Data & Compliance
Effective: 5 September 2026 · Last updated: 22 August 2026
This page explains in plain language exactly what data Hauffi collects from each type of user, why it is collected, how it is stored and protected, and your rights over it. Our full Privacy Policy is available at hauffi.com/privacy.
1. Data We Collect, By User Type
Patients
| Data | Purpose | Retention | Shared publicly |
|---|---|---|---|
| Full name | Account creation and appointment matching | Account lifetime; removed from live systems on account deletion | No |
| Email address | Login, appointment confirmations, reminders | Account lifetime | No |
| Phone number | Contact by practitioner for appointment | Account lifetime | No |
| Medical aid selection | Match patients with suitable booking and billing options | Account lifetime | No |
| Medical aid name and plan | Match with doctors who accept your scheme | Account lifetime | No |
| Appointment history | Continuity of care and dispute resolution | While account is active; removed from live systems on account deletion | No |
| Push notification token | Appointment reminders and status updates | Until sign-out or account deletion | No |
| Walk-in billing metadata | On-demand fee authorisation, refunds, reconciliation, support | Per account lifecycle and finance/support retention needs | No |
| Foreground and on-demand location data | Find nearby doctors and route active walk-in requests | Stored with active walk-in requests and related operational records | No |
Healthcare Practitioners (Doctors)
| Data | Purpose | Retention | Shared publicly |
|---|---|---|---|
| Full name | Public profile, patient booking | Account lifetime | Yes, public |
| Optional profile photograph | Help patients identify the doctor across directories, booking, appointment and referral screens | Until removed, replaced, or account deletion; temporary cache copies may persist | Yes, public when uploaded |
| Email address | Login, notifications | Account lifetime | No |
| Phone number | Visible to booked patients only | Account lifetime | Limited, booked patients only |
| HPCSA registration number | Credential verification against HPCSA register | Account lifetime | No |
| Practice name, address, consultation fee | Public doctor profile | Account lifetime | Yes, public |
| Specialty | Search and matching | Account lifetime | Yes, public |
| Medical aids accepted | Search and matching | Account lifetime | Yes, public |
| HPCSA certificate (image) | Admin credential verification | While account is active; removed from live systems on account deletion | No, admin only, signed URL |
| Subscription plan and status | Billing and service tier access | While account is active; removed from live systems on account deletion | No |
| Paystack authorization and payment metadata | Subscription billing via Paystack | While account is active; removed from live systems on account deletion | No |
| Biometric verification outcome | Practitioner identity confirmation (via Smile ID) | Account lifetime | No |
| Verified name (from Smile ID) | Admin cross-reference check | Account lifetime | No |
| Appointment history | Analytics and dispute resolution | While account is active; removed from live systems on account deletion | No |
Practice Managers and Receptionists
| Data | Purpose | Retention | Shared publicly |
|---|---|---|---|
| Full name and email address | Account access, invitation, identification, and audit records | While the account or practice membership is active; subject to account-deletion and audit-retention rules | No |
| Practice membership and assigned role | Authorise practice-scoped workflows and enforce permissions | While active plus limited audit records | No |
| Practice actions | Operate and audit appointments, availability, referrals, patient contact, on-demand requests, and co-payment documents | According to the retention period of the related practice record | No |
| Push notification token | Practice appointment, referral, and on-demand notifications | Until sign-out, device revocation, or account deletion | No |
| Optional Google Calendar connection data | Export the practice schedule to a dedicated Google calendar | While connected; removed after disconnect cleanup or account deletion | No |
Important: Smile Identity exclusively processes and retains practitioner selfies, liveness checks, and government-issued ID documents. Hauffi stores only the verification outcome, related audit fields, the practitioner's HPCSA certificate, and verified name received from Smile Identity.
Dual-Role Accounts
If you hold both a patient profile and a healthcare practitioner profile under the same account, each profile maintains separate data records. Your patient data is governed by the patient data table above, and your practitioner data is governed by the healthcare practitioner data table. Deleting your account will delete both profiles and all associated data.
2. Data We Do NOT Collect
Hauffi is designed with data minimisation as a core principle. We do not collect:
- Medical records, diagnoses, prescriptions, or clinical notes
- SA ID numbers (practitioner biometric flow, captured by Smile Identity only)
- Full card numbers or CVVs
- Passport numbers
- Free-text medical disclosures from patients (cancellation reasons are from a predefined list only)
- Browsing history or cross-app tracking data
- Advertising identifiers (IDFA, GAID)
3. Third-Party Processors
We use the following service providers under their applicable service terms and, where required, data-processing agreements:
| Provider | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase | Database, authentication, file storage | United States / EU | auth.users, profiles, appointments, documents |
| Expo (Expo Push Service) | Push notifications | United States | Push notification token only |
| Google Maps Platform | Location and places lookups | United States | Practice address search queries and location-related lookups |
| Google Calendar | Optional appointment export and, for doctors only, free/busy conflict prevention | Google processing locations | Connected Google email and account identifier; dedicated Hauffi calendar events; doctors’ free/busy start and end times only |
| Paystack | Patient walk-in billing and practitioner subscriptions | Jurisdictions used by Paystack | Masked card metadata, payment references, authorization and refund data |
| Resend | Transactional email delivery | United States | Email address, appointment reference |
| Browserless | Automated HPCSA public-register checks when enabled | United States | Practitioner name and HPCSA registration number |
| Smile Identity (Smile ID) | Biometric identity verification (practitioners) | Pan-African / USA | Selfie image, liveness, government-issued ID document, verification outcome and verified name |
| OpenAI | Doctor portal analytics assistant | United States | Aggregated practice analytics only; no patient records |
We do not share data with any advertising networks, data brokers, or analytics platforms that track individuals across services.
3.1 Optional Google Calendar Data
Google Calendar is connected only when a doctor, practice manager, or receptionist affirmatively chooses to connect an account and approves Google's authorization screen. Hauffi requests permission to create and manage only its dedicated secondary calendar. For doctors, Hauffi also requests free/busy access to the primary calendar.
| Data | Purpose | Retention | Shared publicly |
|---|---|---|---|
| Google account email and identifier | Identify and display the connected account | While connected | No |
| Encrypted OAuth refresh token | Maintain the user-authorised connection without repeated sign-in | While connected; deleted after disconnect cleanup or account deletion | No |
| Doctor free/busy start and end times | Remove patient booking times that overlap a doctor’s Google busy periods | Rolling scheduling window of no more than 90 days; replaced on refresh | No |
| Managed-calendar and webhook identifiers | Deliver, monitor, and renew Calendar synchronization | While connected | No |
| Hauffi appointment event data | Create the dedicated Google calendar schedule | Held by Google until the event/calendar is removed under Google’s retention behavior | Visible only according to the connected Google account’s sharing settings |
Hauffi does not read or store the title, description, attendees, location, or content of a doctor's primary-calendar events. Events written to the dedicated Hauffi calendar contain the patient's first name and surname initial, appointment time and status, practice name, and a Hauffi appointment link and identifier.
Hauffi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. It is not sold, used for advertising or credit decisions, or used to train general-purpose AI models.
4. Biometric Data (Smile Identity)
Biometric verification for healthcare practitioners is performed by Smile Identity, a pan-African identity verification provider that processes practitioner verification information under its applicable terms and privacy policy.
What Smile Identity processes
- A real-time selfie captured within the Smile Identity secure environment
- Your government-issued identity document (SA ID or passport)
- A liveness check to confirm the selfie is of a live person
- A comparison of your selfie against your ID document photo
What Hauffi receives from Smile Identity
- Verification outcome and related audit fields
- Your verified full name as it appears on your ID document
What we do not receive
- Your full card details from payment providers
- Medical records, diagnoses, prescriptions, or clinical notes
Smile Identity retains biometric data for the period necessary to complete verification and in accordance with their Privacy Policy. By proceeding with biometric verification, you consent to Smile Identity processing your data for this purpose.
5. Data Storage and Security
Where your data is stored
Hauffi uses Supabase as its primary data platform. Supabase stores data on AWS infrastructure. Our primary production database region is eu-central-1 (Frankfurt, Germany), with Supabase managing replication and backups.
Encryption
- In transit: TLS 1.3 for all data moving between your device and our servers
- At rest: encryption for stored data, including uploaded documents
Access controls
- Row-Level Security (RLS) is enabled on every database table, patients can only access their own data
- Practitioners can only access their own profile and data for appointments they are booked in
- Active practice managers and receptionists receive only practice-scoped access required for their assigned workflows; access is removed when membership is revoked
- Doctor profile photographs are intentionally public when uploaded; only the owning doctor can upload, replace, or remove the object
- Uploaded HPCSA certificates are stored in a private bucket with no public URL, accessible only via time-limited signed URLs (1-hour expiry) generated for authorised admin reviewers
- Admin access is role-restricted and requires authentication
Backup retention
- Automated backups are encrypted at rest using the same encryption as live systems (AES-256)
- Backup copies are retained for a maximum of 30 days for operational recovery purposes only
- Deleted account data may persist in backups until the 30-day retention period expires
6. Data Retention and Deletion
| Data type | Retention period | Deletion |
|---|---|---|
| Patient account data | Until account deletion | Immediately on account deletion |
| Doctor account data | Until account deletion | Immediately on account deletion |
| Appointment records | While account is active | Removed from live systems on account deletion, subject to limited backup retention |
| Verification documents (HPCSA cert only) | While account is active | Removed from live systems on account deletion, subject to limited backup retention |
| Push notification tokens | While active | On sign-out or account deletion |
| Doctor profile photographs | Until removed, replaced, or account deletion | Removed from live storage; temporary cached copies may persist |
| Google Calendar credentials and connection metadata | While connected | Removed after disconnect cleanup or account deletion; users may also revoke access in Google |
| Google free/busy snapshots | Rolling window of up to 90 days while connected | Replaced on refresh and deleted on disconnect |
| Practice membership and staff audit data | While membership is active; limited audit records may be retained for security and accountability | Active access removed on revocation; remaining records follow applicable retention requirements |
| Audit log (deletion record) | Indefinitely (UUID + role + timestamp only, no PII) | Not deleted, POPIA compliance record |
| Smile Identity biometric data | Per Smile Identity's retention policy | Per Smile Identity's deletion process |
You can delete your own account at any time directly within the app. See the Privacy Policy for step-by-step instructions.
7. Regulatory Compliance
| Regulation | Applicability | Status |
|---|---|---|
| POPIA (South Africa) | Primary jurisdiction and core compliance framework | Hauffi controls are designed around POPIA requirements |
| GDPR (EU / EEA) | Applies where Hauffi offers services to covered individuals | Rights and lawful bases are described in the Privacy Policy |
| UK GDPR | Applies where Hauffi offers services to covered individuals | Rights and lawful bases are described in the Privacy Policy |
| CCPA / CPRA (California) | Applies where statutory thresholds and coverage requirements are met | Hauffi does not sell personal information |
| LGPD (Brazil) | Applies where its territorial scope covers the processing | Applicable rights may be exercised through the Privacy Officer |
| PIPEDA (Canada) | Applies where its coverage requirements are met | Applicable rights may be exercised through the Privacy Officer |
| Australian Privacy Act (APPs) | Applies where its coverage requirements are met | Applicable rights may be exercised through the Privacy Officer |
| Nigerian data-protection requirements | May apply to processing performed in Nigeria | Provider processing is governed by its terms and applicable law |
8. Children's Data
Hauffi is not directed at children or minors. You must be at least 18 years old to use Hauffi. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, contact us immediately at admin@hauffi.com and we will delete it promptly.
9. Your Rights
Regardless of your location, you may exercise the following rights by emailing admin@hauffi.com:
- Access, receive a copy of your personal data
- Correction, correct inaccurate or incomplete data
- Deletion, delete your account and personal data (also available self-serve within the app)
- Restriction, limit how we process your data
- Portability, receive your data in machine-readable format
- Objection, object to processing based on legitimate interests
- Withdraw consent, withdraw any consent without affecting prior lawful processing
We respond to all rights requests within 30 days.
10. Contact
For data-related queries, subject access requests, or compliance questions:
Email: admin@hauffi.com
Hauffi, Privacy Officer
South Africa