How UVUNTU Health Pty Ltd collects, uses, stores and shares personal information.
UVUNTU Health Pty Ltd runs a booking platform that helps people in Zimbabwe (and globally) book appointments with healthcare providers. To do that, we collect information about the person making the booking (the Booker), and a small amount of information about the person the appointment is for (the Patient) — these are often the same person, but not always.
We are responsible for the information we collect through the booking platform — your account, your booking history, and limited information about any Patient you book for. We decide how it's used, within the limits of this Policy and the law.
We do not collect or hold clinical information — diagnoses, treatment notes, test results, prescriptions, or anything about the care delivered at the appointment. That information is created and held by the clinic at the point of care, under the clinic's own privacy arrangements. If you want to know what clinical information the clinic holds about you, you need to ask the clinic directly.
Our servers are in Australia. If you're in Zimbabwe, your information is transferred to Australia for processing, with safeguards we describe below.
You have rights over your information — to see it, correct it, delete it (within limits), and complain if you think we've done something wrong. Contact us at [email protected].
UVUNTU Health Pty Ltd (ACN [ACN to be inserted], ABN [ABN to be inserted]) is an Australian company that operates the UVUNTU Health booking platform at uvuntu.com and app.uvuntu.com (the Platform). In this Policy, "UVUNTU", "we", "us", and "our" mean UVUNTU Health Pty Ltd.
This Policy explains how we handle personal information under:
Where these regimes give you different rights, the more protective one applies.
We want to be clear about the scope of this Policy — because the boundary between what UVUNTU holds and what the clinic holds matters for your privacy rights.
UVUNTU is the data controller for everything the booking platform collects: your account information, your booking history, limited information about any Patient you book for (name, optional contact, relationship to you), your payment method reference, and your communications with our support team. We decide how this information is used, within the limits of this Policy and the law, and you exercise your privacy rights directly with us.
We do not collect or hold any clinical information about the Patient — diagnoses, treatment notes, test results, prescriptions, consultation history, or anything recorded at the appointment. The clinic creates and holds that information in its own systems, under its own privacy notice. If you want access to clinical records, correction of them, or deletion, you go to the clinic directly, not to us.
When you book for someone other than yourself — a child, an elderly parent, a person in your care — we collect the minimum information needed to schedule the appointment:
By making a booking for a Patient who is not you, you confirm that you have authority to share their information for this purpose. We do not collect detailed health information about the Patient — the clinic handles that at the appointment, separately from the booking platform and under the clinic's own privacy arrangements.
We do not collect health information about the Patient through the booking platform. The service type you select at booking (such as "General Consultation" or "Dental Checkup") is a service category, not clinical information. If you voluntarily include health information in booking notes or communications with us, we will handle it with the same care as other information, but we ask you to share clinical details with the clinic directly rather than through the Platform — the clinic is the right place for that conversation, and it's their role to hold that information.
We use Booker information to:
Under the CDPA and the Australian Privacy Act, we rely on a combination of:
We do not use your information for purposes you haven't agreed to. We do not sell your information to anyone.
We share information only where necessary to deliver the service or comply with law.
| Who | What they get | Why |
|---|---|---|
| The provider or organisation you book with | Booking details (appointment time, service type, Booker's name, Patient's name if different, contact details, any notes) | To schedule and deliver the appointment |
| Stripe | Payment information, billing details | To process payments securely |
| Wise | Provider identity and payment details (not Booker information) | To pay providers |
| Amazon Web Services (AWS) | All Platform data (hosted in AU region) | Cloud hosting and storage |
| Zoho, communications gateways | Your email address and message content | To send transactional and service emails |
| SMS gateways | Phone number and message content | To send SMS confirmations and Codes |
| Cloudflare | IP address, request metadata | Security, DDoS protection, CDN |
| Sanctions screening service | Name and identifier details | To meet our sanctions compliance obligations |
| Professional advisors (lawyers, accountants, auditors) | Only as necessary | To get legal, tax, or audit advice under confidentiality |
| Regulators and law enforcement | As required by valid legal process | To comply with law |
We maintain a full list of sub-processors (companies that handle personal information on our behalf) and update it as our supplier relationships change. You can request the current list at [email protected].
We do not share your information with advertisers, data brokers, or any party for marketing purposes.
Our Platform is hosted in Australia (AWS Sydney region). If you're in Zimbabwe or elsewhere, using the Platform means your information is transferred to and stored in Australia.
Under the CDPA, cross-border transfer of personal information requires appropriate safeguards. The safeguards we rely on:
Some of our sub-processors (Stripe, Cloudflare, and others with global operations) process information in multiple jurisdictions. We rely on their published cross-border transfer frameworks and the contractual protections they offer.
We don't keep information longer than we need to. Different categories of information have different retention periods, based on why we hold them:
| Information category | How long we keep it | Why |
|---|---|---|
| Your account information | Until you close your account, plus 2 years for complaint-evidence purposes | To defend against any later dispute about the account |
| Booking details | While active; then retained with your account | So you have access to your booking history |
| Payment and financial records | 7 years from the transaction | Tax and accounting law requirements (Australia and Zimbabwe) |
| Consent records (what you agreed to, when) | 2 years after your account closes | To show what version of our terms you accepted |
| Complaint and dispute records | 7 years from closure | Regulatory defence; pattern analysis |
| Data breach records | 7 years minimum | Regulatory requirements if a breach occurred |
| Data-subject request records (access, deletion, correction) | 2 years from closure | To show we responded to your request |
| Operational audit logs (page views, technical events) | 90 days, then archived and eventually purged | Low evidential value, high volume |
We can place a legal hold on any category of information if there's an investigation, complaint, or potential claim. A legal hold pauses automatic deletion for the affected records until the matter is resolved.
You have the following rights over your personal information. These are expressed in different terms under the CDPA and the Australian Privacy Act, but in practice you can exercise all of these with us.
You can ask for a copy of the Booker information we hold about you. We'll respond within 30 days (sometimes longer if the request is complex — we'll tell you if so).
If information is incorrect, you can ask us to fix it. You can update most account information directly in the Platform. For anything else, contact [email protected].
You can ask us to delete your Booker information. We'll delete what we can, and tell you about anything we're required to keep (for example, financial records we must keep for tax purposes). In those cases, we anonymise where we can't delete.
You can ask us to stop using your information for a particular purpose, or to restrict how we use it. Where this is possible under our legal obligations, we'll comply.
You can ask for a machine-readable export of your Booker information so you can take it elsewhere.
Where our use of your information relies on your consent, you can withdraw that consent. Withdrawal doesn't affect anything we did before the withdrawal. It may mean we can no longer provide parts of the Platform.
Your clinical records — diagnoses, treatment notes, test results, anything the clinic recorded about your care — are held by the clinic, not by us. To access, correct, or delete those records, contact the clinic directly. Each clinic has its own process under its own privacy notice, and we don't speak for the clinic on clinical matters.
If you think we've mishandled your information, you can complain to:
We'd prefer you came to us first so we can try to resolve things. But the regulator route is always open to you.
We take security seriously. Our measures include:
No system is perfectly secure. If a data breach happens, we follow our Data Breach Response Plan: we contain the breach, assess the impact, and notify affected people and regulators where the law requires. Under the Australian Privacy Act's Notifiable Data Breaches scheme, we assess the breach and notify affected individuals and the OAIC where required. Under the Zimbabwe CDPA, we notify POTRAZ and affected data subjects where the breach is likely to cause significant harm.
Clinical records held by clinics are outside the scope of our breach response — clinics operate their own systems and run their own breach procedures under their own privacy arrangements.
The Platform uses a small number of cookies and similar technologies. We'll keep this list short — we don't use advertising trackers.
You can control cookies through your browser settings. Blocking essential cookies will stop the Platform working properly.
The Platform is intended for users aged 18 or older. If you're under 18, don't create a Booker account — ask a parent or guardian to book on your behalf.
Patients under 18 can be booked for by parents or guardians. In those cases, information about the minor Patient is handled with additional care: we collect only what's necessary, and the clinic takes additional consent steps at the point of care.
We may update this Policy from time to time. Where changes are material, we'll notify you by email and by a notice on the Platform at least 14 days before the changes take effect. If you continue to use the Platform after the changes take effect, you're accepting the updated Policy. If you don't accept, you can stop using the Platform.
We keep older versions of this Policy on record, so you can see what was in force when you signed up or made a booking. Request an older version at [email protected].
For any privacy question, concern, or request:
Our Data Protection contact is [designated DPO or privacy lead to be inserted], reachable at the privacy email above.