Privacy
Website privacy notice
What this website collects
Booking requests collect a name, surname, mobile number, email address, requested service, appointment preference, new/returning status and an optional short booking note. Employer quote requests collect company and workforce planning information. Contact enquiries collect the details needed to respond.
Do not submit diagnoses, symptoms, test results, identity numbers or other medical-record information through these public forms. This website is an acquisition and appointment system, not an electronic health-record system.
Website usage information
The website creates a random anonymous session identifier in your browser’s session storage. It may record limited events such as a page or service viewed, booking or enquiry progress, calls, directions and WhatsApp clicks. Those events may include the page path, service, landing path, campaign parameters and the referring website’s host name. Form answers, names, contact details, free-text notes and full referring URLs are not included in these analytics events.
If Cloudflare Turnstile is enabled, the browser loads Cloudflare’s anti-spam code and the server sends the request IP address and verification token to Cloudflare Siteverify. The application does not store the raw IP address. Turnstile is currently disabled until the practice approves and configures it.
Why the information is used
The information is used to arrange, confirm, change or cancel appointments; respond to enquiries; prepare employer quotes; notify authorised practice staff; and maintain an operational history of those actions.
Systems and processors
Operational records and limited website-usage events are stored in the InsureSPR Supabase project in the European Union region selected for this project. The website is intended to be hosted by Vercel. Cloudflare will process anti-spam verification data only if Turnstile is enabled. A transactional email provider is not yet approved or configured; notification records remain queued until it is.
Security and minimisation
Browser clients cannot query operational tables directly. Public requests pass through a server-side function with validation, exact-origin CORS, rate limiting and optional anti-spam verification. Raw IP addresses are not stored by the application; a keyed hash is used for short-window abuse prevention. Booking-management tokens are stored only as cryptographic hashes.
Retention and access
The final retention schedule, staff-access process, backup policy and data-subject request procedure remain launch blockers. Until approved, no claim is made here about a specific retention period.
Your choices
You may call or email instead of using a website form. For access, correction, objection or deletion questions, contact health@insuresprhealth.co.za or call 083 450 7861. The practice must confirm the formal Information Officer contact before launch.
Draft version: pending-approval · 12 August 2026