Privacy Policy
Last updated: 6 July 2026
StazaCare Practice Management Platform
Operated by Stazalog (Pty) Ltd, Registration No. 2018/235771/07
This Privacy Policy is issued in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA") and applies to Stazalog (Pty) Ltd, trading as "StazaCare" ("StazaCare", "we", "us", "our"). It explains how we collect, use, store, share, and protect personal information (including special personal information) in connection with the StazaCare practice management platform (the "Platform").
Please read this Policy carefully. If you are a patient, some of the rights and obligations described below are exercised through the dental practice that treats you, because — as explained in Section 3 — the practice, not StazaCare, is legally responsible for your personal information as the "Responsible Party" under POPIA.
1. Who We Are
StazaCare is a multi-tenant practice management system for dental practices, provided by:
| Legal entity | Stazalog (Pty) Ltd |
| Registration number | 2018/235771/07 |
| Trading as | StazaCare |
| Contact number | 082 304 4740 |
| stazalog@gmail.com |
2. Scope of This Policy
This Policy applies to personal information processed through the Platform, including information relating to:
-
Dental practices and businesses that subscribe to StazaCare ("Practices", "Businesses");
-
Users of the Platform employed or engaged by a Practice (owners, administrators, doctors, receptionists, lab technicians) ("Users");
-
Patients of a Practice whose records are processed on the Platform on the Practice's instruction ("Patients").
Where this Policy refers to "you", it refers to whichever of the above categories is relevant to the section being read.
3. Your Relationship With StazaCare: Responsible Party vs Operator
This section is important and governs how the rest of this Policy operates.
Under POPIA:
-
The Practice (the dental business using StazaCare) is the "Responsible Party" in relation to its Patients' personal information. The Practice decides why and how Patient information is collected and used, and is legally accountable for that processing, including obtaining Patient consent, honouring Patient rights requests, and complying with the Health Professions Council of South Africa's record-keeping obligations.
-
StazaCare is an "Operator" in relation to Patient information. We process Patient information only on the Practice's instruction, as set out in the Operator Agreement between StazaCare and the Practice, and we do not use Patient information for our own independent purposes.
-
In relation to Practice and User account information (billing details, login credentials, subscription usage), StazaCare is itself the Responsible Party, because we determine why and how that information is processed (for example, to operate subscriptions and provide support).
If you are a Patient and wish to exercise a right described in Section 10 (access, correction, deletion, objection), you should approach your Practice in the first instance, as it is your Practice's responsibility to action your request. StazaCare will assist the Practice in fulfilling that request as required under our Operator Agreement.
4. Information We Collect
4.1 Practice and Business Information
-
Business name, registration details, address, contact details, logo and branding;
-
Subscription plan, billing cycle, payment status, and usage data (e.g. SMS credits, storage used);
-
Payment information processed via PayFast (StazaCare does not store card or bank account numbers).
4.2 User (Staff) Information
-
Name, email address, phone number, role (e.g. Owner, Admin, Doctor, Receptionist, Lab), and professional specialisation;
-
Login credentials and session activity, for security and audit purposes.
4.3 Patient Information (Special Personal Information)
Where a Practice uses the Platform to manage its patients, the following categories of information may be processed. Much of this constitutes "special personal information" concerning health, as defined in section 26 of POPIA, and is processed subject to the safeguards in Section 5.2 below:
-
Identifying details: name, date of birth, gender, patient code, contact details, address, insurance provider and number;
-
Appointment and scheduling information;
-
Clinical records: chief complaint, clinical notes, treatment history, dental chart data (diagnoses, existing restorations, treatment plans per tooth), ADA treatment codes;
-
Clinical documents: X-rays, lab images, consent forms, prescriptions, sick notes, and other attachments;
-
Billing and invoicing records connected to treatment;
-
Lab work requests connected to a Patient's treatment;
-
Marketing consent status and communication history (appointment reminders, recall messages, campaign messages).
5. Why and On What Legal Basis We Process Your Information
5.1 Purposes
Personal information is processed for the following purposes:
-
Creating and administering Practice, User, and Patient accounts and records;
-
Scheduling and managing appointments;
-
Recording and delivering clinical treatment, including dental charting, prescriptions, and sick notes;
-
Generating invoices and processing billing and subscription payments;
-
Managing dental laboratory work requests;
-
Sending appointment reminders, recall communications, and (where consented to) marketing campaigns by SMS and email;
-
Maintaining audit logs and security records to detect and investigate misuse;
-
Complying with legal, regulatory, and professional record-keeping obligations applicable to dental practices;
-
Improving and supporting the Platform, including responding to support requests.
5.2 Legal Basis, Including for Special Personal Information
Ordinary personal information is processed on one or more of the grounds permitted by section 11 of POPIA, including that processing is necessary to perform the service contract between the Practice and StazaCare, is necessary for the Practice's legitimate business purposes, or is carried out with consent (for example, marketing communications).
Special personal information concerning health is processed in reliance on section 32(1)(a) of POPIA, which permits processing by, or with the consent of, a health institution or health professional acting in accordance with the ethical rules of their profession, or as necessary for proper treatment and care of the Patient. The Practice and its doctors are responsible for ensuring this ground is properly relied upon in respect of their Patients; StazaCare processes such information only as an Operator acting on the Practice's documented instructions.
6. How We Share Information
We do not sell personal information. We share personal information only as follows:
6.1 Within a Practice
Information is visible to authorised Users at the relevant Practice according to their role (for example, a Receptionist cannot access clinical notes reserved for doctors, and Lab users see only lab-work-related information).
6.2 Sub-Operators (Third-Party Service Providers)
We use the following categories of third-party service providers to operate the Platform. Each acts on our instructions under a written agreement that requires them to protect personal information in accordance with POPIA:
| Service Provider | Purpose | Data Involved | Location |
| Google Firebase | Authentication, database (Firestore), file storage, cloud functions | All account, Practice, User, and Patient data processed on the Platform | South Africa (primary hosting region) |
| PayFast (Pty) Ltd | Subscription billing and payment processing | Billing contact details and payment status (not card/bank numbers, which PayFast collects directly) | South Africa |
| Africa's Talking | SMS delivery for reminders, recalls, and campaigns | Patient/recipient phone number and message content | Regional (Africa's Talking group, including operations outside South Africa) |
| Resend | Transactional and campaign email delivery | Recipient email address and message content | United States |
6.3 Cross-Border Transfers
Our primary database and file storage (Firebase) are hosted in a South African region. However, SMS delivery (Africa's Talking) and email delivery (Resend) may involve the transfer of personal information to service providers located outside South Africa. In accordance with section 72 of POPIA, we only transfer personal information across South Africa's borders where the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or where you have consented to the transfer, or where the transfer is necessary to perform a contract with you or in your interest (for example, sending you an appointment reminder). We contractually require our sub-operators to protect personal information to a standard consistent with POPIA.
6.4 Other Disclosures
-
To comply with a legal obligation, court order, or lawful request from a regulator or law enforcement body;
-
To a professional body (e.g. HPCSA) where the Practice is required to produce records;
-
In connection with a merger, acquisition, or sale of business assets, subject to equivalent protections being maintained.
7. Marketing Communications
Where a Patient has provided marketing consent (recorded against their Patient record), a Practice may use the Platform to send SMS or email campaigns, including recall messages to Patients who have not been seen in six months or more. Marketing communications are not sent to Patients who have not given, or who have withdrawn, marketing consent.
You may withdraw marketing consent at any time by contacting your Practice directly, by using any unsubscribe/opt-out mechanism included in a message, or in the case of SMS, by replying "STOP". Withdrawal of marketing consent does not affect appointment reminders or other communications necessary for your treatment, which are sent on a different legal basis.
8. Cookies and Similar Technologies
Our marketing website and Platform may use cookies and similar technologies for functionality, security (e.g. session management), and analytics purposes. Details are set out in our separate Cookie Policy, available on our website.
9. Data Retention
We retain personal information for as long as is necessary to fulfil the purposes described in this Policy, and in particular:
-
Patient records are retained on the Platform for as long as the Patient's consent to be recorded on the Practice's records subsists, or until the Patient requests deletion, whichever is applicable and subject to the exception below;
-
Notwithstanding a deletion request or withdrawal of consent, we and the Practice will retain personal information for a period of five (5) years from the date of the last interaction, record creation, or account closure (as applicable), where retention is required to comply with POPIA's retention and re-use limitation principle (section 14), applicable healthcare record-keeping obligations, tax and financial record-keeping laws, or to establish, exercise, or defend legal claims;
-
After the applicable retention period expires, personal information is securely deleted or de-identified such that it can no longer be used to identify a data subject.
Where you ask a Practice to delete your Patient record before the five (5) year compliance period has elapsed, the Practice (as Responsible Party) will assess that request against its own legal and professional record-keeping obligations and respond to you accordingly; StazaCare will action any deletion instruction it receives from the Practice.
10. Your Rights
Subject to Section 3 above (which explains that Patients generally exercise these rights through their Practice), and subject to any applicable exemptions under POPIA, you have the right to:
-
Be informed that your personal information is being collected and processed, and for what purpose;
-
Access the personal information held about you;
-
Request correction or updating of inaccurate, outdated, incomplete, or misleading personal information;
-
Request deletion or destruction of personal information that we are no longer authorised to retain, subject to Section 9;
-
Object, on reasonable grounds, to the processing of your personal information;
-
Object to processing for purposes of direct marketing;
-
Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
-
Lodge a complaint with the Information Regulator (contact details in Section 14) if you believe your rights have been infringed.
Requests relating to Patient information should be directed to your Practice in the first instance. Requests relating to Practice or User account information held directly by StazaCare should be directed to our Information Officer using the contact details in Section 13.
11. Security Measures
We implement appropriate technical and organisational measures to secure personal information against loss, unauthorised access, interference, and disclosure, as required by section 19 of POPIA, including:
-
Encrypted session cookies (httpOnly) and JWT-based session management with configurable expiry;
-
Role-based access control enforced at the application middleware layer, restricting each User to information relevant to their role;
-
A default-deny database security model: all direct write access is blocked, with all reads and writes routed through authenticated, server-side application logic;
-
Audit logging of key actions (e.g. record creation, updates) including user, action, and timestamp;
-
Secret-protected automated processes (e.g. scheduled reminder and billing checks) that cannot be triggered by unauthenticated requests;
-
Restriction of file storage access to authenticated Users of the relevant Practice.
No system can guarantee absolute security. If we become aware of a security compromise that has affected, or is reasonably likely to have affected, your personal information, we will notify the Information Regulator and affected data subjects (via their Practice, where applicable) as required by section 22 of POPIA, as soon as reasonably possible after discovery.
12. Children's Information
Where a Practice treats a Patient who is a minor, the Practice is responsible for obtaining consent from the minor's parent or legal guardian, or otherwise ensuring processing is permitted under section 35 of POPIA, before that Patient's information is recorded on the Platform. StazaCare processes such information only as an Operator on the Practice's instruction.
13. Information Officer
Our Information Officer is responsible for ensuring compliance with POPIA and for handling requests and complaints relating to personal information processed directly by StazaCare (as opposed to Patient information, which should first be directed to your Practice).
| Information Officer | [Name to be inserted — to be registered with the Information Regulator] |
| Postal/contact address | [To be confirmed] |
| Telephone | 082 304 4740 |
| stazalog@gmail.com |
Note: Stazalog (Pty) Ltd must register its Information Officer with the Information Regulator before this Policy is published, and this section must be updated with the registered Information Officer's confirmed details.
14. Complaints to the Information Regulator
If you are not satisfied with how we or a Practice have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa):
-
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
-
Email: complaints.IR@justice.gov.za
-
Website: www.justice.gov.za/inforeg
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on our website and update the "Last updated" date above. Material changes affecting Patient information will be communicated to Practices for onward notice to Patients where appropriate.
16. Contact Us
For any questions about this Policy or how your personal information is handled, please contact:
| Company | Stazalog (Pty) Ltd (trading as StazaCare) |
| Telephone | 082 304 4740 |
| stazalog@gmail.com |