1. Our privacy commitment
AidFlow respects the privacy of healthcare practices, their staff, patients and website visitors. We aim to process personal information lawfully, fairly, securely and only for appropriate business, support, billing or operational purposes.
This statement provides a practical overview of how personal information may be handled when interacting with AidFlow, requesting a demo, contacting us, or using AidFlow-related services.
2. Information we may collect
Depending on how you interact with AidFlow, we may collect details such as your name, email address, phone number, practice name, role, enquiry details, demo request information and other information you choose to submit through our website or related communication channels.
Where AidFlow is used in a billing or healthcare practice workflow, personal information may include patient, account, visit, claim, payment, shortfall, rejection or billing-related records, depending on the features used and the practice’s own data-capture processes.
3. Why information is processed
Personal information may be processed to respond to enquiries and demo requests, provide information about AidFlow products or services, support billing and claims workflows, assist with implementation or troubleshooting, improve our website and customer experience, and meet operational, legal, security or compliance obligations.
4. POPIA-aligned principles
The Protection of Personal Information Act, commonly known as POPIA, sets conditions for the lawful processing of personal information in South Africa. AidFlow aims to align its handling of personal information with these principles.
This includes processing information for clear and appropriate purposes, limiting information to what is reasonably necessary, protecting information against unauthorised access or misuse, keeping information accurate where reasonably possible, allowing appropriate access, correction or deletion requests, and using service providers responsibly where needed.
5. Healthcare and billing information
Medical aid billing may involve sensitive operational and patient-related information. Practices using AidFlow remain responsible for ensuring that their own users, staff and billing processes comply with applicable laws, professional obligations and internal privacy policies.
AidFlow is being developed to support responsible billing workflows, including traceable claim activity, rejection handling, shortfall tracking and account history preservation.
6. Security safeguards
We aim to apply reasonable technical and organisational safeguards to protect personal information from loss, unauthorised access, misuse, alteration or disclosure.
Security measures may include controlled access, secure hosting, authentication controls, audit history, backups, encrypted communication where applicable, and internal processes for handling support or operational access.
7. Sharing of information
We do not sell personal information. Information may be shared only where reasonably necessary for service delivery, hosting, communication, support, compliance, security, legal obligations or authorised operational purposes.
Where third-party service providers are used, they should process information only for the relevant service purpose and subject to appropriate confidentiality and security expectations.
8. Your rights
Under POPIA, data subjects may have rights to request access to their personal information, request correction or deletion, object to certain processing, or raise privacy-related concerns where applicable.
Requests will be handled according to the nature of the request, the information involved, the role of the requesting party and applicable legal requirements.
9. Security incidents
If a security compromise involving personal information is identified, the matter will be assessed and handled in line with applicable legal, operational and notification requirements.
10. Interim policy status
This is an interim POPIA and data protection statement. It may be updated as AidFlow’s platform, hosting, integrations, customer agreements, support processes and final legal documentation are completed.
The latest version published on this page will apply from the date it is made available.