Our DPIA, available to you
We have filed a Data Protection Impact Assessment with the Information Regulator covering the platform's processing activities. The executive summary is available to facility administrators on request; the full DPIA is available under NDA for your compliance team.
Audit pack per shift
Every booking generates a downloadable audit pack: booking timestamps, QR attendance scans, geofence check-in / check-out rows, escrow ledger entries (on escrow shifts), hash-chained message log, and the SHA-256 chain of every state change. Export per shift, per month, or per quarter directly from your dashboard.
Operator agreement
POPIA Section 21 requires a written operator agreement between you (the responsible party) and Locum (the operator). Our standard operator agreement is available on request from compliance@btlocum.com. Custom terms available for enterprise customers.
Retention
Personal information of locums is retained while the booking is active, plus seven years thereafter as required by the Financial Intelligence Centre Act and SARS. Geofence records are deleted 90 days post-shift. You can request earlier deletion of locum data under POPIA, subject to statutory retention.
Breach notification
In the event of a personal-information breach affecting your data, we notify your designated information officer within 72 hours and the Information Regulator within statutory windows. You may add up to three contacts to the breach notification list per facility.
Sub-operators
We use three sub-operators: PayFast (payment processing, licensed FSP), our hosting provider (data hosted in South Africa), and SendGrid (transactional email). All operate under written agreements requiring POPIA-equivalent protection. The list updates if we add any.
Compliance contact
Email compliance@btlocum.com for the DPIA summary, a copy of the operator agreement, or to add your information officer to the breach notification list.