Test site — not the live store. Orders placed here are not real.
GenXClinics

Legal

Privacy notice

This describes what we hold about you and what we do with it, under the Protection of Personal Information Act. Some of it is health information, which the Act protects more strictly than ordinary personal information — and so do we.

Draft — not yet in effect

This document is prepared but has not been reviewed by a legal adviser or adopted by GenX Clinics. It does not yet govern any order. The effective date appears here once it does.

1. Who is responsible

GenX Clinics, of 2nd Floor, Lifestyle on Kloof, 50 Kloof Street, Gardens, Cape Town, South Africa, is the responsible party for the personal information described here. Requests about your personal information should be addressed to the Information Officer at that address, or by telephone on +27 66 107 7224.

2. What we collect

Grouped by why it exists, because that is what decides how long we keep it and who can see it.

Identity and contact
Your name, email address, telephone number and delivery addresses.
Account and consent
Your sign-in history, and a record of what you consented to and when — the consent log is itself evidence we are required to keep.
Orders
What you ordered, at what price, when, where it was sent, and the timeline of what happened to it, including notes from staff.
Health information
What your clinician records in your account in order to supply you correctly — your prescription, dose, the items on your repeat, and clinical notes attached to your record. This is special personal information under POPIA.
Payment
The amount, the outcome, and a provider reference. Where a card is saved, only the brand, last four digits and expiry. Full card numbers never reach our systems.
Technical
Server logs including IP address, browser and the pages requested, kept for security and to diagnose faults. The cookies we set are listed in the cookie notice.

3. Where it comes from

From you, when you create a profile, place an order or contact us; from your clinician, when they record something in your account or prepare a cart for you; and from our payment and delivery providers, when they report the outcome of a payment or a delivery.

4. Why we process it, and on what basis

POPIA requires a lawful ground for each purpose, not a single blanket consent.

  • To supply what you order — necessary to perform our contract with you.
  • To supply it safely — health information is processed for the purpose of providing care and supplying what has been prescribed, by or under the responsibility of a health care professional bound by a duty of confidentiality.
  • To meet legal obligations — tax records, and the records a practice is required to keep.
  • To keep the platform secure — our legitimate interest, which is why staff access to a patient record is logged and why an audit trail cannot be edited or deleted by anyone, including us.
  • To send you marketing — only with your consent, which you may withdraw at any time. We do not need your consent to send you an order confirmation, a dispatch notice or anything else about an order you placed.

5. Who we share it with

We do not sell personal information, and we do not share patient data with advertisers.

Clinic staff
The practitioners and support staff looking after you. Access is by role, and reads are logged.
Delivery partners
The name, address and telephone number needed to deliver a parcel. Never what is inside it.
Payment providers
The amount and a reference. Card details go directly from your browser to them, not through us.
Email provider
Your address and the content of transactional messages such as sign-in codes and order confirmations.
Hosting and infrastructure
The platform and database, hosted in the United Kingdom (London).
Professional advisers and authorities
Where we are legally required to disclose, or need advice on a dispute. We will tell you unless we are prohibited from doing so.

6. Where it is stored

Our database and application are hosted in the United Kingdom (London), so your information is processed outside South Africa. POPIA permits this where the receiving jurisdiction has comparable protection or the processor is bound by contract to uphold it; our providers are bound by data processing terms to that effect. If that arrangement changes, this notice changes with it.

7. How it is protected

Specifics rather than assurances, so that you can judge them.

  • Sign-in is by one-time code to your email address. There is no password for anyone to steal or reuse.
  • Staff accounts require a second authentication factor to reach the back office at all, and staff access is granted by capability rather than a general administrator role.
  • Opening a patient's record or an order, and every change to one, is written to an append-only audit log that no role can edit or delete.
  • A staff member may assist inside your account only with a recorded reason and for a limited time, and can never complete a purchase as you.
  • Database access is denied by default and granted per table; the catalogue and patient data are reached through server code that applies the rules, not directly from a browser.
  • Traffic is encrypted in transit, and no card number ever reaches our servers.
  • No security is absolute. If a breach puts you at risk, we will tell you and the Information Regulator, as the Act requires.

8. How long we keep it

Not indefinitely, and not for as long as we like — several of these periods are set by law and cannot be shortened at request.

Clinical records
For the period a practice is required to retain patient records. This is the reason a deletion request cannot always be met in full.
Order and tax records
For the period required by tax law, from the end of the relevant year.
Consent log
For as long as the consent is relied upon, and afterwards as evidence that it was given.
Audit log
Retained as the integrity record of who did what. It is append-only by design.
Marketing preferences
Until you withdraw consent — and afterwards, the fact of the withdrawal, so that it is honoured.
Technical logs
A short period for security and diagnosis, then discarded.

9. Your rights

These are exercisable free of charge, and we will answer within a reasonable period.

  • Ask whether we hold information about you, and get a copy.
  • Have inaccurate or incomplete information corrected.
  • Ask us to delete information we are no longer entitled or required to keep.
  • Object to processing based on legitimate interest, on grounds relating to your situation.
  • Withdraw a consent at any time, without affecting what was lawful before you withdrew it.
  • Object to direct marketing at any time, with no reason needed.
  • Complain to the Information Regulator if you believe we have got it wrong.

The Information Regulator of South Africa can be reached through inforegulator.org.za. You are entitled to complain to them directly, and you do not have to come to us first.

10. Children

This platform is for adults. We do not knowingly create profiles for anyone under 18. Where a child is supplied under the care of the clinic, that is handled through the clinic with the consent of a parent or guardian, not through self-registration here.

11. Automated decisions

Nothing that affects you is decided automatically. Whether you may be supplied a prescription item is a clinical decision made by a person.

12. Changes to this notice

We will update this notice when what we do changes. Material changes are notified to account holders. The cookies we set are described separately in the cookie notice.