We licence the platform your system runs on. We do not run the servers. This page says which parts are ours, which are not, and what the system is not built to hold.
Your records live in a platform we licence, hosted outside South Africa, and the company behind it runs the security programme, the encryption and the backups — not us. What we do ourselves is small and worth stating: everyone here uses their own named login, never a shared one, and we hold some of your data outside the platform, because imports and support arrive by email. The system is not set up for health information and it is not the place for card numbers. If you are a South African business, putting your customers’ personal information in means it leaves the country, and telling your customers that is your duty, not ours. Ask us anything on this page and a person answers.
Techanisms builds and runs systems on a platform we licence. We do not own the servers, the network or the databases, and we do not run a security programme of our own. Almost everything worth describing on this page is our platform provider’s work, not ours.
We say that plainly because the alternative is worse. A page that borrows someone else’s certificates and writes them in the first person reads well right up to the moment somebody asks a follow-up question.
So the rest of this page is written in two voices. Our platform provider does — for the infrastructure and the controls that come with the licensed platform. We do, or we do not — only for things Techanisms genuinely does itself.
Your records live inside the licensed platform, on infrastructure our platform provider operates. The hosting is outside South Africa — primarily in the United States, and potentially in other countries where our platform provider operates. That is true wherever your business is, and it matters if you are outside those countries — see POPIA and South African businesses below.
We do not keep client databases on our own machines and we do not take local copies of a workspace to work from. Where a build moves records between systems, they move between those systems, not through a copy we keep.
The controls below belong to our platform provider. They are the provider’s certifications and the provider’s programme. Techanisms holds none of them in its own name, and does not claim to.
If you need to see the underlying documents — a certification report, a sub-processor list — ask us and we will request them from the provider. We cannot send you ours, because there are none.
Some of your data does reach us directly, and it would be easy to leave this section out. Two things, both ordinary:
We do not keep either longer than the work needs. If you would rather a file was removed once an import is done, say so and we will remove it.
Everyone at Techanisms who works in a client workspace does so under their own named credentials. Nobody here logs in as “the team”. There is no shared password, and a request to set one up is refused with the reason given, because a shared login means no record of who did what.
We set client accounts up the same way and we ask you to keep them that way — one login per person, named. What your own team does internally is yours to manage; we can build it correctly, we cannot police it.
When an engagement ends, our access to your workspace is removed. The same applies when someone leaves our team: their credentials go with them.
We are not putting a clock on that here, because a number on this page becomes a promise you can enforce and we would rather tell you the truth than a target. What we will say is that removal is part of closing the work, not a task that waits for you to ask.
If you want it confirmed in writing when it is done, ask and we will confirm it.
Backups are our platform provider’s, on the provider’s schedule. We do not run a backup of your workspace ourselves, and no system we build depends on one.
If you want your own copy of your data — held by you, outside the platform — ask us and we will set up an export. That is a reasonable thing to want and it is not an awkward question.
The platform is not configured for HIPAA, so health information must not go into it. Not in a contact record, not in a note on a job, not in an attachment.
Our platform provider offers HIPAA support as a paid add-on. Techanisms has not bought it. So this is not a case of asking us first — there is no arrangement on our side to switch on, and we would rather you knew that before you built a process around it.
The platform is not PCI-DSS compliant and card numbers are not stored in it. Our platform provider says the same of itself.
So do not type a card number into a contact record, a note or a form field. Where a system we build takes a payment, the card details go to the payment provider handling it and never land in the workspace.
This is the part most worth reading if you are a South African business, and it is the part that is easiest to miss.
The hosting is outside South Africa. If you put your customers’ personal information into the system, that information leaves the country. Under POPIA, telling your customers that their information is processed outside the country — and having a lawful basis for sending it there — is your obligation to your customers. It is not something we can discharge on your behalf.
What we will do is ask our platform provider for the current list of countries your data is processed in, and tell you what they say, so you can meet that duty properly. What we cannot do is meet it for you, and a page that implied otherwise would be doing you a disservice.
If our platform provider tells us about an incident affecting a workspace we run for you, we pass it on to you with what we know at the time. We do not sit on it while we work out how it reads.
We are not promising a number of hours, because the information reaches us from the provider and we do not control when. What we are promising is that we forward it rather than filter it.
Three things, and none of them are difficult:
If your own compliance process needs paperwork — the platform’s certification report, the list of companies the provider uses underneath it — write to info@techanisms.com and we will request it from our platform provider.
We will tell you what we get back and what we could not get. We are not going to send you a Techanisms audit report, because Techanisms does not have one, and a page that offered one would be describing a different company.
If something here does not fit how you actually work, say so — it is usually a sign the wording is wrong rather than that you are. If the answer is that we cannot do a thing, we will say that too.
Anything about your own account or data goes through the chat bubble in your workspace — it stays on the record against the account.