Privacy Policy
PRIVACY NOTICE
HIPP Orthodontics (Pty) Ltd – Version 1.1, effective 6 June 2025
1. Introduction
Welcome to HIPP Orthodontics (Pty) Ltd (“HIPP Orthodontics”, “we”, “our” or “us”). We respect your right to privacy and comply with the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act 2 of 2000 (PAIA). This Privacy Notice explains what personal information we collect when you visit www.hipporthodontics.co.za (the “Website”), why we collect it, how we use it, and the rights you have in relation to that information.
Scope: This notice covers information collected online only. Health‑related information gathered in‑practice is governed by separate patient documentation available at reception.
2. Who we are
Responsible Party: | HIPP Orthodontics (Pty) Ltd, Reg No 2012/123456/07 |
Registered Address: | 30 John X Merriman Street, Oakdale, Bellville 7530 |
Information Officer: | Dr Jacqueline Cupido, Orthodontist & Managing Director |
Contact: | Tel +27 21 948 6580 • Email privacy@hipporthodontics.co.za |
3. Personal information we collect
We collect the minimum data necessary to respond to your online enquiry:
- Identification & contact data – full name, email address, mobile/telephone number.
- Usage data – IP address, browser type, pages visited, time spent (via cookies – see 7).
We do not request ID numbers, medical‑aid membership numbers, credit‑card details or health information through the Website.
4. How we collect information
- Directly from you when you complete the Website’s Contact Us form or communicate with us on social media.
- Automatically via cookies and similar technologies.
Purpose | Legal basis under POPIA | Details |
Responding to your enquiry and scheduling an assessment | Consent (you voluntarily provide data) | You may withdraw consent at any time. |
Website analytics & service improvement | Legitimate interests (Condition 4(1)(b)) | Aggregated statistics via Google Analytics. |
Secure operation of the Website | Legitimate interests | Retention of server logs to detect fraud or abuse. |
We do not use Website‑collected information for direct marketing.
6. Disclosure of personal information
We share data only when necessary and subject to written agreements that uphold POPIA safeguards:
- Microsoft OneDrive (EU data centre) – encrypted backup and document storage.
- Align Technology – iTero Cloud (EU region) – storage of intra‑oral scans (if uploaded by staff).
- Meta Platforms (WhatsApp Business) – appointment confirmations.
- External service providers – laboratory technicians and bookkeeping services.
No personal information is sold or disclosed for advertising purposes.
7. Cookies & tracking technologies
Our Website uses first‑party Google Analytics cookies:
Cookie | Purpose | Expiry |
_ga, _gid | Visitor statistics | 2 years / 24 h |
_gat | Throttle request rate | 1 minute |
Non‑essential cookies load only after you click “Accept” on our cookie banner. You can withdraw consent at any time via Cookie Settings in the footer.
8. Security of your information
We employ reasonable technical and organisational measures, including:
- Password‑protected workstations and two‑factor authentication for cloud services.
- Encryption at rest for OneDrive backups.
- Microsoft 365 Exchange secure email.
- Access restricted to authorised staff bound by confidentiality undertakings.
- Physical safeguards for paper records held on site.
9. Information retention
Data category | Retention period |
Website enquiry records | 24 months, then securely deleted |
Server logs (IP addresses) | 12 months |
Clinical records & radiographs (collected offline) | 6 years after last appointment |
Longer retention may apply where required by law (e.g. SARS).
10. Cross‑border transfers
When we use cloud services hosted outside South Africa (OneDrive, iTero Cloud, WhatsApp Business), transfers occur subject to:
- Contractual safeguards ensuring an adequate level of protection; and
- Provider adherence to recognised security standards (e.g. ISO 27001).
11. Your privacy rights
Under POPIA you may:
- Access the personal information we hold about you (via a PAIA request).
- Object to processing (Form 1).
- Request correction or deletion (Form 2).
- Lodge a complaint with the Information Regulator.
Send completed forms to privacy@hipporthodontics.co.za or post to the address in # 2. We aim to respond within 30 calendar days.
12. Children’s information
We treat patient health data, especially that of minors, as special personal information. Such data is collected only in person at the practice after verified parental consent; it is not requested via the Website.
13. Complaints
If you believe we have infringed your privacy, please contact our Information Officer first. If unresolved, you may complain to:
Information Regulator (South Africa) – Cape Town Office
Salty Sea House, 3 rd Floor, 80 Strand Street, Cape Town 8001
Email complaints.IR@justice.gov.za | Tel +27 10 023 5207
14. Changes to this notice
We may update this notice from time to time. The latest version will always appear on this page with the effective date. Material changes will be signalled via a banner on the Website homepage.
© 2025 HIPP Orthodontics (Pty) Ltd. All rights reserved.