Privacy Policy
At Kwagga Mall X-Rays, we are committed to protecting your privacy and ensuring that your personal information is handled securely. This Privacy Policy outlines how we collect, use, store, and protect your information in compliance with South African data protection laws (POPIA) and the General Data Protection Regulation (GDPR).
By using our website or services, you agree to the collection and processing of your data as described in this policy.
1. Information We Collect
We collect the following types of personal data when you visit our website, book an appointment, or interact with our services:
1.1 Personal Information
- Name and Surname
- Phone Number
- Email Address
- Home Address (if required for billing purposes)
- Medical Aid Details (if applicable)
- Doctor’s Referral Information (if applicable)
1.2 Medical Data (Collected only for diagnostic purposes)
- X-ray images and radiology reports
- Patient health history (if provided by a referring doctor)
1.3 Website Usage Data (Collected via cookies and analytics)
- IP Address
- Device Information (Browser Type, Operating System, etc.)
- Website Usage Behavior (e.g., pages visited, time spent on site)
2. How We Use Your Information
Kwagga Mall X-Rays collects and processes your data for the following purposes:
- To provide diagnostic imaging services and generate X-ray reports.
- To schedule and manage patient appointments.
- To process medical aid claims (where applicable).
- To communicate with patients regarding appointments, results, and follow-ups.
- To comply with legal and medical regulatory obligations.
- To improve our website experience using analytics and tracking technologies.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. How We Store & Protect Your Data
We take appropriate technical and organisational measures to protect your personal and medical data from unauthorised access, disclosure, loss, or alteration. These include:
- Secure Storage – Patient data is stored in HIPAA-compliant, encrypted servers.
- Restricted Access – Only authorised personnel (radiologists, medical staff) can access your X-ray records.
- Data Minimisation – We collect only the information necessary for medical purposes.
- Regular Security Audits – We periodically review our security practices to safeguard patient information.
If a data breach occurs, we will notify affected users and the appropriate regulatory authorities within 72 hours, as required by GDPR.
4. How Long We Retain Your Information
- Medical records and X-ray images are retained for at least 6 years, in accordance with South African medical regulations.
- Contact details and appointment history are retained for 2 years unless you request deletion.
- Website analytics data is stored for a maximum of 12 months for statistical purposes.
5. Sharing Your Data with Third Parties
We may share your data only in the following circumstances:
- With referring doctors or hospitals for medical diagnosis and treatment.
- With medical aid providers for payment processing.
- With legal authorities if required by law (e.g., court orders, legal claims).
- With IT service providers who manage our website and booking system (under strict confidentiality agreements).
Your data is never shared for marketing or commercial purposes.
6. Your Rights Under GDPR & POPIA
As a patient or website visitor, you have the following rights regarding your personal data:
6.1 Right to Access
You can request a copy of the personal data we hold about you.
6.2 Right to Correction
You can request corrections to any incorrect or outdated personal data.
6.3 Right to Deletion (“Right to Be Forgotten”)
You may request deletion of your data, subject to legal and medical retention requirements.
6.4 Right to Restrict Processing
You may request that we limit the use of your data under certain circumstances.
6.5 Right to Data Portability
You can request your medical records in a transferable format for use with another healthcare provider.
6.6 Right to Object to Processing
You may object to the use of your data for analytics, tracking, or marketing purposes.
6.7 Right to Withdraw Consent
If we rely on consent to process your data, you can withdraw your consent at any time.
To exercise your rights, contact us at 📧 info@kwaggamallxrays.co.za.
7. International Data Transfers (GDPR Compliance)
- Your data is stored within South Africa.
- If we need to transfer data internationally (e.g., cloud storage), we ensure adequate protection in compliance with GDPR safeguards.
8. Cookies & Tracking Technologies
We use cookies to enhance user experience and website functionality. For full details, see our Cookie Policy.
9. Updates to This Privacy Policy
We may update this policy periodically to reflect legal, security, or service changes. Updated versions will be published on our website, and continued use of our services implies acceptance.
Last Updated: [10 March 2025]
10. Contact Us for Privacy Inquiries
If you have any questions, concerns, or requests regarding your data privacy, contact us:
- Address: Kwagga Mall X-Rays, Mpumalanga
- Phone: 013 986 0100
- Email: info@kwaggamallxrays.co.za