Privacy Policy
Last updated: [[DATE]]
Payed is medical billing software operated by [[COMPANY LEGAL NAME]] (registration number [[CIPC REG NUMBER]]), trading as Payed. This policy explains how we handle personal information under the Protection of Personal Information Act, 2013 (POPIA).
Information Officer: [[INFORMATION OFFICER NAME]], privacy@payed.co.za, [[PHYSICAL ADDRESS]].
1. Two kinds of information
Patient information. Practices use Payed to record and bill their patients. For this information, the practice is the responsible party and Payed is an operator: we process it only on the practice's instructions, to provide the service. Patients who want to access, correct or ask questions about their information should contact their practice first. We'll help the practice respond.
Customer and website information. For the details of practices, their staff, and people who request a demo, Payed is the responsible party.
2. Patient information we process for practices
Names, ID numbers, contact details, medical aid scheme and membership numbers, services provided, ICD-10 diagnosis codes, invoices, payments, balances, and records of emails sent. Diagnosis codes are health information, which POPIA treats as special personal information. We process it only to provide the billing service to the practice and never use it for any other purpose.
3. Information about practices and users
- Practice details: name, practice number, address, contact details, VAT number and banking details shown on invoices.
- User accounts: names, usernames, roles and hashed passwords.
- Activity records: logins and an audit log of important actions, kept for security.
- Demo requests: the name, practice, email, phone and message you send us.
4. How we protect it
- Each practice's data is kept separate, and users only see the practice they belong to.
- Staff sign in with personal accounts with role-based access.
- Connections are encrypted, and passwords are stored hashed.
- Important actions are recorded in an audit log.
- Access to servers and databases is restricted to authorised personnel.
If a security compromise affects personal information, we'll notify the affected practices without undue delay so they can meet their own POPIA obligations, and we'll notify the Information Regulator where we are required to.
5. Who we share it with
We don't sell personal information. We share it only with: our hosting provider, which stores the system; email providers used to deliver invoices and statements (usually the practice's own mail server); and authorities where the law requires it. Patient information is never shared with other practices.
6. Where it is stored
Payed is hosted on servers located in [[HOSTING COUNTRY]]. If information is processed outside South Africa, we make sure it receives protection similar to POPIA.
7. How long we keep it
We keep patient and billing records for as long as the practice's account is active, and then for the period the practice instructs or the law requires (for example, tax and medical record-keeping rules). When a practice leaves Payed, we'll return or delete its data as agreed in its contract. Demo requests are deleted after 12 months if you don't become a customer.
8. Cookies
We use one essential cookie to keep you signed in. It expires after 8 hours or when you sign out. We don't use advertising or tracking cookies.
9. Your rights
You may ask to access, correct or delete your personal information, or object to how it's used. For patient information, contact your practice. For anything else, email privacy@payed.co.za and we'll respond within 30 days. You may also complain to the Information Regulator at inforegulator.org.za.
10. Changes
We'll tell customers by email before any important change to this policy takes effect.