Privacy Policy
Hart Aesthetics • Effective: • Version: 1.0
This notice explains how we process personal information in line with South Africa’s Protection of Personal Information Act, 4 of 2013 (“POPIA”).
1) Who we are & contact details
Responsible Party: Hart Aesthetics (Pty) Ltd (Reg. No. INSERT COMPANY REG NO) operating multiple branches in South Africa.
Information Officer: INSERT NAME • privacy@hartaesthetics.co.za • Tel: INSERT NUMBER.
You may also contact the Information Regulator (South Africa) via inforegulator.org.za.
2) What information we collect
- Identity & contact data: names, ID/passport (where required by law or for medical records), contact details.
- Medical & treatment data: medical history, allergies, contraindications, clinical photographs, consent forms, treatment notes and outcomes.
- Commercial data: bookings, invoices, payment confirmations (we do not store full card numbers).
- Communications: emails, messages, feedback, and complaints.
- Device & usage data: website analytics, cookies, approximate location, IP address.
- Marketing preferences: opt-in/opt-out records for SMS/email/WhatsApp.
We will only collect sensitive information (such as health data) where necessary for care, with your consent, or as otherwise allowed by POPIA.
3) Why we process your information (POPIA justification grounds)
- Consent: obtaining and documenting informed consent for treatments, photos, and marketing.
- Contract: to make, confirm, and deliver bookings and services you request.
- Legal obligation: record-keeping, tax/VAT, health-professional guidelines, and safety reporting.
- Legitimate interests: to run and protect our business, prevent fraud, train staff, improve services, and handle complaints—balanced against your rights.
4) Cookies & analytics
We use essential cookies for site functionality, and (with consent where applicable) analytics/marketing cookies to understand usage and improve our services. You can manage preferences in your browser and via our cookie banner (where implemented).
5) Sharing your information
- Operators (processors): booking/clinic software, payment gateways, SMS/email providers, secure cloud hosting, and analytics providers.
- Medical professionals: our clinicians involved in your care.
- Legal/regulatory: where required by law or to protect vital interests.
We require operators to safeguard your information and process it only on our instructions.
6) Cross-border transfers
Some providers store data in other countries. Where this occurs, we implement safeguards permitted under POPIA (e.g., contractual clauses, comparable protection in the destination country, or your consent).
7) Retention
- Medical records: retained for at least 6 years from the last consultation, and for minors, at least 6 years after turning 18 (or longer if required by applicable professional rules/law).
- Financial records: typically retained for 5 years to meet legal/tax requirements.
- When no longer required, information is securely destroyed or de-identified.
8) Your rights
You have the right (subject to lawful limitations) to:
- request access to your personal information and a copy of records;
- request correction or deletion where appropriate;
- object to processing (including direct marketing) or request restriction;
- withdraw consent (without affecting prior lawful processing);
- lodge a complaint with the Information Regulator.
How to exercise your rights
Email: privacy@hartaesthetics.co.za • Please include proof of identity and a clear description of your request. We will respond within a reasonable period as required by POPIA.
9) Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including access controls, staff confidentiality obligations, encryption where practical, and secure disposal. No method is 100% secure; we will notify you and regulators of material data breaches as required by law.
10) Children
We process minors’ information only with the consent of a competent person (parent or legal guardian) and as necessary for clinical care and record-keeping.
11) Marketing
We only send direct marketing where lawful. You can opt out at any time using the unsubscribe link/SMS instructions or by contacting us.
12) PAIA
If applicable, you may request our PAIA Manual for details on accessing records under the Promotion of Access to Information Act, 2 of 2000.
13) Changes to this notice
We may update this Privacy Policy from time to time. The latest version will be posted on our website with the effective date above.
14) Contact us
Email: privacy@hartaesthetics.co.za • Tel: INSERT NUMBER • Postal: INSERT ADDRESS