Flag of South Africa
South Africa

Protection of Personal Information Act, 2013

Act No. 4 of 2013

How MolarPlus processes personal information for dental practices in South Africa.

Applies to
South Africa
Regulator
Information Regulator (South Africa)
The clinic is the
Responsible Party
MolarPlus is the
Operator
Data is hosted in
Asia Pacific (Mumbai) region, India
Last reviewed
September 2026

1.Scope

MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement sets out how MolarPlus processes the personal information of data subjects in South Africa under the Protection of Personal Information Act, 2013 (“POPIA”).

2.Responsible party and operator

A dental practice using MolarPlus determines the purpose and means of processing its patients’ personal information and is the responsible party. MolarPlus processes that information for the practice under a contract, without coming under its direct authority, and is an operator as defined in section 1.

Information about a patient’s health is special personal information under section 26. The practice relies on the authorisation in section 32(1) for health care providers, and remains responsible for processing it lawfully.

MolarPlus is the responsible party for the account information of practice owners and staff, and for enquiries made through this website.

3.Operator obligations

Section 20
An operator may process personal information only with the knowledge or authorisation of the responsible party, and must treat it as confidential.
MolarPlus processes practice data only to provide the service to the practice, treats it as confidential, and does not disclose it except as the practice authorises or the law requires.
Section 21(1)
A written contract must ensure that the operator establishes and maintains the security measures referred to in section 19.
MolarPlus maintains the measures described in section 4 of this statement, and enters into a written operator agreement to that effect with any practice that requests one.
Section 21(2)
The operator must notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
Described in section 5 of this statement.

4.Security safeguards

Section 19 requires appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information and to prevent its loss, damage or unlawful access. MolarPlus applies the following measures.

Encryption at rest
Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
Encryption in transit
Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
Network isolation
The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
Role-based access
The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
Authentication
Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
Audit trail
Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
Private document links
Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
Backups and recovery
The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
Portability
A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.

5.Security compromises

Where MolarPlus has reasonable grounds to believe that personal information it processes for a practice has been accessed or acquired by an unauthorised person, it will notify the practice immediately, as section 21(2) requires. MolarPlus will provide the information the practice needs to notify the Information Regulator and each affected data subject as soon as reasonably possible, as section 22 requires, including a description of the possible consequences and the measures taken to address the compromise.

6.Transborder information flows

MolarPlus stores practice data on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Section 72 permits the transfer of personal information outside the Republic where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, substantially similar to the conditions for lawful processing in POPIA.

Personal information held by MolarPlus in India is subject to the Digital Personal Data Protection Act, 2023, and MolarPlus is bound by its agreement with the practice to protect it in a manner consistent with POPIA. The service providers MolarPlus uses are listed in the register of sub-processors.

7.Rights of data subjects

Patients exercise their rights against the practice, as responsible party. MolarPlus gives practices the means to act on those requests.

Section 23
Access to personal information held by a responsible party.
The practice can view and export a patient’s complete record and provide it to the patient.
Section 24
Correction or deletion of personal information that is inaccurate, irrelevant or out of date.
Authorised staff correct records directly, and changes are recorded in the activity log. Deletion is carried out as section 8 describes.
Section 11(3)
Objection to the processing of personal information.
MolarPlus assists the practice in giving effect to an objection on request.
Section 74
Complaint to the Information Regulator.
Any person may submit a complaint to the Information Regulator alleging interference with the protection of personal information.

8.Retention and destruction

MolarPlus retains practice data for as long as the practice’s account is active. A practice may download a complete copy of its data at any time. When a practice closes its account and instructs MolarPlus to destroy or delete its data, MolarPlus deletes that data from its production systems, and copies held in automated backups expire as the 7-day backup window rolls over.

Section 14 permits retention for longer where a law or code of conduct requires it. Practices remain responsible for keeping health records for the period their professional regulator requires, and should export those records before requesting deletion.

9.Contact

Patients should first contact the Information Officer of their practice. Practices, and questions about this statement, may be directed to:

Privacy contact
Grievance Officer, MolarPlus
Telephone: +91 9594078777
Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006, India

© 2026 MolarPlus Powered by Upclick labs (OPC) Pvt. ltd.