Trust & security
Practi-Cal holds health records, which South African law treats as special personal information. This page sets out plainly what we do about that. It is written for the practice owner who has to answer for it, and for the patient who never chose us.
Who is responsible for what
Under POPIA the practice is the Responsible Party — it decides why and how patient information is processed, and it remains accountable for it. Practi-Cal is the Operator: we process that information on the practice's instruction and for no other purpose. Section 21 of POPIA requires a written agreement between the two, and every practice can read, accept and download theirs inside the app under Practice → Compliance.
We do not sell patient data. We do not use it to train anything. We do not share it with anyone except the sub-processors listed below, each of which handles only what its function needs.
Where the data lives
Patient records are hosted in South Africa, on a dedicated server run by HostAfrica. Media files and backups are stored on Cloudflare R2 in the European Union, which has data-protection law substantially similar to POPIA — the basis for cross-border transfer under section 72.
What protects it
- Encryption in transit on every connection, with certificates renewed automatically.
- Encryption at rest for the identifiers that matter most — South African ID numbers, passport numbers and medical aid membership numbers are encrypted in the database and shown masked to the last four digits. Revealing one is itself recorded in the audit log.
- Role-based access. Reception cannot open clinical notes. A therapist sees the full record only for their own patients, unless the practice owner explicitly turns on shared visibility — a decision that is itself logged.
- An audit log of every clinical access — every view, edit, export and reveal, with who and when. The practice can export the whole log at any time.
- Tenant isolation enforced centrally, not left to each query: a request for a record belonging to another practice is refused before the code that would serve it ever runs.
- Two-factor sign-in, available to any practice, remembered per device so it does not become the thing staff switch off.
- Rate limiting and a content security policy on every request.
- Passwords stored with PBKDF2 at 200,000 rounds. Nobody at Practi-Cal can read one.
Backups, and getting your data back
The database is replicated continuously off-site, so the worst-case data-loss window is seconds rather than a day. A full backup is taken nightly, kept for fourteen days, and copied off the server. Restores are rehearsed rather than assumed.
Every practice can export everything it holds, at any time, without asking us and without a support ticket — patients, bookings, invoices with their line detail, clinical notes, outcome measures, consent records and the audit log, as ordinary CSV files. Making it easy to leave is part of what makes it safe to arrive.
If something goes wrong
If we have reasonable grounds to believe patient information has been accessed by anyone unauthorised, we notify the affected practice immediately — our obligation under section 21(2), and in every operator agreement we sign. The practice, as Responsible Party, then notifies the Information Regulator and the affected people under section 22. Practi-Cal supplies the detail needed to do that, and the app carries a breach register so the incident, the response and the notifications are recorded in one place.
We also run an external uptime monitor with more than one alerting channel, on the reasoning that the channel most likely to be broken during an incident is the one you were relying on.
Record retention
Practi-Cal never deletes a patient record on its own. The HPCSA's rules are not a single number — a record for a patient who was a minor runs until their twenty-first birthday, and for a patient who is mentally incompetent it runs for their lifetime. The app works out each patient's date and presents a review list; disposal is the practice's decision and the practice's action.
Who else processes data
- HostAfrica — hosting, South Africa.
- Cloudflare — media and backup storage (European Union), and the public website.
- Twilio — WhatsApp and SMS delivery.
- Twilio SendGrid — email delivery.
- PayFast — payment processing. Card details are entered on PayFast's own hosted page and never reach us.
A practice is told before a new sub-processor handling patient information is added.
What we are not claiming
We would rather be believed than impressive. Practi-Cal is not ISO 27001 certified and has not had an independent penetration test. It is built and run by a small South African company, with the controls described above and an automated security regression suite that runs on every deploy. If either of those facts changes, this page changes with it.
Reporting a vulnerability
If you believe you have found a security problem, please email info@practi-cal.co.za with enough detail to reproduce it. We will acknowledge you, we will not take legal action against anyone reporting in good faith, and we will tell you when it is fixed.
Practical Software (Pty) Ltd · Registration number 2026/549124/07 · info@practi-cal.co.za · practi-cal.co.za