Privacy & POPIA
Last updated: September 2026
Part K — Privacy and POPIA
39. Privacy
Healist processes personal information in accordance with applicable South African privacy law, including the Protection of Personal Information Act 4 of 2013.
Depending on the processing involved, Healist may act as:
- a responsible party determining why and how information is processed; or
- an operator processing information on behalf of a Practitioner.
Privacy enquiries and data-subject requests must be sent to support@healist.co.za.
40. Information Healist may process
Depending on how Healist is used, information may include:
- name;
- email address;
- account information;
- age;
- contact details;
- profile information;
- Practitioner qualifications;
- Practitioner registrations;
- Practitioner verification documents;
- booking information;
- payment records;
- communications;
- matching responses;
- questionnaires;
- goals and preferences;
- health and wellbeing information;
- symptoms or concerns voluntarily disclosed;
- session information;
- Practitioner notes;
- AI-generated summaries;
- technical information;
- device information;
- IP addresses;
- authentication information;
- security logs;
- usage information;
- support requests; and
- other information reasonably required to operate Healist.
41. Purpose of processing
Healist may process information to:
- create and administer accounts;
- provide the Platform;
- match Users with Practitioners;
- facilitate Practitioner discovery;
- make bookings;
- process payments;
- communicate with Users and Practitioners;
- provide reminders;
- facilitate online sessions;
- maintain records;
- provide Practitioner practice-management tools;
- provide AI functionality;
- authenticate accounts;
- verify Practitioners;
- provide customer support;
- prevent fraud;
- secure the Platform;
- enforce these Terms;
- manage disputes;
- comply with law;
- establish, exercise or defend legal rights;
- improve functionality;
- monitor system performance; and
- conduct lawful internal analytics.
42. Special personal information
Information concerning a person's physical health, mental health and certain other personal matters may constitute special personal information.
Where Healist processes special personal information, it will do so only where permitted by applicable law.
Where consent is the applicable basis, the User authorises Healist to process information voluntarily supplied for purposes including:
- matching;
- account functionality;
- booking;
- Practitioner interaction;
- Platform personalisation;
- records;
- support; and
- related services requested by the User.
A User may withdraw consent where applicable by contacting support@healist.co.za.
Withdrawal does not invalidate processing which occurred lawfully before withdrawal or processing which may legally continue on another basis.
43. Practitioner access to User information
Where a User chooses, contacts or books a Practitioner, relevant User information may be made available to that Practitioner.
The Practitioner may become independently responsible for information received or generated within the professional relationship.
The Practitioner must comply with all applicable privacy, confidentiality and professional obligations.
44. Clinical and professional records
Professional or clinical information created by a Practitioner may constitute a Practitioner-controlled professional record.
Where Healist merely stores or processes such information on behalf of the Practitioner, Healist may act as the Practitioner's operator.
The Practitioner remains responsible for:
- lawful creation of the record;
- professional content;
- accuracy;
- required retention;
- Client access rights applicable to professional records;
- confidentiality; and
- lawful use.
Healist remains responsible for processing for which Healist independently determines the purpose and means.
45. Confidentiality
Healist will treat health and Practitioner relationship information as confidential and will restrict access according to applicable law and reasonable operational requirements.
Information may nevertheless be disclosed where:
- authorised by the User;
- reasonably necessary to provide a requested service;
- processed by an authorised service provider;
- required by law;
- required by a valid legal process;
- necessary to establish or defend legal rights; or
- otherwise legally permitted.
Practitioners remain separately responsible for their professional confidentiality obligations.
46. Service providers
Healist may use service providers for functions including:
- cloud hosting;
- databases;
- authentication;
- payment processing;
- email;
- messaging;
- analytics;
- security;
- video communications;
- calendar functionality;
- artificial intelligence;
- infrastructure; and
- customer support.
Service providers may process information only for legitimate purposes associated with the services for which they have been engaged, subject to applicable contractual and legal safeguards.
47. International processing
Some technology providers may process information outside South Africa.
Where personal information is transferred outside South Africa, Healist will take reasonable steps to ensure the transfer satisfies applicable requirements under POPIA.
48. Security
Healist will maintain reasonable technical and organisational security safeguards appropriate to the information being processed.
These may include:
- access controls;
- encryption;
- authentication;
- restricted administrative access;
- logging;
- system monitoring;
- backups;
- secure communications;
- security policies; and
- other reasonable safeguards.
No internet-connected platform can guarantee absolute security.
Users and Practitioners are responsible for protecting their login credentials.
49. Security incidents
Where Healist reasonably believes that personal information has been accessed or acquired by an unauthorised person, Healist will take the actions required by applicable law.
Practitioners must immediately notify Healist at support@healist.co.za of any suspected security breach involving information accessed through Healist.
50. Retention
Healist retains personal information only for as long as reasonably necessary for:
- the purpose for which it was collected;
- Platform operation;
- professional record requirements;
- contractual obligations;
- accounting;
- fraud prevention;
- regulatory compliance;
- dispute resolution;
- legal claims; or
- another lawful purpose.
Retention periods may differ depending on the type of information.
Where deletion is appropriate, information may be deleted, destroyed or irreversibly de-identified.
51. Aggregated and de-identified information
Healist may create aggregated, statistical or genuinely de-identified information from Platform activity where individuals cannot reasonably be identified from that information.
Healist may use such information for lawful purposes including:
- analytics;
- research;
- product development;
- service improvement;
- benchmarking;
- Platform operations;
- commercial analysis; and
- understanding service effectiveness.
Healist will not treat information as de-identified merely because a person's name has been removed if the person can still reasonably be identified from the remaining information.
52. User privacy rights
Subject to applicable law, a person may request:
- confirmation that Healist holds their information;
- access;
- correction;
- updating;
- deletion where legally permitted;
- restriction where applicable;
- objection to processing where applicable; or
- withdrawal of consent where processing depends on consent.
Requests must be submitted to support@healist.co.za.
Identity verification may be required before a request is processed.
Certain records may need to be retained despite a deletion request where required or permitted by law.
53. Information Officer and POPIA contact
All requests intended for Healist's Information Officer function must be submitted to support@healist.co.za.
The request should clearly state that it relates to privacy, POPIA, PAIA or personal information.
54. Direct marketing
Service communications relating to bookings, payments, security, accounts and requested services may be sent where necessary to operate Healist.
Marketing communications will be handled separately and sent only where permitted by law.
Users may opt out of marketing at any time.
Withdrawal from marketing does not prevent transactional or security communications.
55. Cookies and analytics
Healist may use cookies and similar technologies for:
- authentication;
- security;
- preferences;
- Platform functionality;
- performance;
- analytics; and
- lawful measurement.
Where consent is required for a particular technology, Healist may provide an appropriate consent mechanism.
Part L — Children
56. Age requirements
Users must ordinarily be at least 18 years old to independently create and use a Healist account.
Where Healist expressly supports services for a minor, appropriate consent from a parent, guardian or other competent person must be obtained where required.
The Practitioner remains responsible for determining whether they may lawfully provide services to the minor and obtaining any additional treatment consent required by law or professional rules.
The remaining parts of the agreement — including Healist's role, practitioner responsibilities, bookings, payments and liability — are in the full Terms.