Privacy

CareUnion privacy notice — pre-launch draft

CareUnion is designed as healthcare-access and practice-automation software. Clinics decide how they use patient and operational information for their services, while CareUnion processes the information needed to provide, secure and support the configured platform. Final legal roles depend on the signed agreement and applicable jurisdiction.

Data minimisation

CareUnion is designed to collect only information needed for booking and operational workflows. It is not intended to become a general-purpose clinical record by default, and clinic patient data is not automatically reused for unrelated CareUnion marketing.

Isolation and access

Organisation data is tenant-scoped, role-controlled and audited where appropriate. CareUnion internal privileged access is intended to be limited to authorised operational/security needs.

Service providers

Hosting, email, payment, communications, AI or automation providers process data only when the applicable module is legitimately configured. Provider/subprocessor and cross-border implications must be reviewed before production activation.

Security incidents

CareUnion maintains an incident escalation process. Where CareUnion is processing information for a clinic, suspected security compromises are escalated to the clinic's nominated privacy/security contact so the responsible people can assess notification and response duties under applicable law.

Your rights and clinic requests

The product architecture includes controlled export, retention and deletion workflows. Requests may need to be handled by the clinic and/or CareUnion depending on who is responsible for the processing and any lawful retention obligations.

Jurisdiction

South African deployments require POPIA review. Eswatini deployments require review under the Eswatini Data Protection Act, 2022. One country's wording is not assumed to satisfy another country's requirements.

This page remains a product/legal draft. Final company details, lawful bases/notices, processor/operator terms, retention periods, provider disclosures and jurisdiction-specific wording require responsible legal/privacy review before real patient data.