Privacy Notice
CareSavi is the technology layer a South African dental or GP practice runs its communication, scheduling, payments and records on. This notice explains what we do with personal and health information, why we are allowed to, who else touches it, and what you can ask us to do about it.
- Effective
- [[EFFECTIVE_DATE]]
- Version
- [[DOCUMENT_VERSION]]
- Applies to
- CareSavi, operated by MemberSavi / Dinnative Technologies (Pty) Ltd
Draft — not yet in force
This privacy notice is a working draft pending legal review and owner sign-off. It does not yet bind CareSavi, MemberSavi / Dinnative Technologies (Pty) Ltd, or any practice, and it may change before it takes effect. Statements about how the platform actually handles data are drawn from the system as built; every [[PLACEHOLDER]] marks a legal or identity fact that has not been supplied yet.
1.Who is responsible for your information
Under the Protection of Personal Information Act 4 of 2013 (POPIA) there are two distinct roles, and which one applies decides who you go to.
- Your practice is the responsible party. The dental or GP practice you are a patient of decides why your information is collected and what happens to it. It holds the clinical relationship and it answers for the record.
- CareSavi is an operator. We process information on the practice's documented instructions — which modules it has enabled, which automations it has switched on, which consent wording it uses. We do not decide the purposes of processing, we do not use patient information for our own ends, and we do not decide when a clinical record is destroyed.
Practically: if you are a patient, exercise your rights with your practice — it is the responsible party, and we act on its instruction. If you are a practice, CareSavi is the responsible party for your own account and billing information, and this notice applies to us directly.
2.Who we are and how to reach us
CareSavi is operated by MemberSavi / Dinnative Technologies (Pty) Ltd, a company registered in South Africa under registration number [[COMPANY_REGISTRATION_NUMBER]], with its registered address at [[REGISTERED_ADDRESS]] and postal address [[POSTAL_ADDRESS]].
| Role | Name | Contact |
|---|---|---|
| Information Officer | [[INFORMATION_OFFICER_NAME]] | [[INFORMATION_OFFICER_EMAIL]] · [[INFORMATION_OFFICER_PHONE]] |
| Deputy Information Officer | [[DEPUTY_INFORMATION_OFFICER_NAME]] | [[DEPUTY_INFORMATION_OFFICER_EMAIL]] |
| Registration with the Information Regulator | [[INFORMATION_REGULATOR_REGISTRATION]] | |
| Privacy enquiries | [[PRIVACY_CONTACT_EMAIL]] (general enquiries: hello@caresavi.com) | |
Our PAIA manual, which sets out the records we hold and how to request them, is at /paia.
3.What information we process
We process only the categories below. We do not buy personal information, and we do not enrich a patient record from outside sources.
| Category | What it includes | Whose |
|---|---|---|
| Practice and staff account data | Practice name, type and locations; staff name, work email, role, password hash, two-factor secret, session and login-audit metadata | Practice staff |
| Patient identity and contact | Name, WhatsApp/mobile number, email, date of birth, identity number where the practice collects one, preferred language | Patients |
| Health information | Medical history and allergies from intake forms, clinical notes and amendments, aftercare instructions, reason for visit, diagnosis codes, medication reminder schedules, free-text satisfaction-survey answers | Patients |
| Medical-aid information | Scheme, plan, membership number, dependant code and principal-member details; benefit-verification results | Patients |
| Appointment and scheduling data | Appointment times, service, practitioner, status, no-show and cancellation history, recall due dates | Patients |
| Communication data | WhatsApp and SMS message content and delivery status, conversation history with the AI receptionist, email delivery metadata, communication preferences and opt-outs | Patients, practice staff |
| Payment data | Amounts in South African cents, payment references and status, proof-of-payment uploads, subscription and invoice records. We never receive or store card numbers— payment happens on the provider's hosted checkout. | Patients, practices |
| Documents and media | Files a patient or the practice uploads — signed consent forms, proof of payment, medical-aid card images, clinical attachments | Patients |
| Consent and audit records | Every consent granted, withdrawn or objected to, with the purpose, wording version, channel and timestamp; and an append-only log of every access to patient information | Patients, practice staff |
| Technical and diagnostic data | Request identifiers, tenant and record identifiers, error stack traces. Health information and patient identifiers are stripped before any of this is logged or sent to our error monitoring. | Everyone |
4.Why we process it, and on what basis
POPIA and the 2026 Regulations on the processing of health information require a separate, identifiable ground for each purpose — a single “I accept the terms” tick is not enough for health data. Each practice therefore keeps a processing register, and the rows below are the ones CareSavi ships with.
| Purpose | What it covers | Lawful basis |
|---|---|---|
| Clinical care | Providing treatment and maintaining the clinical record | s27(1)(d) — necessary for medical treatment by a health professional under a duty of confidentiality |
| Medical history | Intake forms — history, allergies, current medication | s27(1)(a) — explicit consent |
| Appointment triage | A short, non-clinical reason for visit (“tooth pain”) so the right kind of appointment is booked. No diagnosis is recorded, and urgent presentations are escalated to a person rather than booked by the assistant. | s27(1)(d) — necessary for medical treatment |
| Appointment reminders | Confirmations and the reminder ladder for an appointment you already have | s11(1)(b) — necessary to carry out the arrangement your booking creates |
| Medication and aftercare reminders | A content-free nudge that aftercare is due. The instructions themselves are never sent — see §13. | s27(1)(d) — necessary for medical treatment |
| Recall, engagement and marketing | Recall campaigns, review requests, practice news | s11(1)(a) — consent, given separately from clinical messaging |
| Satisfaction surveys | A short questionnaire after a visit, and what you type into it. Answers are stored encrypted and in-region and are never sent over WhatsApp. | s27(1)(a) — explicit consent (a free-text answer can contain health information) |
| Payments and billing | Booking fees, balances, receipts and reconciliation | s11(1)(a) — consent |
| Cross-border AI | Minimised conversation and intake text sent to the AI provider | s72(1)(a) — consent to the transfer |
| Cross-border clinical note assistant | The clinician's own draft for one visit, sent so it can be laid out under standard headings. Kept separate from the receptionist consent on purpose. | s72(1)(a) — consent to the transfer |
| Cross-border messaging | Message content and recipient number, to deliver WhatsApp and SMS | s72(1)(a) — consent to the transfer |
| Cross-border payments | Minimised billing metadata, to take a payment | s72(1)(a) — consent to the transfer |
An honest note on two of these. Appointment reminders rest on the arrangement your booking creates rather than on consent, because nothing asks you for consent to a reminder and inferring it from the act of booking would be wrong. Strictly, that basis carries no statutory objection right — but we honour STOP for reminders anyway, and say so in the messages themselves.
5.Health information specifically
Health information is special personal information. POPIA s26 prohibits processing it at all unless a s27 ground applies, and the Regulations relating to the Processing of Data Subjects' Health Information (Gazette 54268, in force 6 March 2026) add further requirements. The consequences you can see in the product:
- Health information is encrypted before it is stored, not merely stored on an encrypted disk.
- Every read and write is audited to an append-only log naming who did it and when. That log is what lets a practice tell you who has seen your record.
- Health information is never written to system logs, error reports or analytics. Only opaque identifiers are.
- Consent for health processing is explicit, purpose-specific and timestamped, and recorded with the exact wording version you were shown.
6.Where your information lives
CareSavi's databases, caches, file storage and application servers run in Oracle Cloud Infrastructure's af-johannesburg-1 region — in South Africa. That is the residency anchor for the whole system: patient records, clinical notes, uploaded documents, message history and the search index that powers the AI assistant all sit there.
Practice knowledge used for AI search is, by default, converted into a numeric index by a model that runs inside our own South African infrastructure, so that step involves no third party and no transfer at all.
The exceptions are the transfers in §7 and §8, which are exactly the ones a WhatsApp, payment or AI feature cannot avoid.
7.Who else processes it
These are the third parties that may process information on our behalf, what they touch, and where. We keep this list current; the register behind it is also stored in the system, per practice, so a subject-access request can name the recipients for your record specifically.
| Sub-processor | Purpose | Data | Region | Outside SA? |
|---|---|---|---|---|
| Oracle Cloud Infrastructure (OCI) | Hosting — compute, Postgres, Redis, object storageThe residency anchor. Everything else on this list is downstream of it. | All application data, including health data, at rest | af-johannesburg-1 (South Africa) | No |
| 360dialog | WhatsApp Business Solution Provider — carries every WhatsApp send and receiveMessage content is minimised; no clinical detail is ever placed in a WhatsApp message or template. | Recipient phone number, message content, delivery status | Germany / EU | Yes |
| Meta Platforms (WhatsApp) | WhatsApp transport, downstream of 360dialogMeta exposes no message-deletion API, so an erasure cannot reach content already delivered through WhatsApp. See §10. | Message content, recipient number | United States / global | Yes |
| WinSMS | SMS fallback for a WhatsApp leg that cannot be deliveredA narrow fallback only — never a second channel, and never past a recorded objection. | Recipient number, message content, delivery status | South Africa | No |
| Paystack | Practice subscription billing and patient paymentsHosted checkout (PCI SAQ-A) — card numbers never reach CareSavi. | Billing identity, payer name and email, amount, payment token | Nigeria / South Africa | Yes |
| Anthropic (Claude) | AI receptionist, message classification, and the clinical note assistantZero data retention and no training on API inputs. A practice may supply its own API key (BYOK). | Minimised conversation and intake text; for the note assistant, the clinician's own draft for one visit | United States | Yes |
| OpenAI | Alternative AI model provider for the same featuresNamed because the model provider is an operator-side switch that can change without a patient being asked again. Only one provider is active for a practice at a time. | As for Anthropic | United States | Yes |
| Alibaba Cloud Model Studio | Alternative AI model provider for the same featuresSame reason as OpenAI. Only one provider is active for a practice at a time. | As for Anthropic | Singapore (ap-southeast-1) | Yes |
| Voyage AI | Cloud text embeddings for practice knowledge search — optional, off by defaultNot used unless cloud embeddings are explicitly switched on. By default embeddings are computed in-region by a model that runs inside our own OCI compute, so no third party is involved at all. | Chunked practice knowledge text | United States | Yes |
| Maileroo | Transactional email — verification, invitations, receiptsNo clinical content is sent by email. Residency to be confirmed before sign-off. | Recipient email address, message subject and body | To be confirmed | To be confirmed |
| Sentry (Functional Software, Inc.) | Error monitoring for the backend, worker and scheduled jobsNo patient identifier and no health data is sent. Scrubbing happens before the event leaves our servers. | Stack traces and request metadata with health data and identifiers stripped at source | European Union (Frankfurt) | Yes |
Not on this list, deliberately. CareSavi does not use a speech-to-text vendor: the clinical note assistant is text-only and no audio is recorded or transmitted. A practice may also supply its own AI provider key, which narrows that relationship to the practice and the provider directly.
8.Transfers outside South Africa
POPIA s72 allows personal information to leave South Africa only where you have consented, or where a binding agreement gives protection substantially similar to POPIA, or where the recipient country's law is comparable. We rely on all three layers together:
- A distinct consent for the transfer itself, recorded per purpose — AI, messaging, payments and the clinical note assistant are four separate consents, not one.
- Contractual protection with each recipient, carrying the retention and no-secondary-use commitments in §7 down the chain.
- Minimisation before egress— the primary control. We send the least data the function needs, never the record. The AI receptionist sees minimised conversation text, not your file; the note assistant sees one visit's draft and nothing else — no history, no prior notes, no documents, no identifiers, no medical-aid data, no messages.
9.How we protect it
- Encryption at the record level. Health and identifying fields are encrypted with AES-256-GCM under a per-record key, itself wrapped by a key held in a managed key vault — on top of transport and disk encryption.
- Hard separation between practices.Every record carries its practice, and the database itself enforces the boundary with row-level security, so a query that forgot to filter returns nothing rather than someone else's data.
- An append-only audit trail. Audit entries are chained and cannot be edited or deleted, including by us.
- No health data in logs. Enforced automatically in our build, not by policy alone. Error reports are scrubbed before they leave our servers.
- Access control. Role-based permissions, two-factor authentication, and a second authentication step before the most sensitive actions.
- Time-limited file access. Uploaded documents are served through short-lived signed links, never a public URL.
If information under our control is compromised, we notify the affected practice immediately so it can meet its own POPIA s22 obligations to you and to the Information Regulator.
10.How long we keep it
Health records are the one place where “keep as little as possible” loses. South African law sets minimum retention periods that override minimisation:
| Record class | Minimum retention | Source |
|---|---|---|
| General medical records | At least 6 years from when the record becomes dormant | HPCSA Booklet 9 |
| Occupational health records | 20 years after treatment | Occupational Health and Safety Act 85 of 1993 |
| Records of minors | Until the patient turns 21 | HPCSA |
| Records of mentally disabled patients | Lifetime | HPCSA |
| Operational communications (reminders, message logs) | Minimised — kept only as long as the purpose needs | POPIA s14 |
| Consent and audit evidence | As long as the record it evidences | POPIA s17 and s22 |
Because CareSavi is an operator, we do not choose a destruction date. The practice sets one; our system validates it against the statutory floor above and refuses a date that would destroy a record too early. Where the practice has set no date, nothing is destroyed. A daily job carries out only the destructions the practice has actually instructed, and records each one in the audit trail.
11.Your rights, and how to exercise them
Ask your practice — it is the responsible party. The practice exercises each of these through CareSavi, and every request is itself audited.
| Right | POPIA | What actually happens |
|---|---|---|
| Access | s23 | A full export of everything held about you across patient record, appointments, clinical notes, payments, messages, forms and consents — together with the list of who accessed it, reconstructed from the audit trail. The export is rate-limited and requires a second authentication step by practice staff. If you have a patient portal account you can also see your appointments, profile, documents, visit summaries and consent history yourself. |
| Correction | s24 | You can submit a correction from the patient portal; it goes to a reception queue where staff apply or decline it, with the before-and-after recorded. |
| Objection and withdrawal of consent | s11(3) | Reply STOP on WhatsApp, or use the preferences screen in the patient portal. STOP is honoured the moment the message arrives — before the AI assistant ever sees it — and it stops automated sending. Withdrawal is recorded as a new consent record; nothing is overwritten. |
| Deletion | s24 | Where no retention obligation applies, the record is erased: identifying and clinical fields are destroyed in place, derived data including the AI search index is deleted, and message bodies are redacted. Where an obligation is still running, see the caveat below — nothing is destroyed, but consent-based processing stops and the record is suppressed from ordinary staff screens until the obligation lapses, when the deletion completes automatically. |
Two limits we will not pretend away. First, deletion cannot override the statutory minimums in §10 — a request against a record still under a retention obligation is deferred, not refused, and the response says so rather than reporting a deletion that did not happen. Second, WhatsApp offers no message-deletion facility: once a message has been delivered through Meta's platform, an erasure on our side cannot reach the copy Meta holds. We can guarantee the destruction of our own copy, and we do; we cannot promise more than that.
12.WhatsApp, SMS and direct marketing
CareSavi is WhatsApp-first. Messages fall into two kinds and the distinction is enforced in code, not left to judgement:
- Clinical and transactional — appointment confirmations, reminders, aftercare nudges. These do not depend on a marketing opt-in, because gating a clinical follow-up on a marketing consent would silence it for every patient who declined marketing.
- Marketing and engagement — recalls, review requests, satisfaction surveys, practice news. These require a separate opt-in under POPIA s69, checked again at the moment of sending rather than only when the message was scheduled.
Where a WhatsApp message cannot be delivered, a practice may enable a narrow SMS fallback for that message. It is a fallback for one undeliverable leg, never a second channel, and it is never sent past a recorded objection.
13.Clinical information never rides WhatsApp
Aftercare instructions, visit summaries and clinical notes are not sent as WhatsApp messages. What you receive is a content-free knock— the practice name and a single-use link. The summary itself is served by the practice's patient portal, hosted in South Africa, behind a one-time PIN sent to you and then a PIN you choose. The “aftercare” option in the WhatsApp menu re-sends that link and nothing else.
This is why the sub-processors carrying WhatsApp messages in §7 are described as receiving message content but never clinical detail — there is none in the message to receive.
14.How we use AI
CareSavi uses a large language model for an AI receptionist on WhatsApp, for classifying and summarising conversations, and for a clinical note assistant. Four rules govern all of it:
- The model proposes; code decides. Bookings, payments, sends and record writes are performed by ordinary application code with its own checks. The model can only ask for one of a fixed set of actions.
- Never diagnostic. The assistant does not diagnose, does not give clinical advice, and escalates urgent presentations to a person instead of handling them.
- Clinician in the loop. The note assistant produces a draft that a clinician edits and explicitly approves. Until that approval, no clinical note exists. A clinician can decline it entirely.
- Off unless switched on, and consented. Each AI feature is enabled per practice and checked against a live consent for the cross-border transfer at the moment of use.
The AI providers we use commit to not retaining API inputs and not training on them. We record that an AI interaction happened and what it cost, never the content of the prompt or the reply outside the encrypted store.
15.This website
This marketing site is a brochure. It holds no patient information, has no login, talks to no backend, and sets no analytics or advertising cookies. Fonts are served from Google Fonts, which means your browser makes a request to Google when the page loads.
The practice application, the patient portal and the API are separate systems with their own authentication; they use strictly-necessary cookies to keep you signed in.
16.Children and people who cannot consent
Where the patient is a child or cannot consent for themselves, consent must be given by a competent person — a parent, guardian or someone lawfully authorised. Records of minors are kept until the patient turns 21, per §10, which means a deletion request made before then is deferred rather than carried out.
17.Changes to this notice
We update this notice when what the system does changes — including whenever a sub-processor is added or removed. The version and effective date are at the top. Practices are notified of material changes per their agreement with us.
18.Complaints
Raise it with your practice first, or with our Information Officer at [[INFORMATION_OFFICER_EMAIL]]. If you are not satisfied, you may complain to the Information Regulator (South Africa) — inforegulator.org.za, contact details [[INFORMATION_REGULATOR_COMPLAINTS_CONTACT]]. You may also apply to a court.
See also our Terms of Service and PAIA manual.