← Back to Home

POPIA Compliance

This compliance statement is being finalised with legal counsel. The content below outlines our current POPIA posture. A full legally reviewed version will replace this prior to public launch.

Our Commitment

Practora is designed from the ground up to comply with the Protection of Personal Information Act, 2013 (POPIA). As a platform handling sensitive medical data, we treat data protection as a core architectural requirement, not an afterthought.

Roles Under POPIA

  • Responsible Party (Data Controller): The subscribing medical practice
  • Operator (Data Processor): Practora (Pty) Ltd
  • Data Subject: The patient whose information is being processed

How We Comply

Accountability (Section 8)

Every action in Practora is logged in an immutable audit trail: who accessed what data, when, and what changes were made. Practice administrators have full visibility into all user activity.

Processing Limitation (Section 9-12)

Patient data is processed solely for healthcare administration purposes as directed by the subscribing practice. Data is never used for marketing, advertising, profiling, or AI model training.

Purpose Specification (Section 13-14)

Data is collected and retained for the specific purpose of managing patient care within the subscribing practice. Retention follows South African medical record requirements (minimum 5 years after last consultation).

Further Processing Limitation (Section 15)

Patient data is not shared with third parties except AI service providers for clinical decision support features, where data is encrypted in transit and processed ephemerally (not stored).

Information Quality (Section 16)

Practices can update, correct, and maintain patient records at any time. The system includes validation (SA ID Luhn checks, medical aid number validation) to help ensure data accuracy.

Openness (Section 17-18)

Our Privacy Policy and this POPIA statement are publicly available. Patients may enquire about their data through their medical practice.

Security Safeguards (Section 19)

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Row-level security isolating each practice's data
  • Per-user authentication with per-screen permissions
  • Data hosted in South African data centres
  • Automatic session timeouts after inactivity

Data Subject Participation (Section 23-25)

Practices can export all patient data and delete patient records upon request, supporting the data subject's right to access and erasure.

Contact

Information Officer: hello@practora.co.za

Last updated: March 2026