Data & Compliance

Effective: 5 September 2026 · Last updated: 22 August 2026

This page explains in plain language exactly what data Hauffi collects from each type of user, why it is collected, how it is stored and protected, and your rights over it. Our full Privacy Policy is available at hauffi.com/privacy.

1. Data We Collect, By User Type

Patients

DataPurposeRetentionShared publicly
Full nameAccount creation and appointment matchingAccount lifetime; removed from live systems on account deletionNo
Email addressLogin, appointment confirmations, remindersAccount lifetimeNo
Phone numberContact by practitioner for appointmentAccount lifetimeNo
Medical aid selectionMatch patients with suitable booking and billing optionsAccount lifetimeNo
Medical aid name and planMatch with doctors who accept your schemeAccount lifetimeNo
Appointment historyContinuity of care and dispute resolutionWhile account is active; removed from live systems on account deletionNo
Push notification tokenAppointment reminders and status updatesUntil sign-out or account deletionNo
Walk-in billing metadataOn-demand fee authorisation, refunds, reconciliation, supportPer account lifecycle and finance/support retention needsNo
Foreground and on-demand location dataFind nearby doctors and route active walk-in requestsStored with active walk-in requests and related operational recordsNo

Healthcare Practitioners (Doctors)

DataPurposeRetentionShared publicly
Full namePublic profile, patient bookingAccount lifetimeYes, public
Optional profile photographHelp patients identify the doctor across directories, booking, appointment and referral screensUntil removed, replaced, or account deletion; temporary cache copies may persistYes, public when uploaded
Email addressLogin, notificationsAccount lifetimeNo
Phone numberVisible to booked patients onlyAccount lifetimeLimited, booked patients only
HPCSA registration numberCredential verification against HPCSA registerAccount lifetimeNo
Practice name, address, consultation feePublic doctor profileAccount lifetimeYes, public
SpecialtySearch and matchingAccount lifetimeYes, public
Medical aids acceptedSearch and matchingAccount lifetimeYes, public
HPCSA certificate (image)Admin credential verificationWhile account is active; removed from live systems on account deletionNo, admin only, signed URL
Subscription plan and statusBilling and service tier accessWhile account is active; removed from live systems on account deletionNo
Paystack authorization and payment metadataSubscription billing via PaystackWhile account is active; removed from live systems on account deletionNo
Biometric verification outcomePractitioner identity confirmation (via Smile ID)Account lifetimeNo
Verified name (from Smile ID)Admin cross-reference checkAccount lifetimeNo
Appointment historyAnalytics and dispute resolutionWhile account is active; removed from live systems on account deletionNo

Practice Managers and Receptionists

DataPurposeRetentionShared publicly
Full name and email addressAccount access, invitation, identification, and audit recordsWhile the account or practice membership is active; subject to account-deletion and audit-retention rulesNo
Practice membership and assigned roleAuthorise practice-scoped workflows and enforce permissionsWhile active plus limited audit recordsNo
Practice actionsOperate and audit appointments, availability, referrals, patient contact, on-demand requests, and co-payment documentsAccording to the retention period of the related practice recordNo
Push notification tokenPractice appointment, referral, and on-demand notificationsUntil sign-out, device revocation, or account deletionNo
Optional Google Calendar connection dataExport the practice schedule to a dedicated Google calendarWhile connected; removed after disconnect cleanup or account deletionNo

Important: Smile Identity exclusively processes and retains practitioner selfies, liveness checks, and government-issued ID documents. Hauffi stores only the verification outcome, related audit fields, the practitioner's HPCSA certificate, and verified name received from Smile Identity.

Dual-Role Accounts

If you hold both a patient profile and a healthcare practitioner profile under the same account, each profile maintains separate data records. Your patient data is governed by the patient data table above, and your practitioner data is governed by the healthcare practitioner data table. Deleting your account will delete both profiles and all associated data.

2. Data We Do NOT Collect

Hauffi is designed with data minimisation as a core principle. We do not collect:

  • Medical records, diagnoses, prescriptions, or clinical notes
  • SA ID numbers (practitioner biometric flow, captured by Smile Identity only)
  • Full card numbers or CVVs
  • Passport numbers
  • Free-text medical disclosures from patients (cancellation reasons are from a predefined list only)
  • Browsing history or cross-app tracking data
  • Advertising identifiers (IDFA, GAID)

3. Third-Party Processors

We use the following service providers under their applicable service terms and, where required, data-processing agreements:

ProviderPurposeLocationData shared
SupabaseDatabase, authentication, file storageUnited States / EUauth.users, profiles, appointments, documents
Expo (Expo Push Service)Push notificationsUnited StatesPush notification token only
Google Maps PlatformLocation and places lookupsUnited StatesPractice address search queries and location-related lookups
Google CalendarOptional appointment export and, for doctors only, free/busy conflict preventionGoogle processing locationsConnected Google email and account identifier; dedicated Hauffi calendar events; doctors’ free/busy start and end times only
PaystackPatient walk-in billing and practitioner subscriptionsJurisdictions used by PaystackMasked card metadata, payment references, authorization and refund data
ResendTransactional email deliveryUnited StatesEmail address, appointment reference
BrowserlessAutomated HPCSA public-register checks when enabledUnited StatesPractitioner name and HPCSA registration number
Smile Identity (Smile ID)Biometric identity verification (practitioners)Pan-African / USASelfie image, liveness, government-issued ID document, verification outcome and verified name
OpenAIDoctor portal analytics assistantUnited StatesAggregated practice analytics only; no patient records

We do not share data with any advertising networks, data brokers, or analytics platforms that track individuals across services.

3.1 Optional Google Calendar Data

Google Calendar is connected only when a doctor, practice manager, or receptionist affirmatively chooses to connect an account and approves Google's authorization screen. Hauffi requests permission to create and manage only its dedicated secondary calendar. For doctors, Hauffi also requests free/busy access to the primary calendar.

DataPurposeRetentionShared publicly
Google account email and identifierIdentify and display the connected accountWhile connectedNo
Encrypted OAuth refresh tokenMaintain the user-authorised connection without repeated sign-inWhile connected; deleted after disconnect cleanup or account deletionNo
Doctor free/busy start and end timesRemove patient booking times that overlap a doctor’s Google busy periodsRolling scheduling window of no more than 90 days; replaced on refreshNo
Managed-calendar and webhook identifiersDeliver, monitor, and renew Calendar synchronizationWhile connectedNo
Hauffi appointment event dataCreate the dedicated Google calendar scheduleHeld by Google until the event/calendar is removed under Google’s retention behaviorVisible only according to the connected Google account’s sharing settings

Hauffi does not read or store the title, description, attendees, location, or content of a doctor's primary-calendar events. Events written to the dedicated Hauffi calendar contain the patient's first name and surname initial, appointment time and status, practice name, and a Hauffi appointment link and identifier.

Hauffi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. It is not sold, used for advertising or credit decisions, or used to train general-purpose AI models.

4. Biometric Data (Smile Identity)

Biometric verification for healthcare practitioners is performed by Smile Identity, a pan-African identity verification provider that processes practitioner verification information under its applicable terms and privacy policy.

What Smile Identity processes

  • A real-time selfie captured within the Smile Identity secure environment
  • Your government-issued identity document (SA ID or passport)
  • A liveness check to confirm the selfie is of a live person
  • A comparison of your selfie against your ID document photo

What Hauffi receives from Smile Identity

  • Verification outcome and related audit fields
  • Your verified full name as it appears on your ID document

What we do not receive

  • Your full card details from payment providers
  • Medical records, diagnoses, prescriptions, or clinical notes

Smile Identity retains biometric data for the period necessary to complete verification and in accordance with their Privacy Policy. By proceeding with biometric verification, you consent to Smile Identity processing your data for this purpose.

5. Data Storage and Security

Where your data is stored

Hauffi uses Supabase as its primary data platform. Supabase stores data on AWS infrastructure. Our primary production database region is eu-central-1 (Frankfurt, Germany), with Supabase managing replication and backups.

Encryption

  • In transit: TLS 1.3 for all data moving between your device and our servers
  • At rest: encryption for stored data, including uploaded documents

Access controls

  • Row-Level Security (RLS) is enabled on every database table, patients can only access their own data
  • Practitioners can only access their own profile and data for appointments they are booked in
  • Active practice managers and receptionists receive only practice-scoped access required for their assigned workflows; access is removed when membership is revoked
  • Doctor profile photographs are intentionally public when uploaded; only the owning doctor can upload, replace, or remove the object
  • Uploaded HPCSA certificates are stored in a private bucket with no public URL, accessible only via time-limited signed URLs (1-hour expiry) generated for authorised admin reviewers
  • Admin access is role-restricted and requires authentication

Backup retention

  • Automated backups are encrypted at rest using the same encryption as live systems (AES-256)
  • Backup copies are retained for a maximum of 30 days for operational recovery purposes only
  • Deleted account data may persist in backups until the 30-day retention period expires

6. Data Retention and Deletion

Data typeRetention periodDeletion
Patient account dataUntil account deletionImmediately on account deletion
Doctor account dataUntil account deletionImmediately on account deletion
Appointment recordsWhile account is activeRemoved from live systems on account deletion, subject to limited backup retention
Verification documents (HPCSA cert only)While account is activeRemoved from live systems on account deletion, subject to limited backup retention
Push notification tokensWhile activeOn sign-out or account deletion
Doctor profile photographsUntil removed, replaced, or account deletionRemoved from live storage; temporary cached copies may persist
Google Calendar credentials and connection metadataWhile connectedRemoved after disconnect cleanup or account deletion; users may also revoke access in Google
Google free/busy snapshotsRolling window of up to 90 days while connectedReplaced on refresh and deleted on disconnect
Practice membership and staff audit dataWhile membership is active; limited audit records may be retained for security and accountabilityActive access removed on revocation; remaining records follow applicable retention requirements
Audit log (deletion record)Indefinitely (UUID + role + timestamp only, no PII)Not deleted, POPIA compliance record
Smile Identity biometric dataPer Smile Identity's retention policyPer Smile Identity's deletion process

You can delete your own account at any time directly within the app. See the Privacy Policy for step-by-step instructions.

7. Regulatory Compliance

RegulationApplicabilityStatus
POPIA (South Africa)Primary jurisdiction and core compliance frameworkHauffi controls are designed around POPIA requirements
GDPR (EU / EEA)Applies where Hauffi offers services to covered individualsRights and lawful bases are described in the Privacy Policy
UK GDPRApplies where Hauffi offers services to covered individualsRights and lawful bases are described in the Privacy Policy
CCPA / CPRA (California)Applies where statutory thresholds and coverage requirements are metHauffi does not sell personal information
LGPD (Brazil)Applies where its territorial scope covers the processingApplicable rights may be exercised through the Privacy Officer
PIPEDA (Canada)Applies where its coverage requirements are metApplicable rights may be exercised through the Privacy Officer
Australian Privacy Act (APPs)Applies where its coverage requirements are metApplicable rights may be exercised through the Privacy Officer
Nigerian data-protection requirementsMay apply to processing performed in NigeriaProvider processing is governed by its terms and applicable law

8. Children's Data

Hauffi is not directed at children or minors. You must be at least 18 years old to use Hauffi. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, contact us immediately at admin@hauffi.com and we will delete it promptly.

9. Your Rights

Regardless of your location, you may exercise the following rights by emailing admin@hauffi.com:

  • Access, receive a copy of your personal data
  • Correction, correct inaccurate or incomplete data
  • Deletion, delete your account and personal data (also available self-serve within the app)
  • Restriction, limit how we process your data
  • Portability, receive your data in machine-readable format
  • Objection, object to processing based on legitimate interests
  • Withdraw consent, withdraw any consent without affecting prior lawful processing

We respond to all rights requests within 30 days.

10. Contact

For data-related queries, subject access requests, or compliance questions:

Email: admin@hauffi.com
Hauffi, Privacy Officer
South Africa

© 2026 Hauffi. All rights reserved. Privacy Policy · Terms of Use · Doctor Portal