Skip to content
Privacy

Privacy Notice

CareSavi is the technology layer a South African dental or GP practice runs its communication, scheduling, payments and records on. This notice explains what we do with personal and health information, why we are allowed to, who else touches it, and what you can ask us to do about it.

Effective
[[EFFECTIVE_DATE]]
Version
[[DOCUMENT_VERSION]]
Applies to
CareSavi, operated by MemberSavi / Dinnative Technologies (Pty) Ltd

Draft — not yet in force

This privacy notice is a working draft pending legal review and owner sign-off. It does not yet bind CareSavi, MemberSavi / Dinnative Technologies (Pty) Ltd, or any practice, and it may change before it takes effect. Statements about how the platform actually handles data are drawn from the system as built; every [[PLACEHOLDER]] marks a legal or identity fact that has not been supplied yet.

1.Who is responsible for your information

Under the Protection of Personal Information Act 4 of 2013 (POPIA) there are two distinct roles, and which one applies decides who you go to.

  • Your practice is the responsible party. The dental or GP practice you are a patient of decides why your information is collected and what happens to it. It holds the clinical relationship and it answers for the record.
  • CareSavi is an operator. We process information on the practice's documented instructions — which modules it has enabled, which automations it has switched on, which consent wording it uses. We do not decide the purposes of processing, we do not use patient information for our own ends, and we do not decide when a clinical record is destroyed.

Practically: if you are a patient, exercise your rights with your practice — it is the responsible party, and we act on its instruction. If you are a practice, CareSavi is the responsible party for your own account and billing information, and this notice applies to us directly.

2.Who we are and how to reach us

CareSavi is operated by MemberSavi / Dinnative Technologies (Pty) Ltd, a company registered in South Africa under registration number [[COMPANY_REGISTRATION_NUMBER]], with its registered address at [[REGISTERED_ADDRESS]] and postal address [[POSTAL_ADDRESS]].

RoleNameContact
Information Officer[[INFORMATION_OFFICER_NAME]][[INFORMATION_OFFICER_EMAIL]] · [[INFORMATION_OFFICER_PHONE]]
Deputy Information Officer[[DEPUTY_INFORMATION_OFFICER_NAME]][[DEPUTY_INFORMATION_OFFICER_EMAIL]]
Registration with the Information Regulator[[INFORMATION_REGULATOR_REGISTRATION]]
Privacy enquiries[[PRIVACY_CONTACT_EMAIL]] (general enquiries: hello@caresavi.com)

Our PAIA manual, which sets out the records we hold and how to request them, is at /paia.

3.What information we process

We process only the categories below. We do not buy personal information, and we do not enrich a patient record from outside sources.

CategoryWhat it includesWhose
Practice and staff account dataPractice name, type and locations; staff name, work email, role, password hash, two-factor secret, session and login-audit metadataPractice staff
Patient identity and contactName, WhatsApp/mobile number, email, date of birth, identity number where the practice collects one, preferred languagePatients
Health informationMedical history and allergies from intake forms, clinical notes and amendments, aftercare instructions, reason for visit, diagnosis codes, medication reminder schedules, free-text satisfaction-survey answersPatients
Medical-aid informationScheme, plan, membership number, dependant code and principal-member details; benefit-verification resultsPatients
Appointment and scheduling dataAppointment times, service, practitioner, status, no-show and cancellation history, recall due datesPatients
Communication dataWhatsApp and SMS message content and delivery status, conversation history with the AI receptionist, email delivery metadata, communication preferences and opt-outsPatients, practice staff
Payment dataAmounts in South African cents, payment references and status, proof-of-payment uploads, subscription and invoice records. We never receive or store card numbers— payment happens on the provider's hosted checkout.Patients, practices
Documents and mediaFiles a patient or the practice uploads — signed consent forms, proof of payment, medical-aid card images, clinical attachmentsPatients
Consent and audit recordsEvery consent granted, withdrawn or objected to, with the purpose, wording version, channel and timestamp; and an append-only log of every access to patient informationPatients, practice staff
Technical and diagnostic dataRequest identifiers, tenant and record identifiers, error stack traces. Health information and patient identifiers are stripped before any of this is logged or sent to our error monitoring.Everyone

4.Why we process it, and on what basis

POPIA and the 2026 Regulations on the processing of health information require a separate, identifiable ground for each purpose — a single “I accept the terms” tick is not enough for health data. Each practice therefore keeps a processing register, and the rows below are the ones CareSavi ships with.

PurposeWhat it coversLawful basis
Clinical careProviding treatment and maintaining the clinical records27(1)(d) — necessary for medical treatment by a health professional under a duty of confidentiality
Medical historyIntake forms — history, allergies, current medications27(1)(a) — explicit consent
Appointment triageA short, non-clinical reason for visit (“tooth pain”) so the right kind of appointment is booked. No diagnosis is recorded, and urgent presentations are escalated to a person rather than booked by the assistant.s27(1)(d) — necessary for medical treatment
Appointment remindersConfirmations and the reminder ladder for an appointment you already haves11(1)(b) — necessary to carry out the arrangement your booking creates
Medication and aftercare remindersA content-free nudge that aftercare is due. The instructions themselves are never sent — see §13.s27(1)(d) — necessary for medical treatment
Recall, engagement and marketingRecall campaigns, review requests, practice newss11(1)(a) — consent, given separately from clinical messaging
Satisfaction surveysA short questionnaire after a visit, and what you type into it. Answers are stored encrypted and in-region and are never sent over WhatsApp.s27(1)(a) — explicit consent (a free-text answer can contain health information)
Payments and billingBooking fees, balances, receipts and reconciliations11(1)(a) — consent
Cross-border AIMinimised conversation and intake text sent to the AI providers72(1)(a) — consent to the transfer
Cross-border clinical note assistantThe clinician's own draft for one visit, sent so it can be laid out under standard headings. Kept separate from the receptionist consent on purpose.s72(1)(a) — consent to the transfer
Cross-border messagingMessage content and recipient number, to deliver WhatsApp and SMSs72(1)(a) — consent to the transfer
Cross-border paymentsMinimised billing metadata, to take a payments72(1)(a) — consent to the transfer

An honest note on two of these. Appointment reminders rest on the arrangement your booking creates rather than on consent, because nothing asks you for consent to a reminder and inferring it from the act of booking would be wrong. Strictly, that basis carries no statutory objection right — but we honour STOP for reminders anyway, and say so in the messages themselves.

5.Health information specifically

Health information is special personal information. POPIA s26 prohibits processing it at all unless a s27 ground applies, and the Regulations relating to the Processing of Data Subjects' Health Information (Gazette 54268, in force 6 March 2026) add further requirements. The consequences you can see in the product:

  • Health information is encrypted before it is stored, not merely stored on an encrypted disk.
  • Every read and write is audited to an append-only log naming who did it and when. That log is what lets a practice tell you who has seen your record.
  • Health information is never written to system logs, error reports or analytics. Only opaque identifiers are.
  • Consent for health processing is explicit, purpose-specific and timestamped, and recorded with the exact wording version you were shown.

6.Where your information lives

CareSavi's databases, caches, file storage and application servers run in Oracle Cloud Infrastructure's af-johannesburg-1 region — in South Africa. That is the residency anchor for the whole system: patient records, clinical notes, uploaded documents, message history and the search index that powers the AI assistant all sit there.

Practice knowledge used for AI search is, by default, converted into a numeric index by a model that runs inside our own South African infrastructure, so that step involves no third party and no transfer at all.

The exceptions are the transfers in §7 and §8, which are exactly the ones a WhatsApp, payment or AI feature cannot avoid.

7.Who else processes it

These are the third parties that may process information on our behalf, what they touch, and where. We keep this list current; the register behind it is also stored in the system, per practice, so a subject-access request can name the recipients for your record specifically.

Sub-processorPurposeDataRegionOutside SA?
Oracle Cloud Infrastructure (OCI)Hosting — compute, Postgres, Redis, object storageThe residency anchor. Everything else on this list is downstream of it.All application data, including health data, at restaf-johannesburg-1 (South Africa)No
360dialogWhatsApp Business Solution Provider — carries every WhatsApp send and receiveMessage content is minimised; no clinical detail is ever placed in a WhatsApp message or template.Recipient phone number, message content, delivery statusGermany / EUYes
Meta Platforms (WhatsApp)WhatsApp transport, downstream of 360dialogMeta exposes no message-deletion API, so an erasure cannot reach content already delivered through WhatsApp. See §10.Message content, recipient numberUnited States / globalYes
WinSMSSMS fallback for a WhatsApp leg that cannot be deliveredA narrow fallback only — never a second channel, and never past a recorded objection.Recipient number, message content, delivery statusSouth AfricaNo
PaystackPractice subscription billing and patient paymentsHosted checkout (PCI SAQ-A) — card numbers never reach CareSavi.Billing identity, payer name and email, amount, payment tokenNigeria / South AfricaYes
Anthropic (Claude)AI receptionist, message classification, and the clinical note assistantZero data retention and no training on API inputs. A practice may supply its own API key (BYOK).Minimised conversation and intake text; for the note assistant, the clinician's own draft for one visitUnited StatesYes
OpenAIAlternative AI model provider for the same featuresNamed because the model provider is an operator-side switch that can change without a patient being asked again. Only one provider is active for a practice at a time.As for AnthropicUnited StatesYes
Alibaba Cloud Model StudioAlternative AI model provider for the same featuresSame reason as OpenAI. Only one provider is active for a practice at a time.As for AnthropicSingapore (ap-southeast-1)Yes
Voyage AICloud text embeddings for practice knowledge search — optional, off by defaultNot used unless cloud embeddings are explicitly switched on. By default embeddings are computed in-region by a model that runs inside our own OCI compute, so no third party is involved at all.Chunked practice knowledge textUnited StatesYes
MailerooTransactional email — verification, invitations, receiptsNo clinical content is sent by email. Residency to be confirmed before sign-off.Recipient email address, message subject and bodyTo be confirmedTo be confirmed
Sentry (Functional Software, Inc.)Error monitoring for the backend, worker and scheduled jobsNo patient identifier and no health data is sent. Scrubbing happens before the event leaves our servers.Stack traces and request metadata with health data and identifiers stripped at sourceEuropean Union (Frankfurt)Yes

Not on this list, deliberately. CareSavi does not use a speech-to-text vendor: the clinical note assistant is text-only and no audio is recorded or transmitted. A practice may also supply its own AI provider key, which narrows that relationship to the practice and the provider directly.

8.Transfers outside South Africa

POPIA s72 allows personal information to leave South Africa only where you have consented, or where a binding agreement gives protection substantially similar to POPIA, or where the recipient country's law is comparable. We rely on all three layers together:

  1. A distinct consent for the transfer itself, recorded per purpose — AI, messaging, payments and the clinical note assistant are four separate consents, not one.
  2. Contractual protection with each recipient, carrying the retention and no-secondary-use commitments in §7 down the chain.
  3. Minimisation before egress— the primary control. We send the least data the function needs, never the record. The AI receptionist sees minimised conversation text, not your file; the note assistant sees one visit's draft and nothing else — no history, no prior notes, no documents, no identifiers, no medical-aid data, no messages.

9.How we protect it

  • Encryption at the record level. Health and identifying fields are encrypted with AES-256-GCM under a per-record key, itself wrapped by a key held in a managed key vault — on top of transport and disk encryption.
  • Hard separation between practices.Every record carries its practice, and the database itself enforces the boundary with row-level security, so a query that forgot to filter returns nothing rather than someone else's data.
  • An append-only audit trail. Audit entries are chained and cannot be edited or deleted, including by us.
  • No health data in logs. Enforced automatically in our build, not by policy alone. Error reports are scrubbed before they leave our servers.
  • Access control. Role-based permissions, two-factor authentication, and a second authentication step before the most sensitive actions.
  • Time-limited file access. Uploaded documents are served through short-lived signed links, never a public URL.

If information under our control is compromised, we notify the affected practice immediately so it can meet its own POPIA s22 obligations to you and to the Information Regulator.

10.How long we keep it

Health records are the one place where “keep as little as possible” loses. South African law sets minimum retention periods that override minimisation:

Record classMinimum retentionSource
General medical recordsAt least 6 years from when the record becomes dormantHPCSA Booklet 9
Occupational health records20 years after treatmentOccupational Health and Safety Act 85 of 1993
Records of minorsUntil the patient turns 21HPCSA
Records of mentally disabled patientsLifetimeHPCSA
Operational communications (reminders, message logs)Minimised — kept only as long as the purpose needsPOPIA s14
Consent and audit evidenceAs long as the record it evidencesPOPIA s17 and s22

Because CareSavi is an operator, we do not choose a destruction date. The practice sets one; our system validates it against the statutory floor above and refuses a date that would destroy a record too early. Where the practice has set no date, nothing is destroyed. A daily job carries out only the destructions the practice has actually instructed, and records each one in the audit trail.

11.Your rights, and how to exercise them

Ask your practice — it is the responsible party. The practice exercises each of these through CareSavi, and every request is itself audited.

RightPOPIAWhat actually happens
Accesss23A full export of everything held about you across patient record, appointments, clinical notes, payments, messages, forms and consents — together with the list of who accessed it, reconstructed from the audit trail. The export is rate-limited and requires a second authentication step by practice staff. If you have a patient portal account you can also see your appointments, profile, documents, visit summaries and consent history yourself.
Corrections24You can submit a correction from the patient portal; it goes to a reception queue where staff apply or decline it, with the before-and-after recorded.
Objection and withdrawal of consents11(3)Reply STOP on WhatsApp, or use the preferences screen in the patient portal. STOP is honoured the moment the message arrives — before the AI assistant ever sees it — and it stops automated sending. Withdrawal is recorded as a new consent record; nothing is overwritten.
Deletions24Where no retention obligation applies, the record is erased: identifying and clinical fields are destroyed in place, derived data including the AI search index is deleted, and message bodies are redacted. Where an obligation is still running, see the caveat below — nothing is destroyed, but consent-based processing stops and the record is suppressed from ordinary staff screens until the obligation lapses, when the deletion completes automatically.

Two limits we will not pretend away. First, deletion cannot override the statutory minimums in §10 — a request against a record still under a retention obligation is deferred, not refused, and the response says so rather than reporting a deletion that did not happen. Second, WhatsApp offers no message-deletion facility: once a message has been delivered through Meta's platform, an erasure on our side cannot reach the copy Meta holds. We can guarantee the destruction of our own copy, and we do; we cannot promise more than that.

12.WhatsApp, SMS and direct marketing

CareSavi is WhatsApp-first. Messages fall into two kinds and the distinction is enforced in code, not left to judgement:

  • Clinical and transactional — appointment confirmations, reminders, aftercare nudges. These do not depend on a marketing opt-in, because gating a clinical follow-up on a marketing consent would silence it for every patient who declined marketing.
  • Marketing and engagement — recalls, review requests, satisfaction surveys, practice news. These require a separate opt-in under POPIA s69, checked again at the moment of sending rather than only when the message was scheduled.

Where a WhatsApp message cannot be delivered, a practice may enable a narrow SMS fallback for that message. It is a fallback for one undeliverable leg, never a second channel, and it is never sent past a recorded objection.

13.Clinical information never rides WhatsApp

Aftercare instructions, visit summaries and clinical notes are not sent as WhatsApp messages. What you receive is a content-free knock— the practice name and a single-use link. The summary itself is served by the practice's patient portal, hosted in South Africa, behind a one-time PIN sent to you and then a PIN you choose. The “aftercare” option in the WhatsApp menu re-sends that link and nothing else.

This is why the sub-processors carrying WhatsApp messages in §7 are described as receiving message content but never clinical detail — there is none in the message to receive.

14.How we use AI

CareSavi uses a large language model for an AI receptionist on WhatsApp, for classifying and summarising conversations, and for a clinical note assistant. Four rules govern all of it:

  1. The model proposes; code decides. Bookings, payments, sends and record writes are performed by ordinary application code with its own checks. The model can only ask for one of a fixed set of actions.
  2. Never diagnostic. The assistant does not diagnose, does not give clinical advice, and escalates urgent presentations to a person instead of handling them.
  3. Clinician in the loop. The note assistant produces a draft that a clinician edits and explicitly approves. Until that approval, no clinical note exists. A clinician can decline it entirely.
  4. Off unless switched on, and consented. Each AI feature is enabled per practice and checked against a live consent for the cross-border transfer at the moment of use.

The AI providers we use commit to not retaining API inputs and not training on them. We record that an AI interaction happened and what it cost, never the content of the prompt or the reply outside the encrypted store.

15.This website

This marketing site is a brochure. It holds no patient information, has no login, talks to no backend, and sets no analytics or advertising cookies. Fonts are served from Google Fonts, which means your browser makes a request to Google when the page loads.

The practice application, the patient portal and the API are separate systems with their own authentication; they use strictly-necessary cookies to keep you signed in.

16.Children and people who cannot consent

Where the patient is a child or cannot consent for themselves, consent must be given by a competent person — a parent, guardian or someone lawfully authorised. Records of minors are kept until the patient turns 21, per §10, which means a deletion request made before then is deferred rather than carried out.

17.Changes to this notice

We update this notice when what the system does changes — including whenever a sub-processor is added or removed. The version and effective date are at the top. Practices are notified of material changes per their agreement with us.

18.Complaints

Raise it with your practice first, or with our Information Officer at [[INFORMATION_OFFICER_EMAIL]]. If you are not satisfied, you may complain to the Information Regulator (South Africa) inforegulator.org.za, contact details [[INFORMATION_REGULATOR_COMPLAINTS_CONTACT]]. You may also apply to a court.

See also our Terms of Service and PAIA manual.