Last updated 30 July 2026
Oryx Health Holdings (Pty) Ltd, trading as Oryx ("Oryx", "we", "us", "our"), Reg. No. 2026/366283/07, is at Level 3A, Pearls Mall, Umhlanga, KwaZulu-Natal, 4319, South Africa.
We are the responsible party for the personal information described in this policy, as defined in the Protection of Personal Information Act 4 of 2013 ("POPIA").
Information Officer: Tom Chadwick, hello@oryx.health. If you have a concern about how we handle your personal information, contact our Information Officer before contacting the Information Regulator, so we have a chance to put it right.
Directly from you, through consultation forms, account registration, and your communications with us. Automatically, through cookies and similar technology when you use the Site or App (see section 16).
Health information is special personal information under POPIA. We process it lawfully by relying on the following exemptions under sections 26 and 27:
(a) Consent: you provide informed consent to the processing of your health information when you register for the Services and confirm a consultation;
(b) Medical treatment: processing is necessary for the proper treatment of you as a patient by a health professional (our practitioners and pharmacists) who is subject to professional confidentiality obligations (POPIA s27(1)(d));
(c) Public interest: processing is necessary for reasons of public interest in the area of public health, including ensuring the safety and efficacy of treatments.
Creation Labs (Pty) Ltd processes health data on our behalf as an operator under a written agreement that meets the requirements of POPIA sections 20 and 21. Creation Labs may not process your personal information for any purpose other than those set out in this policy and our agreement with them.
We process your personal information only where we have a lawful basis under POPIA (aligned with GDPR Article 6 and Article 9 equivalents where applicable). The conditions we rely on include:
(a) Consent (POPIA s11(1)(a) / GDPR Art 6(1)(a)): where you have given clear consent, such as for marketing communications or optional profiling.
(b) Contract (POPIA s11(1)(b) / GDPR Art 6(1)(b)): processing necessary to perform our agreement with you, including providing consultations, treatment, and dispensing.
(c) Legal obligation (POPIA s11(1)(c) / GDPR Art 6(1)(c)): processing necessary to comply with legislation such as the Pharmacy Act, Medicines Act, or tax legislation.
(d) Legitimate interest (POPIA s11(1)(f) / GDPR Art 6(1)(f)): processing necessary for our legitimate interests (such as fraud prevention, security, and service improvement), provided those interests are not overridden by your rights.
(e) Health data (POPIA s26–s27 / GDPR Art 9(2)(h)): processing of special personal information for medical treatment purposes as described in section 4 above.
Before you register, you may complete an eligibility check. Your answers are stored against an anonymous session identifier and are not linked to any identifiable person unless you proceed to register. If you do not register, your eligibility answers are automatically purged within a maximum of 30 days. If you do register, the answers are linked to your account and retained as part of your clinical record.
We share your information, where relevant to the purposes above, with the following categories of recipients:
Everyone who receives your information under this section is bound by confidentiality obligations at least as strict as our own. A full, up-to-date list of our third-party service providers is available on request by emailing support@oryx.health.
Where we transfer your personal information outside South Africa, we do so only in accordance with the safeguards required by POPIA section 72. These safeguards include transfers to countries with adequate data protection laws, transfers with your consent, and transfers subject to binding contractual protections. The following services may transfer data outside South Africa:
(a) Google Ads and Google Analytics transfer data to Google's data centres in the United States. We rely on POPIA s72 safeguards (consent and contractual protections under Google's data processing terms).
(b) Meta Ads transfers data to Meta's data centres in the United States. We rely on the same POPIA s72 safeguards (consent and contractual protections).
(c) Cloudflare: all traffic to our website and patient portal flows through Cloudflare's global network for security and performance purposes, which means data may transit through servers outside South Africa. File storage (Cloudflare R2) may also involve servers outside South Africa. We rely on POPIA s72 safeguards (contractual protections under Cloudflare's data processing addendum).
(d) Microsoft Clarity transfers session replay and debugging data to Microsoft data centres, which may be located outside South Africa. Microsoft may use anonymised and aggregated data in its own analytics pipeline. We rely on POPIA s72 safeguards (contractual protections under Microsoft's data processing terms).
(e) Microsoft Teams and Office 365 process consultation audio/video and practitioner communications through Microsoft's cloud infrastructure, which may include data centres outside South Africa.
POPIA section 69 restricts electronic direct marketing. We distinguish between:
(a) Operational/treatment-related communications: booking confirmations, order updates, prescription renewal reminders, and treatment plan notifications are not marketing. They are necessary for the performance of our agreement with you and you will receive them as long as you use the Services.
(b) Promotional marketing: purely promotional communications (such as new product announcements, special offers, or general health content not specific to your treatment) require your prior opt-in consent. You may opt out of promotional marketing at any time by using the unsubscribe link in any marketing email, by adjusting your preferences in your account settings, or by emailing support@oryx.health.
We do not share your personal information with third parties for their own marketing purposes.
Booking confirmations and order notification emails contain only minimal clinical detail (such as appointment date and order reference). To protect your privacy in the event of email account compromise, you must log into the patient portal to view full treatment details, prescription information, and product specifics. This measure ensures that sensitive health information is not exposed through email.
Where no specific period is stated above, personal information is retained only for as long as necessary for the purpose it was collected, then deleted or anonymised, unless we are required by law to keep it longer.
Under POPIA (and, where applicable, the GDPR), you have the right to:
To exercise any of these rights, contact our Information Officer at hello@oryx.health. We will respond within a reasonable time and in any event within 30 days.
Our eligibility check applies rule-based criteria (including age, sex, and location) to determine whether you qualify for the Services. Certain answers may automatically exclude you from proceeding—for example, if you are under 18, are not male, or reside outside South Africa.
Under POPIA section 71, you have the right not to be subject to a decision based solely on automated processing that significantly affects you, unless it is permitted by law or based on your consent. If you are excluded by the eligibility check, you may request human review of that decision by contacting our Information Officer at hello@oryx.health.
We use technical and organisational measures, including encryption in transit and at rest, role-based access controls, and regular security assessments, to protect your personal information. These measures are appropriate to the sensitivity of health data, as required by POPIA and the National Health Act.
Sessions on the patient portal automatically expire after 10 minutes of inactivity to protect your health information. We do not offer a persistent "Remember Me" login option for the patient portal, given the sensitive nature of health data and the access control requirements of POPIA and the National Health Act. You may use biometric authentication (such as facial recognition or fingerprint) provided by your device to streamline login, but this does not extend your session beyond the inactivity timeout.
No system is completely secure. If we become aware of a security compromise, we will follow the breach notification process described in section 18 below.
Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device that help us understand how you use the Site, improve your experience, and deliver relevant advertising. Cookies do not themselves identify you personally. We use the following types of cookies:
(a) Essential cookies: required for the website and patient portal to function (e.g. session management, security tokens). These cannot be disabled without breaking core functionality.
(b) Analytics cookies: used to understand how visitors interact with the website. We use Google Analytics for this purpose. Google Analytics sets cookies that collect anonymised usage data (pages visited, time on site, referral source). Data is transferred to Google's servers in the United States.
(c) Marketing/advertising cookies: used to deliver relevant advertisements and measure campaign effectiveness. We use Google Ads and Meta Ads cookies on the website (not on the patient portal). These cookies allow Google and Meta to correlate your website activity with their advertising platforms. Data is transferred to servers in the United States.
(d) Debugging/performance cookies: Microsoft Clarity uses cookies and session recording technology to help us identify and fix technical issues. Microsoft may use anonymised and aggregated data from Clarity in its own analytics and advertising products.
Analytics, marketing, and debugging cookies load when you visit the website. In accordance with POPIA and GDPR best practice, we display a cookie notification that informs you of our use of cookies and provides you with the ability to opt out of non-essential cookies. You may opt out at any time by adjusting your cookie preferences via the notification banner, or by disabling cookies in your browser settings. If you opt out or disable non-essential cookies, some analytics and advertising features may not function, but core website and portal functionality will not be affected.
Where we introduce new processing activities that are likely to result in a high risk to your rights (for example, large-scale processing of health data, new automated decision-making, or new cross-border transfers), we conduct a data protection impact assessment before commencing the processing. This assessment identifies risks and the measures we take to mitigate them, in line with POPIA's accountability principle and GDPR Article 35.
If we become aware of a security compromise that has compromised, or is reasonably believed to have compromised, the confidentiality or integrity of your personal information, we will:
(a) notify the Information Regulator as soon as reasonably possible, as required by POPIA section 22 (aligned with the GDPR's 72-hour notification requirement to the supervisory authority);
(b) notify you without unreasonable delay, providing sufficient information to allow you to take protective measures; and
(c) take immediate steps to contain and remediate the compromise, and to prevent recurrence.
The Services are restricted to users aged 18 and older, consistent with the eligibility requirements in the Terms of Use and the age restrictions applied by the automated eligibility check. We do not knowingly collect personal information from anyone under 18. Under POPIA, a child is any person under the age of 18. If we become aware that we have collected personal information from a child without appropriate authorisation, we will take reasonable steps to delete that information promptly. If you believe a child has provided us with personal information, please contact our Information Officer immediately.
We will give you notice of any material change to this policy before it takes effect, consistent with the Terms of Use. Non-material changes (such as correcting typographical errors or updating formatting) may be made without notice. We encourage you to review this policy periodically.
If you are not satisfied with our response to a complaint, or you wish to lodge a complaint directly, you may contact the Information Regulator (South Africa):
Physical address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
Email: complaints@inforegulator.org.za.
Telephone: 010 023 5207.
Oryx Health Holdings (Pty) Ltd, Level 3A, Pearls Mall, Umhlanga, KwaZulu-Natal, 4319, South Africa. Email: support@oryx.health. Information Officer: Tom Chadwick, hello@oryx.health.