Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), read with the Protection of Personal Information Act 4 of 2013 (POPIA). Effective 31 August 2026.
| Name | Anchorix |
| Nature | Sole proprietorship |
| Head / Information Officer | Stephen Oosthuizen |
| Physical address | 0D Boundary Road, Honeydew, Randburg, Gauteng |
| Postal address | As above |
| Telephone | 066 576 7571 |
| south-africa-anchorix@outlook.com | |
| Website | https://anchorix.org |
Anchorix provides booking, scheduling, customer-record and invoicing software to appointment-based businesses.
Anchorix and its Information Officer are registered with the Information Regulator (South Africa), as required by sections 55 and 56 of POPIA. A copy of the registration certificate is available on request from the address above.
The Information Regulator has compiled a guide, in terms of section 10 of PAIA, containing information to help a person exercise their rights under the Act. The guide is available from the Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
Website: https://inforegulator.org.za
The following are published on https://anchorix.org and may be accessed without a PAIA request:
| Subject | Categories of records |
|---|---|
| Company / operational | Business correspondence, service documentation, internal policies and compliance records |
| Your business account records | Business account details, contact details of the account owner, subscription and billing records, support correspondence |
| Sales enquiries | Enquiry form submissions: name, email address, business name, trade, message |
| Financial | Invoices, payment records, bank records, tax records |
| Statutory | Records kept under the Tax Administration Act 28 of 2011 and other applicable legislation |
| Information technology | System configuration, infrastructure and source code, security and access logs |
Businesses using Anchorix store information about their own clients and patients on the platform — contact details, appointment records, visit notes, uploaded documents and intake form responses.
For those records that business is the responsible party under POPIA and Anchorix is only the operator, processing them on that business's instructions. Anchorix does not decide what is collected or why, and does not use any of it for its own purposes.
How a request for those records actually works
Anchorix's own staff cannot read those records. Nobody at Anchorix can open a business's client list, appointments, notes or documents through the system, and nobody at Anchorix can sign in to a business's account — unless that business creates a login for them, which it can withdraw at any time.
This is why a question about your own information has to go to the business that holds it. It is not a matter of policy or of us declining to help — we are not able to look.
A request sent to Anchorix will therefore be declined and redirected to the business concerned. That is not an evasion: Anchorix releasing one business's client records to someone who contacted the wrong party would itself be a breach.
Anchorix stores that information as a third-party processor, which the business authorises in Anchorix's Terms of Service — the operator agreement each business owner accepts before use. Anchorix's own obligations under that arrangement (security safeguards, breach notification to the business) are set out in section 3 of those terms.
Anchorix does provide tooling to help a business meet these obligations: customers can raise an access, correction or deletion request from their own portal, which starts the 30-day clock, alerts the business owner, and records what the business decided. The decision and the disclosure remain entirely the business's.
| Purpose of processing | Responding to sales enquiries; providing, administering and billing for the Anchorix service; meeting statutory obligations |
| Categories of data subjects | Prospective customers, customers (business owners and their staff), suppliers |
| Categories of personal information | Names, email addresses, telephone numbers, business names and addresses, billing and payment records |
| Recipients | Amazon Web Services (hosting, Africa (Cape Town) region); SARS and other authorities where legally required |
| Cross-border transfers | Client and account data is stored in South Africa. Anchorix does not process payments and holds no card or bank details. Where a business connects QuickBooks, invoice data is transmitted to Intuit outside South Africa on that business's instruction. |
| Security measures | Encryption in transit and at rest, separation of each business's data, role-based access control, and access-audit logging for accounts handling confidential client records. |
Timeframe. A decision follows within 30 days of receipt. That period may be extended by a further 30 days where the request is for a large number of records or requires a search through records held elsewhere; you will be told in writing if that happens.
Fees. A requester (other than a personal requester) must pay a request fee before the request is processed, and may be required to pay an access fee for search, reproduction and delivery. Fees are those prescribed in the PAIA Regulations, as amended from time to time. You will be notified of any fee before it becomes payable, and may lodge an internal appeal or apply to court against a fee decision.
Grounds for refusal. Access may be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, including protection of another person's privacy, commercial information of a third party, confidential information, and legal privilege. Reasons will be given in writing.
There is no internal appeal against a decision of the head of a private body. A requester who is dissatisfied may:
This manual is available: