to. That distinction is what section 69 of POPIA requires.

What we will never send you under that tick box:

Some messages are not marketing and you will get them whether or not you ticked the box, because they are part of the service you asked us for:

If you have unsubscribed, we stop sending those too.

You can stop hearing from us at any time:

We record when you opted in, and we keep a log of the messages we send you, so we can show what was sent and on what basis.

6. Who else sees it

Inside the practice, access is limited to the clinical and reception staff who need it to treat you or arrange your visit. Outside the practice, we use the following service providers — Operators in POPIA's language — who process information strictly on our instructions:

We may also share information where the law requires it, or with your medical scheme when you ask us to submit a claim on your behalf.

7. Where your information is stored

Your information is currently stored on servers located in Ireland (eu-west-1), not in South Africa.

POPIA section 72 permits this where the destination country is subject to a law that provides a level of protection substantially similar to POPIA. Ireland is subject to the EU General Data Protection Regulation, which meets that standard, and our hosting provider is contractually bound to process the information only on our instructions.

We are in the process of moving this database to a South African region so that patient information is stored locally. This page will be updated when that move is complete.

8. How we protect it

POPIA section 19 requires reasonable technical and organisational safeguards. In practice that means:

No system is perfectly secure. If a breach ever affects your information, POPIA section 22 requires us to notify both the Information Regulator and you, and we will.

9. How long we keep it

When a retention period ends we delete the information or de-identify it so it can no longer be linked to you.

10. Your rights

Under POPIA you may:

To exercise any of these, contact our Information Officer using the details in section 1. We may need to verify your identity first — it protects you if we do. We will respond within a reasonable time, and in any event as required by law.

11. Children

We treat information about patients under 18 as belonging to a child, and we rely on the consent of a parent or guardian. A child may be brought to the practice by a parent or guardian who completes these forms on their behalf.

12. Cookies

This website sets no cookies of its own and runs no advertising trackers. Its analytics are cookieless and do not record your IP address. Some third-party content, such as the embedded map, may set its own cookies when it loads. The details are set out in our Cookie Policy.

13. Complaints

Please raise concerns with our Information Officer first — most issues are resolved quickly. If you are not satisfied, you may complain to:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: complaints.IR@justice.gov.za
Enquiries: enquiries.IR@justice.gov.za
https://inforegulator.org.za

14. Changes to this policy

We update this policy when the way we handle information changes — for example when the database moves to a South African region. The date at the top always reflects the current version. Material changes affecting how we use health information will be brought to your attention rather than made quietly.

Questions about anything on this page? Call 017 632 9450 or WhatsApp 072 438 7749, and ask for the Information Officer.