Echo Reach is responsible for your information
The responsible party for Qera is Echo Reach. Our information officer can be reached at privacy@qera.co.za. For anything else, write to support@qera.co.za.
What we collect
From you (families using Qera): your WhatsApp number; the messages and buttons you send us; your answers to the intake questions; the photos you send; the names of family members you add and the names and species of your pets; your postal code; when you agreed to the terms and gave consent; payment references, amounts and status (never card or bank details); and short-lived login codes for this website, stored only as hashes.
From partner clinics: practice name, contact person's email and phone number, practice or registration number, address or postal code, opening hours, wallet transactions, and invoices families submit when they report overcharging.
We remove location, date and camera details from every photo before we store it or send it for analysis.
Photos and symptoms are health information, so we ask for your consent
Information about your health or your child's health is special personal information under section 26 of POPIA. We process it only with your explicit consent (section 27(1)(a)), which we ask for on WhatsApp, separately from the terms of use, before we look at any photo. If you send a photo before giving consent, we don't store or analyse it. For a child, the consent of a parent or guardian is required (section 35), and by using Qera for a child you confirm that you are that person.
We use the information to assess and track your cases, send the reminders you asked for, make your Clinical Intake Brief, connect you with a clinic when you ask, check invoices you report, take payment, keep the service secure, and meet our legal duties. Information that isn't about health (your number, payments) is processed to provide the service you asked for and for our legitimate interest in running it safely (section 11(1)(b) and (f)).
We do not sell your information, use it for advertising, or send you marketing unless you have opted in.
An AI model suggests the colour; fixed rules can only make it more cautious
The GREEN, AMBER or RED result comes from an AI model, checked by fixed safety rules. Those rules can raise the level, never lower it: for example, emergency words in your message make a case RED, and a worsening case never drops below AMBER. No person reviews each result before you see it. The result has no legal effect and does not decide whether you may get care. You can ask us to explain how a result was reached, or ask a person to look at it, by emailing support@qera.co.za (section 71).
These providers process information for us
We use the following operators, each under a written agreement that requires them to keep the information confidential and secure and to tell us immediately about any breach (sections 20 and 21).
| Provider | What they do | Where |
|---|---|---|
OpenAI | Analyses each photo and your answers to produce the triage result. We send no name or phone number, and photo metadata is removed first. | United States |
Cloudflare (R2 storage) | Stores photos, invoice photos and PDF briefs. | Outside South Africa |
Meta (WhatsApp Business Platform) | Carries WhatsApp messages between you and Qera, including the photos you send, through the WhatsApp Cloud API. | United States and other countries where Meta operates |
Telnyx | Sends SMS alerts about new cases to partner clinics. | United States |
Neon | Hosts the Qera database: your profile, cases, results and payment records. | Outside South Africa |
Render | Runs the Qera application and website. | Outside South Africa |
Paystack | Processes payments in rand. Paystack receives the amount, a payment reference and a contact address built from your number. | South Africa, and other countries where Paystack operates |
Stripe | Processes payments in currencies other than rand, when used. | United States and the European Union |
Resend | Sends email to partner clinics and to our team. Families don't receive email from Qera. | United States |
Your messages also pass through WhatsApp, which Meta runs under its own terms and privacy policy.
Partner clinics receive your information only after you ask Qera to have a clinic call you and a clinic accepts. That clinic receives your phone number, the case summary, the photos and the brief. From then on the clinic is responsible for its own records of your care.
Your information is processed outside South Africa
Our AI, storage, database and hosting providers are outside South Africa, so your photos and answers leave the country. We rely on your consent to that transfer (section 72(1)(b)) and on agreements that bind these providers to protection substantially similar to POPIA (section 72(1)(a)). Before anything is sent for analysis we remove names, phone numbers and photo metadata.
How long we keep it
| Information | Kept for |
|---|---|
Photos of a case | 30 days after the case closes (when its 7 days end, or when you tell us it has healed) |
Clinical Intake Brief PDFs | 30 days after they are made |
The content of your WhatsApp messages as received | 30 days |
Photos you sent that we couldn't use | Up to 24 hours |
Website login codes | Work for 10 minutes. The hashed code and the number it was sent to are deleted within 2 days, so we can enforce the hourly limit. |
Invoice photos you send with OVERCHARGED | Until you delete your data |
Your profile, family list and case results (without photos) | Until you delete your data |
Payment records | At least 5 years, as tax law requires. They hold the amount and reference, not health information. |
Partner clinic records and fee audits | While the clinic is a partner, and at least 5 years after |
When you delete your data we erase your profile, family list, cases, photos and briefs. We keep payment records as the law requires, and a one-way fingerprint of your number that shows the deletion happened without revealing the number.
How we protect it
Information is encrypted in transit. Photos and briefs are never public. A photo opens only through a link that expires within minutes. Each brief opens through its own private link, which stops working after 30 days, or as soon as you reply HISTORY for a fresh one. Login codes and download links are stored as one-way hashes. Only people who need access to run Qera have it. If there is a breach, we will tell the Information Regulator and the people affected as soon as reasonably possible (section 22).
Your rights
- Ask what information we hold about you and who has received it (section 23).
- Ask us to correct or delete information that is wrong, out of date or no longer needed (section 24).
- Withdraw your consent or object to processing at any time. This stops future processing; it doesn't undo what was lawfully done before.
- Delete everything: reply DELETE MY DATA on WhatsApp, or sign in at My cases.
- Complain to the Information Regulator.
Email the information officer at privacy@qera.co.za to use these rights. We answer within 30 days, and we may ask you to prove the number is yours first.
This website uses only essential cookies
We set a sign-in cookie when you log in (it lasts up to 12 hours), a security cookie that protects forms (1 hour), and a cookie that remembers your number while you enter a login code (10 minutes). We use no analytics or advertising cookies.
Contacting the Information Regulator
Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. General enquiries: enquiries@inforegulator.org.za. Complaints: POPIAComplaints@inforegulator.org.za. Website: inforegulator.org.za.
Changes to this notice
If we change how we use your information, we will update this notice and ask for your consent again on WhatsApp before we rely on the change.