How PractoSync handles personal information, including the patient information we process on behalf of the practices that use our software.
Last updated: 13 September 2026
PractoSync is provided by Cilliers Koch Investments (Pty) Ltd (“PractoSync”, “we”, “us” or “our”). PractoSync provides practice management software to healthcare practices in South Africa, covering appointments, patient administration, clinical records, digital intake, billing, claims, payments and related services.
Business address: 35 Coral Rd, Blue Lagoon 2, Langebaan, 7357, South Africa
This policy explains what personal information PractoSync processes, why we process it, how we protect it, who may receive it and the rights available to people under the Protection of Personal Information Act, 2013 (“POPIA”).
It matters which of our products you are using, because they hold very different information.
practosync.com is our public marketing and information website. It exists to explain what PractoSync does. It holds no patient records, no clinical information and no practice data. The only personal information it involves is the technical and analytics information described below, and whatever you choose to send us through an enquiry or demo request form.
practoplatform.com is the PractoSync application itself. This is where practices work, and where patient, clinical, billing and claims information is created and stored. Patient-facing features such as online booking and digital intake forms also run here, not on the marketing website.
The PractoSync mobile app (iOS and Android) is part of that same application, used by practitioners rather than by patients. There is no public sign-up: practitioners sign in with the account their practice has given them, and see only their own appointments. The app’s purpose is to record a consultation — and it will not begin recording until the practitioner confirms that the patient has consented. The recording is sent over an encrypted connection to practoplatform.com, where it is transcribed into a clinical note, and it is deleted from the phone as soon as the upload is confirmed. If an upload cannot complete, the recording stays in the app’s private storage on that device, together with the appointment it belongs to, until it is either uploaded or deleted by the practitioner. No other patient records are held on the phone.
Everything in this policy about patient and practice information relates to the PractoSync application — both at practoplatform.com and in the mobile app.
Where a practice enables WhatsApp messaging, messages are exchanged between the practice and the patient through the patient’s own WhatsApp account and Meta’s WhatsApp Business Platform. The conversation is stored in the PractoSync application as part of the practice’s records, but delivering each message involves Meta as well as PractoSync. This is described under WhatsApp messaging below.
The role PractoSync plays depends on whose information we are processing.
For patient and practice records, PractoSync generally acts as an operator. The healthcare practice using PractoSync is the responsible party. The practice decides what patient information is collected, why it is collected, who may access it and how long it must be retained.
PractoSync processes that information on behalf of the practice to provide, secure, maintain and support the PractoSync service and to carry out functions the practice has chosen to use.
We do not sell patient information and we do not use patient information for advertising.
POPIA requires an operator to process personal information with the knowledge or authorisation of the responsible party and to treat that information as confidential. It also requires appropriate security arrangements between responsible parties and their operators.
For information about PractoSync’s own customers, account users, prospective customers and website visitors, PractoSync acts as the responsible party.
This Privacy Policy does not replace the privacy notice that a healthcare practice must provide to its own patients.
Where you are a patient of a practice using PractoSync, the practice remains responsible for explaining how and why it collects and uses your information and for responding to requests relating to your clinical or patient record.
PractoSync will assist practices with those responsibilities where appropriate.
When you use our marketing website, we may receive technical information such as your IP address, browser and device information, pages viewed, referring pages, dates and times of visits, and cookie and analytics information.
If you submit a contact form, demo request or other enquiry, we receive the information you provide. This will typically include your name, practice or organisation name, email address, telephone number and the contents of your enquiry. No patient or clinical information is collected through this website.
For practitioners and practice staff who have a PractoSync account, we may process information including name, email address and contact information, practice association, role and system permissions, account and authentication information, and records of activity within PractoSync.
Because PractoSync is used for clinical and financial administration, certain actions are recorded so that practices can identify who performed an action and when it occurred.
Where a practitioner uses the PractoSync mobile app, the app holds their signed-in session in the device’s own secure storage. While a recording is waiting to be uploaded, the app also holds that recording and the appointment it relates to on the device. No other patient or practice records are stored on the device.
Where a healthcare practice uses PractoSync, we process information entered into or created through the system on that practice’s behalf. Depending on the features used by the practice, this may include:
The exact information collected is determined by the healthcare practice.
Health information is special personal information under POPIA and is subject to additional protection. POPIA specifically recognises processing of health information by healthcare professionals and healthcare institutions where necessary for treatment, care or administration of a professional practice, subject to confidentiality requirements.
Within PractoSync, access is controlled according to the role and permissions assigned to each user. Access restrictions are enforced by the application and server, not merely by hiding information in the user interface.
Clinical history and clinical records intended for practitioners are restricted accordingly, allowing administrative staff to perform tasks such as bookings, patient administration and billing without automatically receiving access to clinical information.
Where WhatsApp messaging is enabled, access to patient conversations is restricted to the roles the practice has authorised, on the same basis as other restricted information.
PractoSync provides optional AI-assisted functionality to help healthcare practitioners with clinical documentation and understanding a patient’s previous treatment history. These tools assist practitioners; they do not replace professional judgement.
SyncTo can record a consultation, transcribe the conversation and prepare a draft clinical note or populate a practice’s clinical template. A consultation can be recorded in the PractoSync application or in the PractoSync mobile app.
Recording cannot begin until the practitioner confirms that the patient has consented to the recording. PractoSync records that consent separately with the user who obtained it and a server-generated timestamp.
The audio is used for the transcription process and is not retained by PractoSync once that process has been completed. Transcript content is deliberately excluded from general application logs.
A recording made in the mobile app is held in the app’s private storage on that device only until its upload is confirmed, and is then deleted from the device. If an upload cannot be completed, the recording stays on the device until the practitioner uploads it or deletes it.
The practitioner is shown the AI-generated content before it becomes part of the clinical record and remains responsible for reviewing, correcting and approving what is saved.
Patient History may process a patient’s existing clinical session notes to create practitioner-facing information such as a treatment timeline, summary, treatment themes, suggested questions and other clinical context. Access to this functionality is restricted to authorised practitioners.
Providing AI-assisted features may require relevant clinical information, audio or text to be temporarily processed by contracted technology providers. Depending on the feature and configuration in use, these providers may include Microsoft Azure and other contracted AI processing providers used by PractoSync.
Where a provider processes information outside South Africa, the cross-border safeguards described later in this policy apply.
AI-generated information is assistive. PractoSync does not use these AI features to independently diagnose patients, determine treatment or make final clinical decisions about a patient.
A healthcare practice may choose to enable WhatsApp messaging. Where it does, the practice connects its own WhatsApp Business Account and its own telephone number to PractoSync. PractoSync does not operate a shared WhatsApp number, and one practice’s messages, message volume and account standing are separate from every other practice’s.
What is processed. Where a practice uses this feature, we process the patient’s mobile number in the form WhatsApp uses to identify an account, the name shown on the patient’s WhatsApp profile, the content of messages sent and received, the date and time of each message, delivery and read status, and any images, voice notes, video or documents the patient sends to the practice.
Messages patients send become part of the practice’s records. A reply to the practice is stored in PractoSync alongside the patient’s other records and is visible to the users the practice has authorised to see patient conversations. It is not a private exchange with one member of staff.
Attachments are copied into PractoSync’s own storage. Files a patient sends are retrieved and stored in the Microsoft Azure storage described under Where information is stored, so that the practice controls how long they are kept rather than that depending on Meta’s systems.
Consent is required before a practice messages a patient. PractoSync will not send an appointment reminder or any other outbound WhatsApp message unless the patient’s consent has been recorded. Consent may be recorded in four ways: by the practice on the patient’s record; by the patient on a digital intake or online booking form; by the patient at a self check-in kiosk; or by the patient sending the practice a WhatsApp message, which is plainly contact the patient has chosen to start. Whichever route is used, the record includes when the consent was captured, how it was captured and — where a member of staff captured it — who. Where no consent has been recorded, automated reminders are skipped rather than sent.
Patients can opt out at any time. Replying STOP, UNSUBSCRIBE or OPT OUT, or the equivalent in Afrikaans, withdraws consent. The withdrawal is recorded on the patient’s record and blocks both automated and staff-initiated WhatsApp messages. A patient may also ask the practice directly.
A withdrawal is never reversed automatically. Once a patient has opted out, WhatsApp messaging can only be switched back on by the practice recording that the patient has asked for it, on the patient’s record. Completing another intake form, checking in at a kiosk or sending a further message will not turn it back on by itself.
Automated reminders carry no clinical information. Appointment reminder messages are limited to the patient’s first name, the appointment date and time, the practice name and the practice location. They do not include the reason for the visit, the practitioner’s discipline, a diagnosis or any billing or clinical code.
Meta’s role. Messages are delivered through the WhatsApp Business Platform operated by Meta. Because the practice’s WhatsApp number is connected to that platform through PractoSync rather than run on a physical phone, message content is processed by Meta in order to deliver it and is accessible to the practice within PractoSync. Meta processes this information outside South Africa, and the cross-border safeguards described under Information processed outside South Africa apply. A patient’s own use of WhatsApp is additionally governed by WhatsApp’s own terms and privacy policy.
WhatsApp is not for urgent or emergency matters. Messages are not monitored continuously and a practice may not see a message immediately. Patients should not use WhatsApp to report an emergency or a clinically urgent change.
History is retained. If a practice disconnects WhatsApp, the conversation history already stored remains part of the practice’s records in PractoSync and is retained as described under How long we keep information. No further messages are sent or received.
We process personal information where necessary to:
We only process information for purposes permitted by POPIA and compatible with the purpose for which the information was collected. POPIA requires personal information to be collected for a specific, explicitly defined and lawful purpose.
Some information is necessary for PractoSync to provide a service. For example, a practitioner or staff member cannot have a PractoSync account without the information needed to identify and authenticate that user.
Fields marked as required on our website are necessary for us to process the relevant enquiry or request.
For patient information, the healthcare practice determines what information it requires from patients and is responsible for explaining whether providing that information is voluntary or mandatory and what the consequences of not providing it may be.
PractoSync uses separate systems for structured application data and files.
The main PractoSync application database is stored using MongoDB Atlas. This includes structured information used by the system, such as patient, account, appointment, clinical, billing, claim, payment, practice and audit information.
MongoDB Atlas includes security protections at the infrastructure level. Atlas encrypts cluster storage and snapshot volumes at rest using AES-256 encryption and requires TLS encryption for database connections. It also provides access-control and network-security capabilities which form part of the security measures surrounding the PractoSync database.
Uploaded files and files created or received during claim processing are stored separately using Microsoft Azure. These files are stored within South Africa across two Azure locations, providing geographic resilience while keeping this file storage within South Africa.
Microsoft Azure also provides infrastructure used to operate parts of the PractoSync service.
We use a limited number of third-party providers to operate PractoSync and to provide functions selected by healthcare practices. Depending on the feature being used, these may include:
A healthcare practice may also instruct PractoSync to transmit information to parties involved in providing care, billing or payment, including medical schemes, administrators, insurers and other healthcare-related organisations.
We require service providers that process personal information on our behalf to process it only for the services they are contracted to provide and to apply appropriate privacy and security safeguards.
We do not sell personal information.
Where a practice uses an integrated payment provider, relevant transaction information such as the amount, payment status and transaction reference may be exchanged between PractoSync and the payment provider so that the payment can be recorded and allocated correctly.
Payment-card information or online-banking credentials handled directly by the payment provider are not intended to be stored in the PractoSync patient database.
Most PractoSync patient and practice information is held in the systems described above, and uploaded files and processed claim files stored in Microsoft Azure are kept in South Africa.
However, some providers used to deliver particular services — including communication, messaging, security or AI services — may process information outside South Africa. Where a practice has enabled WhatsApp messaging, the content of messages exchanged with patients is processed by Meta outside South Africa.
Where personal information is transferred outside South Africa, PractoSync and the relevant practice apply the requirements of section 72 of POPIA. This includes using providers that are subject to laws, binding corporate rules or contractual protections that provide an adequate level of protection, or relying on another transfer mechanism permitted by POPIA.
We seek to limit the information transferred to what is reasonably necessary for the relevant service.
We use technical and organisational safeguards designed to protect personal information against loss, misuse, unauthorised access, unauthorised disclosure and unlawful processing. These measures include, where applicable:
MongoDB Atlas requires TLS for database connections and encrypts customer data at rest by default.
Security measures are reviewed and changed as our systems and the risks affecting them evolve. This reflects POPIA’s requirement for organisations to identify foreseeable risks, maintain appropriate safeguards and update those safeguards when new risks or deficiencies are identified.
No online service can guarantee absolute security, and we do not claim that it can.
Where PractoSync is acting as an operator for a healthcare practice and we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the affected practice in accordance with POPIA and assist the practice with its investigation and notification obligations.
Under POPIA, an operator must notify the responsible party of such an incident, while the responsible party carries the obligation to notify the Information Regulator and affected data subjects where required.
Where PractoSync itself is the responsible party for the affected information, we will make the notifications required of us under POPIA.
The healthcare practice determines the appropriate retention period for patient information held within PractoSync, subject to POPIA and the healthcare, professional, accounting and other legal obligations that apply to that practice.
Healthcare practices may be required to retain certain clinical records for substantial periods, and different requirements can apply depending on the profession, record type and circumstances of the patient, including where the patient is a child.
PractoSync therefore does not automatically delete an active practice’s patient records merely because a general retention period has elapsed.
POPIA provides that personal information should not be retained longer than necessary unless continued retention is authorised by law, reasonably required for a lawful purpose, required by contract or otherwise permitted under POPIA. Information that is no longer authorised to be retained must be deleted, destroyed or de-identified as soon as reasonably practicable.
WhatsApp conversation history and attachments form part of the patient record and are retained on the same basis, including after a practice disconnects its WhatsApp number.
When a practice ends its PractoSync subscription, arrangements for exporting and deleting the practice’s information are handled in accordance with our agreement with that practice.
Information may remain temporarily in protected backups or recovery systems after deletion from active systems and will be removed as those backups expire in accordance with our backup and retention processes.
Information relating to PractoSync accounts is retained while the account or related contractual relationship is active and thereafter for as long as reasonably necessary for security, support, accounting, legal or dispute-resolution purposes.
Website enquiries and prospective-customer information are retained for as long as reasonably necessary to deal with the enquiry and for an appropriate period afterwards.
POPIA gives data subjects rights relating to their personal information. Depending on the circumstances, these include the right to:
POPIA provides rights of access and correction, but it does not create an unrestricted right to erase records that a healthcare provider is legally or professionally required to retain.
If you are a patient of a healthcare practice that uses PractoSync, that practice is normally the responsible party for your patient and clinical records. Requests concerning those records should therefore be made to the healthcare practice. PractoSync will assist the practice where necessary to respond to a valid request.
Where your request concerns information for which PractoSync is the responsible party, you may contact us using the details at the end of this policy. We may need to verify your identity before providing access to or making changes to personal information.
Our general marketing website is not directed at children.
Healthcare practices using PractoSync may, however, provide healthcare services to children and therefore process information about children through the platform.
The healthcare practice is responsible for ensuring that it has the consent or other lawful authority required to process a child’s information and for obtaining consent from a competent person where applicable.
Where an intake form is completed on behalf of another person, PractoSync may record information indicating that the form was completed by a parent, guardian, account holder or other representative.
Our marketing website uses cookies and similar technologies required to operate the site and may use analytics technologies to understand how the website is used.
Third-party services used on the website, including security services such as Google reCAPTCHA, may also use browser technologies as part of providing their service.
You can control or delete cookies using your browser settings. Some parts of the website may not function correctly if necessary cookies are disabled.
The PractoSync application also uses browser storage or similar technologies where necessary to maintain a user’s session, support security and remember relevant preferences. The PractoSync mobile app does not use cookies; it keeps the equivalent information — the signed-in session and app preferences — in the device’s own storage.
We may update this Privacy Policy when our services, technology, service providers or legal obligations change.
The Last updated date at the top of the policy identifies the most recent revision.
Where a material change significantly affects how we process information on behalf of healthcare practices, we will communicate that change through an appropriate channel.
Questions about this Privacy Policy or requests relating to personal information for which PractoSync is the responsible party can be sent to:
PractoSync
Cilliers Koch Investments (Pty) Ltd
35 Coral Rd, Blue Lagoon 2, Langebaan, 7357, South Africa
Email: info@practosync.com
You also have the right to lodge a complaint with the Information Regulator (South Africa).
Email: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
Website: inforegulator.org.za
info@practosync.com
+27 72 292 2310
© 2025 Copyright Cilliers Koch Investments (Pty) Ltd. All rights reserved.

Say goodbye to scheduling conflicts and long phone calls! With PractoSync’s online booking feature, your patients can effortlessly schedule appointments at their convenience. This streamlined process not only enhances patient satisfaction but also minimizes administrative burdens. You can manage your calendar in real-time and receive instant notifications for new bookings or changes. This means less time spent on the phone and more time dedicated to your patients. Enhance your practice’s efficiency and improve patient engagement with our easy-to-use online booking system, designed specifically for modern medical practices.

Our note-keeping functionality is designed to simplify patient documentation for medical experts. With this feature, you can effortlessly take notes during patient consultations, ensuring accurate and real-time record-keeping. The platform allows you to export notes for easy sharing or offline access and even summarize them for quick overviews. Additionally, you can create and use fully customizable templates tailored to your practice’s unique needs, streamlining your workflow and saving time. Stay organized, efficient, and focused on providing the best care to your patients with this versatile tool.

With PractoSync, billing becomes a hassle-free experience. Our platform automates billing processes, ensuring that invoicing is accurate and timely. Track payments, manage outstanding invoices, and generate financial reports with ease. You can customize invoices to reflect your branding, making them professional and clear for your patients. Additionally, our integrated claims submission feature takes the guesswork out of working with medical aids, allowing for faster reimbursements. Say goodbye to billing headaches and let PractoSync simplify your financial management so that you can concentrate on what matters most—your patients.