Privacy Policy
Last updated: 5 March 2026
This Privacy Policy explains how LocumLead ("we", "us", or "our") collects, uses, and protects your personal information in compliance with the Protection of Personal Information Act (POPIA) of South Africa.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, password
- Profile Information: Professional qualifications, HPCSA number, specializations, work experience, profile photo
- Facility Information: Facility name, type, address, contact details, registration information
- Verification Documents: ID documents, qualification certificates, HPCSA registration proof, proof of insurance
- Communication Data: Messages sent through our platform
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent on platform
- Device Information: Browser type, operating system, IP address
- Cookies: Session cookies for authentication and preferences
2. Purpose of Processing
We process your personal information for the following purposes:
- Service Delivery: To operate the platform and connect clinicians with facilities
- Verification: To verify professional qualifications and facility legitimacy
- Communication: To send booking confirmations, reminders, and important updates
- Safety and Security: To maintain platform security and prevent fraud
- Legal Compliance: To comply with applicable laws and regulations
- Improvement: To improve our services based on usage patterns
3. Legal Basis for Processing
Under POPIA, we process your information based on:
- Consent: Where you have given explicit consent
- Contract: Where processing is necessary to fulfill our service agreement
- Legal Obligation: Where required by law
- Legitimate Interest: Where we have a legitimate business interest that doesn't override your rights
4. Information Sharing
We share your information only in the following circumstances:
4.1 With Other Users
- Clinician profiles are visible to facilities when applying for jobs
- Facility information is visible to clinicians viewing job listings
- Contact details are shared only after a booking is confirmed
4.2 With Service Providers
- Supabase: Database and authentication services
- Resend: Email delivery services
- Vercel: Hosting and infrastructure
4.3 Legal Requirements
We may disclose information when required by law, court order, or to protect our rights.
5. Data Retention
- Active Accounts: Data is retained while your account is active
- Closed Accounts: Data is deleted within 90 days of account closure, except where legal retention is required
- Legal Requirements: Some data may be retained for up to 7 years for tax and legal compliance
- Anonymized Data: Anonymized usage statistics may be retained indefinitely
6. Your Rights Under POPIA
You have the following rights regarding your personal information:
- Right of Access: Request a copy of your personal information
- Right to Rectification: Request correction of inaccurate information
- Right to Deletion: Request deletion of your information (subject to legal requirements)
- Right to Object: Object to certain types of processing
- Right to Data Portability: Request your data in a portable format
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@locumlead.co.za.
7. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with password hashing
- Regular security audits and updates
- Access controls limiting data access to authorized personnel
- Row-level security in our database
8. Cookies and Tracking
We use the following types of cookies:
- Essential Cookies: Required for platform functionality and authentication
- Analytics Cookies: To understand how users interact with our platform (Google Analytics)
You can control cookies through your browser settings, but disabling essential cookies may affect platform functionality.
9. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information immediately.
10. International Data Transfers
Our services may involve transferring data to servers outside South Africa (for hosting and email services). We ensure appropriate safeguards are in place for such transfers, including data processing agreements with our service providers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or platform notification. Continued use of our services after changes constitutes acceptance of the updated policy.
12. Information Officer
Our designated Information Officer is responsible for ensuring compliance with POPIA:
Information Officer: LocumLead Privacy Team
Email: privacy@locumlead.co.za
Address: Cape Town, South Africa
13. Complaints
If you believe your privacy rights have been violated, you may lodge a complaint with:
- Our Information Officer (contact details above)
- The Information Regulator of South Africa: www.justice.gov.za/inforeg/
14. Contact Us
For any questions about this Privacy Policy or our data practices:
Email: privacy@locumlead.co.za
General Enquiries: support@locumlead.co.za