Processing of personal information
Scope and role allocation
The particulars in this section describe Sequrin's processing of personal information in its corporate, website, research, development and service activities. The nature and extent of processing depend on the relevant business activity or customer arrangement.
Sequrin acts as a responsible party for personal information processed for its own corporate and operational purposes. Where Sequrin processes information on behalf of a customer under documented instructions, its role is determined by the applicable contractual and statutory arrangement.
Purposes of processing
Sequrin may process personal information for corporate administration, governance and statutory compliance; finance, accounting, banking, tax and procurement administration; managing customers, prospective customers, partners, vendors, advisers and other business relationships; recruitment, contracting and workforce administration where applicable; operating, securing, supporting and improving websites, software, systems and development environments; responding to communications, rights requests, PAIA requests, legal notices and regulatory enquiries; protecting Sequrin's systems, rights, intellectual property and legitimate business interests; research, product development, testing, validation, demonstrations and quality assurance; and providing authorised claims-integrity analytics, fraud/waste/abuse risk detection, investigation support or related services under applicable customer arrangements.
Any processing of real medical-scheme, member, beneficiary, dependant, provider, clinical or claims information is subject to the applicable POPIA role allocation, lawful basis, contractual terms, security requirements, retention rules, transfer requirements and any required prior authorisation.
Categories of data subjects and personal information
Data subjects may include directors, shareholders and beneficial owners; customers, prospective customers and partners; vendors, advisers and service providers; applicants, contractors and personnel; website users and correspondents; regulators and authorities; and members, beneficiaries, dependants, providers and other persons represented in customer-controlled claims data where lawfully processed.
Personal information may include identity, contact, corporate-role, ownership and statutory information; business contact, organisation, correspondence, contract, due-diligence and relationship information; contractual, financial and access information; qualification, application and remuneration information; IP or technical request information, device/browser information where generated, messages and related correspondence; official contact, submission, registration and case information; and, where lawfully processed, claims, benefit, provider and identity information, pseudonymous identifiers, health or clinical information, fraud, waste and abuse indicators, information concerning alleged unlawful conduct and derived risk or investigative signals.
Recipients or categories of recipients
Recipients may include authorised Sequrin personnel and contractors; professional advisers, auditors and insurers; banks, payment providers and financial-administration providers; approved hosting, cloud, security, communications, software-development and IT providers; customers, counterparties and their authorised representatives where relevant to the relationship; and regulators, law-enforcement bodies, courts or other authorities where disclosure is authorised or required by law.
Planned transborder flows of personal information
Sequrin uses technology and cloud service providers that may process business information outside South Africa. Transborder processing is managed in accordance with section 72 of POPIA and applicable contractual and security requirements.
For customer-controlled claims, health or clinical information, permitted processing locations and transfer arrangements are determined for the relevant customer deployment. Cross-border processing of such information is permitted only where the applicable customer instructions, legal basis, safeguards and any required prior authorisation allow it.
General description of information-security measures
Sequrin applies risk-based technical and organisational safeguards appropriate to the nature of the information and the relevant system. These include, as applicable, role-based access control and least privilege; authentication, credential-management and access-review controls; encryption in transit and, where appropriate to the system and risk, at rest; logging, monitoring and audit trails; secure software-development, review and change-management practices; vulnerability, dependency and configuration management; backup, recovery, continuity and resilience measures; confidentiality obligations and supplier-security requirements; incident identification, escalation, response and notification procedures; and periodic privacy, security and vendor-risk review.
For customer deployments involving live claims or health information, deployment-specific access controls, data flows, retention rules, incident responsibilities and security requirements are documented as part of the implementation and customer arrangements.