Masoom Training Solutions

Privacy Notice

Masoom Training Solutions (Pty) Ltd  |  Reg. 2011/000057/07  |  B-BBEE Level 1
Version 9  |  Updated 27 August 2026  |  Supersedes Version 8 of 7 August 2026

This notice explains, in plain language, what personal information Masoom Training Solutions (“MTS”, “we”) collects about you, why we collect it, who can see it, and what you can do about it. It covers our training programmes and the CRICE desktop and mobile applications. We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

1 Who we are and who this covers

In short: MTS holds your information in trust. This notice covers everyone whose information passes through our training programmes and the CRICE system.

Masoom Training Solutions recognises that the personal information it receives is held in a position of trust. This notice sets out how we collect, use, share and otherwise process that information — lawfully, ethically, and in line with industry best practice.

CRICE (Company Representative in Clinical Environment Programme) is a credentialing and access-verification system initiated and developed by members of the healthcare supplier industry and subsequently adopted by participating healthcare facilities as part of their representative access-control requirements.

This notice applies to you if you are:

  • a Learner enrolled in one or more MTS training programmes;
  • a Company Representative using CRICE to access healthcare facilities;
  • an Independent Sales Agent registered directly with MTS to access healthcare facilities;
  • a Company Point of Contact administering representatives on our platform;
  • a Hospital Point of Contact or Appointment Person at a facility;
  • a practitioner or practice that chooses to receive appointments through CABS;
  • a visitor to our website, or anyone who contacts us as a customer, supplier or partner.

MTS is an independent credentialing body. We are not engaged by supplier companies to administer their employees on their behalf: our purpose is patient and staff safety, by ensuring that representatives entering a healthcare facility are trained, declared and identifiable.

MTS is the responsible party for the information described in this notice. Our Information Officer is Fathima Amod, Managing Director of Masoom Training Solutions, registered with the Information Regulator and reachable at info@masoom.co.za. Our PAIA manual is published at masoom.co.za and crice.co.za.

↑ Return to contents

2 The words we use

In short: A few terms come up throughout this notice. Here is what each one means.
  • Client (Supplier Company) — a supplier of medical products to the healthcare industry: pharmaceutical, IVD and medical device companies. Clients buy CRICE from us.
  • Company Representative (CR) — an employee of a Client who needs access to healthcare facilities to sell, educate on, support or maintain medical products.
  • Company Point of Contact (Company POC) — the employee a Client assigns as the primary contact for MTS, and who administers that company’s representatives.
  • Hospital Point of Contact (HPOC) and Appointment Person (AP) — the people based in a healthcare facility who receive and manage representative appointments.
  • Learner — any person enrolled in one or more MTS training programmes.
  • Operator — a service provider that stores or processes personal information on our instruction under a written agreement (POPIA s20–21). For CRICE this means our cloud hosting provider (Amazon Web Services).
  • Responsible party — the organisation that decides why and how personal information is processed. For the CRICE system, that is MTS.

↑ Return to contents

3 What we collect and when

In short: Contact details, a date of birth, training records, and a record of your facility check-ins and appointments. We no longer collect identity numbers.

We collect a date of birth, not an identity number. It is used for one narrow purpose: telling apart two people with the same or a similar name, so that a certificate and an access card are issued to the right person. We do not collect identity numbers at all, and we do not ask for any information beyond what is listed below.

When we collect it

  • When you complete an application form or contact us electronically.
  • When you visit our websites, use the in-app contact feature, buy or use our products and services, or deal with us as a customer, supplier or business partner.
  • When you register on our platforms to be considered for, or enrol in, an MTS training programme.
  • When you send us a CV or resume — including work history, qualifications, publications, awards, references, completed training and your signature.
  • When a CR scans the Digital CRICE Access Card on entering and exiting a healthcare facility.
  • When a CR books a meeting through the CRICE Appointment Booking System (CABS).
  • When we maintain the electronic visit log recording representatives’ presence in facilities.
  • When you take part in MTS online communities, including social media platforms.
  • When we resolve a technical, product or service issue for you.

What we hold, by role

If you are a…We may hold
Company Point of Contact Name, date of birth, work email address, work contact number.
Company Representative Name, date of birth, email address, contact number, digital photograph (see section 8), and confirmation of Hepatitis B vaccination status or exemption (see section 13).
Hospital Point of Contact / Appointment Person Name, work email address, work contact number — entered at the point of booking and not maintained by us as a contact database (see section 9).
Observer Name and professional registration number.
Learner Name, date of birth, email address, contact numbers, qualifications, certifications, work experience, education, publications, awards, references, completed training and signature.

How CRICE accounts are set up

  • A Client registers with MTS and appoints a Company Point of Contact. That person receives this privacy notice, consents to their own information (name, date of birth and business contact details) being used to set up their account, and undertakes to give this notice to each representative and to obtain that representative’s consent before enrolling them.
  • The Company POC gets a secure portal to enrol their own staff. We do not enrol representatives ourselves.
  • The Company POC stays in full control of those accounts and can enrol, transfer or deactivate them at any time.
  • A representative downloads the mobile Digital CRICE Access Card themselves, and grants the camera and location permissions needed at the moment of scanning.
  • The representative makes every input on the CRICE app themselves and is free to choose whether to do so.

MTS built this client-controlled portal specifically so that the Company Point of Contact — not MTS — enrols and manages their own representatives: MTS does not solicit or capture a representative’s personal information directly, and receives it only where a representative enters it themselves on the CRICE app, or where the Company Point of Contact enrols staff (having first given them this notice and recorded their consent).

Independent sales agents. Some people who use CRICE are independent sales agents rather than a company’s employees, and are not administered by a Company Point of Contact. For them, MTS acts as the point of contact: they are registered directly with MTS and give their consent directly to us for the information CRICE processes about them, on the same basis and with the same protections set out in this notice.

CRICE was designed around confidentiality and consent — a secure, client-controlled portal, and real-time permission prompts rather than blanket permissions. Its design and terms comply with POPIA, the Electronic Communications and Transactions Act 25 of 2002, and the Consumer Protection Act 68 of 2008.

↑ Return to contents

4 Why we collect it, and our lawful grounds

In short: To deliver training, issue certificates, and give facilities a reliable record of who entered and when. POPIA gives us six possible grounds; consent is only one of them, and we say which one we rely on for each purpose.
What we doOur POPIA ground
Enrol you, track your progress and issue your certificate Performance of a contract — s11(1)(b)
Create the electronic visit and attendance register when you scan in and out Legitimate interests of MTS, the facility and your employer — s11(1)(f); and the facility’s own legal duties for access control
Manage appointments through CABS Performance of a contract — s11(1)(b); legitimate interests — s11(1)(f)
Verify your identity at a facility using your photograph Legitimate interests in patient and staff safety and fraud prevention — s11(1)(f)
Hold your health declaration Your explicit consent for special personal information — s27(1)(a), alongside occupational health and safety obligations
Send you marketing about our services Your opt-in consent — s69
Keep records the law requires us to keep Compliance with a legal obligation — s11(1)(c)

Facilities use the visit register to monitor and control access, investigate incidents or complaints, and verify training and technical input by representatives. The appointment record holds the representative’s and appointment person’s details, the reason for the visit and the product name.

Where we rely on legitimate interests, you have the right to object on reasonable grounds relating to your particular situation, under section 11(3) of POPIA. See section 18.

↑ Return to contents

5 Location — exactly how it works

In short: CRICE does not track your movements. Location is read only when you actively check in at a facility, only while the app is open, and we store which facility you visited — not a trail of where you go.

We want to be especially clear about location, because we know it’s the thing people worry about most:

  • Only at check-in. Your device’s location is read at the single moment you tap to check in at a facility — to confirm you are within range of that site.
  • No background tracking. The app cannot access your location when it is closed or running in the background. It has no “always-on” location permission.
  • No movement trail. Your check-in record stores which facility you visited and when — not your GPS coordinates or your route.
  • You’re in control. Location is only requested when needed, and you can decline the permission on your device.

↑ Return to contents

6 Who can see your information

In short: Your employer’s coordinator and the facilities you visit can see your compliance status. We use a small number of trusted service providers, all bound to protect your data.
  • Your Point of Contact / employer — your enrolment, progress and compliance status.
  • Facilities you check in at — confirmation of your visit and access status. A copy of the visit register goes only to the facility you actually entered, its facility group, and your Company POC.
  • Trusted service providers (“operators”) — our cloud hosting provider and our email/SMS notification providers. They process data only on our instructions, under written operator agreements as required by section 21 of POPIA.

Once a visit register reaches a facility, that facility decides how long to keep it and how to use it for its own access-control purposes, and is accountable for it under POPIA. If your question concerns a facility’s own copy of a record, approach that facility; if it concerns what MTS holds, approach us.

The only times we’ll disclose without your consent

  • Where the law or a court order requires it.
  • Where disclosure is in the public interest.
  • Where it is necessary to establish, exercise or defend a right in law.

↑ Return to contents

7 Where your information is stored

In short: Your information is stored in South Africa and we do not transfer it abroad.

The CRICE platform is hosted on Amazon Web Services in the Africa (Cape Town) region, so your personal information is stored in South Africa, and access to the production environment is restricted to South African connections — it cannot be reached from outside the country. Our email and office-productivity providers are likewise configured to keep your information within South Africa.

We do not transfer your personal information outside South Africa. Were that position ever to change, we would first put in place a lawful basis and the cross-border safeguards required by section 72 of POPIA — including written assurances that require a level of protection equivalent to our own — before any transfer took place.

↑ Return to contents

8 Your photograph and how we verify identity

In short: Your photograph appears on your Digital CRICE Access Card so facility staff can see that the card belongs to the person presenting it. It is not facial recognition, and we do not use it for anything else.

A digital photograph is part of your Digital CRICE Access Card, so that a person at the facility can confirm the card belongs to you. The check is done by a human being, not by software.

How the check actually works

  • The first time you check in at a facility, the staff member at the pharmacy holds a Unique Site Number (USN), issued to them separately along with that site’s QR codes.
  • Entering the USN releases your photograph on screen, and the staff member compares it with you, standing in front of them.
  • That is the whole mechanism. A person looks at a picture and a face. Nothing is measured, computed or matched automatically.

It exists for two reasons, and no others:

  • To confirm the right person is on site. Facilities admit representatives into clinical areas where patients and controlled stock are present. They are entitled to know that the person in front of them is the person the card was issued to.
  • To prevent fraudulent use of the access card. A card without a photograph can be lent, shared or used by someone whose training or vaccination declaration has never been made. The photograph closes that gap.

Equally important is what the photograph is not:

  • It is not facial recognition. No facial template, faceprint or biometric measurement is created, stored or compared, at any point, by MTS or by any facility.
  • It is not shared beyond the parties listed in section 6.
  • It is not used for marketing, publication, or any purpose unrelated to access control.
  • It is not accessible to anyone once your CRICE account is deactivated, and your photograph and entire account contents are removed when the account is deleted.
Why this distinction matters. POPIA defines “biometrics” as a technique of personal identification based on physical, physiological or behavioural characterisation, and section 26 makes biometric information “special personal information” that may not be processed unless section 27 applies. A photograph a person looks at is ordinary personal information; a photograph fed into an automated matching system is biometric information. The USN process is deliberately manual, and MTS will not introduce automated facial matching without giving notice and obtaining fresh, specific consent.

↑ Return to contents

9 Appointments and business contact details

In short: Appointment person details are used to arrange that one meeting and are not stored in any MTS database — no contact table, no directory, no address book, no marketing list.

Booking a meeting requires knowing who the meeting is with. When a Company Representative books through CABS, they enter the Appointment Person’s work name, work email address and work telephone number — details the facility has already made available for exactly this purpose, and which the appointment person gives out in the ordinary course of their job.

We do not keep them

This is the part worth stating plainly. Those details are used to arrange and confirm the appointment. They are not written to any MTS contact table, directory, address book or autocomplete, and no appointment person record is retained. There is nothing to compile, nothing to sell and nothing to market to, because the data is not held.

  • We do not build a directory of hospital staff, and we could not produce one if asked.
  • We do not sell, rent, licence or share appointment person details with anyone beyond the facility concerned and the booking representative’s Company POC.
  • We do not use them for direct marketing of any kind. We do not market to appointment persons at all.
  • We do not carry them across to a different Client, a different representative or a future booking. Each booking is entered afresh.

Why this is lawful

POPIA sets out six lawful grounds for processing in section 11(1), of which consent is only one. This processing rests on the following:

  • Necessary to perform the arrangement — section 11(1)(b). A meeting cannot be confirmed without an address to confirm it to.
  • Legitimate interests — section 11(1)(f): the facility’s interest in controlled, scheduled access; the representative’s interest in an auditable booking; and the appointment person’s own interest in not being visited unannounced.
  • Minimality — section 10. Work details only. CABS does not ask for, and will not accept, a home address, personal email address, personal mobile number, identity number or date of birth for an appointment person.

If you are an Appointment Person and would prefer your work details were not used this way, write to info@masoom.co.za. Section 11(3) of POPIA gives you a right to object where we rely on legitimate interests, and we will act on it.

↑ Return to contents

10 Practitioners’ consulting rooms

In short: Consulting rooms inside a hospital are not separately access-controlled by CRICE. You check in at the hospital entrance as usual; the practitioner’s rooms themselves are exempt.

Many healthcare practitioners consult from rooms located within a hospital facility, where the only way to reach those rooms is through a hospital entrance door. Because the representative has already passed through that entrance, the hospital’s own access control applies and the visit is recorded there.

The consulting rooms are not separately controlled by CRICE. A practitioner is under no obligation to operate access control over their own rooms, to register with CRICE, or to participate in any way, and nothing in this notice imposes such an obligation.

If a practitioner chooses to use CABS

Some practitioners find the appointment booking system useful and choose to accept bookings through it. That is a voluntary election, made by providing their booking details and asking representatives to use the system, and it can be reversed at any time by telling the representative or writing to info@masoom.co.za.

The booking details a practitioner gives for that purpose are handled exactly as described in section 9: used to arrange the appointment, and not stored in any MTS database. This is separate from the doctor names a representative records at check-out, which are dealt with in section 11 — and which are recorded only for engagements inside a facility, never for a visit to a doctor’s own rooms. Representatives are required to explain this before entering a practitioner’s details, and Company Points of Contact must cover that obligation when briefing their representatives — see section 12.

↑ Return to contents

11 Doctors named at check-out

In short: When a representative checks out of a facility, they record which doctor they engaged with about a product or equipment inside that facility. We keep that name in the visit record for governance and traceability — never for marketing. Engagements in a doctor’s own consulting rooms are not recorded at all.

What we record, and what we do not. At check-out a representative is asked: “Which doctor(s) did you engage with, during this visit, regarding the use of these product(s) or equipment(s)?” The prompt tells the representative to answer only for engagements inside the facility, and not for doctors seen in their own consulting rooms, and that the answer is recorded with the visit and visible to the facility and to their company. We record the doctor’s name and the product or equipment concerned, and nothing else — no contact details, no clinical detail, no patient information, and no assessment of the doctor.

Consulting rooms stay outside this. Section 10 of this notice explains that consulting rooms are not access-controlled by CRICE and that a doctor is under no obligation to participate. That remains true. A visit to a doctor in their own rooms is not recorded here, and a doctor who practises from rooms is not brought into CRICE by this section.

Why doctors are treated separately. Doctors are independent practitioners. They are not employed by the facility, and their details are not provided to us by it. That is different from Hospital Points of Contact, whose details the facility itself supplies to us for loading, and from Appointment Persons — hospital staff whose work details a representative enters into CABS solely to arrange one meeting, and which we do not retain (section 9). Because a doctor’s name reaches us from the representative and from no one else, it needs its own basis, which is set out below.

Why we record it, and our lawful ground. We process this on the ground of legitimate interests — section 11(1)(f) of POPIA — being the interests of the healthcare facility, of the supplier company and of MTS in an accurate record of what took place inside a clinical area. Those interests are: enabling a facility to reconstruct who was present and in connection with what, if an incident, complaint or infection-control query arises; supporting product traceability, vigilance and recall, where knowing which product was involved and with whom is the starting point of any investigation; and evidencing that access was used for a legitimate business purpose. Because we obtain the name from the representative rather than from the doctor, we rely on sections 12(2)(c), 12(2)(d)(v) and 12(2)(f) of POPIA: collecting it this way does not prejudice the doctor, it maintains the legitimate interests described above, and direct collection at the point of a clinical interaction is not reasonably practicable.

Who can see it. The healthcare facility whose premises were entered, and the supplier company that employs the representative. It is not published, not sold, and not shared with any other party.

What it is never used for. We do not use doctors’ names for marketing, and we do not permit them to be used to rank, score, target or set commercial objectives in respect of any doctor. Company Points of Contact must enforce this within their organisations, and any such use is a breach of the terms on which access to the record is given.

How long we keep it. Five years, with the visit register it forms part of, after which it is destroyed or de-identified.

If you are a doctor. You may ask us what we hold about you, ask us to correct it, or object to this processing at any time under sections 5, 11(3), 23 and 24 of POPIA, by writing to info@masoom.co.za. If you object, we will stop recording your name in new visit records unless we are legally required to continue, and we will tell you the outcome in writing.

↑ Return to contents

12 Consent, and who obtains it

In short: Your employer obtains your consent before entering your details on CRICE, and confirms to MTS that it has done so. This has always been the requirement. This section sets out what that consent covers, so that every representative can see it for themselves.

Under POPIA, an employer is the responsible party for the personal information of its own employees. Obtaining a representative’s consent is therefore the employer’s obligation, not MTS’s, and it has been a standing condition of using CRICE since the system was introduced: consent must be obtained before personal information is entered on MTS platforms. The requirement applies to every enrolment, past and present.

By enrolling a representative, a Company confirms to MTS that it holds that consent, that it was obtained before enrolment, and that it covers the matters set out below. Companies warrant this to MTS under their agreement with us, undertake to keep a dated record of each consent, and undertake to produce those records to MTS on request. MTS relies on that confirmation and does not obtain consent from representatives directly.

We set the position out here, in the notice itself, rather than in a separate form, so that any representative, appointment person or practitioner can read what they have agreed to without having to ask anyone for a document.

For every enrolment, the Company Point of Contact must

  1. Give them this notice. Send them the link, or print it. Making it available somewhere they could find it is not the same as giving it to them.
  2. Obtain and record their consent covering the items listed below, and keep that record for as long as the person remains enrolled.

A Company Point of Contact who enters healthcare facilities is a data subject as well as an administrator. Administering the portal does not cover you in your own right — your consent must be recorded in the same way, countersigned by a fellow director or your line manager.

What the consent covers

Most of what CRICE does does not depend on consent, and that is deliberate. Access control, the visit register and identity verification rest on sections 11(1)(b) and 11(1)(f) of POPIA — performance of the arrangement, and the legitimate interests of the facility, the employer and patient safety. You are informed of these rather than asked to agree to them, and you may object on reasonable grounds under section 11(3). Consent is sought where the law requires it, and separately.

1. Matters you are informed of

  • Enrolment — your name, date of birth, work email address and contact number are entered by your employer. No identity number is collected.
  • Your photograph — it appears on your Digital CRICE Access Card, and on your first check-in at a facility a staff member displays and compares it with you, to confirm the card is yours and to prevent it being shared or misused. This is a visual check by a person, not facial recognition.
  • Location at check-in — your device location is read only at the moment you tap to check in, and at no other time. Your route is never recorded.
  • The visit and attendance register — shared with the facility you enter, its facility group and your employer’s Point of Contact, and retained by the facility to control access, investigate incidents or complaints and verify training.
  • Appointment bookings — including your obligation, as a representative, to explain to an appointment person or practitioner how their work contact details are used before entering them.

2. Matters requiring your explicit consent

  • Your health declaration. Health information is protected more strictly and may not be processed at all without your express consent, under sections 26 and 27(1)(a) of POPIA. Your employer must obtain that consent separately and record it. Declining is a real choice: section 13 sets out the route that applies where a representative is not vaccinated, and it does not require you to disclose a medical reason to MTS or to anyone else.

3. Optional matters

  • Use of photographs or video of you in external publications and marketing.
  • Receiving information from MTS about new training, products and services.

These are genuinely optional and severable. Declining them changes nothing else about your enrolment.

Withdrawing consent

You may withdraw the consents in categories 2 and 3 at any time, by telling your Point of Contact or writing to info@masoom.co.za. Withdrawing your health declaration consent means facilities cannot admit you, because they cannot make an admission decision without it. Withdrawal does not affect the lawfulness of processing already carried out.

Other duties of the Point of Contact

  • Deactivate accounts promptly when a representative leaves or changes role.
  • Keep portal credentials confidential and do not share a single login across staff.
  • Tell us without delay if an account or card may have been compromised, shared or used fraudulently.
  • Pass on any request from a representative to access, correct or delete their information, or forward it to info@masoom.co.za.

MTS does not enrol representatives on a Client’s behalf unless specifically asked to, and where we do, we act on the instruction on the basis that consent has already been obtained.

↑ Return to contents

13 Your health declaration

In short: You make a declaration in your own name — we do not collect medical records, certificates, vaccination records or test results. You are never asked about your HIV or AIDS status, and MTS holds no clinical information about you.

Healthcare facilities need assurance about infection risk before admitting a representative to clinical areas. Rather than collecting any medical evidence, CRICE asks you to make a declaration in your own name, which you sign electronically when your Digital CRICE Access Card is issued. It is an attestation by you — not a request for medical records. In the declaration you confirm the following.

What you declare

  • Training. You have completed the relevant product, disease-area and clinical-environment training (and any other relevant speciality training) and hold the relevant certification, and you will keep this up to date for any new products or disease areas.
  • Infection prevention. You understand the risks of transmitting or contracting infectious diseases in a theatre or hospital environment; you will comply with each facility’s infection prevention and control requirements; and you will not enter a clinical area while you know, or have been medically advised, that you have a transmissible infectious condition — managing any such event through your company’s occupational-health function.
  • Hepatitis B. Because hepatitis B vaccination is a condition of admission to clinical areas set by healthcare facilities, you confirm either (a) that you have completed the hepatitis B vaccination course (and, where required, can confirm protective immunity) — your vaccination record and any antibody result being held by you and/or your employer, and not submitted to or retained by Masoom Training Solutions or the facility; or (b) that your employer has assessed the risk and given you a written Declaration of Risk Assessment confirming either that you do not enter clinical areas (low risk, and therefore exempt), or that you have begun the vaccination course and your interim access to clinical areas is being managed.

Where (b) applies, the Declaration of Risk Assessment is held by you and your employer. It may be requested by MTS or the relevant facility as proof that a risk assessment was done, with all personal health information redacted, and you retain it for three (3) years. MTS does not hold it.

What we hold, and what we deliberately do not

  • We hold your signed declaration and the date you signed it, together with your name, company, reference number and signature — the minimum needed to issue your Digital CRICE Access Card. Nothing more.
  • We do not hold vaccination certificates, titre or antibody results, Declarations of Risk Assessment, clinical notes, diagnoses, test results, medical certificates or occupational-health assessments. If one is sent to us in error it is deleted, and we ask for the declaration instead.
  • We do not hold any reason for a representative being unvaccinated. We do not ask, and we do not want to know.
  • We do not verify your declaration against any medical source, and we do not ask your doctor, your medical scheme or your employer for anything clinical.

Clinical information

Masoom Training Solutions holds no clinical information about you. Any health assessment, and any clinical detail arising from it, remains between you and your employer. Where clinical input is ever needed, it passes between your employer’s occupational-health advisor and the facility’s — it does not pass through MTS. If you are pregnant or breastfeeding and have been advised not to be vaccinated, your employer provides only the dates for which access is required: no reason, no diagnosis and no medical certificate is requested or accepted.

HIV and AIDS

You are under no obligation to disclose your HIV or AIDS status, at all. CRICE does not ask for it, has no field to record it, and it forms no part of any admission decision. This is stated expressly in the declaration you sign. It reflects both the sensitivity of that information under POPIA and the protections in South African employment law, which prohibit employers from testing an employee for HIV without authorisation from the Labour Court.

Voluntary, and minimal

You make this declaration of your own free will. The personal information in it is processed solely for facility-access credentialing, in line with the minimality principle of the Protection of Personal Information Act, 2013 (POPIA).

↑ Return to contents

14 How we keep it safe

In short: A documented information security policy, layered technical controls, staff access limited to what each role requires, and infrastructure built on an independently assessed platform.

We take appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and to prevent unlawful access to or processing of it. We identify foreseeable internal and external risks, establish safeguards against them, verify that those safeguards are working, and update them as new risks emerge.

Our controls

  • Identity and access management. Staff can reach only the systems and information their role requires, on a least-privilege basis. Everyone with access has completed privacy training and is bound by a written confidentiality undertaking.
  • Data loss prevention. Technical safeguards restrict the transmission of personal information outside our network.
  • Encryption in transit and at rest. Information moving between your device and our servers travels over an encrypted HTTPS connection, so it cannot be read if intercepted. Information stored on our systems is held using AWS storage encryption, so that the underlying media and backups are unreadable without authorised access.
  • Logging and monitoring of access to and use of personal information.
  • Incident response. A documented plan under which, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we notify both the Information Regulator and the affected data subjects as soon as reasonably possible, as section 22 of POPIA requires.
  • Physical, computer and network security, and secure communications.
  • Secure retention and disposal of information at the end of its life.
  • Operator terms. Providers that process personal information on our behalf do so under written terms as contemplated by section 21 of POPIA. Our hosting provider’s security, data protection and breach notification obligations are set out in its published terms and data processing addendum.

Why our hosting choice supports this

Section 19(3) of POPIA does not prescribe a specific technology. It requires us to have due regard to generally accepted information security practices and procedures. The reasoning we apply is straightforward:

  • The frameworks published by the United States National Institute of Standards and Technology — the NIST Cybersecurity Framework, and the control catalogue in NIST SP 800-53 — are among the most widely adopted information security practices in the world, and are exactly the kind of standard section 19(3) points to.
  • Our hosting provider’s infrastructure is independently assessed against those frameworks: AWS holds a FedRAMP authorisation, which is built on the NIST SP 800-53 control baseline, and aligns its services to the NIST Cybersecurity Framework. It is also certified to ISO/IEC 27001, 27017 (cloud security) and 27018 (protection of personal information in the cloud), and reports under SOC 1, SOC 2 and SOC 3.
  • Under the shared responsibility model, AWS secures the infrastructure of the cloud, and MTS is responsible for what it builds in the cloud — configuration, access control, encryption keys and application security.
  • It follows that CRICE inherits an independently assessed control baseline at the infrastructure layer, and MTS’s own controls are informed by the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover).
A note on wording. Certification belongs to the platform, not automatically to everything built on it. MTS does not claim to be “NIST certified” — the Cybersecurity Framework has no certification scheme. What MTS says is that its controls are informed by that framework, and that it hosts on infrastructure independently assessed against NIST-derived baselines.

↑ Return to contents

15 Our confidentiality commitment

In short: Your information stays inside a closed loop — you, your Point of Contact, the facility you actually entered, and our vetted operators. It is never sold, never rented, never traded, and never disclosed to anyone outside that loop except where the law compels us.

We want to state this without hedging, because it is the commitment our clients and their representatives rely on most.

  • We have never sold personal information, and we never will. Not to data brokers, not to advertisers, not to market research firms, not to anyone. It is not a revenue line, and it is not available at any price.
  • We do not rent, trade, licence or barter it, and we do not disclose it to unaffiliated third parties for their own direct marketing or any other independent purpose.
  • We do not use it for advertising, profiling, or automated decision-making about you.
  • We do not pool it across Clients. One Client cannot see another Client’s representatives, and no backend information is shared between Clients or between facilities.
  • Disclosure is limited to the closed loop in section 6 — you, your Company POC, the facility you actually entered and its facility group, and operators acting solely on our written instruction.

The single, narrow exception is compulsion by law. Where a court order, a statute or a lawful regulatory demand requires disclosure, we comply — and no responsible party can promise otherwise. Even then, we disclose only what is legally required, we record every such disclosure, and we notify you unless the law forbids us from doing so.

Behind that commitment sits a documented information security policy, owned and maintained by MTS at director level. Every employee is bound by a written confidentiality undertaking; every operator by a written operator agreement. Unauthorised processing or disclosure by an employee is a disciplinary offence that may lead to termination, and where the law is broken we will say so and act accordingly. We hold ourselves to the standard we ask our clients to trust us with.

↑ Return to contents

16 How long we keep it

In short: Five years for training and access records. Your photograph and entire account contents go when your account is deleted, and are not accessible to anyone once it is deactivated. Appointment person details are never retained at all.
RecordHow long we keep it
Training and certification records Five years, in line with SETA record-keeping expectations.
Electronic visit and attendance registers Five years. Facilities set their own retention periods for the copies they hold.
Health declaration Five years.
Digital photograph and account details Not accessible to anyone once the account is deactivated. The photograph and entire account contents are removed when the account is deleted.
Appointment person details Not retained. Used to arrange the appointment and not stored in any MTS database.
Practitioner booking details given for CABS Not retained. Used to arrange the appointment and not stored in any MTS database.
Doctors named at check-out Five years, with the visit register — see section 11.

Section 14 of POPIA requires that records not be retained for longer than is necessary for the purpose they were collected for, unless a law requires or authorises a longer period. Where we cannot delete a record, we de-identify it so that you can no longer be identified from it. MTS owns and maintains the retention schedule behind this table.

↑ Return to contents

17 Your consent and your choices

In short: Consent is not the only basis we use, and where we do rely on it, it must be specific and freely given — and you can withdraw it.

Section 4 sets out which ground we rely on for each purpose, and section 12 sets out what your employer must obtain your consent for. Where a purpose depends on your consent, that consent is sought separately and specifically. Using our website or receiving a service does not by itself amount to consent to processing that requires it, and we do not treat it as such.

  • You can withdraw consent at any time, by writing to info@masoom.co.za. Withdrawal does not affect the lawfulness of processing already carried out, or processing that rests on a different ground.
  • You can decline. Where we ask for information directly through the mobile app, we offer the option “I do not wish to provide this information”. Declining is a real choice, though it may limit what we can do for you — without a valid access card, for example, facility access is not available.
  • You can object. Where we rely on legitimate interests, section 11(3) of POPIA gives you a right to object on reasonable grounds relating to your particular situation.
  • Separate consent for images. We seek separate consent before using photographs or video of identifiable individuals in any external publication.

↑ Return to contents

18 Your rights over your information

In short: You can ask to see, correct or delete what we hold. Email info@masoom.co.za and we’ll act on it.
  • Ask what we hold. You may request details of the personal information we hold about you. We’ll take reasonable steps to confirm your identity before releasing anything.
  • Correct it. If anything we hold is wrong or incomplete, tell us and we’ll correct it promptly.
  • Delete it. You can ask us to delete your information, unless the law requires us to keep it. Where we cannot delete it, we’ll take all practical steps to de-identify it.
  • Object. You may object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent that you previously gave.
  • Complain. To us first, and to the Information Regulator if we do not resolve it — see section 24.

Requests are handled under POPIA sections 23 to 25 and, where applicable, the Promotion of Access to Information Act 2 of 2000. Our PAIA manual is published at masoom.co.za and crice.co.za.

↑ Return to contents

19 Cookies

In short: Only the cookies needed to make the site work are set automatically. Nothing optional loads until you agree to it, and you can change your mind at any time.

When you first visit this site you are asked what you allow. Until you answer, the only cookies set are the ones the site cannot function without. Analytics and marketing cookies are held back — the scripts that would set them are prevented from running, rather than merely disclosed to you while they run anyway.

The three categories

  • Strictly necessary. Page navigation, secure areas, and remembering your cookie choice. These cannot be switched off, because the site would not work without them.
  • Analytics. Tells us which pages are used and where visitors get stuck, so we can improve the site. Set only if you allow it. We do not use analytics to identify you personally.
  • Marketing. Used to measure whether our own campaigns reach the right people. Set only if you allow it. We do not sell your information and we do not share it for third-party advertising.

Changing your mind

Withdrawing consent must be as easy as giving it, so the Cookie settings link in the footer of every page reopens your choices at any time. If you switch a category off, we do not simply stop setting new cookies — we delete the ones already set in that category.

Your choice is recorded in a single cookie on this site, together with the date you made it and the version of this notice it relates to. We ask again every six months, and sooner if we materially change what our cookies do. Because cookies cannot be shared between different web addresses, a choice made on this site does not carry across to our other sites, and you will be asked separately on each.

You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site working.

↑ Return to contents

20 Marketing and service updates

In short: Only if you have opted in — and you can unsubscribe whenever you like.

If you have opted in, we may use your details to tell you about new services or products that may interest you, by post, email or SMS. Section 69 of POPIA requires opt-in consent for electronic direct marketing to people who are not already our customers, and we apply that standard. Every message carries an unsubscribe option, and you can also contact us to be removed from the mailing list.

↑ Return to contents

21 Children

In short: We do not knowingly process the information of anyone under 18 without consent from a competent person.

MTS will not collect personal information from anyone we know to be under the age of 18 without prior, verifiable consent from a competent person, as required by sections 34 and 35 of POPIA. That person has the right, on request, to view the information provided and to require that it be deleted. CRICE is not intended for use by children.

↑ Return to contents

22 Changes to this notice

In short: We may update this notice. The current version on this page always applies.

We may amend this notice from time to time. All amendments are posted on our website, and the version number and date at the top of this page tell you which version is current. Where a change materially affects how we process your information, we will bring it to your attention rather than relying on you to notice it. Unless stated otherwise, the current version supersedes all previous versions.

Version history

This log records material changes to this notice. Earlier versions are available on request from the Information Officer.

VersionDateChange
927 August 2026NAPPI codes removed. NAPPI codes are no longer collected at any facility and the field has been removed from CABS. The appointment record holds the reason for the visit and the product name.

↑ Return to contents

23 Learnership programmes — medsalesrep.co.za

In short: We recruit for and administer accredited health products learnerships through medsalesrep.co.za. For those candidates we do collect an identity number, and we collect race, disability status and socio-economic status — because SETA registration, B-BBEE verification and employment-equity reporting require them.

MTS also recruits for and administers accredited health products learnership qualifications — including the QCTO-accredited Health Products Sales Representative qualification (SAQA ID 118735, NQF Level 5) — through our dedicated website, medsalesrep.co.za. That site publishes its own Privacy Notice & Cookie Policy and PAIA & POPIA Manual; this section incorporates that processing into this notice.

Whose information we hold

  • Learnership candidates — people accepted onto and enrolled in a learnership programme.
  • Potential candidates — people who apply or register interest but are not (or not yet) enrolled, including applicants who do not meet the minimum entrance requirements.
  • Companies and sponsors — organisations registering interest in participating in or sponsoring a learnership.
  • Mentors and coaches — workplace mentors, coaches and assessors who support learners.
  • Referees — the people a candidate nominates as references.

What we collect

  • Pre-qualification form — answers to the screening questions used to determine whether an applicant meets the minimum entrance requirements.
  • Learner application form — title, first name, middle name(s), surname and maiden name where applicable; telephone and cellphone numbers; email address; residential and postal addresses with postal codes; date of birth and identity number (and whether a certified copy of the SA identity document is held); driver’s licence details; home language, gender, race, disability status and socio-economic status; highest tertiary qualification; and two references (name, contact number, email address).
  • Company participation and sponsorship forms — company name, contact person, telephone and cellphone numbers, email address, employment figures, B-BBEE-related information, divisions of interest and reasons for interest in the learnership.
  • Programme records once enrolled — assessment and moderation results, attendance, portfolios of evidence, workplace logbooks, mentor and coach reports, and certification records.

Special personal information, and why identity numbers differ here

Race, disability status and socio-economic status are special or sensitive categories under POPIA. We collect them only because SETA registration, B-BBEE verification and employment-equity reporting require them; where a candidate declines to provide them, we explain the consequence for the application rather than compelling disclosure. Identity numbers are collected for learnership candidates because SETA registration and certification require them — this differs from the CRICE® Programme described elsewhere in this notice, where we do not collect identity numbers at all.

Consent and legal basis

Learnership information is obtained directly from the data subject with their consent, given when the application form is submitted. Processing is also necessary for the performance of the learnership agreement and to comply with the Skills Development Act and SETA requirements. Consent may be withdrawn at any time by writing to the Information Officer, subject to records we are obliged by law to retain.

References

Referee details are used solely to verify a candidate’s application. Candidates should make sure their referees are aware of, and agree to, their details being shared with us.

Who it is shared with

The relevant SETA and the QCTO for registration, verification and certification; the employer or host workplace where a learner is placed; accredited assessors and moderators; and trusted service providers who host or support our systems. It is not sold, and it is not used for marketing.

Retention

Learner and assessment records are retained for five years, in line with SETA, QCTO and National Qualifications Framework record-keeping requirements, and thereafter destroyed or de-identified. Applications from candidates who are not enrolled are retained only for as long as the recruitment cycle requires, unless the applicant asks to be kept on file for future opportunities.

Cookies on medsalesrep.co.za

That site uses essential cookies, plus optional analytics cookies that are set only after a visitor accepts them in the site’s privacy pop-up. Visitors can change their choice at any time using the “Cookie settings” button on every page there.

↑ Return to contents

24 Contact us and your right to complain

In short: One address for every privacy question — info@masoom.co.za. Come to us first; the Information Regulator is there if we fall short.

Get in touch if you have a question about this notice, want more detail on our privacy practices, wish to withdraw consent, want to set your preferences, or want to access or correct your information.

Masoom Training Solutions (Pty) Ltd — Information Officer

21 Woodlands Drive, Country Club Estate, Woodmead, 2128

Telephone: +27 11 807 2813

Email: info@masoom.co.za

Web: www.masoom.co.za

If you believe MTS has used your personal information contrary to this notice, you have the right to lodge a complaint with the Information Regulator under POPIA. We would ask you to contact us first so that we can try to put it right. If we do not resolve it adequately, you can contact:

The Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

PO Box 31533, Braamfontein, Johannesburg, 2017

inforegulator.org.za

↑ Return to contents

Masoom Training Solutions
Masoom Training Solutions (Pty) Ltd  |  Registration 2011/000057/07  |  B-BBEE Level 1 certified
21 Woodlands Drive, Country Club Estate, Woodmead, 2128  |  +27 11 807 2813  |  info@masoom.co.za  |  www.masoom.co.za
Privacy Notice version 7 — 23 July 2026. Supersedes version 6 of 29 September 2025.
Also published at masoom.co.za and crice.co.za.