How SeptiBytes Solutions handles personal information across MedicalBytes, its portals and this website.
This notice explains how SeptiBytes Solutions handles personal information in the MedicalBytes platform, in the portals that run on it, and on this website. It is written for three audiences: members and their dependants whose information is processed in the platform, healthcare providers who submit claims through it, and the schemes, administrators and employers who license it.
Most of the information in MedicalBytes does not belong to us. A medical scheme, insurer or third party administrator decides what is collected and why, and we process it on their written instruction. In the language of the Protection of Personal Information Act, they are the responsible party and SeptiBytes is the operator.
The practical consequence is that if you are a member and you want your record corrected or explained, your scheme or administrator is the party that decides, and we act on what they instruct. We will always tell you who that is and pass your request on rather than leaving it with us.
There is a narrow set of processing where we are the responsible party in our own right: enquiries submitted through this website, the contact details of people we deal with at client organisations, and our own security and audit logs. This notice covers both, and says which is which.
| Category | What it includes |
|---|---|
| Identity and contact | Name, identity or passport number, date of birth, membership number, contact details, employer or scheme, dependant relationships |
| Biometric | Fingerprint and facial templates, enrolment records, verification attempts and their outcomes |
| Health | Diagnoses and ICD-10 codes, procedures and CPT codes, treating provider, dates and places of service, authorisation requests and the clinical notes attached to them |
| Financial | Benefit structures and balances, claims, tariffs, co-payments, invoices, payment runs and reconciliations |
| Provider | Practice and practitioner numbers, credentials and their expiry, contracted tariffs, banking details for settlement |
| Technical | Portal and app access logs, device and session information, IP address, and what was done in the system and by whom |
| Website | What you submit on the contact form, and aggregate analytics about how pages are used |
Health information and biometric information are special personal information under section 26 of POPIA. They carry conditions beyond those applying to ordinary personal information, and section 5 below deals with them separately.
| Purpose | Lawful basis |
|---|---|
| Proving that the person receiving care is the person entitled to it | Consent at enrolment, and the legitimate interest of the scheme in preventing claims against another person's membership |
| Resolving membership, dependants, waiting periods and terminations at the point of service | Performance of the contract between the member and their scheme |
| Deciding authorisation before treatment, and adjudicating the claim after it | Performance of that same contract, and the obligations the scheme carries under its own rules |
| Paying providers and reconciling those payments | Performance of the provider contract, and legal obligations relating to financial records |
| Detecting fraud, waste and abuse | Legitimate interest of the scheme and its members in protecting the benefit pool |
| Reporting to the scheme, its board, its actuaries and its regulator | Legal obligation and legitimate interest |
| Keeping an audit trail of who did what | Legal obligation, and our own legitimate interest in being able to demonstrate what the system did |
| Answering an enquiry you send through this website | Your consent, given by submitting the form |
Biometric verification exists to answer one question at the point of care: is this the person entitled to this benefit. How it is handled:
Access to diagnoses and to identifying details is masked from users with no clinical or legal need to see them. A finance clerk processing a payment run sees the amounts and the codes, not the condition.
From you, when you enrol, present for care or submit an enquiry. From your scheme, employer or administrator, when they load membership. From your healthcare provider, when they request authorisation or submit an invoice. From the platform itself, in the form of logs and the decisions it records.
We do not sell personal information. We do not share it for advertising. We do not use member or claims data to build or train anything for another client.
Member and claims data is held in South Africa. Some of the cloud infrastructure, backup and tooling the platform relies on is operated by providers whose facilities or support functions sit outside the Republic, which means personal information may be transferred across a border within the meaning of section 72 of POPIA.
Where that happens, the transfer is made on a basis section 72 allows: the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles for lawful processing substantially similar to POPIA and includes provisions substantially similar to section 72 on onward transfer; or the transfer is necessary for performance of the contract between the member and their scheme. Every such provider is contracted on written terms carrying those obligations through.
A client scheme may require that its data never leaves the Republic. That is a configuration we support, and it is recorded in the agreement with that client.
Retention is set by the responsible party, because the scheme carries the record-keeping obligation, not us. Where a client has not set a period, we apply the longer of the period required by South African law for medical scheme and financial records, and the period needed to defend a claim that could still be brought.
Biometric templates are deleted when membership ends and the retention period for the associated claims record has run, or earlier on the instruction of the responsible party. Audit logs are kept for the full retention period, because deleting them would defeat their purpose.
If a security compromise affects your personal information we notify the responsible party without undue delay, and section 22 of POPIA requires notification to the Information Regulator and to affected data subjects. Where we are the responsible party, we make those notifications ourselves.
Under POPIA you may ask what personal information we hold about you, ask for it to be corrected or deleted, object to processing, and withdraw consent where consent is the basis we rely on. You may object to direct marketing at any time.
Send the request to info@med-bytes.com. We will acknowledge it and tell you, within a reasonable period, either what we hold or which responsible party the request has been passed to and who there will answer it. We may need to verify your identity first, and we will ask for no more than is necessary to do that.
Withdrawing consent to biometric verification does not end your cover. It moves you to the exception route described in section 5, which may mean verification takes longer at the point of service.
This website uses two third-party services and nothing else:
The contact form collects your name, organisation, work email, an optional phone number, the type of organisation you represent and roughly how many lives you administer. It is used to answer you and to prepare for the conversation. It is not added to a marketing list and it is not shared.
The platform decides some authorisations automatically, against rules your scheme has configured. Section 71 of POPIA restricts decisions based solely on automated processing where they have legal consequences for a person.
Two things follow, and both are built in. An automatic decline is only ever issued on an explicit rule: anything uncertain becomes a review by a person, never a refusal. And every automated decision carries the rule that produced it, so it can be explained and challenged. You may ask for any automated decision about you to be reviewed by a person, through your scheme or through the address below.
When this notice changes materially we update the effective date shown at the foot of the page. Where the change affects how member information is processed, the responsible party is notified so it can tell its members.
Write to info@med-bytes.com, marked for the attention of the Information Officer. If you are not satisfied with how we have answered, you are entitled to complain to the Information Regulator (South Africa), whose current contact details are published at inforegulator.org.za.
SeptiBytes Solutions, for the MedicalBytes platform.
Effective 25 September 2026