Our website address is: https://www.doctorbrandt.co.za. We are an online medical practice.
Privacy Policy for Dr. Brandt, Online GP Practice
Effective Date: 15/05/2026
1. Introduction
Dr. Brandt (“we”, “us”, “our”, “the practice”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website, book appointments, or use our services, in compliance with:
· The Protection of Personal Information Act (POPIA) (Act 4 of 2013)
· The Health Professions Council of South Africa (HPCSA) guidelines on patient confidentiality
· The National Health Act (Act 61 of 2003)
By using our website and services, you confirm that you have read and understood this Privacy Policy.
2. Information We Collect
We may collect the following types of personal information:
Category Examples
Identity Information – Full name, ID number, date of birth, gender
Contact Information – Email address, phone number, physical address
Health Information – Medical history, current symptoms, medications, allergies, past procedures, family history
Booking Information – Appointment dates, times, consultation type
Payment Information – Billing details, payment method (processed securely via Yoco)
Technical Information – IP address, browser type, device information, cookies
Communication Records – Emails, messages, or calls between you and the practice
3. How We Collect Your Information
We collect information in the following ways:
· Directly from you: When you book an appointment, complete forms on our website, send us an email, or communicate with us telephonically.
· Through our booking system: When you schedule a consultation through our integrated booking calendar.
· During consultations: Medical information you share during your visit (recorded in your patient file).
· Automatically: Through cookies and similar technologies when you use our website.
· From third parties: With your consent, we may receive information from other healthcare providers or your medical aid scheme.
4. How We Use Your Information
We use your personal information only for legitimate healthcare and business purposes:
Purpose Legal Basis (POPIA)
To manage appointments and consultations – Performance of a contract
To provide medical diagnosis and treatment – Performance of a contract
To communicate appointment confirmations and reminders – Performance of a contract
To process payments and provide receipts – Performance of a contract
To maintain accurate patient records (as required by HPCSA) – Compliance with a legal obligation
To respond to medical emergencies – Protection of your vital interests
To comply with legal and regulatory requirements – Compliance with a legal obligation
To improve our services and website functionality – Legitimate interest
To investigate complaints or legal claims – Legitimate interest
5. Legal Basis for Processing (POPIA)
Under POPIA, we process your personal information based on one or more of the following grounds:
Ground When It Applies
Consent – You have given explicit consent for a specific purpose (e.g., sharing your information with another healthcare provider)
Performance of a contract – Processing is necessary to provide medical services you have requested
Compliance with a legal obligation – Processing is required by law (e.g., HPCSA record-keeping requirements)
Protection of your vital interests – Processing is necessary in a medical emergency
Legitimate interest – Processing is necessary for our legitimate business interests (e.g., improving our services)
6. How We Store and Protect Your Information
We take data security seriously. We implement appropriate technical and organisational measures to protect your information, including:
· Secure servers with access controls and firewalls
· SSL encryption for all data transmitted through our website
· Strong password policies and two-factor authentication for staff access
· Regular backups of all patient data
· Staff training on confidentiality and data protection
· Limited access – only authorised healthcare staff can access your medical records
· Secure disposal – paper records are shredded; electronic records are permanently deleted when no longer required
Despite these measures, no method of transmission over the internet is 100% secure. You use our website at your own risk.
7. How Long We Keep Your Information (Retention Policy)
In compliance with HPCSA guidelines, we retain patient records for:
Record Type Retention Period
Adult patient records 6 years from the date of last contact
Minor patient records 6 years from the date the patient turns 18 (i.e., until age 24)
After the retention period expires, we securely destroy or anonymise your information so it can no longer be linked to you.
8. Sharing Your Information
We do not sell, rent, or trade your personal information. We may share your information in the following circumstances:
Recipient Reason
Third-party service providers – Booking system, payment processors, email service providers (under strict confidentiality agreements)
Other healthcare professionals – With your explicit consent, to coordinate your care
Medical aid schemes – If you choose to submit claims (invoices are provided to you for submission)
Regulatory authorities – HPCSA, Health Ombud, or courts if required by law
Law enforcement – If required by a valid legal request (e.g., court order)
All third parties who handle your information are contractually bound to comply with POPIA and maintain appropriate security measures.
—
9. Your Rights Under POPIA
You have the following rights regarding your personal information:
Right to access – You may request a copy of the personal information we hold about you
Right to correction – You may request that we correct inaccurate or incomplete information
Right to deletion – You may request that we delete your information (subject to HPCSA retention requirements)
Right to object – You may object to the processing of your information for certain purposes
Right to withdraw consent – Where processing is based on your consent, you may withdraw it at any time
Right to complain – You may lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, please contact us using the details provided in Section 13.
—
10. Cookies and Website Tracking
Our website uses cookies to enhance your browsing experience. Cookies are small text files stored on your device. We use:
Essential cookies – Required for website functionality (e.g., booking calendar)
Analytics cookies – To understand how visitors use our website (e.g., Google Analytics)
Functional cookies – To remember your preferences
You may disable cookies in your browser settings, but this may affect website functionality, including our booking calendar.
11. Children’s Privacy
Our services are not directed at children under 18. We do not knowingly collect personal information from minors without parental consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us.
12. Third-Party Links
Our website may contain links to third-party websites (e.g., payment gateways, booking platforms). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing them with your information.
13. Contact Us
For any questions about this Privacy Policy, to exercise your rights, or to report a data breach:
Dr. Sonja Brandt
Email: admin@doctorbrandt.co.za
Phone: 068 196 6906
Physical address: Galena Avenue, Kloofendal, Roodepoort, 1709
14. Complaints to the Information Regulator
If you are dissatisfied with how we have handled your personal information, you have the right to lodge a complaint with:
The Information Regulator (South Africa)
Website: https://www.inforegulator.org.za
Email: inforeg@justice.gov.za
Phone: 012 406 4818
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our practices. The current version will always be available on our website. Material changes will be communicated to you directly (e.g., via email). The “Effective Date” at the top of this page indicates when this policy was last revised.
.
