Skip to content
DermDesk

POPIA notice

Last updated: June 2026

Draft. This document is pending external legal review and may change before launch.

Purpose of this notice

This notice is provided under the Protection of Personal Information Act, 4 of 2013 (POPIA). DermDesk processes special personal information (health information) on behalf of healthcare practices, and we hold ourselves to the standards POPIA sets for that category.

Responsible party and operator roles

The submitting healthcare practice is the responsible party for its patients' information; DermDesk acts as an operator processing that information for the purpose of specialist review, and as a responsible party for practitioner account information.

What health information is processed

Clinical photographs, clinical notes, the patient's age and sex, and the practice's internal file reference. We deliberately collect no patient names, identity numbers, or contact details — the information is pseudonymous in our hands, and only the submitting practice can link it to a patient.

Lawful basis

Processing occurs with patient consent, confirmed by the submitting practitioner for every case (the consent wording is versioned and stored with the case), for the purpose of providing healthcare through a specialist opinion to the treating practitioner.

Where information is processed

All patient data is stored and processed in South Africa (application compute, database, and image storage all in the Cape Town region, encrypted at rest). One cross-border processing event applies: transient AI analysis of photographs and notes by Anthropic (United States) under a data processing agreement prohibiting retention and training use — used solely to assist the reviewing dermatologist.

Safeguards

  • Encryption in transit and at rest; images accessible only via signed, time-limited URLs.
  • Practice-scoped access control; staff roles cannot view clinical responses.
  • Individual logins only; mandatory multi-factor authentication for the reviewing dermatologist.
  • Append-only audit log recording the acting user on every submission and view (7-year retention).
  • Retention limits: photographs 12 months; case records 5 years.
  • Notifications and emails never contain clinical information.

Data subject rights

Data subjects may request access, correction, or deletion of personal information via their practice or directly at hello@dermdesk.co.za. Complaints may be lodged with the Information Regulator (South Africa): inforegulator.org.za.

Breach notification

In the event of a security compromise, we will notify the Information Regulator and affected responsible parties as required by section 22 of POPIA, per our internal breach response procedure.

Read with our Privacy policy and Terms of service.