Privacy Policy

Version 1.0 · Effective date: 29 June 2026

This Privacy Policy explains how Medifile collects, uses, and protects personal information in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA). It applies to all users of the Platform and to visitors to medifile.co.za.

1. Who we are

ML Meiring t/a Medifile operates the Medifile platform. ML Meiring is the responsible Information Officer for purposes of POPIA. Information Officer Registration: Pending.

Contact us at: hello@medifile.co.za

2. What personal information we collect

2.1 Practice and User information

  • Practice name, address, HPCSA/practice number, and contact details
  • User names, email addresses, and passwords (stored as irreversible hashes)
  • Login activity, IP addresses, and device identifiers for security and audit purposes
  • Payment-related information processed by PayFast (we do not store card numbers)
  • Communications you send us via email or the contact form

2.2 Patient Data

Patient Data is uploaded to the Platform by the Practice and processed on the Practice's instructions. Medifile acts as Operator in relation to Patient Data. Patient Data may include:

  • Names, identity numbers, dates of birth, and contact information
  • Health records, consultation notes, diagnoses, medications, and treatment history
  • Lab results, imaging reports, referral letters, and other clinical documents
  • Consent records and correspondence
Medifile does not use Patient Data for any purpose other than providing the Platform to the Practice. Patient Data is never sold, shared with third parties for marketing, or used to train AI models without explicit consent.

2.3 Website visitor information

  • Standard server logs including IP address, browser type, pages visited, and timestamps
  • Analytics data collected via privacy-respecting analytics tools (no cross-site tracking)
  • Information submitted via the contact form

3. How we use personal information

PurposeLawful basis (POPIA s11)
Providing and operating the PlatformPerformance of contract
Authenticating users and maintaining securityLegitimate interest / legal obligation
Processing paymentsPerformance of contract
Sending service emails (account, security, referral notifications)Performance of contract
Responding to support requestsLegitimate interest
Improving the Platform based on aggregated, anonymised usage dataLegitimate interest
Complying with legal obligations (POPIA, PAIA, court orders)Legal obligation
Processing Patient Data on behalf of the PracticeOperator instruction from Practice (Responsible Party)

4. Sharing personal information

4.1 Sub-processors

We use the following sub-processors to provide the Platform. All are bound by data processing agreements and appropriate safeguards:

Sub-processorCategoryPurpose
SupabaseDatabase & AuthSecure storage of platform data; authentication. SA region where available.
Google Cloud / Vision AIOCR ProcessingText extraction from uploaded documents. Content is not retained by Google beyond the API call.
ResendTransactional EmailSending system emails (account, security, referral notifications).
PayFastPayment ProcessingProcessing subscription payments. We do not receive or store card numbers.
VercelHostingApplication hosting and delivery (SA region where available).

4.2 Other disclosures

We may also share personal information:

  • With law enforcement or regulatory bodies where required by law or court order
  • With professional advisors (lawyers, accountants) under confidentiality obligations
  • In connection with a sale or merger of our business, subject to the acquirer honouring these commitments

We will never sell personal information or share it for third-party marketing purposes.

5. Data storage & security

5.1 Where data is stored

We store data in South Africa where available through our infrastructure providers. Where data must transit or be processed outside South Africa (for example, through certain sub-processors), we ensure appropriate safeguards are in place as required by POPIA section 72.

5.2 Security measures

  • 256-bit AES encryption for data at rest
  • TLS 1.2+ encryption for all data in transit
  • Role-based access controls — data is isolated per practice; no practice can access another's data
  • Multi-factor authentication available to all users
  • Immutable audit logs of all data access and modifications
  • Regular security assessments and penetration testing
  • Strict access controls limiting Medifile staff access to platform data

5.3 Retention

  • Practice and User account data: retained for the duration of the Subscription and 30 days thereafter
  • Patient Data: retained per HPCSA guidelines (minimum 6 years from date of last entry) unless the Practice instructs earlier deletion, subject to legal minimums
  • Audit logs: retained for 5 years for compliance purposes
  • Payment records: retained for 5 years for financial and tax purposes

6. Your rights under POPIA

Practices and their patients have the following rights under POPIA, which can be exercised using the tools in the Platform or by contacting us:

RightHow to exercise it
AccessRequest a copy of your personal information — use the data export tool in Settings or contact hello@medifile.co.za
CorrectionCorrect inaccurate personal information — edit directly in the Platform or contact us
DeletionRequest deletion of your account and data — contact us. Legal retention obligations may prevent immediate deletion of certain records.
ObjectionObject to processing on grounds of legitimate interest — contact us in writing
RestrictionRequest restriction of processing in certain circumstances — contact us
PortabilityExport your data in a structured format using the data export tool in Settings
Lodge a complaintComplain to the Information Regulator (South Africa) if you believe we have violated POPIA

We will respond to rights requests within 30 days of receipt.

7. Cookies

The Platform uses only essential session cookies required for authentication and security. We do not use advertising cookies or third-party tracking cookies. The marketing website may use minimal, privacy-preserving analytics. No cookie consent banner is required for session-only cookies.

8. Children

The Platform is not directed at individuals under 18. Minor patients' records may be processed through the Platform at the instruction of their treating practitioner, consistent with applicable healthcare laws and the patient's guardian's consent.

9. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published at medifile.co.za/privacy. Material changes will be communicated by email to Practice Owners at least 14 days before taking effect.

10. Contact & complaints

Information Officer: ML Meiring, ML Meiring t/a Medifile
Email: hello@medifile.co.za
Postal address: PO Box 100003, Moreleta Plaza, 0167
IO Registration: Pending

If you are not satisfied with our response to a privacy complaint, you may contact the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, 2001 · POPIAComplaints@inforegulator.org.za.

This Privacy Policy was last reviewed on 29 June 2026 and is published at medifile.co.za/privacy.

Privacy Policy v1.0 · medifile.co.za · hello@medifile.co.za