Privacy Policy
KardioFit (Pty) Ltd, with its head office situated at 22 1st Avenue, Houghton Estate, Houghton, Johannesburg, South Africa, has developed the KardioFit Mobile Application (“KardioFit App” / “App” / “Application”). The KardioFit App is a healthcare App for individuals (“User”). This Service is provided by KardioFit to the individual at a monthly subscription fee and is intended for use, “as is”.
KardioFit enables the individual to record his/her biometric readings utilising inter alia any of a blood pressure monitor, glucose monitor and spirometer in a private setting and allows health professionals to monitor certain patient-related data for greater reliability of measures made and time saving (hereinafter referred to as the “Application”).
This Application allows for the collection and processing of certain personal data (hereinafter referred to as the “Personal Data“) of the individual. The Personal Data that is collected is used for providing and improving the Service, we provide to you. KardioFit will not use or share your information with anyone except as described in this Privacy Policy and as consented to by you.
KardioFit protects the Personal Data that it processes and hereby undertakes, in this regard, to comply with applicable regulations on the protection of personal data, and in particular the Protection of Personal Information Act, No.4 of 2013, South Africa (” POPI Act”), as amended, and Regulation (EU) 2016/679 of 27 April 2016, referred to as the “GDPR” (hereinafter referred to as the “Applicable Regulations”).
This privacy policy (the “Privacy Policy”) is intended to inform the User of his/her rights and obligations with respect to the processing of his/her Personal Data implemented through the Application.
By accepting the General Terms of Use of the Application to which he/she subscribes, the User acknowledges having read and accepted this Privacy Policy.
Personal Data Processing
Processing of the Users’ Personal Data
Purposes and legal basis of processing
Certain Personal Data is collected by KardioFit for the following purposes:
- creating the User’s account on the Application,
- identifying the User as a KardioFit customer,
- providing services associated with the Application, and
- managing their business relationship.
KardioFit, is required to collect and process certain Personal Data of the User according to his/her use of the Application, namely:
- last name, first name, professional email address, phone number, gender, title and mailing address, and
- certain specific and sensitive data related to their health (pulse or blood pressure constants, medical history, etc.).
This processing is necessary to enable KardioFit to provide its service to the User via the Application, and is based on the agreement binding both parties, expressed by the acceptance of the General Terms of Use related to the Application.
User Status and Obligations
Such processing is carried out under the exclusive control of the User. Therefore, for such data processing, the User acts as the data controller, as defined in the Applicable Regulations.
The User undertakes to meet all of his/her obligations and to take into account the particularly sensitive nature of the health data he/she processes.
The User agrees and confirms that he/she shall apply the requisite degree of care in the processing and storage of his/her Personal Data, on the device within which it is captured.
KardioFit Status and Obligations
KardioFit provides the User with the tool required for the processing described above and provides him/her with a secure solution for hosting his/her Personal Data.
KardioFit undertakes to meet its obligations as a data processor, including the implementation of appropriate technical and organisational measures to secure the Personal Data.
KardioPro hosts Personal Data on a virtualised environment in Microsoft Azure in the Johannesburg Data centre with an ongoing hosting contract. For such hosting activity in the South African environment region, Microsoft Azure acts as a subsequent subcontractor of KardioPro, which the User expressly and unreservedly accepts, as the data controller, by accepting the General Terms of Use of the Application.
KardioFit hereby acknowledges that it shall only act on the documented instructions of the User and that it shall notify him/her of any security breaches of which it may become aware.
Once the User ceases to use the Application, the User shall indicate to KardioFit, which will comply with such indication, whether he/she wants his/her Personal Data to be destroyed or to be returned to him/her or to a third party, and in what format.
KardioFit also hereby states that it keeps a record of all of the categories of processing activities performed on behalf of the User and that it shall provide the User with the necessary documentation to evidence its compliance with all of its obligations.
Retention Period of the Personal Data
KardioFit shall keep the Personal Data for the duration of use of the Application by the User. KardioFit shall retain the Personal Data for five (5) years after the User ceases to use the Application, in order to meet its legal obligations, notably in terms of prescription.
Personal Data Security
KardioFit processes the Personal Data collected in accordance with Applicable Regulations, and notably implements the appropriate safeguards to protect the confidentiality and integrity of the User’s Personal Data. KardioFit undertakes to take all useful and reasonable precautions to ensure the security of the Personal Data collected from the User and in particular to prevent them from being destroyed, lost or corrupted and to prevent access to them by unauthorised third parties.
The features of the Application are implemented in a secure environment ensuring the protection of all Personal Data and any potential communication with the User.
User’s Rights
Each User is hereby reminded that he/she has, in accordance with Applicable Regulations, the right to access, rectify and delete his/her Personal Data. The User also has the right to request the limitation of the processing of his/her Personal Data and to object to such processing, as well as the right to the portability of his/her Personal Data. Lastly, the User may file a complaint with the competent supervisory authority (the office of the Information Regulator, South Africa).
These rights may be exercised by sending a letter to: KardioFit 22 1st Avenue, Houghton Estate, Houghton, Johannesburg, 2198, or an email to the following email address: support@kardiogroup.com, with a copy of the User’s identity document. The User may also contact the KardioFit Data Protection Officer (DPO), at the following email address: support@brandmedgroup.com.
Disclosure of Personal Data
KardioFit will not sell, trade, rent or transfer the User’s Personal Data in any other way, without the User’s consent, which will have been given after the User has received prior information, except for the cases listed below:
- Within KardioFit and its associated companies: KardioFit may share the User’s Personal Data within KardioFit and its associated companies, to ensure the proper functioning of the Applications and of the Products, and their related features;
- With third-party providers: KardioFit may communicate the User’s Personal Data to third parties in or outside the South African region, in particular in the context of offers or joint services, as well as to help us operate the Applications and the Products;
- With third-party applications: KardioFit provides connection options to third-party applications, which are partners of KardioFit. Such partners may offer to synchronise the User’s Personal Data with their applications. In such cases, KardioFit has specific agreements with such partners allowing KardioFit and the partners to access the Personal Data collected by their respective applications. Such access is subject to the User’s prior consent. Such consent shall be specific, provided independently of any other consent that the User may have previously given.
- With third parties for legal reasons: in the event that KardioFit would be required to comply with laws and regulations and / or lawful requests and orders or if permitted by law (that is, for the protection and the defence of rights, a situation that threatens life, health or safety, etc.).
Cookies
KardioFit may use Cookies when using the Application to facilitate their operation. For more information on such Cookies, KardioFit recommends that the User refer to the Cookie Policy section on www.kardiofit.co.za for such purpose.
Amendment of the Policy
KardioFit reserves the right to amend the terms of this Privacy Policy. The User shall be informed of any amendments made before they become effective.
The User is invited, in any event, to carefully read and regularly consult the Privacy Policy.
[Privacy Policy for South Africa updated on October 10, 2019]
References
http://www.justice.gov.za/inforeg/docs/InfoRegSA-POPIA-act2013-004.pdf
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679