Website and Platform Privacy Notice
| Version | v1.3 — supersedes v1.2 |
|---|---|
| Effective date | 17 August 2026 |
| Applies to | remmed.co.za, remmedsa.co.za, the RemMed platform, and the Remeez assistant |
| Responsible party | Vowels Africa (Pty) Ltd t/a RemMed SA, registration number 2025/722562/07 |
| Information Officer | Yaseen Samsodien, registered with the Information Regulator under number 2026-063725 |
| Contact | privacy@remmed.co.za |
| Review cycle | Annually, and on any material change to processing |
1. Who we are and what this notice does
1.1 Vowels Africa (Pty) Ltd, registration number 2025/722562/07, trading as RemMed SA ("RemMed", "we", "us"), operates a revenue recovery platform for South African medical practices. The platform reads medical aid remittance advices, reconciles claim lines, identifies unpaid and under-paid amounts, and tells the practice what to act on. It is read-only by design: it does not write to any practice billing system.
1.2 This notice explains what personal information we collect, why, who we share it with, where it goes, how long we keep it, and what you can do about it. It is issued in terms of section 18 of POPIA.
1.3 It does not replace the Master Services Agreement. Where you are a subscribing practice, the MSA and its POPIA Annexure govern our handling of your data and prevail over this notice to the extent of any conflict.
2. The two capacities in which we act
This distinction determines who is accountable for what, and it runs through the rest of this notice.
| Capacity | When it applies | What it means |
|---|---|---|
| Responsible party | Our website visitors, prospective customers, practice users of the platform, and our own suppliers and staff. | We decide why and how this information is processed. We are directly accountable to you and to the Information Regulator for it. |
| Operator | Remittance data, claim lines and patient identifiers belonging to a subscribing practice. | The practice is the responsible party. We process that information only on the practice's documented instruction, under the POPIA Annexure to the Master Services Agreement. We do not decide the purposes of that processing and we do not use it for our own purposes. |
If you are a patient of a practice that uses RemMed, your medical aid claim information reaches us through that practice. Your relationship is with the practice, and requests about your information should be directed to the practice in the first instance. We will assist the practice in responding.
3. What we collect, and why
3.1 Website visitors and enquirers
| Information | Purpose | Lawful basis (POPIA s11) |
|---|---|---|
| Name, practice name, email address, telephone number, submitted through a contact, demo or Remittance Review form | To respond to your enquiry, arrange a demonstration, and prepare a quotation or Remittance Review | s11(1)(b) — steps taken at your request before entering into a contract |
| IP address, browser and device type, pages viewed, referring source, session duration | To keep the site secure and available, and to understand which pages are useful | s11(1)(f) — our legitimate interest in operating and improving the site |
| Marketing preferences and communication history | To send you material you have asked for, and to stop sending it when you say so | s11(1)(a) — consent, which you may withdraw at any time |
| Cookie and analytics identifiers | See the separate Cookie Notice | s11(1)(a) for non-essential cookies; s11(1)(f) for strictly necessary cookies |
3.2 Practice users of the platform
| Information | Purpose | Lawful basis |
|---|---|---|
| Name, work email address, role, mobile number, authentication credentials | To create and secure your account, authenticate you, and control what you can see | s11(1)(b) — performance of the Master Services Agreement |
| Access logs, actions taken in the platform, IP address | Security monitoring, audit trail, and investigation of any suspected compromise | s11(1)(f) and s19 — our legitimate interest and our security obligations |
| Billing contact and payment reference details | To invoice and collect subscription fees | s11(1)(b) and s11(1)(c) — contract, and compliance with tax law |
| Support correspondence, including WhatsApp messages to Remeez | To answer your questions and improve the service | s11(1)(b) and s11(1)(f) |
3.3 Remittance data processed for a practice (operator capacity)
The following reaches us from medical aid remittance advices delivered to a mailbox the practice controls. We process it only to perform the service the practice has contracted for.
- Member and dependant numbers, initials and surname, and medical aid scheme and plan
- Claim numbers, account numbers, dates of service, tariff and procedure codes, ICD-10 codes where present, amounts claimed, paid, short-paid and rejected, and scheme reason codes
- Practitioner and practice identifiers, including practice numbers
Special personal information. Claim-line data includes information concerning health, which is special personal information under section 26 of POPIA. We process it under section 32(1) as an operator acting on the instruction of the practice, which processes it in the course of providing treatment and administering the resulting claim. We do not process it for any other purpose, and we do not submit it to any third-party artificial intelligence or machine-learning service that is not contractually bound to protections no less stringent than our POPIA Annexure.
4. Who we share information with
4.1 We do not sell personal information, and we do not share it with third parties for their own marketing.
4.2 We use a small number of service providers — operators in POPIA terms — to run the platform. Each is bound by a written agreement imposing data protection obligations no less protective than those we owe. They are disclosed by category below. A named list is maintained in our Sub-Operator Register and is available to any subscribing practice on written request to the Information Officer.
| Category | What it does | Location |
|---|---|---|
| Managed database, authentication and file storage | Holds the application database and stored files | United Kingdom (London) |
| Application hosting and content delivery | Runs and serves the web application | United Kingdom (London) |
| Transactional email delivery | Sends account and authentication messages, the 07:00 daily digest, and recovery statements | United States |
| Electronic signature | Circulates and executes agreements | United States |
| Payment processing | Collects the monthly subscription and once-off fees. Card and bank details are entered with the payment provider directly — we never receive, store or transmit card numbers, and no claim-line, patient or health information reaches this provider. | South Africa |
| Marketing and newsletter email | Sends the updates you subscribe to on our website. Processes your email address and the record of your consent only. | United States |
| Secrets management | Holds the encryption key protecting mailbox credentials, separately from the data itself. Holds no personal information. | United States |
4.3 Your email provider (for example Google Workspace or Microsoft 365) is not our service provider. Where a practice grants us access to a mailbox for remittance ingestion, that access is under the practice's own account with its own provider.
4.4 Google user data.Where a practice connects a Google mailbox, RemMed requests read-only access to that mailbox (the read-only Gmail permission, gmail.readonly) with the practice's explicit consent. We access only messages that match our medical scheme remittance filters, and we use them for one purpose: extracting the remittance advice PDF attachments and parsing them into the claim records shown on the practice's own dashboard.
4.5 We do not store email messages or bodies. Source remittance PDFs are parsed and discarded — only the extracted claim-line data is retained. The credentials that authorise our access are encrypted at rest, are never disclosed, and can be revoked at any time from the RemMed settings page or from the practice's own Google Account security settings. We do not use Google user data for advertising, we do not sell it, and no person reads it except with the practice's consent for support or security purposes, or where the law requires disclosure.
4.6 RemMed's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.7 We may also disclose information where the law requires it, where it is necessary to establish, exercise or defend a legal claim, or to our professional advisers under duties of confidentiality.
5. Where your information goes (cross-border transfer)
5.1 Our primary data storage and application compute are located in the United Kingdom (London region). Certain supporting services — transactional email, marketing email, electronic signature and secrets management — are provided from the United States. Payment processing takes place in South Africa.
5.2 These are trans-border flows under section 72 of POPIA. We rely on section 72(1)(a): each recipient is bound by a written agreement that upholds principles for reasonable processing substantially similar to the conditions in POPIA, and the primary hosting environment is subject to the UK and EU General Data Protection Regulation and holds independent certifications including ISO/IEC 27001 and SOC 2. Our payment processing takes place within South Africa, so no personal information leaves the country for that purpose.
5.3 We do not transfer personal information to any other jurisdiction without first establishing a lawful basis under section 72 and, where a practice is affected, notifying that practice.
6. How long we keep it
| Category | Retention period | Reason |
|---|---|---|
| Website enquiry and demo request data | 24 months from last contact, unless you become a customer | Sales follow-up, then deletion |
| Marketing contact data | Until you withdraw consent, then suppressed on a do-not-contact list | s69 POPIA |
| Practice user accounts and access logs | Duration of the agreement, plus 12 months | Security investigation and dispute resolution |
| Remittance and claim-line data (operator capacity) | As instructed by the practice under the Master Services Agreement; returned or deleted on termination | The practice sets retention as responsible party |
| Accounting and tax records | 5 years | Companies Act 71 of 2008 and Tax Administration Act 28 of 2011 |
| Signed agreements | 5 years after termination | Prescription and evidentiary purposes |
| Mailbox connection credentials | Deleted immediately on withdrawal of the connection or termination, and in any event within 30 days | Clause A3.3 of the Master Services Agreement |
Where information no longer serves the purpose it was collected for and no law requires us to keep it, we delete or de-identify it.
7. How we protect it
- Encryption of data in transit and at rest
- Role-based access control, with access granted on a least-privilege basis and reviewed periodically
- Multi-factor authentication on administrative access
- Logging and monitoring of access to practice data
- A read-only architecture — the platform holds no write credentials to any practice billing system, which materially limits what a compromise could do
- Where your email provider does not support Google or Microsoft sign-in and you supply mailbox credentials directly, those credentials are encrypted at rest with AES-256-GCM under a key held in a separate secrets management system, are never written to any log or error report, and cover incoming mail only — we hold no credentials capable of sending email from your address
- Written agreements with every service provider imposing equivalent security obligations
If a security compromise affects your personal information, we will notify you and the Information Regulator as soon as reasonably possible after establishing the scope of the compromise, in accordance with section 22 of POPIA. Where we act as operator, we will notify the practice without undue delay and in any event within 48 hours of becoming aware.
8. Your rights
Under POPIA you may:
- Ask what we hold. Confirm free of charge whether we hold personal information about you, and request a copy or description of it (sections 23 and 24). A prescribed fee may apply to the copy itself.
- Correct or delete it. Request correction of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or deletion of a record we are no longer authorised to retain (section 24). Use Form 2 of the POPIA Regulations.
- Object. Object on reasonable grounds to processing we carry out on the basis of legitimate interest (section 11(3)). Use Form 1 of the POPIA Regulations.
- Withdraw consent. Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Opt out of direct marketing. Ask us to stop sending you electronic marketing at any time (section 69). Every marketing message we send carries an unsubscribe mechanism.
- Not be subject to automated decision-making. Section 71 applies. Our platform prioritises and ranks recovery actions but does not make decisions with legal consequences about any individual — a person at the practice decides what to act on.
- Complain. Lodge a complaint with us or directly with the Information Regulator.
To exercise any of these, contact our Information Officer at privacy@remmed.co.za. We will respond within 30 days. Forms 1 and 2 are available from our Information Officer and from the Information Regulator's website.
9. Contact details
| Responsible party | Vowels Africa (Pty) Ltd t/a RemMed SA |
|---|---|
| Registration number | 2025/722562/07 |
| Registered office and postal address | 57 Innis Road, Wynberg, Cape Town, Western Cape, 7800 |
| Information Officer | Yaseen Samsodien |
| Information Regulator registration number | 2026-063725 |
| Email — privacy and data requests | privacy@remmed.co.za |
| Email — general enquiries | hello@remmed.co.za |
| Website | remmed.co.za |
| Cookie Notice and preferences | remmed.co.za/cookies · change your choice at any time using the Cookie preferences link in the footer of any page |
We are contactable by email. Section 18 of POPIA requires the name and address of the responsible party, both of which appear above; it does not require a telephone number, and we do not publish one.
You may complain to the Information Regulator at any time:
| The Information Regulator (South Africa) | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg |
|---|---|
| Postal address | PO Box 31533, Braamfontein, Johannesburg, 2017 |
| General enquiries | enquiries@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| Website | inforegulator.org.za |
10. Changes to this notice
We may update this notice. The version number and effective date at the top will change, and the current version will always be available at remmed.co.za/privacy. Where a change materially affects how we process your personal information, we will bring it to your attention directly rather than relying on the website alone.
Version history is maintained by the Information Officer. Superseded versions are retained for five years.