Skip to content
Legal

Privacy & POPIA

How we collect, use, and protect your personal information under the South African Protection of Personal Information Act, 2013.

Last updated 15 June 2026 · Version 1.2

BrandTelligence (Pty) Ltd, trading as BT iLocum, is the responsible party for personal information you provide to us. This policy explains what we collect, why, who we share it with, and how to exercise your rights under POPIA.

What we collect

We collect only what is necessary to operate the marketplace. For healthcare professionals we hold name, email, phone, profession and statutory-council registration details (e.g. HPCSA registration and registration category), ID document hash (not the document itself), qualifications, specialties, indemnity insurer and policy expiry date, self-logged CPD activity entries, ratings, shift history, a saved home address with coordinates (used to power the travel-radius map and the per-shift distance badges), notification channel preferences, and your separate opt-in consent records for marketing channels and Benefits categories (including the consent wording version you accepted).

For facilities we hold the business name, structured address with coordinates from Google Places, geofence radius, contact details, the admin user's name + email, the facility wallet ledger, and any payment instrument tokens returned by our payment processor (we never store raw card numbers).

For both we record audit metadata: login timestamps, last-seen timestamp, IP address (last login + scan events only), user-agent strings, and a hash-chained log of every booking, message, payment, geofence check-in, and QR attendance scan action.

Why we collect it

Three lawful purposes under POPIA: contractual necessity (delivering bookings, attendance verification, and — for escrow shifts — the payments you ask for), legal obligation (financial-record retention required by SARS and the Financial Intelligence Centre), and legitimate interest (fraud detection, dispute resolution, security monitoring).

Two purposes run on your separate OPT-IN consent only, off by default and revocable per channel/category at any time from settings: (1) direct marketing on the channels you select (POPIA section 69 — every consent is recorded with the wording version you saw), and (2) Benefits-category offers (indemnity, banking, tax). Your indemnity expiry date drives a service reminder shown to you; it is never shared with a partner unless you explicitly request an introduction.

Who we share it with

Your data is shared only with the parties needed to complete a booking. Professionals who apply for a shift have their name, photo, credentials, and council registration number disclosed to that facility. Facilities posting shifts have their name, structured address, and contact reveal disclosed to accepted professionals.

Benefits partners: when — and only when — you press a request button (for example "Request indemnity quotes"), we pass your name and contact details to the relevant partner so they can contact you. Partners pay us a flat introduction fee; they never receive your credential, earnings, or shift data without a separate, named consent. Credential-passport share links are created only by you, expire after 30 days, and contain professional credentials only — never contact details.

We use the following operator-category third parties, each under written agreements requiring POPIA-equivalent protection: PayFast (payment processing + payouts, licensed FSP), our hosting provider (data hosted in South Africa), SendGrid (transactional email), Twilio (SMS for high-urgency events only), Google Cloud (Places Autocomplete + Maps tiles, no personal data crosses the boundary beyond the address string the user types), OpenStreetMap (map tiles for the directory map; only an approximate map position is requested, never your exact address), and the browser-native Web Push services (Mozilla, Google, Apple) which receive only the encrypted push payload and a per-device token.

The directory, messaging & paid features

Verified-professional directory: if you are a professional, your verified profile — name, photo, profession, specialties, reliability score, star rating, and an APPROXIMATE area derived from your home coordinates and rounded so your exact address is never shown — is discoverable by facilities that hold an active directory subscription. The lawful basis is legitimate interest (connecting verified professionals with facilities that need cover), balanced by your control: you can opt out of the directory at any time from your profile, which removes you from directory search and contact reveal without affecting the rest of your account. When a facility reveals your contact details, we log which facility account did so and when in an append-only audit table, so the access can be reviewed in a dispute.

In-app messaging and shift invitations: facilities and professionals can message each other about a specific shift, and a facility can invite a professional to one of its shifts. We process message content and metadata to deliver the conversation, power notifications, and — where necessary — resolve disputes or enforce our Terms. Invitation and shift threads are retained as described under "How long we keep it".

Paid features (directory subscriptions, the Facility Premium and Locum Premium plans, professional featuring, and boost packs): we store the purchase, the period it covers, the amount, and the payment processor's transaction reference. We never store raw card numbers — card payments are handled by PayFast — and because these features are prepaid for a fixed period and do not auto-renew, we do not retain card credentials to charge you again.

How long we keep it

Account data: as long as your account is active, plus 90 days after closure to allow account recovery.

Booking, payment, audit, and attendance-scan records: 7 years from the date of the transaction, as required by the Financial Intelligence Centre Act and SARS.

Geofence location records: 90 days after the shift, then permanently deleted.

QR attendance scan rows: retained for the same 7-year period as financial records; the JWT issued for each scan has a ~2 minute expiry and is never persisted in plaintext beyond the scan row's `token_jti` reference.

Web Push subscription records: kept while you remain opted in; pruned automatically when the push service returns a 404/410 (subscription dead) on a delivery attempt. You can revoke any subscription per browser from your profile.

Communications (in-app messages, including shift-invitation threads): kept while the related booking is active or pending; threads on declined or expired invitations are anonymised after 12 months.

Your rights

Under POPIA Section 23 you have the right to access, correct, or delete your personal information at any time. You can also object to processing, opt out of direct marketing, and lodge a complaint with the Information Regulator.

  • AccessDownload a complete export of everything we hold about you, from your profile settings or via privacy@btlocum.com.
  • CorrectionEdit your profile data directly. For records you cannot edit (audit logs, payment history), email us with the correction requested.
  • DeletionDelete your account from settings. We honour deletion within 14 days; statutory retention applies only to anonymised financial records.
  • ObjectionOpt out of marketing emails with one click. We do not sell or rent data.

How we protect it

Data is hosted in South Africa and encrypted at rest with AES-256. Data in transit is encrypted with TLS 1.3. Passwords are bcrypt-hashed; reset tokens are SHA-256 hashed and short-lived.

We run external penetration tests annually and SAST + SCA on every deployment. The full security overview is at /security.

Breach notification

If we suffer a personal-information breach affecting your data, we will notify you and the Information Regulator without undue delay — within 72 hours of detection where the breach is likely to result in adverse effects.

Cookies & analytics

We use a small number of strictly necessary cookies to keep you signed in and to keep the platform secure, plus privacy-respecting product analytics to understand how the marketing site and app are used so we can improve them. We do not use advertising or cross-site tracking cookies, and we do not sell data. Analytics run on the basis of legitimate interest and you can opt out from your browser. Full detail — the cookie categories and the providers we use — is in our Cookie Policy at /cookies.

Information Officer

Our Information Officer is registered with the Information Regulator. Direct any POPIA queries to privacy@btlocum.com. We respond within 7 working days for standard requests; 30 days for complex ones.

Exercising your rights

Under POPIA you have the right to access, correct, or delete your data. Email privacy@btlocum.com or use the DSAR endpoint in your profile settings.

Contact the Information Officer