| Term | Meaning |
|---|---|
| DIO | Deputy Information Officer, if designated. |
| IO | Information Officer. |
| Member | An individual whose information is processed in connection with PrimaEdge health and wellness services. |
| PAIA | Promotion of Access to Information Act 2 of 2000, as amended. |
| POPIA | Protection of Personal Information Act 4 of 2013. |
| PrimaEdge | Prima Edge Health (Pty) Ltd, registration number 2026/512082/07. |
| Regulator | Information Regulator (South Africa). |
This Manual is prepared for PrimaEdge as a private body in terms of section 51 of PAIA. It assists a person to identify records held by PrimaEdge, understand which records may be available without a formal request, understand how to request access to other records, and understand relevant aspects of PrimaEdge's processing of personal information for purposes of PAIA and POPIA.
This Manual must be read, where relevant, with PrimaEdge's Privacy Notice, POPIA Consent Notice, Member/App Terms of Service, Employer Services / Commercial Terms and Data Governance Statement.
The inclusion of a record category does not mean that every record in that category exists in every case or that access will automatically be granted. Access remains subject to PAIA, POPIA, confidentiality obligations, health-information protections, legal privilege and any applicable ground of refusal.
| Particular | Details |
|---|---|
| Registered name | Prima Edge Health (Pty) Ltd |
| Registration number | 2026/512082/07 |
| Registered office | 15 Mt Fletcher Street, Midlands, Midstream Estate, Centurion, Gauteng, South Africa |
| Postal address | TO CONFIRM |
| Website | primaedge.co.za |
| General email | TO CONFIRM |
| Telephone | TO CONFIRM |
A DIO should be listed only if one has actually been designated. The applicable Information Officer / Head of Private Body must be registered with the Information Regulator before taking up POPIA Information Officer duties.
| Role | Details |
|---|---|
| Information Officer / Head of Private Body |
Name: Ms Lebogang Matlala Designation: Nurse Email: information@primaedge.co.za Telephone: +27 63 856 4669 Regulator registration confirmed: TO CONFIRM |
| Deputy Information Officer (if designated) |
Name: TO CONFIRM Email: TO CONFIRM Telephone: TO CONFIRM |
| PAIA / privacy request channel |
Email: TO CONFIRM Telephone: TO CONFIRM |
Records deliberately made public by PrimaEdge may generally be accessed without a formal PAIA request, subject to the manner in which they are published or otherwise made available.
| Category | Examples / manner of access |
|---|---|
| Public legal and privacy documents | PAIA Manual; Privacy Notice; POPIA Consent Notice; Member/App Terms of Service; Data Governance Statement, where published on PrimaEdge's website or otherwise made publicly available. |
| Public company and service information | Website information about PrimaEdge, its services, public contact particulars and public-facing service information. |
| Member self-service information | To the extent implemented in the live app, a Member may directly access the Member's own results, history, consent choices or other information made available through the Member account without needing to use PAIA merely to view that functionality. |
| Employer self-service reporting | To the extent implemented in the live service, an authorised Employer user may directly access the aggregated and appropriately de-identified reporting made available for that Employer. This does not create access to individual Member health information. |
| Public communications | Notices, announcements and other material intentionally published by PrimaEdge. |
Direct application or account access does not convert confidential or personal records into public records and does not create access rights for another person.
PrimaEdge may hold records required by legislation applicable to its business and activities. The applicability of a statute to a particular record depends on the activity and record concerned.
| Legislation | Examples of records, where applicable |
|---|---|
| Companies Act 71 of 2008 | Corporate and statutory company records. |
| Promotion of Access to Information Act 2 of 2000 | This Manual and PAIA request, decision and administration records. |
| Protection of Personal Information Act 4 of 2013 | Privacy, data-subject request and information-governance records. |
| National Health Act 61 of 2003 and other applicable health legislation | Health, clinical and confidentiality-related records to the extent applicable to PrimaEdge services and health professionals. |
| Employment and labour legislation | Employment, workforce and statutory personnel records to the extent applicable. |
| Income Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011 | Tax, accounting and supporting financial records to the extent applicable. |
| Electronic Communications and Transactions Act 25 of 2002 | Electronic transaction and communication records to the extent applicable. |
This list is not intended to state that every listed statute applies to every PrimaEdge activity or record, nor is it exhaustive of legislation that may apply from time to time.
| Subject | Categories of records that may be held |
|---|---|
| Members and health/wellness services | Registration and profile information; identity and contact information; Employer/programme and medical-scheme affiliation; health history; biometric readings; screening and wellness information; applicable mental-health screening scores; risk assessments; referrals and follow-up records; Member-entered information; consent and withdrawal records; account/authentication records; service communications. |
| Employer-sponsored programmes | Employer agreements and Service Schedules; implementation records; eligibility/affiliation information actually supplied to PrimaEdge; aggregated and appropriately de-identified reports; programme administration records; invoices and commercial correspondence. Employer sponsorship does not create a right to individual Member health information. |
| Medical-scheme submissions | Individual-level submission records and related correspondence where the applicable Member choice or another lawful basis permits processing or disclosure. |
| Consent and choice records | The relevant consent purpose, grant or decline where recorded, timestamp, applicable notice version, and withdrawal/change history. |
| Access and security records | Logins, high-risk case access, exports generated or downloaded, consent changes and other system/security logs to the extent captured by the live system. |
| Research, statistics and trend analysis | Appropriately de-identified research, statistical, trend and population-level outputs and related governance records where permitted. |
| Website and prospective clients | Website enquiries, screening/service enquiries, contact information, proposals and related correspondence. |
| Corporate, finance and tax | Company, governance, accounting, invoice, payment, banking, tax and supporting records. |
| Personnel and contractors | Employment/contract records, remuneration, leave, qualifications, training, performance and disciplinary records where applicable. |
| Suppliers, operators and advisers | Contracts, due diligence, operator/data-processing terms, invoices, confidentiality/security arrangements and professional-service records. |
| Legal and compliance | Contracts, legal correspondence, complaints, litigation, PAIA/POPIA requests, policies, assessments, incident records, retention records and governance registers. |
| Technology, security and intellectual property | Access-control records, system/security records, backup/recovery records, technical documentation, audit records, software-related records, confidential know-how and proprietary material. Security-sensitive records may be restricted where disclosure would create a legal or security risk. |
11.1 PrimaEdge processes personal information for purposes connected with its health and wellness services and business operations. These may include Member registration and account administration; health screening, early risk identification, health management and referral; Member-selected functionality; programme administration; medical-scheme submissions where lawfully authorised; aggregated and appropriately de-identified Employer reporting; research, statistical analysis, trend analysis and population-level health insights where permitted; communications and support; security and fraud prevention; contractual administration; legal/regulatory compliance; corporate administration; finance; personnel administration; and supplier/operator management.
| Data subjects | Information that may be processed |
|---|---|
| Members | Identity/contact information; Employer/programme and medical-scheme affiliation; health/wellness information; health history; screening results and measurements; Member-entered information; consent choices; account/authentication and service-use information; communications. |
| Participating Employer contacts/users | Identity/business contact details; role/authorisation information; contractual/programme administration information; system access information where applicable. |
| Prospective clients / website enquirers | Name, company, contact details, enquiry information and related communications. |
| Personnel and contractors | Identity/contact information; employment/contract information; qualifications; remuneration/payment information; training, performance and other workforce records where applicable. |
| Suppliers, operators and professional advisers | Identity/business information; contact details; contracts; payment information; due-diligence, confidentiality, security and service information. |
| Directors and corporate representatives | Identity, contact, statutory, governance and corporate records as required or appropriate. |
Depending on the processing activity and applicable law, information may be supplied to authorised PrimaEdge personnel and health professionals; the relevant Member; operators and service providers; medical schemes or authorised recipients where the applicable Member choice or another lawful basis permits; professional advisers; regulators, courts or public authorities where legally required; and participating Employers only to the extent permitted by the service model, Member choices and law.
Participating Employers are not, merely by sponsoring or procuring PrimaEdge services, entitled to individual Member health results. Employer reporting is intended to be aggregated and appropriately de-identified and subject to the additional safeguards described in the related PrimaEdge documents.
PrimaEdge's current operating model is that the production database containing Member information is hosted in South Africa. Routine storage of, or access to, personal information from outside South Africa: none identified at present, consistent with the confirmation already recorded in PrimaEdge's Privacy Notice, Section 6 TO CONFIRM against third-party providers. Any applicable transborder information flow will be handled in accordance with applicable law.
PrimaEdge applies technical and organisational safeguards appropriate to its operating model and risk profile. The Data Governance Statement describes the current governance and technical controls in greater detail.
This Manual forms part of PrimaEdge's broader privacy and information-governance framework and should be read, where relevant, with the Privacy Notice, POPIA Consent Notice, Member/App Terms of Service, Employer Services / Commercial Terms and Data Governance Statement.