Legal and trust
Acceptable Use Policy
Version 1.0 · Effective 17 August 2026
Published 26 August 2026
HealthLynk stores and organises information; it does not diagnose, prescribe, provide medical treatment or replace professional medical advice.
HealthLynk Acceptable Use Policy
Version: 1.0 Effective date: 17 August 2026 Last updated: 17 August 2026
This Acceptable Use Policy ("Policy") sets out the rules that apply when accessing or using the HealthLynk website, application, progressive web application, APIs, systems and related services (collectively, the "Service").
HealthLynk is operated by HealthLynk (Pty) Ltd, registration number 2026/646559/07, a private company registered in the Republic of South Africa.
This Policy forms part of the HealthLynk Terms of Service.
By using HealthLynk, you agree not to use the Service in a way that is unlawful, harmful, fraudulent, abusive or inconsistent with its intended purpose.
1. Purpose of HealthLynk
HealthLynk is designed to help authorised users securely store, organise, manage, access and share health-related information.
Depending on the functionality available to you, HealthLynk may allow you to:
- manage your own health information;
- manage a family member's or another person's profile where you have appropriate authority;
- upload health-related documents;
- record healthcare encounters;
- organise prescriptions, tests and related information;
- store healthcare receipts;
- share selected information with authorised persons;
- invite people to claim profiles relating to them;
- export information;
- and use other health-information management functionality.
The Service must be used consistently with these purposes.
2. General Acceptable Use Rule
You may use HealthLynk only:
- for lawful purposes;
- in accordance with this Policy and the Terms of Service;
- within the permissions granted to your account;
- in a manner that respects the privacy and rights of other people;
- and without compromising the security, availability or integrity of the Service.
Having technical access to functionality does not necessarily mean that every possible use of that functionality is authorised.
3. Accessing Another Person's Information
You must not access, attempt to access, view, download, modify, copy or disclose another person's private HealthLynk information unless you are appropriately authorised to do so.
This applies even where:
- you know the person;
- you are related to the person;
- you previously had access;
- you know or can guess their password;
- their account is accessible on a shared device;
- you discover a technical vulnerability;
- you accidentally receive a link intended for somebody else;
- or the information may be useful to you.
If you unexpectedly gain access to information that you believe you should not be able to see, stop accessing it and report the issue to HealthLynk.
4. Managed and Family Profiles
HealthLynk may allow a person to manage health information relating to another individual.
You may only create or manage another person's profile where you have an appropriate lawful basis or authority.
Depending on the circumstances, this may include situations where:
- the person has authorised you;
- you are legally authorised to act for the person;
- you are a parent, guardian or other competent person lawfully managing a child's information;
- or another lawful basis applies.
You must not use managed-profile functionality to:
- monitor another person without appropriate authority;
- obtain confidential medical information for an unrelated purpose;
- control another person's profile improperly;
- prevent a person from obtaining lawful access to information relating to them;
- or misrepresent your authority over another person.
5. Children's Profiles
Where you create or manage information relating to a child, you must have the authority required by applicable law.
You must not use HealthLynk to:
- create deceptive profiles concerning children;
- obtain children's health information without appropriate authority;
- disclose children's information unlawfully;
- exploit a child's information;
- impersonate a parent or guardian;
- or falsely represent that you have authority over a child.
HealthLynk may take additional steps to verify or review relationships involving children's profiles where reasonably necessary.
6. Profile Invitations and Claims
HealthLynk may allow a profile manager to invite another person to claim a profile relating to them.
You must not misuse this functionality.
You must not:
- send profile claims to an incorrect person intentionally;
- use another person's email address to intercept an invitation;
- impersonate the intended recipient;
- attempt to claim a profile that does not relate to you;
- interfere with another person's legitimate claim;
- bypass verification mechanisms;
- manipulate profile relationships;
- repeatedly send unwanted invitations;
- or use profile invitations to harass or monitor another person.
If you receive an invitation that you believe was sent to you incorrectly, do not use it to access information belonging to another person.
7. Account Impersonation and False Information
You must not:
- impersonate another person;
- create an account using another person's identity without authority;
- falsely claim to be a healthcare professional;
- falsely claim to represent an organisation;
- falsify your relationship to another user;
- misrepresent your authority over a managed profile;
- deliberately provide false verification information;
- or use another person's credentials without permission.
You should provide accurate information where accuracy is necessary for account security, profile management or operation of the Service.
8. Authentication Credentials
You must protect the credentials associated with your HealthLynk account.
You must not:
- knowingly give your password to an unauthorised person;
- publish your authentication credentials;
- sell or transfer access credentials;
- use credentials obtained unlawfully;
- attempt to obtain another person's password or verification code;
- intercept another person's authentication messages;
- or bypass authentication mechanisms.
If you believe your credentials have been compromised, you should change or secure them and notify HealthLynk as soon as reasonably possible.
9. Unauthorised Security Activity
You must not attempt to compromise, bypass, disable or interfere with HealthLynk security controls.
Unless HealthLynk has given you specific prior written authorisation, you must not:
- probe HealthLynk systems for vulnerabilities;
- conduct penetration testing;
- attempt privilege escalation;
- bypass access controls;
- circumvent authentication;
- intercept communications;
- exploit vulnerabilities;
- attempt SQL injection;
- perform cross-site scripting attacks;
- manipulate application requests to obtain unauthorised information;
- attempt to access administrative functionality;
- extract credentials or secrets;
- interfere with encryption or security controls;
- or otherwise attempt to defeat mechanisms intended to protect HealthLynk or its users.
This restriction does not prevent a person from making a good-faith security report after inadvertently discovering a potential issue.
10. Responsible Vulnerability Reporting
If you believe you have discovered a security vulnerability, report it privately to HealthLynk.
Current security contact: YangaSodoza@outlook.com
The official HealthLynk security/support address will replace this address once operational.
When reporting an issue:
- describe the potential problem clearly;
- provide only the information reasonably necessary for HealthLynk to investigate;
- avoid accessing other users' information;
- do not download another person's private records;
- do not modify or delete information;
- do not create persistence within HealthLynk systems;
- do not intentionally disrupt the Service;
- do not use social engineering;
- do not demand payment in exchange for withholding harmful activity or disclosure;
- and do not publicly disclose exploit details while doing so could place users at material risk.
Reporting a possible vulnerability does not automatically authorise continued testing of HealthLynk systems.
This Policy does not establish a paid bug-bounty programme.
11. Malicious Software and Files
You must not upload, transmit, distribute or attempt to introduce:
- viruses;
- ransomware;
- trojans;
- worms;
- spyware;
- malicious scripts;
- destructive files;
- exploit code;
- deliberately corrupted files;
- or other software or content intended to compromise systems or users.
Uploaded health documents must be genuine user content rather than a method of delivering malicious software.
HealthLynk may block, quarantine or remove files reasonably suspected of creating a security threat.
12. Interference With the Service
You must not intentionally interfere with the availability, reliability or operation of HealthLynk.
Prohibited activity includes:
- denial-of-service activity;
- distributed denial-of-service activity;
- excessive automated requests;
- deliberately exhausting application resources;
- interfering with servers or networks;
- attempting to overload HealthLynk infrastructure;
- deliberately triggering repeated expensive operations;
- abusing file-upload functionality;
- or otherwise degrading the Service for other users.
Reasonable ordinary use of HealthLynk is not prohibited merely because it consumes computing resources.
13. Automated Access, Scraping and Bots
You must not use automated systems to access HealthLynk in a way that is unauthorised or materially harmful.
Unless expressly permitted by HealthLynk, you may not use:
- scraping tools;
- crawlers;
- bots;
- automated extraction systems;
- scripts;
- automated account creation;
- automated profile-claim tools;
- or similar mechanisms
to systematically extract private information, circumvent functionality, overload the Service or reproduce HealthLynk datasets.
Ordinary public search-engine indexing of pages that HealthLynk intentionally makes publicly indexable is not treated as access to private user information.
HealthLynk may provide APIs or other authorised automated interfaces in future. Use of those interfaces may be subject to additional terms and limits.
14. Circumventing Usage Limits
You must not deliberately circumvent limits or controls established for:
- subscription plans;
- storage;
- exports;
- profile numbers;
- family profiles;
- invitations;
- account eligibility;
- free trials;
- payment requirements;
- API usage;
- or other Service functionality.
This includes creating multiple deceptive accounts or manipulating identifiers primarily to avoid legitimate restrictions.
15. Free-Trial and Subscription Abuse
You must not use deceptive methods to obtain repeated free trials or subscription benefits that you are not eligible to receive.
Prohibited conduct may include:
- deliberately creating duplicate identities;
- repeatedly creating accounts solely to restart a trial;
- using stolen payment information;
- manipulating payment status;
- falsifying student or other eligibility information;
- or interfering with subscription controls.
A legitimate person having more than one lawful role or profile within HealthLynk is not automatically considered subscription abuse.
16. Payment Fraud
You must not use HealthLynk or its payment functionality to:
- use stolen payment credentials;
- submit fraudulent payment information;
- make payments without authority;
- falsify payment confirmation;
- manipulate payment callbacks or notifications;
- forge payment-provider communications;
- abuse refunds;
- make knowingly fraudulent chargebacks;
- launder funds;
- or otherwise conduct unlawful payment activity.
HealthLynk may provide relevant transaction records to payment providers, financial institutions or competent authorities where lawfully required or reasonably necessary to investigate suspected fraud.
17. Medical Documents and Records
You must not knowingly use HealthLynk to create or distribute fraudulent medical documentation.
This includes knowingly falsifying:
- prescriptions;
- medical certificates;
- test results;
- laboratory reports;
- healthcare-provider documents;
- referral documents;
- medical reports;
- receipts;
- or other health records
for purposes such as fraud, deception or unlawful gain.
HealthLynk is a record-management platform and does not independently certify the authenticity of user-uploaded medical documents.
18. Medical Misrepresentation
You must not use HealthLynk to falsely represent:
- that HealthLynk has diagnosed a medical condition;
- that HealthLynk issued a prescription;
- that HealthLynk provided medical treatment;
- that a HealthLynk-generated summary is an official medical certificate;
- that an export was issued by a healthcare professional when it was not;
- or that HealthLynk has clinically verified user-provided information where it has not done so.
HealthLynk-generated organisational tools must not deliberately be misrepresented as documents issued by an independent healthcare provider.
19. Sharing and Disclosure of Health Information
You must use HealthLynk's sharing functionality responsibly.
You must not knowingly use HealthLynk to:
- disclose another person's private medical information without appropriate authority;
- publish another person's health information publicly without a lawful basis;
- distribute medical records for harassment or humiliation;
- use health information to unlawfully discriminate against another person;
- threaten to disclose another person's health information;
- or use access obtained for one legitimate purpose for an unrelated unlawful purpose.
Before sharing information, verify that the intended recipient is correct.
20. Harassment, Threats and Coercion
You must not use HealthLynk to harass, threaten, intimidate, exploit or coerce another person.
In particular, you must not use:
- profile invitations;
- access requests;
- shared records;
- health information;
- personal information;
- or communication functionality
as a means of repeatedly contacting, controlling, threatening or intimidating another person.
Threatening to reveal someone's private health information in order to obtain money, access, compliance or another benefit is prohibited.
21. Unlawful Discrimination or Exploitation
HealthLynk must not be used to unlawfully exploit a person's health information.
You must not use information obtained through HealthLynk for an unlawful purpose such as unlawfully discriminating against a person in relation to:
- employment;
- insurance;
- financial services;
- accommodation;
- education;
- access to services;
- or another protected context.
This section does not prevent lawful processing that is appropriately authorised under applicable law.
22. Unlawful Content
You must not knowingly use HealthLynk to store, distribute or facilitate content where doing so is unlawful.
HealthLynk is not intended to be a general-purpose file hosting service.
HealthLynk may restrict or remove content where there are reasonable grounds to believe that:
- storing it is unlawful;
- it creates a material security threat;
- it seriously infringes another person's rights;
- or HealthLynk is legally required to restrict access to it.
HealthLynk will consider privacy and confidentiality before accessing or reviewing private user content.
23. Intellectual Property
You must not knowingly use HealthLynk to infringe another person's intellectual-property rights.
You may upload a medical or health-related document where you have a lawful right or legitimate authority to retain and manage that document through the Service.
You must not use HealthLynk to distribute copyrighted material unlawfully merely because the Service permits file uploads.
Nothing in this section prevents conduct permitted by applicable law.
24. HealthLynk Software and Systems
Except where applicable law expressly permits otherwise, you must not:
- copy protected HealthLynk source code;
- attempt to obtain non-public source code through unauthorised means;
- circumvent technical protection measures;
- modify HealthLynk systems without permission;
- create unauthorised derivative services from private HealthLynk functionality;
- or commercially exploit HealthLynk's protected systems without authorisation.
This section does not restrict rights that cannot lawfully be excluded.
25. API and Integration Use
If HealthLynk provides APIs, integrations or machine-to-machine functionality in future, you must use them only according to the permissions and documentation applicable to them.
You must not:
- exceed applicable rate limits intentionally;
- use an API token belonging to another organisation;
- disclose secret API credentials;
- use integrations to obtain information outside your authorised scope;
- or circumvent user permissions through an integration.
HealthLynk may revoke or rotate compromised integration credentials where necessary to protect the Service.
26. Healthcare and Organisational Accounts
Organisations using HealthLynk must ensure that their authorised representatives use the Service consistently with:
- this Policy;
- applicable agreements;
- applicable privacy obligations;
- professional obligations where applicable;
- and the permissions granted to the organisation.
An organisational account must not be used as a general mechanism to obtain unrestricted access to individuals' health information.
HealthLynk may impose additional requirements through organisational, care, operator or data-processing agreements.
27. Sponsored Access
Where HealthLynk access is funded by a sponsor, the sponsor does not automatically receive access to the beneficiary's private health information.
Sponsored access must not be used as a condition for obtaining unrelated confidential health information unless the relevant processing is separately lawful and appropriately disclosed.
A sponsor must not attempt to circumvent HealthLynk permissions merely because it pays for another person's subscription.
28. Actions HealthLynk May Take
Where HealthLynk reasonably believes that this Policy has been violated, HealthLynk may take proportionate steps including:
- issuing a warning;
- requiring corrective action;
- limiting particular functionality;
- invalidating a suspicious session;
- requiring account re-verification;
- blocking malicious files;
- revoking compromised credentials;
- temporarily restricting access;
- suspending an account;
- terminating access in serious cases;
- preserving relevant records;
- or taking another reasonable protective measure.
The appropriate action will depend on factors such as:
- the seriousness of the conduct;
- whether it was intentional;
- whether other people are at risk;
- the sensitivity of affected information;
- whether the conduct is ongoing;
- whether fraud or criminal activity is reasonably suspected;
- and whether immediate action is required to protect users or systems.
29. Immediate Protective Action
HealthLynk may act without prior notice where this is reasonably necessary to respond to:
- an active security incident;
- account compromise;
- malicious software;
- ongoing unauthorised access;
- suspected fraud;
- a material threat to another person's privacy;
- an attack on HealthLynk infrastructure;
- or a legal requirement requiring prompt action.
Where appropriate and legally permitted, HealthLynk will subsequently communicate with the affected account holder.
30. Preservation of Information
Where HealthLynk investigates suspected abuse or a security incident, relevant technical and account records may be preserved for an appropriate period.
This may include information reasonably required to:
- investigate the event;
- protect affected users;
- establish what occurred;
- prevent recurrence;
- respond to a payment dispute;
- meet legal obligations;
- or cooperate with a lawful investigation.
Preservation does not give HealthLynk unrestricted permission to use retained information for unrelated purposes.
31. Reporting to Authorities
HealthLynk may report suspected unlawful conduct to an appropriate authority where:
- required by law;
- directed by a valid legal process;
- necessary to comply with a regulatory obligation;
- or otherwise lawfully justified.
Where HealthLynk receives a request for user information from an authority, HealthLynk will assess the request according to applicable legal requirements before disclosure.
HealthLynk will not voluntarily disclose unrelated medical information merely because an investigation concerns a user's account.
32. Reporting Abuse
If you believe someone is misusing HealthLynk, you may report the matter to:
Email: YangaSodoza@outlook.com Telephone: 074 663 3106
Please provide enough information for HealthLynk to understand and investigate the concern.
Do not send unnecessary medical records or sensitive information when making an abuse report.
For an urgent medical situation, contact an appropriate emergency or healthcare service rather than using the HealthLynk abuse-reporting channel.
33. Good-Faith Mistakes
HealthLynk recognises that users can make genuine mistakes.
An accidental error will not automatically be treated in the same way as deliberate abuse.
For example, a user who accidentally:
- uploads a document to the wrong profile;
- enters incorrect information;
- sends an invitation to the wrong email address;
- or discovers information they were not expecting to access
should take reasonable steps to correct or report the issue.
HealthLynk may assist with appropriate remediation.
Repeated or deliberate conduct may be treated differently from a reasonable good-faith error.
34. Relationship With Applicable Law
This Policy does not replace applicable South African law.
Use of HealthLynk may be subject to legislation including, where relevant:
- the Protection of Personal Information Act 4 of 2013;
- the Cybercrimes Act 19 of 2020;
- the Electronic Communications and Transactions Act 25 of 2002;
- the Consumer Protection Act 68 of 2008;
- and other applicable law.
Nothing in this Policy authorises conduct that would otherwise be unlawful.
Where this Policy provides less protection than a mandatory legal requirement, the applicable legal requirement will prevail.
35. Changes to This Policy
HealthLynk may update this Policy as:
- the Service develops;
- new functionality is introduced;
- new forms of misuse arise;
- security requirements change;
- applicable law changes;
- or HealthLynk's risk environment evolves.
The latest version will be published on the HealthLynk website with its effective date and version number.
Material changes will be communicated where reasonably appropriate.
36. Contact HealthLynk
Questions concerning acceptable use may be directed to:
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07 Director: Yanga Sodoza Website: healthylynk.com Email: YangaSodoza@outlook.com Telephone: 074 663 3106 Business address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
Contact information is rendered from the current HealthLynk Organisation record.
Related Documents
This Acceptable Use Policy should be read together with:
- HealthLynk Terms of Service
- HealthLynk Privacy Policy and POPIA Privacy Notice
- HealthLynk Refund, Cancellation and Subscription Policy
- HealthLynk PAIA Manual
- HealthLynk Medical Disclaimer
- HealthLynk Cookie Policy
- HealthLynk Security and Data Protection Statement
HealthLynk (Pty) Ltd Your health information. Organised around you.