Legal and trust
PAIA Manual
Version 1.0 · Effective 17 August 2026
Published 26 August 2026
HealthLynk stores and organises information; it does not diagnose, prescribe, provide medical treatment or replace professional medical advice.
HealthLynk PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended
Version: 1.0 Date of compilation: 17 August 2026 Date of revision: 17 August 2026
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07
1. Acronyms and Abbreviations
For purposes of this Manual:
"ECTA" means the Electronic Communications and Transactions Act 25 of 2002.
"HealthLynk" means HealthLynk (Pty) Ltd.
"IO" means Information Officer.
"PAIA" means the Promotion of Access to Information Act 2 of 2000, as amended.
"POPIA" means the Protection of Personal Information Act 4 of 2013.
"Regulator" means the Information Regulator of South Africa.
"Republic" means the Republic of South Africa.
2. Introduction
HealthLynk (Pty) Ltd is a South African private company that operates a digital personal health information management platform.
HealthLynk enables users, depending on the functionality and subscription plan available to them, to store, organise, access and share health-related information and documents.
The platform may include functionality relating to:
- personal health profiles;
- family and managed profiles;
- healthcare encounters;
- prescriptions;
- tests and related records;
- healthcare receipts;
- uploaded health documents;
- profile invitations and claims;
- authorised sharing;
- health-information exports;
- subscriptions; and
- related digital services.
Because HealthLynk processes personal information, including health information and potentially children's personal information, the company recognises the importance of both access to information and the protection of privacy.
3. Purpose of This PAIA Manual
This Manual has been prepared to assist members of the public to understand how they may request access to records held by HealthLynk.
The Manual is intended to enable a person to:
- understand the categories of records held by HealthLynk;
- identify records that may be available without submitting a formal PAIA request;
- understand how to make a request for access to a HealthLynk record;
- obtain the relevant contact details for access-to-information requests;
- understand the categories of records HealthLynk holds under applicable legislation;
- understand the purposes for which HealthLynk processes personal information;
- understand the categories of data subjects and personal information processed by HealthLynk;
- understand the categories of recipients to whom personal information may lawfully be supplied;
- understand whether HealthLynk may process or transfer personal information outside South Africa;
- understand the general security safeguards HealthLynk applies to personal information; and
- obtain information about the remedies available where a PAIA request is refused or not answered.
This Manual does not mean that every record identified in it will automatically be disclosed.
A request for access remains subject to PAIA, POPIA and any other applicable law.
4. Details of the Private Body
4.1 Legal Entity
Legal name: HealthLynk (Pty) Ltd Registration number: 2026/646559/07 Legal form: Private Company Country of incorporation: Republic of South Africa Website: healthylynk.com
4.2 Head of the Private Body
Name: Yanga Sodoza Capacity: Director Telephone: 074 663 3106 Email: YangaSodoza@outlook.com
4.3 Information Officer
Information Officer: Yanga Sodoza (Director / Head of Private Body)
The Information Officer details are rendered from the current HealthLynk Organisation record.
Until the final Information Officer contact details are published, PAIA and privacy enquiries may be directed to:
Name: Yanga Sodoza Telephone: 074 663 3106 Email: YangaSodoza@outlook.com
4.4 Deputy Information Officer
Deputy Information Officer: None currently designated.
HealthLynk may designate one or more Deputy Information Officers in future where this becomes reasonably necessary as the organisation grows.
4.5 General PAIA Contact
Email: YangaSodoza@outlook.com Telephone: 074 663 3106
The general PAIA contact email will be updated to an official HealthLynk email address once the applicable business email infrastructure is operational.
4.6 Registered and Head Office
Physical business address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
Postal address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
Telephone: 074 663 3106 Email: YangaSodoza@outlook.com Website: healthylynk.com
5. Guide on How to Use PAIA
The Information Regulator has prepared and made available a Guide explaining how to exercise rights under PAIA and POPIA.
The Guide explains matters including:
- the purpose of PAIA and POPIA;
- how to request access to a record of a public or private body;
- the assistance available from Information Officers and the Information Regulator;
- available legal remedies;
- complaints to the Information Regulator;
- PAIA manuals;
- automatically available records;
- applicable PAIA fees; and
- the regulations made under PAIA.
The Guide is available from the Information Regulator and through the Regulator's official website.
The Information Regulator currently provides the Guide in South Africa's official languages and in accessible formats made available by the Regulator.
Information Regulator
Website: inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Telephone: 010 023 5200 Toll-free: 0800 017 160
Current versions of the Guide and prescribed PAIA forms should be obtained directly from the Information Regulator.
6. Records Available Without a Formal PAIA Request
HealthLynk makes, or intends to make, certain records publicly available without requiring a formal PAIA request.
Subject to publication and availability, these may include:
| Category | Record | Method of Access |
|---|---|---|
| Corporate information | HealthLynk legal and contact information | Website |
| Legal | Terms of Service | Website |
| Privacy | Privacy Policy and POPIA Privacy Notice | Website |
| Billing | Refund, Cancellation and Subscription Policy | Website |
| Access to information | PAIA Manual | Website |
| Health and safety information | Medical Disclaimer | Website |
| Privacy | Cookie Policy | Website |
| Security | Security and Data Protection Statement | Website |
| Commercial information | Public subscription plans and pricing | Website |
| Service information | Public descriptions of HealthLynk features and services | Website |
| Support | Public support and contact information | Website |
Documents that have not yet been published will become automatically available only once they are made available on the HealthLynk website.
HealthLynk may add further categories of automatically available records in future.
The fact that a category is listed as automatically available does not mean that confidential records, personal information or internal records falling within a similarly named category are automatically accessible.
7. Records Available in Accordance With Other Legislation
HealthLynk creates, maintains or may be required to maintain records under various South African laws.
The following list is not necessarily exhaustive and will be updated as HealthLynk's operations develop.
| Applicable Legislation | Examples of Relevant Records |
|---|---|
| Companies Act 71 of 2008 | Incorporation records, Memorandum of Incorporation, director records, shareholder/securities records, company resolutions, statutory company records and accounting records |
| Promotion of Access to Information Act 2 of 2000 | PAIA Manual, PAIA requests, correspondence and decisions concerning requests for access |
| Protection of Personal Information Act 4 of 2013 | Privacy notices, data-subject requests, consent and authorisation records where applicable, operator-related records, information-security and privacy compliance records |
| Electronic Communications and Transactions Act 25 of 2002 | Electronic agreements, electronic transaction records, website supplier information and electronic communications relevant to transactions |
| Consumer Protection Act 68 of 2008 | Consumer agreements, subscription terms, cancellation and refund records, complaints and relevant consumer transaction records |
| Income Tax Act 58 of 1962 | Tax-related accounting and supporting records where applicable |
| Tax Administration Act 28 of 2011 | Tax registrations, returns, supporting documentation and records required for tax administration |
Where further legislation becomes applicable to HealthLynk, this Manual may be updated accordingly.
The inclusion of a record in this section does not mean that the record is publicly available.
Access remains subject to the relevant legislation and the applicable provisions of PAIA.
8. Subjects on Which HealthLynk Holds Records
HealthLynk may hold records concerning the following subjects.
8.1 Corporate and Governance Records
These may include:
- company registration records;
- Memorandum of Incorporation;
- director records;
- shareholder and securities records;
- company resolutions;
- corporate policies;
- governance records;
- statutory records;
- agreements; and
- company correspondence.
8.2 Financial, Accounting and Tax Records
These may include:
- accounting records;
- invoices;
- expenses;
- bank-related business records;
- tax records;
- financial statements;
- budgets;
- payment records;
- subscription income records;
- payment-provider settlements;
- refunds;
- financial reconciliations; and
- supporting financial documentation.
8.3 Customer and Account Records
These may include:
- account registration information;
- user contact details;
- authentication and verification records;
- account status;
- subscription information;
- support records;
- account notifications;
- user preferences; and
- relevant account activity.
8.4 Health Profile and Health Information Records
Depending on the information users choose to provide, HealthLynk may hold:
- personal health profiles;
- healthcare encounter records;
- medical-history information;
- prescription information;
- test-related information;
- healthcare-provider information;
- discharge information;
- ongoing care information;
- health-related notes;
- uploaded medical documents;
- health-related images;
- healthcare receipts;
- supporting documents; and
- other health information entered or uploaded by authorised users.
The existence of this category does not mean that a person may obtain another person's health information merely by submitting a PAIA request.
Any request involving health information will be assessed particularly carefully under PAIA, POPIA and other applicable law.
8.5 Family and Managed Profile Records
These may include:
- family relationships;
- parent or guardian relationships;
- managed-profile relationships;
- profile access permissions;
- profile invitations;
- profile-claim records;
- invitation status;
- verification records;
- profile-access history; and
- audit information relating to profile management and sharing.
8.6 Subscription and Payment Records
These may include:
- subscription plans;
- trial information;
- billing frequency;
- payment status;
- payment references;
- recurring-payment references or tokens;
- cancellation records;
- refund records;
- payment-provider transaction information; and
- subscription history.
HealthLynk does not intend to store complete card credentials where payment credentials are processed directly by an authorised payment service provider.
8.7 Privacy and POPIA Records
These may include:
- privacy policies and notices;
- records of data-subject requests;
- objections;
- correction requests;
- deletion requests;
- consent or authorisation records where applicable;
- Information Officer records;
- privacy assessments;
- personal-information impact assessments;
- operator agreements;
- incident records;
- security-compromise records;
- privacy complaints; and
- records demonstrating privacy compliance.
8.8 PAIA Records
These may include:
- this PAIA Manual;
- PAIA request forms;
- supporting documents;
- correspondence with requesters;
- fee notices;
- decisions on PAIA requests;
- third-party notices;
- correspondence with the Information Regulator; and
- complaints or proceedings relating to access to information.
8.9 Information Security and Technical Records
These may include:
- security policies;
- access-control records;
- authentication logs;
- application and server logs;
- audit logs;
- security-event records;
- vulnerability-management records;
- software-deployment records;
- backup and recovery records;
- infrastructure records;
- configuration records;
- incident-response records; and
- technical documentation.
Disclosure of security-sensitive records may be restricted where disclosure would create a security risk or where another lawful ground for refusal applies.
8.10 Service Provider and Contractual Records
These may include:
- service-provider agreements;
- software and infrastructure agreements;
- operator or data-processing agreements;
- payment-provider agreements;
- professional-service agreements;
- confidentiality agreements;
- supplier records; and
- related correspondence.
8.11 Website and Public Communication Records
These may include:
- website content;
- legal policies;
- pricing information;
- public notices;
- service descriptions;
- support information; and
- marketing or communication material.
8.12 Personnel Records
At the date of compilation, HealthLynk is an early-stage company and does not maintain a conventional employee workforce.
The company nevertheless maintains appropriate director and corporate-officer records.
If HealthLynk employs personnel in future, this category may include records such as:
- employment agreements;
- payroll records;
- leave records;
- employment policies;
- training records;
- performance records; and
- other records required by applicable employment legislation.
This Manual will be updated where appropriate as the workforce develops.
9. Processing of Personal Information
9.1 Purpose of Processing
HealthLynk may process personal information for purposes including:
- registering and administering user accounts;
- verifying users;
- authenticating access to the Service;
- creating and maintaining health profiles;
- storing and organising health-related records and documents;
- managing family and managed profiles;
- enabling profile invitations and claims;
- managing permissions and authorised sharing;
- providing health-information exports;
- administering subscriptions and trials;
- processing and reconciling payments;
- providing customer support;
- sending service and security communications;
- detecting and preventing fraud or unauthorised access;
- protecting HealthLynk's systems and users;
- maintaining audit and security records;
- complying with legal and regulatory obligations;
- responding to privacy and PAIA requests;
- managing service providers;
- maintaining business records; and
- improving the reliability and security of the Service.
HealthLynk's Privacy Policy and POPIA Privacy Notice provides additional information about these processing activities.
10. Categories of Data Subjects and Personal Information
HealthLynk may process personal information concerning the following categories of data subjects.
| Data Subject | Categories of Personal Information That May Be Processed |
|---|---|
| Account holders | Name, surname, contact details, date of birth, authentication information, account information, subscription information, technical and security information |
| Health-profile subjects | Identification and profile information, health information, medical history, prescriptions, tests, encounters, health documents and other voluntarily recorded health information |
| Children | Identification, profile, relationship and health information where lawful authority exists |
| Parents, guardians and profile managers | Identity, contact, relationship, authority, access and profile-management information |
| Family members and authorised recipients | Identity, contact, relationship, invitation and access information |
| Profile invitees and claimants | Contact details, verification data, invitation details, claim status and related security records |
| Subscribers and payers | Account information, plan, billing information, transaction references, payment status and recurring-payment information |
| Website visitors | Technical information, IP address, session information and cookie information where applicable |
| Support contacts | Contact information, correspondence, complaint or support-request information |
| Directors and officers | Identity, contact, corporate, financial and statutory information |
| Suppliers and service providers | Names, contact information, contractual details, company details, payment information and service information |
| Organisational representatives | Name, contact details, organisation, role, account and contractual information |
Health information is treated as special personal information.
Children's personal information is subject to the additional protections required by applicable law.
11. Recipients of Personal Information
Personal information may be supplied to the following categories of recipients where lawfully permitted and reasonably necessary.
| Category of Information | Potential Recipient or Category of Recipient |
|---|---|
| Information deliberately shared by a user | Family members, carers, healthcare professionals or other persons authorised by the relevant user |
| Cloud-hosted application and stored information | Authorised cloud infrastructure and hosting providers acting for HealthLynk |
| Email and verification information | Authorised communication and email-delivery providers |
| Payment and subscription information | PayFast by Network and relevant payment, banking or financial-system participants |
| Technical and security information | Authorised infrastructure, monitoring, security and technical service providers |
| Business records | Accountants, auditors, legal advisers or other professional advisers where required |
| Information required by law | Courts, regulators, law-enforcement agencies or other competent authorities where disclosure is legally required |
| Organisational-service information | Relevant contracting organisation where a lawful service arrangement and appropriate privacy basis exists |
HealthLynk does not make user health profiles publicly available.
HealthLynk does not sell identifiable health information to advertisers or data brokers.
12. Planned Transborder Flows of Personal Information
HealthLynk uses technology and cloud-based services that require a careful assessment of where personal information is stored, routed, backed up or otherwise processed.
The following production data-flow description is current for Version 1.0:
- the primary AWS workload is in af-south-1;
- structured application and health data is held in PostgreSQL/RDS;
- uploaded documents and generated exports are held in private S3 storage;
- transactional email is sent through Amazon SES; and
- subscription payment processing is handled by PayFast, which returns payment references and status needed for billing administration.
Tracked verification item: confirm the final AWS operator/subprocessor and any cross-border transfer details before production publication. No unverified operator or transfer is asserted here.
HealthLynk will not intentionally transfer personal information outside South Africa unless the requirements of applicable data-protection law have been considered and satisfied.
Special personal information and children's personal information will receive particular consideration when assessing any transborder processing.
13. Information Security Measures
HealthLynk recognises that it processes information of a sensitive nature and therefore takes reasonable technical and organisational steps intended to preserve the confidentiality, integrity and availability of personal information.
Depending on the system and risk involved, safeguards may include:
- secure user authentication;
- email verification;
- role-based and account-based access controls;
- restrictions on administrative access;
- encrypted network communications;
- secure cloud infrastructure;
- separation of customer access;
- logging and monitoring;
- audit records;
- secure configuration management;
- backups and recovery procedures;
- vulnerability and dependency management;
- container and software-security scanning;
- secure development and deployment practices;
- security reviews;
- incident-response procedures;
- account and session protections;
- security controls imposed on operators and service providers; and
- regular review and improvement of safeguards.
HealthLynk does not disclose detailed security configurations publicly where doing so could materially undermine the security of the Service or its users.
14. How to Request Access to a HealthLynk Record
A person seeking access to a HealthLynk record under PAIA must use the prescribed Form 2: Request for Access to Record.
The current prescribed Form 2 can be obtained from the Information Regulator.
The completed request should be submitted to HealthLynk using the PAIA contact details contained in this Manual.
The requester should provide sufficient information to enable HealthLynk to:
- identify the requester;
- identify the requested record;
- locate the record;
- understand the preferred form of access;
- contact the requester; and
- determine the right the requester wishes to exercise or protect.
Because HealthLynk is a private body, a requester must identify the right that the requested record is required to exercise or protect and explain why the requested record is necessary for that purpose.
Where a request is made on behalf of another person, appropriate proof of authority may be required.
Where a request concerns sensitive personal or health information, HealthLynk may require reasonable identity and authority verification before disclosing information.
15. Requests Concerning Your Own Personal Information
A person seeking access to their own personal information may also have rights under POPIA.
Depending on the request, HealthLynk may process the matter under:
- PAIA;
- POPIA;
- the HealthLynk Privacy Policy and POPIA Privacy Notice; or
- a combination of the applicable procedures.
HealthLynk will not require a requester to disclose unnecessary medical information merely to establish their identity.
Reasonable verification may nevertheless be required before access to sensitive personal information is provided.
16. Requests Concerning Another Person's Health Information
Submitting a PAIA request does not create an automatic entitlement to another person's health or medical information.
Where a request relates to another person's health information, HealthLynk may consider:
- the identity of the requester;
- the identity of the person to whom the record relates;
- the relationship between the parties;
- whether the requester is legally authorised to act for the person;
- the privacy rights of the data subject;
- whether disclosure is necessary for the exercise or protection of a right;
- any objection by an affected third party;
- applicable POPIA requirements; and
- the grounds for granting or refusing access under PAIA.
HealthLynk may redact or sever information where PAIA permits part of a record to be disclosed while another part must or may lawfully be withheld.
17. Fees
PAIA permits prescribed fees to apply to certain requests and forms of access.
Where a fee is lawfully payable, HealthLynk will notify the requester in accordance with PAIA and the applicable PAIA Regulations.
Depending on the request, fees may relate to:
- the request itself where applicable;
- reproduction of records;
- searching for and preparing records;
- copying;
- electronic media;
- postage; or
- other prescribed access costs.
HealthLynk will use the current prescribed PAIA fee structure rather than creating its own arbitrary access fees.
Where an exemption from a particular fee applies under PAIA or its Regulations, HealthLynk will apply that exemption.
18. Decision on a PAIA Request
HealthLynk will consider a properly submitted request in accordance with PAIA.
Subject to the provisions governing matters such as third-party notification, HealthLynk will make a decision within the period required by PAIA.
The ordinary statutory period is 30 days after receipt of a properly completed request, subject to any lawful extension permitted under PAIA.
Where PAIA permits an extension, the period may be extended once for up to a further 30 days, and the requester will be notified as required.
If access is granted, HealthLynk will provide information about:
- the access granted;
- the applicable form of access;
- any prescribed fee payable; and
- the steps required to obtain the record.
If access is refused, HealthLynk will provide the notice and reasons required by PAIA.
19. Grounds on Which Access May Be Refused
A request may be refused only on a ground permitted by PAIA or other applicable law.
Depending on the circumstances, this may include grounds relating to:
- protection of another person's privacy;
- commercial information of a third party;
- confidential information;
- safety of individuals or protection of property;
- legally privileged records;
- HealthLynk's commercial information;
- research information;
- or another applicable statutory ground.
HealthLynk will not refuse a request merely because disclosure is inconvenient.
Where only part of a record is subject to a lawful ground for refusal, HealthLynk will consider whether the remainder can lawfully be disclosed.
20. Complaints and Remedies
There is no compulsory internal appeal procedure for an ordinary PAIA decision by a private body such as HealthLynk.
Where a requester is dissatisfied with HealthLynk's decision, refusal, non-response or other PAIA-related conduct, the requester may have the right to:
- lodge a complaint with the Information Regulator; and/or
- approach a competent court in accordance with PAIA.
Complaints to the Information Regulator must use the prescribed complaint procedure.
The current complaint form and instructions should be obtained from the Information Regulator.
Information Regulator
Website: inforegulator.org.za General enquiries: enquiries@inforegulator.org.za PAIA complaints: PAIAComplaints@inforegulator.org.za Telephone: 010 023 5200 Toll-free: 0800 017 160
21. Availability of This Manual
A copy of this Manual will be made available:
- on the HealthLynk website at healthylynk.com;
- at HealthLynk's registered/head office for inspection during normal business hours once the final business address is established;
- to a person upon request, subject to any prescribed fee lawfully applicable to the requested copy; and
- to the Information Regulator upon request.
The intended website location is:
healthylynk.com/paia/
or another clearly accessible legal/compliance location on the HealthLynk website.
Electronic access to the publicly published version will be provided without charge.
22. Updating This Manual
HealthLynk will review this PAIA Manual regularly and update it where reasonably necessary.
An update may be required following changes involving:
- HealthLynk's business address;
- Information Officer or Deputy Information Officer details;
- company structure;
- categories of records held;
- applicable legislation;
- personal-information processing;
- service providers;
- international data processing;
- security arrangements;
- products or services;
- or applicable legal or regulatory requirements.
The latest published version will state its revision date.
23. Related HealthLynk Documents
This Manual should be read together with, where relevant:
- HealthLynk Terms of Service
- HealthLynk Privacy Policy and POPIA Privacy Notice
- HealthLynk Refund, Cancellation and Subscription Policy
- HealthLynk Medical Disclaimer
- HealthLynk Cookie Policy
- HealthLynk Security and Data Protection Statement
24. Contact HealthLynk
For PAIA or access-to-information enquiries:
HealthLynk (Pty) Ltd Registration Number: 2026/646559/07 Head of Private Body: Yanga Sodoza Telephone: 074 663 3106 Email: YangaSodoza@outlook.com Website: healthylynk.com Physical Address: 131 Eoan Ave, Eden Heights, Scottsdene, Kraaifontein, Cape Town, Western Cape, South Africa, 7570
25. Issued By
Yanga Sodoza Director HealthLynk (Pty) Ltd
Date: 17 August 2026
HealthLynk (Pty) Ltd Your health information. Organised around you.