NuMeRI
  • Home
  • About Us
  • Our Operations
    • Overview
    • Preclinical Molecular Imaging Centre
    • Medical Physics & Radiobiology
    • Radiopharmacy
    • Basic & Translational Research (BTR) Laboratory
    • Clinical and Theranostics
    • Node for Infection Imaging
    • Publications
  • Highlights
  • News
  • Team
  • Contact Us

Privacy Policy

NuMeRI’s Data Privacy and Protection Policy, and how this website uses your information.

NuMeRI Data Privacy and Protection Policy
Version 1.0  ·  Policy owner: Information Officer  ·  Review cycle: annually, or following a material regulatory, organisational or security change
Effective date: [TO CONFIRM: effective date]

On this page

  • 1. Purpose · 2. Scope · 3. Personal information we process
  • 4. Principles · 5. Purpose of processing · 6. Medical imaging and research information
  • 7. Access · 8. Information security · 9. Passwords and authentication
  • 10. Third parties and operators · 11. Cross-border transfers · 12. Storage and backup
  • 13. Retention and disposal · 14. Data subject rights · 15. Website and electronic information
  • 16. Email · 17. Security incidents and data breaches · 18. Responsibilities
  • 19. Confidentiality · 20. Privacy by design · 21. Information Officer
  • 22. Contact details · 23. Information Regulator · 24. Non-compliance · 25. Policy review
  • Appendix A — This website

1. Purpose

NuMeRI is committed to protecting the privacy, confidentiality, integrity and availability of personal information entrusted to it.

This policy establishes how NuMeRI collects, processes, stores, shares, protects, retains and disposes of personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African legislation, ethical requirements and research governance requirements.

This policy applies to personal information processed electronically, physically, verbally or in any other format.

2. Scope

This policy applies to all NuMeRI:

  • Employees and contractors
  • Researchers and research collaborators
  • Students and visiting researchers
  • Patients and research participants
  • Healthcare professionals
  • Suppliers and service providers
  • Partners and collaborating institutions
  • Website visitors
  • Information systems, applications, databases and physical records

All persons who process personal information on behalf of NuMeRI must comply with this policy.

3. Personal Information We Process

Depending on the relationship with the individual, NuMeRI may process information including:

  • Names and contact information
  • Identity and demographic information
  • Employment and HR information
  • Financial and payment information
  • Professional and academic information
  • Research participant information
  • Patient and clinical information
  • Medical history and treatment information
  • Medical imaging and associated DICOM information
  • Laboratory and research results
  • Biological and scientific research data
  • IP addresses, website usage information and electronic logs
  • CCTV and physical-access records
  • Communications and correspondence

Special Personal Information

Due to the nature of NuMeRI’s activities, information processed may include special personal information, particularly health, medical, biometric, genetic and research-related information.

Such information will receive enhanced protection and will only be processed where permitted by law, appropriate consent, research protocols, ethical approvals, contractual requirements or another lawful basis.

4. Principles of Processing

NuMeRI will process personal information according to the following principles:

  • Accountability — NuMeRI remains responsible for personal information under its control.
  • Lawful processing — information will only be processed where there is a lawful and legitimate basis.
  • Purpose specification — information will be collected for specific and defined purposes.
  • Data minimisation — only information reasonably required for the relevant purpose will be collected.
  • Accuracy — reasonable steps will be taken to maintain accurate and current information.
  • Retention limitation — information will not be retained longer than [TO CONFIRM: the source text is garbled here — it reads "longer than requiresearch requirements or legitimate operational needs". Please supply the intended wording, e.g. "longer than required by law, research requirements or legitimate operational needs"].
  • Transparency — individuals will be informed, where appropriate, about how their information is used.
  • Security — appropriate technical and organisational safeguards will be implemented.

5. Purpose of Processing

NuMeRI may process personal information for purposes including:

  • Providing medical imaging and associated clinical services
  • Conducting approved scientific and medical research
  • Managing clinical trials and research projects
  • Patient administration and care
  • Research participant recruitment and management
  • Medical imaging acquisition, storage, analysis and transfer
  • Collaboration with hospitals, universities, research institutions and other authorised organisations
  • Regulatory and ethical compliance
  • Human resources and payroll
  • Procurement and supplier management
  • Financial administration
  • Information technology and cybersecurity
  • Facility and physical security
  • Communication with researchers, patients, partners and stakeholders
  • Legal and contractual obligations
  • Website operation and administration

Personal information will not be used for an incompatible purpose without an appropriate lawful basis.

6. Medical Imaging and Research Information

Medical imaging and associated information, including PET, PET-CT, SPECT-CT, CT and other imaging data, must be treated as confidential information.

Access to identifiable medical imaging information will be restricted to appropriately authorised personnel.

Where practical and appropriate for research activities, information should be:

  • De-identified;
  • Pseudonymised; or
  • Anonymised

before being provided to researchers or third parties.

Original medical and research information must be protected from unauthorised modification or deletion.

Research data must be processed in accordance with approved research protocols, ethics approvals, participant consent requirements and applicable legislation.

7. Access to Personal Information

Access must be granted according to the principle of least privilege.

Employees, researchers and contractors will only receive access to personal information reasonably necessary for their duties.

Where technically possible:

  • Each user must have an individual user account.
  • Shared user accounts should be avoided.
  • Strong authentication must be used.
  • Multi-factor authentication should be implemented for sensitive and remote-access systems.
  • Access permissions must be reviewed periodically.
  • Access must be removed or amended when a person’s role changes or employment/engagement ends.
  • Access to sensitive systems should be logged and auditable.

Unauthorised access to patient, research or employee information is prohibited.

8. Information Security

NuMeRI will maintain reasonable technical and organisational safeguards appropriate to the sensitivity of the information being processed.

These measures may include:

  • Firewalls and network security controls
  • Endpoint protection
  • Anti-malware protection
  • Encryption
  • Multi-factor authentication
  • Access control
  • Secure remote access
  • Vulnerability and patch management
  • System monitoring and logging
  • Secure backups
  • Disaster recovery procedures
  • Network segmentation
  • Email security
  • Physical access controls
  • Security awareness training
  • Vendor and third-party security controls

Security measures will be reviewed and improved as risks, technology and regulatory requirements change.

9. Passwords and Authentication

Users must:

  • Keep passwords confidential.
  • Not share passwords with colleagues or third parties.
  • Use strong and unique passwords.
  • Use multi-factor authentication where required.
  • Immediately report suspected account compromise.

Credentials belonging to another person may not be used.

10. Third Parties and Operators

NuMeRI may use service providers and other organisations to process personal information on its behalf.

These may include:

  • IT service providers
  • Cloud service providers
  • Healthcare organisations
  • Laboratories
  • Universities
  • Research institutions
  • Pharmaceutical organisations
  • Clinical research organisations
  • Equipment manufacturers and technical support providers
  • Financial and payroll providers
  • Professional advisers

Where a third party acts as an Operator under POPIA, NuMeRI will take reasonable steps to ensure that an appropriate written agreement is in place requiring the Operator to protect the information and maintain appropriate security safeguards.

Third parties will only be provided with information reasonably necessary for the authorised purpose.

11. International and Cross-Border Transfers

Personal information may only be transferred outside South Africa where the transfer complies with POPIA and other applicable requirements.

Where NuMeRI uses international cloud platforms, research collaborators or other international service providers, appropriate safeguards must be implemented.

Sensitive medical or research information must not be transferred internationally without appropriate authorisation and safeguards.

12. Storage and Backup

Personal information must only be stored on systems, devices and locations approved by NuMeRI.

Sensitive information must not be stored on unauthorised:

  • Personal computers
  • Personal cloud storage accounts
  • USB devices
  • External hard drives
  • Mobile devices
  • Consumer file-sharing platforms

unless specifically authorised and appropriately protected.

Critical information must be backed up according to NuMeRI’s backup and disaster-recovery requirements.

Backups containing personal information are subject to the same confidentiality and security requirements as production information.

13. Retention and Disposal

NuMeRI will retain personal information only for as long as required by:

  • Applicable legislation
  • Medical record retention requirements
  • Research protocols
  • Ethics requirements
  • Contractual obligations
  • Funding requirements
  • Scientific integrity requirements
  • Legitimate operational purposes

Once information is no longer required, it must be securely deleted, destroyed, anonymised or archived where lawful retention remains necessary.

Paper records containing personal information must be securely shredded or destroyed.

Electronic information must be securely erased using an appropriate method.

14. Data Subject Rights

Subject to applicable law, individuals have the right to:

  • Request confirmation that NuMeRI holds their personal information.
  • Request access to their personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion or destruction where legally appropriate.
  • Object to certain processing.
  • Withdraw consent where processing relies upon consent.
  • Lodge a complaint regarding the processing of their information.

Requests relating to personal information must be submitted to NuMeRI’s Information Officer.

Certain information may need to be retained despite a deletion request where NuMeRI has a legal, medical, scientific, contractual or regulatory obligation to retain it.

15. Website and Electronic Information

NuMeRI may collect limited information when individuals use the NuMeRI website, including:

  • IP address
  • Device and browser information
  • Website activity
  • Cookies
  • Information voluntarily submitted through online forms

Website information will only be used for legitimate purposes such as website operation, security, analytics and responding to enquiries.

Where required, appropriate cookie notices and consent mechanisms will be implemented.

What this website actually does today. This section describes what NuMeRI’s website may collect. As currently built, sanumeri.co.za sets no cookies, uses no analytics and runs no advertising or tracking technology. See Appendix A and our Cookie Policy for exactly what is and is not collected.

16. Email and Electronic Communication

Personal and confidential information must be handled carefully when sent electronically.

Employees must verify recipients before sending sensitive information.

Where appropriate, sensitive information should be transmitted through secure or encrypted mechanisms rather than normal unprotected email.

Patient and research information must not be sent to personal email accounts unless specifically authorised.

17. Security Incidents and Data Breaches

All actual or suspected privacy or security incidents must be reported immediately to NuMeRI’s Information Officer and designated IT/security personnel.

Examples include:

  • Lost or stolen devices
  • Misdirected emails
  • Unauthorised access to patient information
  • Compromised user accounts
  • Malware or ransomware
  • Accidental publication of confidential information
  • Loss of medical or research records
  • Unauthorised copying or transfer of information

NuMeRI will investigate suspected incidents, contain the threat, preserve relevant evidence and determine appropriate remedial action.

Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, NuMeRI will comply with the applicable POPIA requirements for notification to the Information Regulator and affected data subjects.

Employees must not independently communicate publicly about a data breach unless authorised to do so.

18. Employee and Researcher Responsibilities

Everyone with access to NuMeRI information must:

  • Protect the confidentiality of personal information.
  • Only access information required for authorised duties.
  • Not disclose information without authority.
  • Follow NuMeRI information-security policies and procedures.
  • Keep authentication credentials secure.
  • Secure computers when unattended.
  • Report suspected security incidents immediately.
  • Complete required privacy and cybersecurity training.
  • Ensure physical records are appropriately protected.

Browsing patient or research records without an authorised business, research or clinical reason is prohibited.

19. Confidentiality

Employees, researchers, students, contractors and relevant third parties may be required to enter into confidentiality agreements.

Confidentiality obligations continue after employment, research involvement or contractual relationships have ended.

20. Privacy by Design

New systems, projects and research activities that involve significant processing of personal or special personal information should consider privacy and security requirements during the design stage.

Where appropriate, NuMeRI should conduct a privacy or information-security risk assessment before implementing:

  • New clinical information systems
  • PACS or medical imaging systems
  • Research databases
  • Cloud services
  • Artificial intelligence systems
  • Patient portals
  • New external integrations
  • Large-scale research projects
  • Systems processing special personal information

21. Information Officer

NuMeRI’s Information Officer is responsible for oversight of POPIA compliance and privacy governance.

Information Officer[TO CONFIRM: name]
Deputy Information Officer[TO CONFIRM: name, if applicable]
Email[TO CONFIRM: privacy / POPIA email address]
Telephone[TO CONFIRM: telephone number]

Privacy-related requests, complaints and suspected breaches should be directed to the Information Officer.

22. NuMeRI Contact Details

NuMeRI Main Centre
C/O Steve Biko and Malan Street
Capital Park
Pretoria, 0002
South Africa

Telephone: 010 030 0599
Website: www.sanumeri.co.za

23. Information Regulator

Individuals also have the right to lodge a complaint with the Information Regulator of South Africa.

Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, South Africa
Email: enquiries@inforegulator.org.za
Website: www.inforegulator.org.za

24. Non-Compliance

Failure to comply with this policy may result in:

  • Removal or restriction of system access
  • Disciplinary action
  • Termination of contractual or research access
  • Regulatory reporting where required
  • Civil or criminal consequences where applicable

25. Policy Review

This policy will be reviewed at least annually and whenever there is:

  • A significant change to legislation;
  • A significant change to NuMeRI’s operations;
  • Implementation of major new information systems;
  • A significant security incident;
  • A material change in the nature of information being processed; or
  • A requirement from an ethics committee, regulator or other competent authority.

Appendix A — This website

This appendix supplements the policy above with the specific detail required by section 18 of POPIA for visitors to sanumeri.co.za. It reflects what the website does as built and verified on 22 August 2026.

What this website collects

WhereWhatWhy
Contact form Name, email address, organisation (optional), subject and message. To read and reply to your enquiry. The message is emailed to our office; it is not stored in a database on this website.
Job applications Whatever you include — typically a CV, a cover letter, and the names and contact details of three referees. To assess your application and contact you and your referees. Applications are emailed directly to HR; nothing is uploaded to or stored on this website.
Web server logs Standard hosting records, which may include IP address, browser type and pages requested. To keep the site running and secure. Not used to identify individual visitors.

Supplying information through this website is entirely voluntary. The only consequence of not doing so is practical: we cannot reply to an enquiry, or consider an application, without the relevant details. You may contact us by telephone or post instead.

If you supply a referee’s contact details, please make sure they are content for you to do so — we receive their information from you rather than from them.

Cookies and third parties

This website sets no cookies, uses no analytics, and runs no advertising or tracking technology. It stores nothing on your device. Two external services are contacted by your browser, and both therefore receive your IP address:

  • Google Fonts — on every page, to load the site’s typeface. Sets no cookies.
  • YouTube — on the home page only, for an embedded video, using YouTube’s privacy-enhanced youtube-nocookie.com domain. It does not set tracking cookies unless you play the video.

Both are operated by Google and process data outside South Africa. Neither receives your contact-form or application information. Full detail is in our Cookie Policy.

Security note

This site is served over an encrypted HTTPS connection. No transmission over the internet is completely secure, so please do not send sensitive information — such as medical details or identity-document numbers — through the contact form.

Exercising your rights

The rights set out in section 14 above apply to information collected through this website. To exercise them, or to complain, contact the Information Officer (section 21) or the Information Regulator (section 23).

Last updated: 22 August 2026. NuMeRI may update this document from time to time; the current version always appears on this page.

Nuclear Medicine Research Infrastructure

NuMeRI (SBAH)

NuMeRI Main Centre: C/O Steve Biko and Malan Street,
Capital Park,
Pretoria
0002
TEL: 010 030 0599
E-Mail: KMogale@sanumeri.co.za

NuMeRI Node for Infection Imaging

NuMeRI Node for Infection Imaging

Premises of Tygerberg Hospital
Francie van Zijl Drive,
Tygerberg,
7500
NuMeRI NII PET-CT Unit: https://share.google/rxuLGm3rSZ03q3VEZ

Quick Links

  • Home
  • About us
  • Team
  • Contact us

Our Operations

  • Overview
  • Preclinical Molecular Imaging Centre
  • Medical Physics & Radiobiology
  • Radiopharmacy
  • Basic & Translational Research (BTR) Laboratory
  • Clinical and Theranostics
  • Node for Infection Imaging
  • Publications

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms & Conditions
  • Disclaimer
  • Imprint

© NuMeRI 2025. All rights reserved Copyrights 2025