External Platform Connection Terms

(Version 1.0 — [3 September 2026])

1. About These Terms

These terms apply when an authorised user of a Practice connects HealthAccess to an external account, service or platform selected by the Practice — for example a cloud storage, email marketing, accounting, calendar or imaging service, or another third-party integration made available in future. In these terms, "Practice" means the Customer organisation using HealthAccess, consistent with our Privacy Policy.

These terms operate alongside the HealthAccess SaaS Agreement, our Privacy Policy, our Support & Security Policy, any platform-specific terms shown during connection, and the external platform's own terms and privacy policy. If these terms conflict with the SaaS Agreement or another signed agreement on contractual matters, that agreement prevails.

An important distinction. A customer-connected external platform is an account or service selected, connected and controlled by the Practice, under the Practice's own agreement with that provider. It is not automatically a HealthAccess Sub-Processor. Sub-Processors are service providers appointed by HealthAccess to help operate and deliver the HealthAccess platform, and are addressed separately in our Privacy Policy and applicable agreements.

2. How External Connections Work

Depending on the integration, a connection may allow information to be imported, exported, copied, transmitted or synchronised between HealthAccess and the external platform. A connection may operate into HealthAccess, from HealthAccess, or bidirectionally, and not every integration synchronises information continuously — some transfer information only when a user initiates an action, on a schedule, or once-off.

The purpose of each connection, the categories of information involved and the direction of transfer differ by platform. These details should be displayed to the administrator during the connection process and should be reviewed before the connection is approved.

3. Authority and Practice Responsibilities

By connecting an external platform, the person completing the connection confirms that they are authorised to act for the Practice; that the account is owned or formally approved by the Practice; that they are authorised to grant the requested permissions; that the Practice has approved the intended sharing of information; and that the connection complies with the Practice's internal policies and legal obligations. HealthAccess may rely on the administrator's confirmation of authority.

The Practice is the Responsible Party for its patient or client Personal Information and is responsible for:

  • establishing a lawful basis for the transfer and obtaining and recording any required patient or client consent or authorisation;
  • assessing whether the external platform is appropriate for the intended information, including reviewing the provider's terms, privacy practices, storage locations and security controls;
  • correctly configuring users, folders, permissions and sharing settings, and restricting access to authorised users;
  • protecting login details, API keys, tokens and connected devices, enabling multi-factor authentication where available, and removing access when staff leave or no longer require it;
  • managing retention, archiving, backups and deletion of information held within the external platform; and
  • complying with POPIA, professional obligations and other applicable laws.

4. HealthAccess Responsibilities

HealthAccess will apply reasonable technical and organisational safeguards to the connection components under its control. Depending on the integration, this may include authorisation and access controls, secure transmission, restricting requested permissions or scopes to what the integration requires (where the external platform supports granular permissions — some integrations use API keys whose breadth of access is determined by the external provider), audit logging where supported, secure handling of connection credentials and tokens, controlled development and maintenance of the integration, and incident handling for HealthAccess-controlled components in line with our Support & Security Policy, which is the authoritative description of our security practices.

5. External Provider and Shared Responsibilities

External platforms operate independently and are governed by their own terms, privacy notices, availability commitments and security controls. HealthAccess does not control the external platform's infrastructure or availability, changes made by the provider, the provider's retention or recovery processes, access granted within the external account, actions performed by external-platform users, or the provider's suspension or termination of an account. The availability of a connection does not mean HealthAccess endorses, warrants or has audited the platform.

Secure use of a connection is a shared responsibility between HealthAccess, the Practice and the external provider. To the extent permitted by applicable law and subject to the applicable agreement, HealthAccess is not responsible for loss, deletion, corruption, unauthorised disclosure or unavailability caused by incorrect Practice configuration, excessive or inappropriate permissions, compromised Practice credentials, unauthorised external-account users, actions performed within the external platform, external-platform outages or service changes, or the Practice's failure to maintain its own backup or retention arrangements.

This section does not exclude or limit HealthAccess's responsibility for its own breach of the applicable agreement, its own negligence, a security failure in components under its control, or its own non-compliance with applicable law.

6. Personal Information and International Processing

A connected platform may receive Personal Information and, depending on the integration, Special Personal Information such as clinical images or health information. The connection-screen description should identify the categories of information being shared, and the Practice, as Responsible Party, determines the lawful basis and remains responsible for patient or client notices, consent and professional-record obligations.

An external provider may store or process information outside South Africa. Before connecting, the Practice must review the provider's processing locations and safeguards and satisfy itself that the connection complies with POPIA and other applicable laws. The Practice should review and verify the external provider's current processing locations and safeguards. Any provider-specific information made available by HealthAccess is provided for general guidance and may change when the external provider changes its services. See the International Transfers section of our Privacy Policy for how we approach cross-border processing for the components under our control.

7. Authorisation, Reauthorisation and Disconnection

Before a connection is established, HealthAccess may require an authorised administrator to review a platform-specific connection summary, acknowledge these External Platform Connection Terms, approve the stated data sharing and grant the requested permissions or scopes. To evidence the authorisation, HealthAccess may record the Practice, the authorising user, the platform, the connected account identifier, the purpose of the connection, the data categories and transfer direction, the permissions or scopes granted, the date and time, and the version of these terms acknowledged.

Reauthorisation may be required when a different account is connected, when the purpose, data categories, permissions or scopes materially change, or when these terms are materially updated. HealthAccess will notify affected customers of material changes where appropriate.

An authorised administrator may disconnect a platform, subject to available functionality and permissions. Disconnecting stops future transfers once effective, but does not necessarily delete information already copied to HealthAccess or already transferred to the external platform, and does not replace the Practice's responsibility to manage or delete information in the external account. Queued or already initiated transfers may need to complete or be handled separately.

Third-party providers may change their APIs, permissions, commercial terms or availability, and HealthAccess may modify, suspend or discontinue an integration where reasonably required for security, compliance, compatibility or commercial reasons, subject to the applicable agreement.

8. Updates and Contact

HealthAccess may update these terms from time to time. Updates will be published on this page with a revised version number and effective date. Customers will be notified of material changes where appropriate.

For questions about these terms or a platform connection, or to report a suspected compromise of a connected account, credential, API key or token, please contact us via the Contact Us page. Incidents affecting components under HealthAccess's control are handled in accordance with our Support & Security Policy; incidents occurring solely within the external platform may also need to be reported directly to that provider. For privacy-related questions, please see the Contact & Complaints section of our Privacy Policy.

Version History

  • Version 1.0: Initial publication of the External Platform Connection Terms. (3 September 2026)
HealthAccess
40 Swart Street
Brackenfell
Cape Town, 7560
Phone: +27 60 087 2136