Privacy Policy
Valomate Solutions (Pty) Ltd, registration number 2025/408783/07
1. Introduction and purpose
1.1 Valomate Solutions (Pty) Ltd funds, administers and collects medical claims against the Road Accident Fund and the Compensation Fund on behalf of Medical Service Providers. We place road accident patients in private hospitals and manage the medical care of patients who hold an RAF Undertaking. We register employers with the Compensation Fund and administer their COID claims, and we administer COID awards on the instruction of attorneys.
1.2 To do this work we Process Personal Information, including the health information and identity numbers of injured patients. We are the Responsible Party for that Personal Information under POPIA.
1.3 We also comply with the National Health Act 61 of 2003, the Road Accident Fund Act 56 of 1996, COIDA, the Children's Act 38 of 2005 and PAIA in so far as they apply to the records we hold.
1.4 This Policy sets out what Personal Information we collect, on what lawful basis, how we use, share, secure and retain it, and how a Data Subject exercises their rights.
2. Scope
2.1 This Policy applies to all Personal Information we Process in the ordinary course of business. The Personal Information of employees, job applicants, consultants and contractors is governed by the Employee Data Privacy Policy.
2.2 This Policy binds every director, employee, consultant, contractor and Operator who Processes Personal Information for us.
3. Background
3.1 POPIA gives effect to the constitutional right to privacy by regulating the Processing of Personal Information. It sets eight conditions for lawful Processing, gives Data Subjects enforceable rights, and establishes the Information Regulator to monitor and enforce compliance.
3.2 We are registered with the Information Regulator as a Responsible Party, and our Information Officer is registered with the Regulator.
4. Policy statement
4.1 We Process Personal Information lawfully, for a specific and explicitly defined purpose, in a manner that respects the Data Subject's right to privacy, and in accordance with POPIA.
4.2 This Policy is read with POPIA and its Regulations, with PAIA, and with the supplementary policies listed in clause 12.
5. Definitions
In this document:
(a) Clause headings are for convenience and do not affect interpretation.
(b) A reference to one gender includes the other genders. A reference to a natural person includes a juristic person where the context allows.
(c) Annexures form part of this document.
(d) Words defined in POPIA carry the same meaning here. The following words have the meanings given below.
Child means a natural person under the age of 18 years.
COIDA means the Compensation for Occupational Injuries and Diseases Act 130 of 1993. COID refers to a claim or process under COIDA. The Compensation Fund is the fund established under COIDA.
Competent Person means a person legally competent to consent to an action or decision on behalf of a Child, such as a parent or legal guardian.
Consent means a voluntary, specific and informed expression of will by which a Data Subject permits the Processing of their Personal Information.
Data Subject means the person to whom Personal Information relates.
De-identify means to delete information that identifies a Data Subject, that can be used or manipulated by a reasonably foreseeable method to identify the Data Subject, or that can be linked by a reasonably foreseeable method to other information that identifies the Data Subject.
Information Officer means the person designated under section 55 of POPIA and section 17 of PAIA and registered with the Information Regulator. The Information Officer's details appear at the end of this document.
Information Regulator or Regulator means the Information Regulator established under section 39 of POPIA.
Matter means a single patient placement, claim, recovery or registration that we fund, administer or collect, and the file of records that belongs to it.
Medical Service Provider or MSP means an emergency medical services provider, private hospital, medical specialist or other health practitioner or health establishment that treats a patient and whose claim we fund, administer or collect.
Operator means a person who Processes Personal Information for us under a contract or mandate, without coming under our direct authority.
PAIA means the Promotion of Access to Information Act 2 of 2000.
Personal Information means information relating to an identifiable, living, natural person and, where applicable, an identifiable, existing juristic person. It includes information about race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth; information about education, medical, financial, criminal or employment history; any identifying number, symbol, email address, physical address, telephone number, location information, online identifier or other particular assigned to the person; biometric information; personal opinions, views or preferences; private or confidential correspondence; the views or opinions of another person about the person; and the person's name where it appears with other Personal Information or where disclosure of the name itself would reveal information about the person.
POPIA means the Protection of Personal Information Act 4 of 2013 and its Regulations.
Processing means any operation or activity, whether automated or not, concerning Personal Information, including collection, receipt, recording, organisation, collation, storage, updating, modification, retrieval, alteration, consultation, use, dissemination by transmission, distribution or making available in any other form, merging, linking, restriction, degradation, erasure or destruction.
RAF means the Road Accident Fund established under the Road Accident Fund Act 56 of 1996. An Undertaking is a certificate issued by the RAF under section 17(4)(a) of that Act by which the RAF undertakes to pay the future medical costs of an injured person.
Record means any recorded information, regardless of form or medium, in our possession or under our control, whether or not we created it and regardless of when it came into existence.
Responsible Party means a public or private body or any other person that, alone or together with others, determines the purpose of and means for Processing Personal Information. We are the Responsible Party for the Personal Information described in this document.
Security Compromise means any event in which there are reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person.
Special Personal Information means Personal Information concerning a person's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour.
VCM means the Valomate Claims Manager, the claims administration platform that we own and host on our own hardware.
Valomate, we, us and our mean Valomate Solutions (Pty) Ltd, registration number 2025/408783/07.
6. Data subject rights
Every Data Subject has the following rights under POPIA, and we give effect to each of them:
(a) to be notified that Personal Information about them is being collected, and that their Personal Information has been accessed or acquired by an unauthorised person (sections 18 and 22);
(b) to establish whether we hold Personal Information about them and to request access to it (section 23);
(c) to request the correction, destruction or deletion of Personal Information (section 24);
(d) to object, on reasonable grounds relating to their particular situation, to the Processing of their Personal Information (section 11(3));
(e) to object to Processing for purposes of direct marketing (section 11(3)(b) and section 69);
(f) not to be subject to a decision based solely on automated Processing that has legal consequences for them (section 71);
(g) to submit a complaint to the Information Regulator (section 74); and
(h) to institute civil proceedings regarding an interference with the protection of their Personal Information (section 99).
The procedure and forms for exercising these rights are set out in our Data Subject Request Procedure.
7. Conditions for lawful processing
We comply with the eight conditions for lawful Processing in Chapter 3 of POPIA.
7.1 Accountability (section 8)
7.1.1 The directors are accountable for compliance with POPIA. The Information Officer is responsible for it day to day and reports to the directors.
7.2 Processing limitation (sections 9 to 12)
7.2.1 We Process Personal Information only where at least one of the following grounds in section 11 applies: the Data Subject or a Competent Person consents; the Processing is necessary to carry out actions for the conclusion or performance of a contract to which the Data Subject is party; the Processing complies with an obligation imposed by law; the Processing protects a legitimate interest of the Data Subject; or the Processing is necessary to pursue our legitimate interests or those of a third party to whom the information is supplied.
7.2.2 We collect Personal Information directly from the Data Subject where reasonably practicable. We collect it from a third party where the Data Subject or a Competent Person has consented, where the information is contained in a public record, where collection from another source does not prejudice a legitimate interest of the Data Subject, or where collection from the Data Subject would prejudice a lawful purpose of the collection or is not reasonably practicable (section 12(2)). Patient information reaches us from the treating Medical Service Provider, the referring EMS provider, the patient's attorney, the RAF or the Compensation Fund.
7.2.3 A Data Subject may withdraw consent or object to Processing at any time by following the Data Subject Request Procedure. Withdrawal does not affect Processing that took place before it, or Processing that continues on another lawful ground.
7.3 Purpose specification (sections 13 and 14)
7.3.1 We collect Personal Information for the specific purposes described in clause 8. We collect only what those purposes require and what the RAF, the Compensation Fund or the treating Medical Service Provider requires for the claim.
7.3.2 We make the Data Subject aware of the purpose of collection through the Notice and Consent to Processing of Personal Information (RAF Patients), the Patient Consent Form (Undertaking), our Public Privacy Statement, the website privacy notice and the notification described in clause 7.6.
7.3.3 We keep Personal Information for no longer than the Record Retention Policy and the Record Retention Schedule allow, and then destroy or De-identify it so that it cannot be reconstructed in an intelligible form.
7.4 Further processing limitation (section 15)
7.4.1 We use Personal Information for a purpose other than the original purpose only where the further purpose is compatible with it, the Data Subject consents, the information is contained in a public record, further Processing is required by law or in legal proceedings, or the Regulator has granted an exemption.
7.4.2 We do not sell Personal Information and we do not use it for direct marketing.
7.5 Information quality (section 16)
7.5.1 We take reasonable steps to keep Personal Information complete, accurate, not misleading and up to date. Patient details are verified against the identity document and the treating Medical Service Provider's records. We correct information on request in terms of the Data Subject Request Procedure.
7.6 Openness (sections 17 and 18)
7.6.1 We maintain the PAIA Manual required by section 51 of PAIA and section 17 of POPIA.
7.6.2 Before we collect Personal Information from a Data Subject, or as soon as reasonably practicable after we collect it from another source, we tell the Data Subject or the Competent Person: what information we collect; our name and address; the purpose of collection; whether supply is voluntary or mandatory and the consequences of not supplying it; the law that requires the collection, where one does; that we will share the information with the RAF, the Compensation Fund, the Medical Service Providers involved in the Matter, and the patient's attorney; whether the information will be stored outside South Africa; and their rights of access, correction, objection and complaint. The Notice and Consent to Processing of Personal Information (RAF Patients) and the Patient Consent Form (Undertaking) carry this notification.
7.6.3 Where notification is not reasonably practicable, for example where a patient is unconscious and no Competent Person can be reached, we record the reason and give the notification as soon as we can (section 18(4)).
7.7 Security safeguards (sections 19 to 22)
7.7.1 We secure the integrity and confidentiality of Personal Information in our possession or under our control through appropriate, reasonable technical and organisational measures. We identify reasonably foreseeable internal and external risks, establish and maintain safeguards against them, verify that the safeguards work, and update them when new risks appear.
7.7.2 Physical measures include: premises inside a gated estate with 24-hour security guards, sensors and cameras; armed response; a security gate at the office entrance; and no hard-copy records. Paper we receive is scanned into the Matter file and shredded.
7.7.3 Technical measures include: password and multi-factor authentication on every account, device and system, governed by the Password Policy; encryption of every laptop; up-to-date antivirus and endpoint protection; automatic software updates; email warnings on messages from outside the company; backups of VCM and OneDrive under our control; a data recovery plan; and the controls in the Information Security Policy and the IT Change Management Policy.
7.7.4 Organisational measures include: access to Personal Information limited to the people who need it for the Matter; a signed non-disclosure agreement from every director, employee, consultant and contractor before access is granted; POPIA training at induction and every 12 months; the Clean Desk Policy; and the Employee Exit Policy.
7.7.5 An Operator Processes Personal Information for us only under a written contract that requires it to Process the information only with our knowledge or authorisation, to treat it as confidential, to maintain security measures at least equal to ours, and to notify us immediately of any Security Compromise (sections 20 and 21). Our Operator Register lists every Operator and the contract that governs it.
7.7.6 Where there are reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, we notify the Information Regulator and the affected Data Subjects as soon as reasonably possible, in the manner set out in the Incident Response Policy and Procedure (section 22).
7.8 Data subject participation (sections 23 to 25)
7.8.1 We confirm, free of charge, whether we hold Personal Information about a Data Subject. We give access to the record, correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, and destroy or delete information we are no longer authorised to keep, on request and within the time limits in the Data Subject Request Procedure.
8. Personal information we process, and why
8.1 Patients
8.1.1 We Process the Personal Information of patients in order to: fund and case-manage private hospital treatment of road accident patients; submit and collect the Medical Service Provider's supplier claim against the RAF; manage the medical care of patients who hold an RAF Undertaking and claim the costs from the RAF; administer COID claims for injured employees on behalf of their employers, and COID awards on behalf of attorneys; verify the patient's identity; respond to queries from the patient, the Competent Person, the Medical Service Provider, the attorney, the RAF or the Compensation Fund; and comply with the law and with lawful requests from the Regulator, a court or a public body.
8.1.2 The Personal Information we Process about a patient is limited to what the RAF, the Compensation Fund or the treating Medical Service Provider requires for the Matter. It may include:
| Category | Information |
|---|---|
| Identity and contact | Name; identity number or passport number; date of birth; gender; nationality; telephone number; email address; physical address; name and contact details of the next of kin or Competent Person |
| Accident or incident | Date, place and type of accident; SAPS station and case number; RAF claim or AR number; for COID, the employer, date of injury and Compensation Fund claim number |
| Admission | Admission date; referring EMS provider; admitting hospital and physician; level of care; suspected injury |
| Health information (Special Personal Information) | Vital signs on admission; comorbidities; details of injuries; procedures and surgeries; duration of stay; treatment and recovery plans; names of treating practitioners; medical reports and accounts required for the claim |
| Undertaking | The RAF Undertaking certificate and the medical reports, quotations and accounts required to claim under it |
| Employment (COID) | Employer name and registration; occupation; earnings where the Compensation Fund requires them |
8.1.3 Health information is Special Personal Information. We Process it on the following grounds: consent of the patient or a Competent Person (section 27(1)(a)); the Processing is necessary for the establishment, exercise or defence of a right or obligation in law, being the supplier claim, the Undertaking claim or the COID claim (section 27(1)(b)); and, where the patient is a Child, consent of a Competent Person or the establishment of a right in law (section 35(1)(a) and (b)).
8.1.4 We collect a patient's race only where the RAF or the Compensation Fund requires it on the claim form, and for no other purpose (section 29(a)).
8.1.5 We use identity numbers to verify identity and to identify the patient to the RAF, the Compensation Fund and the Medical Service Provider. We do not link identity numbers with information held by other responsible parties for any other purpose, and prior authorisation under section 57 is therefore not required.
8.2 Medical Service Providers
8.2.1 We Process the following information about Medical Service Providers and their staff in order to contract with them, fund and collect their claims, pay them, and respond to their queries: entity name and registration number; practice number; names, telephone numbers and email addresses of contact persons at head office and at each hospital, clinic or branch; physical and postal addresses; bank details; and invoices, statements and claim documents.
8.3 Employers, attorneys and referrers
8.3.1 We Process the names, entity details, registration numbers, contact details and instructions of employers who engage us for COID registration and claims, attorneys who instruct us on COID awards or refer Undertaking patients, and state facilities that refer patients, in order to carry out the instruction, report on progress and invoice for our services.
8.4 Website enquirers
8.4.1 A person who submits an enquiry on valomatesolutions.co.za gives us their name, contact details and the audience they belong to, and a short description of what they need. We use this only to respond to the enquiry. We do not ask for health information on the website. Where an enquiry becomes a Matter, the enquiry joins the Matter file. Where it does not, we delete it 12 months after our last contact with the enquirer.
8.5 Suppliers
8.5.1 We Process the contact and banking details of our suppliers in order to procure and pay for goods and services, as described in the Financial Data Policy.
9. Storage and access
9.1 We store Personal Information in VCM, which we own and host on our own hardware, in Microsoft 365 email and OneDrive, and on encrypted company laptops.
9.2 Only directors, employees and Operators who need the information for a Matter or for a business function have access to it, and only to the extent they need it. Access rights are set per user and reviewed when a person's role changes and when they leave.
9.3 We hold no hard-copy records. Paper we receive is scanned into the Matter file and shredded.
9.4 VCM and OneDrive are backed up under our control. The Information Security Policy governs backups, recovery and system security.
9.5 We keep a Security Compromise Register of every security incident, whether or not it is notifiable.
10. Sharing and transfer of personal information
10.1 We share a patient's Personal Information, including health information, only with the parties to the Matter: the RAF or the Compensation Fund, in order to submit and collect the claim; the Medical Service Providers treating the patient; the patient's attorney, where one is instructed; and the employer, in a COID Matter, to the extent the claim requires. Each recipient is a Responsible Party in its own right for the information it receives.
10.2 We disclose Personal Information to any other person only where the Data Subject or a Competent Person has consented, the law or a court requires it, or disclosure is necessary to establish, exercise or defend a right in law.
10.3 Our Operators are Microsoft (email and OneDrive), our external IT support provider, and our payroll, accounting and audit providers. Each is bound as described in clause 7.7.5.
10.4 VCM and its data are hosted on our own hardware in South Africa. Microsoft 365 and OneDrive data are stored in Microsoft's South African data centres under Microsoft's data protection terms. We do not transfer Personal Information outside South Africa. Where a transfer becomes necessary, we make it only on a ground in section 72 and, for Special Personal Information or the information of a Child going to a country without adequate protection, only with the prior authorisation of the Regulator (section 57(1)(d)).
10.5 We do not use WhatsApp to send health information to anyone other than the Medical Service Provider treating the patient, and only as the WhatsApp Policy allows.
11. Information Officer
11.1 The directors have designated the Information Officer under section 55 of POPIA and section 17 of PAIA, and have registered the designation with the Information Regulator. The Information Officer:
(a) encourages and monitors compliance with the conditions for lawful Processing;
(b) maintains this Policy, the Public Privacy Statement, the PAIA Manual and the supplementary policies, and makes them available on request and, where required, on our website;
(c) maintains the Processing Activities Register, the Operator Register, the Security Compromise Register, the Data Subject Request Register and the Complaints Register;
(d) conducts a privacy impact assessment before we adopt a new system, process or category of Processing;
(e) handles data subject requests and complaints within the statutory time limits;
(f) approves Operator contracts and monitors Operator compliance;
(g) manages Security Compromises and notifies the Regulator and Data Subjects;
(h) arranges POPIA training at induction and every 12 months, and keeps the Training Register;
(i) submits the annual PAIA report to the Regulator; and
(j) co-operates with the Regulator in any investigation or assessment.
12. Supplementary policies
This Policy is supported by the following documents, each of which is available from the Information Officer:
PAIA Manual and PAIA Policy
Public Privacy Statement
Data Subject Request Procedure and forms
Notice and Consent to Processing of Personal Information (RAF Patients)
Patient Consent Form (Undertaking)
Information Security Policy
IT Change Management Policy
Record Retention Policy and Record Retention Schedule
Employee Data Privacy Policy
Employee Exit Policy
Incident Response Policy and Procedure
Complaints Policy and Procedure
Clean Desk Policy
Password Policy
Financial Data Policy
WhatsApp Policy and WhatsApp POPIA Notice
Operator Privacy Agreement and Operator Register
Processing Activities Register
Register of Interpretations and Interpretation Schedule
Privacy Impact Assessment Guide
13. Staff training and acceptance
13.1 Every director, employee, consultant and contractor receives POPIA training at induction and every 12 months thereafter. The Information Officer records attendance in the Training Register.
13.2 Every employment contract and every consultancy or contractor agreement contains confidentiality and POPIA clauses. Every person signs acceptance of this Policy and the supplementary policies that apply to their role.
14. Policy review
The Information Officer reviews this document every 12 months, before the anniversary of its effective date, and at any earlier time when legislation, guidance from the Information Regulator, or our systems or processes change in a way that affects it. The directors approve each new version.
15. Details of the Information Officer
Information Officer
Name: Bianca van Zyl
Telephone: 012 012 5746
Email: popia@valomatesolutions.co.za
Physical and postal address: 613 Andries Strydom Street, Constantia Park, Pretoria, 0181
We have not designated a Deputy Information Officer. The directors act in the absence of the Information Officer.
16. Recourse
Enquiries, requests and complaints about this document or about the Processing of Personal Information go to the Information Officer at popia@valomatesolutions.co.za. Our Complaints Policy and Procedure describes how we handle a complaint. A Data Subject who is not satisfied with our response may complain to the Information Regulator.
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Telephone: 010 023 5200
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: www.inforegulator.org.za
Version control
| Item | Detail |
|---|---|
| Document | Privacy Policy |
| Responsible party | Valomate Solutions (Pty) Ltd, registration number 2025/408783/07 |
| Version | 2.0 |
| Effective date | 7 September 2026 |
| Approved by | B van Zyl and J de Clercq, directors |
| Document owner | Information Officer |
| Next review date | September 2027 |
| Supersedes | Version 1.0 issued under Valomate Medical Services (Pty) Ltd, 2022 |