Legal
Privacy Policy
Last updated September 2026
This Privacy Policy explains how Reya Health collects, uses, protects and shares your personal information - including your health information - when you use our telehealth medical weight-loss service. We’ve written it in plain language, as the Protection of Personal Information Act 4 of 2013 (POPIA) and the National Health Act 61 of 2003 require.
Who we are
Reya Health is a business unit of OpsMed (Pty) Ltd (registration number 2026/473691/07), a private company incorporated in the Republic of South Africa. For the purposes of POPIA, OpsMed (Pty) Ltd is the “responsible party” - meaning we decide why and how your personal information is used and protected. When we say “we”, “us” or “Reya Health”, we mean OpsMed (Pty) Ltd and the healthcare professionals and staff who provide care through this practice.
We have appointed an Information Officer who oversees privacy questions and requests. You can reach them at:
Information Officer: Dr Rani John Elenjical
Email: privacy@opsmed.ai
Address: 7 Meadow Close, Southdowns Estate, Highveld, 0157
If you deal with us mainly over WhatsApp, you can ask Reya or our team for the Information Officer’s details at any time and we’ll share them in writing.
What information we collect
The information we collect depends on how you interact with us, but it usually includes:
- Personal details - your name, ID or passport number, date of birth, gender, and contact details.
- Health and medical information - your weight and body-mass index, medical history, medications, allergies, relevant lifestyle factors, test results, diagnoses, treatment plans, and consultation notes. POPIA calls this special personal information because it is especially sensitive.
- Your interactions with us - messages, voice notes, photos or documents you share on WhatsApp, information you give our digital assistant, and notes from your video or telephone consultations. These form part of your medical record.
- Payment information - handled through our secure payment processors - and records of payments you make.
- Technical and usage information - when you use our website, such as device type, IP address, browser type and pages visited, as explained under Cookies below.
Where necessary and lawful, we may also receive information about you from third parties such as your pharmacy or laboratory. We treat it with the same care as information you give us directly.
Why we’re allowed to use it
We only use your information when the law allows. In most cases we process it because it is necessary to provide you with medical care and because you have asked us to by using our service.
We process your health information because it is necessary for your proper treatment and care, because health professionals are legally and ethically required to keep proper records, and because you have given your explicit consent. When you sign up, we ask you to read this policy and to consent to our use of your health information for the purposes described here. You may withdraw consent at any time, though this may limit our ability to keep treating you or to meet our legal duties.
We also process some information because the law requires it - for example, keeping medical records and prescriptions for set periods, or keeping financial records for tax. We never use your health information for purposes incompatible with your care, and we do not sell your personal information.
What we use it for
We use your personal and health information to:
- assess whether our medical weight-loss treatment is safe and appropriate for you, and identify any risks or contraindications;
- provide medical advice, diagnoses, treatment plans and prescriptions, run your consultations and monitor your progress;
- coordinate your care - for example sending a prescription to your chosen pharmacy or arranging tests;
- keep accurate medical records, as the law and professional guidelines require;
- run the practice - appointments, communication, payments, fraud prevention, and service quality and security;
- comply with our legal, regulatory and professional obligations and cooperate with bodies such as the Information Regulator or the HPCSA where required.
We may also use de-identified or aggregated information (which does not identify you) to improve and audit our service. If we ever need to use your information for a new, incompatible purpose, we’ll explain it and, where required, ask your permission first.
Who we share it with
We treat your information as confidential and only share it when it’s necessary for your care, required by law, or otherwise permitted under POPIA and the National Health Act - and only what is reasonably necessary.
Within Reya Health, your information is shared among the doctors, clinical and authorised administrative staff involved in your care, all bound by confidentiality. Outside the practice, we may share it with pharmacies that dispense your medication, laboratories, other healthcare providers involved in your treatment, payment processors, and the technology providers who host our systems - each bound by law or contract to keep it confidential and to use it only as we specify.
In limited cases the law may require us to share information - for example under a court order, to assist a criminal investigation, or to protect public health. We limit any such disclosure to what is necessary and, where lawful and practical, tell you about it. We do not share your information for third-party marketing, and we do not sell it.
WhatsApp, cloud services and cross-border transfers
Because we use modern communication and cloud technology, some of your information may be stored or processed outside South Africa. We host on cloud providers with strong protections (including South African data centres, such as in the Cape Town region) that are contractually bound to protect your information in a way substantially similar to POPIA. In some cases a provider may back up or process data in another country.
When information is transferred across borders, we only do so as POPIA allows - where the recipient is subject to laws or agreements providing adequate protection, where you have consented, or where the transfer is necessary for your care.
When you contact us via WhatsApp, you use a service provided by Meta Platforms, which has its own privacy terms. WhatsApp encrypts messages end-to-end, but certain information (such as your phone number and device data) may be processed by WhatsApp on servers outside South Africa. By choosing to message us on WhatsApp you accept this. If you’d rather not use WhatsApp, tell us and we’ll offer another way to communicate.
How long we keep it
We keep your information only as long as needed for the purposes it was collected - unless the law or professional guidelines require us to keep it longer. As a healthcare provider, we must keep your medical records for a minimum period even after you stop using our service. In general we keep adult health records for at least six years after your last consultation, following HPCSA guidance; records for children and certain other records may need to be kept longer.
When we no longer need your information and aren’t required to keep it, we securely delete or de-identify it. If you ask us to delete your information, we’ll explain what we can delete and what we’re required to retain, and act on your request as far as the law allows.
How we protect it
We use technical, physical and organisational measures to protect your information against loss, damage and unauthorised access - including secure systems and data centres, access restricted to authorised staff, strong access controls, encryption in transit and at rest where appropriate, security monitoring, staff training, and incident-response procedures. Our third-party providers are contractually required to protect your information and to notify us of incidents.
No system can be guaranteed completely secure, and the safety of messages you send also depends on your own devices. Please use strong passwords, keep your devices and apps updated, and tell us immediately if you suspect someone else has accessed your account or your messages with us. If a breach may affect your information, we’ll act as POPIA requires - which may include reporting it to the Information Regulator and notifying you.
Our digital assistant and automated processing
We use an AI-powered digital assistant (Reya) to help gather information from you, guide you through questionnaires, and provide general information and support. Reya may ask about your health, lifestyle and goals and give automated responses based on what you share.
Reya does not replace your doctor and does not make final decisions about your diagnosis, your suitability for treatment, or your prescriptions. Those decisions are always made by a registered doctor who reviews your information and applies their clinical judgement. We may use automated processing to support human decisions - for example tracking your progress or flagging potential risks - but not to replace them. If we ever make a decision about you based solely on automated processing that significantly affects you, we’ll ensure POPIA permits it and that you can ask a person to review it, give your view, and contest it.
When you ask to book an appointment, the messages you send are read by an AI service provided by Anthropic so that Reya can understand what you need, find you a doctor and offer you times. Anthropic processes those messages on our instructions as our operator. It keeps them for up to 30 days so that it can check for misuse of its service, then deletes them, and it does not use them to train its models. It does not make clinical decisions and does not decide who may treat you. If you would rather not have your messages processed this way, reply 4 at any time and a member of our team will book for you instead.
When an appointment is confirmed, we add it to your doctor’s own work calendar so they know to expect you. That entry shows your first name and the type of appointment- for example “follow-up” - and nothing about your health. Your doctor’s calendar is provided by Google or Microsoft and is subject to their terms and to your doctor’s own settings, which may mean other staff at their practice can see that entry.
If you are a doctor registering with us
Everything above is about patients. This section is about you. When you register to practise with Reya Health we collect your name, HPCSA registration number and category, qualification, email address, WhatsApp number and, if you have one, your practice number. We ask you to upload your HPCSA certificate or practising card, your ID or passport, your professional indemnity cover and proof of your bank account, and we collect the bank account details themselves so that we can pay you. We use all of it to confirm that you are registered and entitled to practise, to open your account, and to pay you.
Your documents are read by the same AI service provided by Anthropicdescribed above. It pulls the details off each document and compares them against what you typed, so that a mistyped registration number or account number is caught before it reaches your record. It only ever suggests. A person at the practice checks your registration against the HPCSA register themselves and decides whether to approve you, and no account is ever opened or declined by software. Anthropic keeps what it is sent for up to 30 days, as above, and does not use it to train its models.
Before your details are used we show them back to you - including the bank account your earnings will be paid into - and ask you to confirm they are correct. If we later correct or complete anything, we ask you to confirm again. Your documents are stored in private, encrypted storage in the European Union, are never publicly accessible, and are opened only by the person reviewing your registration, through a link that expires within minutes. Your bank account number is encrypted.
We do not keep your documents indefinitely. Your ID or passport is deleted 30 days after a decision, because it has done its job once we have confirmed you are the person on the register. Your HPCSA certificate, indemnity cover and proof of bank account are kept for six years after your account closes, which matches the period a claim can still arrive in. If you start an application and never submit it, we delete it after 30 days. If we decline your application, we keep it for 90 days so that you can appeal or resubmit, and then delete it.
Signing in uses a code sent to your WhatsApp number and an authenticator app, and we keep a record of when you signed in and what administrative actions were taken on your account. If you connect a work calendar so that patients can book you, we read when you are busy and write only to the separate Reya Health calendar we create in it; the connect screen explains that in full before you agree to it. You may also be asked to approve or refuse a request from our team to read what a patient wrote. Your rights over your own information are the same as everyone else’s, and are set out below.
Cookies and website analytics
When you visit our website we may collect some information automatically using cookies and similar technologies. Some cookies are necessary to make the site work; others help us understand how the site is used so we can improve it, sometimes via third-party analytics tools that don’t directly identify you.
You can control or delete cookies through your browser settings. Blocking some cookies may affect how parts of the site work. We do not use cookies to track you across other websites or to serve advertising based on your health information. If we introduce new tracking technologies, we’ll update this policy and, where required, ask for your consent.
Your rights
POPIA gives you important rights over your personal information. You can:
- ask whether we hold information about you and request access to it;
- ask us to correct or update information that is inaccurate or out of date;
- in certain circumstances, ask us to delete information or stop processing it, or object to processing;
- object at any time to the use of your information for direct marketing.
Sometimes we may not be able to give access or delete information immediately - for example where it would affect another person’s privacy, or where the law requires us to keep medical records for a minimum period. If so, we’ll explain our reasons as far as the law allows. To exercise any right, contact our Information Officer. We may ask for proof of identity, and may charge a reasonable, disclosed fee for copies where the law permits.
Complaints
If you have a concern about how we handle your information, please contact our Information Officer first - we’d like the chance to put it right. If you’re not satisfied, you have the right to complain to the Information Regulator, which oversees POPIA compliance in South Africa:
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: enquiries@inforegulator.org.za / POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za
Please verify the Information Regulator’s current contact details on their website before publishing, as these can change.