Prepared in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA)
1.1 Moonlighter Group (Pty) Ltd, registration number 2013/139783/07 ("Moonlighter Group", "the Company", "we", "us" or "our"), respects your privacy and is committed to protecting Personal Information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Constitution of the Republic of South Africa, 1996, and other applicable law.
1.2 This Privacy Policy explains what Personal Information we collect, how and why we collect, use, disclose, store and secure it, and what rights you have in relation to that information, across all digital platforms operated by Moonlighter Group, including HealthGrid Africa, Alternivite, and SME Business OS (each a "Platform" and collectively the "Platforms").
1.3 This Privacy Policy should be read together with our Payment Terms and Conditions, applicable Platform Terms of Use, and our PAIA Manual, all of which are available on the relevant Platform.
1.4 We are the "responsible party" as defined in POPIA in respect of Personal Information we collect directly from you and use for our own purposes. In respect of certain data we process strictly on behalf of and under instruction from a client (for example, patient data processed within HealthGrid Africa on behalf of a healthcare provider, or payroll data processed within SME Business OS on behalf of an employer client), we act as an "operator" as defined in POPIA, and the relevant client remains the responsible party for that data. Where we act as operator, the client's own privacy notice, and the data processing agreement between Moonlighter Group and that client, govern the processing of that data, and this Policy applies to our processing only to the extent it is consistent with those instructions.
2.1 "Personal Information" means information relating to an identifiable, living natural person, and where applicable, an identifiable, existing juristic person, as defined in section 1 of POPIA, including but not limited to names, contact details, identification numbers, financial information, and online identifiers;
2.2 "Special Personal Information" means Personal Information concerning a data subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometric information, or criminal behaviour, as defined in section 26 of POPIA;
2.3 "Data Subject" means the person to whom Personal Information relates, referred to in this Policy as "you" or "your";
2.4 "Processing" means any operation performed on Personal Information, including collection, storage, use, dissemination, and destruction, as defined in section 1 of POPIA;
2.5 "Operator" means a person or entity that processes Personal Information on behalf of a responsible party, in terms of a contract or mandate, without coming under the direct authority of that party;
2.6 "Information Officer" means the person appointed by Moonlighter Group in accordance with section 55 of POPIA, whose details appear in clause 15 of this Policy;
2.7 "Information Regulator" means the Information Regulator of South Africa established under section 39 of POPIA.
3.1 We collect Personal Information that you provide to us directly, information generated through your use of a Platform, and information received from third parties, including the following categories:
| Category | Examples | Typical Source |
|---|---|---|
| Identity and contact information | Name, surname, ID/passport number, job title, company name, email, phone number, physical/postal address | Provided directly by you at registration or during onboarding |
| Account and authentication data | Username, hashed password, login history, multi-factor authentication data, IP address | Generated automatically when you use a Platform |
| Financial and billing information | Billing address, subscription plan, invoice history, limited transaction metadata (PayFast processes and stores full card details, not Moonlighter Group) | Provided by you and received from PayFast |
| Special Personal Information (health) | Where applicable to HealthGrid Africa, clinical, diagnostic, or patient-identifying data processed on behalf of a healthcare provider client acting as responsible party | Provided by our healthcare-sector clients or their systems, under a data processing agreement |
| Business and compliance data | For Alternivite and SME Business OS, information relating to a client's compliance status, HR records, payroll data, and regulatory filings | Provided directly by the client or its authorised users |
| Technical and usage data | Device type, browser type, operating system, pages visited, session duration, cookies and similar tracking technologies | Collected automatically |
| Communications | Support tickets, emails, call recordings (where disclosed), survey responses | Provided directly by you |
4.1 In accordance with section 4 of POPIA (the eight conditions for lawful processing), we only process Personal Information where we have a lawful basis to do so, which may include: your consent; that processing is necessary to conclude or perform a contract with you; that processing is required to comply with a legal obligation (including tax, FICA, and financial recordkeeping legislation); that processing protects a legitimate interest of yours; or that processing is necessary to pursue our own legitimate interests or those of a third party to whom the information is supplied, provided this is not overridden by your interests, rights, or freedoms.
4.2 We process Personal Information for the following purposes, among others:
4.3 We do not use Personal Information for a purpose materially different from that for which it was originally collected, unless the further processing is compatible with the original purpose (as assessed under section 15 of POPIA), you have consented, or further processing is required or permitted by law.
5.1 Health information processed within HealthGrid Africa constitutes Special Personal Information under section 26 of POPIA and, in general, may only be processed with the additional protections and justifications set out in sections 27 to 33 of POPIA, including where processing is carried out by, or under the responsibility of, a healthcare professional or institution, subject to an obligation of confidentiality, or is necessary for the proper treatment and care of the data subject, or is required by law.
5.2 Where Moonlighter Group processes health information within HealthGrid Africa on behalf of the South African Department of Health, a provincial health department, or another healthcare provider or parastatal client, Moonlighter Group acts as an operator under POPIA, and processes such data strictly under written instruction from, and subject to a data processing agreement with, that client, who remains the responsible party.
5.3 Moonlighter Group applies enhanced technical and organisational safeguards to Special Personal Information, including encryption at rest and in transit, role-based access controls, audit logging, and alignment with recognised health-data interoperability and security standards (including principles drawn from HL7 FHIR and OpenHIE architectures), consistent with the heightened security safeguard obligations under section 19 of POPIA.
6.1 Our Platforms are not directed at, and are not intended for use by, children as defined in POPIA (persons under the age of 18), save where a Platform is used by a school, guardian, or healthcare provider strictly in a professional or custodial capacity and in accordance with section 35 of POPIA.
6.2 Where the processing of a child's Personal Information is unavoidable within a healthcare context on HealthGrid Africa (for example, patient records for a minor), such processing occurs strictly under the responsibility of, and subject to consent obtained by, the treating healthcare provider or the child's competent guardian, in accordance with section 35 of POPIA.
7.1 Our Platforms may use cookies, web beacons, and similar tracking technologies to operate essential features, remember preferences, and understand usage patterns, in accordance with section 69(3) of POPIA (read with the direct marketing provisions) and section 51 of ECTA.
7.2 You may configure your browser to refuse some or all cookies. Disabling essential cookies may impair the functionality of a Platform.
8.1 We do not sell Personal Information. We may disclose Personal Information to the following categories of recipients, only to the extent reasonably necessary for the purposes described in clause 4:
8.2 Any third party who processes Personal Information on our behalf does so as an operator under a written agreement that requires them to process the information only for the agreed purpose, to keep it confidential, and to apply appropriate security safeguards, as required by section 21 of POPIA.
9.1 Some of our service providers, including cloud infrastructure and AI processing providers, may store or process Personal Information outside the Republic of South Africa. Alternivite, in particular, serves clients based in the United States, and related account and billing information may accordingly be processed outside South Africa.
9.2 Where Personal Information is transferred across South Africa's borders, we do so in accordance with section 72 of POPIA, which requires that the recipient be subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or that the transfer is necessary for the performance of a contract with the data subject, is for the data subject's benefit, or the data subject has consented.
9.3 Where our AI-assisted features (including those used in HealthGrid Africa's intelligence layer and Alternivite's compliance copilot) rely on third-party large language model providers, such providers are engaged under terms that restrict their use of submitted data to providing the contracted service, and Special Personal Information is, wherever reasonably possible, minimised, de-identified, or excluded from such processing.
10.1 Certain features of our Platforms use artificial intelligence or automated tools to generate recommendations, flags, risk scores, or draft outputs (for example, compliance risk indicators on Alternivite or clinical decision-support prompts on HealthGrid Africa).
10.2 In accordance with section 71 of POPIA, we do not subject a data subject to a decision that results in legal consequences for them, or that affects them to a substantial degree, based solely on automated processing intended to profile them, without human review, unless an exception under section 71(2) applies (such as the decision being necessary for entering into or performing a contract, and appropriate measures being in place to protect the data subject's legitimate interests, or the decision being governed by law).
10.3 Where a Platform generates an automated output that could materially affect a data subject (for example, a compliance risk flag or a clinical decision-support suggestion), that output is presented as a recommendation for review by a qualified human user (such as a compliance officer or healthcare professional), and is not treated as a final, binding decision made without human oversight.
10.4 You may request further information about the logic involved in automated processing that affects you by contacting our Information Officer using the details in clause 15.
11.1 We retain Personal Information only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law, whichever is longer, in accordance with section 14 of POPIA.
11.2 Typical retention periods include: account and profile information, for the duration of your account plus a reasonable period thereafter for legitimate business and legal purposes; financial and tax records, a minimum of 5 years in accordance with the Tax Administration Act 28 of 2011; and health records processed on behalf of a healthcare provider client, in accordance with that client's own retention obligations under applicable health-sector legislation and the relevant data processing agreement.
11.3 Where Personal Information is no longer required, we will delete, destroy, or de-identify it in a manner that prevents its reconstruction in an intelligible form, save where retention is required by law.
12.1 In accordance with section 19 of POPIA, we implement appropriate technical and organisational measures to secure the integrity and confidentiality of Personal Information, including encryption of data in transit and, where appropriate, at rest, access controls based on the principle of least privilege, network security monitoring, regular security review of our infrastructure, and contractual security obligations imposed on operators and sub-processors.
12.2 We take reasonable measures to identify and guard against internal and external risks to Personal Information, including risks addressed under the Cybercrimes Act 19 of 2020, and to regularly verify that these safeguards are effectively implemented.
12.3 No system of transmission or storage can be guaranteed to be 100% secure. While we take reasonable steps to protect Personal Information, we cannot guarantee absolute security, and you also play a role in protecting your account credentials.
13.1 Where we have reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery, in accordance with section 22 of POPIA, unless a public body responsible for the prevention, detection, or investigation of offences requests a delay.
13.2 Notification to affected data subjects will, to the extent reasonably possible, describe the nature of the breach, the Personal Information reasonably believed to be affected, our recommendations to mitigate possible harm, and contact details for further enquiries.
14.1 Subject to the limitations set out in POPIA, you have the right to:
14.2 To exercise any of these rights, please contact our Information Officer using the details in clause 15. We may need to verify your identity before giving effect to your request, and we will respond within the timeframes prescribed by POPIA.
15.1 Moonlighter Group's Information Officer, appointed and registered in accordance with section 55 of POPIA, can be contacted as follows:
| Information Officer | Nompumelelo Maseko |
| mpumi@moonlightergroup.co.za | |
| Postal Address | 158 Vlas Street, Pretoria, Gauteng, South Africa |
15.2 If you are not satisfied with our response to a request or complaint, you may lodge a complaint with the Information Regulator of South Africa:
| Website | www.justice.gov.za/inforeg |
| complaints.IR@justice.gov.za | |
| Physical Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
16.1 We may update this Privacy Policy from time to time to reflect changes in law, our processing activities, or our Platforms. The updated version will be published with a revised "Last Reviewed" date, and material changes will be notified to you by email or in-Platform notice where reasonably practicable.