Website and Platform Privacy Notice

1. Who we are and what this notice does

1.1 Vowels Africa (Pty) Ltd, registration number 2025/722562/07, trading as RemMed SA ("RemMed", "we", "us"), operates a revenue recovery platform for South African medical practices. The platform reads medical aid remittance advices, reconciles claim lines, identifies unpaid and under-paid amounts, and tells the practice what to act on. It is read-only by design: it does not write to any practice billing system.

1.2 This notice explains what personal information we collect, why, who we share it with, where it goes, how long we keep it, and what you can do about it. It is issued in terms of section 18 of POPIA.

1.3 It does not replace the Master Services Agreement. Where you are a subscribing practice, the MSA and its POPIA Annexure govern our handling of your data and prevail over this notice to the extent of any conflict.

2. The two capacities in which we act

This distinction determines who is accountable for what, and it runs through the rest of this notice.

If you are a patient of a practice that uses RemMed, your medical aid claim information reaches us through that practice. Your relationship is with the practice, and requests about your information should be directed to the practice in the first instance. We will assist the practice in responding.

3. What we collect, and why

3.1 Website visitors and enquirers

3.2 Practice users of the platform

3.3 Remittance data processed for a practice (operator capacity)

The following reaches us from medical aid remittance advices delivered to a mailbox the practice controls. We process it only to perform the service the practice has contracted for.

Special personal information. Claim-line data includes information concerning health, which is special personal information under section 26 of POPIA. We process it under section 32(1) as an operator acting on the instruction of the practice, which processes it in the course of providing treatment and administering the resulting claim. We do not process it for any other purpose, and we do not submit it to any third-party artificial intelligence or machine-learning service that is not contractually bound to protections no less stringent than our POPIA Annexure.

4. Who we share information with

4.1 We do not sell personal information, and we do not share it with third parties for their own marketing.

4.2 We use a small number of service providers — operators in POPIA terms — to run the platform. Each is bound by a written agreement imposing data protection obligations no less protective than those we owe. They are disclosed by category below. A named list is maintained in our Sub-Operator Register and is available to any subscribing practice on written request to the Information Officer.

4.3 Your email provider (for example Google Workspace or Microsoft 365) is not our service provider. Where a practice grants us access to a mailbox for remittance ingestion, that access is under the practice's own account with its own provider.

4.4 Google user data.Where a practice connects a Google mailbox, RemMed requests read-only access to that mailbox (the read-only Gmail permission, gmail.readonly) with the practice's explicit consent. We access only messages that match our medical scheme remittance filters, and we use them for one purpose: extracting the remittance advice PDF attachments and parsing them into the claim records shown on the practice's own dashboard.

4.5 We do not store email messages or bodies. Source remittance PDFs are parsed and discarded — only the extracted claim-line data is retained. The credentials that authorise our access are encrypted at rest, are never disclosed, and can be revoked at any time from the RemMed settings page or from the practice's own Google Account security settings. We do not use Google user data for advertising, we do not sell it, and no person reads it except with the practice's consent for support or security purposes, or where the law requires disclosure.

4.6 RemMed's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.7 We may also disclose information where the law requires it, where it is necessary to establish, exercise or defend a legal claim, or to our professional advisers under duties of confidentiality.

5. Where your information goes (cross-border transfer)

5.1 Our primary data storage and application compute are located in the United Kingdom (London region). Certain supporting services — transactional email, marketing email, electronic signature and secrets management — are provided from the United States. Payment processing takes place in South Africa.

5.2 These are trans-border flows under section 72 of POPIA. We rely on section 72(1)(a): each recipient is bound by a written agreement that upholds principles for reasonable processing substantially similar to the conditions in POPIA, and the primary hosting environment is subject to the UK and EU General Data Protection Regulation and holds independent certifications including ISO/IEC 27001 and SOC 2. Our payment processing takes place within South Africa, so no personal information leaves the country for that purpose.

5.3 We do not transfer personal information to any other jurisdiction without first establishing a lawful basis under section 72 and, where a practice is affected, notifying that practice.

6. How long we keep it

Where information no longer serves the purpose it was collected for and no law requires us to keep it, we delete or de-identify it.

7. How we protect it

If a security compromise affects your personal information, we will notify you and the Information Regulator as soon as reasonably possible after establishing the scope of the compromise, in accordance with section 22 of POPIA. Where we act as operator, we will notify the practice without undue delay and in any event within 48 hours of becoming aware.

8. Your rights

Under POPIA you may:

To exercise any of these, contact our Information Officer at privacy@remmed.co.za. We will respond within 30 days. Forms 1 and 2 are available from our Information Officer and from the Information Regulator's website.

9. Contact details

We are contactable by email. Section 18 of POPIA requires the name and address of the responsible party, both of which appear above; it does not require a telephone number, and we do not publish one.

You may complain to the Information Regulator at any time:

10. Changes to this notice

We may update this notice. The version number and effective date at the top will change, and the current version will always be available at remmed.co.za/privacy. Where a change materially affects how we process your personal information, we will bring it to your attention directly rather than relying on the website alone.

Version history is maintained by the Information Officer. Superseded versions are retained for five years.