Legal
What we record, who can access it, and how long we keep it
Maatla Healthcare (Pty) Ltd · CIPC registered, South Africa
Version 1.0 · Effective date: TODO: insert effective date
This policy explains what audit logs are, what actions we record, who can access them, and how long we keep them. It applies to all users of Maatla Facilities.
In this document, we, us, our and Maatla refer to Maatla Healthcare (Pty) Ltd. You and your refer to the clinic, pharmacy or healthcare network using Maatla Facilities.
An audit log is a record of who did what, when, and from where on Maatla Facilities. Audit logs allow us to track access to patient data, identify unusual activity, support investigations, and meet compliance requirements.
Maatla records the following actions in our audit logs:
4.1 Maatla access. Maatla uses audit logs internally for security monitoring, compliance audits, and breach investigations. Only authorized Maatla staff with a specific compliance or security role can access facility audit logs.
4.2 Facility access. A facility may request access to their own audit logs by emailing info@maatlahealthcare.com. To request audit logs, provide:
4.3 Maatla discretion. Maatla will review the request and may:
4.4 What we do not share. Maatla will redact or withhold:
4.5 Patients’ right to their logs. Patients can request a record of who accessed their personal information by emailing info@maatlahealthcare.com. Maatla will provide this upon verification of identity.
Maatla Facilities supports the following roles, each with specific permissions:
5.1 Admin
5.2 Manager
5.3 Pharmacist
5.4 Nurse
5.5 Data Officer
6.1 Assignment. The facility Admin assigns roles to staff members. Role assignment is logged in the audit trail.
6.2 Least privilege principle. Each staff member must be assigned only the role and permissions necessary for their job. Over-provisioning (giving more access than needed) is prohibited.
6.3 Prompt removal. When a staff member leaves or changes role, their access must be removed or downgraded immediately. Delayed removal is a compliance failure and may result in account suspension.
6.4 Shared logins prohibited. Staff members must not share login credentials. Each person must have their own account. Shared logins are impossible to audit and are a security risk.
7.1 Retention period. Audit logs are retained for as long as necessary to meet legal and compliance requirements. Maatla typically retains audit logs for a minimum of one year and a maximum of three years, depending on the type of log and applicable law.
7.2 Deletion after retention. Once the retention period expires, audit logs are permanently deleted unless there is an ongoing investigation, legal hold, or regulatory requirement to keep them longer.
7.3 Breach or incident investigation. If a security incident or breach is reported, relevant audit logs are retained for the duration of the investigation and for as long as required by law, which may be longer than the standard retention period.
Audit logs themselves contain sensitive information (staff identities, patient data, access patterns). Maatla protects audit logs by:
Once a facility uploads patient data to Maatla Facilities, that data is processed by Maatla in accordance with our Privacy Policy and Terms and Conditions. However:
9.1 Facility responsibility. You (the facility) remain responsible for:
9.2 Patient access rights. Patients retain their right to access, correct, or request deletion of their personal information. Requests can be made to either your facility (the uploader) or to Maatla at info@maatlahealthcare.com.
10.1 Facility export. A facility can request an export of their complete patient database (names, contact details, collection history, notes) at any time. To request an export, email info@maatlahealthcare.com with your facility name and account email.
10.2 Patient export. A patient can request an export of their own records by emailing info@maatlahealthcare.com. Maatla will provide the export in a machine-readable format within 30 days.
10.3 Direct-registered patients. Patients who registered directly with Maatla (not through a facility) cannot be exported by a facility without the patient’s written consent.
11.1 Who can delete. Only Maatla staff (specifically the Data Officer or Admin role) can delete patient records. Facility staff cannot delete patients directly.
11.2 How to request deletion. To request deletion of a patient record, the facility must email info@maatlahealthcare.com with:
11.3 Soft vs. hard delete. Maatla may soft-delete a patient (hide them from active lists but retain data) or hard-delete (permanently remove all records) depending on the reason and legal requirements. Hard deletions are final and cannot be reversed.
11.4 Data retention after deletion. Deleted patient data is retained in secure backups for a limited time (typically 90 days) to allow recovery if a deletion was made in error. After that period, the data is permanently deleted.
12.1 Unusual activity. Maatla monitors audit logs for unusual activity, such as:
12.2 Investigation. If unusual activity is detected, Maatla may contact the facility to clarify or may temporarily limit access while investigating.
12.3 Cooperation. If Maatla investigates a suspected breach or misuse, the facility agrees to cooperate by answering questions and providing information about staff members and access patterns.
Maatla may update this policy at any time by publishing a new version on our website. Changes take effect from the moment of publication. By continuing to use Maatla Facilities, you accept the updated policy.
For questions about audit logs or access control: