Legal and trust
Cookie Policy
Version 1.0 · Effective 17 August 2026
Published 26 August 2026
HealthLynk stores and organises information; it does not diagnose, prescribe, provide medical treatment or replace professional medical advice.
HealthLynk Cookie Policy
Version: 1.0 Effective date: 17 August 2026 Last updated: 17 August 2026
This Cookie Policy explains how HealthLynk (Pty) Ltd uses cookies and similar technologies when you visit or use the HealthLynk website and application.
HealthLynk is a private company registered in the Republic of South Africa under registration number 2026/646559/07.
This Policy should be read together with the HealthLynk Privacy Policy and POPIA Privacy Notice.
1. What Are Cookies?
Cookies are small pieces of information that a website may store through your web browser.
Cookies can be used for purposes such as:
- maintaining a secure login session;
- remembering information during navigation;
- protecting forms and transactions;
- maintaining preferences;
- measuring website usage;
- detecting suspicious activity; and
- providing other website functionality.
Some cookies exist only while your browser session is active.
Others may remain on your device for a defined period or until they are removed.
2. Similar Technologies
HealthLynk may also use browser technologies that are not technically cookies but perform related functions.
These may include:
- local browser storage;
- session storage;
- browser cache;
- service-worker storage and caches;
- security tokens;
- device or session identifiers; and
- similar technologies required for application functionality.
For simplicity, this Policy may refer collectively to these technologies as "cookies and similar technologies."
3. HealthLynk's Approach to Cookies
HealthLynk is a personal health-information management platform.
Because privacy is particularly important to the Service, HealthLynk aims to minimise the use of cookies and similar technologies.
Our approach is:
- use only technologies reasonably necessary to operate and secure the Service unless there is a legitimate reason to introduce additional technologies;
- clearly explain material cookie use;
- avoid unnecessary tracking of users;
- avoid using health information for behavioural advertising;
- obtain an appropriate choice or consent before using optional technologies where required; and
- regularly review the technologies used by the Service.
HealthLynk does not treat acceptance of optional website cookies as consent to process health information for unrelated purposes.
4. Essential Cookies and Technologies
HealthLynk uses, or may use, technologies that are necessary for the website and application to work correctly and securely.
These technologies may perform functions such as:
- keeping a user securely signed in;
- associating requests with the correct user session;
- protecting website forms against cross-site request forgery and similar attacks;
- maintaining authentication state;
- supporting account verification;
- protecting against unauthorised access;
- preventing security abuse;
- maintaining temporary application state;
- remembering security-related settings; and
- enabling core application functionality.
Because these technologies are required for the Service to operate or remain secure, disabling them may prevent HealthLynk from functioning correctly.
Where essential technologies process personal information, HealthLynk processes that information only where an appropriate lawful basis exists.
5. Session Cookies
A session cookie may be used to associate activity with a particular authenticated or anonymous browser session.
For example, after you sign in, HealthLynk may need to recognise requests from your browser as belonging to your authenticated session.
Session information may be used to:
- keep you signed in;
- enforce access controls;
- prevent one account from accessing another account's information;
- maintain secure application state; and
- protect the integrity of the Service.
Session cookies do not give a person permission to access another user's health information.
HealthLynk applies appropriate security settings to authentication and session technologies based on the functionality and deployment environment.
6. Security and CSRF Protection
HealthLynk may use a browser token or cookie to help protect forms and authenticated actions against cross-site request forgery (CSRF) and similar security threats.
This technology helps HealthLynk determine whether certain requests originated from a legitimate interaction with the Service.
It is used for security rather than advertising or behavioural profiling.
Disabling this functionality may prevent forms or authenticated actions from working correctly.
7. Authentication and Account Security
Cookies or similar technologies may be used as part of HealthLynk's authentication and account-security controls.
These technologies may support functionality such as:
- authentication;
- session management;
- verification;
- security-event detection;
- account protection; and
- prevention of unauthorised access.
Authentication information is handled in accordance with the HealthLynk Privacy Policy and security controls.
8. Preferences
The launch application does not use localStorage, sessionStorage or IndexedDB for user data or preferences.
No such browser-storage preferences are currently configured. Examples below describe technologies that are not enabled at launch:
- interface preferences;
- display settings;
- dismissed informational notices;
- accessibility preferences; or
- similar non-essential settings.
Where possible, preference storage will be limited to what is reasonably necessary for the requested functionality.
Health information will not intentionally be placed into a preference cookie merely for convenience.
9. Progressive Web Application and Service Workers
HealthLynk operates as a Progressive Web Application (PWA).
A service worker and browser cache store only the application shell and static assets listed by the worker. Authenticated pages, APIs, media, exports and other private routes are excluded from the cache.
- faster loading;
- storing application assets;
- maintaining an application shell;
- improving reliability where network connectivity is temporarily unavailable; and
- supporting selected offline functionality.
Service-worker caches are not traditional cookies.
They are nevertheless browser-side storage technologies and are therefore addressed in this Policy.
HealthLynk will take particular care before allowing sensitive health information to be stored persistently on a user's device for offline access.
Where future functionality involves local storage of identifiable health information for offline use, HealthLynk will assess:
- whether the functionality is necessary;
- the security implications;
- appropriate access controls;
- retention and deletion behaviour;
- what information must be communicated to users;
- whether additional consent or choice is required; and
- how locally stored information can be removed.
Static application assets stored by the PWA should not be confused with a user's centrally stored HealthLynk health records.
10. Analytics Cookies
HealthLynk does not currently intend to rely on behavioural analytics cookies as a prerequisite for using the Service.
If HealthLynk introduces optional analytics tools in future, they may be used to understand matters such as:
- which public website pages are used;
- general website performance;
- application errors;
- broad usage patterns; and
- opportunities to improve usability.
Where analytics technology is not necessary for the Service to operate, HealthLynk will provide an appropriate choice before enabling it where required.
HealthLynk will favour privacy-preserving and aggregated analytics approaches where reasonably possible.
Analytics should not be designed to expose the contents of users' private health records to an analytics provider.
11. Advertising and Behavioural Tracking
HealthLynk does not use users' identifiable health information for behavioural advertising.
HealthLynk does not currently intend to use third-party advertising cookies that track users across unrelated websites for the purpose of targeting advertisements based on their health information.
HealthLynk will not intentionally provide advertisers with access to private health-profile information for targeted advertising.
If HealthLynk's use of advertising or tracking technologies materially changes in future, this Policy and the relevant privacy notices will be updated before the new processing begins.
Where consent is required, the relevant technology will not be enabled until the necessary consent has been obtained.
12. Health Information and Cookies
HealthLynk does not intend to store detailed medical records directly inside ordinary browser cookies.
For example, ordinary cookies should not intentionally contain information such as:
- diagnoses;
- prescription contents;
- test results;
- medical reports;
- medical-history details; or
- uploaded health documents.
Certain technical identifiers may nevertheless be associated with a logged-in account that contains health information on HealthLynk's secure systems.
Such identifiers are therefore protected as part of HealthLynk's overall security and privacy framework.
13. Local Storage and Session Storage
The launch application does not use localStorage, sessionStorage or IndexedDB. It does not store identifiable health records in browser storage.
Browser session state is held in the essential Django session cookie described in the cookie register.
Local storage can remain on a device until it is removed by the application, the browser or the user.
HealthLynk will avoid storing sensitive personal information in persistent browser storage unless the functionality has been specifically designed and assessed for that purpose.
14. Payment Provider Technologies
HealthLynk uses PayFast by Network to process online subscription payments.
When you proceed to a PayFast-controlled payment environment, PayFast may use its own cookies or similar technologies.
Those technologies are controlled by PayFast and are subject to PayFast's applicable privacy and cookie practices.
HealthLynk may receive transaction information needed to administer your subscription, but this does not mean that HealthLynk controls every technology used on PayFast's own systems.
Where HealthLynk later embeds or integrates payment functionality in a manner that causes third-party technologies to operate directly within a HealthLynk page, the cookie register and consent implementation will be reviewed accordingly.
15. Other Third-Party Services
HealthLynk may use third-party infrastructure and operational providers for services such as:
- hosting;
- email delivery;
- security;
- payment processing;
- technical monitoring; and
- other supporting services.
Use of a third-party provider does not automatically mean that the provider places cookies in a user's browser.
HealthLynk will list material third-party browser technologies in this Policy or the applicable cookie-management interface where those technologies are introduced.
16. Third-Party Embedded Content
If HealthLynk later embeds content supplied by another organisation, such as:
- videos;
- maps;
- support widgets;
- social-media content;
- external authentication components; or
- other embedded services,
that third party may attempt to set its own cookies or collect information from the browser.
HealthLynk will assess the privacy impact of such integrations before deployment.
Optional embedded content that introduces non-essential tracking should not be activated without an appropriate user choice where required.
17. Cookie Categories
HealthLynk may classify browser technologies into the following categories.
17.1 Strictly Necessary
These are required for security or essential application functionality.
Examples include:
- authentication;
- session management;
- form protection;
- security controls; and
- core application state.
These cannot necessarily be disabled through HealthLynk while continuing to use the affected functionality.
17.2 Functional
These technologies remember optional preferences or provide enhanced functionality.
Examples may include:
- user-interface preferences;
- accessibility preferences; and
- remembered optional settings.
Where these technologies are not necessary, users may be given an appropriate choice regarding their use.
17.3 Analytics
These technologies help understand website or application performance and usage.
Where analytics are optional and involve personal-information processing, HealthLynk will implement an appropriate lawful-processing mechanism and user choice where required.
17.4 Marketing
These technologies may be used to measure or personalise marketing.
HealthLynk does not currently use health information for behavioural marketing and does not intend to enable marketing cookies by default.
If marketing cookies are introduced, they will be treated as optional and handled in accordance with applicable privacy and direct-marketing requirements.
18. Current HealthLynk Cookie Register
The launch application uses only essential first-party cookies and the service-worker cache described below. No analytics or marketing cookies are configured.
| Cookie / Technology | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| Django session cookie (`sessionid`) | HealthLynk | Maintains anonymous and authenticated session state | Strictly Necessary | Session cookie; expiry follows Django session settings |
| CSRF cookie (`csrftoken`) | HealthLynk | Protects forms and authenticated requests | Strictly Necessary | Session cookie |
| Authentication/security controls | HealthLynk | Django session authentication and security controls | Strictly Necessary | No separate optional authentication cookie is configured |
| Service-worker cache | HealthLynk | Stores static application assets and the public offline page | Strictly Necessary | Replaced through the application cache lifecycle |
Status: Launch browser-storage review complete. Optional analytics and marketing cookies are not configured.
HealthLynk will not deliberately populate this register with generic cookie names that are not actually present in the production Service.
19. Cookie Consent and User Choice
Where HealthLynk uses only technologies necessary to provide a service specifically requested by the user or to maintain security, those technologies may operate without an optional cookie preference being enabled, subject to applicable law.
Where HealthLynk introduces technologies for purposes such as optional:
- analytics;
- marketing;
- behavioural tracking; or
- non-essential third-party functionality,
HealthLynk will provide an appropriate mechanism for users to make a choice where required.
Where consent is used as the lawful basis, the consent must be:
- voluntary;
- specific;
- informed; and
- capable of being withdrawn.
Rejecting optional cookies should not prevent a user from accessing core HealthLynk functionality merely because the user declined unrelated analytics or marketing technologies.
20. Cookie Banner
If optional cookies are introduced, HealthLynk may display a cookie-management notice or consent banner.
The banner should allow users to make meaningful choices rather than encouraging them to accept optional tracking by default.
Depending on the technologies deployed, options may include:
- Accept optional cookies
- Reject optional cookies
- Manage preferences
Strictly necessary technologies will be identified separately from optional technologies.
HealthLynk should not describe an optional cookie as "necessary" merely because it is commercially useful.
21. Withdrawing Consent
Where HealthLynk relies on consent for an optional cookie or similar technology, a user may withdraw that consent.
Withdrawal should be available through an appropriate cookie preference mechanism where such functionality is implemented.
Withdrawal will apply to future processing and will not necessarily make earlier lawful processing unlawful.
Some information previously collected may need to be retained where HealthLynk has a separate lawful obligation or basis to do so.
22. Browser Controls
Most browsers allow users to:
- view stored cookies;
- delete cookies;
- block cookies;
- block third-party cookies;
- clear local storage;
- clear cached data; and
- change browser privacy settings.
The exact options depend on the browser and device.
Blocking all cookies may prevent important HealthLynk functionality from operating correctly, particularly:
- login;
- authenticated sessions;
- form submission;
- account security; and
- other protected actions.
Users should therefore distinguish between essential HealthLynk technologies and optional tracking technologies.
23. Clearing HealthLynk Data From a Device
A user may be able to remove locally stored HealthLynk information by:
- signing out;
- clearing HealthLynk cookies;
- clearing site data through the browser;
- removing locally cached information;
- uninstalling the PWA where installed; or
- using application functionality that HealthLynk may provide for this purpose.
Clearing browser data does not necessarily delete information stored securely in the user's HealthLynk account on HealthLynk's servers.
Account closure and personal-information deletion requests are governed separately by the HealthLynk Privacy Policy and POPIA Privacy Notice.
24. Shared Devices
HealthLynk may contain sensitive health information.
Users accessing HealthLynk from shared or public devices should take particular care.
We recommend:
- signing out after use;
- not allowing the browser to save authentication credentials where inappropriate;
- avoiding unauthorised sharing of devices;
- clearing browser data where appropriate; and
- protecting the device with suitable security controls.
Users should consider the privacy implications before installing HealthLynk as a PWA or enabling persistent functionality on a device shared with other people.
25. Children's Information
Cookies and similar technologies associated with a child's managed profile may indirectly relate to information about that child.
HealthLynk will therefore take additional care when designing tracking or browser-storage technologies affecting children's personal information.
HealthLynk will not intentionally use children's health information for behavioural advertising.
Any processing of children's personal information remains subject to the additional requirements described in the HealthLynk Privacy Policy and applicable law.
26. Security
HealthLynk applies reasonable technical and organisational safeguards to cookies and related technologies where they are involved in authentication or personal-information processing.
Depending on the applicable technology, controls may include:
- secure transport;
- appropriate cookie security attributes;
- access restrictions;
- session expiry;
- session invalidation;
- protection against cross-site request forgery;
- authentication controls;
- monitoring; and
- secure application configuration.
The exact security configuration may evolve as the platform develops.
HealthLynk does not publish detailed security configuration where disclosure could make the Service less secure.
27. Changes to Our Use of Cookies
HealthLynk's use of browser technologies may change as the platform develops.
For example, HealthLynk may introduce new:
- functionality;
- analytics;
- security controls;
- payment integrations;
- accessibility functionality;
- PWA capabilities; or
- third-party services.
Before introducing a new technology that materially changes personal-information processing, HealthLynk will assess the privacy implications and update this Policy where appropriate.
Where consent is legally required, the relevant technology will not be treated as previously consented to merely because a user accepted an older version of this Policy.
28. Changes to This Cookie Policy
HealthLynk may update this Cookie Policy to reflect:
- changes to technologies used;
- new functionality;
- changes to third-party providers;
- changes in law or regulatory guidance; or
- improvements to HealthLynk's privacy practices.
The current version will be published on the HealthLynk website.
The effective date and version number will be updated when material changes are made.
29. Contact HealthLynk
Questions regarding HealthLynk's use of cookies or similar technologies may be directed to:
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07 Director: Yanga Sodoza Website: healthylynk.com Email: YangaSodoza@outlook.com Telephone: 074 663 3106 Business address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
Privacy-related enquiries may also be directed to the HealthLynk Information Officer once the final Information Officer details have been published.
Related Documents
This Cookie Policy should be read together with:
- HealthLynk Terms of Service
- HealthLynk Privacy Policy and POPIA Privacy Notice
- HealthLynk Refund, Cancellation and Subscription Policy
- HealthLynk PAIA Manual
- HealthLynk Medical Disclaimer
- HealthLynk Security and Data Protection Statement
HealthLynk (Pty) Ltd Your health information. Organised around you.