Legal

Our policies and terms governing the use of HISA services.

Privacy Policy

Last updated: 26 April 2026

1. Introduction

HISA Health is committed to protecting the personal information of all individuals who interact with our platforms, website, and services. This Privacy Policy sets out how we collect, use, store, and protect personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

2. Information We Collect

We collect personal information provided directly by users of our systems, including name, contact details, professional credentials, and healthcare facility information. For clinical deployments, patient personal information is collected and processed strictly within the scope of the relevant healthcare facility's mandate.

3. Lawful Basis for Processing

All personal information processed by HISA is done so on a lawful basis under POPIA, including: (a) explicit consent of the data subject; (b) contractual necessity with healthcare institutions; (c) compliance with a legal obligation; or (d) the legitimate interests of the organisation where not overridden by the rights of the data subject.

4. Data Storage and Security

All patient and user data is stored exclusively on South African servers. We implement AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access controls, multi-factor authentication, and immutable audit logging on every write operation. Data is backed up daily with 30-day retention.

5. Data Retention

Patient clinical records are retained for the duration of the care relationship plus a minimum of six years, in accordance with the Health Professions Act. Contact and enquiry data submitted via our website is retained for no longer than 12 months unless a contractual relationship is established.

6. Your Rights

Under POPIA, you have the right to: access personal information we hold about you; request correction of inaccurate information; object to processing; and request deletion of information where legally permissible. To exercise these rights, contact our Information Officer at privacy@hisahealth.co.za.

7. Data Breach Notification

In the event of a data breach involving personal information, HISA will notify the Information Regulator and all affected data subjects within 72 hours of becoming aware of the breach, as required under POPIA Section 22.

8. Contact

For any privacy-related enquiries, please contact our Information Officer at privacy@hisahealth.co.za or write to: HISA, Parktown, Johannesburg, 2193, South Africa.

base44
Edit with Base44