Privacy policy

Protecting personal and medical information.

This policy explains how BioFITT Wellness collects, uses, stores, shares and protects personal information, health information, wearable data and digital communications across our preventative healthcare services.

Last updated: 1 July 2026

Health dataHandled as sensitive personal information with clinical access controls.
WhatsAppUsed only where permitted, requested or consented to, with opt-out options.
WearablesGarmin and similar data is optional and requires user authorisation.
AIPersonal, medical and Garmin data is not used to train third-party AI engines.

1. Who we are

BioFITT Wellness CC, trading as BioFITT Wellness, provides preventative healthcare, wellness screening, home visits, digital health journeys, care navigation, programme reporting and related clinical support services.

For purposes of South African privacy law, BioFITT may act as a responsible party when we determine why and how personal information is processed, and as an operator when we process information on behalf of an employer, medical scheme, insurer, healthcare provider, partner or other responsible party.

Primary contact

Email: info@biofitt.co.za
Telephone: +27 21 820 4858
Address: Unit 3, Canal Edge 2, 4 Carl Cronje Drive, Bellville, 7550, South Africa

2. Scope of this policy

This policy applies to personal information processed through our websites, screening events, digital platforms, Emma virtual health assistant, home visit services, WhatsApp and other messaging channels, call centres, reports, integrations, wearable-device connections and partner programmes.

This policy should be read together with any consent form, programme notice, employer or scheme notice, clinical intake form, app notice, wearable integration notice, WhatsApp opt-in wording, service contract or platform-specific notice that applies to a specific programme.

Where a partner, employer, medical scheme, insurer, healthcare provider, Garmin, Meta, WhatsApp, cloud provider or other third party has its own privacy notice, that third-party notice may also apply to its independent processing activities.

3. Personal information we may collect

The information we collect depends on the service, programme and permissions involved. It may include:

Identity and contact details

Name, surname, ID or passport number where required, date of birth, gender, employee or member number, email address, phone number, preferred contact channel, address and emergency contact details.

Programme eligibility

Employer, branch, region, business unit, medical scheme, option, insurer, membership status, benefits, programme enrolment status and appointment details.

Health and screening information

Health risk assessments, lifestyle questionnaires, consent records, height, weight, BMI, blood pressure, blood glucose, cholesterol, chronic conditions, medication information, vaccination status, screening results and care notes.

Care journey information

Care plans, referrals, coaching notes, booking history, home visit notes, case navigation records, reminders, member goals, risk categories, escalation status and programme outcomes.

Digital and device data

App activity, login data, device identifiers, browser data, IP address, usage logs, support tickets, notification preferences, wearable data and integration status.

Communications

Emails, SMS messages, WhatsApp messages, call recordings where enabled and lawful, chatbot interactions, support messages and consent or opt-out records.

4. Medical, health and special personal information

Health information is sensitive. BioFITT treats health, biometric, lifestyle, medication, disability, pregnancy, chronic-condition, mental-health and clinical care information as special personal information under South African privacy law.

We process health information only where there is an appropriate legal basis, such as explicit consent, provision of healthcare or wellness services, a contractual programme, a legal obligation, protection of legitimate interests, medical care and treatment, public health requirements or another lawful basis that applies to the service.

We use health information to provide preventative healthcare services, not to unfairly discriminate against members or employees. Employers generally receive de-identified, aggregated or programme-level reports unless identifiable information is lawfully required, expressly authorised, clinically necessary or otherwise permitted.

We do not sell personal health information. We do not provide individual clinical records to employers for employment discipline, promotion, dismissal or performance management decisions. Any exception must be lawful, transparent and limited to what is necessary.

Our services are designed to support prevention and care coordination. They are not a substitute for emergency medical services, a treating doctor, hospital care or urgent clinical intervention. If a person has a medical emergency, they should contact emergency services or a healthcare professional immediately.

5. Garmin, wearable and connected-device data

Where BioFITT offers Garmin Health API, Garmin Connect or other wearable-device integrations, the integration is optional unless a specific programme notice clearly states otherwise. We will provide notice of the integration purpose and request permission before connecting a wearable account or receiving wearable data.

Depending on the device, settings and permissions, wearable data may include activity, steps, intensity minutes, distance, calories, sleep, heart rate, resting heart rate, stress, respiration, pulse oxygen, body battery or recovery indicators, body composition, blood pressure, workout or activity summaries, timestamps and device-sync data.

We use Garmin and wearable data to support prevention, engagement, coaching, risk awareness, reminders, programme insights and personalised care pathways. We do not treat wearable data as a definitive medical diagnosis. Wearable data may be incomplete, delayed, device-dependent or affected by user settings, device placement and device accuracy.

We do not ask for your Garmin username or password. Any Garmin integration must use Garmin-approved authorisation flows. We will not attempt to bypass Garmin access controls or obtain Garmin data by using an alternative authorisation method that Garmin has not approved.

Where a Garmin integration transfers information to or from Garmin Connect, Garmin's own privacy terms may also apply. Garmin's privacy policy for Garmin Connect and compatible Garmin devices is available at https://www.garmin.com/privacy/connect.

You may disconnect a wearable integration through the relevant device platform, Garmin account settings where available, the BioFITT service channel or by contacting us. Disconnecting an integration stops future collection from that source, but we may retain information already collected where retention is lawful and necessary.

We do not sell Garmin, wearable or connected-device data. We do not distribute Garmin device-sourced data to unapproved third-party applications, websites, platforms, services or products. Where Garmin device-sourced data is displayed, exported, reported or shared in a way that requires Garmin attribution, we will apply the required Garmin attribution and branding rules.

We do not use Garmin, wearable or connected-device data to train third-party artificial intelligence models or third-party AI engines. We also do not submit identifiable Garmin or wearable data to open, public or general-purpose AI tools. If BioFITT ever proposes to use Garmin end user data for AI training or AI processing beyond the limited operational analytics described in this policy, we will update this policy and obtain any explicit consent required before that processing starts.

We will not use Garmin or wearable data for employer disciplinary action, workplace performance management, insurance underwriting or benefit denial unless a separate lawful basis and clear, specific consent or legal requirement applies.

6. WhatsApp, Meta and messaging channels

BioFITT may use WhatsApp Business Platform, WhatsApp Business App, Meta-approved business messaging tools, SMS, email or similar channels for appointment reminders, wellness nudges, care journey messages, support, education, consent management, booking updates and service communication.

Where WhatsApp is used, Meta, WhatsApp, our business solution provider and related service providers may process message content, phone numbers, message templates, timestamps, delivery status, opt-in status, opt-out status, device or account information and technical metadata in accordance with their own terms and privacy notices.

We use WhatsApp in a way intended to comply with WhatsApp Business Platform and Meta requirements, including using appropriate opt-in, approved message categories where required, clear business identity, relevant message content and accessible opt-out mechanisms. You can ask us to stop WhatsApp communication, and may also block or manage communication through WhatsApp settings.

WhatsApp should not be used for emergencies or highly urgent clinical issues. We also encourage users not to send unnecessary sensitive information by WhatsApp. Where health information is exchanged over WhatsApp for care-related purposes, we limit use to the service purpose and apply appropriate access controls.

BioFITT does not use WhatsApp message content, phone numbers, opt-in records, appointment messages or care journey messages to train third-party AI engines. If you message BioFITT on WhatsApp, you understand that WhatsApp is a third-party channel. Your use of WhatsApp is also subject to WhatsApp and Meta terms, privacy notices and security practices, including any cross-border processing by those providers.

7. How we use personal information

We process personal information for lawful, specific and legitimate purposes, including to:

  • confirm eligibility, enrolment and consent for BioFITT programmes;
  • perform screenings, assessments, health risk stratification and care navigation;
  • deliver home visits, virtual consultations, wellness days, coaching, reminders and follow-ups;
  • operate Emma, member journeys, appointment booking, digital tools and programme dashboards;
  • personalise prevention pathways, education, nudges, benefit matching and escalation routes;
  • communicate through email, SMS, WhatsApp, calls, apps and partner-approved channels;
  • prepare de-identified, aggregated or limited reports for employers, schemes, insurers and partners;
  • manage quality assurance, clinical governance, fraud prevention, security, audit and compliance;
  • improve services, analytics, platform reliability and care outcomes;
  • meet legal, regulatory, contractual, tax, accounting, insurance and record-keeping duties.

8. Sharing personal information

We share personal information only where necessary, lawful and proportionate. Recipients may include:

  • BioFITT clinicians, nurses, care coordinators, agents, operations staff, data teams and authorised personnel;
  • healthcare providers, laboratories, pharmacies, emergency contacts or referral partners where clinically appropriate or authorised;
  • employers, medical schemes, insurers, brokers, administrators or programme sponsors, usually in aggregated or de-identified form unless identifiable sharing is lawful and necessary;
  • technology providers, cloud hosting providers, CRM systems, analytics providers, communication platforms, WhatsApp/Meta providers, Garmin or wearable-integration providers and IT support providers, where they are needed to deliver, secure or support the service;
  • professional advisers, auditors, insurers, legal representatives, regulators, law-enforcement bodies or courts where required or permitted by law.

When we appoint operators or service providers, we require appropriate confidentiality, security and data-processing controls. Where information is transferred outside South Africa, we use safeguards intended to comply with POPIA, such as contractual protections, consent where required, adequate protection or another lawful transfer basis.

We do not share identifiable personal information, medical information, Garmin data, wearable data or WhatsApp message content with third-party AI engines for model training. We do not sell personal health information or connected-device data.

9. Security and confidentiality

BioFITT applies administrative, technical and organisational safeguards appropriate to the sensitivity of the information. These may include role-based access, access logging, confidentiality undertakings, secure hosting, encryption where appropriate, password controls, user authentication, staff training, incident management, vendor due diligence and data minimisation.

No website, messaging channel, app, API or electronic system can be guaranteed to be completely secure. If we become aware of a security compromise affecting personal information, we will assess the incident and notify affected parties and regulators where required by law.

10. Retention and deletion

We keep personal information only for as long as necessary for the purpose collected, programme delivery, clinical continuity, reporting, consent proof, legal duties, contractual obligations, dispute resolution, audit, tax, insurance and legitimate business records.

Retention periods may differ for clinical records, screening records, WhatsApp messages, consent records, wearable data, programme reports, financial records and system logs. When information is no longer required, we will delete, de-identify, aggregate or securely archive it, unless retention remains lawful and necessary.

11. Your privacy rights

Subject to applicable law, you may have the right to:

  • ask whether we hold personal information about you;
  • request access to your personal information;
  • ask us to correct or update inaccurate, irrelevant, excessive, outdated, incomplete or misleading information;
  • object to processing in certain circumstances;
  • withdraw consent where processing is based on consent;
  • request deletion or restriction where lawful grounds exist;
  • opt out of direct marketing or non-essential communications.

We may need to verify your identity before actioning a request. Some rights are limited where we must keep information for legal, clinical, contractual, safety, audit or legitimate purposes.

12. Children and vulnerable persons

BioFITT may process information relating to children or vulnerable persons where a programme includes dependants, family care, school or community services, or where a parent, guardian, competent person, scheme, employer or healthcare provider lawfully provides or authorises the information.

We apply additional care to child and vulnerable-person information and process it only where lawful, appropriate and limited to the relevant health, wellness or support purpose.

13. Analytics, AI and automated support

BioFITT may use risk scoring, segmentation, rules engines, dashboards, trend analytics, automated reminders and structured decision-support tools to support preventative care. These tools help prioritise outreach, identify care gaps and suggest next best steps.

BioFITT does not use personal information, medical information, WhatsApp message content, Garmin data, wearable data or connected-device data to train third-party AI engines. We do not send identifiable health, wearable or messaging data to open public AI tools or general-purpose AI platforms for model training.

Where BioFITT uses analytics or automation, it is intended to support programme operations, reporting, care coordination, member engagement and clinical oversight. Automated tools do not replace clinical judgement where a clinical decision is required. We aim to keep automated processing fair, relevant, explainable and subject to appropriate human oversight.

If a future BioFITT service introduces AI processing of personal, medical, Garmin, wearable or messaging data beyond the limited operational analytics described here, we will provide additional notice, update this policy and obtain explicit consent where required before that processing starts.

14. Website cookies and analytics

Our website may use necessary cookies, basic analytics, security logs or similar technologies to operate the site, understand usage and maintain security. Where optional analytics or marketing technologies are introduced, we will provide appropriate notice and controls where required.

15. Changes to this policy

We may update this policy to reflect changes in our services, legal requirements, technology providers, integrations or operational practices. The latest version will be published at https://www.biofitt.co.za/privacy-policy.

16. Contact BioFITT

For privacy requests, questions, objections, access requests, correction requests, WhatsApp opt-out support or wearable integration concerns, contact BioFITT at:

Email: info@biofitt.co.za

Telephone: +27 21 820 4858

Address: Unit 3, Canal Edge 2, 4 Carl Cronje Drive, Bellville, 7550, South Africa

We will review privacy concerns and respond through the appropriate BioFITT channel as soon as reasonably possible.