POPIA Operator Schedule (South Africa)
The s 21 operator contract for South African practices, relay tiers and Cloud.
POPIA Operator Schedule — South Africa
(Protection of Personal Information Act 4 of 2013 — for the relay tiers and the Cloud edition)
POPIA's terminology differs from the GDPR's: the practice is the responsible party, SideClick the operator (POPIA s 1).
This schedule forms part of the Terms of Service between SideClick (Pty) Ltd ("Operator") and the subscribing practice ("Responsible Party"), and applies to South African Responsible Parties using the sync relay, patient portal, or Cloud edition. For the relay tiers it supplements the relay DPA, whose Annexes A–C are incorporated by reference; for the Cloud edition it supplements the applicable cloud instrument.
1. Roles (POPIA ss 19–21)
The Responsible Party determines the purpose and means of processing the personal information — including special personal information (health information, s 26) — of its patients and staff. The Operator processes personal information only for the Responsible Party and with its authorisation (s 20), namely: storing and routing end-to-end-encrypted content and the service metadata inventoried in the relay DPA Annex A (or the cloud instrument's annex). The Operator holds no decryption keys for clinical content and cannot read it.
This schedule is the written contract s 21(1) requires, obliging the Operator to establish and maintain the security measures of s 19.
2. Confidentiality (s 20)
The Operator, and every person processing personal information on its behalf, treats all personal information processed under this schedule as confidential, and does not disclose it unless required by law or in the proper performance of the services.
3. Security measures (s 19)
The Operator implements the technical and organisational measures of the relay DPA Annex B (zero-knowledge end-to-end encryption, encryption at rest and in transit, minimisation enforced by automated tests, hashed connection records, invitation tokens stored only as hashes), maintains them against currently accepted security practices, and verifies and updates them regularly.
4. Sub-operators
The Operator engages sub-operators only under written terms no less protective than this schedule, per the sub-processor register and the notice and objection mechanics of the relay DPA §4.
5. Security-compromise notification (ss 21(2) and 22)
Where there are reasonable grounds to believe that personal information processed under this schedule has been accessed or acquired by an unauthorised person, the Operator notifies the Responsible Party immediately — the standard s 21(2) imposes on operators — with sufficient information for the Responsible Party to meet its own s 22 obligations to notify the Information Regulator and affected data subjects as soon as reasonably possible (the Responsible Party makes those notifications as responsible party; the Operator provides all reasonable assistance). The parties record that a compromise of relay or cloud storage alone exposes ciphertext and service metadata, not readable health information — relevant to the s 22(1) assessment, which is nonetheless made per incident.
6. Cross-border transfers (s 72)
Personal information processed under this schedule is hosted in the region stated in the sub-processor register. Where hosting is outside South Africa, the parties rely on s 72(1)(a): this schedule binds the Operator (and its sub-operators) to an effectively similar level of protection to POPIA's conditions for lawful processing. The Responsible Party authorises hosting in the stated region.
In addition, push notifications to the Responsible Party's enrolled iPhones are delivered via the Apple Push Notification service, which operates on Apple infrastructure in the United States. The transmitted payloads carry no personal information — a fixed alert text and opaque identifiers only (enforced by automated test); Apple observes the device's push token and delivery metadata.
7. Data-subject participation and portability
Requests under ss 23–25 (access, correction, deletion) are fulfilled by the Responsible Party, which alone holds readable records, using the software's built-in access, rectification and erasure tooling. The Operator: forwards any request it receives directly, without undue delay; maintains the portability floor (relay DPA §8 — download and acknowledgement are never refused, nothing is deleted on licence lapse); and deletes or returns stored information at the end of services per relay DPA §8.
8. Health-sector context
The Responsible Party remains responsible for compliance with the National Health Act 61 of 2003 (confidentiality of health records), HPCSA record-keeping guidance (including minimum retention periods), and any other professional obligations. The software's retention tooling supports, but does not replace, those duties: it computes when records become eligible for destruction under the retention period the Responsible Party configures, and destroys nothing without an explicit, confirmed action by an authorised person in the practice (EULA §7.7). The Operator's role never includes clinical judgement or access to clinical content.
9. General
For personal-information obligations this schedule prevails over the Terms of Service. It is governed by the law of the Republic of South Africa. The Information Regulator (South Africa) can be reached at enquiries@inforegulator.org.za (complaints: POPIAComplaints@inforegulator.org.za). The Operator's Information Officer: Franco De Beer, franco@sideclick.io.
Signatures
| Responsible Party | Operator | |
|---|---|---|
| Entity | ______________________ | SideClick (Pty) Ltd |
| Name, title | ______________________ | ______________________ |
| Date, signature | ______________________ | ______________________ |
Version 1.1 · Published 2026-09-12