Medinsert Privacy Policy
This Privacy Policy describes how Medinsert (Pty) Ltd collects, uses, stores, shares, and protects your personal information when you access or use the Medinsert website (medinsert.co.za) and mobile application. By using the Service, you consent to the practices described in this Policy.
SECTION 1: INTRODUCTION AND OVERVIEW
1.1 Who We Are
Medinsert (Pty) Ltd (“Medinsert”, “we”, “us”, or “our”) is a South African technology company that develops and operates digital health information platforms, including Medinsert, accessible at medinsert.co.za and through its companion mobile application. Medinsert acts as the Responsible Party in terms of the Protection of Personal Information Act 4 of 2013 (“POPIA”) with respect to personal information collected through the Medinsert platform.
1.2 Purpose of This Policy
This Privacy Policy (“Policy”) has been prepared in compliance with POPIA, the Electronic Communications and Transactions Act 25 of 2002 (“ECT Act”), the National Health Act 61 of 2003, and the right to privacy as enshrined in Section 14 of the Constitution of the Republic of South Africa, 1996. It sets out:
- – What personal information we collect from you;
- How, why, and on what legal basis we collect and use your personal information;
- How long we retain your personal information;
- With whom we share your personal information, and under what conditions;
- How we protect your personal information;
- Your rights as a Data Subject under POPIA; and
- How to contact us or the Information Regulator of South Africa if you have concerns.
1.3 Scope of This Policy
This Policy applies to all personal information collected through:
- The Medinsert website at medinsert.co.za;
- The Medinsert mobile application (iOS and Android);
- Any APIs or integrations provided by Medinsert;
- Email, telephone, or written correspondence with Medinsert; and
- Any other channel through which you interact with Medinsert in relation to the Medinsert platform.
This Policy does not apply to third-party websites or services linked from our platform, or to the internal HR or employment data of Medinsert employees.
1.4 Audience
Medinsert is a platform designed exclusively for registered healthcare professionals in South Africa. All users are required to be registered with a recognised South African statutory healthcare council (such as HPCSA, SAPC, SANC, or AHPCSA). This Policy is accordingly directed at adult professionals with the capacity to understand and consent to its terms.
SECTION 2: LEGAL AND REGULATORY FRAMEWORK
2.1 Primary Legislation
Our processing of personal information is governed by and interpreted in accordance with the following South African legislation:
| Legislation | Relevance to This Policy |
|---|---|
| Protection of Personal Information Act 4 of 2013 (POPIA) | Primary data protection statute. Governs all collection, processing, storage, and disclosure of personal information. Establishes conditions for lawful processing and rights of Data Subjects. |
| Constitution of the Republic of South Africa, 1996 โ Section 14 | Establishes the fundamental right to privacy for all persons in South Africa. Provides constitutional grounding for data protection rights. |
| Electronic Communications and Transactions Act 25 of 2002 (ECT Act) | Governs electronic transactions, data messages, unsolicited electronic communications (spam), and consumer rights in online environments. |
| National Health Act 61 of 2003 | Governs the rights of health care users, confidentiality of health information, and the duties of healthcare providers regarding patient data. |
| Cybercrimes Act 19 of 2020 | Criminalises unauthorised access to computer systems and interception of personal data; informs our security obligations. |
| Consumer Protection Act 68 of 2008 | Regulates fair dealing, plain language requirements, and consumer rights in commercial transactions, including digital services. |
| Pharmacy Act 53 of 1974 (as amended) | Professional confidentiality obligations applicable to pharmacists using the platform. |
| Health Professions Act 56 of 1974 (as amended) | Ethical and professional confidentiality obligations applicable to HPCSA-registered practitioners. |
2.2 POPIA Key Concepts
For the purposes of this Policy, the following POPIA concepts are relevant:
| POPIA Concept | Explanation |
|---|---|
| Responsible Party | Medinsert (Pty) Ltd โ the entity that determines the purpose of and means of processing personal information. |
| Operator | A third party that processes personal information on behalf of Medinsert, under contract. |
| Data Subject | You โ the registered healthcare professional whose personal information is processed. |
| Processing | Includes any operation performed on personal information โ collection, receipt, recording, storage, updating, consultation, use, transmission, distribution, merging, linking, restriction, degradation, erasure, or destruction. |
| Personal Information | Information relating to an identifiable, living, natural person or existing juristic person, including name, contact details, registration numbers, location data, correspondence, and more. |
| Special Personal Information | Includes health or medical information, biometric data, race, religion, sexual orientation, and criminal record โ subject to heightened protection under POPIA Section 26. |
| Consent | Voluntary, specific, informed, and unambiguous agreement by a Data Subject to processing of their personal information. |
| Information Officer | The person responsible for ensuring Medinsert complies with POPIA. Contact: [email protected]. |
2.3 Eight Conditions for Lawful Processing Under POPIA
All personal information processing by Medinsert must comply with the eight conditions for lawful processing set out in POPIA. These conditions are:
| POPIA Condition | Requirement Summary | How Medinsert Complies |
|---|---|---|
| 1. Accountability | Responsible Party must ensure compliance with POPIA. | Medinsert has appointed an Information Officer and maintains this Policy. |
| 2. Processing Limitation | Personal information may only be processed with consent or another lawful ground. | We process only what is necessary and obtain consent at registration. |
| 3. Purpose Specification | Collected for a specific, explicitly defined, lawful purpose. | Purposes are stated clearly in this Policy and at the point of collection. |
| 4. Further Processing Limitation | Further processing must be compatible with original purpose. | We do not use data for undisclosed purposes without renewed consent. |
| 5. Information Quality | Data must be complete, accurate, not misleading, updated. | Users can update their profile at any time; we verify credentials periodically. |
| 6. Openness | Data Subject must be made aware of processing. | This Policy, communicated at registration, provides full transparency. |
| 7. Security Safeguards | Reasonable technical and organisational measures must protect data. | Encryption, access controls, and security audits protect all data. |
| 8. Data Subject Participation | Rights to access, correct, and object to processing must be upheld. | Rights are clearly described and can be exercised via our Information Officer. |
SECTION 3: PERSONAL INFORMATION WE COLLECT
3.1 Information You Provide Directly
We collect personal information that you voluntarily provide to us when you interact with the Medinsert platform. This includes:
3.1.1 Registration and Account Information
- Full name (first name, surname)
- Email address (used as primary account identifier and communication channel)
- Password (stored in encrypted, hashed form โ never in plain text)
- Contact telephone number (optional but may be used for account verification or support)
- Professional registration number issued by your statutory council (e.g., SAPC registration number, HPCSA registration number)
- Name of your statutory council or professional regulatory body
- Professional category and specialisation (e.g., pharmacist, medical practitioner, nurse, physiotherapist)
- Name of your employing institution or practice (optional)
- Province and city of practice
3.1.2 Profile and Preferences
- User-configured notification preferences
- Bookmarked or saved package inserts
- Preferred therapeutic areas or drug categories
- Profile photograph (optional, if enabled)
3.1.3 Communications and Support
- Content of messages submitted through the contact or support form
- Feedback, ratings, or feature requests submitted voluntarily
- Any attachments or supporting documents shared with our support team
3.2 Information Collected Automatically
When you access or use the Medinsert platform, we automatically collect certain technical and usage data. This is necessary for the operation, security, and improvement of the Service:
3.2.1 Device and Technical Data
- Internet Protocol (IP) address
- Device type, model, and operating system version
- Browser type, version, and language settings
- Mobile device identifiers (where applicable, including device UUID)
- Screen resolution and display settings
- Time zone and locale
3.2.2 Log and Session Data
- Date, time, and duration of access sessions
- Pages visited, features accessed, and navigation paths within the platform
- Search queries entered into the platform search function
- Package inserts viewed, downloaded, or bookmarked
- Error logs and crash reports
- Referral URL (the web address from which you arrived at medinsert.co.za, if applicable)
3.2.3 Cookies and Similar Technologies
Medinsert uses cookies, local storage, session tokens, and similar tracking technologies. Please refer to Section 11 of this Policy for a detailed explanation of our cookie practices.
3.3 Information from Third Parties
In limited circumstances, we may receive personal information from third-party sources, including:
- Professional registration verification services used to confirm your credentials with the relevant statutory council;
- Analytics or performance monitoring service providers (in aggregated or pseudonymised form);
- Payment processors, if you subscribe to a paid tier (we do not receive or store your full card details); and
- References or verification submissions from your employing institution or supervisor, where applicable.
3.4 Special Personal Information
| Special Personal Information: Medinsert processes certain categories of information that may qualify as “special personal information” under POPIA Section 26, namely your healthcare professional registration details and professional health-sector affiliation. While this does not constitute patient health information, it relates to a regulated health profession. Medinsert processes this data solely on the basis of your explicit consent and for the purpose of verifying professional eligibility to use the platform. |
Medinsert does NOT collect patient health records, clinical notes, prescription data, or any identifiable patient information. The platform is a reference tool for healthcare professionals and is not designed or intended for patient data capture.
SECTION 4: HOW WE USE YOUR PERSONAL INFORMATION
4.1 Purposes of Processing
Medinsert processes your personal information only for specific, explicitly defined, and lawful purposes, as required by POPIA Section 13. The table below sets out each processing purpose, the category of information used, and the legal basis for processing:
| Purpose | Data Categories Used | Legal Basis (POPIA) |
|---|---|---|
| Account creation and authentication | Name, email, password, registration number | Consent; contract performance |
| Professional credential verification | Registration number, professional category, council name | Consent; legitimate interest |
| Providing and personalising the Service | Profile info, bookmarks, usage data, search history | Contract performance; consent |
| Platform security and fraud prevention | IP address, device data, log data, session data | Legitimate interest; legal obligation |
| Service improvement and analytics | Aggregated/anonymised usage data, device data | Legitimate interest (analytics are anonymised where possible) |
| Service communications and notifications | Email address, notification preferences | Contract performance; consent |
| Subscription and payment processing | Name, email, billing details (via payment processor) | Contract performance; legal obligation |
| Legal compliance and dispute resolution | All categories as required by law or legal proceedings | Legal obligation; legitimate interest |
4.2 Marketing Communications
Medinsert may, from time to time, send you information about new features, platform updates, educational content relevant to your profession, or information about other Medinsert products. Such communications will only be sent where you have opted in to receive them, in compliance with Section 45 of the ECT Act, which prohibits unsolicited commercial electronic communications. You may opt out of marketing communications at any time by:
- Clicking the “unsubscribe” link in any marketing email;
- Updating your notification preferences in your account settings; or
- Contacting us at [email protected].
Opting out of marketing communications will not affect service-related communications, such as account security alerts, password resets, or important policy updates, which form part of the contractual service.
4.3 Automated Decision-Making
Medinsert may use automated processes for the following purposes:
- Verification of your professional registration number format against expected patterns for your selected council;
- Automated detection of unusual access patterns that may indicate unauthorised account use or security threats;
- Personalisation of search results and content recommendations based on your usage history and professional profile.
Where any automated decision-making has a significant legal or similarly significant effect on you, you have the right to request human review of that decision. To exercise this right, contact [email protected].
SECTION 5: SHARING AND DISCLOSURE OF PERSONAL INFORMATION
5.1 General Principle
| Medinsert does not sell, rent, trade, or monetise your personal information to any third party. Personal information is shared only where strictly necessary, in the categories and circumstances described below. |
5.2 Service Providers (Operators)
We engage trusted third-party service providers (“Operators” under POPIA) who process personal information on our behalf for specific, limited purposes. All such Operators are contractually required to:
- Process personal information only on documented instructions from Medinsert;
- Maintain appropriate technical and organisational security measures;
- Not engage sub-processors without our prior authorisation;
- Delete or return all personal information upon termination of the service agreement; and
- Comply with POPIA and all applicable South African data protection laws.
Categories of Operators we engage include:
| Operator Category | Purpose |
|---|---|
| Cloud hosting and infrastructure providers | Hosting the Medinsert website, database, and application servers on secure cloud infrastructure. |
| Email delivery service providers | Sending transactional emails such as registration confirmation, password reset, and service notifications. |
| Analytics service providers | Providing aggregated, anonymised platform usage statistics to help improve the Service. No individual-level data is shared. |
| Payment processors | Processing subscription payments securely. Medinsert does not receive or store card details; payment data is handled by PCI-DSS compliant processors. |
| Professional verification services | Confirming the validity of healthcare professional registration numbers with relevant statutory councils. |
| Customer support tools | Managing support requests and user communications through our support platform. |
| Security and monitoring services | Providing intrusion detection, vulnerability scanning, and uptime monitoring. |
5.3 Legal and Regulatory Disclosure
Medinsert may be required or permitted by law to disclose your personal information to competent authorities or third parties in the following circumstances:
- In response to a court order, search warrant, subpoena, or other lawful legal process issued under South African law;
- To comply with a request from a law enforcement authority, regulatory body, or government agency with lawful jurisdiction;
- Where we reasonably believe disclosure is necessary to protect the safety of any person or to prevent fraud, criminal activity, or a threat to public health;
- To SAHPRA or another health regulatory authority where required by health sector legislation; or
- To the Information Regulator of South Africa in the context of an investigation or compliance matter.
Where legally permissible, we will notify you of any such disclosure request before complying with it.
5.4 Business Transfers
In the event that Medinsert undergoes a merger, acquisition, reorganisation, asset sale, or insolvency proceedings, your personal information may be transferred to a successor entity as part of that transaction. In such circumstances, we will:
- Provide you with reasonable advance notice of the transfer;
- Ensure that the successor entity is bound by this Policy or an equivalent privacy policy; and
- Allow you to delete your account prior to the transfer if you do not wish to have your data transferred.
5.5 Anonymised and Aggregated Data
Medinsert may share anonymised, aggregated, or pseudonymised data โ from which individual users cannot reasonably be identified โ with research institutions, pharmaceutical industry partners, healthcare bodies, or the public for purposes including platform usage reporting, health sector analytics, and product improvement. This does not constitute disclosure of personal information under POPIA.
5.6 Cross-Border Transfers
Medinsert’s primary infrastructure is hosted within the Republic of South Africa or within jurisdictions that offer adequate data protection comparable to POPIA. Where personal information is processed outside South Africa by an Operator (for example, by a global cloud provider), Medinsert will only permit such transfers where:
- The recipient country’s laws provide an adequate level of protection for personal information as contemplated in POPIA Section 72; or
- We have entered into binding contractual arrangements with the recipient that impose POPIA-equivalent obligations; or
- You have consented to the transfer after being informed of the lesser degree of protection that may apply.
SECTION 6: DATA RETENTION
6.1 General Retention Principle
Medinsert retains personal information only for as long as is necessary to fulfil the specific purpose for which it was collected, or as required by applicable law, regulatory guidance, or legitimate business need โ in accordance with POPIA Section 14. We do not retain personal information in a form that permits identification of Data Subjects for longer than is reasonably necessary.
6.2 Retention Schedule
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account registration data (name, email, registration number) | Duration of account, plus 5 years after closure | Legal obligation; dispute resolution |
| Professional verification records | Duration of account, plus 3 years after closure | Legitimate interest; legal compliance |
| Usage and activity logs (searches, bookmarks, sessions) | 2 years from date of creation (rolling) | Security; service improvement |
| Support and communications records | 3 years from last correspondence | Legitimate interest; dispute resolution |
| Payment and subscription records | 5 years from transaction date | Legal obligation (SARS; Companies Act) |
| Security and access logs (IP, device) | 12 months on a rolling basis | Security monitoring; Cybercrimes Act |
| Marketing consent records | Duration of consent, plus 3 years after withdrawal | Legal obligation (ECT Act compliance) |
| Anonymised analytics data | Indefinite (cannot be linked to individual) | No restriction (not personal information) |
6.3 Deletion and Destruction
Upon expiry of the applicable retention period, personal information will be securely deleted, destroyed, or anonymised, in accordance with POPIA Section 14 and our internal data disposal procedures. Secure deletion means that the data cannot be reconstructed or recovered after deletion. Where technical limitations prevent immediate deletion (for example, backup systems), data will be isolated from further active processing and destroyed at the earliest practicable opportunity.
6.4 Account Closure
If you close your Medinsert account, we will:
- Deactivate your account immediately upon request;
- Cease active processing of your personal information for service delivery purposes;
- Retain certain categories of data for the periods specified in the retention schedule above, in accordance with our legal obligations; and
- Delete all retained data at the end of the applicable retention period.
You may request confirmation of deletion by contacting [email protected].
SECTION 7: SECURITY OF PERSONAL INFORMATION
7.1 Our Security Commitment
Medinsert takes the security of your personal information seriously and has implemented a range of technical, administrative, and physical security measures to protect personal information against unauthorised access, loss, disclosure, alteration, or destruction, in accordance with POPIA Section 19 and industry best practices.
7.2 Technical Security Measures
- Transport Layer Security (TLS/HTTPS) encryption for all data in transit between your device and our servers;
- At-rest encryption for databases containing personal information;
- Bcrypt or equivalent strong hashing algorithms for all stored passwords โ passwords are never stored in plain text;
- Multi-factor authentication (MFA) options available for account login;
- Role-based access controls (RBAC) limiting staff access to personal information on a strict need-to-know basis;
- Automated session timeout after a period of inactivity;
- Regular automated vulnerability scanning and penetration testing;
- Web Application Firewall (WAF) and DDoS protection;
- Intrusion detection and monitoring systems operating on a continuous basis.
7.3 Administrative and Organisational Measures
- All staff and contractors with access to personal information are bound by confidentiality agreements;
- Regular privacy and security awareness training for personnel;
- Formal data breach response procedures, including notification protocols;
- A designated Information Officer responsible for POPIA compliance;
- Vendor due diligence assessments for all Operators processing personal data on our behalf;
- Formal data processing agreements with all Operators;
- Regular internal policy reviews and audits.
7.4 Your Responsibilities
While we implement robust security measures, the security of your account also depends on your own actions. You are responsible for:
- Choosing a strong, unique password and not sharing it with any person;
- Logging out of your account after each session, particularly on shared or public devices;
- Keeping your device’s operating system and browser up to date;
- Notifying us immediately at [email protected] if you suspect any unauthorised access to your account; and
- Not accessing the platform over unsecured or public Wi-Fi networks without a VPN.
7.5 Data Breach Notification
In the event of a security compromise involving your personal information that is reasonably likely to cause harm to you, Medinsert will comply with its notification obligations under POPIA Section 22. This includes:
- Notifying the Information Regulator of South Africa as soon as reasonably possible after discovery of the breach;
- Notifying affected Data Subjects in writing (via email) as soon as reasonably possible, with sufficient information to allow you to take protective steps; and
- Documenting the breach and the response measures taken, as required by POPIA.
Notification will include the nature of the breach, the personal information involved, the measures we have taken, and guidance on steps you can take to protect yourself.
SECTION 8: YOUR RIGHTS AS A DATA SUBJECT
8.1 Overview of Your Rights
As a Data Subject under POPIA, you have important rights regarding your personal information. These rights are summarised below. To exercise any of these rights, please contact our Information Officer at [email protected]. We will respond to all lawful requests within a reasonable period, and not later than 30 days from receipt of your request, unless exceptional circumstances require an extension.
8.2 Right to Be Notified (Section 18, POPIA)
You have the right to be informed when Medinsert collects your personal information, of the purpose for which it is collected, whether supply of the information is voluntary or mandatory, the consequences of non-supply, and the identity of any third parties to whom information may be transferred. This Policy, presented to you at the point of registration, fulfils this obligation.
8.3 Right of Access (Section 23, POPIA)
You have the right to request confirmation of whether Medinsert holds personal information about you, and to receive a copy of that information. Your access request should be submitted in writing to [email protected]. We may require you to verify your identity before processing your request. We are entitled to charge a prescribed fee for processing access requests in certain circumstances, as set out in POPIA regulations.
8.4 Right to Correction (Section 24, POPIA)
You have the right to request that we correct or delete personal information that is inaccurate, incomplete, outdated, irrelevant, excessive, misleading, or obtained unlawfully. You may update your own account profile information at any time through your account settings. For information you are unable to self-update, submit a correction request to [email protected]. We will either correct the information or provide a written explanation for why we are unable to do so, within 30 days.
8.5 Right to Deletion / Erasure (Section 24, POPIA)
You may request that we delete or destroy your personal information where:
- The purpose for which it was collected has been fulfilled and retention is no longer legally required;
- You have withdrawn your consent, and there is no other lawful basis for continued processing;
- The information was collected unlawfully; or
- Deletion is required to comply with a legal obligation.
Note that we may be obligated by law to retain certain categories of data for specified periods (see Section 6), and erasure requests that conflict with those obligations may be partially declined, with written reasons provided.
8.6 Right to Object (Section 11(3), POPIA)
You have the right to object, on reasonable grounds, to the processing of your personal information in circumstances where we rely on our legitimate interests as the legal basis for processing. Where we process your information for direct marketing purposes, you have an absolute right to object at any time, without providing justification. We will cease such processing promptly upon receipt of a valid objection.
8.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, contact [email protected] or update your preferences in your account settings. Withdrawal of consent to certain essential processing may result in the inability to provide the Service to you.
8.8 Right to Lodge a Complaint
If you believe that Medinsert has not complied with its obligations under POPIA, or that your personal information has been processed in violation of your rights, you have the right to lodge a complaint with the Information Regulator of South Africa:
| Contact Detail | Information Regulator of South Africa |
|---|---|
| [email protected] | |
| Website | www.justice.gov.za/inforeg |
| Physical Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal Address | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
We encourage you to contact our Information Officer first, to allow us an opportunity to address your concerns before escalating to the Information Regulator.
8.9 How to Submit a Data Subject Request
All Data Subject requests should be submitted in writing to our Information Officer at [email protected] with the subject line “POPIA Data Subject Request โ [Your Full Name]”. Please include:
- Your full name and email address registered on the platform;
- A clear description of the right you wish to exercise;
- Any supporting information or context relevant to your request; and
- A copy of a valid form of identification (for verification purposes).
We will acknowledge your request within 5 business days and respond substantively within 30 calendar days. Where we require additional time or information, we will notify you in writing.
SECTION 9: CHILDREN AND MINORS
The Medinsert platform is exclusively for use by registered healthcare professionals and is not directed at children or persons under the age of 18 years. We do not knowingly collect personal information from minors. If we become aware that a minor has registered for an Account, we will suspend that Account immediately and take steps to delete the associated personal information as soon as practicable. If you are the parent or legal guardian of a minor who you believe has provided information to Medinsert without appropriate consent, please contact us at [email protected] and we will take prompt action.
SECTION 10: HEALTH INFORMATION AND PATIENT CONFIDENTIALITY
10.1 No Patient Data Collection
| Medinsert is a professional reference platform. It does not collect, store, or process patient health records, clinical notes, prescription data, patient identifiers, or any other personally identifiable patient health information. Healthcare professionals must not enter, upload, or submit any patient-identifiable information through the Medinsert platform. |
10.2 Your Professional Confidentiality Obligations
Healthcare professionals using Medinsert remain fully subject to their professional confidentiality obligations under the National Health Act 61 of 2003, POPIA, and the ethical rules and codes of their statutory council. Nothing in your use of the Medinsert platform modifies, limits, or satisfies any patient confidentiality obligation imposed on you by law or professional ethics.
10.3 Professional Registration Information
Your professional registration number and healthcare profession details are collected solely to verify your eligibility to use the platform. This information is not shared with patients, pharmaceutical companies, or any party other than as described in Section 5 of this Policy. It is not used to monitor or evaluate your clinical practice.
SECTION 11: COOKIES AND TRACKING TECHNOLOGIES
11.1 What Are Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work more efficiently, remember your preferences, and provide information to website owners. Similar technologies include web beacons, pixel tags, local storage, and session storage.
11.2 Cookies We Use
| Cookie Type | Examples / Names | Purpose and Legal Basis |
|---|---|---|
| Strictly Necessary | Session token; CSRF token; authentication cookie | Required to enable core platform functionality such as login sessions and security. Cannot be disabled. Legal basis: contract performance. |
| Functional / Preference | language_pref; theme; last_viewed_category | Remembers your preferences and customises your experience. Can be disabled without affecting core functionality. Legal basis: consent. |
| Analytics / Performance | _ga; _gid (Google Analytics or equivalent, pseudonymised) | Collects anonymised data on how users interact with the platform. Used to identify popular content and diagnose issues. Legal basis: consent; legitimate interest. |
| Security Monitoring | csrf_token; rate_limit_id | Protects against Cross-Site Request Forgery (CSRF) and brute-force login attempts. Required for platform security. Legal basis: legitimate interest. |
11.3 Cookie Consent and Controls
When you first access the Medinsert platform, you will be presented with a cookie consent notice. You may accept all cookies, accept only strictly necessary cookies, or customise your preferences. You can change your cookie settings at any time through your browser settings or the cookie preferences panel on the Platform.
Note that disabling strictly necessary cookies may impair your ability to log in or use core features of the platform. Disabling analytics or functional cookies will not affect your ability to use the core Service.
SECTION 12: THIRD-PARTY LINKS AND SERVICES
The Medinsert platform may contain hyperlinks to external websites and resources, including the SAHPRA online medicine database, pharmaceutical manufacturer websites, clinical guideline repositories, and professional council portals. These external sites are not operated by Medinsert and are not covered by this Privacy Policy.
We encourage you to review the privacy policies of any third-party sites you visit. Medinsert has no control over and accepts no responsibility for the privacy practices, content, security, or availability of any external site. The inclusion of a link does not imply endorsement of the linked website or its operator.
SECTION 13: CHANGES TO THIS PRIVACY POLICY
13.1 Right to Amend
Medinsert reserves the right to review, update, and amend this Privacy Policy periodically to reflect changes in applicable law, regulatory guidance, our data processing practices, or new features of the Service. The most current version of this Policy will always be available on the Medinsert platform at medinsert.co.za/privacy-policy.
13.2 Notification of Material Changes
Where we make material changes to this Policy โ including changes that affect how we use your personal information, changes to your rights, or changes in how we share data with third parties โ we will notify you by:
- Email notification to your registered email address, at least fourteen (14) days before the change takes effect; and/or
- A prominent notice displayed on the Medinsert platform when you next log in.
Your continued use of the Service after the effective date of any amended Policy constitutes your acceptance of the revised terms. If you do not accept the amended Policy, you must cease using the Service and may request deletion of your account.
13.3 Version History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.0 | April 2026 | Initial publication โ Comprehensive POPIA-compliant Privacy Policy for Medinsert platform. |
SECTION 14: CONTACT US AND DATA SUBJECT REQUESTS
14.1 Information Officer
Medinsert has designated an Information Officer as required by POPIA Section 55. The Information Officer is responsible for ensuring the company’s compliance with POPIA, handling Data Subject requests, and liaising with the Information Regulator of South Africa. All formal POPIA-related enquiries, complaints, and requests must be directed to the Information Officer.
14.2 Contact Details
| Contact | Details |
|---|---|
| Organisation | Medinsert (Pty) Ltd |
| Platform | Medinsert (medinsert.co.za) |
| Information Officer Email | [email protected] |
| General Support | [email protected] |
| Content Accuracy Issues | [email protected] |
| Developer / Corporate | Medinsert.co.za |
| Data Subject Request Subject Line | “POPIA Data Subject Request โ [Your Full Name]” |
| Response Timeline | Acknowledgement within 5 business days; substantive response within 30 calendar days |
14.3 Information Regulator of South Africa
If you are not satisfied with our response to your Data Subject request or complaint, you have the right to escalate your complaint to the Information Regulator of South Africa, the independent statutory body established under POPIA to oversee data protection compliance in South Africa.
| Contact | Information Regulator of South Africa |
|---|---|
| Email (General Enquiries) | [email protected] |
| Email (Complaints) | [email protected] |
| Website | www.inforegulator.org.za |
| Physical Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal Address | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
ACKNOWLEDGEMENT AND CONSENT
| By registering for and using the Medinsert Service, you acknowledge that you have read this Privacy Policy in its entirety, that you understand how your personal information will be collected, used, stored, and shared, and that you consent to such processing in accordance with this Policy. If you do not agree to the terms of this Privacy Policy, you must not access or use the Medinsert platform. |