Privacy Policy
Last updated: July 2026
1. Introduction
DocAppointment ("we", "our", "us"), operated by Vayo Consulting (Pty) Ltd, is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA).
2. Information Officer
Our designated Information Officer responsible for ensuring compliance with POPIA is:
- Name: Siyabonga Pangase
- Email: privacy@docappointment.co.za
- Organisation: Vayo Consulting (Pty) Ltd
You may contact our Information Officer to exercise any of your rights under POPIA or to raise privacy-related concerns.
3. Information We Collect
We collect information you provide directly, including:
- Practitioner data: name, email address, phone number, practice name, address, specialisation, HPCSA registration number
- Patient data: name, phone number, email (when provided), appointment history, symptom descriptions shared during booking
- Payment information: processed securely via PayFast — we do not store card details
- Usage data: pages visited, features used, session duration, device type
- Communication data: WhatsApp messages exchanged with our booking assistant, email correspondence
4. Lawful Basis for Processing
We process personal information under the following POPIA conditions:
- Contractual necessity (Section 11(1)(b)): To provide the services you signed up for — booking management, notifications, calendar management
- Legitimate interest (Section 11(1)(f)): To improve our platform, prevent fraud, and ensure security
- Consent (Section 11(1)(a)): For optional communications such as marketing emails. You may withdraw consent at any time
- Legal obligation (Section 11(1)(c)): To comply with applicable laws, tax requirements, or valid legal processes
5. How We Use Your Information
- To provide and maintain our booking and practice management service
- To process appointments and send notifications (Email/WhatsApp)
- To manage subscriptions and billing
- To communicate with you about your account and service updates
- To improve our platform, train AI models for symptom classification, and develop new features
- To detect and prevent fraud, abuse, and security incidents
6. AI and Automated Decision-Making
DocAppointment uses artificial intelligence for:
- Symptom classification: Understanding patient descriptions and routing them to the appropriate specialist
- Location resolution: Matching patients with nearby practitioners
- Booking assistance: Guiding patients through the appointment scheduling process via WhatsApp or website chatbot
In accordance with POPIA Section 71, you have the right to:
- Be informed that automated decision-making is being used
- Request human intervention in any automated process
- Challenge the outcome of an automated decision
AI-generated suggestions (e.g. specialist matching) are recommendations only — final booking decisions are always made by the patient.
7. Data Protection & Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls (practitioner, doctor, admin, patient)
- OAuth 2.0 / OpenID Connect authentication via Keycloak
- Database-level schema isolation per service
- Regular dependency vulnerability scanning
- Infrastructure hosted on dedicated VPS servers in South Africa (HostAfrica)
8. Data Sharing & Sub-Processors
We do not sell your personal information. We share data only with the following third-party service providers (sub-processors) necessary to deliver our service:
| Provider | Purpose | Data Location |
|---|---|---|
| HostAfrica | Infrastructure hosting (VPS) | South Africa |
| PayFast | Payment processing | South Africa |
| Meta (WhatsApp Cloud API) | Messaging & notifications | Global (Meta infrastructure) |
| Google (reCAPTCHA) | Bot protection | Global (Google infrastructure) |
| Keycloak (self-hosted) | Authentication | Cape Town, South Africa |
9. Cross-Border Data Transfers
Your primary data (patient records, bookings, practice data) is stored in South Africa on dedicated VPS servers hosted by HostAfrica. However, some processing may involve data transfer outside South Africa:
- WhatsApp messaging: Messages sent via WhatsApp Cloud API are processed through Meta's global infrastructure
- reCAPTCHA: Bot-detection tokens are processed by Google's global infrastructure
These transfers are necessary for service delivery and are conducted with appropriate safeguards as permitted under POPIA Section 72, specifically that the recipients are subject to binding rules providing adequate protection.
10. Data Controller vs Data Processor
Under POPIA:
- Practitioners are the "responsible party" (data controller) for their patient data. They determine the purpose and means of processing patient information
- DocAppointment acts as an "operator" (data processor), processing patient data on behalf of the practitioner in accordance with their instructions and this policy
Practitioners are responsible for ensuring they have appropriate consent or lawful basis for collecting patient information through our platform.
11. Cookies & Tracking
We use the following cookies:
- Essential cookies: Session management, authentication state, CSRF protection. These are necessary for the platform to function and cannot be disabled
- reCAPTCHA cookies: Set by Google to provide bot protection on forms. Required for security
- Preference cookies: Cookie consent choice, theme preference. Duration: 1 year
We do not use analytics tracking cookies or advertising cookies. We do not share cookie data with third-party advertisers.
12. Data Retention
- Active accounts: Data is retained for as long as your account is active
- Post-cancellation: Data is preserved for 30 days after subscription ends, then permanently deleted
- Chat/booking logs: Retained for 12 months for service improvement and dispute resolution
- Payment records: Retained for 5 years as required by South African tax law (Tax Administration Act)
- Immediate deletion: You may request immediate deletion of your data by contacting privacy@docappointment.co.za
13. Data Breach Notification
In the event of a data breach that compromises the confidentiality or integrity of your personal information:
- We will notify the Information Regulator as required under POPIA Section 22
- We will notify affected users within 72 hours of becoming aware of the breach
- Notification will include the nature of the breach, the data affected, steps we are taking, and recommendations for you to protect yourself
14. Your Rights Under POPIA
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Objection: Object to the processing of your data on reasonable grounds
- Portability: Request your data in a structured, machine-readable format
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
- Complain: Lodge a complaint with the Information Regulator at inforegulator.org.za
To exercise any of these rights, contact our Information Officer at privacy@docappointment.co.za. We will respond within 30 days.
15. Children's Privacy
DocAppointment is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. Patient bookings for minors must be made by a parent or legal guardian.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be communicated via email and posted on this page with an updated "Last updated" date. Continued use of the platform after changes constitutes acceptance of the updated policy.
17. Contact Us
For privacy-related inquiries:
- Information Officer: privacy@docappointment.co.za
- General support: support@docappointment.co.za
- Information Regulator (SA): inforegulator.org.za