Privacy Policy
AutoChat AI (PTY) Ltd (registration number 2025/653699/07) ("AutoChat AI", "we", "us") is committed to protecting personal information in line with the Protection of Personal Information Act, 2013 (POPIA). This policy explains how we handle personal information when we provide our WhatsApp-based patient reception service to medical practices, and when you use this website or contact us.
Effective date: 18 June 2026.
Who we are
Responsible party: AutoChat AI (PTY) Ltd. Address: Unit 23, The Gallery Centre, 1 Turf Club Drive, Milnerton, Cape Town, 7441, South Africa. Information Officer: Lena Raman, lena@autochatai.co.za. General contact: connect@autochatai.co.za.
Our service and our role
AutoChat AI provides software that helps medical practices manage patient enquiries sent to the practice's WhatsApp Business number. When a patient messages a practice, our service reads the message, prepares a suggested reply, and shows it to the practice's staff in a secure dashboard. The practice controls how replies are reviewed and sent. When we process patient personal information through this service, we act as an operator on behalf of the medical practice, which is the responsible party. We process that information only on the practice's instructions and to provide the service. When you visit this website or contact us directly, we act as the responsible party for that information.
Information we process
For the service (on behalf of the practice): WhatsApp messages and their content, the patient's WhatsApp number and name, and appointment or enquiry details the patient provides. Some of this may be health-related and is treated as special personal information under POPIA. For the website: the contact details and message content you send us by email.
Why we process it
To deliver the reception service to practices — reading and understanding incoming messages, preparing accurate suggested replies, and presenting conversations in a secure dashboard the practice controls — and to respond to enquiries you send us.
How we share it
We use trusted service providers to run the service, including cloud hosting, an AI processing provider, and the WhatsApp Business Platform operated by Meta. These providers process information only to provide their service to us and under appropriate agreements. We do not sell personal information and we do not use it for advertising.
Cross-border processing
Some information is processed on secure servers located outside South Africa, in the European Union. Where this happens, we rely on the safeguards permitted under section 72 of POPIA, which require a comparable level of protection.
Retention
We keep personal information only as long as needed to provide the service and to meet legal and regulatory obligations, after which it is deleted or anonymised. Patient information processed on behalf of a practice is retained in line with the practice's instructions and applicable healthcare record-keeping requirements.
Security
We protect personal information using encryption in transit and at rest, access controls, and activity logging.
Your rights
Under POPIA you may request access to your personal information, ask us to correct or delete it, or object to its processing. To exercise these rights, contact connect@autochatai.co.za or lena@autochatai.co.za. Where the information is held on behalf of a medical practice, we may refer your request to that practice or act on its instructions.
Requesting deletion of your data
You can request deletion of your personal information at any time by emailing connect@autochatai.co.za with "Data deletion request" in the subject line. We will action verified requests within 30 days, subject to any legal retention obligations. See our Data Deletion page for details.
Changes
We may update this policy from time to time. The current version is always available on this website.
Contact
Questions about this policy or your personal information: connect@autochatai.co.za.