Privacy
Website privacy notice
Who is responsible
Responsible party: InsureSPR Precision Healthcare. Designated Information Officer: Motselisi R. Mosiana, designated by the owner on 21 August 2026. Privacy requests may be sent to motselisi@bonevc.co.za. This designation is recorded; the website does not claim that Information Regulator registration is complete until the registration record is held by the practice.
What this website collects
Booking requests collect a name, surname, mobile number, email address, requested service, appointment preference, new/returning status and an optional short booking note. Employer quote requests collect company and workforce planning information. Contact enquiries collect the details needed to respond.
Do not submit diagnoses, symptoms, test results, identity numbers or other medical-record information through these public forms. This website is an acquisition and appointment system, not an electronic health-record system.
Why and on what basis it is used
Information is used to take steps requested by you, arrange and manage appointment requests, respond to enquiries, prepare employer quotes, protect the service against abuse, notify authorised staff and keep evidence of consent and operational actions. Where special personal information is processed, it is limited to what is necessary for a requested healthcare or occupational-health pathway and handled under applicable POPIA and professional duties. The public forms are not used for automated clinical decisions or direct marketing.
Website usage information
The website creates a random anonymous session identifier in your browser’s session storage. It may record limited events such as a page or service viewed, booking or enquiry progress, email clicks and directions clicks. Those events may include the page path, service, landing path, campaign parameters and the referring website’s host name. Form answers, names, contact details, free-text notes and full referring URLs are not included in these analytics events.
When Cloudflare Turnstile is enabled, the browser loads Cloudflare’s anti-spam code and the server sends the request IP address and verification token to Cloudflare Siteverify. The application does not store the raw IP address. Turnstile is not active until both approved keys are configured.
Systems, processors and transfers
Operational records and limited website-usage events are stored in the InsureSPR Supabase project in the European Union. Vercel hosts and delivers the website. Cloudflare will process anti-spam verification data only when Turnstile is enabled. Resend is the selected transactional-email provider but will receive no queued message until its sending domain, processor configuration and delivery worker are activated. Cross-border processing is limited to these stated purposes and must be supported by the safeguards or other basis required by POPIA section 72.
Security and minimisation
Browser clients cannot query operational tables directly. Public requests pass through a server-side function with validation, exact-origin CORS, rate limiting and fail-closed anti-spam verification. Raw IP addresses are not stored by the application; a keyed hash is used for short-window abuse prevention. Booking-management tokens are stored only as cryptographic hashes.
Retention
- Incomplete or spam submissions: up to 90 days.
- Unconverted contact enquiries and employer leads: 24 months after last activity.
- Booking requests, booking history and consent evidence: 6 years after last booking activity.
- Notification delivery metadata: 12 months after its terminal state.
- Anonymous website analytics: 13 months.
- Rate-limit records: no more than 30 days; booking-management credentials expire after 90 days.
- Security and audit evidence: 6 years after closure, unless a documented legal hold requires longer.
If a website record becomes part of a clinical or statutory occupational-health record, that record’s separately approved professional retention rule applies. Information is deleted, de-identified or placed in a restricted archive when its period ends.
Your rights and request process
You may ask for access, correction, deletion, restriction or object to processing by emailing motselisi@bonevc.co.za. The practice will acknowledge the request, verify identity proportionately, search the relevant website systems and explain the outcome. A record subject to a legal hold, active complaint, security incident or another statutory duty may be restricted rather than erased.
Prescribed objection, correction/deletion and complaint forms are available from the Information Regulator. You may also use the Regulator’s eServices portal.
Security compromises
InsureSPR will contain and investigate a suspected compromise, preserve evidence and notify the Information Regulator and affected people as required. Provider incidents must be escalated to the responsible party without delay.
Publication version: 2026-08-21.1 · approved 21 August 2026