Privacy Policy

Last updated: [[DATE]]

Payed is medical billing software operated by [[COMPANY LEGAL NAME]] (registration number [[CIPC REG NUMBER]]), trading as Payed. This policy explains how we handle personal information under the Protection of Personal Information Act, 2013 (POPIA).

Information Officer: [[INFORMATION OFFICER NAME]], privacy@payed.co.za, [[PHYSICAL ADDRESS]].

1. Two kinds of information

Patient information. Practices use Payed to record and bill their patients. For this information, the practice is the responsible party and Payed is an operator: we process it only on the practice's instructions, to provide the service. Patients who want to access, correct or ask questions about their information should contact their practice first. We'll help the practice respond.

Customer and website information. For the details of practices, their staff, and people who request a demo, Payed is the responsible party.

2. Patient information we process for practices

Names, ID numbers, contact details, medical aid scheme and membership numbers, services provided, ICD-10 diagnosis codes, invoices, payments, balances, and records of emails sent. Diagnosis codes are health information, which POPIA treats as special personal information. We process it only to provide the billing service to the practice and never use it for any other purpose.

3. Information about practices and users

4. How we protect it

If a security compromise affects personal information, we'll notify the affected practices without undue delay so they can meet their own POPIA obligations, and we'll notify the Information Regulator where we are required to.

5. Who we share it with

We don't sell personal information. We share it only with: our hosting provider, which stores the system; email providers used to deliver invoices and statements (usually the practice's own mail server); and authorities where the law requires it. Patient information is never shared with other practices.

6. Where it is stored

Payed is hosted on servers located in [[HOSTING COUNTRY]]. If information is processed outside South Africa, we make sure it receives protection similar to POPIA.

7. How long we keep it

We keep patient and billing records for as long as the practice's account is active, and then for the period the practice instructs or the law requires (for example, tax and medical record-keeping rules). When a practice leaves Payed, we'll return or delete its data as agreed in its contract. Demo requests are deleted after 12 months if you don't become a customer.

8. Cookies

We use one essential cookie to keep you signed in. It expires after 8 hours or when you sign out. We don't use advertising or tracking cookies.

9. Your rights

You may ask to access, correct or delete your personal information, or object to how it's used. For patient information, contact your practice. For anything else, email privacy@payed.co.za and we'll respond within 30 days. You may also complain to the Information Regulator at inforegulator.org.za.

10. Changes

We'll tell customers by email before any important change to this policy takes effect.