Last updated: December 2025
MedCascade is committed to protecting your privacy and ensuring the security of your personal and health information in compliance with South African law, including the Protection of Personal Information Act 4 of 2013 (POPIA).
MedCascade supports billing-assist workflows for South African healthcare providers. For patient/practice data that customers upload, the customer organisation is the POPIA "responsible party" and MedCascade is an "operator" processing personal and special personal information (health data) on the customer's behalf and instructions.
For our own account management, security monitoring and communications, MedCascade is a responsible party.
We may collect and process the following categories of information:
We follow the POPIA principles of lawfulness, purpose limitation, minimality, and confidentiality in all our processing activities.
We process personal information for the following purposes:
For special personal information (health), we act primarily as operator for the responsible party (our customer) and process on documented instructions under the applicable POPIA grounds relied upon by that customer (e.g., healthcare provision, legal claims or explicit consent). Customers are responsible for ensuring a lawful basis and necessary notices/consent.
We implement comprehensive security measures to protect your information:
As operator, we retain customer data according to the customer's configuration and instructions, and for as long as necessary to provide the Service, meet legal obligations and maintain auditability.
Backups have limited retention windows. Upon termination, we will delete or return data per our agreement and the customer's instructions unless retention is legally required.
Under POPIA, you have the following rights:
To exercise your rights, contact our Information Officer using the details below.
We do not directly target services to children. Where customer data includes information about minors, customers must ensure lawful processing and appropriate authorisations. We process such data as operator on their instructions.
In the event of a security compromise creating a real risk of harm, we will notify the affected customer (responsible party) and, where applicable, the Information Regulator and data subjects in accordance with POPIA and our contractual commitments.
We may update this policy occasionally to reflect changes in our practices or legal requirements. Material changes will be communicated in-product or by email. Continued use of the Service after such changes indicates acceptance of the updated policy.
Lodge Complaints with the Information Regulator (South Africa)
Website: https://inforegulator.org.za
This privacy policy is part of our commitment to transparency and compliance with South African privacy laws.
For questions about our Terms of Service, please visit our Terms page.