Skip to content
FIDEREMEN'S HEALTH
Our approach What we manage Memberships Member experience About
Contact us

Legal

Privacy policy

Fidere holds health information, which South African law treats as special personal information. This policy explains exactly what we collect, why, who sees it, how long we keep it and what you can demand of us.

On this page

1. Who is responsible for your information 2. What we collect 3. Why we use it 4. Automated processing and clinical software 5. Who we share it with 6. Information sent outside South Africa 7. How long we keep it 8. How we protect it 9. Your rights 10. Children 11. The Information Regulator 12. Changes to this policy

Version 1.0 · Effective 18 September 2026 · Last reviewed 18 September 2026

1. Who is responsible for your information

The responsible party under the Protection of Personal Information Act, 2013 (POPIA) is Fidere Clinic (Pty) Ltd, registration number 2026/526977/07, of 19 Greenwich Grove, Station Road, Rondebosch, Cape Town, 7700, South Africa.

Our Information Officer can be reached at info@fidere.co.za or by post at the address above.

2. What we collect

CategoryExamples
Identity and contactName, identity or passport number, date of birth, email address, phone number, postal address, next of kin
Health informationMedical and family history, symptoms, medication, allergies, consultation notes, examination findings, laboratory and imaging results, genetic and epigenetic test results where ordered, treatment plans, prescriptions
Lifestyle informationSleep, exercise, nutrition, alcohol and tobacco use, stress, and wearable or device data you choose to share
FinancialBilling records, invoices, payment status. We do not hold your full card number
TechnicalIP address, browser type, device type, pages visited, and cookie data. See our cookie policy
CommunicationsEmails, enquiry forms, messages in the member platform

Health information and genetic information are special personal information under section 26 of POPIA. We handle them under section 32, which permits processing by or under the responsibility of a health care professional where it is necessary for the proper treatment and care of the person concerned.

3. Why we use it

PurposeLawful basis under POPIA
Providing clinical care, diagnosis, treatment and monitoringSection 32, health care, and your consent
Running your membership, booking and recordsPerformance of our contract with you
Billing, payment and accountingContract and legal obligation
Keeping medical records as the law requiresLegal obligation, HPCSA and National Health Act
Improving and securing our serviceOur legitimate interest, balanced against your rights
Sending you service and clinical messagesContract
Sending marketingYour consent only. You can withdraw it at any time

What we never do

We do not sell your personal or health information. We do not share it with advertisers or data brokers. We do not share your health information with an employer, an insurer or a medical scheme unless you instruct us in writing to do so.

4. Automated processing and clinical software

Fidere uses software to organise your results, flag values outside reference ranges and prepare draft summaries for your clinician. No clinical decision about you is made by software alone. A registered clinician reviews and is responsible for every clinical decision, in line with section 71 of POPIA.

5. Who we share it with

  • Your clinical team at Fidere, on a need to know basis.
  • Laboratories, imaging providers and pharmacies, limited to what they need to perform the test or dispense the medicine you agreed to.
  • Specialists to whom you are referred, with your agreement.
  • Our payment provider, Paystack, which processes card payments and receives your name, email address and the amount. It does not receive your health information.
  • Technology suppliers that host and secure our platform, email and backups, under written operator agreements requiring them to protect your information and to act only on our instructions.
  • Professional advisers and auditors, where they are bound by confidentiality.
  • A regulator, court or law enforcement body, where the law compels disclosure.

6. Information sent outside South Africa

Some of our suppliers store data outside South Africa. Where that happens, we transfer information only under section 72 of POPIA, which means the recipient is bound by rules giving protection substantially similar to POPIA, or you have consented, or the transfer is necessary to perform our contract with you. We keep a record of where your information is held and will tell you on request.

7. How long we keep it

RecordRetention period
Adult medical recordsAt least 6 years from the date they became dormant, as required by the HPCSA and the National Health Act, 2003
Records where a claim may still ariseLonger where the law or a legal claim requires it
Financial and tax records5 years, as required by the Tax Administration Act, 2011
Enquiry forms from people who did not become members12 months, then deleted
Website analytics and cookie dataUp to 26 months

When a retention period ends, we destroy or de-identify the information securely.

8. How we protect it

  • Encryption in transit and at rest.
  • Role based access, so staff only see what their role requires.
  • Individual logins, with an audit trail of who viewed or changed a record.
  • Multi-factor authentication on clinical and administrative systems.
  • Regular backups, stored separately and encrypted.
  • Written confidentiality undertakings from everyone with access.

If a security compromise affects your personal information, we will notify you and the Information Regulator as soon as reasonably possible, as section 22 of POPIA requires.

9. Your rights

Under POPIA you may:

  • Ask what personal information we hold about you and get a copy.
  • Ask us to correct or complete information that is wrong or out of date.
  • Ask us to delete information we no longer have a lawful reason to keep. Medical records within their legal retention period cannot be deleted on request.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, including for marketing. Withdrawing consent does not affect processing already done, and may mean we can no longer treat you safely.
  • Complain to us, and then to the Information Regulator.

To exercise a right, email info@fidere.co.za. We may ask you to confirm your identity first. We respond within 30 days. Access to your own records is free once a year. Our PAIA process is set out in the PAIA manual.

10. Children

Fidere serves adults. We do not knowingly collect information about anyone under 18. If we learn that we have, we delete it.

11. The Information Regulator

Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za

12. Changes to this policy

We will post any change here and update the version date at the top. Where a change materially affects how we use your health information, we will tell you by email before it takes effect.

Back to Fidere
FIDEREMEN'S HEALTH

Private, proactive and coordinated healthcare for men.

Fidere Clinic (Pty) Ltd
Registration number 2026/526977/07
19 Greenwich Grove, Station Road,
Rondebosch, Cape Town, 7700
South Africa
071 975 9553
info@fidere.co.za

Explore

Our approachWhat we manageMembershipsMember experience

Policies

Terms and conditionsFees, payment and refundsPrivacy and POPIACookie policyPAIA manualContact and complaints

Clinical notice

This website provides general information and is not a diagnosis, treatment recommendation or prescription. Treatment is decided only by a qualified clinician after appropriate assessment.

© 2026 Fidere Clinic (Pty) LtdRegistration number 2026/526977/07 · Cape Town, South Africa