Privacy Policy
keeping you safe & sound.
Doxi Health Privacy Policy
At Doxi Health (Pty) Ltd t/a Doxi Health ("us", "we", "our" or the "Company") we value your privacy and the importance of safeguarding your data. This Privacy Policy applies to Doxi Health, a healthcare service provider ("Doxi Health," "we," "us," or "our"), and governs the processing and protection of personal information collected of patients, clients, and users of our services (referred to as "you"). Doxi Health is committed to protecting the confidentiality and privacy of the personal information it processes. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), as amended from time to time, and other applicable data protection regulations. By engaging with our services, whether in person, online, or through any other means, you agree to the terms outlined in this policy regarding the collection, processing, and storage of your personal information.
This policy applies to the Doxi Health websites, domains, applications, services, and products.
This Policy does not apply to third-party applications, websites, products, services or platforms that may be accessed through (non-Doxi Health) links that we may provide to you. These sites are owned and operated independently from us, and they have their own separate privacy and data collection practices. Any Personal Data that you provide to these websites will be governed by the third-party's own privacy policy. We cannot accept liability for the actions or policies of these independent sites, and we are not responsible for the content or privacy practices of such sites.
Processing Activities
This Policy applies when you interact with us by doing any of the following:
• Make use of our application and services as an authorised user
• Visit any of our websites that link to this Privacy Statement
WHO WE ARE
We are Doxi Health, a registered healthcare services provider, specializing in patient care, consultation, and related medical services. Our registration number is 2023/836669/07.
​
WHAT IS PERSONAL INFORMATION
Under POPIA, "personal information" refers to any information that identifies or relates to you, including but not limited to:
-
Basic details such as name, contact details, and identification numbers (ID number, medical aid number, etc.).
-
Demographic information such as age, gender, marital status, and race.
-
Health-related information such as medical history, health conditions, diagnosis, treatment, and prescriptions.
-
Biometric data like fingerprints or retina scans, if applicable.
-
Sensitive personal information including mental or physical health, sexual orientation, and other details that require special handling under POPIA.
-
Other identifiable information including email addresses, phone numbers, and location data.
WHAT PERSONAL INFORMATION WE COLLECT AND PROCESS
In order to provide you with our healthcare services, we may collect and process various types of personal information, including:
-
Your full name, contact information such as your address and email address, and identity number.
-
Your medical history, diagnosis, prescriptions, treatment plans, and test results.
-
Payment details for billing purposes such as credit card information, banking details, medical aid information, and payment history.
-
Other health-related information necessary for the provision of our services.
HOW WE COLLECT PERSONAL INFORMATION
We primarily collect personal information directly from you. This may occur when you:
-
Register for our services or book an appointment.
-
Fill out forms on our website or provide information via email or phone.
-
Attend consultations, where we may document your health history and medical records.
We may also collect personal information from third-party sources, such as health insurers, medical aids, or other healthcare providers, if you have given consent for us to obtain this information.
PERSONAL MEDICAL INFORMATION
This information remains confidential. Access to this information is protected from any third parties or users, and may be accessed in the following cases:
-
The person requests access to records of their own information, after their identity is validated.
-
The person requesting information legally qualifies as the guardian or carer of the person involved, under South African law.
-
Where further medical care requires this Personal Medical Information to be discussed or disclosed with another healthcare professional, facility, or healthcare-related service provider.
-
Where permission to share Personal Medical Information is granted by the user to be shared with a particular third party or person.
PURPOSES FOR COLLECTING PERSONAL INFORMATION
We process your personal information for the following purposes:
-
To provide you with healthcare services, including diagnosing, treating, and managing your healthcare.
-
To process payments, manage appointments, and ensure the proper functioning of our services.
-
To fulfil our obligations under healthcare laws, such as keeping medical records for the required retention periods, or reporting to health authorities as necessary.
-
To send you updates, reminders about appointments, and health-related information, where you have consented to such communications.
-
For statistical and research purposes to improve our services, while ensuring confidentiality.
WHO WE SHARE YOUR PERSONAL INFORMATION WITH
We do not sell or rent your personal information to third parties. However, we may share your personal information with the following parties for the purposes outlined in this policy:
-
If necessary, we may share your information with other healthcare professionals, such as specialists or hospitals, involved in your care.
-
If you have health insurance or a medical aid, we may share information for billing and claims purposes.
-
Third-party companies who provide support services to us, such as IT services, document storage, and medical record management, will have access to your information only as necessary to perform their functions and are required to adhere to our privacy policies.
-
We may disclose personal information to government bodies, regulators, or law enforcement agencies as required by law or to protect our rights and interests.
-
We may share your personal information, including contact details and payment history, with third-party service providers such as debt collectors or collection agencies in the event of unpaid bills or outstanding payments. This sharing will only occur if necessary to facilitate the collection of any amounts owed to us and in compliance with relevant legal requirements. We ensure that any third-party service providers we work with maintain the confidentiality and security of your personal information, in line with our privacy practices.
HOW WE SECURE PERSONAL INFORMATION
We implement a range of technical, organizational, and physical security measures to safeguard your personal information against loss, theft, and unauthorized access. These measures include:
-
Sensitive personal information, including financial data, is encrypted to prevent unauthorized access.
-
Only authorized employees and contractors have access to your personal information based on their roles.
-
We conduct periodic audits of our security systems and processes to ensure they meet industry standards.
Despite our efforts, no data transmission method over the internet is entirely secure. While we take reasonable steps to protect your information, we cannot guarantee that unauthorized third parties will not be able to bypass our security measures.
RETENTION OF YOUR PERSONAL INFORMATION
We will retain your personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law or professional regulations. After this period, your information will be securely deleted or anonymized, unless we are legally required to keep it for longer periods.
TRANSFER OF PERSONAL INFORMATION OUTSIDE SOUTH AFRICA
Although we aim to store and process your personal information within South Africa, certain operations or third-party service providers may necessitate the transfer of your data to countries outside South Africa. In such cases, we will ensure that any transfers comply with POPIA and provide an adequate level of protection for your personal information.
PROCESSING SPECIAL PERSONAL INFORMATION
We may collect and process special categories of personal information, such as your health records, with your explicit consent, where required by law, or when it is necessary for the provision of healthcare services. We take extra precautions to protect sensitive information, ensuring compliance with relevant data protection laws.
YOUR RIGHTS UNDER POPIA
Under POPIA, you have the following rights regarding your personal information:
-
You may request a copy of the personal information we hold about you.
-
You may request us to correct any inaccurate or outdated information.
-
You may request that we delete your personal information, subject to certain exceptions (such as legal obligations).
-
You may object to the processing of your personal information on legitimate grounds.
-
You have the right to opt out of receiving marketing communications from us at any time.
To exercise these rights, please contact us using the details provided below.
COMPLAINTS
-
If you believe that we have violated your privacy rights, you have the right to lodge a complaint with us, or if you want to object to us processing your personal information or request the correction, deletion or destruction of any of the personal information records we hold about you, please contact our Information Officer at doxihealth@gmail.com, so that we can resolve the complaint or attend to your request.
-
All requests for access to personal information records we hold must be submitted using the prescribed form in terms of the Promotion of Access to Information Act (PAIA).
-
Any objections to our processing of your personal information should be submitted to us using prescribed Form 1, as outlined in the POPIA Regulations.
-
Requests for correction, deletion, or destruction of your personal information records should also be submitted to us using prescribed Form 2, in accordance with the POPIA Regulations.
-
You can access the POPIA Regulations and the PAIA Act on the Information Regulator’s website: https://inforegulator.org.za
-
Under POPIA, you are entitled to file a complaint with the Office of the Information Regulator, South Africa, if you believe your complaint has not been adequately addressed by us. Complaints to the Information Regulator must be made in the prescribed manner and on Form 5, Part II, as set out in the POPIA Regulations.
-
You can contact the Information Regulator via email at: inforeg@justice.gov.za (general enquiries) or POPIAComplaints.IR@justice.gov.za (for complaints).
-
For more information and access to forms, visit the Information Regulator’s website: https://inforegulator.org.za/popia-forms/
AUTOMATED TECHNOLOGIES OR INTERACTIONS
As you interact with our website, our website may automatically collect the following types of data (all as described above):
-
Device Data about your equipment, Usage Data about your browsing actions and patterns, and Contact Data where tasks carried out via our website remain uncompleted, such as incomplete orders or abandoned service request. We collect this data by using cookies, server logs and other similar technologies. Please see our “Cookie” section (below) for further details.
Third parties: We may receive Personal Data about you from various third parties, including:
-
Account Information and Payment Information from another individual when they purchase a service for you on our website;
-
Device and Usage Data from third parties, including analytics providers such as Google;
-
Account Information and Payment Data from social media platforms when you log in to our website using such social media platforms;
-
Content from communication services, including email providers and social networks, when you give us permission to access your data on such third-party services or networks;
-
Account Information and Payment Data from third parties, including organizations (such as law enforcement agencies), associations and groups, who share data for the purposes of fraud prevention and detection and credit risk reduction; Account Information, Payment Data, and Financial Data from providers of technical, payment and delivery services.
If you provide us, or our service providers, with any Personal Data relating to other individuals, you represent that you have the authority to do so and acknowledge that it will be used in accordance with this Policy. If you believe that your Personal Data has been provided to us improperly, or to otherwise exercise your rights relating to your Personal Data, please contact us by using the information set out in the “Contact us” section below.
DEVICE AND USAGE DATA
When you visit a Doxi Health website, we automatically collect and store information about your visit using browser cookies (files which are sent by us to your computer), or similar technology. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. The Help Feature on most browsers will provide information on how to accept cookies, disable cookies or to notify you when receiving a new cookie. If you do not accept cookies, you may not be able to use some features of our Service and we recommend that you leave them turned on.
COOKIES
What are Cookies? A cookie is a small file with information that your browser stores on your device. Information in this file is typically shared with the owner of the site in addition to potential partners and third parties to that business. The collection of this information may be used in the function of the site and/or to improve your experience.
​
HOW WE USE COOKIES
-
To give you the best experience possible, we use the following types of cookies:
-
Strictly Necessary: As a web application, we require certain necessary cookies to run our service.
-
Preference: We use preference cookies to help us remember the way you like to use our service.
-
Some cookies are used to personalize content and present you with a tailored experience. For example, location could be used to give you services and offers in your area.
MERGER OR ACQUISITION
If we are involved in a merger, acquisition or asset sale, your personal information may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different Privacy Policy. Under certain circumstances, we may be required to disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
HOW WE KEEP YOUR DATA SAFE
We have appropriate organizational safeguards and security measures in place to protect your Personal Data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. The communication between your browser and our website uses a secure encrypted connection wherever your Personal Data is involved.
We require any third party who is contracted to process your Personal Data on our behalf to have security measures in place to protect your data and to treat such data in accordance with the law. In the unfortunate event of a Personal Data breach, we will notify you and any applicable regulator when we are legally required to do so.
CHILDREN’S PRIVACY
We handle the personal information of children with the same level of privacy protection as any other user's personal data, including Personal Medical Information as outlined above. Any request to transfer, delete, or amend this information may only be made by the child's legal guardian, unless the child, in accordance with their legal rights, chooses to withhold certain information.
This version aligns with POPIA's provisions while maintaining the spirit of the original clause. It also acknowledges the legal rights of children where applicable under South African law.
CHANGES
We may amend this Policy at any time. If we make changes, we will post the updated version on this website. When you use our services, you will be asked to review and accept our updated Privacy Policy. This allows us to record your acceptance and notify you of any future amendments to this Policy, in accordance with the requirements of the Protection of Personal Information Act (POPIA).
This version references POPIA for added clarity regarding privacy regulations in South Africa.
LAWS APPLICABLE TO THIS PRIVACY POLICY
This Privacy Policy is governed by the laws of the Republic of South Africa, and you hereby consent to the jurisdiction of the South African courts in respect of any dispute which may arise out of or in connection with the formation, interpretation, substance or application of this Privacy Policy.
CONTACT US
To request a copy of your information, unsubscribe from our email list, ask for your data to be deleted, or if you have any questions or concerns about your data privacy, please contact us at info@doxi.co.za.