Security and POPIA

Your patients’ records, hosted in South Africa

Cliniweb runs on Amazon Web Services (AWS) in Cape Town. Patient records and documents are stored there, and access is controlled by role and logged.

How we protect your data

Security built into the everyday

Built around POPIA, HPCSA and OHSC requirements from the start.

Hosted in Cape Town

Amazon Web Services, af-south-1 (Cape Town) region.

  • Records, attachments and signed forms stored in South Africa
  • Regular backups
  • Every page, form and API call over HTTPS
  • Nothing to install at the practice

Access by role

People see what their job needs.

  • Own login per staff member, never a shared login
  • Role-based permissions, from reception to doctor
  • Clinical results limited to nurses and above
  • Read-only access where that’s all someone needs

Everything on record

Who did what, and when.

  • Audit trail of records viewed and changed
  • Submitted invoices locked, with changes added, not overwritten
  • WhatsApp conversations kept with times and delivery status
  • Medication changes kept with the staff member and date
Patients

Private links and signed consent

Patients use links from your practice on their own phone, so they can see their own forms and nothing else.

  • No personal details on booking pages. Booking details that don’t match are never shown back.
  • Private links for check-in, questionnaires and consent that expire.
  • Signed consent: patient and provider signatures each saved with a name, timestamp and IP address, then filed as a PDF.
  • Uploads checked by their actual contents, not just the file name.
  • Bot checks and rate limits on public booking pages.
POPIA

Clear roles under POPIA

Your practice is the Responsible Party for its patients’ information. Arokiam (Pty) Ltd, which makes Cliniweb, is the Operator that processes it on your behalf.

  • Your data, kept while your account is active and paid, on full access or the Data-Only Package.
  • Data-Only Package for practices that stop practising: data kept and backed up, no logins, storage fee only.
  • Get a copy of your data on written request before your account is closed.
  • AI features may be powered by third-party AI providers (terms section 10).

Full details are in sections 5, 10, 12 and 13 of our terms.

Part of one system

Works with the rest of Cliniweb

Clinical records

Structured notes, consent and an audit trail in one record.

Clinical records

Pricing

About R250 a month for most practices. Data-Only Package available.

See pricing
Questions

Security: common questions

Where is Cliniweb hosted?

On Amazon Web Services (AWS) in the Cape Town (af-south-1) region, where patient records and documents are stored. We also keep regular backups.

Is Cliniweb POPIA compliant?

Cliniweb is built around POPIA, HPCSA and OHSC requirements, with role-based access, an audit trail and signed consent. Under POPIA your practice is the Responsible Party for patient information, and Arokiam is the Operator that processes it for you.

Does every staff member get their own login?

Yes. Every staff member has their own login, and what they can see and change depends on their role. Staff logins are unlimited.

What happens to our data if we stop using Cliniweb?

Your data is kept while your account is active and paid. If you stop practising, you can move to the Data-Only Package to keep your data stored without access, or ask for a copy of your data before your account is closed.

Does patient information go to AI providers?

When an AI feature is used, the information it works from may be processed by a third-party AI provider, as set out in section 10 of our terms.

Get started

Spend less time on admin

Register your practice today. We'll set you up and pair you with a GP who already uses cliniweb.

Already on Cliniweb? Sign in