Privacy Policy
Version 2.0 · effective 15 September 2026. This version supersedes the policy last updated on 14 June 2026.
This Privacy Policy explains how Netpractice collects, uses, stores, and protects personal information when you use the Service. Netpractice is committed to compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and all other applicable South African privacy legislation.
It should be read together with our Terms of Service, our Operator Agreement, and our PAIA Manual.
1. Who We Are
Netpractice (Pty) Ltd ("Netpractice", "we", "us", or "our"), registration number 2012/072246/07, operates an online healthcare practice management and medical billing platform.
Our role under POPIA depends on whose information is involved:
- We are the Responsible Party for information about your practice and its users - the account, billing, and support information we need in order to provide the Service to you.
- We are your Operator for the patient information your practice enters into the Service. Your practice is the Responsible Party for that information, and we process it only on your instruction. The terms are set out in our Operator Agreement.
Our Information Officer is Mpatle Ditabo, contactable at privacy@netpractice.co.za.
2. Personal Information We Collect
We collect personal information that is necessary to provide and improve the Service. This includes:
Practice & User Information: Name, professional registration number, contact details, HPCSA or relevant registration body details, banking information for billing, and login credentials.
Patient Information (as entered by you): Name, identity or passport number, date of birth, contact details, medical aid membership details, and clinical or billing information entered by your practice into the Service.
Technical & Usage Information: IP address, browser type, device identifiers, session activity logs, and aggregated, non-identifying usage statistics.
We do not collect more personal information than is necessary for the stated purposes.
3. How We Use Your Information
Netpractice processes personal information only for lawful purposes under POPIA. We use your information to:
- provide, operate, maintain, and improve the Service;
- process subscriptions, invoices, and payments;
- send Service-related communications, including billing notifications, feature updates, and system alerts;
- provide technical support and resolve system issues;
- comply with our legal and regulatory obligations;
- generate aggregated, anonymised analytics to understand how the Service is used and to improve its design and functionality.
We will never use your patient Data or practice information for marketing, profiling, or any purpose unrelated to the Service without your explicit consent.
4. Healthcare & Patient Data
Patient health information is Special Personal Information under section 26 of POPIA and is afforded the highest level of protection. Netpractice acts as an Operator in relation to patient Data entered by your practice, and processes it only on your instruction and for the purposes of providing the Service.
As the Responsible Party for your patients' information, you are responsible for:
- having a lawful basis for the processing before capturing health information through the Service, whether that is the patient's consent or the medical-treatment basis in section 32(1) of POPIA, in accordance with the NHA and POPIA;
- ensuring that patient records are accurate, complete, and lawfully held;
- complying with HPCSA confidentiality guidelines regarding patient information.
Netpractice staff will not access identifiable patient records except where you have granted permission to assist with a technical issue, or where access is unavoidable in maintaining the Service. Such access is logged.
In designing the safeguards described in section 6 below, we have regard to the security standards expected of parties processing health information in South Africa, including those reflected in the Regulations relating to the Processing of Data Subjects' Health or Sex Life by Certain Responsible Parties published under section 112(2)(c) of POPIA and in force from 6 March 2026.
5. You Own Your Data
All Data you enter into the Service remains your property. Netpractice does not claim ownership of your Data and will not use it for any purpose beyond providing and improving the Service. On request, we will provide you with a full export of your Data in a common machine-readable format.
6. Data Security
Netpractice maintains appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, and unlawful access or processing, as required by section 19 of POPIA. These measures include:
- TLS encryption for all data in transit between your browser and our servers;
- encryption of data at rest;
- role-based access controls limiting staff access to personal information, with access logging;
- network controls restricting access to the systems that hold patient information;
- periodic security risk assessment, with mitigation measures reviewed and updated for effectiveness;
- daily automated back-ups to secure, redundant storage;
- secure disposal of records, so that deleted information cannot be reconstructed in an intelligible form.
While we take all reasonable precautions, no system is completely secure. You are responsible for keeping your login credentials confidential. Please notify us immediately at security@netpractice.co.za if you suspect any unauthorised access to your account.
7. If Something Goes Wrong
Where we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will:
- notify the affected practice in writing without undue delay, and in any event within 72 hours of becoming aware of it;
- tell you what we know about what happened, what information was involved, and what we are doing about it;
- give you the information you reasonably need in order to meet your own notification obligations under section 22 of POPIA;
- notify the Information Regulator through its eServices portal, and affected data subjects, where the law requires us to.
Where we act as your Operator, the obligation to notify the Information Regulator and the affected patients rests with you as the Responsible Party. We will support you in doing so.
8. Data Retention & Deletion
We retain your personal information for as long as your subscription is active and for a further 40 days after termination, unless a longer retention period is required by law.
We will not delete your Data during that period without first giving you a reasonable opportunity to export it. Where you are legally obliged to retain records for longer - for example, patient record retention obligations under the NHA and HPCSA rules - we will extend the retention period on your written request.
After the retention period, your Data will be securely deleted, destroyed, or de-identified in a manner that prevents its reconstruction in an intelligible form. You may request early deletion of your personal information by contacting privacy@netpractice.co.za, subject to any overriding legal obligations.
9. Sharing of Information
Netpractice does not sell your personal information or patient Data to any third party. We share personal information only in the following limited circumstances:
Sub-operators. We engage service providers who process personal information strictly on our instruction, under written agreements imposing obligations no less protective than those we owe you. We remain responsible to you for their processing. Our current sub-operators are:
| Provider | What it does | Where it processes |
|---|---|---|
| Microsoft (Azure) | Cloud hosting, databases, storage, back-ups | South Africa (primary); Ireland for certain legacy components |
| Twilio, incl. SendGrid | Transactional email, SMS notifications, voice support line | United States |
| PayGate | Card payment processing for subscription fees | South Africa |
| Cloudflare | Bot protection on our sign-up and public forms | Global edge network |
| Anthropic | Optional AI assistance and support chat, where your practice has enabled it | United States |
| Xero | Our own accounting records, including your practice billing details | Outside South Africa |
Medical schemes, and the switches that reach them. When you submit a claim, we transmit it on your instruction to the medical scheme or scheme administrator concerned - for example Discovery Health, Bonitas, GEMS, or Metropolitan Health, depending on the patient's cover. Most schemes are not reached directly: the claim passes through a switching provider that connects healthcare providers to schemes. We currently use MediLink, Allegra, SwitchOn, and a direct connection to Metropolitan Health.
Which route a given claim takes is determined by the scheme and plan you are claiming against, not by us choosing a supplier. Schemes change their own connections from time to time, so this list changes. The current list is always the one published here.
Schemes, scheme administrators, and switching providers are separate Responsible Parties. They process claim information for their own purposes - adjudicating and paying the claim - under their own privacy terms and the rules of the relevant scheme, not on our instruction.
Legal & Regulatory Authorities. We may disclose personal information where required to do so by applicable law, court order, or a regulatory authority.
Professional Advisors. We may share information with our auditors and legal advisors where necessary, subject to their professional duties of confidentiality.
10. Cross-Border Data Transfers
Patient information entered into the Service is hosted primarily in South Africa. Some processing takes place outside the Republic, as set out in the sub-operator table above.
Where we transfer personal information outside South Africa, we do so only on a basis permitted by section 72 of POPIA - in practice, under written agreements that impose data protection obligations substantially similar to POPIA's conditions for lawful processing, or where the transfer is necessary to perform our contract with you.
If you would like the specific transfer basis for any provider listed above, write to privacy@netpractice.co.za and we will provide it.
11. Cookies & Session Management
The Service uses session cookies and similar technologies to maintain your authenticated session, remember your preferences, and ensure the security of your account. These cookies do not identify you personally beyond the current session. Clearing or disabling cookies may limit Netpractice functionality.
We do not store your card details. Payment information is processed and held securely by our authorised payment service provider in accordance with PCI-DSS standards.
12. Analytics and advertising cookies
On our public website (netpractice.co.za) we use Google Analytics 4 and Google Ads to understand how visitors find and use the site and to measure the effectiveness of our advertising. These services set cookies and may process pseudonymous identifiers (such as a randomly-generated client ID) together with usage data. This helps us improve the site and our marketing; we do not use it to identify you by name.
In line with POPIA, these analytics and advertising cookies are denied by default and are only activated if you select Accept on our cookie banner (we use Google Consent Mode). You can change your choice at any time via the Cookie preferences link in the footer, or by clearing cookies in your browser. Declining does not affect your ability to use the website, and you can additionally opt out of Google Analytics on all sites using Google's browser opt-out add-on.
We do not use advertising cookies inside the Service itself.
13. Your Rights Under POPIA
As a data subject under POPIA, you have the following rights:
- Right of Access - to request confirmation of whether we hold your personal information and to receive a copy of it;
- Right to Correction - to request that inaccurate or incomplete personal information be corrected or updated;
- Right to Deletion - to request the deletion of your personal information where we are no longer legally required to retain it;
- Right to Object - to object, on reasonable grounds, to the processing of your personal information, and at any time to its processing for direct marketing;
- Right to Complain - to lodge a complaint with the Information Regulator (South Africa) if you believe your rights under POPIA have been infringed.
To exercise any of these rights, contact our Information Officer at privacy@netpractice.co.za. We will respond within 30 days of receipt of your request. Requests for access to records may also be made under PAIA using the procedure in our PAIA Manual.
If you are a patient of a practice that uses Netpractice, your request should be directed to that practice, which is the Responsible Party for your information. If you send it to us, we will pass it on and support the practice in responding.
14. Direct Marketing
Netpractice may send you Service-related communications, including billing notices, product updates, and Service announcements. Where we send direct marketing communications by electronic means, we do so only with your consent or to existing customers in respect of similar services, and every such message contains a clear and easy mechanism to opt out. You may also contact us at any time to opt out of marketing emails. We process opt-out requests promptly and do not ask again once you have refused.
15. Third-Party Links & Integrations
The Service may enable integrations with authorised third-party applications. Netpractice is not responsible for the privacy practices or content of those third-party services. We recommend reviewing the privacy policy of any third-party application you connect to through the Service.
16. Updates to this Policy
Netpractice may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. Material changes will be communicated to you by email or in-platform notification. Each version carries a version number and effective date, and superseded versions are listed below and remain available on request.
17. Contact & Complaints
For any privacy-related queries, requests, or complaints, please contact:
Information Officer - Netpractice (Pty) Ltd
Mpatle Ditabo
Email: privacy@netpractice.co.za
Website: www.netpractice.co.za
If you are not satisfied with our response, you have the right to escalate your complaint to:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Telephone: 010 023 5200
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za
Version history
| Version | Effective | Note |
|---|---|---|
| 2.0 | 15 September 2026 | Named Information Officer and sub-operators, added breach notification, cross-border disclosure, health-information safeguards, retention and export on exit, and full data subject rights. |
| 1.1 | 14 June 2026 | Cookie consent and analytics disclosure added (Consent Mode). |
| 1.0 | Pre-2021 | Original policy. Available on request from privacy@netpractice.co.za. |