Legal
How Amy handles your data
Last updated: June 2026 · Republic of South Africa
Amy handles conversations on behalf of your clinic. That means she processes your clients’ personal information - and we take that responsibility seriously. This page explains what we collect, why, who else is involved, and what rights your clients have.
Who we are
Media Matters (Pty) Ltd, trading as MedSpa OS
MedSpa OS is the Operator - we process personal information on behalf of your clinic (the Responsible Party) in accordance with the Protection of Personal Information Act, 2013 (POPIA).
What Amy collects
When a client messages your clinic through a channel Amy manages, she processes:
- Phone number - to reply to the conversation
- Name - if the client shares it during the conversation
- Message content - to understand the enquiry and respond appropriately
- Treatment interests - to route the enquiry to the right service
- Safety flags - to protect the client by escalating clinical questions to your team
Amy does not collect or store:
- ID numbers or identity documents
- Payment or banking details
- Medical records or clinical notes
- Physical addresses
- Any information not voluntarily shared in the conversation
Why we process this data
All processing is for the purpose of handling client enquiries and booking requests on behalf of your clinic. The lawful basis for processing is legitimate interest - your clinic has a legitimate interest in responding to client enquiries efficiently and safely.
Amy never uses client data for marketing, advertising, profiling, or any purpose beyond handling the conversation on your clinic’s behalf.
Who else is involved
Amy is powered by the following service providers (sub-processors):
- Anthropic - AI language model that generates Amy’s replies. Message content is sent to Anthropic’s API for processing and is not retained for model training.
- Twilio - delivers WhatsApp messages between Amy and your clients.
- Hostinger - server infrastructure where conversation logs and client profiles are stored.
Data is processed using infrastructure located in the United States. Each provider is bound by data processing agreements that include standard contractual clauses for the protection of personal information in accordance with POPIA Section 72.
Your client data is never sold, shared with advertisers, or used to train AI models.
How long we keep data
- Conversation logs: retained for 12 months from the date of the conversation, then deleted.
- Client profiles: retained while your clinic is active with Amy.
- On cancellation: all clinic data is deleted within 30 days of your cancellation date. Written confirmation is provided on request.
Data security
- Each clinic’s data is isolated in its own workspace - there is no cross-clinic data access.
- All communications between Amy, your clients, and our service providers are encrypted in transit (HTTPS/TLS).
- Access to clinic data is restricted to authorised MedSpa OS personnel only.
- Safety-flagged messages are held for human review by your clinic team before delivery to the client.
- We maintain incident response procedures and will notify affected parties of any data breach as required by POPIA.
Your clients’ rights
Under POPIA, any person whose personal information Amy has processed has the right to:
- Request access to their personal information
- Request correction of inaccurate information
- Request deletion of their personal information
- Object to the processing of their information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, contact privacy@useamy.co.za. We will respond within 30 days.
Your responsibilities as a clinic
By using Amy, your clinic remains the Responsible Party under POPIA. We recommend that you:
- Inform your clients that an AI assistant helps handle enquiries on your behalf
- Include a reference to Amy in your own clinic privacy notice
- Review safety-flagged messages promptly when Amy holds them for your approval
A Data Processing Agreement (DPA) is provided to every clinic during onboarding, setting out the responsibilities of both parties.
Contact
For any privacy-related questions or data requests:
Information Regulator of South Africa
Website: https://inforegulator.org.za
Email: enquiries@inforegulator.org.za