← Back to PraxiLog

Privacy Policy

Last Updated: 11 August 2026

1. Introduction & Roles Under POPIA

PraxiLog ("we", "us", "our") is operated by PraxiLog (Pty) Ltd (Registration No. 2026/581918/07) and provides practice management software to healthcare practices ("Practices") in South Africa. This Privacy Policy explains how we collect, process, and protect information in accordance with the Protection of Personal Information Act (POPIA).

Under POPIA:

  • The Practice is the Responsible Party for its patients' personal information — it decides what data to collect and why, and is accountable for obtaining valid patient consent.
  • PraxiLog is the Operator — we process data on the Practice's behalf, under its instructions, using the security measures described below.

2. Information We Process

Depending on how a Practice uses PraxiLog, this includes:

  • Account information — practitioner and staff name, email, role, and (where provided) statutory registration number, managed via our authentication provider, Clerk.
  • Patient demographic & contact information — name, date of birth, gender, ID number, contact details, and medical aid details.
  • Clinical information — allergies, chronic conditions, current medications, ICD-10 codes, and clinical notes (structured as Subjective/Objective/Assessment/Plan).
  • Consent records — how and when a patient's processing consent was captured, and any withdrawal.
  • Scheduling & booking data — appointments, online bookings, and reminder/confirmation activity.
  • Billing information — invoices, line items, tariff/ICD-10 billing codes, and payment records.
  • Documents a Practice uploads to a patient's file.
  • Audit & disclosure records — a log of who accessed a record, and of any letter or export made from it.

3. Communications

PraxiLog sends the operational emails needed to run your practice — appointment confirmations and reminders to patients, sent on the Practice's behalf, and account, billing, and product emails to practitioners and staff. These are transactional communications necessary to provide the Service, not direct marketing, and we do not send promotional email on our own initiative. A patient who no longer wants appointment reminders can ask their Practice to turn them off.

4. AI-Assisted Drafting

PraxiLog can help draft clinical notes and correspondence using Google's Gemini AI model. Text typed by the practitioner, as well as audio recorded during a consult (where audio consultation features are enabled by the Practice), is sent to Gemini solely to generate a draft for the practitioner to review.

  • Informed consent: before enabling audio recording for a consult, the Practice must have the patient's informed consent to the recording, consistent with its obligations as Responsible Party and with HPCSA guidance.
  • Data processing & ephemerality: recorded audio is processed transiently in memory and is never written to disk or any storage bucket by PraxiLog — only the resulting text draft is kept in the patient's record.
  • Model training: text and audio sent to Gemini are processed under Google's paid-tier API terms and are not used by Google or PraxiLog to train or improve public AI models.
  • Clinical responsibility: the AI is instructed to structure only what the practitioner said or typed, not to invent clinical content or provide automated diagnoses. PraxiLog is an administrative drafting tool, not a diagnostic system. The practitioner retains sole clinical judgment and responsibility for reviewing, editing, and approving every AI-assisted draft before it is saved to the medical record.

5. Security Measures

  • In transit: all traffic between your device and PraxiLog is encrypted with TLS.
  • At rest, server-side: data held in our database and file storage is protected by our infrastructure providers' encryption at rest.
  • At rest, on your device: while you are signed in, PraxiLog keeps a local cache of your practice's data so an active session keeps working through load-shedding or a patchy connection, syncing back once connectivity returns. Signing in for the first time, or reopening PraxiLog after closing it, still requires an internet connection. Clinical fields in that local cache are additionally encrypted with AES-GCM, using a key unique to your practice that is fetched fresh each session and never stored outside that session — a signed-out or lost device holds only ciphertext.
  • Access control: access is scoped to your Practice and to your role — for example, receptionist accounts cannot view clinical notes.
  • Audit trail: record access, letter/document exports, role changes, and other sensitive actions are logged.

6. Third Parties We Use

We use the following service providers to operate PraxiLog. Each processes data only as needed to provide their service to us:

  • Clerk — authentication and account management.
  • Neon — hosts our PostgreSQL database.
  • Google Cloud Platform — application hosting (Cloud Run), file storage (Cloud Storage) for uploaded documents, and the Gemini API for AI-assisted drafting.
  • PayFast — payment processing for subscriptions. PayFast receives the billing information needed to process payment; PraxiLog does not store card details.

Cross-border transfers: some of these providers may process or store data outside South Africa. These transfers are governed by data processing agreements requiring compliance with standards substantially similar to POPIA or the GDPR (POPIA section 72(1)(a)), and are necessary to perform our contract with you (section 72(1)(b)) — we could not provide PraxiLog without them.

7. Data Retention

Clinical records are retained for a minimum of 6 years from the patient's last clinical contact, in line with HPCSA record-keeping rules, or until a minor reaches their 21st birthday if that is later. Longer retention may apply where a specific HPCSA rule or other statutory obligation requires it — for example, records relating to mental incapacity, obstetric or neonatal care, or occupational health. Records cannot be erased before the applicable retention period has passed, even at the Practice's request.

8. Your Rights

Patients may request access to, correction of, or erasure of their personal information, subject to the retention rule above. On the Paperless plan, a Practice can action an access request directly in PraxiLog via its built-in export and erasure tools — producing a complete export of everything held on a patient, and erasure once the retention period has passed. On other plans, the same request can be sent to us and we will action it on the Practice's behalf.

These are patient rights, not plan features: regardless of plan, a request can always be made to the Practice directly, or to us at popia@praxilog.co.za.

Formal requests can use the Information Regulator's prescribed forms — Form 2 to request correction or deletion, and Form 1 to object to processing — though a plain email to the Practice or to us works just as well. If you believe your information has been processed unlawfully, you may also lodge a complaint with the South African Information Regulator at inforegulator.org.za.

9. Cookies & Local Storage

In the application (app.praxilog.co.za), PraxiLog does not use advertising or tracking cookies. Your browser's session storage holds your practice's encryption key only for the duration of your session, cleared on sign-out or when the tab closes. Your browser's local database (IndexedDB) holds a cached copy of your practice's data so an active session keeps working through brief connectivity drops.

On this website (praxilog.co.za), we use Google Analytics to understand traffic and improve the site — this sets a small number of analytics cookies and processes your IP address. Google Signals and ad personalization are switched off, so this data is not used to build advertising profiles. No patient or practice data is ever processed on this website.

10. Changes to This Policy

We may update this Privacy Policy as PraxiLog evolves. Material changes will be communicated to Practices before they take effect.

11. Information Officer & Contact

Kagiso Ditabo, Managing Director, is PraxiLog's Information Officer under POPIA section 55, registered with the Information Regulator.

Questions about this Privacy Policy, or requests relating to your personal information, can be sent to popia@praxilog.co.za. Our PAIA Manual sets out the categories of records we hold and how to request access to them.