Legal
Privacy Statement
How OUTLIV collects, uses, shares, secures and retains personal and health information under POPIA.
Privacy Notice (POPIA)
Responsible party and contact details
Outliv Longevity (Pty) Ltd - 2026/236646/07 trading as OUTLIV, is the responsible party for membership, Platform, account, payment, support, coordination, security and business-administration processing it determines.
The identified Clinical Provider, laboratory, imaging provider, pharmacy or specialist may be a separate responsible party for its clinical, diagnostic, dispensing or professional records. In some workflows OUTLIV may act as an operator for a Clinical Provider, or the provider may act for OUTLIV. Written agreements and this Notice must reflect the actual role; labels do not override the facts.
Laws and principles
We process personal information under the Protection of Personal Information Act, 2013 (“POPIA”), the National Health Act, 2003, applicable professional rules and other South African law. We apply accountability, processing limitation, purpose specification, further-processing compatibility, information quality, openness, security safeguards and data-subject participation.
Health, genetic and biometric information is special personal information. We process it only where POPIA authorises the processing, including as necessary for treatment, care, health-service administration, legal or professional duties, or with valid consent where required, and subject to confidentiality safeguards.
Personal information we collect
- Identity and contact. Name, identity or passport details where needed, date of birth, sex where clinically relevant, address, email, phone, emergency contact and verification records.
- Account and membership. Credentials, consents, accepted document versions, preferences, eligibility, orders, appointments, support requests and sponsor status.
- Health and clinical. History, symptoms, diagnoses, allergies, family history, medicines, supplements, measurements, laboratory orders, specimens, results, imaging, clinical notes, protocols, prescriptions, referrals and communications.
- Genetic and biometric. Only where a separately authorised service needs it; genetic testing requires additional consent.
- Device and lifestyle. Wearable, activity, sleep or device data only when you choose a supported integration; questionnaire information you submit.
- Payments and transactions. Billing details, transaction identifiers, invoices and limited payment information; full card data is ordinarily handled byPayGate.
- Technology and use. IP address, device and browser details, authentication logs, timestamps, audit trails, security events, portal use and cookies described in the Cookie Notice.
- Communications. Email, SMS, WhatsApp, call notes, support messages and, only with proper notice or consent, recordings.
- Corporate programme. Sponsor eligibility, employment-group identifier and programme administration data; individual clinical results remain separate from employer reporting.
Where information comes from
We collect information from you; an authorised representative; the Clinical Provider; laboratories, imaging providers, pharmacies and specialists; a sponsor for eligibility and payment; payment and identity providers; supported devices you connect; and public or official sources where lawful and necessary. We will not obtain clinical information from an employer merely because it sponsors membership.
Why and on what basis we process information
| Purpose | Typical information | POPIA justification |
|---|---|---|
| Create and administer membership | Identity, contact, account, order, payment | Contract; legitimate interests; legal duties |
| Coordinate testing and clinical care | Health history, orders, results, provider data | Health-service authorisation; contract; consent where required |
| Provide secure access and support | Credentials, audit logs, communications | Contract; security and legitimate interests |
| Process payment and prevent fraud | Transaction and verification data | Contract; legal duties; legitimate interests |
| Communicate service information | Contact, booking and status data | Contract and service administration |
| Improve quality and operations | De-identified or appropriately minimised usage and service data | Legitimate interests compatible with original purpose |
| Comply with law and professional duties | Records, tax, complaints, security events | Legal obligation; establishment or defence of rights |
| Send marketing | Contact and channel preferences | Separate consent or another lawful basis, with opt-out |
| Research using identifiable information | Only the specifically approved dataset | Separate consent and any required ethics approval |
Where processing is necessary to conclude or perform the membership or clinical service, failure to provide essential information may mean we cannot safely or lawfully provide it. Optional information and optional consents are identified separately.
Sharing and recipients
We disclose only information reasonably necessary for the relevant purpose, including to:
- Clinical Providers, laboratories, collection providers, imaging centres, pharmacies, specialists and referral providers involved in your care or chosen service;
- technology hosting, cybersecurity, communications, customer-support, analytics, payment, identity and professional-advisory providers bound by appropriate confidentiality and processing terms;
- couriers and fulfilment providers using the minimum delivery information necessary;
- medical schemes or sponsors only where you request or authorise a claim or where another lawful basis applies;
- regulators, courts, law enforcement, professional bodies or public authorities where lawfully required or permitted; and
- a successor in a genuine corporate transaction, subject to confidentiality, due diligence minimisation and continued legal protection.
We do not sell personal health information. We do not disclose identifiable clinical results, diagnoses, prescriptions, consultations or protocols to an employer merely because it funds the programme. Employer reporting is limited as described in the Corporate-Sponsored Member Addendum.
Operators and security obligations
An operator processing information for us must act only with our authorisation, keep information confidential, implement appropriate technical and organisational safeguards, help us respond to incidents and requests, and delete or return information as instructed subject to lawful retention. We assess providers proportionately to risk and use written agreements where required.
Cross-border processing
Some technology or support providers may process information outside South Africa. We transfer personal information across borders only where POPIA section 72 permits it, such as where the recipient is subject to a law, binding corporate rules or contract providing an adequate level of protection; the transfer is necessary for the agreement or your benefit; or you consent where appropriate.
Before publication, OUTLIV must name or meaningfully describe material cross-border hosting and AI providers and verify contractual safeguards, data locations, onward transfers and incident-support arrangements.
Artificial intelligence and automated processing
We may use vetted tools to structure data, generate drafts, prioritise workflow or support practitioners. We minimise data, restrict access and require human clinical review before a patient-specific output becomes clinical advice. We do not permit a vendor to use identifiable member health information to train a general-purpose model unless a separate lawful arrangement and any required consent are in place.
We do not make a solely automated decision that has legal or similarly significant effects on a member unless POPIA permits it and appropriate safeguards, notice and a right to human intervention are provided.
Corporate-sponsored memberships
A sponsor may receive the minimum information required to confirm eligibility, enrolment and billing. It does not receive individual health information. Aggregate reports must be de-identified, limited to a cohort of at least 50 members, and suppress or combine small cells and rare combinations that could reasonably identify a person.
OUTLIV does not provide the programme for an employer to assess fitness, make employment decisions or conduct genetic or HIV testing. Any occupational medical testing requires a separate lawful basis and Employment Equity Act review outside this general programme.
Cookies, analytics and advertising
We use essential cookies for security and operation. Non-essential analytics or advertising technologies are used only in accordance with the Cookie Notice and your choices. We do not deploy third-party advertising pixels on authenticated portal pages, clinical intake forms, result pages or other areas revealing health information.
Retention and disposal
We retain information only for as long as reasonably required for the purpose, legal or professional retention duties, audit, security, tax, dispute or continuity-of-care needs. Clinical records are retained by the responsible Clinical Provider for the applicable statutory and professional period, which may extend after the membership ends and may be longer for particular patients or records.
When retention is no longer justified, we securely delete, destroy or de-identify information using measures appropriate to its sensitivity and medium. Backups are removed through controlled rotation and remain protected until deletion.
Security and security compromises
We use risk-appropriate safeguards such as access control, least privilege, authentication, encryption where appropriate, logging, secure development, vendor controls, staff confidentiality, incident response and tested backups. No system is completely secure, but POPIA requires reasonable technical and organisational measures.
If there are reasonable grounds to believe that unauthorised access to personal information has occurred, we will investigate, contain and notify the Information Regulator and affected data subjects as required by POPIA, as soon as reasonably possible after discovery and subject to any lawful delay requested by authorities.
Your rights
Subject to POPIA and other law, you may:
- ask whether we hold personal information about you and request access;
- request correction, completion, deletion or destruction of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing on a statutory ground;
- withdraw consent prospectively where processing depends on consent;
- object to direct marketing and change channel preferences;
- ask for information about a significant automated decision and request human review where applicable;
- request transfer of a practical electronic copy where we can reasonably provide it; and
- complain to our Information Officer or the Information Regulator.
Send a request through any reasonably accessible channel listed by us. We may verify identity and authority. We will respond within the applicable statutory period, currently generally 30 days for prescribed POPIA requests, unless law permits an extension. Some rights are limited by clinical-record integrity, another person’s privacy, legal privilege, statutory retention or the establishment or defence of rights.
Direct marketing
Marketing consent is separate and optional. Each communication will identify the sender and provide a practical opt-out. We will record and honour individual objections and applicable pre-emptive blocks, including duties arising from the national opt-out framework. Withdrawal does not stop necessary service, safety, billing or legal messages.
Children
The membership is for adults aged 18 or older. We do not knowingly process children’s information for membership. If we learn that an account was created for a child without proper lawful authority, we will restrict it and take appropriate steps, while preserving any record a provider must lawfully retain.
Changes to this Notice
We may update this Notice to reflect law, technology or services. We will publish the effective date and provide prominent notice of a material change. Where a new purpose requires consent, we will obtain it before relying on consent.
Health Data Processing and Sharing Consent
Consent and other lawful grounds
I consent to OUTLIV and the identified Clinical Providers processing my special personal information as described below to coordinate and deliver the services I choose. I understand that some processing also occurs under health-service, contractual, legal or professional authorisations in POPIA and does not depend solely on consent. I may withdraw consent prospectively by contacting hello@outliv.co.za. Withdrawal does not invalidate prior lawful processing, require destruction of a clinical record that must be retained or prevent processing required by law. If essential processing is withdrawn, OUTLIV or the provider may be unable to continue the affected service.
Information covered
This consent covers identity and contact details; health and family history; symptoms; medicines and supplements; allergies; measurements; orders; specimens; laboratory and imaging results; practitioner notes; protocols; prescriptions; referrals; clinical and support communications; and relevant records obtained from or sent to providers involved in my chosen service. It covers genetic or biometric information only where I separately choose a service that needs it and receive any additional consent required for that service.
Essential purposes
- verify my identity and create and administer my membership and clinical workflow;
- collect my intake and records and make them available to the responsible practitioner;
- order, collect, transport, analyse and report authorised tests;
- coordinate imaging, pharmacy, specialist, delivery or other optional services I select;
- enable practitioner review, interpretation, protocols, prescribing, monitoring, referrals and follow-up;
- communicate appointments, instructions, result availability, follow-up and safety information;
- maintain clinical, consent, audit and transaction records;
- protect the security and integrity of systems and investigate incidents; and
- comply with legal and professional duties and establish or defend rights.
Authorised recipients
I authorise proportionate disclosure of the minimum necessary information to the Clinical Provider; relevant laboratory and collection provider; imaging centre; pharmacy or dispensing provider; specialist or referral provider; secure technology and communications operators; payment provider for transaction data; courier for delivery data; and regulators or authorities where lawful.
Each independent healthcare provider may process its own clinical records under its legal and professional duties. OUTLIV must contractually protect information handled by an operator acting only on OUTLIV’s or a provider’s instructions.
Information from and to other providers
- REQUIRED — I authorise OUTLIV and the Clinical Provider to request relevant records from, and send relevant reports to, the healthcare providers I identify, after reasonable identity and recipient verification.
A broad permission does not require disclosure of the entire record. The disclosing party must limit information to what is reasonably necessary for the stated care purpose, unless I request a broader transfer or law requires it.
Electronic and cross-border processing
I understand that secure digital systems, email, SMS and WhatsApp may be used as described in the Privacy Notice. I authorise cross-border processing only in accordance with POPIA section 72 and the safeguards described in the Privacy Notice. This is not consent to place health information in an unprotected consumer tool or to use it for unrelated vendor purposes.
AI-assisted processing
I understand that vetted software may organise or summarise my information or support a practitioner. A qualified practitioner must review patient-specific clinical interpretations and protocols. My identifiable health information may not be used to train a general-purpose model without a separate lawful arrangement and any consent required by law.
Employer and sponsor restriction
If a sponsor pays for membership, I do not consent to OUTLIV disclosing my individual results, history, diagnoses, prescriptions, protocol, messages or attendance detail beyond minimal eligibility and billing administration. Only properly de-identified aggregate reporting may be supplied under the Corporate-Sponsored Member Addendum.
Excluded optional purposes
This required consent does not cover the following, which require separate optional choices:
- direct marketing by email, SMS, telephone or WhatsApp;
- connection to a wearable or third-party health account;
- identifiable research or publication;
- sharing with family, an employer, insurer or other third party not necessary for the chosen service;
- genetic testing and related familial implications; or
- use of identifiable health information to train a general-purpose AI model.
Consent confirmations
- REQUIRED — I have read the Privacy Notice and understand the categories, purposes, recipients, retention, safeguards and rights described there.
- REQUIRED — I consent to the essential health-data processing and sharing described in this document for the services I choose.
- REQUIRED — I understand that withholding or withdrawing essential processing may make the clinical service impossible to provide safely or lawfully.
- REQUIRED — I understand that my employer or sponsor will not receive my individual clinical information under this consent.