Privacy Statement

Privacy Notice (POPIA)

Responsible party and contact details

Outliv Longevity (Pty) Ltd - 2026/236646/07 trading as OUTLIV, is the responsible party for membership, Platform, account, payment, support, coordination, security and business-administration processing it determines.

The identified Clinical Provider, laboratory, imaging provider, pharmacy or specialist may be a separate responsible party for its clinical, diagnostic, dispensing or professional records. In some workflows OUTLIV may act as an operator for a Clinical Provider, or the provider may act for OUTLIV. Written agreements and this Notice must reflect the actual role; labels do not override the facts.

Laws and principles

We process personal information under the Protection of Personal Information Act, 2013 (“POPIA”), the National Health Act, 2003, applicable professional rules and other South African law. We apply accountability, processing limitation, purpose specification, further-processing compatibility, information quality, openness, security safeguards and data-subject participation.

Health, genetic and biometric information is special personal information. We process it only where POPIA authorises the processing, including as necessary for treatment, care, health-service administration, legal or professional duties, or with valid consent where required, and subject to confidentiality safeguards.

Personal information we collect

Where information comes from

We collect information from you; an authorised representative; the Clinical Provider; laboratories, imaging providers, pharmacies and specialists; a sponsor for eligibility and payment; payment and identity providers; supported devices you connect; and public or official sources where lawful and necessary. We will not obtain clinical information from an employer merely because it sponsors membership.

Why and on what basis we process information

PurposeTypical informationPOPIA justification
Create and administer membershipIdentity, contact, account, order, paymentContract; legitimate interests; legal duties
Coordinate testing and clinical careHealth history, orders, results, provider dataHealth-service authorisation; contract; consent where required
Provide secure access and supportCredentials, audit logs, communicationsContract; security and legitimate interests
Process payment and prevent fraudTransaction and verification dataContract; legal duties; legitimate interests
Communicate service informationContact, booking and status dataContract and service administration
Improve quality and operationsDe-identified or appropriately minimised usage and service dataLegitimate interests compatible with original purpose
Comply with law and professional dutiesRecords, tax, complaints, security eventsLegal obligation; establishment or defence of rights
Send marketingContact and channel preferencesSeparate consent or another lawful basis, with opt-out
Research using identifiable informationOnly the specifically approved datasetSeparate consent and any required ethics approval

Where processing is necessary to conclude or perform the membership or clinical service, failure to provide essential information may mean we cannot safely or lawfully provide it. Optional information and optional consents are identified separately.

Sharing and recipients

We disclose only information reasonably necessary for the relevant purpose, including to:

We do not sell personal health information. We do not disclose identifiable clinical results, diagnoses, prescriptions, consultations or protocols to an employer merely because it funds the programme. Employer reporting is limited as described in the Corporate-Sponsored Member Addendum.

Operators and security obligations

An operator processing information for us must act only with our authorisation, keep information confidential, implement appropriate technical and organisational safeguards, help us respond to incidents and requests, and delete or return information as instructed subject to lawful retention. We assess providers proportionately to risk and use written agreements where required.

Cross-border processing

Some technology or support providers may process information outside South Africa. We transfer personal information across borders only where POPIA section 72 permits it, such as where the recipient is subject to a law, binding corporate rules or contract providing an adequate level of protection; the transfer is necessary for the agreement or your benefit; or you consent where appropriate.

Before publication, OUTLIV must name or meaningfully describe material cross-border hosting and AI providers and verify contractual safeguards, data locations, onward transfers and incident-support arrangements.

Artificial intelligence and automated processing

We may use vetted tools to structure data, generate drafts, prioritise workflow or support practitioners. We minimise data, restrict access and require human clinical review before a patient-specific output becomes clinical advice. We do not permit a vendor to use identifiable member health information to train a general-purpose model unless a separate lawful arrangement and any required consent are in place.

We do not make a solely automated decision that has legal or similarly significant effects on a member unless POPIA permits it and appropriate safeguards, notice and a right to human intervention are provided.

Corporate-sponsored memberships

A sponsor may receive the minimum information required to confirm eligibility, enrolment and billing. It does not receive individual health information. Aggregate reports must be de-identified, limited to a cohort of at least 50 members, and suppress or combine small cells and rare combinations that could reasonably identify a person.

OUTLIV does not provide the programme for an employer to assess fitness, make employment decisions or conduct genetic or HIV testing. Any occupational medical testing requires a separate lawful basis and Employment Equity Act review outside this general programme.

Cookies, analytics and advertising

We use essential cookies for security and operation. Non-essential analytics or advertising technologies are used only in accordance with the Cookie Notice and your choices. We do not deploy third-party advertising pixels on authenticated portal pages, clinical intake forms, result pages or other areas revealing health information.

Retention and disposal

We retain information only for as long as reasonably required for the purpose, legal or professional retention duties, audit, security, tax, dispute or continuity-of-care needs. Clinical records are retained by the responsible Clinical Provider for the applicable statutory and professional period, which may extend after the membership ends and may be longer for particular patients or records.

When retention is no longer justified, we securely delete, destroy or de-identify information using measures appropriate to its sensitivity and medium. Backups are removed through controlled rotation and remain protected until deletion.

Security and security compromises

We use risk-appropriate safeguards such as access control, least privilege, authentication, encryption where appropriate, logging, secure development, vendor controls, staff confidentiality, incident response and tested backups. No system is completely secure, but POPIA requires reasonable technical and organisational measures.

If there are reasonable grounds to believe that unauthorised access to personal information has occurred, we will investigate, contain and notify the Information Regulator and affected data subjects as required by POPIA, as soon as reasonably possible after discovery and subject to any lawful delay requested by authorities.

Your rights

Subject to POPIA and other law, you may:

Send a request through any reasonably accessible channel listed by us. We may verify identity and authority. We will respond within the applicable statutory period, currently generally 30 days for prescribed POPIA requests, unless law permits an extension. Some rights are limited by clinical-record integrity, another person’s privacy, legal privilege, statutory retention or the establishment or defence of rights.

Direct marketing

Marketing consent is separate and optional. Each communication will identify the sender and provide a practical opt-out. We will record and honour individual objections and applicable pre-emptive blocks, including duties arising from the national opt-out framework. Withdrawal does not stop necessary service, safety, billing or legal messages.

Children

The membership is for adults aged 18 or older. We do not knowingly process children’s information for membership. If we learn that an account was created for a child without proper lawful authority, we will restrict it and take appropriate steps, while preserving any record a provider must lawfully retain.

Changes to this Notice

We may update this Notice to reflect law, technology or services. We will publish the effective date and provide prominent notice of a material change. Where a new purpose requires consent, we will obtain it before relying on consent.

Health Data Processing and Sharing Consent

Consent and other lawful grounds

I consent to OUTLIV and the identified Clinical Providers processing my special personal information as described below to coordinate and deliver the services I choose. I understand that some processing also occurs under health-service, contractual, legal or professional authorisations in POPIA and does not depend solely on consent. I may withdraw consent prospectively by contacting hello@outliv.co.za. Withdrawal does not invalidate prior lawful processing, require destruction of a clinical record that must be retained or prevent processing required by law. If essential processing is withdrawn, OUTLIV or the provider may be unable to continue the affected service.

Information covered

This consent covers identity and contact details; health and family history; symptoms; medicines and supplements; allergies; measurements; orders; specimens; laboratory and imaging results; practitioner notes; protocols; prescriptions; referrals; clinical and support communications; and relevant records obtained from or sent to providers involved in my chosen service. It covers genetic or biometric information only where I separately choose a service that needs it and receive any additional consent required for that service.

Essential purposes

Authorised recipients

I authorise proportionate disclosure of the minimum necessary information to the Clinical Provider; relevant laboratory and collection provider; imaging centre; pharmacy or dispensing provider; specialist or referral provider; secure technology and communications operators; payment provider for transaction data; courier for delivery data; and regulators or authorities where lawful.

Each independent healthcare provider may process its own clinical records under its legal and professional duties. OUTLIV must contractually protect information handled by an operator acting only on OUTLIV’s or a provider’s instructions.

Information from and to other providers

A broad permission does not require disclosure of the entire record. The disclosing party must limit information to what is reasonably necessary for the stated care purpose, unless I request a broader transfer or law requires it.

Electronic and cross-border processing

I understand that secure digital systems, email, SMS and WhatsApp may be used as described in the Privacy Notice. I authorise cross-border processing only in accordance with POPIA section 72 and the safeguards described in the Privacy Notice. This is not consent to place health information in an unprotected consumer tool or to use it for unrelated vendor purposes.

AI-assisted processing

I understand that vetted software may organise or summarise my information or support a practitioner. A qualified practitioner must review patient-specific clinical interpretations and protocols. My identifiable health information may not be used to train a general-purpose model without a separate lawful arrangement and any consent required by law.

Employer and sponsor restriction

If a sponsor pays for membership, I do not consent to OUTLIV disclosing my individual results, history, diagnoses, prescriptions, protocol, messages or attendance detail beyond minimal eligibility and billing administration. Only properly de-identified aggregate reporting may be supplied under the Corporate-Sponsored Member Addendum.

Excluded optional purposes

This required consent does not cover the following, which require separate optional choices:

Consent confirmations