Legal
Privacy Policy
This policy explains how Martin Grimbly Optometrist collects, uses, and protects your personal information, and what rights you have under the Protection of Personal Information Act 4 of 2013 (POPIA).
Last updated: 28 July 2026
1. Who we are and what this policy covers
Martin Grimbly Optometrist is an independent optometry practice in Brackenfell, Western Cape, South Africa. We are the responsible party for personal information collected through this website and in the course of providing optometric services. Our Information Officer is accountable for ensuring this practice complies with POPIA.
Scope of this policy: this document describes how we handle personal information collected through this website and its associated online services — contact and appointment enquiries, lens orders, auto-reorder subscriptions, and website analytics. Clinical records created during in-practice consultations (eye examinations, prescriptions, clinical history) are held in our separate practice management system and are governed by the professional duties of the Health Professions Council of South Africa (HPCSA) and by a separate clinical records notice available on request from the Information Officer.
Information Officer: Dr Martin Grimbly
Address: 3 Church Street, Arauna, Brackenfell, Western Cape, 7560
Email: [email protected]
Telephone: 021 981 4579
2. Personal information we collect
We collect only the personal information necessary for the purposes described below.
Contact and appointment enquiries
When you submit a contact, appointment, or general enquiry via our website forms, we collect your name, email address, phone number, and the content of your message. This information is delivered to the practice by email. We do not retain this information in our records beyond our practice email system, where it is kept for as long as needed to respond to your enquiry.
Special offers sign-up (direct marketing)
If you sign up for special offers or practice news, we collect your email address and tick-box confirmation that you consent under section 69 of POPIA to receive occasional electronic direct marketing from the practice. We also record the date and time, your IP address, and the version of the consent text you agreed to as an audit trail. Marketing emails are sent via our email provider, Brevo, who hosts the list. Every marketing email includes a one-click unsubscribe link, and you can withdraw consent at any time by clicking that link, by replying to any such email, or by contacting our Information Officer.
Contact lens reorder requests (manual form)
When you submit a lens reorder request form, we collect your name, email address, phone number, lens product, quantities, and delivery preference. New patients may also upload a prescription. This information is delivered to the practice by email for processing and is not retained in our records.
Online checkout orders (one-off)
When you place a contact lens order through our online checkout, we record and retain: your name, email address, phone number, lens product details, quantities, delivery address (if applicable), order amount, payment reference, payment status, your IP address, and your browser information (user agent). This is used to process, fulfil, and administer your order. If you choose to upload your prescription at checkout, the file is sent directly to the practice's email inbox for verification and is not stored by the website — we record only that a file was provided and its filename.
Medical aid claims at checkout
If you choose to claim from your medical aid at checkout instead of paying the cash price, we collect your medical aid scheme name and membership number, with your consent, so our staff can confirm your contribution and send you a payment request for the balance. We treat these details as sensitive personal information: they are stored only for this order, used solely to process your payment, never shared beyond what is needed to administer your order, and included in any access or deletion request you make. We do not store any clinical benefit or claim-history data.
Auto-reorder subscriptions
If you enrol in our contact lens auto-reorder programme, we store in addition to the above: your prescription expiry date (entered by our staff after verification), your billing schedule and subscription status, and a secure payment token issued by PayFast that represents your card. We never receive or store your card number or CVV. Your explicit consent is recorded with a timestamp and version reference for each purpose you agreed to.
Website usage data
We use analytics services to understand how our website is used. See section 10 for full details.
Children under 18
Our online ordering and subscription services are directed at adults (18 and older). We do not knowingly collect personal information from children under 18 through this website. Where a minor is the patient of record — for example, when a parent orders contact lenses for a child — the account-holder and person giving consent must be a competent adult (parent or legal guardian), as required by section 34 of POPIA. If you believe a child has provided us with personal information through this website, please contact our Information Officer and we will delete it promptly.
3. Legal basis for processing
We process your personal information on the following grounds under POPIA:
- Performance of a contract — to process and fulfil your lens orders and subscriptions.
- Consent — for auto-reorder subscriptions, payment tokenisation, optional script-expiry reminder emails, and electronic direct marketing (POPIA s69). You may withdraw consent at any time (see section 9).
- Legitimate interest — to maintain records for security, fraud prevention, and dispute resolution, and to operate website analytics to improve our service.
- Legal obligation — to retain financial records as required by South African law, including the VAT Act 89 of 1991.
4. Who we share your information with
We do not sell your personal information. We share it only with the service providers listed below, each of whom processes it on our behalf under the terms of our service agreement with them, and each of whom publishes its own data-protection terms describing how it handles the information it receives.
PayFast (DPO PayFast (Pty) Ltd)
Our payment processor. PayFast receives your name, email, and order amount to process card payments. For subscriptions, PayFast issues a secure token that represents your card — we never receive or store your card number. PayFast is based in South Africa and is PCI-DSS compliant.
Brevo SAS
Our transactional email provider (formerly known as Sendinblue SAS). Form submissions, order notifications, and marketing campaigns to special-offers subscribers are transmitted via Brevo's servers; Brevo also hosts the marketing subscriber list itself. Brevo is based in France and operates under the EU General Data Protection Regulation (GDPR), which affords protections comparable to POPIA.
Cloudflare Inc.
Our website host and infrastructure provider. All web traffic passes through Cloudflare's global network. Cloudflare also provides our form bot-detection service. Cloudflare is based in the United States and participates in recognised cross-border data transfer frameworks.
Google LLC
We use Google Analytics (GA4) to measure website usage. Google receives anonymised usage data including your approximate location, device type, and pages visited. IP addresses are anonymised before storage in GA4. Google is based in the United States. Our contact page also embeds a Google Map; loading it connects your browser to Google's servers. See section 10 for opt-out options.
5. Cross-border transfers
Some of the service providers listed above are based outside South Africa. Where your personal information is transferred internationally we rely on section 72 of POPIA, which permits cross-border transfer where the recipient is subject to a law, binding corporate rules, or binding agreement providing an adequate level of protection. In practice this means we use providers who operate under legislation comparable to POPIA (such as the EU GDPR) or who participate in recognised cross-border data transfer frameworks. We do not knowingly transfer your information to countries that lack adequate data-protection safeguards.
6. How long we keep your information
We keep personal information only for as long as it serves the purpose it was collected for, or for as long as the law requires us to keep it — whichever is longer. In practice that means:
Online orders and payment records — at least 7 years from the date of the transaction, to meet financial record-keeping obligations under the VAT Act and to preserve evidence in the event of a payment dispute or chargeback.
Subscription and patient records — for as long as you remain a patient of the practice, and thereafter for the periods required by our professional and financial record-keeping obligations.
Consent records — for as long as we rely on that consent, and afterwards as required by POPIA to demonstrate that our processing was lawful (a record of what you agreed to and when).
Enquiries, form submissions, and analytics data — for as long as needed to deal with your enquiry or, for analytics, in line with the retention period set on our analytics account (see section 10).
You may ask us at any time to delete information we no longer have a lawful basis to keep — see section 9.
7. How we protect your information
We take the following technical and organisational measures to protect your personal information:
- All website traffic is encrypted via HTTPS.
- Access to our records and patient data is restricted to authorised staff only.
- Payment card data is never stored by us — only a secure token issued by PayFast.
- Access to our administrative systems requires authenticated staff sign-in.
No method of electronic transmission or storage is completely secure. If we become aware of a data breach that materially affects your rights and interests, we will notify the Information Regulator and, where required, affected individuals within a reasonable timeframe as required by section 22 of POPIA.
8. Automated processing
Some subscription operations are automated: scheduled processes send script-expiry reminder emails and attempt scheduled subscription charges on your chosen cadence. If your prescription has expired, an automated charge will be skipped (not failed) and we will contact you to arrange a renewal. If a scheduled charge cannot be completed after several attempts, your subscription is automatically paused and a staff member contacts you. You can request human review of any automated decision at any time under section 71 of POPIA by contacting our Information Officer.
9. Your rights under POPIA
As a data subject under POPIA you have the following rights:
Right of access (section 23)
You may request a copy of the personal information we hold about you.
Right to correction or deletion (section 24)
You may request that we correct inaccurate or out-of-date information, or delete personal information we are no longer entitled to retain. Note that certain records (e.g. financial transaction logs) must be kept for statutory periods and cannot be deleted on request — we will explain any such constraints when responding to your request.
Right to object (section 11(3))
You may object to the processing of your personal information on grounds relating to your particular situation where processing is based on legitimate interest. If the objection is justified, we will cease the relevant processing.
Right to withdraw consent
Where processing is based on your consent — such as auto-reorder subscriptions or script-expiry reminder emails — you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of any processing that occurred before withdrawal.
Right to complain
If you believe your rights have been infringed, you may lodge a complaint with the Information Regulator (see section 11).
To exercise any of these rights, submit a request using our online data rights request form, or contact our Information Officer directly at [email protected] or 021 981 4579. We will respond within 30 days. We may need to verify your identity before acting on a request.
10. Cookies and analytics
Google Analytics (GA4)
We use Google Analytics to understand how visitors use our website. Google Analytics places cookies on your device to collect data including pages visited, session duration, device type, and approximate geographic location. IP addresses are anonymised before storage. Data is retained within Google Analytics in line with the retention period configured on our analytics account.
The simplest way to opt out is to click "Decline analytics" on the cookie notice at the bottom of this site — this sets a preference in your browser that prevents our Google Analytics script from tracking you on subsequent visits. You can also install the Google Analytics Opt-out Browser Add-on or configure your browser to block third-party cookies.
Cloudflare Turnstile
Our public forms use Cloudflare Turnstile to distinguish human visitors from automated bots. Turnstile may use cookies or browser storage as part of its challenge process. No personal information from Turnstile verification is stored by us.
Google Maps
Our contact page embeds a Google Map. Viewing that page causes your browser to connect to Google's servers, which may set Google cookies. If you wish to avoid this, you can view our address and directions directly in Google Maps without visiting the contact page, or use a browser extension that blocks third-party embeds.
Essential and session cookies
We do not use login or session cookies on the public-facing website. Our admin area requires staff authentication, which uses short-lived session cookies for authorised staff only.
11. The Information Regulator
If you are not satisfied with how we have handled your personal information or your rights request, you may lodge a complaint with South Africa's Information Regulator:
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Email: [email protected]
Website: www.inforegulator.org.za
12. Changes to this policy
We may update this policy from time to time. Material changes will be noted on this page with an updated date at the top. Continued use of the website after a change constitutes acceptance of the revised policy.
13. Contact our Information Officer
For any privacy-related queries, requests, or concerns, please contact:
Dr Martin Grimbly (Information Officer)
Martin Grimbly Optometrist
3 Church Street, Arauna, Brackenfell, Western Cape, 7560
Email: [email protected]
Tel: 021 981 4579
Hours: Mon to Fri 08:30 to 17:30, Sat 08:30 to 13:00