Privacy policy
Last updated: June 2026
Draft. This document is pending external legal review and may change before launch.
Who we are
DermDesk is a South African teledermatology clinical decision support service that connects healthcare practitioners with a registered dermatologist. This policy explains what personal information we process, why, and how we protect it.
What we collect about practitioners
- Account details: name, email address, phone number, HPCSA number, practice details.
- Billing records: payment references and amounts (card details are processed by Paystack and never stored by us).
- Usage records: an audit log of actions taken on the platform, kept for accountability.
What we collect about patients — and what we deliberately don't
We never collect patient names, identity numbers, or contact details. A case contains only: the practice's own internal file reference, the patient's age and sex, clinical notes, and clinical photographs. Only the submitting practice can connect a case to a patient, through its own records. The submitting practitioner confirms patient consent for every case, and the consent wording is stored with the case.
Where data lives
All patient data is stored and processed in South Africa: our application runs in Cape Town, and case records and photographs are stored encrypted in data centres in the Cape Town region. One exception applies: photographs and clinical notes are transiently processed by our AI analysis provider (Anthropic, United States) under a data processing agreement that prohibits training on the data and retention beyond processing. The AI output is used only to assist the reviewing dermatologist.
Who we share data with
- The reviewing dermatologist (clinical purpose of the service).
- Service providers under data processing agreements: AWS (hosting), Anthropic (transient AI analysis), Paystack (payments), Resend (email — never clinical content), Sentry and PostHog (error and product analytics, scrubbed of personal information), Vercel (application hosting), Upstash (rate limiting).
- No data is ever sold or used for advertising.
Retention
- Clinical photographs: deleted after 12 months.
- Case records: retained as part of the clinical record, then deleted after 5 years.
- Audit logs: 7 years.
Your rights
Practitioners may access, correct, or export their information (practices can export their full case history from the dashboard), and may lodge a complaint with the Information Regulator (South Africa). Requests: hello@dermdesk.co.za.
Security
Encryption in transit and at rest, individual logins with mandatory multi-factor authentication for the reviewing dermatologist, practice-scoped access controls, signed time-limited image URLs, and an append-only audit log.
See also our POPIA notice and Terms of service.