Your health results
Your Employer does not receive your individual health results merely because it sponsors the service.
Your Employer does not receive your individual health results merely because it sponsors the service.
Employer reports are aggregated and appropriately de-identified and are subject to safeguards against re-identification.
PrimaEdge does not sell personal information to third parties.
You retain statutory rights of access, correction, objection and, where applicable, deletion or withdrawal of consent.
This Privacy Notice sets out how Prima Edge Health (Pty) Ltd ("PrimaEdge") collects, uses, stores, discloses and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and other applicable law, and records the principal rights available to data subjects.
This Notice applies principally to "Members" who use PrimaEdge's health and wellness services and app. In this Notice, an "Employer" means an organisation participating in or sponsoring the PrimaEdge service for its employees; "Healthcare Personnel" means authorised healthcare professionals involved in screening, follow-up, monitoring or referral; and a "Service Provider" means an operator or other third party that processes information for or supports PrimaEdge under appropriate controls.
The Notice may also apply, where relevant, to PrimaEdge personnel, Employer administrators and persons who submit enquiries through PrimaEdge's website or other approved channels.
Responsible party: Prima Edge Health (Pty) Ltd, registration number 2026/512082/07, with registered office at 15 Mt Fletcher Street, Midlands, Midstream Estate, Centurion, Gauteng, South Africa.
Depending on the service used and the circumstances, PrimaEdge may process the following categories of personal information:
Personal information may be obtained directly from the person concerned, from an Employer where this is necessary and lawful for the employer-sponsored service, from a healthcare professional involved in the service, or generated through use of the PrimaEdge platform.
PrimaEdge processes personal information only for lawful, specific and legitimate purposes connected with its services. These purposes include:
Some information is necessary for PrimaEdge to register a Member, conduct a requested screening, maintain an accurate health record or provide a particular service. Where information is required for that purpose and is not provided, PrimaEdge may be unable to provide the relevant service or functionality. Information requested for an optional purpose will be identified as optional, and declining to provide it will not prevent access to unrelated services.
PrimaEdge does not treat consent as the only lawful basis for all processing. Personal information is processed only where POPIA and other applicable law permit it, having regard to the particular purpose and activity. Depending on the circumstances, this may include consent, performance of an agreement, compliance with a legal obligation, protection of a legitimate interest, or another lawful ground recognised by POPIA.
Health information is special personal information and receives additional protection. PrimaEdge processes health information only where the additional requirements applicable to special personal information are satisfied. Where PrimaEdge asks a Member to make a separate choice for a particular activity, that choice is dealt with in the POPIA Consent Notice and is kept distinct from acceptance of contractual terms or any clinical informed-consent process.
Access to personal information is restricted according to role, purpose and operational need. An Employer does not become entitled to an individual Member's health results merely because it sponsors or pays for the PrimaEdge service.
Subject to the purpose and applicable law, information may be disclosed or made available as follows:
PrimaEdge does not sell personal information to third parties. Health information is confidential and will be processed and disclosed only in accordance with POPIA, applicable health legislation and other applicable law. PrimaEdge will not disclose an individual Member's health information to an Employer merely because the Employer sponsors or pays for the service. Health information may be disclosed only where the disclosure is authorised by the Member, necessary and lawful for the provision of the relevant health service, or otherwise permitted or required by law.
PrimaEdge has confirmed that its current production hosting is in South Africa through a South African hosting provider. This statement concerns the present hosting arrangement and is not intended as a representation that no Service Provider, support function or future processing activity could ever involve access or processing outside South Africa.
Before implementing any arrangement under which personal information is stored, accessed or otherwise processed outside South Africa, PrimaEdge will assess the proposed processing against POPIA. Where personal information is transferred outside the Republic, PrimaEdge will apply the safeguards required by section 72 of POPIA and any other applicable legal requirements.
PrimaEdge retains personal information only for as long as reasonably necessary for the purpose for which it was collected or subsequently processed, or for a longer period where retention is required or permitted by applicable law, professional record-keeping requirements, an agreement or another lawful basis. Different categories of records may therefore be subject to different retention periods.
PrimaEdge maintains retention requirements appropriate to the different categories of records it processes. Applicable retention periods are determined with regard to the purpose of processing and any statutory, regulatory, professional, contractual or other lawful retention requirement. The specific retention bands PrimaEdge currently applies to health readings (a minimum of 6 years, up to 20 years or longer for certain record types) are set out in the Data Governance Statement rather than restated here.
The current service model is intended to preserve a Member's longitudinal health history after the Member leaves a participating Employer. Leaving an Employer does not, by itself, require deletion of the Member's health record. Any continued retention remains subject to POPIA and other applicable legal requirements.
A request for deletion or destruction will be dealt with in accordance with applicable law. PrimaEdge will not destroy information which it is required or lawfully entitled to retain.
When a Member leaves a participating Employer, the Member's record is separated from that Employer relationship and is no longer treated as part of that Employer's active Member population. The former Employer is not thereby entitled to the Member's individual health information.
PrimaEdge's current service model is intended to allow the Member to retain access to historical health information, subject to applicable legal, technical and service requirements. The detailed rules governing any future association with another participating Employer, or any direct-to-Member continuation service, are dealt with in the applicable Member/App Terms rather than in this Privacy Notice.
PrimaEdge maintains appropriate, reasonable technical and organisational safeguards to protect personal information against loss, damage, unauthorised destruction, unlawful access and other unauthorised processing.
These measures include access controls, authentication, role-based permissions, security logging, backup arrangements and integrity controls to the extent implemented and verified in the live production environment. Further high-level information is contained in PrimaEdge's Data Governance Statement.
Security measures are reviewed in the context of the information processed, the risks presented and the safeguards implemented in the live environment. No information system is represented as incapable of compromise.
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, PrimaEdge will respond to the security compromise and give the notifications required by POPIA.
Subject to POPIA, PAIA and other applicable law, a data subject may:
Members may use ordinary in-app access for information made available through the platform. This does not remove or limit any statutory right of access or correction. Formal record requests are dealt with under PrimaEdge's PAIA Manual. Ordinary Member access to information made available through the app is not treated as a formal PAIA request merely because the information is a record.
Where PrimaEdge seeks a separate Member choice, the POPIA Consent Notice explains the information involved, the purpose, the relevant recipient or category of recipient, whether the choice is optional, and the effect of declining or later withdrawing the choice.
Separate consent may be sought for medical-scheme submissions, Employer reporting where consent is used as an additional privacy safeguard, and research or statistical analysis. Research and statistical processing will be subject to appropriate safeguards and, where reasonably practicable and appropriate to the purpose, will use information that has been de-identified so as to reduce the risk of identifying individual Members.
Where processing is based on consent, consent may be withdrawn for future processing. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal and does not require the destruction of information which may lawfully be retained.
A reminder configured by a Member is treated as a user-selected app function and not, without more, as a separate consent purpose under POPIA.
PrimaEdge may update this Notice when its services, processing activities, service providers, legal obligations or privacy practices materially change. The current version and effective date will be published with the Notice. Where a change materially affects a consent-controlled activity, PrimaEdge will address that change through the appropriate consent process rather than relying only on a general update to this Notice.
This Notice should be read together with PrimaEdge's POPIA Consent Notice, PAIA Manual, Data Governance Statement and the applicable Member/App Terms. Those documents perform different functions and do not replace one another.