Legal

Privacy Policy

Last updated: 12 July 2026

This policy is issued by Sweet Phoenix Creations (Pty) Ltd, a company registered in the Republic of South Africa ("Sweet Phoenix", "Company", "we", "us", "our"), trading as Symptone Care. It is drafted with reference to the Protection of Personal Information Act 4 of 2013 ("POPIA") and, where relevant to users outside South Africa, general principles reflected in the EU General Data Protection Regulation ("GDPR"). It does not constitute legal advice, and nothing in it overrides the rights you have under mandatory law.

1. Who we are and how this policy applies

Symptone Care is a care facility management platform operated by Sweet Phoenix Creations (Pty) Ltd. It is used by care facility operators ("Facilities", "you", when referring to a customer) to manage residents, staff, and clinical records, and by caregivers employed or engaged by a Facility.

Under POPIA, in relation to resident (patient) data entered into the platform, the Facility is the "responsible party" (it decides what resident data is collected and why), and Sweet Phoenix acts as an "operator"— we process that data only on the Facility's instructions, to provide the platform. In relation to a Facility's own account and billing data, Sweet Phoenix is the responsible party.

Each Facility is responsible for ensuring it has a lawful basis (consent, contract, legitimate interest, or another basis recognised under POPIA and any other applicable law) for entering resident and staff information into the platform, and for meeting any duty it has to inform residents, families, or staff about how their information is processed.

2. Information we process

Depending on how the platform is used, we process:

  • Facility account data: facility name, registration/company code, contact email, phone, and address.
  • Staff (caregiver) data: names, roles, login credentials (usernames and salted PIN/password hashes — never stored in plain text), and shift/attendance history.
  • Resident data entered by a Facility, which may include special personal information under POPIA section 26 (health information): name, date of birth, contact and emergency contact details, medical history, medication schedules, vitals, care logs, and incident reports.
  • Billing data: processed through our payment processor, Paystack. We do not collect or store full card numbers ourselves.
  • Technical/usage data: device and browser type, sync status, and audit-trail metadata (who made a change and when), needed to keep the offline-first app reliable and accountable.

3. Special personal information (health data)

Resident health information processed through the platform falls within POPIA's definition of special personal information. Processing of this category of information is carried out on the Facility's instructions and for purposes connected to the resident's care, consistent with the exemptions in POPIA section 27 for processing carried out by, or for, bodies providing care or treatment (including for administering care, treatment, and health services). It remains each Facility's responsibility to ensure it holds an appropriate basis (such as consent, or a legal or contractual duty of care) to process a resident's health information on the platform.

4. Why we process information

  • To provide the core service: patient records, task and medication tracking, rostering, inventory, and reporting.
  • To operate billing on a per-active-patient basis, verify payments, and prevent fraud or abuse.
  • To alert facility managers to overdue care tasks, delays, or low stock via email.
  • To maintain an audit trail of who created, changed, or deleted clinical records, for accountability and dispute resolution.
  • To comply with our own legal, regulatory, tax, and accounting obligations.

5. Facility data isolation

Every Facility's data — residents, staff, schedules, records — is strictly isolated from every other Facility on the platform. This is enforced at the database level, not only in the interface: no Facility, however many are on the platform, can query or view another Facility's data. Facility administrators can see all data belonging to their own Facility; caregivers see what their role requires to do their job.

6. Cross-border storage and processing

The platform is hosted using cloud infrastructure providers that may store or process data outside South Africa. Where personal information is transferred across borders, we rely on the fact that our infrastructure providers maintain data protection standards at least equivalent to those required by POPIA section 72 (including contractual and technical safeguards), and we take reasonable steps to ensure information remains protected wherever it is processed.

7. Retention

Clinical and operational records are retained for as long as a Facility's account remains active, plus a reasonable period afterward to meet applicable health-record, financial, and legal recordkeeping obligations. Information is retained only for as long as necessary for the purposes it was collected, consistent with POPIA's retention limitation principle. A Facility may request deletion of its account and associated data, subject to any legal retention requirements that apply to health and financial records.

8. Who we share information with

We do not sell Facility or resident data, and we do not share data between Facilities under any circumstances. Information is shared only with third parties reasonably necessary to operate the platform, each engaged under terms requiring them to protect the information they process on our behalf:

  • Our database and hosting infrastructure providers.
  • Our payment processor, Paystack, for billing and subscription payments.
  • Professional advisors (e.g. auditors, legal counsel) where necessary, and regulators or authorities where required by law.

9. Your rights

Subject to POPIA and other applicable law, you (or, for resident data, the Facility acting as responsible party on a resident's behalf) have the right to:

  • Request confirmation of, and access to, the personal information we hold;
  • Request correction, updating, or deletion of inaccurate, irrelevant, excessive, or unlawfully obtained information;
  • Object to processing of personal information in certain circumstances;
  • Withdraw consent, where processing is based on consent, without affecting processing carried out before withdrawal;
  • Lodge a complaint with the Information Regulator (South Africa) if you believe your information has been processed unlawfully.

Facility administrators can access, correct, or export their Facility's records at any time from within the app. Residents, staff, or their representatives who wish to exercise these rights over information held about them should in the first instance contact their care Facility directly, as the Facility is the responsible party for its own resident and staff records; we will assist the Facility in fulfilling such requests as its operator.

10. Security safeguards

Consistent with POPIA section 19, we implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, interference, and destruction, including:

  • Authenticated access only — facility login for administrators, and a facility code plus username and PIN for caregivers.
  • Automatic account lockout after repeated failed login attempts.
  • Passwords and PINs stored as salted cryptographic hashes, never in plain text.
  • Database-level access controls enforcing per-Facility isolation, independent of the application interface.
  • Card and payment details processed entirely by our PCI-compliant payment processor and never stored on our own servers.

No system can be guaranteed completely secure. In the event of a security compromise affecting personal information, we will notify affected Facilities and the Information Regulator without undue delay, as required by POPIA section 22.

11. Automated decision-making

The platform does not make decisions about residents, staff, or care outcomes based solely on automated processing that would produce legal or similarly significant effects. Alerts (e.g. overdue-task or low-stock notifications) are informational only and require human review and action.

12. Changes to this policy

We may update this policy as the platform or applicable law evolves. Material changes will be reflected here with an updated date. Continued use of the platform after a change constitutes acceptance of the updated policy, to the extent permitted by law.

13. Contact us / Information Officer

Questions about this policy, or requests relating to your personal information, can be directed to our Information Officer at info@sweetphoenix.co.za, or via our main site at sweetphoenix.co.za. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa (inforeg.org.za).