Patient Privacy Notice

First Step Investments (Pty) Ltd t/a MediScan  |  Version 1.0  |  Effective date: 1 June 2025  |  POPIA Compliant

First Step Investments (Pty) Ltd t/a MediScan ("we", "us", "MediScan") is committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and all applicable South African health-data legislation, including the National Health Act 61 of 2003. This notice explains what information we collect, why we collect it, how long we keep it, and what rights you have.

1. Who is the Responsible Party?

First Step Investments (Pty) Ltd t/a MediScan is the Responsible Party as defined by POPIA. Our registered Information Officer can be reached at:

The healthcare facility at which you are registered acts as an Operator processing your data on behalf of MediScan under a Data Processing Agreement.

2. What Personal Information We Collect

CategoryExamplesSensitivity
IdentityFull name, South African ID number, date of birth, genderPersonal
ContactPhone number, addressPersonal
BiometricFingerprint template hash, facial recognition vectorSpecial (biometric)
Clinical / HealthEncounter records, diagnostic forms, uploaded documents (X-ray, MRI, etc.)Special (health)
Consent recordsDate, type and outcome of each consent givenPersonal
Audit trailTimestamp, action, user agent - who accessed what and whenPersonal

We do not collect racial or ethnic information beyond what is clinically required by the receiving healthcare facility.

3. Lawful Basis for Processing

For biometric and health data (Special Personal Information), we rely exclusively on your explicit written consent (POPIA s 27(1)(a)) supplemented where applicable by the medical treatment exception (s 32).

4. How We Use Your Information

5. Data Sharing and Cross-Border Transfers

RecipientPurposeLocationSafeguard
Healthcare facility staffPatient identification & careSouth AfricaStaff NDA + T&Cs
Hospital HMSEncounter synchronisationSouth Africa (facility data centre)Encrypted webhook (TLS 1.2+), Data Processing Agreement
Google Firebase (Firestore)Cloud data storageUS (us-central1) / EU fallbackGoogle's Standard Contractual Clauses (GDPR Article 46); POPIA s 72 adequacy assessment on file
RegulatorsLegal complianceSouth AfricaMandatory disclosure under POPIA, NHA, or court order only

We do not sell your personal information to any third party.

6. Retention Periods

Record typeMinimum retentionAuthority
Patient identity & biometric5 years after last contactNHA Reg. & POPIA s 14
Clinical encounter records6 years (adults); until age 21 for minorsMedical Schemes Act / NHA
Consent records10 yearsPOPIA & NHA best practice
Audit logs3 yearsPOPIA s 14 & internal policy
Uploaded documentsAs per clinical recordNHA

7. Security Measures

8. Your Rights Under POPIA

You have the right to:

Submit rights requests to privacy@medi-scan.co.za. We will respond within 30 days.

9. Automated Decision-Making and Profiling

MediScan does not use your data for automated decision-making that produces legal or similarly significant effects on you. Identity verification is a technical match solely used to confirm your identity at point of care.

10. Cookies and Analytics

The MediScan web application does not use marketing or tracking cookies. Firebase Analytics may collect anonymised usage telemetry (session duration, feature usage) to improve the product. No personally identifiable information is sent to analytics.

11. Changes to This Notice

We will inform you of material changes by posting an updated notice in the application and, where feasible, by direct notification. The effective date at the top of this page indicates the current version.

12. Contact Us

For privacy inquiries, data requests, or consent withdrawal: