Anchorix
Legal

PAIA Manual

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), read with the Protection of Personal Information Act 4 of 2013 (POPIA). Effective 31 August 2026.

1. The private body

NameAnchorix
NatureSole proprietorship
Head / Information OfficerStephen Oosthuizen
Physical address0D Boundary Road, Honeydew, Randburg, Gauteng
Postal addressAs above
Telephone066 576 7571
Emailsouth-africa-anchorix@outlook.com
Websitehttps://anchorix.org

Anchorix provides booking, scheduling, customer-record and invoicing software to appointment-based businesses.

Anchorix and its Information Officer are registered with the Information Regulator (South Africa), as required by sections 55 and 56 of POPIA. A copy of the registration certificate is available on request from the address above.

2. Guide in terms of section 10

The Information Regulator has compiled a guide, in terms of section 10 of PAIA, containing information to help a person exercise their rights under the Act. The guide is available from the Information Regulator:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
Website: https://inforegulator.org.za

3. Records available without a request

The following are published on https://anchorix.org and may be accessed without a PAIA request:

4. Records held, by subject

SubjectCategories of records
Company / operationalBusiness correspondence, service documentation, internal policies and compliance records
Your business account recordsBusiness account details, contact details of the account owner, subscription and billing records, support correspondence
Sales enquiriesEnquiry form submissions: name, email address, business name, trade, message
FinancialInvoices, payment records, bank records, tax records
StatutoryRecords kept under the Tax Administration Act 28 of 2011 and other applicable legislation
Information technologySystem configuration, infrastructure and source code, security and access logs

Records Anchorix holds but does not control

Businesses using Anchorix store information about their own clients and patients on the platform — contact details, appointment records, visit notes, uploaded documents and intake form responses.

For those records that business is the responsible party under POPIA and Anchorix is only the operator, processing them on that business's instructions. Anchorix does not decide what is collected or why, and does not use any of it for its own purposes.

How a request for those records actually works

  1. The person makes their request to the business, not to Anchorix. Anchorix has no relationship with a business's clients and does not deal with them directly.
  2. The business retrieves what it needs from Anchorix — its own dashboard, its own data — and provides it to the requester itself.
  3. Anchorix does not release, alter or delete anything on a business's behalf, and has no way to verify who a requester is or whether a request should be granted.

Anchorix's own staff cannot read those records. Nobody at Anchorix can open a business's client list, appointments, notes or documents through the system, and nobody at Anchorix can sign in to a business's account — unless that business creates a login for them, which it can withdraw at any time.

This is why a question about your own information has to go to the business that holds it. It is not a matter of policy or of us declining to help — we are not able to look.

A request sent to Anchorix will therefore be declined and redirected to the business concerned. That is not an evasion: Anchorix releasing one business's client records to someone who contacted the wrong party would itself be a breach.

Anchorix stores that information as a third-party processor, which the business authorises in Anchorix's Terms of Service — the operator agreement each business owner accepts before use. Anchorix's own obligations under that arrangement (security safeguards, breach notification to the business) are set out in section 3 of those terms.

Anchorix does provide tooling to help a business meet these obligations: customers can raise an access, correction or deletion request from their own portal, which starts the 30-day clock, alerts the business owner, and records what the business decided. The decision and the disclosure remain entirely the business's.

5. Processing of personal information (section 51(1)(c)(i))

Purpose of processingResponding to sales enquiries; providing, administering and billing for the Anchorix service; meeting statutory obligations
Categories of data subjectsProspective customers, customers (business owners and their staff), suppliers
Categories of personal informationNames, email addresses, telephone numbers, business names and addresses, billing and payment records
RecipientsAmazon Web Services (hosting, Africa (Cape Town) region); SARS and other authorities where legally required
Cross-border transfersClient and account data is stored in South Africa. Anchorix does not process payments and holds no card or bank details. Where a business connects QuickBooks, invoice data is transmitted to Intuit outside South Africa on that business's instruction.
Security measuresEncryption in transit and at rest, separation of each business's data, role-based access control, and access-audit logging for accounts handling confidential client records.

6. How to request access

  1. Complete Form 2 of the PAIA Regulations (available from the Information Regulator's website) and send it to the Information Officer at the address in section 1.
  2. Provide enough detail to identify the record, your identity, and the form of access you want. If the request is made on behalf of someone else, include proof of authority.
  3. State the right you are seeking to exercise or protect, and why the record is required to exercise or protect it.
  4. If you are unable to read, write, or communicate in writing, you may make the request orally, and the Information Officer will reduce it to writing and give you a copy.

Timeframe. A decision follows within 30 days of receipt. That period may be extended by a further 30 days where the request is for a large number of records or requires a search through records held elsewhere; you will be told in writing if that happens.

Fees. A requester (other than a personal requester) must pay a request fee before the request is processed, and may be required to pay an access fee for search, reproduction and delivery. Fees are those prescribed in the PAIA Regulations, as amended from time to time. You will be notified of any fee before it becomes payable, and may lodge an internal appeal or apply to court against a fee decision.

Grounds for refusal. Access may be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, including protection of another person's privacy, commercial information of a third party, confidential information, and legal privilege. Reasons will be given in writing.

7. Remedies

There is no internal appeal against a decision of the head of a private body. A requester who is dissatisfied may:

8. Availability of this manual

This manual is available: