We are Novation (Pty) Ltd, a limited liability company incorporated in South Africa, registration number: 2000/006781/07. Our address is 210 Long Street, Cape Town, 8001 and if you need to send us any legal documents, please send them there. You can contact us at info@novation.co.za.


What is POPI?

The Protection of Personal Information (POPI) Act no. 3 of 2013 is a South African law which protects people’s personal information (PI) and privacy.

Why should you care?

Protecting your own and other people’s personal information helps develop trust, stop criminal acts (like fraud and identity theft), prevent privacy invasion and avoid fines and litigation. Of course there are many more reasons than that, but isn’t that enough?

What must you do?

You gotto try a little governance. ☺ This course only works if you participate. What you are doing is identifying the problems (risks) relating to your use of personal information, and changing the way you behave and the way you use that PI to reduce your risks and become more POPI compliant.

Will all your POPI risks be fixed by the end of this course?

The course helps you identify the biggest POPI risks in your practice, and to come up with some solutions to reduce or elimate those risks.
That being said; POPI is a complex piece of legislation which expects you to apply a whole lot of principles to your medical practice and then to take appropriate action. To do this you need POPI experts to come to your business and evaluate it properly and design solutions. Even then you often don’t get rid of all the risks, but you definitely make it less likely that you will breach the law and get into any litigation.

Why doesn’t the POPI DIY course fix everything?

The simple answer is that every practice and every business is different, and POPI is complex. If, by the end of this course, you feel that you need an in-depth, on-site risk analysis, contact us and we can set up a day to meet with you and your staff.

Is this legal advice?

Nope, it’s not. We can give you advice, but then we’d have to spend more time learning about the risks in your environment. Like any consulting service we undertake to give you the best advice we can.


What are you paying?

The price of the POPI course is R3990 (including VAT).

What does the price include?

The price includes a weekly email for the 10 weeks, an hour’s consultation time with one of our POPI experts, a risk register template, examples of a process diagram showing the flow of personal information, and plenty of resources to help you.
The course is designed to take about 1 hour of your time per week and is specifically designed for a busy medical practice where sometimes time is more important than money.
Our price does not include any evaluation of your business processes, nor any time we may spend at your business (but you can ask us to quote for this if you want some help).

When must you pay?

The course price must be paid into our bank account (we will send you an invoice) before you can start the course.

How must you pay?

Payment must be made by means of Electronic Funds Transfer (EFT), into our bank account. There are payment instructions (including your payment reference number) on the invoice. Ensure that you follow them so we can allocate your payment correctly.

What happens if you pay late?

If you pay late, we will enrol you into the next POPI DIY course.


Can the order be cancelled?

You may cancel the POPI DIY course before it starts, but once it has started you cannot cancel it. We will try and be reasonable if you have a good reason to cancel the course (such as enrolling you in a later course) so please let us know if you need to cancel.
If you want to cancel the POPI DIY course you must let us know in writing by sending us an email at info@novcon.co.za. Please remember that you must cancel the course more than 10 calendar days before the start of the course.

What are the financial implications of cancelling the order?

If you cancel your order within 10 calendar days of placing your order we will refund the full price you paid. You cannot cancel the order more than 10 calendar days after placing the order.


What do we use your personal information for?

We use your personal information to make a record of who purchased the POPI DIY course so that we can generate our invoice, deliver the POPI DIY course to you, to get feedback from you on any problems, and to enforce our rights (like copyright, for example).
Please ensure that the information you gave us is correct, and let us know if your personal information changes. We’d hate to send the weekly emails to the wrong address!

Will we share your personal information?

We will not share your information unless we have to in order to fulfil our agreement with you, if you have given your informed and specific consent or if we are legally required to do so.

What personal information do we keep?

We keep the following personal information about you and the entity (such as a company) you represent:
Your name and surname,
The name of your medical practice,
Telephone and email details,
VAT number,
Your bank account details (if you pay by means of EFT and send us proof of payment).

What personal information do we refuse to keep?

We don’t collect (or want) the personal information of your patients. Please don’t send them to us.
Please do not send us any information that could compromise your security (like what your alarm code is or where your spare key is located). We will just delete this.

Can you find out what personal information we have about you?

You are entitled to know what personal information we hold about you. Before we can respond to any requests you make about your information we must make sure of your identity. If you want to find out what information we hold about you, please email liezl@novcon.co.za with the details of your request.

What about personal information shared with other companies?

We will share your personal information with any person / legal entity that you ask us to. Once we have shared this personal information with them they will be responsible for keeping your personal information safe and secure and respecting your rights. You agree that you will not hold us liable in any way for any damages of any sort that you may suffer from their failure to protect your personal information or use it correctly.

What do you do if you suspect that there has been a security breach?

We do all we reasonably can to protect and secure your personal information. Despite this, if you suspect that we (or you) have had a security breach please NOTIFY US IMMEDIATELY by sending an email to liezl@novcon.co.za or call us at +27 21 481 1835.
When you notify us please include as much information as you can, such as:

  • when the security breach occurred,
  • when you found out about the security breach,
  • the Information that was affected by the breach,
  • the people who were or may be affected,
  • any steps you have taken to rectify the breach, and
  • any suggestions you have that could minimise the effect of the security breach.


What should you do if either of us have a complaint?

If you have a complaint please send an email to liezl@novcon.co.za or call us at +27 21 481 1835. We will do our best to resolve complaints internally.
If we cannot resolve your complaint and it relates to the quality of our POPI DIY course or the terms of this agreement, you should complain to the Consumer Goods and Services Ombud via its online complaint form, by e-mail to info@cgso.org.za or by calling 0860 000 272.
If we have a complaint about non-payment, we may institute legal action in the ordinary courts. A certificate issued by a manager or director regarding how much you owe will be considered sufficient evidence for purposes of provisional sentence, summary judgment proceedings or other proceedings. In other words, you have to prove that our account of what is owed to us is incorrect.
We will be entitled to recover all costs and charges relating to debt collection, including all legal costs charged by our legal representatives (in legal terms, costs on the attorney and own client scale).

Which country’s laws will apply to this agreement?

This contract was concluded in South Africa. This means that South African law will apply to this agreement and, unless we agree otherwise.

Where and how must legal notices must served?

The address and the e-mail address you have given us are very important. We will use it to serve any legal documents in terms of this contract.
We choose the address we mentioned at the beginning of this Agreement as the address for service of legal documents.