This Data Processing Agreement (
“DPA”) sets out how GreenNotes (Pty) Ltd processes personal information on behalf of the practices and organisations that use GreenNotes. It is the written contract between a responsible party and its operator required by section 21 of the Protection of Personal Information Act, 2013 (
“POPIA”). It forms part of our
Terms and Conditions. An organisation that needs a signed copy can request one from our Information Officer.
1. Definitions
- Customer means the practice, organisation or individual practitioner that subscribes to the Services, together with the users it authorises.
- Customer Personal Information means personal information, including special personal information, that GreenNotes processes on the Customer’s behalf in providing the Services. It includes the information about patients and other people that the Customer records in GreenNotes.
- Security Compromise means a situation in which there are reasonable grounds to believe that Customer Personal Information has been accessed or acquired by an unauthorised person.
- Sub-processor means a third party that GreenNotes engages to process Customer Personal Information.
- Other terms have the meanings given in POPIA or in our Terms and Conditions.
2. Roles
For Customer Personal Information, the Customer is the responsible party and GreenNotes is its operator. The Customer decides why and how the information is processed. GreenNotes processes it only to provide the Services, under the Customer’s instructions.
GreenNotes is a responsible party in its own right only for the information it needs to run its own business, such as account, billing and sign-up details. Our Privacy Policy covers that information.
3. Details of the processing
- Subject matter and purpose: providing the Services: electronic health records, practice management, billing and medical-aid claims, scheduling, patient intake and consent, and AI-assisted documentation.
- Duration: the term of the Customer’s subscription and the return and deletion period in section 12.
- Categories of data subjects: patients and prospective patients; their emergency contacts, guarantors, medical-aid main members and billing contacts; referring and treating healthcare practitioners; and the Customer’s users.
- Categories of personal information: identifiers and contact details; demographic details; medical-aid, billing and payment records; clinical records, including consultation notes, diagnoses, procedures, medications, allergies and vitals; consultation audio and transcripts; documents, images and letters; consent records and signatures; appointments and tasks.
- Special personal information: health information, and the personal information of children where patients are minors.
4. GreenNotes’ obligations
GreenNotes will:
- process Customer Personal Information only on the Customer’s documented instructions. These are the Terms and Conditions, this DPA, the Customer’s use and configuration of the Services, and any other written instructions GreenNotes agrees to. The exception is where the law requires otherwise; in that case GreenNotes will tell the Customer before processing, unless the law prohibits it;
- tell the Customer if it believes an instruction breaches POPIA or another law;
- treat Customer Personal Information as confidential, and allow access to it only by personnel who need it to provide, support or secure the Services and who are bound by confidentiality obligations;
- not sell Customer Personal Information, not use it for its own marketing, and not use it, or allow its sub-processors to use it, to train or fine-tune AI models;
- use Customer Personal Information to maintain and improve the Services only for that Customer’s benefit. For example, GreenNotes may build a list of medical terms from a practice’s corrections to its transcripts and use it only in that practice’s own transcriptions.
5. The Customer’s obligations
The Customer is responsible for:
- having a lawful basis for the processing, including any consents it relies on. This includes patient consent to consultation recording, AI-assisted documentation and processing outside South Africa;
- telling patients and other data subjects how their information is processed, as POPIA section 18 requires, including the use of the sub-processors and countries listed on our Sub-processors page;
- managing who can access its practice: giving every person their own account, setting each member’s permissions, removing access promptly when someone leaves, and considering whether to require two-factor authentication;
- keeping the devices and browsers its users use to access GreenNotes secure; and
- ensuring that its instructions to GreenNotes comply with the law.
6. Security
GreenNotes maintains appropriate, reasonable technical and organisational measures to protect Customer Personal Information against loss, damage, unauthorised destruction, and unlawful access or processing, as POPIA section 19 requires. These include:
- encryption in transit, and encryption of sensitive fields and files with a key unique to each practice;
- separation between practices, enforced by the database’s security rules and again by our servers;
- role-based access, per-feature permissions, and two-factor authentication that a practice can require;
- restricted, two-factor-protected access for GreenNotes super-administrators;
- change history for clinical and account records;
- automated security testing of access rules on every code change; and
- hosting on infrastructure independently certified against ISO/IEC 27001.
GreenNotes reviews these measures regularly and updates them as risks and technology change. It will not reduce the overall level of protection during the Customer’s subscription. A detailed security overview is available on request.
7. Security compromises
GreenNotes will notify the Customer immediately of any Security Compromise, as section 21(2) of POPIA requires. The notice will describe, as far as it is then known:
- what happened;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the steps GreenNotes has taken or proposes to take; and
- a contact person.
GreenNotes will provide further information as it becomes available, and will help the Customer meet its obligations to notify the Information Regulator and affected data subjects under POPIA section 22. It will not notify them on the Customer’s behalf unless the Customer instructs it to or the law requires it.
8. Sub-processors
The Customer authorises GreenNotes to use the sub-processors listed on our Sub-processors page, and generally authorises GreenNotes to engage others under this section. GreenNotes will:
- bind each sub-processor by written agreement to data-protection obligations no less protective than those in this DPA, so far as they apply to the service provided; and
- remain responsible to the Customer for the performance of its sub-processors.
9. Processing outside South Africa
Customer Personal Information is stored in South Africa. Some Services involve processing in other countries, in particular:
- AI-assisted transcription and documentation, in the European Union and the United States; and
- email delivery, push notifications and internal alerting, in the United States.
The Sub-processors page lists the countries involved. GreenNotes transfers Customer Personal Information outside South Africa only to recipients bound by agreements that provide an adequate level of protection. Those agreements uphold principles substantially similar to POPIA’s conditions for lawful processing, and include provisions on further transfers substantially similar to POPIA section 72; or the transfer is otherwise permitted by section 72. The Customer remains responsible for any notification to data subjects, and for any prior authorisation from the Information Regulator, that its own processing requires.
10. Data subject requests
If GreenNotes receives a request from a data subject about Customer Personal Information, it will refer the request to the Customer and will not respond itself unless the Customer instructs it to or the law requires it. The Services let the Customer view, correct and export records. GreenNotes will provide reasonable further help where the Services do not cover a request.
11. Assistance
GreenNotes will give the Customer reasonable assistance with:
- personal information impact assessments;
- enquiries from the Information Regulator; and
- the Customer’s other obligations under POPIA relating to the Services.
The assistance takes into account the nature of the processing and the information available to GreenNotes.
12. Return and deletion
During the subscription, the Customer can view its records, and export individual records and reports, using the Services. When the subscription ends:
- GreenNotes keeps the Customer Personal Information available to the Customer, read-only, for 90 days, so that the Customer can retrieve what it needs using the Services;
- after that period, or earlier if the Customer asks in writing, GreenNotes deletes the Customer Personal Information from its active systems within 30 days. Copies in backups and in sub-processors’ systems are deleted as those expire, and in any event within 180 days; and
- GreenNotes will confirm the deletion in writing on request.
GreenNotes may keep information for longer only where the law requires it. It then continues to protect the information under this DPA and processes it only for the purpose that requires it to be kept.
13. Information and audits
GreenNotes will make available the information reasonably necessary to show that it complies with this DPA, including a description of its security measures and its sub-processors’ independent certifications and reports, where their terms allow this to be shared.
If that information is not enough to satisfy a legal requirement, the Customer, or an independent auditor bound by confidentiality, may audit GreenNotes’ compliance:
- once in any 12-month period, on at least 30 days’ written notice;
- during business hours and at the Customer’s cost; and
- without access to other customers’ information.
14. General
This DPA applies for as long as GreenNotes processes Customer Personal Information. If it conflicts with the Terms and Conditions on the processing of personal information, this DPA prevails. Each party’s liability under this DPA is subject to the limits in the Terms and Conditions, except where the law does not allow liability to be limited.
NameDavid Howe
Address2nd Floor, Shamrock Office Park, 97 York Street, George, Western Cape 6529