-
- Akiva Medical NPS (Registration number: 2021/946061/08) (“Akiva”) is a non-profit organization assisting members of the Jewish community with medical aid coverage. Akiva is not a medical aid, but it refers clients to Cratos Life and Discovery Medical Aid. Akiva provides financial assistance, in conjunction with co-sponsors, to Jewish applicants requiring medical aid.
-
- As part of managing the business and creating value for its various stakeholders, Akiva is required to process personal information. Accordingly, Akiva is obligated to comply with The Protection of Personal Information Act 4 of 2013 (“POPIA”) insofar as it processes personal information, including special personal information, during its ordinary course of business. Under POPIA, Akiva is defined as the Responsible Party for all personal information it processes.
- Akiva takes the protection of Personal Information very seriously. The purpose of this policy is to expand upon our Privacy Policy and Statement and to describe the way in which we facilitate consumer complaints regarding the aforementioned Policy and Statement, as well the conduct of Akiva.
This Policy applies to you, if you are:
-
- A data subject whose Personal Information Akiva has processed in order to assist you in securing medical aid cover
- An Employee or Prospective Employee
- Any data subject who has shared information with Akiva, or who has reasons to believe that Akiva currently holds personal information on you
For further information on our POPIA Policies please request the Privacy Policy, PAIA Policy and Privacy Statement.
Akiva is committed to following best practice, to aligning with the principles of good governance and to adhering to all legislative compliance requirements in all aspects of our business.
Akiva guarantees its commitment to protecting the data subject’s privacy and ensuring their Personal information and Special Personal Information is processed in accordance with all applicable legislation relevant to our industry.
As the Responsible Party, Akiva processes Personal Information in accordance with the requirements of the Protection of Personal Information Act, 2013 (POPIA) as well as the General Data Protection Regulation (EU) 2016/679 (GDPR).
This Policy must be read in conjunction with POPIA and its Regulations, where applicable.
In this notice:
-
- Clause headings are for convenience and reference only and shall not be used in the interpretation thereof
-
- Any gender includes the other genders and a natural person includes a juristic person and vice versa
-
- All the annexures (if any) hereto are incorporated herein and shall have the same force and effect as if they were set out in the body of this notice
-
- The following words and/or expressions shall, unless the context indicates otherwise, bear the meaning assigned to them below and in POPIA
-
-
- Data Subject means the person to whom personal information relates
-
-
-
- Child means a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take any action or decision in respect of any matter concerning himself. A child is afforded special protection under POPIA in relation to the lawful processing of his information
-
-
-
- Competent Person is any person who is legally competent to consent to any action or decision in respect of a Child, i.e. a Child's parent or legal guardian;
-
-
-
- POPIA refers to the Protection of Personal Information Act 4 of 2013;
- GDPR refers to the General Data Protection Regulation (EU) 2016/679
- Responsible Party means a public or private body or any other person which, alone or in conjunction with others determines the purpose of and means for processing personal information. Called Controllers in other jurisdictions (GDPR)
-
-
-
- Operator means a person who is contracted to process personal information on behalf of the responsible party but is not controlled by the Responsible Party. Called Processors in other jurisdictions (GDPR)
-
-
-
- Processing means any operation or activity, whether by automatic means or not, concerning personal information, including:
-
- The collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use of data
- Dissemination by means of transmission, distribution or making available in any other form
- Merging, linking, restriction, degradation, erasure or destruction of information.
-
-
- Record means any recorded information
-
- Regardless of form or medium, including any of the following:
- Writing of any material
- Information produced, recorded or stored by means of any tape-recorder, computer equipment, whether hardware or software or both, or other device, and any material subsequently derived from information so produced, recorded or stored
- Label, marking or other writing that identifies or describes anything of which it forms part, or to which it is attached by any means
- Book, map, plan, graph or drawing
- Photograph, film, negative, tape or other device in which one or more visual images are embodied to be capable, with or without the aid of some other equipment, of being reproduced, in the possession or under the control of a responsible party
- Whether or not it was created by a responsible party and
- Regardless of when it came into existence.
-
-
- Personal Information means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to
-
- Information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, wellbeing, disability, religion, conscience, belief, culture, language and birth of the person.
- Information relating to the education or the medical, financial, criminal or employment history of the person
- Any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other assignment to the person
- The biometric information of the person
- The personal opinions, views or preferences of the person
- Correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence
- The views or opinions of another individual about the person
- The name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person
-
-
- Special Personal Information refers to the personal information concerning the following: the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject.
-
-
-
- De-identify means to delete any information which identifies the data subject; can be used or manipulated by a reasonably foreseeable method to identify the data subject; or can be linked by a reasonably foreseeable method to other information that identifies the data subject.
-
-
-
- Consent is defined as the voluntary, specific and informed expression of will in terms of which permission is granted for the Processing of Personal Information;
-
-
-
- Medical Service Providers (MSP’s) means all Medical Service providers (Doctors, Nurses, Physiotherapists, Radiologists, Surgeons etc…) as well as Private Hospitals and Clinics.
-
-
- Objection to the use of personal information on reasonable grounds relating to his situation
-
- Notification if:
- Information is being collected
- Information is being used for something other than the original purpose for which consent was given
- Information has been accessed or acquired by an unauthorised person
- Notification if:
-
- Establishing whether the responsible party holds information and to request access to said information
- Requesting that information can be corrected, destructed or deleted
- Refusing processing for direct marketing by unsolicited electronic communications
- Lodging a complaint with the Information Regulator
- Instituting civil proceedings against a party who has acted unlawfully in relation to the Data Subjects Personal Information (Sec 99)
-
- Information is processed in order to:
- Partially fund the medical aid premiums of eligible members of the Jewish community
- Facilitate the transaction between the Data Subject/Community Member and Cratos Life and Discovery Health for them to secure Medical Aid cover.
- Information is processed in order to:
-
- The Patient Personal Information:
-
-
- General Personal Information
-
- Name
- ID Number
- Date of Birth and Age
- Gender
- Contact Details (Email; Telephone Number)
- Residential Address
- ID Document
- Dependent Names and ID Numbers
- Rabbi Name and Contact Details
-
-
- Financial Information
- Bank Statements
- Employment Status
- Personal Income
- Family Income
- Previous Medical Aid Memberships and reasons for leaving
- Details of Financial Assistance received from other organizations (the Chevra Kadisha or Yad Aharon)
- Name and Contact Details of Co-Sponsor
- Financial Information
-
-
-
- Full Medical File
-
- Medical Conditions/Comorbidities
- Diagnosis Date(s) and Doctor(s)
- Medications used, past and present
- Allergies
- Hospitalization history
- GP Name and contact details
- Any Specialists Names and contact details
-
- The Medical Service Provider Personal:
-
-
- Name
- Contact Details
- Physical Addresses
- Practice Numbers
-
-
- Co-Sponsor Details
- Name
- Contact Information
- Co-Sponsor Details
-
- All the above Personal Information is processed in order to:
-
-
- Approve the applicant for the subsidy of their Medical Aid Premium
- To complete the required documentation for submission to Cratos Life and Discovery Health
- To comply with all legislative or regulatory requirements related to services provided by us
- To satisfy any requirement by a professional body or network to which we are a member
- To fulfil our moral obligations to funders and donors, to ensure the eligibility of applicants and prevent fraud.
-
-
- Information is stored on DropBox
-
- Information is accessible only to Akiva staff and Operators who have a verifiable need to access the information in order to meet an objective/requirement of either the organization or the data subject.
-
- Any physical sources of data are scanned in and stored electronically, and the original hard copy is, wherever permitted by legislation, destroyed.
-
- Where a hard copy needs to be kept, it is kept in a locked, fireproof filing cabinet to which only limited staff have access.
-
- Data is stored on secure servers owned and managed by compliant operators, with whom Akiva has signed NDA’s, SLA’s and privacy agreements.
-
- All electronic files or data are backed up by the IT Service Provider who is also responsible for system security which protects third party access and physical threats. Please see Information Security Policy for further details.
-
- Information is only processed in so far as it is necessary to fulfil the requirements of the data subject or to meet a need of the Responsible Party
-
- A Security Incident Management Register will be kept to log any security incidents
Our employees will have access to Personal Information to administer and manage our services and internal business processes.
We do not share Personal Information with third parties unless we have a lawful basis for doing so:
-
- Akiva shares Personal Information it has collected from the Medical Service Providers with Cratos Life/Discovery Health in the furtherance of its legitimate interest to assist members in securing medical aid cover.
-
- Akiva will never disclose any of the Personal Information it collects to any other third parties, unless:
- The sharing of the information is essential in order to fulfil a need of the Data Subject, but will only be shared in this instance with express consent of the data subject.
- We have a duty or a right to disclose in terms of legislation, regulations or industry codes
- We believe it is necessary to protect our rights
- It is explicitly requested by the Data Subject;
- Akiva will never disclose any of the Personal Information it collects to any other third parties, unless:
-
- At this stage we do not have the need to share Personal Information outside of South Africa. If ever a legitimate need for cross-border data transfer to arise, it will only be done in very limited circumstances and in strict adherence to all requirements of POPIA and other relevant legislation (Section 72).
-
- Personal Information is kept, in accordance with POPIA, for no longer than the minimum time required for the original processing requirement
- This retention period is determined by Akiva, in accordance with other relevant legislation
- When the retention period is complete, Akiva deletes all information or completely de-identifies it.
- Please see our Record Retention Policy for further information on retention.
-
- If you believe that:
- Your data has been compromised
- Akiva has not acted in accordance with the principles of POPIA
- Akiva has not acted in accordance with our Privacy Policy or Privacy Statement
you are afforded the ability to lodge a complaint directly with Akiva, by:
-
-
- Completing the complaints form attached
- Emailing us directly via popi@akivamedical.co.za
- Requesting a call from our Compliance Department
-
-
- If you are not satisfied with the response from Akiva, it is your right under POPIA to lodge a complaint directly with the Information Regulator
-
- The Information Regulator (South Africa) is an independent body established in terms of Section 39 of the POPIA of 2013. It is, among other things, empowered to monitor and enforce compliance by public and private bodies, and is subject only to the constitution and accountable to the National Assembly.
Information Regulator of South Africa
SALU Building
316 Thabo Sehume Street
Pretoria
Tel: 012 406 4818
Fax: 086 500 3351
Email: inforeg@justice.gov.za