Privacy Policy

OmniCore-AI is a practice-management platform used by South African healthcare practices. This policy explains what personal information we process, why, on what lawful basis, and how we protect it - in line with the Protection of Personal Information Act, 2013 (POPIA), the HPCSA's guidance on patient records, and, for EU-hosted data, the GDPR.

Who we are (responsible party)

This platform is operated by Omnicore AI (Pty) Ltd (registration number 2026/429590/07), a private company incorporated in South Africa with its registered office at 39 Corbel Crescent, Glenhazel, Johannesburg, Gauteng, 2192. OmniCore-AI is the responsible party for personal information we process about practice staff and website visitors. General privacy queries can be sent to admin@omnicore-ai.app or via our contact page.

Information Officer

As required by POPIA, OmniCore-AI has designated an Information Officer who is responsible for compliance with the Act and for handling data-subject requests and complaints. You can reach the Information Officer at admin@omnicore-ai.app. Please mark your message for the attention of the Information Officer.

Responsible party vs operator - an important distinction

For patient and clinical data captured by a practice using OmniCore-AI, the practice is the responsible party and OmniCore-AI acts as its operator under sections 20 and 21 of POPIA: we process patient data only on the practice's documented instructions and only to provide the service, and we do not decide the purposes for which patient data is used. The terms of that relationship, as section 21(2) of POPIA requires, are set out in our Operator Agreement. For the practice's own account, staff and billing data, OmniCore-AI is the responsible party. Each practice remains responsible for having a lawful basis and any patient consents required to enter patient information into the platform.

Categories of personal information we process

For practice staff: names, work email addresses, roles, login credentials and audit/usage logs. On behalf of practices (as operator): patient identifiers and contact details, medical-aid and billing information, appointment and clinical records, hearing-aid and repair data, and the content and delivery metadata of messages the practice sends. Some of this is special personal information (health data) under POPIA, which we process solely to provide the service on the practice's instructions.

Purposes of processing

To create and administer practice accounts; to operate, maintain and secure the platform; to deliver the features a practice enables (scheduling, billing, records, messaging, reporting); to provide support; to send service and security notices; and to comply with legal obligations. We do not sell personal information and do not use patient data for advertising or profiling.

Lawful basis

We process staff and account data on the basis of the contract with your practice and our legitimate interests in running and securing the service. Patient data is processed on behalf of the practice under our operator agreement; the lawful basis for that processing (for example patient consent, or the practice's legitimate healthcare purpose) rests with the practice as responsible party.

Sharing and sub-processors

We use a small set of vetted sub-processors to deliver the service: Supabase (EU-resident database, authentication and file storage, on Amazon Web Services eu-west-1); Cloudflare (application hosting, content delivery and bot protection); Twilio (WhatsApp, SMS and voice message delivery); Resend (email delivery); Google (calendar sync for connected accounts - see below); Sentry (error and performance monitoring); and PostHog (product analytics). Each processes personal information only to provide its function to us. We do not otherwise share personal information except to comply with law or as part of a merger or acquisition where the recipient continues to honour this policy. A current sub-processor list is available on request.

Google user data

OmniCore-AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. When you connect a Google account, the only Google user data we access is your Google Calendar events (the calendar.events scope), used solely to keep appointments in OmniCore-AI and your connected calendar in sync. We do not request access to Gmail or to any other Google data. We do not use Google user data for advertising, do not sell it, and do not use it to develop, improve or train generalised artificial-intelligence or machine-learning models. We do not transfer Google user data to third parties except as necessary to provide the calendar-sync feature you enabled, to comply with law, or as part of a merger or acquisition where the recipient continues to adhere to this policy. No one at OmniCore-AI reads your Google Calendar data except with your explicit consent, where necessary to investigate abuse or security incidents, or to comply with law. You can revoke OmniCore-AI's access at any time from Settings → Integrations in the app, or directly at myaccount.google.com/permissions.

Cross-border transfer

Our primary database is hosted in an EU-resident region. Where personal information is transferred outside South Africa (for example to our EU database or to sub-processors located abroad), we rely on the conditions in section 72 of POPIA - including that the recipient is subject to laws or binding agreements providing an adequate level of protection comparable to POPIA. The EU's data-protection regime (GDPR) is recognised as providing such protection.

Retention

For patient and clinical data we hold as operator, we operate no automatic deletion, expiry or purge. Records are retained for as long as the practice's account exists, and after termination until the practice instructs us otherwise, so that a practice is never put in breach of the record-keeping periods the HPCSA and the National Health Act impose - at least six years from the last entry, and longer for the records of minors. Because we do not decide when a practice's records are no longer needed, the section 14 duty not to retain records longer than necessary rests with the practice as responsible party. We delete, anonymise or restrict patient data on the practice's written instruction, and the platform lets a practice do so for individual records. For staff, account and website data we hold as responsible party, we retain it while the account is active and thereafter only for the period required by law or to resolve disputes. When someone accepts these documents at signup we record which version they accepted, together with the date, the IP address and the browser user agent of that acceptance; because that record is the evidence the agreement was entered into, we keep it for as long as the practice's account exists and for as long afterwards as we may need to rely on it. A new practice is also given a provisional web address derived from the account holder's name, which the first setup step replaces with the practice's own; it is never published or reachable before setup is finished, and it is kept only until it is replaced.

Your rights as a data subject

Under POPIA you may request access to, correction of, or deletion of your personal information, and you may object to certain processing. For patient data, requests are directed to the practice acting as responsible party, and we will assist the practice in giving effect to them. For staff and account data held by OmniCore-AI as responsible party, contact support@omnicore-ai.app.

Complaints and the Information Regulator

If you believe we have not handled your personal information lawfully, please contact our Information Officer first so we can try to resolve it. You also have the right to lodge a complaint with the Information Regulator (South Africa): enquiries@inforegulator.org.za or POPIAComplaints@inforegulator.org.za, JD House, 27 Stiemens Street, Braamfontein, Johannesburg.

Cookies and analytics

The website uses essential cookies needed for it to function and privacy-conscious product analytics (PostHog) to understand aggregate usage and improve the product. Error monitoring (Sentry) may capture technical diagnostic data when something goes wrong. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings.

Security measures

Personal information is protected with encryption in transit and at rest, row-level-security tenant isolation so one practice cannot access another's data, audit logging, least-privilege access controls, and bot protection on public forms. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the sensitivity of health data and review them on an ongoing basis.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated to account holders, and the 'last updated' date above will reflect the latest version.

Contact

Questions about this policy or your personal information can be sent to support@omnicore-ai.app or via our contact page.

Last updated 16 September 2026. Questions? Get in touch.