Back to Home

Privacy Policy

Last updated: July 2026 (revision 4)

1. Introduction

Baselayer.med ("we", "our", or "us") is committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and other applicable data protection laws.

This Privacy Policy explains how we collect, use, store, share and protect personal information when practices and their staff use our cloud-based practice management platform (the "Platform"). The Platform serves dental, general practitioner, biokineticist, chiropractic, cardiac physiology, psychology, anaesthetic and aesthetic practices, and includes consent and clinical document generation, appointment scheduling, dental charting, body charting, spine charting, observation charts, injection mapping, patient records, chronic-medication tracking, pathology lab-result capture, a built-in billing engine with scheme-linked tariff and NAPPI reference data (via MedPrax), optional accounting and medical-aid integrations, stock and lab-case tracking, practice analytics, an AI Copilot / command palette for drafting clinical and billing documents, telehealth video consultations on supported verticals (currently general practitioner, cardiac physiology, psychology, anaesthetics and aesthetics), practice data export, and patient communications.

2. Information We Collect

We collect the following categories of personal information:

  • Identity Information: Full name, title/gender, SA ID number, passport number, date of birth, file number
  • Contact Information: Phone number, email address, physical address, WhatsApp number, emergency contact details
  • Guardian Information: For child / dependant patients, guardian name, contact details, ID number and relationship
  • Medical Information: Medical history, allergies, current medications, chronic medication regimens, medical conditions, pregnancy/bleeding flags, medical aid details (scheme, plan, member number, dependant code, main member)
  • Biometric Information: Digital signature and (where the patient has been photographed by the practice) patient photographs
  • Clinical and Treatment Information: Treatment type, procedure details, consent records, clinical findings, recommendations, referral details, dental implant data, medical certificates, lab work specifications, patient reports, and patient ICD-10 / diagnostic codes maintained by the practice
  • Pathology Lab Results: Uploaded pathology reports (PDF or image) from laboratories such as Ampath, Lancet or similar, together with structured analyte values, units, reference ranges, flags and narrative findings extracted (with practitioner review) and stored against the patient file; the original report file is retained as a patient document
  • Chronic Medication Records: Ongoing / chronic medication entries linked to a patient, including drug name, NAPPI code where resolved, dose, frequency, regimen grouping and related notes authored by the practice
  • Patient Photographs & Imagery: Intra-oral photographs, before/after photographs and other clinical images uploaded by the practice and linked to a patient's file
  • Dental Charting Data: Odontogram and periodontal charts, including per-tooth marks, surfaces, conditions, layers (existing / proposed / completed), pocket depths, furcations, mobility and chart-level summary notes
  • Clinical Overview: Patient history notes, follow-ups, phone-call notes, general notes, visit records and (where enabled for the vertical) charting data authored or maintained by Practitioners within the Clinical Overview feature
  • Voice Recordings (transient): Audio captured by the in-app dictation feature (including live voice input in the command palette) is sent to a third-party transcription service to produce text. Audio is not retained by Baselayer.med after transcription
  • Telehealth Session Metadata: Where the practice uses the telehealth video consultation feature on a supported vertical, we record session metadata such as the linked appointment, the practitioner, the patient name and join token, scheduled start and end times, actual start, join and end timestamps, the duration of the session, whether the patient consented to recording (and the timestamp of that consent), and basic technical signals required to establish and audit the call
  • Telehealth Recordings (opt-in): Where the practice elects to record a telehealth session and the patient has consented for that session, the audio and video of the session is captured and stored as a recording file. Recordings are stored in our managed object storage scoped to the issuing practice. Where no recording is opted in, the live audio/video stream is delivered in real time through the telehealth video provider and is not retained by Baselayer.med
  • Telehealth Transcripts & AI-drafted SOAP Notes: Where the practice instructs the platform to transcribe a telehealth recording, the recording is sent to a third-party speech-to-text provider to produce a transcript, and the transcript may then be summarised by an AI provider into a draft SOAP / clinical note for the practitioner to review, edit and accept
  • Appointment Data: Appointment dates, times, doctor assignments, appointment types, recurrence, patient names, contact details and appointment notes (including a flag for telehealth appointments); reminder delivery status
  • Stock-Take Data: Stock categories, items, lots, suppliers, opening/added/sold/practice-use/reserved/needed counts, supplier invoices, reorder thresholds, and (where the practice tracks bookings) the patient name or unknown-patient flag linked to a stock booking or procedure usage
  • Lab Case Tracker Data: Dental laboratory case records including lab, due dates, priority, delivery status and related notes; optional due-date alert preferences
  • Practice Tasks: Weekly task lists with content and authoring metadata
  • Billing & Financial Information: Quotes, invoices and payment records created in the built-in Baselayer Billing engine or via a connected external accounting service; line items, dental/medical procedure codes, NAPPI product codes, ICD-10 codes, tariff amounts, scheme-linked rates, tax, due dates, balances, billing templates and patient billing details
  • MedPrax Reference Lookups (cached): On-demand lookups of tariff codes, scheme/plan options, medicine and product (NAPPI) catalogue rows, SEP / rate slices and related reference metadata retrieved from the MedPrax clinical and billing data service. Lookups are demand-driven and cached only for a short TTL; they are not a standing full copy of the MedPrax corpus
  • Medical Aid Claim Data: Where the practice submits electronic claims via a medical-aid switching service, claim payloads include patient identity, scheme/plan/member/dependant codes, treatment codes, ICD-10 codes, amounts, destination codes and the resulting acknowledgement / rejection / status response
  • Saved Payment Card Data: Card number, cardholder name, bank, card type and expiry date stored for autofill on supplier forms (CVV/CVC is never stored)
  • Subscription & Payment Data: When a practice subscribes to Baselayer.med, our subscription provider collects bank account / card mandate data and processes recurring debit orders or card payments. We retain subscription status, plan, billing dates, mandate references and invoice records
  • Communication Data: Email and WhatsApp messages sent by the platform on behalf of the practice (patient instructions, appointment reminders, document delivery); internal signup / operational WhatsApp alerts to Baselayer.med staff where configured
  • Account & Authentication Data: User name, email, role, practice membership, hashed password (held by the authentication provider), session tokens and password-reset metadata
  • Practice Configuration: Practice name, logo, vertical (dental / GP / biokinetics / psychology / anaesthetics / aesthetics), form customisations, instruction templates, role assignments, directories (specialists, medications, labs), MedPrax Service Addendum acceptance records (acceptor identity, timestamp, IP / user-agent and practice snapshot), notification preferences (e.g. stock reorder and lab due-date alerts)
  • Practice Export Archives: Where an authorised owner or admin requests a practice data export, a zip archive of practice-scoped tables and files is written into the practice's own object-storage prefix and made available via a short-lived signed URL
  • Technical & Audit Information: Device type, browser, IP address, timestamps, activity logs (which document was created, viewed, sent, or modified, and by whom) and AI-agent invocation logs
  • Marketing Information (opt-in only): Email address and source for newsletter subscribers, and demo-booking conversations conducted via WhatsApp

3. Purpose of Collection

We collect personal information for the following purposes:

  • To obtain, record and store informed consent for medical and dental treatments
  • To enable healthcare providers to maintain patient records, charts, chronic medications, lab results and visit history
  • To generate clinical documents (consent forms, prescription scripts, referrals, lab forms, implant reports, medical certificates, patient reports and post-operative instructions), including AI-assisted drafts that the practitioner must review and accept
  • To create and store dental charting records (odontogram and periodontal charts) and link them to patient files, including AI-assisted chart drafts grounded in clinical notes where the practitioner requests them
  • To capture and store patient photographs and imagery linked to a patient's file
  • To upload, extract and store pathology lab results (including AI-assisted extraction from Ampath, Lancet or similar reports) for practitioner review
  • To maintain chronic medication regimens against a patient file, including AI-assisted drafts from clinical notes
  • To provide voice dictation by transcribing audio captured in the app (including the command palette) into text the practitioner can review
  • To run an AI medication safety check that flags potential allergies, interactions, contraindications, pregnancy / bleeding risks and (where available) scheme-exclusion or schedule context against the patient's recorded profile and NAPPI active ingredients
  • To resolve NAPPI codes, active ingredients, drug schedules and scheme-linked tariff / product rates via the MedPrax clinical and billing data service, under the MedPrax Service Addendum accepted by the practice
  • To create, store, send and track quotes, invoices and payments using the built-in Baselayer Billing engine (including multi-template billing and AI-assisted quote / invoice drafts), and (optionally) to mirror those records into a connected external accounting service
  • To submit electronic medical-aid claims and receive responses through a medical-aid switching service when the practice elects to do so
  • To manage appointments, send appointment reminders by WhatsApp, and (optionally) sync practitioner calendars with a supported third-party calendar service
  • To facilitate telehealth video consultations between a practitioner and a patient on supported verticals, including issuing the patient's join link, establishing the live audio and video connection through a third-party real-time video infrastructure provider, and logging session metadata for audit and billing purposes
  • Where the practice elects to record a telehealth session and patient consent is obtained, to store the recording in our managed object storage and (on the practitioner's instruction) to transcribe it and generate an AI-drafted SOAP / clinical note for the practitioner's review
  • To track practice stock levels, reservations, supplier invoices and reorder alerts, and to link stock bookings to patient visits where the practice has enabled that feature
  • To track dental laboratory cases and optional due-date alerts
  • To send patient communications (documents, post-operative instructions, reminders) by email and WhatsApp
  • To produce practice analytics, including aggregated dashboards on patient demographics, billing performance, treatment mix, team activity and retention, optional monthly practice performance report emails, and (optionally) AI-generated narrative insights based on those aggregates
  • To allow authorised owners / admins to export a practice-scoped archive of tables and files for backup, migration or offboarding
  • To process subscription payments and recurring debit orders for the Platform subscription
  • To provide the AI Writing Assistant, AI Copilot / command palette, and AI Chatbot features
  • To maintain audit trails of data access and modifications for security and POPIA compliance
  • To send marketing communications (newsletter) only to recipients who have explicitly opted in
  • To comply with legal, regulatory and professional-body requirements, and with MedPrax licensee reporting obligations (Licensee Certificate and monthly client register) where the practice has accepted the MedPrax Service Addendum

4. Legal Basis for Processing

We process your personal information based on:

  • Consent: Patients provide explicit consent when submitting a consent form, and additional consent (e.g. for WhatsApp communications, photography or medical-aid claim submission) is captured by the treating practice where required
  • Contract: Processing is necessary to deliver the practice management service contracted for by the subscribing practice and its users
  • Legal Obligation: Healthcare providers are legally required to obtain and retain informed consent and to keep accurate medical records
  • Legitimate Interest: Maintaining accurate medical records for patient safety, securing the Platform, preventing fraud, and providing essential analytics and audit trails to the practice

5. Data Storage and Security

Patient records, documents, charts, billing data and configuration are stored in Baselayer.med's managed cloud database and object storage, hosted on enterprise-grade infrastructure provided by our database, storage and hosting partners. Where the practice has connected an external accounting service, billing data may also be synced to that service.

Your information is protected through:

  • Industry-standard encryption for all data in transit (HTTPS/TLS) and encryption at rest provided by our cloud database and storage partners
  • A managed object-storage bucket holding all generated PDFs, photographs and uploaded files, scoped per practice and accessed only via short-lived signed URLs minted by authenticated server endpoints
  • Database-level row isolation ensuring data belonging to one practice cannot be read or modified by another
  • Authenticated API access requiring valid session tokens for every protected endpoint
  • Practice membership verification ensuring users can only access data for their authorised practice
  • Role-based access controls limiting data access to authorised users (admin, doctor / practitioner, hygienist / nurse / assistant, staff)
  • Server-side-only access for sensitive data (e.g. payment card details and medical-aid switch credentials are never exposed to the browser)
  • Browser security policies (CSP, HSTS and related headers) restricting which external resources can load
  • Input validation, sanitisation of rich-text content, and rate limiting on all public and authenticated endpoints
  • Comprehensive activity logging for document creation, sending and modification
  • An immutable audit trail recording which user accessed or modified patient data, including IP address and timestamp
  • An AI-agent invocation log recording every automated agent run, the model used, and a summary of the inputs and outputs
  • Regular security assessments and dependency updates

Telehealth video and recordings.Live telehealth audio and video is delivered in real time through a third-party real-time video infrastructure provider on Baselayer.med's behalf. The live stream itself is not stored by Baselayer.med. Where the practice opts in to record a session and the patient has consented for that session, the resulting recording file is written to our managed object storage, scoped to the issuing practice, and is accessible only to authorised users via short-lived signed URLs minted by authenticated server endpoints.

Our hosting, database, storage, AI, messaging, accounting, real-time video, MedPrax and medical-aid switching partners may operate servers located outside South Africa. We require all such partners to apply equivalent data-protection standards and to process data only on documented instructions.

6. Data Retention

Consent forms, clinical records, charting data, patient notes, pathology lab results, chronic medication records, billing records and related medical records are retained for a minimum of 7 years from the date of treatment, or longer if required by law, by professional-body rules, or for ongoing medical care.

Voice recordings used for dictation are not retained: audio is streamed to the transcription service, the resulting text is returned to the practitioner, and the recording is discarded.

MedPrax reference cache rows are retained only for the short licence-compliant TTL and are purged thereafter; they are not clinical records of the practice.

Practice export archives stored under the practice's object-storage prefix remain until the practice deletes them or until the applicable retention / offboarding process removes practice data.

Audit logs and AI-agent invocation logs are retained for at least the same period as the underlying records they relate to.

Marketing newsletter subscribers can unsubscribe at any time, after which their record is deleted from the marketing audience.

After the applicable retention period, data will be securely deleted or anonymised.

7. Data Sharing and Sub-Processors

We share personal information only with the following categories of recipient, and only to the extent necessary to deliver the Platform:

  • The healthcare provider / practice where the patient was seen (the data controller for clinical data)
  • Cloud database, storage and hosting providers for secure document hosting, database operations and serving the application
  • Authentication provider for user account management, password handling and session security
  • Email delivery provider for sending documents, instructions, appointment reminders, system emails and (for opt-in subscribers only) newsletters
  • Messaging provider for delivering WhatsApp messages, patient instructions, appointment reminders and demo-booking conversations
  • AI service providers for the AI Writing Assistant, AI Copilot / command palette (clinical and billing drafts), AI Chatbot, AI medication safety check, voice transcription, telehealth-recording transcription, AI-drafted SOAP / clinical notes from telehealth transcripts, pathology lab-result extraction, invoice / quote document reading, and the analytics "AI insights" summary. Only the specific text, audio or document content required for each task is transmitted; full patient records are not sent as a bulk dump
  • Real-time video infrastructure provider for delivering the live audio and video connection of telehealth sessions on supported verticals. The provider transmits the live stream between practitioner and patient; the live stream itself is not stored by the provider, and recordings (when opted in) are written to our managed object storage rather than to the provider
  • MedPrax clinical and billing data service for on-demand tariff, scheme, medicine and NAPPI product lookups used in billing and prescribing workflows. Query parameters and returned reference rows may be cached briefly under the MedPrax licence; patient clinical free-text is not sent to MedPrax for catalogue search
  • External accounting service providers when the practice has connected one, patient names and billing details are shared as part of invoice and payment creation. The built-in Baselayer Billing option keeps this data inside our own managed cloud database and does not share it with an external accounting service
  • Medical-aid switching service when the practice elects to submit electronic claims, claim payloads (including patient identity, scheme membership and treatment details) are transmitted to the switch and forwarded to the relevant scheme
  • Subscription / payment provider for processing the practice's Baselayer.med subscription via debit-order or card payment
  • Calendar integration provider only when a practitioner has explicitly connected a third-party calendar
  • Marketing-site analytics providers (industry-standard search and web analytics tools) used only for the public marketing website (baselayer.med), these do not receive patient or clinical data
  • Legal authorities when required by law or to protect the rights, safety or property of patients, practices, or Baselayer.med

We do not sell your personal information to third parties, and we do not use patient or clinical data for advertising.

8. Your Rights

Under POPIA, you have the right to:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your information (subject to legal retention requirements applicable to medical records)
  • Objection: Object to processing of your information
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
  • Complaint: Lodge a complaint with the Information Regulator of South Africa

To exercise these rights, contact the healthcare practice where you submitted your consent form (the data controller for your clinical data), or contact us using the details in section 22.

9. AI Features

The Platform includes several AI-powered features provided by third-party AI service providers. In every case, the AI does not make clinical decisions and the practitioner remains responsible for any output that is acted upon.

Responsible Party and Operator Relationships: The healthcare practice remains the responsible party for all patient information processed through the Platform, as defined under POPIA. Baselayer.med and any third-party AI or software provider involved in processing that information acts as an operator or service provider, where applicable, and processes data only on documented instructions from the responsible party. Patient information may not be used by any AI or software provider for purposes unrelated to the service being provided, including marketing, model training, or onward sharing, unless separately disclosed to the practice and legally permitted. POPIA places duties on the responsible party (the practice) to maintain appropriate safeguards and to manage operator relationships securely, including ensuring that data-processing agreements or equivalent contractual protections are in place with all operators handling patient data.

AI Writing Assistant

  • Only the specific text content of the field being polished (e.g. clinical findings, recommendations, or treatment notes) is sent to the AI provider for processing. Full patient records, names, ID numbers, or other personal identifiers are not transmitted.
  • AI-generated suggestions are presented to the practitioner for review and must be explicitly accepted before replacing the original text.
  • The AI provider processes data via their API, which is configured not to use submitted data for model training.
  • The AI does not add medical information that was not present in the original text. All clinical content remains the responsibility of the practitioner.

AI Chatbot

  • The AI Chatbot provides general assistance with using the Platform. It does not provide medical advice.
  • Conversation content is transmitted to and processed by the AI provider. Users should not enter patient personal information, clinical details, or other sensitive data into the chatbot.
  • The AI provider processes chatbot data in accordance with their API data-usage policies and does not use API-submitted data for training.

AI Medication Safety Check

  • When a practitioner is prescribing, the medication name, any resolved NAPPI active-ingredient descriptions already attached to the script entry, and a non-identifying summary of the patient's allergies, current medications, conditions, pregnancy status and bleeding history are sent to the AI provider to surface potential allergy, interaction, contraindication, pregnancy and bleeding-risk concerns.
  • Where scheme-exclusion or drug-schedule context is available from MedPrax / practice catalogue data, it may be shown to the practitioner as an advisory warning. It is not a guarantee of medical-aid cover or of schedule compliance.
  • The patient's name, ID, contact details or other direct identifiers are not transmitted.
  • The output is advisory only. The prescribing practitioner is solely responsible for the prescription.

AI Copilot / Command Palette (Clinical & Billing Drafts)

  • The command palette (Cmd+K / Ctrl+K) and related Copilot agents can draft clinical and billing documents from the practitioner's instruction and from selected practice-held context (for example recent clinical notes, implant details, odontogram marks, chronic-medication history, or billing catalogue hints). Draft types may include scripts, referrals, medical certificates, patient reports, implant reports, chronic-medication regimens, chart / body-map suggestions, follow-up notes, and quote / invoice line suggestions (including NAPPI consumables where applicable).
  • Only the minimum context required for the requested draft is sent to the AI provider. Direct identifiers are minimised where practicable; practitioners should avoid pasting unnecessary identifiers into free-text prompts.
  • NAPPI codes and MedPrax catalogue enrichment for drafted medications or products are typically resolved after the model response (post-draft lookup against the practice directory, short-TTL cache, or live MedPrax API). MedPrax corpus data is not used to train models.
  • All drafts are presented for review. The practitioner must edit and explicitly accept a draft before it becomes part of a clinical record, prescription, referral, certificate, report, chart or billing document. Declined or empty drafts are not saved as clinical content.
  • Live voice input in the command palette is transcribed via the same third-party speech-to-text path as Voice Dictation; audio is not retained after transcription.

Pathology Lab-Result Extraction

  • When a practitioner uploads a pathology report (PDF or image), the file is stored as a patient document and the content (extracted text or image) is sent to an AI provider to propose structured analyte lines, units, reference ranges and narrative findings.
  • The extraction is a draft only. The practitioner must review, correct and accept results before they are relied upon clinically. The AI does not invent values that cannot be read from the source document.
  • The AI provider processes data via their API, which is configured not to use submitted data for model training.

Invoice / Quote Document Reading

  • Where the practice uploads a supplier or clinical invoice / quote for AI-assisted capture, the document content is sent to an AI provider to propose line items, codes and amounts for practitioner review before any stock booking or billing record is created.
  • Accepted suggestions remain the practice's responsibility; Baselayer.med does not verify supplier invoices or clinical billing accuracy.

Voice Dictation / Transcription

  • When a practitioner uses the in-app dictation tool, the recorded audio is streamed to a third-party speech-to-text service and the resulting transcript is returned to the practitioner for review.
  • Audio is not stored by Baselayer.med after transcription. The practitioner must review and accept the transcribed text before it is saved into a clinical record.
  • Practitioners should avoid dictating direct identifiers (e.g. ID numbers, full names of third parties) where this is not clinically necessary.

Telehealth Transcripts & AI-drafted SOAP Notes

  • Where a telehealth session has been recorded (with patient consent for that session) and the practitioner instructs the platform to transcribe it, the recording is sent to a third-party speech-to-text provider to produce a text transcript.
  • The transcript may then be summarised by an AI provider into a draft SOAP / clinical note, structured into the standard subjective, objective, assessment and plan sections. Only the transcript text is sent to the AI provider for this step — the underlying audio/video is not.
  • The transcript and the AI-drafted note are presented to the practitioner for review. The practitioner must read, edit and explicitly accept the draft before it is saved into the patient record. AI-drafted notes are advisory drafts only and do not constitute medical advice or a clinical record on their own.
  • The AI provider processes data via their API, which is configured not to use submitted data for model training.

Practice Analytics & AI Insights

  • The analytics dashboard is computed entirely inside our own database from the practice's existing records. No patient-level data is sent to a third party for the dashboard itself.
  • If the practice opts to generate AI narrative "insights", only aggregated, non-identifying summary numbers (counts, percentages, top categories) are sent to the AI provider, never patient names, contact details, identifiers or clinical free-text.
  • Insights are advisory only and must not be relied upon for clinical or financial decisions.

10. MedPrax Clinical & Billing Reference Data

Where the practice uses MedPrax-backed tariff, scheme, medicine or NAPPI product lookups, Baselayer.med retrieves reference data from the MedPrax clinical and billing data service under a licence between Baselayer.med and MedPrax. Practices accept the MedPrax Service Addendum (or an equivalent incorporation into these Terms) before using those features.

  • Lookups are live-first and demand-driven. We may cache small result sets for a short time-to-live (currently up to six days) and purge stale rows; we do not maintain a standing full copy of the MedPrax corpus.
  • Acceptance of the Addendum is recorded (acceptor name and email, timestamp, IP / user-agent, practice snapshot and Addendum version). Baselayer.med may generate a Licensee Certificate and a monthly client register for MedPrax as required by the licence.
  • MedPrax data must not be used to train, fine-tune or calibrate any AI model. Inference-only use of small amounts of MedPrax-derived text (for example tariff descriptions or NAPPI active-ingredient names already attached to a script line) is permitted only where the AI provider is contractually restricted from training on API inputs.
  • Scheme rates, SEP figures, NAPPI matches, drug schedules and exclusion flags are reference aids only. The practice remains responsible for verifying codes, prices and cover before billing or prescribing.
  • MedPrax remains the owner of its licensed data. Practices may not scrape, bulk-download, redistribute or commercially exploit MedPrax data outside the Platform's intended workflows.

11. Lab Results & Chronic Medications

On supported verticals (notably general practitioner practices for pathology results, and prescribing verticals for chronic medications), the Platform stores practitioner-managed clinical tracking data against the patient file.

  • Lab results: Uploaded pathology reports and any accepted structured extraction are stored in our managed cloud database and object storage, scoped to the issuing practice. Original files are retained as patient documents (category lab_result).
  • Chronic medications: Regimen entries (drug, dose, frequency, NAPPI where resolved, grouping and notes) are stored against the patient and may be drafted with AI assistance from clinical notes, subject to practitioner review.
  • Hard-delete of lab results or chronic medications, where offered, permanently removes those practice-held records subject to any legal retention duty that still applies to related clinical documentation.
  • The treating practice remains the data controller for this content and is responsible for clinical accuracy, patient communication of results, and any onward sharing with other clinicians.

12. Built-in Baselayer Billing

Baselayer.med includes a built-in billing engine ("Baselayer Billing") that allows practices to create, send and track quotes, invoices and payment records inside the Platform without using an external accounting service.

  • Quotes, invoices, line items, procedure / tariff codes, ICD-10 codes, amounts, taxes, dates, balances and patient billing details are stored in our managed cloud database, scoped to the issuing practice.
  • Invoice and statement PDFs may be emailed to the patient via our email delivery provider on behalf of the practice.
  • The practice remains responsible for the accuracy of all billing information, including procedure codes, tariffs, taxes and patient details.
  • Practices may switch between Baselayer Billing and a connected external accounting service at any time. Historical records remain associated with the provider that created them.

13. External Accounting Integrations

Practices may optionally connect their own account with a supported third-party accounting service instead of, or alongside, Baselayer Billing.

  • When such an integration is enabled, patient names and billing details (procedure codes, amounts, dates, line items) are shared with the connected accounting service to create customers, quotes, invoices and payment records.
  • The practice's OAuth connection credentials and refresh tokens are stored securely in our database and used only to call the relevant accounting API on the practice's behalf. The practice can disconnect at any time.
  • Beyond what is needed to facilitate the integration, Baselayer.med does not retain copies of the records held in the external accounting service. The source of truth for those records is the practice's account with the accounting provider.
  • The accounting service provider processes billing data in accordance with its own privacy policy and terms of service.

14. Electronic Medical-Aid Claims

Where the practice has elected to submit electronic medical-aid claims through Baselayer.med, claims are transmitted to a medical-aid switching service which routes them to the relevant medical aid scheme.

  • Claim payloads include the patient's identity details, the scheme, plan and main-member / dependant information, ICD-10 codes, treatment / tariff codes, line amounts, the destination code for the chosen scheme and the issuing practitioner's practice and provider numbers.
  • The switching service's acknowledgement, status and remittance responses are stored against the corresponding invoice for the practice's reference.
  • Per-practice switch credentials are stored securely server-side and are never exposed to the browser.
  • Each claim is initiated by the practice. Baselayer.med does not adjudicate, approve or guarantee any claim and is not the medical aid scheme or its agent.

15. Saved Payment Card Data (Supplier Forms)

Practices may optionally store payment card details for use with internal supplier forms:

  • Card details (number, cardholder name, bank, type, expiry) are stored in our secure database with access controls ensuring data isolation between practices.
  • CVV/CVC is never stored. It must be entered manually each time a supplier form is submitted.
  • Card data is accessible only via server-side API routes using the service-role key. It is never exposed directly to the browser.
  • Admins can add, edit, deactivate, or delete stored cards at any time from Practice Settings.
  • Saved card data is used only for the practice's own supplier forms and is never used to charge a patient.

16. Subscription Payments

Subscription fees for Baselayer.med are processed by a third-party payment provider that supports debit orders and card payments.

  • Bank-account or card details captured at sign-up are submitted directly to the payment provider; Baselayer.med does not store full bank-account or card numbers used for the platform subscription.
  • The payment provider returns a mandate / consent reference which we store against the practice record so we can request scheduled debits.
  • We retain subscription status, plan, billing dates, mandate references, invoice records and any failed-payment reasons for accounting and dispute-handling purposes.
  • Practices may receive subscription reminder emails and invoice PDFs.

17. Patient Communications & WhatsApp

The Platform sends patient communications by email and WhatsApp on the practice's behalf, using a third-party messaging service:

  • WhatsApp messages are sent using pre-approved templates and are initiated by the practice.
  • The patient's phone number is shared with the messaging provider solely for the purpose of message delivery and reminder workflows.
  • Message content is limited to post-operative instructions, appointment reminders, and document delivery as authorised by the practice.
  • Where automated appointment reminders are enabled, a scheduled task sends a single reminder per active appointment in a defined window before the appointment time.
  • Patients should direct any clinical questions to the treating practice, not to the WhatsApp number used for delivery.
  • Baselayer.med may also send internal operational WhatsApp alerts (for example new practice sign-ups) to Baselayer.med staff. Those alerts are not patient clinical communications.

18. Practice Export & Performance Reports

Authorised practice owners and admins may request a full practice data export. Separately, the Platform may email aggregated monthly practice performance reports to the practice.

  • Exports package practice-scoped database tables and files into a zip archive written under the practice's own object-storage prefix and returned via a short-lived signed URL. Doctors and staff cannot initiate exports.
  • Export archives inherit the same access controls and retention practices as other practice files. The practice is responsible for securing any copy it downloads.
  • Monthly performance report emails contain aggregated practice metrics appropriate to the configured vertical. They are sent to practice contacts configured for that purpose and do not replace clinical records.

19. Marketing & Newsletter

Marketing communications are sent only to recipients who have explicitly opted in via the public marketing website. Patients of subscribing practices are not added to marketing audiences as a result of using the Platform clinically.

  • Newsletter subscribers' email addresses are stored with our email delivery provider's audience service.
  • Subscribers may unsubscribe at any time using the link in any newsletter or by contacting us.
  • The public marketing site uses industry-standard search and web analytics tooling only to measure marketing performance. These tools do not receive any patient or clinical data.

20. Psychology Vertical — Limits of Confidentiality, Telehealth & Crisis Resources

Where the Platform is configured for a psychology practice, the Psychology Consent Form captures additional data points alongside the standard demographic and clinical fields, including the patient's acknowledgement of the limits of confidentiality (such as harm-to-self/others, mandatory reporting under the Children's Act, and disclosure required by court order), and the patient's baseline opt-in or opt-out of telehealth sessions and any session-recording policy.

  • The acknowledgement and opt-in fields are stored alongside the rest of the consent form record in our managed cloud database, scoped to the issuing practice.
  • Telehealth sessions on the psychology vertical are now provided as a built-in Platform feature. The live audio and video of a session is delivered through a third-party real-time video infrastructure provider on Baselayer.med's behalf. The live stream is not stored.
  • Recording remains opt-in per session. The Psychology Consent Form opt-in is a baseline acknowledgement; the practitioner must additionally confirm the patient's consent to recording at the start of any session that is to be recorded. Where a session is recorded, the audio/video file is stored in our managed object storage scoped to the issuing practice, and is accessible only to authorised users via short-lived signed URLs.
  • Where the practitioner instructs the platform to transcribe a recording, the recording is sent to a third-party speech-to-text provider to produce a transcript, which may then be summarised by an AI provider into a draft SOAP / clinical note for the practitioner to review, edit and accept (see section 9).
  • The treating practice remains the data controller for any telehealth recording, transcript and resulting clinical note, and is responsible for retention, withdrawal-of-consent handling, access management and any subsequent deletion request.
  • Decisions about mandatory reporting or disclosure under the limits of confidentiality are made by the treating Practitioner outside the Platform. Baselayer.med does not detect, advise on, or trigger any such disclosure, and does not contact emergency services, designated persons, facilities or any third party on the Practice's behalf.
  • Crisis-resource references (for example, SA Police Service 10111, ambulance 10177, SADAG and similar services) reproduced in patient instruction templates are public information for patient-facing reference only. They are not integrations: no patient data is transmitted to those services through the Platform.

21. Cookies & Local Storage

The Platform uses essential cookies and browser local storage for authentication, session management, kiosk-device identification (a per-device ID), remembering the user's last selected practice, and short-lived handoff state for AI draft workflows (for example sessionStorage keys used to auto-open a drafted form after navigation). Marketing pages may use additional analytics cookies; these are not used inside the authenticated practice management application. We do not use advertising or cross-site tracking cookies.

22. Information Officer

For any privacy-related queries or to exercise your data rights, please contact:

Information Officer

Email: hello@baselayer.med

23. Changes to This Policy

We may update this Privacy Policy from time to time, particularly when new features, sub-processors or integrations are added. Material changes will be posted on this page with an updated revision date and, where appropriate, communicated to practice administrators within the Platform. Operator / processor obligations when we process personal information on behalf of a practice are set out in our Data Processing Agreement.

24. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Baselayer.med

Email: hello@baselayer.med