The short version
Telafia lets you see a licensed doctor from your phone. To do that we need some personal information (your phone number and name) and, during a consultation, health information. We use it only to give you care, to take payment, and to meet our legal duties. We never sell it and we never put health information in a text message.
This notice is written for people in South Africa. The law that protects you here is the Protection of Personal Information Act 2013 (POPIA), supervised by the Information Regulator (South Africa).
What we collect
- Account: phone number, name, country, language, and the time you gave consent.
- Bookings: the doctor, time, consultation type, and anything you choose to write about your reason for booking.
- Health records you add: allergies, conditions, medicines, vitals. Stored encrypted.
- Consultation notes and prescriptions written by your doctor. Notes are stored encrypted.
- Payments: amount, currency, payment reference and status. We never see your card or mobile-money PIN; the payment provider handles that.
- Call signalling: short technical messages that connect your call. The call audio and video go directly between you and the doctor (or through a relay that does not record them) and are never stored by us.
- Activity log: who did what and when (for example “doctor read note”), to protect your records.
Health information
Health information is "special personal information" under POPIA. We process it with your consent and because it is necessary for the health care you asked for from a registered practitioner.
Only you and the doctor you booked can read your consultation notes. Administrators can see that an appointment happened and whether it was paid, but not what was discussed. Every time a note is read, we record who read it.
Why we are allowed to use it
- Your consent, which you gave when you created your account and can withdraw at any time.
- Providing the service you asked for (the consultation and payment).
- Legal duties, such as keeping financial records for tax and keeping medical records for the period the Health Professions Council of South Africa (HPCSA) requires.
Who else sees it
We use a small number of service providers, each bound by contract to protect your data:
- Linode (hosting)
- Cloudflare (TURN relay for calls; media is end-to-end between devices and the relay does not store it)
- Paystack / Flutterwave (payments; they see your name, email and amount, never your health data)
- Termii (SMS codes and reminders; messages never contain health information)
Your data is stored on a server in a European data centre (Linode), with daily encrypted backups. Where the law in South Africa requires safeguards for storing data abroad, we rely on contractual protections and encryption.
We share information with authorities only when the law clearly requires it.
How long we keep it
Your account and health records for as long as you use the service. HPCSA guidance requires clinical records to be kept for at least 6 years from the last entry (longer for minors). Financial records are kept for 5 years for SARS. When you ask us to delete your account we remove or anonymise everything we are not legally required to keep (see Your rights).
How we protect it
- Encrypted connections (HTTPS) and encrypted storage for notes and health records.
- Sign-in with one-time codes to your phone; no passwords to steal.
- Strict access rules: a doctor can only open the appointments they are part of.
- Daily encrypted backups, logging of access to records, and regular security updates.
If something goes wrong: We must tell the Information Regulator and you as soon as reasonably possible after we discover a breach, unless a lawful authority asks us to delay.
Your rights
Under the Protection of Personal Information Act 2013 (POPIA) you can:
- Be notified when we collect your information
- Access the information we hold about you
- Correct or delete inaccurate, out-of-date or excessive information
- Object to processing
- Not be subject to decisions made only by automated means
- Complain to the Information Regulator
Use them from Your data (download a copy, request deletion) or by writing to privacy@telemed.example. We answer within 30 days. You can complain to the Information Regulator (inforegulator.org.za), or contact us or our Information Officer first.
Children
The service is for adults. A parent or guardian may book for a child under their own account; the child's health information is then held under the guardian's consent.
Changes and contact
If we change this notice in a way that matters, we will tell you in the app before it takes effect. Questions: privacy@telemed.example.
Open points for legal review: Appoint and register an Information Officer; Confirm PAIA manual requirement; Confirm HPCSA telemedicine guideline alignment.