Privacy Policy (POPIA) – Sere-Health & myBP (Sere-med CC)

Effective date: 02/09/2026
Last updated: 02/09/2026

This Privacy Policy explains how Sere-med CC (the “Responsible Party” as defined in the Protection of Personal Information Act 4 of 2013 (“POPIA”)) processes personal information when you use the Sere-Health website (a division of Sere-med CC) and the myBP service available on or via the Sere-Health website (collectively, the “Services”).

Website: health.seremed.com
Trading/Division name: Sere-Health (division of Sere-med CC)

1) Contact details

If you have questions, requests, or complaints about privacy:

Sere-med CC (Sere-Health division)
Email: serehealth@seremed.com
Phone: 011 262 2220
Toll-Free Phone: 0800 622 220
Address: 8 Quark Crescent, Linbro Business Park, Sandton, Gauteng

You may also lodge a complaint with the Information Regulator (South Africa).


2) What personal information we collect

2.1 Website and account information

  • Name, surname

  • Email address, phone number

  • Username / account identifier (if you create an account)

  • Password (stored in encrypted/hashed form by the platform)

  • Address details (billing and delivery)

  • Order history and preferences (e.g., items ordered)

2.2 Order, payment, and delivery information (WooCommerce)

  • Products purchased and transaction details

  • Payment status and payment method

  • Proof of payment / EFT reference (where applicable)

  • Delivery and fulfilment information (e.g., courier details, tracking)

Note: We do not intentionally collect or store full card details on our servers. Card payments are handled by payment providers (see section 6).

2.3 myBP information (health-related / “special personal information”)

When you use myBP, you may submit:

  • Blood pressure readings (systolic, diastolic) and related measures (e.g., pulse, pulse pressure)

  • Date/time of reading

  • Notes/comments you add

  • Your identifying/contact details (if included in the form or account)

  • Doctor details you provide (e.g., doctor name, practice name, email address)

Health information is “special personal information” under POPIA and we treat it with extra care (see section 5).

2.4 Technical, usage, and security information

  • IP address

  • Browser type, device identifiers, and operating system (where available)

  • Date/time of visits, pages viewed, interactions

  • Login and security logs (e.g., failed login attempts)

2.5 Communications

  • Emails you send to us (support requests, queries)

  • Records of communications we send to you (order confirmations, service emails)

2.6 Comments and user-generated content (if enabled)

If we enable blog comments or reviews, we may collect:

  • Comment content

  • Name/display name, email address (if provided)

  • IP address and browser user agent to help detect spam

2.7 Media uploads (if enabled)

If we enable image/media uploads (e.g., profiles, forms, comments), we may process those files and associated metadata. We recommend you avoid uploading images with embedded location data (EXIF GPS).


3) Why we process personal information (purposes)

We process personal information for the following purposes:

3.1 To provide the Services

  • Create and manage your account

  • Process orders, payments, EFT confirmations, fulfilment, delivery, and returns

  • Provide customer support

  • Enable myBP submissions and send readings to the doctor you specify

3.2 To communicate with you

  • Transactional messages (order confirmations, shipping updates)

  • Service messages (password resets, account notices)

  • Responding to support requests

3.3 To improve and secure the Services

  • Website analytics and performance monitoring

  • Troubleshooting and error resolution

  • Preventing fraud, abuse, and unauthorised access

3.4 Marketing and measurement (where applicable)

  • Measuring campaign performance via UTM tracking

  • Analytics and tag management (e.g., GA4, GTM)

  • Advertising measurement tools (e.g., Meta Pixel) when implemented

Where required by law or platform rules, we will obtain consent for certain cookies/trackers (see section 10).


4) Lawful grounds for processing (POPIA)

We process personal information in line with POPIA on one or more of the following grounds, as applicable:

  • Consent (including explicit consent for health-related information where appropriate)

  • Performance of a contract with you (e.g., fulfilling orders; providing myBP functionality you request)

  • Legitimate interests (e.g., site security, fraud prevention, service improvement) balanced against your rights

  • Legal obligations (e.g., tax/accounting record-keeping where applicable)


5) Special personal information (myBP health data)

Blood pressure readings and related health information are treated as special personal information.

5.1 How myBP works

When you submit myBP information:

  • the information is stored in our systems (see retention in section 9); and

  • an email containing the information is sent to the doctor email address you provide, and may also be sent to you and/or to our administrative mailbox (serehealth@seremed.com) for operational oversight.

5.2 Access controls and confidentiality

You stated that access is strictly controlled. In practice, this means:

  • Access to myBP submissions is restricted to authorised Sere-med CC / Sere-Health personnel who require access to oversee and support the service.

  • The doctor who receives the email is the doctor you choose (by entering the doctor’s details).

  • You (the client) may receive a copy/confirmation where configured.

  • From time to time, approved partners/contractors may have access only where necessary for support/operations, and subject to confidentiality and security obligations.

5.3 Important email notice

Email is not guaranteed to be delivered instantly or at all (spam filters, server issues), and if you enter an incorrect doctor email address, the email may be sent to the wrong recipient. Once delivered to a doctor’s system, it will be handled under that recipient’s own security and privacy practices.


6) Who we share personal information with

We share personal information only as needed to operate the Services.

6.1 Service providers (“Operators” under POPIA)

We may use third parties to host and operate the website and services, including:

  • Website hosting providers

  • Email delivery / SMTP services

  • Security plugins/services (firewall, malware scanning)

  • Backup and performance tools

These providers process data on our instructions as Operators and are required to implement appropriate security safeguards.

6.2 Payment providers (WooCommerce)

We may use payment providers and gateways such as PayFast, and potentially Peach Payments, Stripe, PayPal, or others over time.

Payment processing is handled by the selected provider under their terms and privacy policies. We typically receive only the information needed to confirm payment (e.g., payment status, transaction reference), not full card details.

6.3 Couriers and fulfilment partners

We may share necessary delivery details (name, address, phone) with couriers or fulfilment partners to deliver your order.

6.4 Doctors (as chosen by you)

myBP information is shared with the doctor email address you provide.

6.5 Legal and safety disclosures

We may disclose information if required by law or to protect rights, safety, and security, in line with POPIA.

We do not sell personal information.


7) International transfers

Some service providers (hosting, email, analytics, security) may store or process data outside South Africa.

Where cross-border processing occurs, we take reasonable steps to ensure the recipient is subject to laws, contracts, or binding rules that provide an adequate level of protection consistent with POPIA.


8) Security safeguards

We implement reasonable technical and organisational measures to protect personal information, including:

  • HTTPS encryption in transit (where supported)

  • Strong access control to admin systems and mailboxes

  • Role-based permissions for staff

  • Security monitoring and logging

  • Regular software updates and patching where practicable

  • Backups and recovery measures (where applicable)

No method of transmission or storage is 100% secure. You should use strong passwords and keep your login credentials confidential.


9) Data retention

We keep personal information only for as long as necessary for the purposes described above, unless a longer period is required or permitted by law.

Typical retention periods (guidelines; adjust to your operational needs):

9.1 Ecommerce / orders

  • Order records, invoices, and related communications: as required for accounting/tax/legal purposes (commonly several years)

  • Customer account information: while the account remains active, and a reasonable period thereafter

9.2 myBP submissions (health-related)

  • myBP submissions stored in our systems: for 12 months or as operationally required

9.3 Logs and security data

  • Security logs and audit records: up to 24 months (or longer if needed for investigations)

If you request deletion, we will consider the request in line with POPIA and any legal obligations to retain certain records.


10) Cookies, analytics, and tracking

We use cookies and similar technologies for site functionality, security, and measurement.

10.1 Essential cookies

These are required for core site features such as login sessions, shopping cart functionality, and security. Disabling them may cause the site to stop working properly.

10.2 Analytics and tag management

You indicated you use:

  • UTM tracking

  • Google Analytics 4 (GA4)

  • Google Tag Manager (GTM)

These tools help us understand traffic and improve the Services. Depending on configuration, they may collect device and usage data, including IP address (often in truncated or controlled ways depending on settings).

10.3 Advertising pixels (future)

You indicated you may implement tools such as:

  • Meta Pixel and other similar marketing/advertising measurement technologies

Where required, we will implement appropriate consent mechanisms and provide choices.

10.4 Managing cookies

You can manage cookies in your browser settings. If we implement a cookie consent banner, you will be able to manage preferences there as well.


11) WordPress features: comments, embedded content, and Gravatar

11.1 Comments (if enabled)

If visitors leave comments, we may collect the data shown in the comment form, plus IP address and browser user agent for spam detection.

If we use Gravatar, an anonymised string (hash) of your email address may be shared with Gravatar to display an avatar. (Gravatar is operated by Automattic.)

11.2 Embedded content from other websites

Pages may include embedded content (e.g., videos, images, articles). Embedded content behaves as if you visited the other website directly, and those websites may collect data, use cookies, and track interactions.


12) Your rights under POPIA

Subject to POPIA and certain limits/exceptions, you may request to:

  • Access the personal information we hold about you

  • Correct or update your information

  • Delete personal information where applicable

  • Object to certain processing

  • Withdraw consent (where processing is based on consent)

To make a request, contact serehealth@seremed.com. We may require identity verification before fulfilling a request.


13) Where your data is sent

Depending on site features enabled:

  • Visitor comments may be checked through an automated spam detection service.

  • Analytics and tag tools may send data to their platforms.

  • Payment processing sends relevant data to the selected payment provider.

  • myBP submissions are emailed to the doctor you specify and may be copied to authorised internal mailboxes for oversight.


14) Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date will change. Continued use of the Services after an update means you accept the revised policy.