Privacy Policy

How we collect, use, and protect personal and clinical data.

Version: 1.0
Effective Date: 9 August 2026
Issued by: Respocare (Pty) Ltd


1. Introduction

Respocare (Pty) Ltd ("Respocare", "we", "our", or "us") is committed to protecting the privacy and security of personal information processed through the Respocare Connect AI platform.

This Privacy Policy explains:

  • what personal information we collect
  • how it is used
  • how it is protected
  • what rights users and patients have regarding their information

Respocare Connect AI is designed for use by licensed healthcare professionals and clinics.

2. Legal Framework

Respocare processes personal information in accordance with applicable data protection laws including:

  • POPIA — Protection of Personal Information Act (South Africa)
  • internationally recognised healthcare privacy principles

Where international users access the platform, additional privacy standards may apply.

3. Roles in Data Processing

Within the Respocare Connect AI platform:

Clinics / Healthcare Providers act as the Data Controllers.

This means they determine:

  • what patient data is collected
  • how it is used for clinical care

Respocare (Pty) Ltd acts as the Data Processor.

Respocare processes personal information only to operate the platform.

Respocare does not own patient data.

4. Information We Process

The platform may process the following categories of information.

4.1 Patient Information

Patient data uploaded by clinicians may include:

  • name
  • patient identifiers
  • date of birth
  • clinical reports
  • diagnostic results
  • consultation notes

This information is provided by clinicians using the platform.

4.2 Clinical Documentation

Respocare Connect AI may process clinical information including:

  • uploaded medical documents
  • AI-generated draft clinical notes
  • clinical summaries created by clinicians
  • transcriptions of voice dictation

These outputs are always reviewed by clinicians before use.

4.3 Platform Usage Data

The platform may collect operational metadata such as:

  • login activity
  • timestamps
  • system usage statistics
  • security audit logs

This information is used to maintain platform security and performance.

5. Purpose of Processing

Personal information is processed solely to operate the platform and support clinical workflows.

This includes:

  • storing clinical records
  • assisting clinicians with documentation
  • retrieving relevant patient information
  • maintaining system security and performance

Respocare does not use patient data for marketing or advertising purposes.

6. Artificial Intelligence and Third-Party Data Processing

6.1 AI Services Used

Respocare Connect AI uses the following third-party artificial intelligence services to power clinical features:

OpenAI, Inc. (San Francisco, USA)

  • OpenAI Whisper — transcribes audio recordings of clinical consultations into text
  • OpenAI GPT-4o — generates structured clinical notes, summaries, and clinical reasoning from patient context and transcriptions
  • OpenAI text-embedding-3-small — creates document embeddings for semantic search and retrieval within patient records

Anthropic, PBC (San Francisco, USA)

  • Anthropic Claude — used for non-clinical support features only. No patient health information (PHI) is transmitted to Anthropic services.

6.2 What Data Is Sent to Third-Party AI Services

When you use AI-powered features, the following data may be transmitted to OpenAI:

  • Audio recordings of clinical consultations
  • Transcribed consultation text
  • Patient clinical context including relevant medical history, documents, and records needed for accurate note generation
  • Clinical queries and prompts entered by the clinician

6.3 Data Protection Agreements

Respocare maintains a Zero Data Retention (ZDR) agreement with OpenAI. Under this agreement:

  • Patient data is not stored by OpenAI after processing
  • Patient data is not used to train, improve, or fine-tune any AI models
  • Data is processed solely to fulfil the clinical request and is discarded immediately after

6.4 Data Minimisation

Only the minimum data required for each AI operation is transmitted. Respocare does not send entire patient records — only clinically relevant context needed for the specific request.

6.5 In-App Consent

On mobile devices, users are shown a one-time AI data processing disclosure after their first sign-in and must explicitly consent before accessing the clinical workspace. The disclosure identifies OpenAI as the AI processor and links back to this Privacy Policy for review.

6.6 Clinical Oversight

AI features are designed only to assist clinicians. AI does not diagnose, prescribe, or replace clinical judgement. All AI-generated outputs must be reviewed and approved by the clinician before use.

6.7 Third-Party Subprocessors

The following third-party services process data on behalf of Respocare:

  • OpenAI Whisper — audio transcription — audio recordings
  • OpenAI GPT-4o — clinical note generation — clinical text
  • OpenAI Embeddings — semantic document search — document content
  • Supabase (AWS) — database and authentication — all platform data
  • Vercel — web frontend hosting — no PHI
  • Railway — backend API hosting — API requests

7. Data Security

Respocare implements appropriate technical and organisational security measures including:

  • encryption of data in transit
  • encryption of stored data
  • secure authentication systems
  • restricted system access
  • audit logging

These controls are designed to protect patient data against unauthorised access or disclosure.

8. Data Access Controls

Access to clinical data is strictly controlled.

Only authorised users may access the data required for their role.

The platform ensures:

  • clinicians access only their authorised patients
  • clinics cannot access other clinics' data
  • system access is authenticated and logged

9. Data Sharing

Respocare does not sell or share patient data for commercial purposes.

Personal information may only be shared:

  • where required to operate the platform
  • where required by law
  • where authorised by the clinic controlling the data

10. Data Retention

Personal information is retained only for as long as necessary to operate the platform and comply with legal obligations.

Clinics remain responsible for determining appropriate retention periods for patient records.

11. Rights of Data Subjects

Patients may have rights under applicable data protection laws including:

  • the right to access their personal information
  • the right to request correction of inaccurate information
  • the right to request deletion where legally permitted

Requests relating to patient data should be directed to the clinic providing care.

12. International Data Processing

Where infrastructure used to operate the platform involves international services, Respocare ensures that appropriate safeguards are in place to protect personal information.

13. Updates to this Policy

Respocare may update this Privacy Policy periodically.

Material updates will be communicated through:

  • the platform
  • email notifications
  • updated policy notices

14. Contact Information

For privacy-related inquiries:

Respocare (Pty) Ltd
Johannesburg, South Africa

Email: privacy@respocare.co.za