← Back to HealthHalo

HH-PRIV-001 · Version 1.0

Privacy Policy

In compliance with the Protection of Personal Information Act (POPIA), Act 4 of 2013

Effective Date: 10 March 2026 · Information Officer: Dr Musa Chauke

1

Introduction

HealthHalo (Pty) Ltd ("HealthHalo", "we", "us", or "our") is a South African telemedicine and home visit platform operated by registered medical practitioners. We are committed to protecting the privacy and personal information of every patient and visitor who uses our services.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, who we share it with, and what your rights are under the Protection of Personal Information Act (POPIA), Act 4 of 2013.

This Privacy Policy applies to all users of the HealthHalo website (healthhalo.co.za), mobile application, and consultation platform. By using our services, you acknowledge that you have read and understood this Policy.
2

Who We Are (Responsible Party)

DetailInformation
Company NameHealthHalo (Pty) Ltd
Registration Number2026/208414/07
Tax Reference Number9190835281
Registered AddressSouth Africa
Emailhello@healthhalo.co.za
Websitehealthhalo.co.za
Information OfficerDr Musa Chauke
Information Officer Emaildr.mchauke@healthhalo.co.za
3

What Personal Information We Collect

We collect only the information that is necessary to provide you with safe, accurate, and legally compliant medical consultation services.

3.1 Information You Provide Directly

CategoryExamplesWhen Collected
Identity InformationFull name, date of birth, ID / passport number, genderRegistration & booking
Contact InformationPhone number, email address, physical addressRegistration & booking
Medical Aid InformationMedical aid scheme, membership number, dependent codeBooking & billing
Health InformationMedical history, current medications, allergies, symptoms, diagnoses, clinical notes, prescriptions, sick notes, referral lettersConsultation
Clinical ImagesPhotographs of skin conditions, wounds, rashes uploaded by youPre-consultation
Payment InformationPayment method, EFT proof of payment (for verification)Payment processing
Guardian InformationParent/guardian details for minor patientsMinor consultations

3.2 Information Collected Automatically

CategoryExamplesPurpose
Technical DataIP address, browser type, device typeSecurity and fraud prevention
Usage DataPages visited, session duration, consultation logsPlatform improvement
Consent RecordsTimestamp and IP of consent givenLegal compliance
4

Why We Collect Your Information (Purpose)

We process your personal information only for the following lawful purposes:

PurposeLawful Basis (POPIA)Details
Medical consultationContractual necessity + consentTo deliver the telemedicine or home visit service you requested
Clinical record keepingLegal obligation + consentHPCSA requires clinical records for every consultation
Billing and paymentContractual necessityTo process your payment via PayFast or EFT
Medical aid claimsConsentTo submit a claim on your behalf to your medical aid scheme
Appointment communicationsContractual necessityBooking confirmations, reminders, and post-consult documents via email and SMS
Emergency escalationVital interestTo direct you to emergency services if red-flag symptoms are detected
Legal complianceLegal obligationHPCSA guidelines, National Health Act, POPIA, SARS records
AI-assisted intakeConsentTo use AI to pre-screen symptoms and assist the doctor with a pre-consult brief
Platform securityLegitimate interestTo detect and prevent fraud, abuse, and unauthorised access
We do NOT use your personal or health information for marketing, profiling, or sale to third parties. Your health information will never be used for advertising purposes.
5

Who We Share Your Information With

HealthHalo shares your personal information only where strictly necessary and only with parties who are bound by confidentiality agreements and data processing agreements (DPAs).

5.1 Technology Service Providers (Data Processors)

ProcessorRoleData SharedLocation
SupabaseDatabase & file storageAll personal and health dataUSA (GDPR-compliant)
VercelWeb hosting & platform deliverySession data, IP addressUSA (GDPR-compliant)
Google (Workspace & Meet)Email communication & video consultationsName, email, consultation linkUSA (GDPR-compliant)
Anthropic (Claude AI)AI-assisted symptom intake and pre-consult briefAnonymised symptom data onlyUSA (GDPR-compliant)
PayFastPayment processingPayment method, transaction amountSouth Africa
BulkSMSSMS notificationsPhone number, appointment detailsSouth Africa
ResendTransactional email deliveryName, email, consultation documentsUSA (GDPR-compliant)

5.2 Medical Aid Billing (With Your Consent)

Where you request medical aid billing, we share the minimum necessary clinical information (ICD-10 diagnosis code, tariff code, date of service, your membership details) with:

  • Healthbridge (medical aid clearinghouse) — for claim submission
  • Your medical aid scheme — for claim adjudication and payment

5.3 Legal and Regulatory Authorities

We may disclose personal information without your consent where required by law, including:

  • Notifiable medical conditions (TB, cholera, measles) — to the Department of Health
  • Court orders or formal legal process — to the relevant authority
  • Child abuse or neglect — to Social Development or SAPS
  • Gunshot wounds or unnatural injuries — to SAPS

5.4 What We Will NEVER Do

  • Sell, rent, or trade your personal or health information to any third party
  • Share your information for marketing, advertising, or commercial purposes
  • Transfer your data outside South Africa or the EU/EEA without adequate protections
6

How We Protect Your Information

Security MeasureDetails
Encryption at restAll data stored in Supabase is encrypted using AES-256
Encryption in transitAll data transmitted over HTTPS/TLS 1.2+
Access controlRow-level security — each patient accesses only their own records
AuthenticationMulti-factor authentication required for doctor access
Audit loggingAll access to clinical records is logged with timestamp and user ID
Breach notificationYou and the Information Regulator will be notified within 72 hours of a confirmed breach
Staff accessOnly treating doctors can access patient health records
AI data handlingSymptom data passed to Claude AI is processed per Anthropic's data processing agreement and is not used to train AI models
7

How Long We Keep Your Information

Record TypeRetention PeriodReason
Clinical records (SOAP notes, prescriptions, sick notes)5 years minimumHPCSA guidelines + National Health Act
Clinical photographs and images5 years minimumHPCSA guidelines
AI intake forms and symptom data5 years minimumContinuity of care
Payment and transaction records5 yearsSARS tax compliance
Consent records5 years minimumLegal compliance
Account and registration dataDuration of account + 1 yearContractual necessity
Technical and session logs12 monthsSecurity monitoring

After the retention period, records are securely and permanently deleted or anonymised. You may request early deletion of non-clinical data — see Section 8 for your rights.

8

Your Rights Under POPIA

As a data subject under POPIA, you have the following rights:

RightWhat It MeansHow to Exercise
Right of AccessRequest a copy of all personal information HealthHalo holds about youEmail hello@healthhalo.co.za — we will respond within 30 days
Right to CorrectRequest correction of inaccurate or incomplete personal informationEmail hello@healthhalo.co.za with the correction required
Right to DeleteRequest deletion of your personal information (subject to legal retention obligations)Email hello@healthhalo.co.za — clinical records must be kept for 5 years
Right to ObjectObject to the processing of your personal information for non-essential purposesEmail hello@healthhalo.co.za
Right to Withdraw ConsentWithdraw consent for any processing based on consent at any timeEmail hello@healthhalo.co.za — withdrawal does not affect past processing
Right to ComplainLodge a complaint with the Information Regulator if you believe your rights have been violatedenquiries@inforegulator.org.za
Information Regulator of South Africa:
Email: enquiries@inforegulator.org.za · Website: inforegulator.org.za
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
9

Cookies and Tracking Technologies

The HealthHalo platform uses essential cookies and session tokens only. We do NOT use third-party advertising cookies, tracking pixels, or behavioural profiling tools.

Cookie TypePurposeDuration
Session tokenKeeps you logged in during your sessionSession (deleted on logout)
Authentication tokenSecure authentication via Supabase Auth7 days
Consent timestampRecords that you accepted the consent formSession
10

Third-Party Links and Services

The HealthHalo platform may contain links to third-party websites or services (e.g. Google Meet consultation links). HealthHalo is not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.

11

Children and Minors

HealthHalo may provide medical consultation services to minor patients (under 18 years) where a parent or legal guardian provides consent. We do not knowingly collect personal information from minors without parental or guardian consent. Where a minor's information is provided, it is treated with the same (or greater) level of protection as adult patient data.

12

Changes to This Privacy Policy

HealthHalo may update this Privacy Policy from time to time. Changes will be published on healthhalo.co.za with a revised effective date. Where changes are material, we will notify registered users by email. Continued use of our services after a policy update constitutes acceptance of the updated policy.

VersionDateChanges
1.010 March 2026Initial Privacy Policy — platform launch
13

Contact Us

For any questions, requests, or complaints regarding this Privacy Policy or the handling of your personal information, please contact:

Information OfficerDr Musa Chauke — HealthHalo (Pty) Ltd
Emailhello@healthhalo.co.za
Websitehealthhalo.co.za
Postal AddressHealthHalo (Pty) Ltd, South Africa
Information Regulator (Complaints)enquiries@inforegulator.org.za

HealthHalo (Pty) Ltd · Reg No: 2026/208414/07 · Tax No: 9190835281

hello@healthhalo.co.za · healthhalo.co.za

Information Officer: Dr Musa Chauke (HPCSA: MP0995363 · Practice: 1298887)

Co-Founder: Dr Sphiwe Chauke (HPCSA: MP0993719 · Practice: 1297988)