Operator Agreement (Annexure A)
Last updated: 6 July 2026
OPERATOR AGREEMENT
(Data Processing Addendum in terms of the Protection of Personal Information Act 4 of 2013)
Annexure to the StazaCare Terms and Conditions
This Annexure forms an integral part of, and is incorporated by reference into, the Terms and Conditions entered into between Stazalog (Pty) Ltd, Registration No. 2018/235771/07, trading as StazaCare ("Operator", "StazaCare", "we"), and the dental practice or business that has accepted the Terms and Conditions ("Responsible Party", "Practice", "you"), governing the processing of personal information through the StazaCare practice management platform (the "Platform"). In the event of any conflict between this Annexure and the body of the Terms and Conditions regarding the processing of personal information, this Annexure prevails. Capitalised terms not defined in this Annexure bear the meaning given to them in the Terms and Conditions.
1. Purpose
1.1 In providing the Platform, StazaCare processes personal information — including special personal information relating to the health of the Practice's patients ("Patient Personal Information") — on behalf of, and only on the documented instructions of, the Practice.
1.2 For the purposes of the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Practice is the Responsible Party in respect of Patient Personal Information, and StazaCare is the Operator, as those terms are defined in section 1 of POPIA.
1.3 This Annexure records the Practice's instructions to StazaCare, the nature and purpose of processing, and the safeguards StazaCare undertakes to apply, as required by sections 20 and 21 of POPIA.
2. Definitions
-
"Personal Information", "Special Personal Information", "Processing", "Data Subject", "Responsible Party", "Operator", "Consent" and "Security Compromise" bear the meanings given to them in section 1 of POPIA.
-
"Patient Personal Information" means any Personal Information of a Patient of the Practice that is collected, stored, or otherwise Processed through the Platform, including without limitation the categories described in Schedule 1.
-
"Sub-Operator" means any third party engaged by StazaCare to Process Patient Personal Information on StazaCare's behalf in the course of providing the Platform.
-
"Instruction" means an instruction given by the Practice to StazaCare regarding the Processing of Patient Personal Information, including the instructions recorded in this Annexure and any further written instruction given by the Practice through the Platform's ordinary functionality (e.g. creating, editing, or deleting a Patient record) or in writing.
3. Processing Only on Instruction
3.1 StazaCare will Process Patient Personal Information only in accordance with the Practice's Instructions, including the instructions set out in this Annexure and Schedule 1, and only for the purpose of providing the Platform and the services described in the Terms and Conditions, unless Processing is required by applicable law, in which case StazaCare will, to the extent legally permitted, notify the Practice of that legal requirement before Processing.
3.2 StazaCare will not use, sell, rent, or otherwise deal in Patient Personal Information for its own purposes, and will not use Patient Personal Information to develop, train, or improve any product or service outside the scope of providing the Platform to the Practice, without the Practice's prior written consent.
3.3 If StazaCare considers that an Instruction from the Practice infringes POPIA or any other applicable law, StazaCare will promptly notify the Practice, and may suspend performance of that Instruction pending resolution.
4. Confidentiality
4.1 StazaCare will ensure that all its personnel, contractors, and Sub-Operators who have access to Patient Personal Information are subject to a binding duty of confidentiality in respect of that information, whether by contract or by statutory or professional obligation.
4.2 Access to Patient Personal Information within StazaCare's organisation is restricted to personnel who require such access to provide the Platform or associated support.
5. Security Measures
5.1 In accordance with section 19 of POPIA, StazaCare has implemented, and will maintain, appropriate technical and organisational measures to secure the integrity and confidentiality of Patient Personal Information against loss, damage, unauthorised destruction, and unlawful access or Processing, including:
-
encrypted, httpOnly session cookies and signed JWT-based session management with configurable expiry;
-
role-based access control enforced at the application middleware layer, restricting each user of the Platform to information relevant to their assigned role;
-
a default-deny database security model, under which no direct client-side write access to the database is permitted and all reads and writes are routed through authenticated, server-side application logic;
-
audit logging of key data-processing actions, including the acting user, action taken, and timestamp;
-
secret-protected scheduled processes (e.g. automated reminders, recalls, and subscription checks) that cannot be invoked by unauthenticated requests;
-
restriction of file storage access (e.g. X-rays, consent forms, lab images) to authenticated users of the relevant Practice;
-
hosting of the primary database and file storage within a South African data centre region.
5.2 StazaCare will periodically review its security measures to ensure they continue to provide a level of security appropriate to the risk presented by the Processing, having regard to the state of the art, the cost of implementation, and the nature of Patient Personal Information Processed.
6. Sub-Operators
6.1 The Practice provides StazaCare with general written authorisation to engage the Sub-Operators listed in Schedule 2 as at the date of this Annexure.
6.2 StazaCare may appoint additional or replacement Sub-Operators from time to time, provided that StazaCare:
-
imposes on each Sub-Operator, by written contract, data protection obligations no less protective than those set out in this Annexure;
-
remains fully liable to the Practice for the performance of each Sub-Operator's obligations relating to Patient Personal Information as if such Processing were carried out by StazaCare directly;
-
gives the Practice at least twenty (20) business days' prior written notice (which may be given by email or by notice posted within the Platform) before a new Sub-Operator begins Processing Patient Personal Information, identifying the Sub-Operator and the nature of the Processing involved.
6.3 If the Practice reasonably objects, on legitimate data protection grounds, to the appointment of a new Sub-Operator within the notice period referred to in clause 6.2, StazaCare and the Practice will engage in good faith to address the objection. If the objection cannot be resolved within a further fifteen (15) business days, either party may terminate the affected part of the Platform's functionality without penalty, without prejudice to the remainder of the Terms and Conditions.
7. Cross-Border Transfers
7.1 Patient Personal Information is primarily hosted within a South African data centre region. Where a Sub-Operator is located outside the Republic of South Africa (as at the date of this Annexure, this includes Sub-Operators providing SMS and email delivery services), StazaCare will only transfer Patient Personal Information to that Sub-Operator where the requirements of section 72 of POPIA are met, including where the Sub-Operator is subject to a law, binding corporate rules, or binding agreement affording an adequate level of protection substantially similar to POPIA's conditions for lawful Processing.
7.2 StazaCare will maintain a written agreement with each such Sub-Operator giving effect to the requirements of clause 7.1.
8. Security Compromises
8.1 StazaCare will notify the Practice without undue delay, and in any event within 72 hours of becoming aware, of any Security Compromise that has affected or may reasonably be expected to affect the confidentiality, integrity, or availability of Patient Personal Information.
8.2 The notification referred to in clause 8.1 will, to the extent reasonably known to StazaCare at the time, describe the nature of the Security Compromise, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the Security Compromise and mitigate its effects.
8.3 StazaCare will provide reasonable assistance to the Practice to enable the Practice to comply with its own notification obligations under section 22 of POPIA, including notification to the Information Regulator and affected Patients, provided that the decision on whether and how to notify affected Patients and the Information Regulator remains that of the Practice as Responsible Party.
8.4 StazaCare will take reasonable steps to identify the cause of any Security Compromise, to remediate the cause to the extent within its control, and to prevent a recurrence.
9. Assistance With Data Subject Requests
9.1 Taking into account the nature of the Processing, StazaCare will provide reasonable technical and organisational assistance to the Practice to enable the Practice to respond to requests from Patients (or their authorised representatives) to exercise their rights under Chapter 3 of POPIA, including requests for access, correction, or deletion of Patient Personal Information.
9.2 Where the Platform's ordinary functionality allows the Practice to directly access, correct, or delete Patient Personal Information, the Practice will use that functionality in the first instance. Where a request cannot be fulfilled through ordinary Platform functionality, StazaCare will provide reasonable assistance upon the Practice's written request, at no additional charge for reasonable, occasional requests.
10. Audits and Information
10.1 StazaCare will make available to the Practice, on reasonable written request and no more than once in any twelve (12) month period (unless a Security Compromise or reasonable suspicion of non-compliance justifies a further request), such information as is reasonably necessary to demonstrate StazaCare's compliance with its obligations under this Annexure.
10.2 Where the Practice reasonably requires a physical or technical audit or inspection (as opposed to a written information request), the parties will agree the reasonable scope, timing, cost allocation, and confidentiality terms of that audit in advance, and StazaCare may, at its option, satisfy this obligation by providing a current third-party audit report or certification relevant to the Sub-Operator or system concerned (for example, a Google Cloud/Firebase security or compliance report), where such a report reasonably addresses the Practice's request.
11. Return or Deletion of Patient Personal Information
11.1 Subject to clause 11.2, on termination or expiry of the Terms and Conditions, StazaCare will, at the Practice's written election, either export and make available to the Practice a copy of the Patient Personal Information held on the Platform in a commonly used electronic format, or delete such Patient Personal Information, within thirty (30) days of the Practice's election.
11.2 StazaCare may retain Patient Personal Information, or copies thereof, after termination to the extent and for the period required to comply with the retention obligations described in the Privacy Policy (including the five (5) year compliance retention period), applicable law, or to establish, exercise, or defend legal claims, and will apply the security measures described in clause 5 to any information so retained.
12. Liability
12.1 Each party's liability arising out of or in connection with this Annexure is subject to the limitations and exclusions of liability set out in the Terms and Conditions.
12.2 Nothing in this Annexure limits either party's liability for its own non-compliance with POPIA to the extent such liability cannot lawfully be limited or excluded.
13. Relationship to the Terms and Conditions and Term
13.1 This Annexure takes effect on the date the Practice accepts the Terms and Conditions and continues for as long as the Terms and Conditions remain in force, and thereafter for so long as StazaCare Processes any Patient Personal Information in accordance with clause 11.2.
13.2 This Annexure is governed by the laws of the Republic of South Africa, and the parties submit to the jurisdiction provisions recorded in the Terms and Conditions.
Schedule 1 — Description of Processing
| Subject matter of Processing | Provision of a cloud-based dental practice management platform, including patient records, appointment scheduling, clinical documentation, billing, laboratory work tracking, and patient communications. |
| Duration of Processing | For the duration of the Terms and Conditions, and thereafter as described in clause 11 of this Annexure. |
| Nature and purpose of Processing | Collection, storage, organisation, structuring, retrieval, use, transmission, and deletion of Patient Personal Information for the purposes described in clause 5 of the Privacy Policy (account administration, scheduling, clinical treatment recording, billing, laboratory tracking, reminders and recalls, and related support). |
| Categories of Data Subjects | Patients of the Practice, and where applicable, their parents or legal guardians. |
| Categories of Personal Information | Identifying details (name, date of birth, gender, contact details, address, insurance details); appointment and scheduling data; clinical records (chief complaint, clinical notes, treatment history, dental chart data, treatment codes); clinical documents (X-rays, lab images, consent forms, prescriptions, sick notes); billing and invoicing records; laboratory work requests; marketing consent status and communication history. |
| Special Personal Information | Health information as defined in section 26 of POPIA, comprising the clinical records and clinical documents described above. |
Schedule 2 — Approved Sub-Operators
As at the date of this Annexure, the Practice authorises StazaCare to engage the following Sub-Operators, subject to clause 6:
| Sub-Operator | Role | Location |
| Google Firebase (Google LLC / Google Cloud) | Authentication, database (Firestore), file storage, and cloud functions underlying the Platform | South Africa (primary region) |
| PayFast (Pty) Ltd | Subscription billing and payment processing | South Africa |
| Africa's Talking | SMS delivery for appointment reminders, recalls, and campaigns | Africa's Talking group (regional, including operations outside South Africa) |
| Resend | Transactional and campaign email delivery | United States |