Compliance & data security
NotifyMe is built for South African healthcare. The app is designed around the Protection of Personal Information Act (POPIA), Health Professions Council of South Africa (HPCSA) record-keeping expectations, and modern data security practices. This page summarises how — it is not legal advice, and individual practices remain responsible for their own compliance.
POPIA (South Africa)
POPIA governs how personal information of South African data subjects may be collected, processed and stored. NotifyMe is designed with POPIA's eight conditions in mind:
- Accountability and lawful processing — doctors register an account and accept terms; patients accept an explicit consent checkbox at signup.
- Purpose specification — patient data is used only to deliver messages from the doctor who invited them.
- Minimal collection — we collect name, contact details and the messages the doctor chooses to send.
- Data subject participation — patients can request access, correction or deletion of their personal information at any time.
- Security safeguards — see the security section below.
For full details, see our Privacy Policy.
HPCSA professional standards
Healthcare practitioners using NotifyMe remain bound by HPCSA ethical and professional rules. NotifyMe supports these obligations by:
- Keeping a timestamped, audit-friendly record of messages sent to each patient group.
- Retaining clinical communications in line with long-term record-keeping expectations rather than hard-deleting them on request — deletion requests anonymise the patient's identifying details while preserving the clinical record.
- Making it clear that NotifyMe is a communication tool, not a substitute for clinical consultation or emergency care.
Data security
- Encryption in transit: all traffic between the app and our servers uses HTTPS / TLS.
- Encryption at rest: data is stored in a managed Postgres database with disk-level encryption.
- Row-level access control: database rules ensure a doctor can only access their own patients and groups, and a patient can only access messages sent to groups they belong to.
- Authentication: accounts are protected by email + password; sessions are managed by a vetted authentication provider.
- Hosting: infrastructure is provided by reputable cloud providers with industry-standard physical and operational security.
Data retention
Messages and group history are retained to support continuity of care and professional record-keeping. When a user requests deletion, we anonymise personally identifying information while preserving the underlying clinical record where required by professional standards.
Your rights
You can request access to your data, correction of inaccurate information, or deletion of your account at any time. See our Privacy Policy or contact support@notify-me.net.
Emergencies
NotifyMe is not for medical emergencies. In South Africa, call 10177 (ambulance) or 112 (from a mobile) for emergency care.