Privacy Policy
Flexi E-Health Systems Privacy Policy
Introduction
Flexi-e Health System is committed to protecting the privacy and confidentiality of personal data processed through our healthcare management software solutions. This Privacy Policy outlines how we collect, use, store, share, and protect your personal data in accordance with Zimbabwe’s Cyber and Data Protection Act (CDPA).
Scope of the Policy
This Policy applies to all personal data processed by Flexi-e Health System as a data processor on behalf of healthcare centres and providers (data controllers) using our system for patient registration, treatment documentation, consultations, billing, bookings, and claims management.
Categories of Personal Data Processed
- Identifying information: Name, national ID, phone number, email address, and other contact details.
- Demographic information: Gender, age, address.
- Medical and health records: Treatment history, test results, diagnoses, medications, and any other health-related data.
- Billing and claims data: Insurance, invoices, payment history.
- Appointment and consultation data
Purpose of Processing
- Facilitating patient registration and health record management
- Supporting healthcare service delivery and documentation
- Scheduling appointments and diagnostic tests
- Managing billing, invoicing, and medical aid claims
- Enhancing system performance and data accuracy
- Complying with applicable legal and regulatory obligations
Legal Basis for Processing
Personal data is processed on behalf of healthcare providers based on one or more of the following legal bases:
- Consent of the data subject (especially for sensitive data)
- Contractual necessity for healthcare provision
- Legal obligation of the healthcare provider
- Public interest in healthcare and disease prevention
Processing of Sensitive Personal Data
Health data, as a special category of personal data, is processed under strict safeguards and only:
- With the express written consent of the data subject
- Where necessary for medical diagnosis, treatment, or management
- When required for public health interests or legal claims
Data Subject Rights
Data subjects have the following rights under the CDPA:
- Right to access their personal data
- Right to rectify incorrect or incomplete data
- Right to erase data (where legally applicable)
- Right to object to processing
- Right to withdraw consent at any time
Requests may be submitted through the respective healthcare provider. As a data processor, we will support data controllers in fulfilling these rights.
Data Sharing and Disclosure
We do not share personal data with third parties except:
- As instructed by the healthcare provider
- With authorized medical aid societies and laboratories
- When required by law or court order
Cross-Border Data Transfers
Where data is transferred outside Zimbabwe, we ensure:
- Adequate protection is provided in the recipient country
- Compliance with notification requirements to POTRAZ
10. Data Security Measures
We implement appropriate technical and organisational measures including:
- Access controls: limiting access to authorized personnel.
- Data encryption: Protecting data in transit and at rest.
- Regular audits: Monitoring and updating our security practices
- Audit trails and activity logging.
Data Retention
We retain personal data only as long as instructed by the data controller and in compliance with applicable regulations.
Data Breach Notification
In the event of a personal data breach, we will:
- Notify the controller immediately
- Support the controller in notifying POTRAZ within 24 hours
- Assist in communicating with affected individuals where required
Accountability and Record-Keeping
We maintain up-to-date records of all data processing activities and cooperate with audits and inspections by the data controller or regulator.
Contact Information
For inquiries related to this policy, please contact:
Data Protection Officer
Flexi-e Health System
No 7, San Fernando, 132 Five Ave, Cnr 5th Street, Harare
Email: msithole@flexiehealthsystems.com
Phone: +263778791092, +2638688002612
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in legal, regulatory, or operational requirements. Updates will be communicated to our clients and published appropriately.
Review and Approval
This Privacy Policy shall be reviewed annually or upon significant changes in applicable laws or in the way Flexi-e Health System processes personal data. Approval of this policy is the responsibility of the senior management team and the appointed Data Protection Officer.
This policy is aligned with Zimbabwe’s Cyber and Data Protection Act (CDPA) and Cloud Data Protection Regulations (CDPR). For further information or guidance, contact the Data Protection Officer.