HealthLynk Privacy Policy and POPIA Privacy Notice
Version: 1.0 Effective date: 17 August 2026 Last updated: 17 August 2026
HealthLynk (Pty) Ltd respects the privacy of the people who use our services and recognises that health information requires a particularly high level of care.
This Privacy Policy and POPIA Privacy Notice ("Privacy Policy") explains how HealthLynk collects, uses, stores, shares, protects and otherwise processes personal information when you use HealthLynk.
It should be read together with our Terms of Service and other applicable policies.
1. Who We Are
HealthLynk is operated by:
Legal name: HealthLynk (Pty) Ltd Registration number: 2026/646559/07 Country of registration: Republic of South Africa Director: Yanga Sodoza Website: healthylynk.com Telephone: 074 663 3106 Email: YangaSodoza@outlook.com Physical business address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
For purposes of the Protection of Personal Information Act 4 of 2013 ("POPIA"), HealthLynk will generally act as the responsible party for personal information processed through the HealthLynk consumer platform where HealthLynk determines why and how that information is processed.
In some organisational or care-service arrangements, another organisation may determine the purposes for which certain information is processed. In such circumstances, the parties' respective privacy responsibilities may also be governed by an additional written agreement.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed through the HealthLynk website, application, progressive web application, support channels and related services.
It applies to information concerning:
- account holders;
- people whose health profiles are stored on HealthLynk;
- children whose profiles are lawfully managed by a parent, guardian or other competent person;
- family members and other people connected through HealthLynk;
- people invited to claim a profile;
- authorised carers or persons with whom information is shared;
- customers and subscribers;
- representatives of organisations using HealthLynk; and
- visitors to our website.
A person whose information is processed is referred to in this Policy as a "data subject".
3. Personal Information We May Process
The personal information HealthLynk processes depends on the features you use.
3.1 Account and identity information
This may include your:
- name and surname;
- email address;
- telephone number;
- date of birth;
- authentication and verification information;
- account identifiers;
- account status; and
- subscription information.
3.2 Profile and family information
HealthLynk may process information relating to:
- personal profiles;
- family relationships;
- parent, guardian, dependant or manager relationships;
- invitations to another person;
- profile-claim status;
- permissions and access relationships; and
- information required to determine who may lawfully manage or access a profile.
3.3 Health and medical information
Depending on what users choose to record or upload, HealthLynk may process information concerning:
- medical history;
- healthcare encounters;
- visits to doctors, clinics, hospitals and other healthcare providers;
- medical conditions or health events;
- prescriptions and medicines;
- tests and test-related information;
- healthcare professionals;
- treatment-related information;
- discharge information;
- ongoing healthcare information;
- health-related notes;
- uploaded medical records, images or documents; and
- other health information voluntarily recorded through the Service.
Health information is treated as special personal information and receives additional protection.
3.4 Documents and files
Users may upload documents such as:
- prescriptions;
- test results;
- medical reports;
- referral documents;
- healthcare receipts;
- proof-of-payment or related documents; and
- other health-related records.
The contents of an uploaded document may themselves contain personal information or special personal information.
3.5 Payment and subscription information
When paid subscriptions are available, we may process information such as:
- selected subscription plan;
- billing frequency;
- transaction amount;
- payment status;
- payment reference;
- payment-provider identifiers;
- recurring-payment or token references; and
- subscription start, renewal, cancellation and expiry information.
Full payment-card details are intended to be processed by our authorised payment provider rather than stored directly by HealthLynk.
3.6 Technical and security information
We may process technical information reasonably necessary to operate and secure HealthLynk, including:
- IP address;
- browser and device information;
- session information;
- login activity;
- timestamps;
- security events;
- application and server logs;
- authentication events;
- failed-access attempts; and
- information used to detect fraud, abuse or unauthorised access.
3.7 Communications
If you communicate with HealthLynk, we may process your:
- name;
- contact details;
- support request;
- correspondence;
- complaint;
- feedback; and
- other information you provide during the communication.
4. Special Personal Information
HealthLynk is specifically designed to help people manage health-related information.
Health information is sensitive and is treated as special personal information under POPIA.
HealthLynk will only process special personal information where an appropriate legal basis and authorisation exists under applicable law.
Where HealthLynk relies on your consent to process health information, that consent must relate to the relevant processing activity.
You may withdraw consent where the law gives you that right. Withdrawal does not necessarily affect processing that was lawful before withdrawal, and it may mean that HealthLynk can no longer provide functionality that depends on processing the relevant information.
HealthLynk does not treat acceptance of general website cookies, marketing messages or unrelated functionality as consent to process health information.
5. Children's Personal Information
HealthLynk may allow a parent, legal guardian or other legally competent person to manage a profile relating to a child.
Personal information relating to children receives additional protection.
HealthLynk will process a child's personal information only where permitted under applicable law, including where prior consent has been provided by a competent person or another lawful basis applies.
A person creating or managing a child's profile must have the legal authority to do so.
Where appropriate, HealthLynk may require confirmation or evidence of the relationship or authority relied upon.
A competent person may, subject to applicable law, request access to, correction of, restriction of, or cessation of processing involving the child's personal information.
HealthLynk will not intentionally encourage children to disclose more personal information than is reasonably necessary for the functionality being provided.
6. Where We Obtain Personal Information
Most personal information processed through HealthLynk is provided directly by the account holder.
We may also receive personal information from another person where HealthLynk functionality allows that person to lawfully manage information on somebody else's behalf.
For example, information may be supplied by:
- a parent or guardian managing a child's profile;
- a family member authorised to manage another person's profile;
- a profile manager;
- a person sending a profile-claim invitation;
- the person claiming a profile;
- an authorised organisation or care provider where an applicable agreement permits this; or
- a payment or technical service provider.
Where information is obtained from somebody other than the data subject, HealthLynk will process that information only where there is an appropriate legal basis to do so.
7. Why We Process Personal Information
HealthLynk processes personal information only for defined and lawful purposes.
Providing the HealthLynk Service
We process information to create accounts, authenticate users, maintain health profiles, store records and documents, display health timelines, generate exports, manage family relationships and provide other requested HealthLynk functionality.
Managing Profiles for Other People
We process information where necessary to enable appropriately authorised people to create, maintain or assist with profiles belonging to family members, children, dependants or other persons.
Profile Invitations and Claims
We process identity, contact and relationship information to send invitations, verify recipients, permit a person to claim a profile relating to them and reduce the risk of duplicate or unauthorised profiles.
Sharing and Permissions
Where a user chooses to share information, we process the information necessary to establish, manage and revoke authorised access.
Subscription and Payment Administration
We process account, subscription and payment-related information to start subscriptions, administer trials, confirm payments, manage recurring billing, process cancellations and maintain financial records.
Security
We process appropriate technical and account information to authenticate users, prevent fraud, investigate suspicious activity, secure accounts, protect personal information and maintain the integrity of the Service.
Communications
We use contact information to send verification messages, security notices, account notifications, subscription communications, requested support responses and other service-related communications.
Legal and Regulatory Compliance
We may process information where reasonably necessary to comply with applicable laws, respond to lawful requests, protect legal rights, handle regulatory matters or maintain records required by law.
Service Reliability and Improvement
We may process appropriate operational and technical information to diagnose errors, measure service performance, improve accessibility, improve security and develop the Service.
Where possible and appropriate, HealthLynk will use aggregated or de-identified information for these purposes rather than identifiable health information.
8. Our Grounds for Processing Personal Information
Depending on the processing activity, HealthLynk may process personal information because:
you have consented to the processing;
processing is necessary to perform an agreement with you or take steps requested by you before entering into an agreement;
processing is required to comply with an obligation imposed by law;
processing protects a legitimate interest of the data subject;
processing is necessary to pursue a legitimate interest of HealthLynk or another person where permitted by law; or
another authorisation recognised by POPIA or other applicable law applies.
HealthLynk will not rely on a general lawful basis for ordinary personal information where additional legal requirements apply to special personal information or children's information.
9. Family Profiles, Managed Profiles and Profile Claims
HealthLynk is designed to accommodate situations where one person lawfully assists another person with managing their health information.
A profile manager does not become the owner of another person's personal information merely because they created or managed the profile.
Where HealthLynk allows a profile to be claimed by the person to whom it relates, we may process information necessary to:
- identify the relevant profile;
- send and validate the invitation;
- verify the invited email address or other identifier;
- prevent duplicate profiles;
- record the claim;
- change access relationships; and
- maintain appropriate security and audit information.
The ability of a manager to access a claimed profile may change after the claim according to the permissions established through HealthLynk and applicable law.
10. Sharing Personal Information
HealthLynk does not make health profiles publicly available.
Personal information may be disclosed only where reasonably necessary and lawfully permitted.
This may include disclosure to:
People You Authorise
Information may be shared with a family member, carer, healthcare professional or other person where you deliberately use HealthLynk's sharing functionality or otherwise authorise the disclosure.
Service Providers
HealthLynk may use trusted service providers to perform services such as:
- cloud hosting and storage;
- email delivery;
- payment processing;
- application infrastructure;
- security;
- backup and recovery;
- technical monitoring; and
- other operational services.
These service providers may process information on HealthLynk's behalf only for authorised purposes and subject to appropriate contractual and security obligations.
Payment Providers
When subscription payments are enabled, payment-related information may be exchanged with PayFast by Network or another payment service provider disclosed at checkout.
Legal and Regulatory Recipients
Information may be disclosed where HealthLynk is legally required to do so, including where necessary to respond to a valid court order, regulatory requirement or other lawful process.
Business Transactions
If HealthLynk undergoes a legitimate corporate restructuring, investment, merger, acquisition or transfer of business, information may be disclosed where reasonably necessary for that transaction and subject to appropriate confidentiality, security and legal safeguards.
HealthLynk will not permit a business transaction to be used as a means of circumventing data-protection obligations.
11. Our Service Providers and Operators
Where another organisation processes personal information on HealthLynk's behalf as an operator, HealthLynk requires appropriate security and confidentiality protections.
HealthLynk's infrastructure may use reputable technology providers, including cloud infrastructure and communication providers.
Before public launch, HealthLynk will maintain an appropriate internal record of material service providers and the categories of information each provider may process.
Where required, further information about material operators may be provided on request or through an updated version of this Privacy Policy.
12. Payment Information
HealthLynk uses PayFast by Network for subscription payment processing.
Where payment details are entered through PayFast, the payment provider processes those payment credentials according to its own security and privacy requirements.
HealthLynk may receive information required to administer the transaction, such as payment status, amount, merchant reference, transaction identifier, payment token or recurring-payment status.
HealthLynk does not require access to a user's complete payment-card number where the payment service provider can process the payment without providing those credentials to HealthLynk.
13. Cookies and Similar Technologies
HealthLynk may use cookies or similar browser technologies required to:
- maintain secure sessions;
- authenticate users;
- protect against security threats;
- remember necessary settings; and
- provide core website functionality.
Where non-essential analytics or other optional cookies are introduced, HealthLynk will provide appropriate information and consent choices where required.
Further information will be available in the HealthLynk Cookie Policy.
14. Service Communications and Marketing
HealthLynk may send communications necessary to provide the Service, including:
- verification codes;
- profile invitations;
- security alerts;
- account notifications;
- payment and subscription notices;
- important service changes; and
- responses to support requests.
These operational messages are different from direct marketing.
HealthLynk will handle electronic direct marketing in accordance with applicable law and will provide an appropriate method to object or unsubscribe where required.
Health information will not be used to target advertising to users.
15. Sale of Personal Information
HealthLynk does not sell users' personal information or health information to advertisers, data brokers or other third parties.
HealthLynk's business model is based on providing HealthLynk services and subscriptions, not selling identifiable health information.
If HealthLynk's business model changes in a way that materially affects how personal information is processed, this Privacy Policy will be updated and any additional consent required by law will be obtained before that processing takes place.
16. International Processing and Transfers
HealthLynk is a South African company and is subject to South African data-protection requirements.
Some service providers may operate infrastructure, support systems or other facilities in more than one country.
Where HealthLynk transfers personal information to a recipient outside South Africa, the transfer will only take place where the requirements of applicable law, including POPIA, are satisfied.
This may involve ensuring that the recipient is subject to appropriate legal, contractual or other binding protections; obtaining consent where legally appropriate; or relying on another permitted basis.
Because health information and children's information require additional protection, HealthLynk will assess cross-border processing involving these categories particularly carefully.
Primary HealthLynk production-data hosting location: AWS af-south-1. Structured application and health data is stored in PostgreSQL/RDS. Uploaded documents and generated exports use private S3 storage. Transactional email uses Amazon SES. PayFast processes subscription payments and returns payment references/statuses required for billing administration.
Tracked infrastructure item: confirm final AWS operator/subprocessor and any cross-border transfer details before production publication. This notice does not assert unverified operator locations.
17. How Long We Keep Personal Information
HealthLynk does not intend to retain personal information indefinitely merely because it has been collected.
Information will generally be retained for as long as reasonably necessary to:
- provide the Service;
- maintain an active account or profile;
- fulfil the purpose for which the information was collected;
- comply with contractual obligations;
- resolve disputes;
- maintain appropriate security or audit records; or
- comply with applicable law.
Health and profile information stored by a user will ordinarily remain available while the relevant profile and account remain active, subject to the user's rights, the rights of other data subjects, applicable law and HealthLynk's retention rules.
Where personal information is no longer lawfully required, HealthLynk will delete, destroy or appropriately de-identify it as required.
Some information may need to remain for a limited additional period in secure backups, security records, transaction records or legal records before being deleted according to established retention procedures.
Temporary generated files, such as downloadable exports, may be automatically removed after a limited availability period even though the underlying records remain in the user's HealthLynk profile.
A subscription ending does not necessarily mean that all personal information is immediately deleted. After a 7-day PAST_DUE grace period, access may become READ_ONLY. READ_ONLY data is retained for 12 months, with notices before deletion, and is permanently deleted after that retention period unless another lawful retention reason applies.
The launch storage limits are 2 GiB per HealthProfile and 25 MiB per uploaded file. Supported launch file types are PDF, JPEG, PNG and WebP.
18. Account Closure and Deletion Requests
Users may request account closure through functionality made available by HealthLynk or through our support contact.
Account closure and deletion of personal information are related but not necessarily identical actions.
Before deleting information, HealthLynk may need to consider:
- whether the information relates to another data subject;
- whether another authorised manager or claimed profile is affected;
- whether retention is required by law;
- whether records are reasonably required for legal or contractual purposes; and
- whether the requester has authority to request deletion.
Where HealthLynk is no longer authorised to retain personal information, it will delete or destroy the information as required by applicable law.
19. Security
HealthLynk recognises that the confidentiality and integrity of health information are fundamental to the Service.
HealthLynk maintains reasonable technical and organisational safeguards appropriate to the nature of the information processed and the risks involved.
These safeguards may include measures relating to:
- authentication and access control;
- account verification;
- encrypted communications;
- secure infrastructure configuration;
- separation of user access;
- logging and monitoring;
- backup and recovery;
- vulnerability and dependency management;
- restricted administrative access;
- secure software-development practices; and
- incident response.
Security measures are reviewed as HealthLynk and the risks facing the Service develop.
No internet-connected service can provide an absolute guarantee against every possible security incident, but HealthLynk will continuously work to maintain safeguards appropriate to the sensitivity of the information entrusted to it.
Users also have a responsibility to protect their passwords, email accounts and devices from unauthorised access.
20. Personal Information Security Compromises
Where HealthLynk has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, HealthLynk will investigate and take appropriate steps to contain and address the incident.
HealthLynk will notify the Information Regulator and affected data subjects where and in the manner required by applicable law.
Notifications to affected people will, where required, provide information reasonably necessary to help them protect themselves against potential consequences of the compromise.
21. Your Privacy Rights
Subject to applicable law and appropriate identity verification, you may have the right to:
- ask whether HealthLynk holds personal information about you;
- request access to personal information HealthLynk holds about you;
- request correction of inaccurate, incomplete, misleading or outdated information;
- request deletion or destruction of information HealthLynk is no longer authorised to retain;
- object to certain processing;
- withdraw consent where processing depends on consent;
- request restriction or cessation of processing where provided by law;
- lodge a complaint about HealthLynk's processing of your information; and
- lodge a complaint with the Information Regulator.
Some requests may be subject to lawful limitations, including requirements relating to the rights and privacy of other people.
HealthLynk may require reasonable proof of identity before providing access to sensitive information.
22. How to Exercise Your Privacy Rights
Privacy requests may be submitted to:
HealthLynk (Pty) Ltd Email: YangaSodoza@outlook.com Telephone: 074 663 3106 Address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
Please provide enough information for us to identify the relevant account or record and understand the request.
Do not send unnecessary medical information merely to identify yourself.
Where a prescribed POPIA or PAIA procedure applies, HealthLynk may ask you to complete the appropriate form.
23. Information Officer
HealthLynk's Information Officer is responsible for overseeing HealthLynk's compliance with applicable personal-information and access-to-information requirements.
Information Officer: Yanga Sodoza (Director / Head of Private Body) Email: YangaSodoza@outlook.com Telephone: 074 663 3106
The Information Officer's details will be updated after the applicable registration process has been completed.
24. Information Concerning Another Person
HealthLynk's family and managed-profile functionality may mean that more than one person's rights are relevant to a particular record.
Having access to another person's profile does not give a user an unrestricted right to use, disclose, alter or delete that person's information.
When considering a request affecting another person's information, HealthLynk may need to verify:
- the identity of the requester;
- the identity of the data subject;
- the relationship between them;
- the requester's authority;
- existing profile claims and permissions; and
- the rights and legitimate interests of all affected persons.
HealthLynk may decline or limit a request where granting it would unlawfully interfere with another person's rights.
25. Automated Decision-Making and Artificial Intelligence
HealthLynk is primarily an information-management platform.
HealthLynk does not currently use a person's health information to make solely automated decisions that determine medical treatment, medical eligibility, insurance eligibility, employment eligibility or similar decisions producing significant legal or personal consequences.
If HealthLynk introduces artificial-intelligence, automated extraction, summarisation or decision-support features in future, the privacy and safety implications of those features will be assessed before deployment.
Where such functionality materially changes the processing of personal information, this Privacy Policy will be updated and additional notice or consent will be provided where required.
Automated functionality will not turn HealthLynk into a healthcare professional and must not be relied upon as a substitute for professional medical advice.
26. De-Identified and Aggregated Information
HealthLynk may create statistical or aggregated information for purposes such as understanding service usage, capacity planning, reliability, security and product improvement.
Where information is de-identified, HealthLynk will take appropriate steps to prevent it from being used to identify an individual.
HealthLynk will not represent identifiable health information as anonymous merely because obvious identifiers such as a name have been removed.
Research involving identifiable or re-identifiable health information will not automatically be treated as ordinary product analytics and will be subject to any additional legal, ethical and consent requirements that apply.
27. Organisational and Care Accounts
HealthLynk may offer services to healthcare organisations, care organisations, sponsors, non-profit organisations or other entities.
The privacy roles of HealthLynk and the organisation may depend on the particular service.
For example, an organisation may in some circumstances be the responsible party for information it instructs HealthLynk to process, while HealthLynk acts as its operator.
HealthLynk may remain a responsible party for separate processing that HealthLynk independently determines, such as account security, platform administration or HealthLynk's own legal obligations.
Where appropriate, these responsibilities will be addressed in additional data-processing or service agreements.
28. Links and Third-Party Services
HealthLynk may contain links to services operated by other organisations.
A third-party service is responsible for its own privacy practices where HealthLynk does not determine that processing.
Users should review the relevant third party's privacy information before providing personal information directly to that service.
29. Changes to This Privacy Policy
HealthLynk may update this Privacy Policy when the Service, our processing activities, service providers, legal obligations or privacy practices change.
The current version will be published on the HealthLynk website with its effective date and version number.
Where a change materially affects how sensitive information is processed or otherwise requires additional notice or consent, HealthLynk will take appropriate steps before the new processing begins.
Previous versions may be retained for governance and accountability purposes.
30. Complaints
We encourage you to contact HealthLynk first if you believe your personal information has been handled incorrectly so that we can investigate the matter.
HealthLynk privacy contact
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07 Email: YangaSodoza@outlook.com Telephone: 074 663 3106 Address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
You also have the right to lodge a complaint with the Information Regulator (South Africa).
Information about complaints and the Regulator's current contact details are available through the Information Regulator's official website and eServices portal.
Information Regulator general enquiries: enquiries@inforegulator.org.za Telephone: 010 023 5200 Website: inforegulator.org.za
31. Relationship With Our Other Policies
This Privacy Policy should be read together with:
- the HealthLynk Terms of Service;
- the Refund, Cancellation and Subscription Policy;
- the PAIA Manual;
- the Cookie Policy;
- the Medical Disclaimer; and
- the Security and Data Protection Statement.
Where applicable law provides a data subject with greater protection than this Policy, the applicable legal requirement will prevail.
32. Contact HealthLynk
For privacy, account or personal-information enquiries:
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07 Director: Yanga Sodoza Website: healthylynk.com Email: YangaSodoza@outlook.com Telephone: 074 663 3106 Business address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
HealthLynk (Pty) Ltd Your health information. Organised around you.