Privacy Policy

Your privacy is fundamental to our mission. Learn how we protect and manage your data.

Last updated: June 2026

Our Commitment to Privacy

TruScript is built on the principle that patient identity and medical data must be protected by design. We implement privacy-first architecture across every layer of our platform, ensuring compliance with POPIA and international healthcare data protection standards.

1. Information We Collect

Patient Information

  • Full name and identification number (encrypted at rest)
  • Date of birth and contact information
  • Medical certificate metadata (not clinical notes)
  • Verification history and audit logs

Practitioner Information

  • Professional registration details
  • Practice information and HPCSA number
  • Digital signature credentials
  • Organisation affiliation

Usage Data

  • Authentication logs and access patterns
  • System performance metrics
  • Device and browser information

2. How We Use Your Information

  • •Certificate Issuance: To create, sign, and issue verifiable medical certificates
  • •Identity Verification: To maintain a trusted patient identity across healthcare providers
  • •Audit & Compliance: To maintain immutable audit trails required by healthcare regulations
  • •Security: To detect and prevent fraud, unauthorised access, and certificate tampering
  • •Service Improvement: To enhance platform reliability and user experience (anonymised data only)

3. Data Protection Measures

Encryption

All sensitive data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Access Control

Role-based access with multi-factor authentication and session management.

Data Minimisation

We collect only essential data required for certificate verification and issuance.

Audit Trails

Every access and modification is logged with immutable blockchain-style records.

4. Data Sharing & Third Parties

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is only shared with:

  • • Healthcare regulators when legally required for compliance audits
  • • Verification requestors who present a valid certificate token (limited metadata only)
  • • Cloud infrastructure providers under strict data processing agreements (South Africa region only)
  • • Law enforcement only with valid court orders or subpoenas

5. Your Rights

Under POPIA, you have the right to:

✓Access your personal data
✓Request corrections to inaccurate data
✓Request deletion of your data (where legally permissible)
✓Object to processing of your data
✓Receive your data in a portable format
✓Lodge a complaint with the Information Regulator

6. Data Retention & Storage

  • • Active Certificates: Retained for 7 years as required by South African healthcare regulations
  • • Audit Logs: Maintained indefinitely for compliance and security purposes
  • • Revoked Certificates: Retained with revocation status for audit trail integrity
  • • Anonymous Analytics: Retained for 24 months before deletion
  • • All data is stored in secure South African data centres compliant with POPIA

7. Contact Our Privacy Officer

For privacy-related inquiries, data subject requests, or to report a concern:

Email: privacy@gettruscript.co.za

Address: TruScript, Cape Town, South Africa

We will respond to all legitimate requests within 30 days as required by law.