Privacy Policy
Version 1.0 · Effective date: 29 June 2026
1. Who we are
ML Meiring t/a Medifile operates the Medifile platform. ML Meiring is the responsible Information Officer for purposes of POPIA. Information Officer Registration: Pending.
Contact us at: hello@medifile.co.za
2. What personal information we collect
2.1 Practice and User information
- Practice name, address, HPCSA/practice number, and contact details
- User names, email addresses, and passwords (stored as irreversible hashes)
- Login activity, IP addresses, and device identifiers for security and audit purposes
- Payment-related information processed by PayFast (we do not store card numbers)
- Communications you send us via email or the contact form
2.2 Patient Data
Patient Data is uploaded to the Platform by the Practice and processed on the Practice's instructions. Medifile acts as Operator in relation to Patient Data. Patient Data may include:
- Names, identity numbers, dates of birth, and contact information
- Health records, consultation notes, diagnoses, medications, and treatment history
- Lab results, imaging reports, referral letters, and other clinical documents
- Consent records and correspondence
2.3 Website visitor information
- Standard server logs including IP address, browser type, pages visited, and timestamps
- Analytics data collected via privacy-respecting analytics tools (no cross-site tracking)
- Information submitted via the contact form
3. How we use personal information
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Providing and operating the Platform | Performance of contract |
| Authenticating users and maintaining security | Legitimate interest / legal obligation |
| Processing payments | Performance of contract |
| Sending service emails (account, security, referral notifications) | Performance of contract |
| Responding to support requests | Legitimate interest |
| Improving the Platform based on aggregated, anonymised usage data | Legitimate interest |
| Complying with legal obligations (POPIA, PAIA, court orders) | Legal obligation |
| Processing Patient Data on behalf of the Practice | Operator instruction from Practice (Responsible Party) |
4. Sharing personal information
4.1 Sub-processors
We use the following sub-processors to provide the Platform. All are bound by data processing agreements and appropriate safeguards:
| Sub-processor | Category | Purpose |
|---|---|---|
| Supabase | Database & Auth | Secure storage of platform data; authentication. SA region where available. |
| Google Cloud / Vision AI | OCR Processing | Text extraction from uploaded documents. Content is not retained by Google beyond the API call. |
| Resend | Transactional Email | Sending system emails (account, security, referral notifications). |
| PayFast | Payment Processing | Processing subscription payments. We do not receive or store card numbers. |
| Vercel | Hosting | Application hosting and delivery (SA region where available). |
4.2 Other disclosures
We may also share personal information:
- With law enforcement or regulatory bodies where required by law or court order
- With professional advisors (lawyers, accountants) under confidentiality obligations
- In connection with a sale or merger of our business, subject to the acquirer honouring these commitments
We will never sell personal information or share it for third-party marketing purposes.
5. Data storage & security
5.1 Where data is stored
We store data in South Africa where available through our infrastructure providers. Where data must transit or be processed outside South Africa (for example, through certain sub-processors), we ensure appropriate safeguards are in place as required by POPIA section 72.
5.2 Security measures
- 256-bit AES encryption for data at rest
- TLS 1.2+ encryption for all data in transit
- Role-based access controls — data is isolated per practice; no practice can access another's data
- Multi-factor authentication available to all users
- Immutable audit logs of all data access and modifications
- Regular security assessments and penetration testing
- Strict access controls limiting Medifile staff access to platform data
5.3 Retention
- Practice and User account data: retained for the duration of the Subscription and 30 days thereafter
- Patient Data: retained per HPCSA guidelines (minimum 6 years from date of last entry) unless the Practice instructs earlier deletion, subject to legal minimums
- Audit logs: retained for 5 years for compliance purposes
- Payment records: retained for 5 years for financial and tax purposes
6. Your rights under POPIA
Practices and their patients have the following rights under POPIA, which can be exercised using the tools in the Platform or by contacting us:
| Right | How to exercise it |
|---|---|
| Access | Request a copy of your personal information — use the data export tool in Settings or contact hello@medifile.co.za |
| Correction | Correct inaccurate personal information — edit directly in the Platform or contact us |
| Deletion | Request deletion of your account and data — contact us. Legal retention obligations may prevent immediate deletion of certain records. |
| Objection | Object to processing on grounds of legitimate interest — contact us in writing |
| Restriction | Request restriction of processing in certain circumstances — contact us |
| Portability | Export your data in a structured format using the data export tool in Settings |
| Lodge a complaint | Complain to the Information Regulator (South Africa) if you believe we have violated POPIA |
We will respond to rights requests within 30 days of receipt.
7. Cookies
The Platform uses only essential session cookies required for authentication and security. We do not use advertising cookies or third-party tracking cookies. The marketing website may use minimal, privacy-preserving analytics. No cookie consent banner is required for session-only cookies.
8. Children
The Platform is not directed at individuals under 18. Minor patients' records may be processed through the Platform at the instruction of their treating practitioner, consistent with applicable healthcare laws and the patient's guardian's consent.
9. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published at medifile.co.za/privacy. Material changes will be communicated by email to Practice Owners at least 14 days before taking effect.
10. Contact & complaints
Email: hello@medifile.co.za
Postal address: PO Box 100003, Moreleta Plaza, 0167
IO Registration: Pending
If you are not satisfied with our response to a privacy complaint, you may contact the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, 2001 · POPIAComplaints@inforegulator.org.za.
Privacy Policy v1.0 · medifile.co.za · hello@medifile.co.za