Last updated 27 July 2026 · Botswana Data Protection Act, 2018
In short: patient data entered into Bupilo belongs to the practice, not to us. We hold it only to run the service for that practice. We never sell it, never share it for anyone else's marketing, and never use it to build products for other customers. Each practice's data sits in its own separate database.
Bupilo (Pty) Ltd is a company incorporated in the Republic of Botswana (registration number [COMPANY REG NO]), with its office at [STREET ADDRESS], Gaborone. We develop and operate Bupilo, a hospital and medical practice management system used by healthcare providers in Botswana.
Our data protection contact is privacy@bupilo.co.bw.
This distinction matters, so it is worth being precise:
We do not use patient data for marketing, profiling, advertising, resale or product development for other customers, and we do not permit anyone else to.
Under the Botswana Data Protection Act, 2018 we rely on:
We share personal data only where it is necessary, and only with the following categories:
| Who | What they receive | Why |
|---|---|---|
| Our hosting provider (certified data centre, France, EU) | Encrypted storage and compute for the platform | To run the service. Bound by a written processing agreement. |
| DPO Pay and PayPal | Invoice number, amount, currency and billing email | To take subscription payments. Card numbers are entered on their secure pages and are never sent to, processed by, or stored on Bupilo's systems. We receive only a confirmation that payment succeeded. |
| SMTP2GO (email delivery) | Recipient address and the content of the notification | To deliver billing and system notification emails. |
| Medical-aid schemes and funders | Claim data the practice chooses to submit | Only when the practice submits a claim. The practice controls this entirely. |
| Courts, regulators and law enforcement | Only what is lawfully required | Where we are legally compelled. We notify the affected practice unless the law forbids it. |
We never sell personal data. We never share patient data between practices. We never give one customer access to another customer's data.
Bupilo is hosted in a certified data centre in France, in the European Union. The European Union maintains a data-protection regime recognised as providing a standard of protection at least equivalent to that required by the Botswana Data Protection Act, 2018, including binding obligations on processors, mandatory breach notification and enforceable individual rights. Transfers of data outside Botswana are made on that basis and are governed by written processing agreements with our providers.
Backups are encrypted and stored separately from the live system. Backup copies are subject to the same protections and retention limits as the live data.
Fuller detail is in our security statement.
| Data | Retention |
|---|---|
| Patient and clinical records in a practice environment | For as long as the practice's subscription is active. The practice sets its own retention rules in line with its professional and legal obligations. |
| All practice data after cancellation | 90 days, so the practice can export or return, then securely and permanently deleted including from backups. |
| Invoices, payments and accounting records | As required by Botswana tax law (currently seven years). |
| Security and audit logs | Up to 24 months. |
| Support correspondence | 24 months from closure of the request. |
Data is not deleted because an invoice is unpaid. Suspension restricts access only — see the terms of service.
Under the Botswana Data Protection Act, 2018 you have the right to:
Write to privacy@bupilo.co.bw. We respond within 30 days and do not charge for a first request.
If you are a patient of a practice that uses Bupilo, your relationship is with that practice. They decide what is recorded about you and why; we only hold it on their behalf. Please direct requests to see, correct or erase your records to your healthcare provider — they can act on them directly in the system. If you contact us instead, we will pass your request to the practice and tell you we have done so; we are not permitted to change or disclose a practice's patient records ourselves.
If a personal data breach occurs, we will notify the affected practice without undue delay and in any event within 72 hours of becoming aware of it, with what we know about what happened, what data was involved, what we are doing about it, and what we recommend. We will notify the Information and Data Protection Commission where the law requires it, and support the practice in notifying affected individuals where that is required of them.
This website (www.bupilo.co.bw) sets no cookies, runs no third-party analytics, no advertising trackers, no social media pixels and no external fonts or scripts. Nothing is loaded from another company's servers. Our web server keeps standard access logs (IP address, time, page requested, browser type) for security and troubleshooting, for up to 30 days.
The application itself (app.bupilo.co.bw) uses cookies and browser storage that are strictly necessary to keep you signed in securely. It does not track you for advertising.
If we change this policy in a way that materially affects how personal data is handled, we will notify subscribing practices in writing at least thirty days before the change takes effect. The date at the top of this page always reflects the current version.
Bupilo (Pty) Ltd
[STREET ADDRESS], Gaborone, Botswana
Data protection: privacy@bupilo.co.bw
General: hello@bupilo.co.bw
Telephone: [PHONE]
You also have the right to complain directly to the Information and Data Protection Commission of Botswana.