Privacy Policy

Last updated: 20 April 2026

1. Who we are

Risk Navigator is a healthcare environmental compliance platform operated for Mediclinic hospital facilities. This policy describes how we collect, use, store, and protect your personal information in line with the Protection of Personal Information Act (POPIA) of South Africa and the General Data Protection Regulation (GDPR).

Information Officer

Name: Mediclinic Information Officer
Email: privacy@mediclinic.example
Contact for any privacy, access, or deletion request.

2. What data we collect

3. Why we process it

We process your data to:

4. Lawful basis

We process your data on the basis of your explicit consent (captured on first sign-in), contractual necessity (your employment or engagement with the hospital), and legal obligation (audit and health-and-safety record-keeping).

5. Who we share it with

We do not sell your data, use it for marketing, or share it with third parties for any other purpose.

6. How long we keep it

7. Your rights

Under GDPR and POPIA you have the right to:

On a deletion request, we anonymise rather than hard-delete personal identifiers, to preserve the integrity of the audit trail required by ISO 14001. Your name and email are replaced with a non-reversible hash; your linked inspection records remain but can no longer be traced back to you.

8. Security

9. Cookies

We use only essential cookies required to keep you signed in. We do not use tracking, analytics, or advertising cookies.

10. Data location

Your data is stored on Supabase infrastructure in a region selected for POPIA compliance. No personal data is transferred outside of approved jurisdictions without explicit contractual safeguards.

11. Complaints

If you believe we have mishandled your personal data, contact our Information Officer first. You may also lodge a complaint with:

12. Changes to this policy

We may update this policy. Material changes will be notified via email and require renewed consent.