Privacy Policy | Medara

Effective 12 July 2026

Privacy Policy

This policy explains how Medara Limited collects, stores, and protects data on the Medara platform.

01

Sensitive personal data

Medara stores identifiable health information, clinical notes, and imaging. This is sensitive personal data and is handled with a higher standard of care: explicit consent where required, encryption, access controls, and audit logging.

02

Roles: controller and processor

The practitioner (and their practice, where applicable) is the data controller for the patients they manage in Medara. Medara Limited acts as the data processor providing the platform. This split is set out in the Terms of Service and Data Processing Agreement.

03

Lawful basis

Processing is necessary for the provision of healthcare and professional medical services. Where consent is required for storage or sharing, it is recorded on the patient chart.

04

Data subject rights

Patients are not typically direct platform users. Access, correction, and deletion requests are fulfilled by the practitioner using Medara's privacy request workflows (export pack, chart correction, retention-gated deletion), with a target response window of 30 days.

05

Data residency

Production infrastructure is hosted in Africa (AWS af-south-1, Cape Town) wherever practical, for latency and residency expectations. Any subprocessor that handles data outside the region is disclosed here along with the contractual and technical safeguards in place (encryption, data processing agreements).

06

Retention

Medical records are retained for a minimum operational period of seven years from creation or last clinical activity by default (configurable per practice), consistent with medical records guidelines in most jurisdictions. Erasure requests are logged immediately; hard redaction or purge is applied once the retention period has elapsed.