Privacy Policy
Last Updated: 30th June 2026
1. INTRODUCTION
This Privacy Policy (“Policy”) establishes the legally binding framework governing the collection, processing, use, disclosure, retention, and protection of Personal Information by Etherealmed (Pty) Ltd and all of its subsidiaries, affiliated companies, divisions, brands, products, and related corporate entities (collectively referred to as “the Group”, “we”, “us”, or “our”). This includes, without limitation, the commercial platforms known as Paydoc, MxNode, and NodeMe, as well as any current or future websites, mobile applications, cloud software architectures, Application Programming Interfaces (APIs), partner or provider portals, and ancillary services operated or provisioned by the Group.
The Group is deeply committed to safeguarding the privacy, dignity, and confidentiality of data subjects. This Policy is engineered to ensure strict compliance with the Protection of Personal Information Act, No. 4 of 2013 (“POPIA”), the National Health Act, No. 61 of 2003, the Ethical Rules of the Health Professions Council of South Africa (“HPCSA”), the Electronic Communications and Transactions Act, No. 25 of 2002 (“ECTA”), and all other applicable regulatory enactments operating within the Republic of South Africa.
2. SCOPE OF POLICY
This Policy applies universally to all processing of Personal Information carried out by the Group or on its behalf. The data subjects covered under this Policy include, but are not limited to:
- Patients: Individuals completing registration or intake forms and receiving healthcare services through practitioners utilizing our digital ecosystems.
- Medical Practitioners & Staff: Specialists, clinical professionals, allied healthcare workers, practice administrative staff, billing bureau partners, and professional accounting partners.
- Commercial & Corporate Entities: Institutional healthcare providers, suppliers, vendors, contractors, business partners, job applicants, and employees.
- Digital Visitors: General website visitors, mobile application users, and any other individuals interacting with our user interfaces.
3. LEGAL DEFINITIONS
In this Policy, words and expressions shall bear the meanings assigned to them in POPIA, unless the context explicitly indicates otherwise:
“Data Subject” means the person to whom Personal Information relates, including both natural persons and identifiable, existing juristic persons.
“Operator” means a person or entity who processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party.
“Personal Information” means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including but not limited to identity details, contact info, financial metrics, and unique identifiers.
“Processing” means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Information, including collection, receipt, recording, organization, storage, updating, modification, retrieval, dissemination, erasure, or destruction.
“Responsible Party” means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing Personal Information.
“Services” encompasses all applications, websites, cloud platforms, embedded software, payment processing architectures, customer support environments, and technical ecosystems provisioned by the Group.
“Special Personal Information” means Personal Information concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasions, health, sexual life, biometric information, or criminal behavior of a data subject.
4. EXPLICIT PATIENT CONSENT TO SHARE INFORMATION
PATIENT MANDATE & EXPRESS CONSENT:
By submitting your information, filling out digital intake or registration forms, or uploading documents through our Services, you expressly consent and direct that your Personal Information and Special Personal Information (including health, clinical, and billing data) be made immediately available to your designated, treating healthcare practitioner, medical practice, and authorized members of that practice staff. This sharing is strictly authorized for the purposes of facilitating medical treatment, clinical diagnostic workflows, healthcare administration, medical scheme claims submission, financial billing, payment collection, and related platform services.
5. DISTINCT PROCESSING ACTIVITIES BY USER CATEGORY
To ensure clarity regarding data minimisation, processing is segmented into distinct tracks tailored strictly to your engagement with the Group:
| User Class | Core Processing Activities | Data Minimisation & Legal Justification |
| Patients / Healthcare Users | Digital intake processing; account
authentication; clinical document uploads; invoice generation; medical aid claims routing; online payments; and automated refund management. |
Collection is restricted strictly to what is necessary to administer medical files, facilitate safe treatment execution, and process healthcare billing. |
| Medical Practitioners & Practice Staff | Practitioner onboarding and credentials
verification; practice profile creation; API integration; clearinghouse analytics; automated software reporting; and customer support ticketing. |
Processed strictly to fulfill service level agreements, manage digital medical practices, and enforce platform technical security. |
| Website Visitors | Cookie preference management; digital newsletter distribution; aggregate
performance tracking; and general service inquiries. |
Limited entirely to basic digital identifiers based on user-selected opt-ins or core functional web operations. |
| Suppliers & Business Partners | Corporate onboarding; contractual drafting; compliance auditing; and business payment routing. | Necessary for the execution, maintenance, and regular performance of lawful business contracts. |
6. USER CONTENT & PATIENT-GENERATED DOCUMENTS
Our platforms allow patients and practitioners to actively upload and store user-generated files (“User Content”) necessary to maintain continuity of care. This includes copies of National Identity Documents (IDs) or passports for verification, signed digital consent forms, clinical referrals, pathology reports, diagnostic test results, medical photographs, and formal correspondence. The Group processes and stores this content strictly as an Operator on the explicit instruction of the treating practitioner, applying rigid cryptographic segmentation to ensure file security.
7. DEVICE PERMISSIONS
To deliver advanced diagnostic or operational features within our mobile and web applications (such as MxNode, NodeMe), our systems may request specific access permissions on your hardware device. These permissions may include:
- Camera Access: To capture real-time profile images, scan barcode identifiers, or ingest medical photographs directly into clinical workflows.
- Photo Library Access: To upload pre-saved medical documents, registration forms, or digital verification
- Location Services: To identify nearby medical practices, secure localized network endpoints, or authenticate transaction
You maintain autonomy over these settings and may withdraw or disable these device permissions at any time through the native settings dashboard of your operating system. Disabling these permissions may limit your ability to use certain software features.
8. ELECTRONIC COMMUNICATIONS FRAMEWORK
The Group operates an integrated multi-channel communications architecture to distribute vital operational alerts and transactional data. By using the Services, you acknowledge that you will receive communication via Short Message Service (SMS), WhatsApp Business channels, automated electronic mail (email), and native system notifications.
8.1 Transactional & Service Notifications
These communications are critical to the secure execution of our platforms and include: One-Time Pins (OTPs) for multi-factor authentication, appointment confirmations and reminders, fee estimates, medical medical aid claim updates, financial invoices, digital account statements, and payment or refund reminders. These communications are necessary to provide the Services and therefore may continue while you use the Services.
8.2 Marketing Communications
We may periodically distribute optional communications, including digital newsletters, new feature product updates, medical webinar invitations, and optional educational material. In strict compliance with POPIA, these messages are cleanly separated from service alerts. Users have an right to opt out of marketing messages at any time using the one-click unsubscribe mechanism provided within the text or by contacting the Information Officer. Special Personal Information (including health or clinical conditions) is never used, cross-referenced, or processed for direct marketing targets.
9. ARTIFICIAL INTELLIGENCE & AUTOMATED PROCESSES
The Group deploys advanced algorithms and Artificial Intelligence (“AI”) sub-systems within its digital platforms to streamline practice workflows, automate document formatting, extract data from uploaded content, optimize billing routing, detect transaction fraud, and analyze system errors.
CRITICAL CLINICAL BOUNDARY: All automated outputs function exclusively as administrative or analytical support tools, and any material or treatment decisions remain subject to human oversight, clinical verification, and the independent judgment of qualified healthcare practitioners.
10. GRANULAR COOKIE POLICY
Our web services and applications use cookies, web beacons, and persistent tokens to optimize performance. We categorize our cookie deployments as follows:
- Essential Cookies: Strictly required to operate the basic architecture of our site. They handle secure session routing, user login preservation, and multi-factor authentication states. These cannot be disabled.
- Functional Cookies: Store choices you make, such as language preferences, portal layouts, or font scalings, to deliver an optimized experience.
- Analytics Cookies: Collect anonymous data regarding visitor flows, page interaction times, and platform This data is fully aggregated and used to fix software bugs and improve layout usability.
- Marketing Cookies: Designed to track user journeys across web properties to build advertising profiles. The Group does not currently deploy tracking or marketing cookies, nor do we sell user data to any external advertising brokers.
11. INTEGRATED PAYMENT PROCESSING & ONLINE REFUNDS
Through our specialized payment platform, the Group manages the orchestration of healthcare financial transactions, including electronic credit/debit card processing, Instant EFT settlements, and payment allocations.
To safely execute these actions and prevent financial crime, your payment metadata is securely shared with regulated clearing banks, accredited payment gateways, and secondary payment processors. In instances where patients make an online prepayment or overpayment prior to final medical scheme adjudication, Paydoc notifies the medical practitioner for manual refund routing. Relevant financial strings are securely transmitted to authorized refund processors and dedicated fraud detection networks to validate banking source details before funds are returned.
12. HEALTHCARE RECORD OWNERSHIP & STATUTORY RETENTION
12.1 Control of Clinical Records
The Group explicitly affirms that all physical or electronic clinical medical records generated, captured, or stored through our platforms remain under the ultimate legal control and ownership of the treating healthcare practitioner or clinical practice. The Group maintains zero independent proprietary rights over patient files and acts purely as a technical custodian or Operator processing data on behalf of the practitioner.
12.2 Medical Record Retention Mandates
In strict compliance with the National Health Act, HPCSA ethical rulings, and general South African medical practices, healthcare records cannot be summarily destroyed or prematurely deleted. Medical files are subject to mandatory minimum statutory retention periods, including:
- A minimum standard retention period of six (6) years from the date of the last clinical entry for adult patients;
- For minors (individuals under the age of 18), records are preserved in alignment with statutory prescription limitations;
12.3 Legal Inability to Delete Healthcare Records
Data subjects are hereby explicitly notified that their general right under POPIA to request the deletion or destruction of personal data is limited by Section 67 of the National Health Act and HPCSA rules. The Group and its integrated practitioners are legally prohibited from deleting valid clinical files or billing records prior to the expiration of these statutory retention periods. If a deletion request is lodged, files will be securely isolated but preserved until all statutory retention timeframes have run their full legal course.
13. ACCOUNT CLOSURE PROTOCOLS
When a practitioner, medical practice, or individual user terminates their relationship with the Group and formally closes their platform account, a structured decommissioning sequence is initiated. General administrative profile data, marketing contact lists, and non-statutory interaction logs are systematically deleted or anonymized within ninety (90) days of account finalization. However, core billing transactions, corporate taxation ledgers, and clinical patient records are securely archived in an encrypted, read-only format to enable practitioners to meet their ongoing statutory retention and legal defense obligations.
14. INFORMATION SECURITY ARCHITECTURE & PENETRATION TESTING
The Group maintains a highly structured security model focused on protecting data confidentiality, record integrity, and system resilience. Our defenses incorporate standard administrative, physical, and digital safeguards:
- Cryptographic Shielding: Full implementation of Advanced Encryption Standard for data stored at rest and Transport Layer Security for data moving across networks.
- Access Restrictions: Multi-factor authentication (MFA) and strict role-based access control (RBAC), limiting record access to authorized individuals under the principle of least privilege.
- External Governance & Penetration Testing: Beyond continuous internal system logs, vulnerability monitoring, and daily backups, the Group undergoes regular, independent external penetration testing executed by accredited third-party cybersecurity firms. This active testing ensures that our cloud architectures remain defended against emerging threat variants.
15. DATA INTEGRITY, ACCURACY, AND MINIMISATION
The Group operates under a strict data minimisation paradigm, ensuring we do not collect or process information that is excessive or irrelevant to our core operational and healthcare services. Data subjects bear a concurrent responsibility to ensure that all information provided to our platforms is accurate, complete, and updated.
16. CORPORATE CONTINUITY & BUSINESS TRANSFERS
In the event that Etherealmed (Pty) Ltd undergoes a structural corporate transition—such as a formal merger, corporate acquisition, restructuring, or a complete sale of company assets to a successor entity—the personal data under our management will be considered a corporate asset. It may be transferred to the purchasing or successor entity to ensure continuity of your software platforms, medical practice workflows, and patient billing records. Any such successor entity will be legally bound to uphold the identical terms, data protections, and statutory obligations outlined in this Privacy Policy.
17. INTERNATIONAL / CROSS-BORDER DATA TRANSFERS
The Group primarily hosts and processes data within localized data centers inside the Republic of South Africa. Where technical cloud infrastructure requirements necessitate the routing or storage of information across international borders (e.g., global cloud providers like AWS or Azure), the Group complies fully with Section 72 of POPIA. We verify that the destination jurisdiction enforces data privacy regulations substantially similar to POPIA, or we execute binding Data Transfer Agreements that bind the recipient to strict security standards.
18. DATA BREACH RESPONSE PROTOCOLS
In the event that the Group discovers or reasonably suspects a security compromise, systemic vulnerability exploit, or unauthorized breach concerning Personal Information, a formal incident response framework is triggered. Pursuant to Section 22 of POPIA, the Group will immediately execute containment, isolation, and technical remediation protocols. We will formally notify the national Information Regulator and all affected Data Subjects as soon as reasonably possible after discovery, except where law enforcement mandates a delay to facilitate a criminal investigation.
19. GOVERNING LAW
This Privacy Policy, including its schedules, interpretations, and any disputes arising from its terms or application, is governed exclusively by and construed in accordance with the laws of the Republic of South Africa.
20. CONTACT DETAILS & STATUTORY REDRESS
For any queries, statutory access requests under PAIA, exercises of legal data rights, or formal privacy complaints, please contact our Group Information Officer using the contact points below. If you believe your privacy concerns have not been adequately resolved internally, you maintain the right to lodge a formal complaint with the Information Regulator of South Africa.
| Group Information Officer | Etherealmed (Pty) Ltd
Physical Address: The Cliffs, Block 1, 5th Floor Niagara Way Primary Email: info@paydoc.co.za Alternative Email: info@mxnode.co.za PAIA Statutory Access: www.paydoc.co.za – PAIA Manual |
| The Information Regulator (South Africa) | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Website: https://inforegulator.org.za Complaints Email: POPIAComplaints@inforegulator.org.za |