Entriva
Start free trial
Back to home

Operator Agreement

Version 1.0.0 · A POPIA §20–21 operator contract. The practice is the responsible party; Entriva is the operator.

This Operator Agreement (“Agreement”) is entered into between:

[PRACTICE LEGAL NAME] (practice number [HPCSA/PRACTICE NO.]) — the “Responsible Party”; and Praxiva (Pty) Ltd (CIPC 2026/392940/07), operating the Entriva service — the “Operator”.

It governs the Operator's processing of personal information on the Responsible Party's behalf and forms part of the Responsible Party's use of Entriva.

1. Definitions

Terms used here — including personal information, special personal information, processing, data subject, responsible party, operator, and operator(sub-processor) — have the meanings given in the Protection of Personal Information Act 4 of 2013 (“POPIA”).

2. Roles

The Responsible Party determines the purpose and means of processing patient personal information (the provision of healthcare and the keeping of patient records). The Operator processes that information solely on the Responsible Party's behalf and on its documented instructions, and does not come under its direct authority.

3. Scope and instructions

The Operator will process personal information only:

(a) to provide the Entriva service (WhatsApp/web patient intake, clinical summarisation, and the associated dashboard, audit, and compliance features); and

(b) on the Responsible Party's documented instructions, including as set out in this Agreement and the Entriva terms.

The Operator will not process patient personal information for its own purposes— including product development, analytics for the Operator's benefit, model training, or marketing.

4. Special personal information

The Responsible Party is responsible for establishing a lawful basis for processing patients' health information (special personal information) — typically the provision of medical treatment by a health professional, together with the patient's consent captured at intake. The Operator processes such information only under the Responsible Party's authorisation.

5. Confidentiality

The Operator will treat all personal information as confidential and ensure that persons authorised to process it are bound by confidentiality obligations.

6. Security safeguards (POPIA §19)

The Operator maintains appropriate, reasonable technical and organisational measures, including:

  • field-level encryption of personal and health information at rest (AES-256-GCM) and encryption in transit (TLS);
  • role-based access controls limiting access to the Responsible Party's authorised users;
  • a tamper-evident, append-only audit log of actions on patient data (aligned to POPIA §17 and §19 and HPCSA Ethical Rule 5); and
  • regular review of these measures.

7. Security compromise (POPIA §22)

Where there are reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, the Operator will notify the Responsible Party without undue delay after becoming aware, so the Responsible Party can meet its notification obligations to the Information Regulator and affected data subjects.

8. Sub-operators

The Responsible Party authorises the Operator to engage the following sub-operators, each bound to materially equivalent data-protection obligations:

Sub-operatorRoleLocation
SupabaseManaged database & hosting (data at rest)European Union (Ireland)
Twilio Inc.WhatsApp message delivery (intake in transit)United States
AnthropicAI clinical summarisation (ICD-10, risk flags)United States

The Operator will give the Responsible Party reasonable notice of any intended addition or replacement of a sub-operator, and the Responsible Party may object on reasonable data-protection grounds.

9. Cross-border transfers (POPIA §72)

Patient data at rest is hosted in the European Union. AI processing is performed in the United States. These transfers are made under §72-compliant safeguards — the sub-operators are bound by data-processing agreements incorporating standard contractual clauses providing protection substantially similar to POPIA. No patient data at rest leaves the EU region.

10. Retention

The Responsible Party determines the retention period. Consistent with HPCSA Ethical Rule 5 and the National Health Act, patient records are retained for six (6) yearsfrom the date of the last entry (longer where the law requires — e.g. records of minors), enforced automatically by the service. The Operator holds these records on the Responsible Party's behalf and will delete or return them on the Responsible Party's instruction or on termination.

11. Data-subject requests

The Operator will, taking into account the nature of the processing, assist the Responsible Party in responding to data-subject requests for access, correction, or deletion (DSARs), including through the service's DSAR tooling.

12. Return or deletion on termination

On termination of the service, the Operator will, at the Responsible Party's election, return or securely delete the personal information it processes on the Responsible Party's behalf, save where retention is required by law.

13. Liability, term, and law

This Agreement takes effect on the Responsible Party's acceptance and continues while it uses the service. It is governed by the laws of the Republic of South Africa. Each party remains liable for its own compliance obligations under POPIA; the Responsible Party remains ultimately accountable to data subjects and the Regulator as the responsible party.

Accepted by the Responsible Party: [NAME] · [PRACTICE] · [DATE]

(Accepted electronically at signup.)