Privacy Policy
INFRMD handles health information. This policy explains what we collect, why we collect it, how long we keep it, and the control you have over it under South Africa's POPIA (and the UK/EU GDPR where it applies to you).
Last updated: 18 August 2026
1. Responsible Party (data controller)
INFRMD is the Responsible Party under the South African Protection of Personal Information Act, 2013 (POPIA), and the data controller under the UK/EU GDPR where that law applies to you. Our service providers (hosting, database, AI processing, email and payments) act as Operators / processors on our written instruction.
- Responsible Party: INFRMD, South Africa.
- Information Officer: the Information Officer, reachable at privacy@infrmdmsk.com.
- All privacy questions, access requests, corrections, objections and complaints: privacy@infrmdmsk.com.
2. What we collect
- Account details: your name, email address, optional phone number and billing country.
- Health information you enter: your symptoms, history, previous treatment, medication, functional limitations, lifestyle factors and the goals or questions you want answered.
- Documents you choose to upload: imaging reports, clinical letters, referral notes and similar files. Uploading documents is optional.
- Assessment output: the AI-generated analysis, safety screening result, clinician review notes and the report produced for your case.
- Technical and payment records: timestamps, case status history, plan selected and payment reference. We never see or store your card details.
Health information is special personal information under section 26 of POPIA (and special-category data under the GDPR). We process it only with your explicit consent, given before your case is analysed, as permitted by section 27(1)(a) of POPIA.
3. Why we process it, and our lawful basis
- To provide the assessment you asked for — your explicit consent (POPIA s11(1)(a) and s27(1)(a); GDPR Art. 6(1)(a) and 9(2)(a)).
- To deliver clinician review where your plan includes it — performance of our agreement with you (POPIA s11(1)(b)).
- To run safety screening that flags presentations needing urgent medical attention — your consent, and our legitimate interest in your safety (POPIA s11(1)(f)).
- To take payment and keep financial records — our agreement with you and legal obligations under tax law (POPIA s11(1)(c)).
- To keep the service secure and diagnose faults — legitimate interest.
Giving us this information is voluntary. If you choose not to provide it, we cannot produce an assessment.
4. Who we share it with (Operators and recipients)
- Qualified clinicians engaged by INFRMD, where your plan includes clinician review. They see only the case assigned to them.
- Supabase (Lovable Cloud) — hosting, database and encrypted file storage.
- Google (Gemini) and OpenAI, accessed through the Lovable AI Gateway — AI processing of your case text and uploaded document text to generate the analysis. Your data is not used by us or by them to train models.
- Resend, through Lovable's managed email service — transactional email delivery. Emails contain no clinical detail.
- PayFast (Payfast (Pty) Ltd, South Africa) — card and EFT payment processing. Card details go to PayFast directly and never reach INFRMD.
- Anyone you deliberately share your report with using the share feature.
- Authorities, where the law requires disclosure.
Every Operator is bound by a written agreement requiring confidentiality and appropriate security measures, as required by sections 20 and 21 of POPIA. We never sell your data and we do not use your health information for advertising or profiling unrelated to your assessment.
5. Transborder flows of information
Some of the Operators above process data outside South Africa, including in the European Union and the United States. We transfer personal information across borders only as permitted by section 72 of POPIA — with your consent, where the transfer is necessary to perform our agreement with you, and under contracts that impose protection substantially similar to POPIA (Standard Contractual Clauses or equivalent).
6. How long we keep it
- Case data, AI analysis, clinician review and reports: kept while your account is open so you can return to your report, and in any event no longer than 5 years after the case is completed, unless you delete it sooner.
- Uploaded documents: deleted together with the case they belong to, and immediately on request.
- Payment and invoicing records: retained for 5 years as required by the Tax Administration Act and the Companies Act. When you delete your account or a case, we first archive these records in an anonymised form — payment reference, amount, currency, status and date only. No name, email, account identifier, case detail or health information is kept with them, and the raw payment-gateway records linked to your cases are redacted at the same time.
- Account records: deleted when you delete your account.
- Security and audit logs: retained for up to 12 months.
Records are deleted or de-identified once the applicable period expires, in line with section 14 of POPIA.
7. Your rights
You can exercise the following rights yourself from your profile page, or by emailing us:
- Access and portability — download a machine-readable copy of everything we hold about you.
- Erasure — delete an individual case, or delete your entire account and all associated health data.
- Rectification — correct your account details at any time.
- Withdrawal of consent — stop further processing of your cases. Withdrawal does not affect processing already carried out.
- Objection and restriction — ask us to pause processing while a concern is resolved.
- Object to processing — on reasonable grounds, using Form 1 under POPIA or simply by emailing us.
- Complaint — you may complain to the Information Regulator (South Africa) at complaints.IR@justice.gov.za or POPIAComplaints@inforegulator.org.za, JD House, 27 Stiemens Street, Braamfontein, Johannesburg. If you are in the UK or EU, you may complain to your national data protection authority instead.
8. Security
Data is encrypted in transit and at rest. Access to your records is enforced at database level so that only you, and a clinician assigned to your case, can read them. Uploaded files are stored in a private bucket and served only through short-lived signed links. See our security page for more detail.
9. Children
INFRMD is intended for adults. You must be 18 or older to create an account. If you believe a child has submitted information to us, contact us and we will delete it.
10. Cookies
We use strictly necessary cookies and local storage to keep you signed in and to remember your country selection. We do not use advertising or cross-site tracking cookies.
11. PAIA manual
Our manual under the Promotion of Access to Information Act, 2000 (PAIA) describes the records INFRMD holds and how to request access to them. Request a copy at any time from privacy@infrmdmsk.com, and we will send it free of charge.
12. Changes
If we make a material change to this policy we will notify you by email or in the application before the change takes effect.
