Appointify PAIA manual.
A public manual for requesting access to Appointify records under PAIA, with POPIA context for personal information handled by the platform.
Purpose of this manual
This manual is prepared for Appointify in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), read with the Protection of Personal Information Act 4 of 2013 (POPIA).
It explains what records Appointify holds, how a person may request access to those records, and how Appointify processes personal information in the ordinary course of providing its practice administration platform.
Appointify details
Business name: Appointify.
Website: www.appointify.co.za.
Information Officer: The head of Appointify or the person authorised to manage PAIA and POPIA requests for Appointify.
PAIA and privacy requests: send the request to your Appointify account contact or to documents@appointify.co.za. If a signed agreement gives a different legal or privacy contact, use that contact.
Information Regulator guide
The Information Regulator publishes a PAIA guide that explains how to use PAIA, how to make access requests, and how to lodge complaints.
The guide, PAIA forms, fee information, and complaint forms are available from the Information Regulator at inforegulator.org.za/paia. The Regulator can be contacted at enquiries@inforegulator.org.za, 010 023 5200, or 0800 017 160.
Records held by Appointify
Company and administration records, including contracts, supplier records, invoices, billing records, correspondence, insurance records, policies, governance records, and operational records.
Platform and customer records, including practice account details, user account records, support requests, configuration records, audit logs, booking records, communication records, document workflow records, billing workflow records, and system metadata.
Technical and security records, including hosting records, access logs, incident records, backups, monitoring records, service-provider records, and records required to operate, secure, maintain, and improve the platform.
Human resources and contractor records, where applicable, including recruitment, employment, contractor, payroll, tax, leave, performance, and access-control records.
Personal information processed
Appointify may process names, identity or registration details, contact details, account credentials, role and access details, payment and billing details, device and usage information, communication content, support content, and related metadata.
Where Appointify processes information on behalf of a healthcare practice, the platform may also hold patient appointment, clinical workflow, document, billing, medical aid, telehealth, communication, and health-related information entered or authorised by that practice.
Appointify usually processes patient personal information as an operator for the relevant practice. The practice remains the responsible party unless a written agreement says otherwise.
Purpose of processing
Appointify processes information to provide, operate, secure, support, bill, maintain, and improve the Appointify platform and related services.
Information may also be processed to manage customer relationships, authenticate users, route communications, support bookings and documents, assist with billing workflows, comply with legal duties, detect misuse, respond to incidents, and protect Appointify, practices, patients, and service providers.
Sharing and cross-border processing
Appointify may share limited information with service providers that help provide hosting, storage, authentication, messaging, email, video links, payments, analytics, support, security, and AI-assisted functionality.
Some service providers may process or store information outside South Africa. Where this happens, Appointify takes reasonable steps to use appropriate contractual, technical, and organisational safeguards.
Appointify may also disclose information where required by law, court order, regulator request, a lawful instruction from the relevant practice, or where necessary to protect rights, safety, security, or platform integrity.
How to request access
A requester must submit the prescribed PAIA Form 2 and provide enough detail to identify the requested record. A private-body requester must identify the right they want to exercise or protect and explain why the record is required for that right.
Requests should be sent to the Information Officer contact listed in this manual. Appointify may ask for proof of identity, authority to act for another person, clarification of the request, and payment of prescribed fees where applicable.
Appointify will respond within the periods required by PAIA. Access may be granted, partly granted, or refused on the grounds allowed by PAIA, including where records contain confidential, privileged, commercial, security, or third-party personal information.
Automatic access and fees
Public information on the Appointify website is available without a PAIA request.
Other records are not automatically available unless Appointify has published them, provided them through the platform, or agreed to provide them under a contract.
PAIA request, access, search, reproduction, and preparation fees may apply where allowed by law. Appointify will advise the requester if a fee is payable before access is provided.
Remedies and complaints
If a request is refused, partly refused, or not answered in time, the requester may use the remedies available under PAIA, including lodging a complaint with the Information Regulator or applying to a competent court where applicable.
Complaints to the Information Regulator are usually made on the prescribed Form 5 and must be submitted within the time periods set by PAIA and the PAIA regulations.
Availability and updates
This manual is available on the Appointify website and may be updated when Appointify changes its services, records, contact details, legal duties, or processing activities.
Last updated: 30 May 2026.
