Data Processing Agreement

POPIA Operator Agreement · Version 1.0 · Effective date: 29 June 2026

This Data Processing Agreement (DPA) is entered into between Medifile (as Operator) and each Practice that uses the Medifile platform (as Responsible Party). It governs the processing of personal information, including special personal information (health data), by Medifile on behalf of the Practice, in compliance with POPIA sections 20–21 and section 26.

1. Definitions

TermDefinition
“Operator”ML Meiring t/a Medifile, operating the Medifile platform.
“Responsible Party”The medical practice or health professional that has registered a Medifile account and controls the purpose and means of processing Patient Data.
“Personal Information”As defined in POPIA section 1 — information relating to an identifiable, living natural person or existing juristic person.
“Special Personal Information”Personal information concerning health or sex life, as defined in POPIA section 26.
“Processing”Any operation performed on personal information as defined in POPIA section 1, including collection, recording, storage, retrieval, use, dissemination, and destruction.
“Patient Data”All personal information and special personal information relating to patients of the Practice that is uploaded to or generated within the Medifile platform.
“Security Incident”Any confirmed or suspected unauthorised access to, disclosure of, alteration of, or destruction of Patient Data.
“Sub-processor”Any third party engaged by the Operator to process Patient Data on behalf of the Responsible Party.

2. Subject matter & duration

2.1 Subject matter

This DPA governs the processing of Patient Data by the Operator on behalf of the Responsible Party for the purpose of providing the Medifile platform and associated services as described in the Terms of Service.

2.2 Nature of processing

The Operator will process Patient Data for the following purposes only:

  • Storing, organising, and retrieving patient health records as directed by the Responsible Party
  • Applying OCR and AI processing to documents uploaded by the Responsible Party to extract and classify content
  • Enabling the Responsible Party to create, share, and manage clinical notes, referrals, and related records
  • Generating AI-assisted patient summaries from data uploaded by the Responsible Party
  • Maintaining compliance, audit, and retention functions on behalf of the Responsible Party
  • Providing technical support and troubleshooting (subject to clause 4.5)

2.3 Categories of data subjects

Patients of the Responsible Party's medical practice, including minors where applicable.

2.4 Categories of personal information

  • Identifying information: name, identity number, date of birth, gender, contact details
  • Special personal information: health records, diagnoses, medications, treatment notes, lab results, imaging reports, and other clinical data (POPIA s26)
  • Administrative records: consent forms, referral letters, correspondence, and appointment records

2.5 Duration

This DPA commences on the date the Responsible Party creates a Medifile account and continues until the termination of the Terms of Service and deletion of all Patient Data.

3. Responsible Party's obligations

The Responsible Party confirms and warrants that:

  1. It has a lawful basis under POPIA to collect and process all Patient Data it uploads to the Platform
  2. Where Patient Data constitutes Special Personal Information (health data), it has obtained the explicit consent of the data subject or is processing on another lawful ground under POPIA section 27 (e.g. processing necessary for healthcare delivery)
  3. It has notified patients that their records will be processed by Medifile as Operator, including in its own POPIA notices and information officer disclosures
  4. It has appointed a POPIA Information Officer and registered with the Information Regulator where required by law
  5. It will only instruct the Operator to process Patient Data in a manner consistent with POPIA
  6. It will respond promptly to data subject access, correction, deletion, and objection requests, using the tools available in the Platform or by contacting the Operator
  7. It will notify the Operator immediately if it becomes aware of any instruction that would require the Operator to breach POPIA or any other law

4. Operator's obligations

4.1 Instructions only

The Operator will process Patient Data only on documented instructions from the Responsible Party (including as set out in the Terms of Service and this DPA) and not for any other purpose. If required by law to process for another purpose, it will inform the Responsible Party to the extent permitted by law.

4.2 Confidentiality

The Operator will ensure that all personnel authorised to process Patient Data are bound by appropriate confidentiality obligations and are aware of the sensitivity of health data. Access is limited to personnel who require it to perform their functions in delivering the Platform.

4.3 Security measures

  • 256-bit AES encryption of Patient Data at rest
  • TLS 1.2+ encryption of Patient Data in transit
  • Strict role-based access controls isolating each Practice's data from all others
  • Multi-factor authentication for Platform access
  • Immutable audit logging of all data access, modifications, and deletions
  • Regular security testing and vulnerability assessments
  • Access control policies limiting Medifile staff access to the minimum necessary for support
  • Incident response procedures for Security Incidents

4.4 Sub-processors

The Operator may engage sub-processors (Schedule 1). The Operator:

  • Will enter into data processing agreements with all sub-processors on terms no less protective than this DPA
  • Remains liable to the Responsible Party for the acts and omissions of sub-processors
  • Will notify the Responsible Party of any intended changes to the sub-processor list at least 14 days before the change takes effect
  • Will give the Responsible Party an opportunity to object to new sub-processors on reasonable grounds

4.5 Access for support

Medifile staff may access Patient Data only to the extent necessary to investigate and resolve technical support issues raised by the Responsible Party, or to maintain and improve the security and integrity of the Platform. All such access is logged in the immutable audit trail.

4.6 Assistance with data subject rights

The Operator will assist the Responsible Party in responding to data subject rights requests under POPIA by providing the tools available in the Platform. Additional assistance may be requested at hello@medifile.co.za.

4.7 Assistance with compliance

  • Demonstrate compliance with its POPIA obligations as Responsible Party
  • Comply with data impact assessment requirements if applicable
  • Conduct audits of the Operator's processing activities (subject to reasonable advance notice and confidentiality protections)

4.8 Security Incident notification

If the Operator becomes aware of a Security Incident affecting Patient Data, it will:

  • Notify the Responsible Party without undue delay and in any event within 72 hours of becoming aware
  • Provide available detail: nature of the incident; categories and approximate number of data subjects and records affected; likely consequences; measures taken or proposed
  • Cooperate with the Responsible Party in investigating and remediating the incident
  • Not make any public disclosure without the Responsible Party's prior consent, except where required by law

The Responsible Party retains sole responsibility for notifying the Information Regulator and affected data subjects as required by POPIA section 22.

4.9 Deletion on termination

  • The Operator will delete all Patient Data within 30 days, unless a longer retention period is required by law
  • The Operator will provide written confirmation of deletion on request
  • The Responsible Party may request a data export in the 30 days before deletion
  • Anonymised, aggregated data that cannot be re-identified is not subject to deletion obligations

4.10 Restriction on use for own purposes

The Operator will not:

  • Use Patient Data to train AI or machine learning models without the explicit written consent of the Responsible Party
  • Sell, licence, or otherwise commercialise Patient Data
  • Process Patient Data for the Operator's own marketing or research purposes
  • Combine Patient Data with data from other practices for any purpose other than platform-wide security and fraud prevention

5. Transfers outside South Africa

Where Patient Data is transferred to or processed outside South Africa, the Operator will ensure that the recipient country provides an adequate level of protection as determined by the Information Regulator, or that appropriate safeguards (such as binding contractual clauses complying with POPIA section 72) are in place.

The Operator's infrastructure is designed to store data in South Africa where available. Where processing by sub-processors involves cross-border transfer (for example, OCR via Google Cloud), this is subject to the sub-processor's data processing terms which provide appropriate safeguards.

6. Special Personal Information (POPIA s26)

The Operator acknowledges that Patient Data constitutes Special Personal Information (health data) under POPIA section 26 and will apply heightened protection, including:

  • Treating all Patient Data as health data regardless of individual labelling
  • Applying access restrictions so only the Responsible Party's authorised Users can access their patients' data
  • Not processing Special Personal Information beyond the purposes in clause 2.2
  • Ensuring sub-processors who process Special Personal Information are bound by equivalent protections
Under POPIA s26, Special Personal Information may only be processed in limited circumstances. The primary lawful ground for processing by medical practitioners is that the processing is necessary for the proper treatment and care of the data subject (s27(1)(c)).

7. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service. Nothing limits either party's liability for breaches caused by gross negligence, fraud, or wilful misconduct; death or personal injury caused by negligence; or any liability that cannot be limited by law. Where both parties are liable for a POPIA violation, liability is apportioned according to each party's degree of fault. The Operator is not liable for violations arising from the Responsible Party's unlawful processing instructions.

8. General

8.1 Order of precedence

In the event of conflict between this DPA and the Terms of Service on data-processing matters, this DPA shall prevail.

8.2 Governing law

This DPA is governed by the laws of the Republic of South Africa, including POPIA.

8.3 How this DPA is accepted

By creating a Medifile account and accepting the Terms of Service at sign-up, the Responsible Party is deemed to have accepted this DPA. The acceptance is recorded with a timestamp in the Platform's audit log. No physical signature is required.

8.4 Amendments

Medifile may update this DPA to reflect changes in law or practice. Material changes will be communicated by email at least 14 days before taking effect. The Responsible Party may object by terminating their account before the effective date.

Schedule 1 — Sub-processors

Current as of 29 June 2026. Updates will be communicated 14 days before any change takes effect.

Sub-processorCountryServiceSafeguard
SupabaseUSA / SA*Database, auth, file storageData Processing Agreement; SA region selected where available
Google Cloud / Vision AIUSAOCR text extractionGoogle Cloud DPA; Standard Contractual Clauses
ResendUSATransactional email deliveryResend Data Processing Agreement
PayFastSouth AfricaPayment processingSA-based; payment data not shared with Medifile
VercelUSA / SA*Application hostingVercel DPA; SA edge region where available

* SA region = South Africa region available on these platforms; used where technically possible.

This DPA was last reviewed on 29 June 2026. It is published at medifile.co.za/dpa and is incorporated into the Medifile Terms of Service by reference.

DPA v1.0 — POPIA Operator Agreement · medifile.co.za · hello@medifile.co.za