Privacy Policy

Our website address is: https://www.doctorbrandt.co.za. We are an online medical practice.

Privacy Policy for Dr. Brandt, Online GP Practice

Effective Date: 15/05/2026

1. Introduction

Dr. Brandt (“we”, “us”, “our”, “the practice”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website, book appointments, or use our services, in compliance with:

· The Protection of Personal Information Act (POPIA) (Act 4 of 2013)

· The Health Professions Council of South Africa (HPCSA) guidelines on patient confidentiality

· The National Health Act (Act 61 of 2003)

By using our website and services, you confirm that you have read and understood this Privacy Policy.

2. Information We Collect

We may collect the following types of personal information:

Category Examples

Identity Information – Full name, ID number, date of birth, gender

Contact Information – Email address, phone number, physical address

Health Information – Medical history, current symptoms, medications, allergies, past procedures, family history

Booking Information – Appointment dates, times, consultation type

Payment Information – Billing details, payment method (processed securely via Yoco)

Technical Information – IP address, browser type, device information, cookies

Communication Records – Emails, messages, or calls between you and the practice

3. How We Collect Your Information

We collect information in the following ways:

· Directly from you: When you book an appointment, complete forms on our website, send us an email, or communicate with us telephonically.

· Through our booking system: When you schedule a consultation through our integrated booking calendar.

· During consultations: Medical information you share during your visit (recorded in your patient file).

· Automatically: Through cookies and similar technologies when you use our website.

· From third parties: With your consent, we may receive information from other healthcare providers or your medical aid scheme.

4. How We Use Your Information

We use your personal information only for legitimate healthcare and business purposes:

Purpose Legal Basis (POPIA)

To manage appointments and consultations – Performance of a contract

To provide medical diagnosis and treatment – Performance of a contract

To communicate appointment confirmations and reminders – Performance of a contract

To process payments and provide receipts – Performance of a contract

To maintain accurate patient records (as required by HPCSA) – Compliance with a legal obligation

To respond to medical emergencies – Protection of your vital interests

To comply with legal and regulatory requirements – Compliance with a legal obligation

To improve our services and website functionality – Legitimate interest

To investigate complaints or legal claims – Legitimate interest

5. Legal Basis for Processing (POPIA)

Under POPIA, we process your personal information based on one or more of the following grounds:

Ground When It Applies

Consent – You have given explicit consent for a specific purpose (e.g., sharing your information with another healthcare provider)

Performance of a contract – Processing is necessary to provide medical services you have requested

Compliance with a legal obligation – Processing is required by law (e.g., HPCSA record-keeping requirements)

Protection of your vital interests – Processing is necessary in a medical emergency

Legitimate interest – Processing is necessary for our legitimate business interests (e.g., improving our services)

6. How We Store and Protect Your Information

We take data security seriously. We implement appropriate technical and organisational measures to protect your information, including:

· Secure servers with access controls and firewalls

· SSL encryption for all data transmitted through our website

· Strong password policies and two-factor authentication for staff access

· Regular backups of all patient data

· Staff training on confidentiality and data protection

· Limited access – only authorised healthcare staff can access your medical records

· Secure disposal – paper records are shredded; electronic records are permanently deleted when no longer required

Despite these measures, no method of transmission over the internet is 100% secure. You use our website at your own risk.

7. How Long We Keep Your Information (Retention Policy)

In compliance with HPCSA guidelines, we retain patient records for:

Record Type Retention Period

Adult patient records 6 years from the date of last contact

Minor patient records 6 years from the date the patient turns 18 (i.e., until age 24)

After the retention period expires, we securely destroy or anonymise your information so it can no longer be linked to you.

8. Sharing Your Information

We do not sell, rent, or trade your personal information. We may share your information in the following circumstances:

Recipient Reason

Third-party service providers – Booking system, payment processors, email service providers (under strict confidentiality agreements)

Other healthcare professionals – With your explicit consent, to coordinate your care

Medical aid schemes – If you choose to submit claims (invoices are provided to you for submission)

Regulatory authorities – HPCSA, Health Ombud, or courts if required by law

Law enforcement – If required by a valid legal request (e.g., court order)

All third parties who handle your information are contractually bound to comply with POPIA and maintain appropriate security measures.

9. Your Rights Under POPIA

You have the following rights regarding your personal information:

Right to access – You may request a copy of the personal information we hold about you

Right to correction – You may request that we correct inaccurate or incomplete information

Right to deletion – You may request that we delete your information (subject to HPCSA retention requirements)

Right to object – You may object to the processing of your information for certain purposes

Right to withdraw consent – Where processing is based on your consent, you may withdraw it at any time

Right to complain – You may lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, please contact us using the details provided in Section 13.

10. Cookies and Website Tracking

Our website uses cookies to enhance your browsing experience. Cookies are small text files stored on your device. We use:

Essential cookies – Required for website functionality (e.g., booking calendar)

Analytics cookies – To understand how visitors use our website (e.g., Google Analytics)

Functional cookies – To remember your preferences

You may disable cookies in your browser settings, but this may affect website functionality, including our booking calendar.

11. Children’s Privacy

Our services are not directed at children under 18. We do not knowingly collect personal information from minors without parental consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us.

12. Third-Party Links

Our website may contain links to third-party websites (e.g., payment gateways, booking platforms). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing them with your information.

13. Contact Us

For any questions about this Privacy Policy, to exercise your rights, or to report a data breach:

Dr. Sonja Brandt

Email: admin@doctorbrandt.co.za

Phone: 068 196 6906

Physical address: Galena Avenue, Kloofendal, Roodepoort, 1709

14. Complaints to the Information Regulator

If you are dissatisfied with how we have handled your personal information, you have the right to lodge a complaint with:

The Information Regulator (South Africa)

Website: https://www.inforegulator.org.za

Email: inforeg@justice.gov.za

Phone: 012 406 4818

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or our practices. The current version will always be available on our website. Material changes will be communicated to you directly (e.g., via email). The “Effective Date” at the top of this page indicates when this policy was last revised.

.