POPIA Privacy Policy

Version: 1.1
Effective Date: 16 September 2026

1. INTRODUCTION

Submitt Medical Accounts (Pty) Ltd (registration number 2013/008088/07) (“Submitt”, “we”, “us” or “our”) operates Submitt.App, a software and billing-administration application used by medical practitioners, medical practices and medical billing bureaux.

This Privacy Policy explains how Submitt collects, receives, uses, stores, processes, discloses and protects Personal Information in connection with Submitt.App and related services (“Services”).

This Privacy Policy must be read together with the Submitt.App Terms and Conditions of Use (“Terms”). Words and expressions defined in the Terms bear the same meanings in this Privacy Policy unless the context indicates otherwise.

Submitt is not a healthcare provider and does not provide medical, clinical or other healthcare services. Submitt does not establish a professional relationship with patients who are the subject of information processed through the Application.

2. APPLICABLE DATA PROTECTION LAW

2.1. Submitt recognises the importance of protecting Personal Information and is committed to processing Personal Information in accordance with applicable data protection and privacy laws, including the Protection of Personal Information Act 4 of 2013 (“POPIA”).

2.2. The Customer acknowledges that, where the Customer uses the Application to collect, capture, upload, store or otherwise process Patient Information, the Customer remains responsible for ensuring that such processing complies with POPIA and any other applicable data protection or privacy requirements.

2.3. To the extent that Submitt processes Patient Information on behalf of the Customer in providing the Services, Submitt processes such information as an operator on behalf of the Customer and in accordance with the Customer’s lawful instructions, these Terms and applicable law.

2.4. Nothing in this Privacy Policy relieves the Customer of its obligations as the responsible party in respect of Patient Information for which the Customer determines the purpose and means of processing. Similarly, nothing in this Privacy Policy limits any obligation imposed directly on Submitt by applicable law in respect of Personal Information processed by Submitt.

2.5. Where Submitt processes Personal Information for its own legitimate business or legal purposes, including the administration of Customer Accounts, subscriptions, communications, security, fraud prevention and compliance with legal obligations, Submitt will process such information in accordance with its obligations as the party responsible for that processing under applicable law.

3. PERSONAL INFORMATION PROCESSED THROUGH SUBMITT.APP

3.1. Depending on how the Application is used by the Customer and its Authorised Users, Submitt may process the following categories of Personal Information:

3.1.1. identification information, including names, surnames and identification numbers;

3.1.2. contact information, including telephone numbers, email addresses and other contact details;

3.1.3. medical aid information, including the name of a medical aid or medical scheme and the relevant membership or beneficiary number;

3.1.4. patient information, including information contained in hospital stickers, medical documentation and other information submitted in connection with a patient;

3.1.5. health and medical information, including information relating to healthcare services provided to a patient and information contained in or associated with medical claims;

3.1.6. billing and claims information, including claim details, billing information, ICD-10 codes, macro codes, dates and claim references;

3.1.7. images and documents, including images of hospital or medical aid documentation uploaded through the Application;

3.1.8. Account and User information, including information relating to the Customer, Authorised Users and their use of the Application;

3.1.9. authentication and security information, including login credentials and information required to maintain the security of Accounts; and

3.1.10. technical and usage information, including information relating to the operation, access and use of the Application and Services.

3.2. The Personal Information processed through the Application may include special personal information as contemplated by POPIA, including information concerning a person’s health or sex life, where such information forms part of Patient Information or is otherwise submitted to or processed through the Application.

3.3. The Customer acknowledges that the categories of Personal Information processed through the Application will depend on the Customer’s use of the Services and the information submitted by the Customer or its Authorised Users.

3.4. Submitt does not require the Customer to submit Personal Information which is not reasonably necessary for the Customer’s use of the relevant functionality of the Application. The Customer remains responsible for ensuring that information submitted to the Application is adequate, relevant and not excessive in relation to the purpose for which it is processed.

4. HOW INFORMATION IS COLLECTED

4.1. Submitt may collect or receive Personal Information in connection with the provision and use of the Services through the following means:

4.1.1. directly from the Customer, including information provided when registering an Account, subscribing to the Services, communicating with Submitt or otherwise engaging with Submitt;

4.1.2. from Authorised Users, including information entered into the Application in the course of using the Services;

4.1.3. through images and documents uploaded to the Application, including images of hospital stickers, medical aid documentation and other documents containing Patient Information;

4.1.4. through information manually entered into the Application, including patient, medical aid, billing and claims-related information;

4.1.5. through the operation and use of the Application, including information generated or recorded through the Customer’s and Authorised Users’ use of the Services;

4.1.6. through third-party integrations and services, where information is transmitted to or received from systems or service providers connected to the Application; and

4.1.7. through communications with Submitt, including correspondence relating to Accounts, support requests, technical issues, billing or the Services.

4.2. In the ordinary operation of the Services, Submitt does not generally collect Patient Information directly from patients. Patient Information is ordinarily provided to Submitt by or on behalf of the relevant Customer or its Authorised Users through their use of the Application.

4.3. Where information is submitted by a Customer or Authorised User on behalf of a patient or other data subject, the Customer is responsible for ensuring that the information has been lawfully collected and that Submitt is authorised to process the information for the purposes for which it is submitted.

4.4. The Application may also automatically collect certain technical and usage information when the Application is accessed or used, including information reasonably necessary for authentication, security, troubleshooting, system administration and the provision and improvement of the Services.

5. PURPOSES OF PROCESSING

5.1. Submitt may process Personal Information for purposes reasonably necessary for the provision, operation, administration, security and support of the Application and the Services, including:

5.1.1. creating, administering and maintaining Customer and User Accounts;

5.1.2. providing access to and operating the Application and its functionality;

5.1.3. capturing, storing and processing Patient Information and other Customer Data submitted through the Application;

5.1.4. facilitating the preparation, administration and management of medical claims;

5.1.5. processing images and information submitted through the Application, including using Amazon Textract to assist with the extraction of specified information from uploaded images;

5.1.6. facilitating the verification, coding and administrative processing of claims-related information;

5.1.7. transmitting claims and claims-related information to the Customer’s nominated medical billing bureau or other authorised recipient;

5.1.8. facilitating integrations with third-party systems and services, including GoodX where applicable;

5.1.9. providing technical support, troubleshooting and assistance to Customers and Authorised Users;

5.1.10. maintaining, securing, monitoring and protecting the Application, Accounts and information processed through the Services;

5.1.11. performing backups, recovery and other business continuity functions;

5.1.12. administering subscriptions, billing and payments;

5.1.13. communicating with Customers and Authorised Users regarding the Services, including service-related notices and support communications;

5.1.14. detecting, preventing and addressing fraud, misuse, security incidents and unauthorised access;

5.1.15. complying with applicable legal, regulatory or professional requirements and responding to lawful requests from competent authorities; and

5.1.16. managing and administering Submitt’s business and contractual relationship with the Customer to the extent reasonably necessary for the provision of the Services.

5.2. Where Submitt processes Patient Information on behalf of a Customer, such processing will be undertaken in accordance with the Customer’s lawful instructions and for purposes reasonably necessary to provide the Services.

5.3. Submitt will not process Patient Information for purposes unrelated to the provision of the Services or the Customer’s lawful instructions, except where such processing is permitted or required by applicable law.

5.4. The Customer remains responsible for ensuring that the purposes for which it collects and submits Patient Information to Submitt are lawful, specific and explicitly defined and that the information processed through the Application is adequate, relevant and not excessive for those purposes.

6. LEGAL BASIS AND CUSTOMER RESPONSIBILITY

6.1. The Customer is responsible for ensuring that it has a lawful basis for the collection and processing of Personal Information submitted to or processed through the Application and that such processing complies with POPIA and any other applicable data protection legislation.

6.2. Where the Customer processes Patient Information through the Application, the Customer remains responsible for determining the purpose and means of such processing and for ensuring that the processing is lawful and justified in terms of POPIA.

6.3. The Customer must ensure that, where required by applicable law, it has obtained the necessary consent or other lawful authority from the relevant data subject before submitting Personal Information to Submitt for processing.

6.4. The Customer is responsible for ensuring that data subjects are provided with any notices or information required under POPIA in connection with the collection and processing of their Personal Information, including information regarding the use of Submitt.App and any relevant third-party service providers.

6.5. Where Submitt processes Patient Information on behalf of the Customer, Submitt does so as an operator in accordance with the Customer’s lawful instructions and for the purposes described in this Privacy Policy and the Terms.

6.6. The Customer acknowledges that Submitt does not determine the purposes for which the Customer collects or uses Patient Information and does not assume the Customer’s responsibilities as the responsible party merely by providing the Application or processing Patient Information on the Customer’s behalf.

6.7. Where Submitt processes Personal Information for its own purposes, including the administration of Customer Accounts, subscriptions, communications, security, fraud prevention and compliance with legal obligations, Submitt will process such information in accordance with its own obligations under applicable law.

7. AI-ASSISTED PROCESSING

7.1. The Application uses Amazon Textract, an artificial intelligence and machine-learning service provided by Amazon Web Services (“AWS”), to assist with the extraction of specified information from images uploaded through the Application.

7.2. The information extracted through Amazon Textract may include information appearing on a patient’s hospital or medical aid documentation, including:

7.2.1. the name of the relevant medical aid or medical scheme;

7.2.2. the medical aid membership or beneficiary number; and

7.2.3. the patient’s identification number.

7.3. The Customer acknowledges that the use of automated information extraction is intended to facilitate the administrative processing of Patient Information and does not constitute a medical, clinical or professional determination.

7.4. Information extracted through Amazon Textract may be inaccurate, incomplete or incorrectly interpreted. The Customer and its Authorised Users remain responsible for reviewing and verifying the extracted information before it is relied upon for purposes of coding, billing, claim preparation or claim submission.

7.5. Submitt does not warrant that information extracted through Amazon Textract will be accurate, complete or error-free and does not assume responsibility for any error or omission resulting from the automated extraction of information.

7.6. The Customer acknowledges that information submitted through the Application may be processed by Amazon Textract and AWS in connection with providing this functionality. Further information regarding such processing, including the applicable AWS AI-services opt-out arrangement, is set out in this Privacy Policy.

7.7. The use of Amazon Textract does not transfer responsibility for the processing of Patient Information from the Customer to Submitt. Where Submitt processes Patient Information on behalf of the Customer, Submitt continues to act as an operator in accordance with the Customer’s lawful instructions and applicable law.

7.8. Where information is not correctly extracted from an uploaded document, including where the document follows a layout not previously encountered, the document may be reviewed by Submitt personnel in order to identify and correct the error and to adjust the manner in which the Application processes documents of that type.

7.9. Any such review is carried out only by those personnel who require access for that purpose, each of whom is bound by a written undertaking of confidentiality in respect of Patient Information, and is undertaken by Submitt as operator in accordance with the Customer’s authorisation under the Terms.

7.10. Submitt does not use Patient Information to train any artificial intelligence or machine-learning model. Development and testing of the extraction functionality by or for Submitt is carried out using specimen data which does not relate to identifiable patients. The arrangements applicable to AWS’s use of content processed through Amazon Textract are set out in clause 9.

8. AWS AND THIRD-PARTY PROCESSORS

8.1. Submitt uses third-party service providers, technology providers and infrastructure providers in connection with the provision, operation, security and support of the Application and Services. These providers may process Personal Information to the extent reasonably necessary to perform the services for which they are engaged.

8.2. Such third-party providers include Amazon Web Services (“AWS”), including Amazon Textract, which is used to assist with the extraction of specified information from images uploaded through the Application.

8.3. The Application may also utilise other third-party systems and service providers, including:

8.3.1. Teamgeek, Submitt’s development service provider, which develops, operates and maintains the Application and administers the environment in which it is hosted;

8.3.2. GoodX, and any medical billing bureau nominated by the Customer, in respect of claims and claims-related information;

8.3.3. Stripe, in respect of the processing of subscription payments;

8.3.4. Sentry, in respect of error and diagnostic reporting relating to the operation of the Application;

8.3.5. AWS Amplify, in respect of usage analytics relating to the Application; and

8.3.6. Expo, in respect of the distribution of updates to the Application.

Submitt may also engage other providers required to facilitate particular functionality, integrations, hosting, support, security or other aspects of the Services.

8.4. Submitt will only permit third-party service providers to process Personal Information to the extent reasonably necessary for the relevant service or functionality and will take reasonable steps to ensure that such providers are subject to appropriate obligations concerning the confidentiality and protection of Personal Information.

8.5. Where a third-party service provider processes Personal Information on Submitt’s behalf, Submitt remains responsible for managing that processing in accordance with its obligations under applicable law and the arrangements governing the Services.

8.6. The Customer acknowledges that the use of third-party service providers may result in Personal Information being processed outside the Republic of South Africa. Further information regarding cross-border processing, including the AWS environment used in connection with the Services, is set out in this Privacy Policy.

8.7. Where Personal Information is transmitted to a third party at the Customer’s instruction, including a medical billing bureau or other recipient selected by the Customer, that party may process the information independently of Submitt and in accordance with its own legal and contractual obligations.

8.8. Submitt may change, replace or appoint additional third-party service providers where reasonably necessary to provide, maintain, secure or improve the Services, subject to applicable data protection requirements.

8.9. In addition to the third-party service providers referred to above, Submitt uses Google Cloud Platform, specifically Google Cloud Run, hosted in the africa-south1 region, in connection with certain application-hosting and data-processing infrastructure used to provide the Services.

8.10. The Application processes data received from authorised requests and does not intentionally persist or permanently store such data within the application container or the Google Cloud Run environment referred to in clause 8.9. That environment is used primarily for processing and transmitting data between authorised systems. Any data temporarily held in application memory during processing is not intended to constitute permanent data storage.

9. AWS AI-SERVICES OPT-OUT

9.1. Submitt uses AWS AI services, including Amazon Textract, in connection with the provision of certain functionality through the Application.

9.2. The AWS AI Services Opt-Out Policy has been applied at the root level of the AWS organisation within which the Submitt environment is hosted. That organisation is held and administered by Teamgeek, Submitt’s development service provider, and hosts the environments of other clients of that provider in addition to Submitt. The opt-out accordingly applies at the level of that organisation, and not at the level of an AWS account held or controlled by Submitt.

9.3. The applicable AWS opt-out configuration is intended to prevent content processed through the relevant AWS AI services from being used by AWS for the purposes of service improvement, to the extent covered by the applicable AWS AI Services Opt-Out Policy.

9.4. Under the AWS AI services opt-out policy, and as described in the AWS documentation applicable to that policy, content previously stored by an AWS AI service for the purpose of improving that service is deleted when the opt-out is applied. Content which is required to provide the relevant AWS service functions is not affected by the opt-out and may continue to be retained by AWS for that purpose.

9.5. Accordingly, the AWS AI-services opt-out does not mean that Personal Information processed through Amazon Textract or other AWS services is immediately deleted or is not retained at all. Information required to provide the relevant services may continue to be processed or retained for that purpose.

9.6. Submitt does not use the AWS AI-services functionality for the purpose of permitting AWS to use Customer Data or Patient Information for service-improvement purposes beyond the applicable AWS opt-out arrangement.

9.7. The Customer acknowledges that the processing of information through AWS and Amazon Textract remains subject to the applicable AWS service arrangements and that the use of the AWS AI-services opt-out does not affect the processing required for AWS to provide the relevant services to Submitt.

10. CROSS-BORDER PROCESSING

10.1. The Customer acknowledges that, in providing the Application and Services, Personal Information may be processed and/or stored outside the Republic of South Africa through third-party service providers and cloud-based infrastructure used by Submitt.

10.2. In particular, the Customer acknowledges that Submitt utilises Amazon Web Services (“AWS”), including AWS infrastructure in the European Union (eu-west-1), in connection with the provision of the Services. Personal Information submitted to the Application may therefore be transferred to, stored in or processed within that environment.

10.3. Where Personal Information is transferred outside the Republic of South Africa, Submitt will take reasonable steps to ensure that the transfer and subsequent processing are undertaken in accordance with the requirements of POPIA, including section 72, which governs the transfer of Personal Information to a third party in a foreign country.

10.4. The Customer acknowledges that cross-border processing may be necessary for Submitt to provide and maintain the Services, including hosting, storage, security, technical support and the AI-assisted functionality provided through Amazon Textract.

10.5. The Customer acknowledges and authorises such cross-border processing to the extent reasonably necessary for the provision of the Services and subject to the safeguards and arrangements described in this Privacy Policy.

10.6. Further information concerning Submitt’s use of AWS, Amazon Textract and other third-party service providers, including the applicable AWS AI-services opt-out arrangement, is set out elsewhere in this Privacy Policy.

11. MEDICAL BUREAUX AND OTHER RECIPIENTS

11.1. The Customer may use the Application to facilitate the preparation and transmission of medical claims and claims-related information to a medical billing bureau or other recipient selected or authorised by the Customer.

11.2. Where the Customer instructs Submitt to transmit Patient Information or other Personal Information to a medical billing bureau or other recipient, the Customer is responsible for ensuring that it is lawfully entitled to disclose the relevant information to that recipient and that the disclosure is consistent with the purpose for which the information was collected.

11.3. The Customer acknowledges that Submitt does not determine which medical billing bureau or other recipient the Customer uses and does not assume responsibility for the subsequent processing of Personal Information by such recipient.

11.4. Once Personal Information has been transmitted to a medical billing bureau or other recipient at the Customer’s instruction, the recipient may process such information independently of Submitt and in accordance with its own legal, regulatory and contractual obligations and applicable privacy policies.

11.5. The Customer remains responsible for ensuring that its nominated medical billing bureau or other recipient is appropriately authorised to receive and process the relevant Patient Information and that any necessary contractual or other arrangements required by applicable law are in place.

11.6. Submitt may facilitate the transmission of claims and claims-related information to the Customer’s nominated medical billing bureau through functionality made available in the Application. Submitt does not guarantee the availability, receipt, processing, acceptance or payment of any claim by a medical billing bureau, medical scheme or other recipient.

11.7. Submitt will process and transmit Personal Information to a medical billing bureau or other recipient only to the extent reasonably necessary to provide the Services and in accordance with the Customer’s instructions, these Terms and applicable law.

12. GOODX AND OTHER INTEGRATIONS

12.1. The Application may integrate with or facilitate communication with third-party software, platforms, applications, APIs and other systems, including GoodX, to enable the exchange or processing of information required for the provision of the Services.

12.2. Where the GoodX integration is enabled, information processed through the Application may be transmitted to GoodX or received from GoodX for purposes reasonably necessary to facilitate the relevant billing or claims-related functionality.

12.3. The Customer acknowledges that the operation of an integration may depend upon the availability, functionality and compatibility of the relevant third-party system, API or service. Submitt does not control such third-party systems and cannot guarantee their uninterrupted availability or continued compatibility with the Application.

12.4. Submitt will not be responsible for any loss, delay, error, interruption or unavailability arising from a failure, modification, suspension or discontinuation of a third-party system, API or integration, to the extent that such event is outside Submitt’s reasonable control.

12.5. The Customer remains responsible for ensuring that it is authorised to use any third-party system integrated with the Application and for complying with any terms, conditions or requirements applicable to its use of that third-party system.

12.6. Where Personal Information is exchanged with a third-party system through an integration, such processing will be undertaken in accordance with the Customer’s instructions and applicable data protection requirements. The Customer acknowledges that the relevant third party may process such Personal Information in accordance with its own legal, contractual and privacy obligations.

12.7. Submitt may modify, suspend, replace or discontinue an integration where reasonably necessary due to changes in the relevant third-party system, API, security requirements, technical requirements or availability of the third-party service.

13. SECURITY

13.1. Submitt recognises the importance of protecting Personal Information and Customer Data and will implement and maintain reasonable technical and organisational measures appropriate to the nature of the information processed through the Application.

13.2. Such measures are intended to protect Personal Information and Customer Data against:

13.2.1. loss, damage or destruction;

13.2.2. unauthorised access;

13.2.3. unauthorised alteration or disclosure;

13.2.4. unlawful processing; and

13.2.5. other reasonably foreseeable risks to the confidentiality, integrity and availability of the information.

13.3. Submitt may employ appropriate access controls, authentication measures, system monitoring, cloud infrastructure security, backup and recovery measures and other technical and organisational safeguards in connection with the Application.

13.4. Access to Personal Information and Customer Data within Submitt’s environment will be restricted to persons and service providers who require such access for purposes reasonably necessary to provide, maintain, secure and support the Services, subject to appropriate confidentiality and security obligations.

13.5. The Customer acknowledges that no electronic system, internet connection or method of transmitting or storing information can be guaranteed to be completely secure. Submitt therefore does not warrant that the Application or any information transmitted through or stored in the Application will be immune from every possible security threat.

13.6. The Customer remains responsible for implementing appropriate security measures within its own environment, including in respect of:

13.6.1. devices and networks used to access the Application;

13.6.2. login credentials and Account access;

13.6.3. Authorised Users and their access rights; and

13.6.4. the secure handling of information downloaded or otherwise obtained from the Application.

13.7. The Customer must notify Submitt without undue delay if it becomes aware of any actual or suspected unauthorised access to its Account, compromise of login credentials, or security incident affecting Personal Information or Customer Data processed through the Application.

13.8. Where Submitt becomes aware of a security compromise affecting Personal Information processed on behalf of a Customer, Submitt will take reasonable steps to investigate and address the incident and will notify the relevant Customer as required by applicable law.

13.9. Where a security incident involves a third-party service provider, Submitt will, where reasonably practicable and appropriate, cooperate with the relevant provider and Customer in addressing the incident and mitigating its potential impact.

14. RETENTION OF PERSONAL INFORMATION

14.1. Submitt will retain Personal Information only for as long as reasonably necessary for the purposes for which it is processed, including for the provision and administration of the Services, the fulfilment of Submitt’s contractual obligations, the maintenance of appropriate backups and security measures, and compliance with applicable legal, regulatory or professional requirements.

14.2. Where Personal Information is processed on behalf of a Customer, the applicable retention period will be determined having regard to the Customer’s lawful instructions and the retention requirements applicable to the Customer.

14.3. Customer Data, including uploaded documents, is retained for the duration of the Customer’s Account, on the standing instruction of the Customer. Submitt does not apply an automatic deletion period to Personal Information held on an active Account, and the Application does not provide a retention-selection function.

14.4. Personal Information is deleted on the written request of the Customer, or following termination of the Account on expiry of the wind-down period referred to in clause 14.7. Submitt’s own internal processing artefacts, including system logs and temporary files, are retained only for a short operational period and are then deleted in the ordinary course.

14.5. The Customer remains responsible for determining the retention period applicable to Patient Information processed on its behalf and for ensuring that such information is not retained for longer than is permitted or required by applicable law.

14.6. Suspension of a Customer’s Account does not, by itself, result in the deletion of Personal Information. Personal Information associated with a suspended Account will remain subject to the applicable retention arrangements.

14.7. Upon termination of an Account, Submitt may retain Personal Information for a wind-down period of 30 (thirty) days to enable the Customer to request an export of its Customer Data. Following expiry of the wind-down period, the Personal Information may be deleted in accordance with Submitt’s deletion procedures.

14.8. Personal Information may remain temporarily available in backup or disaster-recovery systems following deletion from the active Application. Such backup copies will be subject to Submitt’s applicable backup lifecycle and will be permanently deleted in accordance with those procedures.

14.9. Nothing in this Privacy Policy requires Submitt to delete Personal Information where retention is required by law, a court or competent regulatory authority, or is otherwise permitted by applicable law.

14.10. Once Personal Information falls to be deleted in accordance with clause 14.4, Submitt will take reasonable steps to securely delete, destroy or anonymise it, subject to any information retained in accordance with clause 14.9.

15. DELETION

15.1. Subject to the Customer’s right to request an export of Customer Data in accordance with the Terms, Submitt will delete Personal Information processed through the Application on the written request of the Customer, or following termination of the Account, unless retention is required or permitted by applicable law.

15.2. Following termination of a Customer’s Account, Submitt may retain Personal Information for the applicable wind-down period to allow the Customer a reasonable opportunity to request an export of its Customer Data. Once the applicable wind-down and retention periods have expired, the Personal Information may be securely deleted in accordance with Submitt’s deletion procedures.

15.3. Deletion from the active Application may not result in the immediate deletion of all copies of the relevant Personal Information. Personal Information may temporarily remain in backup or disaster-recovery systems maintained for security, recovery and business-continuity purposes.

15.4. Where Personal Information remains in backup or disaster-recovery systems following deletion from the active Application, such information will remain subject to applicable security and confidentiality measures and will be permanently deleted in accordance with Submitt’s applicable backup lifecycle.

15.5. Submitt will not be required to delete Personal Information to the extent that retention is required by law, a court or competent regulatory authority, or is otherwise permitted by applicable law.

15.6. Where Personal Information is retained pursuant to clause 15.5, Submitt will continue to protect the information in accordance with applicable confidentiality, security and data protection requirements and will delete or anonymise it when the applicable retention requirement no longer applies.

15.7. The Customer remains responsible for ensuring that any Personal Information exported to it is retained, used and ultimately deleted or destroyed in accordance with its own obligations under POPIA and any other applicable law.

Users may also request deletion of their Submitt account and associated personal data at any time by following the steps in the Delete Account page.

16. CUSTOMER DATA EXPORT

16.1. Upon termination or cancellation of the Customer’s Account, the Customer may request an export of its Customer Data from Submitt during the applicable wind-down period.

16.2. The Customer Data export will comprise, subject to the format and functionality made available by Submitt:

16.2.1. a folder containing the Customer’s uploaded images; and

16.2.2. a single spreadsheet containing the Customer’s claims, including patient details as captured, applicable codes, dates and claim references.

16.3. The Customer Data export will not include Submitt’s internal system information, including AI processing data, system logs, internal metadata or other proprietary technical information belonging to Submitt.

16.4. The Customer acknowledges that the Customer Data export is a manually triggered service and is not available through a self-service export function. The Customer must submit a request to Submitt for the preparation of the export.

16.5. The preparation and provision of a Customer Data export is a chargeable service. Submitt may invoice the Customer for the applicable export fee before preparing or releasing the export.

16.6. The Customer remains responsible for ensuring that any Customer Data exported to it is thereafter securely stored, used and retained in accordance with its obligations under POPIA and any other applicable law.

16.7. Following expiry of the applicable wind-down period, and subject to the applicable retention period and any legal obligation requiring continued retention, Submitt may delete the Customer Data in accordance with its data retention and deletion procedures.

17. DATA SUBJECT RIGHTS

17.1. Submitt recognises that data subjects have rights in respect of their Personal Information in terms of POPIA and other applicable data protection legislation. Subject to applicable law, a data subject may have the right to:

17.1.1. request confirmation as to whether Submitt or a Customer is processing Personal Information relating to the data subject;

17.1.2. request access to Personal Information held about the data subject;

17.1.3. request the correction, updating or deletion of Personal Information which is inaccurate, incomplete, misleading or unlawfully processed;

17.1.4. object to the processing of Personal Information in circumstances permitted by applicable law;

17.1.5. object to the processing of Personal Information for purposes of direct marketing, where applicable;

17.1.6. request the restriction or cessation of processing where permitted by applicable law; and

17.1.7. exercise any other rights available to the data subject in terms of POPIA or other applicable data protection legislation.

17.2. Where Submitt processes Patient Information on behalf of a Customer, the Customer remains responsible for responding to requests from data subjects concerning the processing of such information, as the responsible party determining the purposes and means of that processing.

17.3. A data subject who wishes to exercise a right in respect of Patient Information processed through the Application should ordinarily direct the request to the relevant medical practice, medical practitioner or other Customer responsible for the processing.

17.4. Where Submitt receives a request relating to Patient Information which it processes on behalf of a Customer, Submitt may refer the request to the relevant Customer and will, where reasonably necessary and legally permissible, provide reasonable assistance to the Customer in responding to the request.

17.5. Where Submitt processes Personal Information for its own purposes, including in relation to Customer Accounts, subscriptions, communications, security or compliance with legal obligations, a data subject may exercise the applicable rights directly with Submitt using the contact details set out in this Privacy Policy.

17.6. A data subject may be required to provide sufficient information to enable Submitt or the relevant Customer to verify the data subject’s identity and locate the relevant Personal Information.

17.7. Nothing in this Privacy Policy limits any right available to a data subject under POPIA or prevents a data subject from lodging a complaint with the Information Regulator where the data subject believes that their Personal Information has been processed in contravention of applicable law.

18. SECURITY INCIDENTS AND DATA BREACHES

18.1. Submitt will take reasonable steps to prevent, detect, investigate and respond to any actual or suspected security incident involving Personal Information or Customer Data processed through the Application.

18.2. For purposes of this Privacy Policy, a “Security Incident” means any actual or reasonably suspected unauthorised access to, acquisition, disclosure, loss, alteration, destruction or other compromise of Personal Information or Customer Data held or processed by Submitt.

18.3. Where Submitt becomes aware of a Security Incident affecting Personal Information processed on behalf of a Customer, Submitt will, without undue delay, notify the relevant Customer of the incident to the extent required by applicable law.

18.4. To the extent reasonably available and appropriate, Submitt’s notification will include information concerning:

18.4.1. the nature of the Security Incident;

18.4.2. the categories of Personal Information potentially affected;

18.4.3. the measures taken or proposed by Submitt to address and contain the Security Incident; and

18.4.4. any reasonable steps which the Customer may take to mitigate potential adverse consequences.

18.5. Submitt will take reasonable steps to investigate and contain a Security Incident and, where appropriate, implement measures intended to prevent or reduce the likelihood of a recurrence.

18.6. Where a Security Incident involves a third-party service provider used by Submitt, Submitt will, where reasonably practicable, cooperate with the relevant provider in investigating and addressing the incident.

18.7. The Customer remains responsible for fulfilling its own obligations under POPIA in relation to any Security Incident, including any obligation to notify the Information Regulator or affected data subjects where required by applicable law.

18.8. The Customer must notify Submitt without undue delay if it becomes aware of any actual or suspected unauthorised access to the Application or compromise of Personal Information or Customer Data arising from the Customer’s Account, Authorised Users, devices or systems.

18.9. The parties will reasonably cooperate with one another in investigating and mitigating the effects of a Security Incident, subject to applicable confidentiality, legal and security requirements.

19. CONFIDENTIALITY

19.1. Submitt will treat Personal Information, Customer Data and other confidential information received from or processed on behalf of the Customer as confidential and will not disclose such information except as permitted by these Terms, this Privacy Policy or applicable law.

19.2. Submitt may disclose or make confidential information available to its employees, contractors, professional advisers and third-party service providers who require access to such information for purposes reasonably necessary to provide, maintain, secure or support the Services, provided that such persons are subject to appropriate confidentiality obligations.

19.3. Submitt may disclose confidential information where such disclosure is:

19.3.1. required by applicable law, regulation, court order or a competent authority;

19.3.2. necessary to protect the rights, property or security of Submitt, the Customer, another user or any third party;

19.3.3. made with the Customer’s lawful instruction or authorisation; or

19.3.4. otherwise permitted in terms of these Terms or applicable law.

19.4. Submitt will not use Customer Data or confidential information for any purpose unrelated to the provision of the Services, except where such use is authorised by the Customer or permitted or required by applicable law.

19.5. The Customer is responsible for ensuring that its employees, Authorised Users, contractors and other persons who have access to Personal Information or confidential Customer Data are subject to appropriate confidentiality obligations.

19.6. The confidentiality obligations contained in this Privacy Policy will continue to apply for so long as the relevant information remains confidential or is protected under applicable data protection or other applicable law, notwithstanding the termination or cancellation of the Customer’s Account or the Services.

19.7. Nothing in this clause prevents Submitt from using information which is lawfully available to the public, independently developed without reference to the Customer’s confidential information, or required to be disclosed by law, provided that such disclosure is limited to what is legally required.

20. CHILDREN’S INFORMATION

The Customer must ensure that the processing of Personal Information relating to children through the Application complies with the additional requirements applicable to children’s Personal Information under POPIA.

The Customer remains responsible for ensuring that any required consent or other lawful basis for such processing has been obtained.

21. CHANGES TO THIS PRIVACY POLICY

Submitt may amend this Privacy Policy from time to time to reflect changes in the Services, applicable law, technology, processing arrangements or Submitt’s business practices.

Where a material change is made, Submitt may notify Customers through the Application, by email or through another appropriate communication channel.

The updated version will apply from the effective date specified in the revised Privacy Policy.

22. RESPONSIBLE PARTY / INFORMATION OFFICER

For information relating to Submitt’s own processing of Personal Information, or where required by applicable law, Submitt’s details are:

Submitt Medical Accounts (Pty) Ltd
Registration Number: 2013/008088/07
Address: Mooikloof Office Park, West Block, Block 7, Cnr Atterbury Road and Jollify Main Road, Mooikloof, Pretoria, 0081.
Email: info@submitt.app
Telephone: 012-3441370

Information Officer: Joaquim Junior Henrique Martins
Email: info@submitt.app

Where Patient Information is processed by Submitt on behalf of a Customer, the relevant Customer remains the responsible party and should be contacted in relation to requests concerning the Customer’s processing of Patient Information.

23. COMPLAINTS

A data subject who believes that their Personal Information has been processed unlawfully may contact Submitt using the details above.

A data subject may also lodge a complaint with the Information Regulator of South Africa in accordance with applicable law.

The data subject’s attention is further drawn to Submitt’s PAIA Manual, which sets out the procedure for requesting access to records held by Submitt.

24. GOVERNING LAW

This Privacy Policy is governed by the laws of the Republic of South Africa.