Privacy Policy
Effective Date: 18 March 2025
Last Updated:
Introduction
Welcome to New Health 263 (Pvt) Ltd (Hereafter “New Health263”) (“we,” “our,” or “us”). We provide a digital platform that enables medical aid funders and medical service providers to manage patient claims, verify member eligibility, process authorisations, and check member benefits.
This Privacy Policy explains how New Health 263 collects and uses your personal information, with whom it is shared, and your choices and rights in relation to your personal information.
It applies to personal information that is collected from you physically or in a borderless digital environment during your interactions with us, whether online, including through our websites (including mobile sites), social media sites and mobile applications (collectively “Internet Services”) that link to this Privacy Statement, in writing or orally, or personal information that we may collect offline or receive from third parties. By using our services, you acknowledge and agree to the practices described in this policy.
Personal Information We Collect
New Health 263 is primarily subject to the Cyber and Data Protection Act of 2021 (“CDPA” and its Regulations) and other data and privacy regulations from where you can access our services or internet services.
“Personal information” is defined in CDPA as information relating to an identifiable, living, natural person and where it is applicable, an identifiable, existing juristic person, including but not limited to:
- the person’s name, address or telephone number;
- the person’s race, national or ethnic origin, colour, religious or political beliefs or associations;
- the person’s age, sex, sexual orientation, marital status or family status;
- an identifying number, symbol or other particulars assigned to that person; fingerprints, blood type or inheritable characteristics;
- information about a person’s health care history, including a physical or mental disability;
- information about educational, financial, criminal or employment history; opinions expressed about an identifiable person;
- the individual’s personal views or opinions, except if they are about someone else;
- and personal correspondence pertaining to home and family life;
Depending on how you interact with us, personal information we collect may include but without limitation to:
- your full name
- Contact Information (Phone Number, Email, Address)
- log-in and account information for authentication purposes and account access
- National ID/Passport Number
- your gender
- health information
- biometric data
We may also collect other information that does not personally identify you. Such other information includes browser and device information, website and application usage data, IP addresses, demographic information such as geographic location, home language, and information collected through cookies and other technologies or information that has been anonymised or aggregated. If we link this information with your personal information, we will treat such linked information as personal information.
You can choose not to provide personal information to us when requested. However, if this is necessary to provide you with our solutions, products and services, access to our Internet Services, or to perform administrative functions, we may be unable to provide you with our solutions or services.
How we collect your personal information
- When you access our Internet Services, or interact with us in any other way, or use our solutions, products and services.
- We collect personal information when you place orders for our solutions, products and services, you create an account with us, we process your orders and payment transactions, perform administrative and business functions, market our solutions, products and services to you and when you register for our events, workshops and seminars or subscribe to our mailing lists and newsletters.
- When you communicate with us.
- We collect personal information when we respond to your inquiries and requests, obtain feedback from you about our solutions, products and services or you apply for employment with us.
- From third party sources.
- We collect personal information from third parties, including public databases, social media sites, business partners with whom we offer co-branded services or engage in joint marketing activities and third parties that provide list enhancement or similar services.
- When you use our Internet Services, we may, and third parties we engage may automatically collect data, including personal information through use of cookies and similar technologies. For more information, see the “Cookies and Similar Technologies” section below.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as your device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When you access the service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.
We may also collect information that your browser sends whenever you visit our service or when you access the service by or through a mobile device.
Legal basis for processing your personal information
When we process your personal information in connection with the purposes set out in this Privacy Statement, we may rely on one or more of the following legal bases, depending on the purpose for which the processing activity is undertaken and the nature of our relationship with you:
- Our legitimate interests (or those of a third party with whom we share your personal information) for the purpose of managing, operating or promoting our business, including direct marketing, and administrative purposes, except where such interests are overridden by your interests or fundamental rights or freedoms which require protection of personal information.
- Where this is necessary to comply with a legal obligation on us, whether contractually or otherwise.
- To protect the vital interests of any individual.
- Where you have consented for such processing to take place.
Use of your personal information
We may use your personal information to:
- Enable you to effectively use and to improve our solutions, products and services, for example to:
- Perform administrative and business functions and internal reporting.
- Send administrative information to you.
- Obtain feedback from you about our services, products and solutions including through client satisfaction surveys, in which event, we will only use your personal information for the sole purpose of sending you a survey.
- Respond to your inquiries and fulfil requests by you.
- Assess the performance of our Internet Services and to improve their operation.
- Inform you about and provide you with our products, services and solutions.
- Update our records and keep your contact details up to date. We engage in these activities to manage our contractual relationship with you, to comply with our legal obligations, or for our legitimate business interests:
- Provide you with marketing materials and to personalise your experience with us, for example to:
- Send marketing communications to you.
- Enable you to subscribe to our newsletters and mailing lists.
- Enable you to register for New Health 263 events, workshops and webinars.
- We engage in these activities with your consent or for our legitimate business interests:
- Achieve our business purposes and analyse information. For example, to:
- Establish, manage, and maintain our business relationship with you.
- Compile usage statistics for our Internet Services.
- Recruit staff.
- Process and respond to privacy requests, questions, concerns and complaints.
- Fulfil legal and contractual obligations.
- We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation and for our legitimate business interests.
Direct Marketing
We may send you direct marketing e-communications about our solutions, products and services. You can choose whether you wish to receive marketing e-communications from New Health 263 by email, SMS, post and phone. You may opt out of receiving marketing materials from us at any time and manage your communication preferences by:
- Following the unsubscribe instructions included in each marketing email
- Sending an email to the sender of the marketing communications; or writing to dpo@health263.systems
- Including your details and a description of the marketing material you no longer wish to receive from us.
- We will comply with your request as soon as is reasonably practicable.
If you opt out of receiving direct marketing related communications from us, we may still send you administrative messages as part of your ongoing use of our products, solutions and services, which you will be unable to opt out of.
We do not provide your personal information to unaffiliated third parties for direct marketing purposes or sell, rent, distribute or otherwise make personal information commercially available to any third party.
Sharing your personal information
We may share your personal information for the purposes set out in this Privacy Policy (as applicable):
- With Service Providers: We may share Your personal information with Service Providers to monitor and analyse the use of our Service, to contact You.
- For Business Transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honour this Privacy Policy. Affiliates include joint venture partners or other companies that We control or that are under common control with Us.
- With Business Partners: We may share your information with our business partners to offer you certain products, services or promotions.
- With your consent: We may disclose Your personal information for any other purpose with Your consent.
- For debt collection agencies or other debt recovery organisations
- For other legal reasons:
- We may share your personal information in response to a request for information by a competent authority in accordance with, or required by any applicable law, regulation or legal process;
- Where necessary to comply with judicial proceedings, court orders or government orders;
- or To protect the rights, property or safety of New Health 263, its business partners, you, or others, or as otherwise required by applicable law.
- Any third parties with whom we share personal information are contractually required to implement appropriate data protection and security measures to protect personal information and are not permitted to use personal information for any purpose other than the purpose for which they are provided with or given access to personal information.
Your rights as a Data Subject
As a data subject you have certain rights under section 14 of the CDPA relating to your personal information which are:
- The right to be informed of the use your personal data will be put.
- The right to access your personal information in our custody.
- The right to object to ways we are using all or parts your personal data.
- The right to correction of inaccurate personal data or incomplete.
- The right to deletion of false or misleading information.
- The right to withdraw consent if we are using your data based on your consent.
- The right to complain to the designated Data Protection Authority which is the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
You can exercise these rights in relation to your personal data by writing to us using the contact details below.
Security of your personal information
New Health 263 is committed to protecting your personal information from accidental or unlawful destruction, damage, loss, alteration, unauthorised access or disclosure by using reasonable, appropriate, physical, administrative and technical safeguards and contractually requiring that third parties to whom we disclose your personal information do the same.
Cross Border Transfers
New Health 263 may be required to fulfil its contractual obligations with you outside of Zimbabwe and may transfer your personal information to South Africa in connection with the purposes identified above and in accordance with this Privacy Statement. Your information, including Personal Data, is processed at the Company’s operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Zimbabwe where the data protection laws may differ. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organisation or a country unless there are adequate controls in place including the security of Your data and other personal information.
Links to third party websites and applications
Our Internet Services may contain links to third party websites and applications. We are not responsible for and make no representations or warranties in relation to the privacy practices or content of any third-party websites and applications. Your use of such sites and applications is subject to the applicable third-party privacy statement and is at your own risk.
Retention of your personal information
We will retain your personal information for as long as is necessary to fulfil the purpose for which it was collected unless a longer retention period is required to comply with legal obligations, resolve disputes, protect our assets, or enforce agreements. The criteria we use to determine retention periods include whether:
- We are under a legal, contractual or other obligation to retain personal information, or as part of an investigation or for litigation purposes;
- Personal information is needed to maintain accurate business and financial records;
- You have consented to us retaining your personal information for a longer retention period, in which case, we will retain personal information in line with your consent.
Updates to this Privacy
We may update this Privacy Statement at any time. If we do, we will update the “last modified” section at the bottom of this Privacy Statement.
We encourage you to regularly review this Privacy Statement to stay informed about our privacy practices.
How to contact us
If you have any complaints, requests or questions about how your personal information is handled by New Health 263, you have a privacy concern or you wish to make a request or a complaint relating to your personal information, please contact us.
You can reach us at:
Email: dpo@health263.systems