Masoom Training Solutions (Pty) Ltd | Reg. 2011/000057/07 | B-BBEE Level 1
Version 9 | Updated 27 August 2026
| Supersedes Version 8 of 7 August 2026
This notice explains, in plain language, what personal information Masoom Training Solutions (“MTS”, “we”) collects about you, why we collect it, who can see it, and what you can do about it. It covers our training programmes and the CRICE desktop and mobile applications. We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).
Masoom Training Solutions recognises that the personal information it receives is held in a position of trust. This notice sets out how we collect, use, share and otherwise process that information — lawfully, ethically, and in line with industry best practice.
CRICE (Company Representative in Clinical Environment Programme) is a credentialing and access-verification system initiated and developed by members of the healthcare supplier industry and subsequently adopted by participating healthcare facilities as part of their representative access-control requirements.
This notice applies to you if you are:
MTS is an independent credentialing body. We are not engaged by supplier companies to administer their employees on their behalf: our purpose is patient and staff safety, by ensuring that representatives entering a healthcare facility are trained, declared and identifiable.
MTS is the responsible party for the information described in this notice. Our Information Officer is Fathima Amod, Managing Director of Masoom Training Solutions, registered with the Information Regulator and reachable at info@masoom.co.za. Our PAIA manual is published at masoom.co.za and crice.co.za.
We collect a date of birth, not an identity number. It is used for one narrow purpose: telling apart two people with the same or a similar name, so that a certificate and an access card are issued to the right person. We do not collect identity numbers at all, and we do not ask for any information beyond what is listed below.
| If you are a… | We may hold |
|---|---|
| Company Point of Contact | Name, date of birth, work email address, work contact number. |
| Company Representative | Name, date of birth, email address, contact number, digital photograph (see section 8), and confirmation of Hepatitis B vaccination status or exemption (see section 13). |
| Hospital Point of Contact / Appointment Person | Name, work email address, work contact number — entered at the point of booking and not maintained by us as a contact database (see section 9). |
| Observer | Name and professional registration number. |
| Learner | Name, date of birth, email address, contact numbers, qualifications, certifications, work experience, education, publications, awards, references, completed training and signature. |
MTS built this client-controlled portal specifically so that the Company Point of Contact — not MTS — enrols and manages their own representatives: MTS does not solicit or capture a representative’s personal information directly, and receives it only where a representative enters it themselves on the CRICE app, or where the Company Point of Contact enrols staff (having first given them this notice and recorded their consent).
Independent sales agents. Some people who use CRICE are independent sales agents rather than a company’s employees, and are not administered by a Company Point of Contact. For them, MTS acts as the point of contact: they are registered directly with MTS and give their consent directly to us for the information CRICE processes about them, on the same basis and with the same protections set out in this notice.
CRICE was designed around confidentiality and consent — a secure, client-controlled portal, and real-time permission prompts rather than blanket permissions. Its design and terms comply with POPIA, the Electronic Communications and Transactions Act 25 of 2002, and the Consumer Protection Act 68 of 2008.
| What we do | Our POPIA ground |
|---|---|
| Enrol you, track your progress and issue your certificate | Performance of a contract — s11(1)(b) |
| Create the electronic visit and attendance register when you scan in and out | Legitimate interests of MTS, the facility and your employer — s11(1)(f); and the facility’s own legal duties for access control |
| Manage appointments through CABS | Performance of a contract — s11(1)(b); legitimate interests — s11(1)(f) |
| Verify your identity at a facility using your photograph | Legitimate interests in patient and staff safety and fraud prevention — s11(1)(f) |
| Hold your health declaration | Your explicit consent for special personal information — s27(1)(a), alongside occupational health and safety obligations |
| Send you marketing about our services | Your opt-in consent — s69 |
| Keep records the law requires us to keep | Compliance with a legal obligation — s11(1)(c) |
Facilities use the visit register to monitor and control access, investigate incidents or complaints, and verify training and technical input by representatives. The appointment record holds the representative’s and appointment person’s details, the reason for the visit and the product name.
Where we rely on legitimate interests, you have the right to object on reasonable grounds relating to your particular situation, under section 11(3) of POPIA. See section 18.
We want to be especially clear about location, because we know it’s the thing people worry about most:
Once a visit register reaches a facility, that facility decides how long to keep it and how to use it for its own access-control purposes, and is accountable for it under POPIA. If your question concerns a facility’s own copy of a record, approach that facility; if it concerns what MTS holds, approach us.
The CRICE platform is hosted on Amazon Web Services in the Africa (Cape Town) region, so your personal information is stored in South Africa, and access to the production environment is restricted to South African connections — it cannot be reached from outside the country. Our email and office-productivity providers are likewise configured to keep your information within South Africa.
We do not transfer your personal information outside South Africa. Were that position ever to change, we would first put in place a lawful basis and the cross-border safeguards required by section 72 of POPIA — including written assurances that require a level of protection equivalent to our own — before any transfer took place.
A digital photograph is part of your Digital CRICE Access Card, so that a person at the facility can confirm the card belongs to you. The check is done by a human being, not by software.
It exists for two reasons, and no others:
Equally important is what the photograph is not:
Booking a meeting requires knowing who the meeting is with. When a Company Representative books through CABS, they enter the Appointment Person’s work name, work email address and work telephone number — details the facility has already made available for exactly this purpose, and which the appointment person gives out in the ordinary course of their job.
This is the part worth stating plainly. Those details are used to arrange and confirm the appointment. They are not written to any MTS contact table, directory, address book or autocomplete, and no appointment person record is retained. There is nothing to compile, nothing to sell and nothing to market to, because the data is not held.
POPIA sets out six lawful grounds for processing in section 11(1), of which consent is only one. This processing rests on the following:
If you are an Appointment Person and would prefer your work details were not used this way, write to info@masoom.co.za. Section 11(3) of POPIA gives you a right to object where we rely on legitimate interests, and we will act on it.
Many healthcare practitioners consult from rooms located within a hospital facility, where the only way to reach those rooms is through a hospital entrance door. Because the representative has already passed through that entrance, the hospital’s own access control applies and the visit is recorded there.
The consulting rooms are not separately controlled by CRICE. A practitioner is under no obligation to operate access control over their own rooms, to register with CRICE, or to participate in any way, and nothing in this notice imposes such an obligation.
Some practitioners find the appointment booking system useful and choose to accept bookings through it. That is a voluntary election, made by providing their booking details and asking representatives to use the system, and it can be reversed at any time by telling the representative or writing to info@masoom.co.za.
The booking details a practitioner gives for that purpose are handled exactly as described in section 9: used to arrange the appointment, and not stored in any MTS database. This is separate from the doctor names a representative records at check-out, which are dealt with in section 11 — and which are recorded only for engagements inside a facility, never for a visit to a doctor’s own rooms. Representatives are required to explain this before entering a practitioner’s details, and Company Points of Contact must cover that obligation when briefing their representatives — see section 12.
What we record, and what we do not. At check-out a representative is asked: “Which doctor(s) did you engage with, during this visit, regarding the use of these product(s) or equipment(s)?” The prompt tells the representative to answer only for engagements inside the facility, and not for doctors seen in their own consulting rooms, and that the answer is recorded with the visit and visible to the facility and to their company. We record the doctor’s name and the product or equipment concerned, and nothing else — no contact details, no clinical detail, no patient information, and no assessment of the doctor.
Consulting rooms stay outside this. Section 10 of this notice explains that consulting rooms are not access-controlled by CRICE and that a doctor is under no obligation to participate. That remains true. A visit to a doctor in their own rooms is not recorded here, and a doctor who practises from rooms is not brought into CRICE by this section.
Why doctors are treated separately. Doctors are independent practitioners. They are not employed by the facility, and their details are not provided to us by it. That is different from Hospital Points of Contact, whose details the facility itself supplies to us for loading, and from Appointment Persons — hospital staff whose work details a representative enters into CABS solely to arrange one meeting, and which we do not retain (section 9). Because a doctor’s name reaches us from the representative and from no one else, it needs its own basis, which is set out below.
Why we record it, and our lawful ground. We process this on the ground of legitimate interests — section 11(1)(f) of POPIA — being the interests of the healthcare facility, of the supplier company and of MTS in an accurate record of what took place inside a clinical area. Those interests are: enabling a facility to reconstruct who was present and in connection with what, if an incident, complaint or infection-control query arises; supporting product traceability, vigilance and recall, where knowing which product was involved and with whom is the starting point of any investigation; and evidencing that access was used for a legitimate business purpose. Because we obtain the name from the representative rather than from the doctor, we rely on sections 12(2)(c), 12(2)(d)(v) and 12(2)(f) of POPIA: collecting it this way does not prejudice the doctor, it maintains the legitimate interests described above, and direct collection at the point of a clinical interaction is not reasonably practicable.
Who can see it. The healthcare facility whose premises were entered, and the supplier company that employs the representative. It is not published, not sold, and not shared with any other party.
What it is never used for. We do not use doctors’ names for marketing, and we do not permit them to be used to rank, score, target or set commercial objectives in respect of any doctor. Company Points of Contact must enforce this within their organisations, and any such use is a breach of the terms on which access to the record is given.
How long we keep it. Five years, with the visit register it forms part of, after which it is destroyed or de-identified.
If you are a doctor. You may ask us what we hold about you, ask us to correct it, or object to this processing at any time under sections 5, 11(3), 23 and 24 of POPIA, by writing to info@masoom.co.za. If you object, we will stop recording your name in new visit records unless we are legally required to continue, and we will tell you the outcome in writing.
Under POPIA, an employer is the responsible party for the personal information of its own employees. Obtaining a representative’s consent is therefore the employer’s obligation, not MTS’s, and it has been a standing condition of using CRICE since the system was introduced: consent must be obtained before personal information is entered on MTS platforms. The requirement applies to every enrolment, past and present.
By enrolling a representative, a Company confirms to MTS that it holds that consent, that it was obtained before enrolment, and that it covers the matters set out below. Companies warrant this to MTS under their agreement with us, undertake to keep a dated record of each consent, and undertake to produce those records to MTS on request. MTS relies on that confirmation and does not obtain consent from representatives directly.
We set the position out here, in the notice itself, rather than in a separate form, so that any representative, appointment person or practitioner can read what they have agreed to without having to ask anyone for a document.
For every enrolment, the Company Point of Contact must
A Company Point of Contact who enters healthcare facilities is a data subject as well as an administrator. Administering the portal does not cover you in your own right — your consent must be recorded in the same way, countersigned by a fellow director or your line manager.
Most of what CRICE does does not depend on consent, and that is deliberate. Access control, the visit register and identity verification rest on sections 11(1)(b) and 11(1)(f) of POPIA — performance of the arrangement, and the legitimate interests of the facility, the employer and patient safety. You are informed of these rather than asked to agree to them, and you may object on reasonable grounds under section 11(3). Consent is sought where the law requires it, and separately.
These are genuinely optional and severable. Declining them changes nothing else about your enrolment.
You may withdraw the consents in categories 2 and 3 at any time, by telling your Point of Contact or writing to info@masoom.co.za. Withdrawing your health declaration consent means facilities cannot admit you, because they cannot make an admission decision without it. Withdrawal does not affect the lawfulness of processing already carried out.
MTS does not enrol representatives on a Client’s behalf unless specifically asked to, and where we do, we act on the instruction on the basis that consent has already been obtained.
Healthcare facilities need assurance about infection risk before admitting a representative to clinical areas. Rather than collecting any medical evidence, CRICE asks you to make a declaration in your own name, which you sign electronically when your Digital CRICE Access Card is issued. It is an attestation by you — not a request for medical records. In the declaration you confirm the following.
Where (b) applies, the Declaration of Risk Assessment is held by you and your employer. It may be requested by MTS or the relevant facility as proof that a risk assessment was done, with all personal health information redacted, and you retain it for three (3) years. MTS does not hold it.
Masoom Training Solutions holds no clinical information about you. Any health assessment, and any clinical detail arising from it, remains between you and your employer. Where clinical input is ever needed, it passes between your employer’s occupational-health advisor and the facility’s — it does not pass through MTS. If you are pregnant or breastfeeding and have been advised not to be vaccinated, your employer provides only the dates for which access is required: no reason, no diagnosis and no medical certificate is requested or accepted.
You are under no obligation to disclose your HIV or AIDS status, at all. CRICE does not ask for it, has no field to record it, and it forms no part of any admission decision. This is stated expressly in the declaration you sign. It reflects both the sensitivity of that information under POPIA and the protections in South African employment law, which prohibit employers from testing an employee for HIV without authorisation from the Labour Court.
You make this declaration of your own free will. The personal information in it is processed solely for facility-access credentialing, in line with the minimality principle of the Protection of Personal Information Act, 2013 (POPIA).
We take appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and to prevent unlawful access to or processing of it. We identify foreseeable internal and external risks, establish safeguards against them, verify that those safeguards are working, and update them as new risks emerge.
Section 19(3) of POPIA does not prescribe a specific technology. It requires us to have due regard to generally accepted information security practices and procedures. The reasoning we apply is straightforward:
We want to state this without hedging, because it is the commitment our clients and their representatives rely on most.
The single, narrow exception is compulsion by law. Where a court order, a statute or a lawful regulatory demand requires disclosure, we comply — and no responsible party can promise otherwise. Even then, we disclose only what is legally required, we record every such disclosure, and we notify you unless the law forbids us from doing so.
Behind that commitment sits a documented information security policy, owned and maintained by MTS at director level. Every employee is bound by a written confidentiality undertaking; every operator by a written operator agreement. Unauthorised processing or disclosure by an employee is a disciplinary offence that may lead to termination, and where the law is broken we will say so and act accordingly. We hold ourselves to the standard we ask our clients to trust us with.
| Record | How long we keep it |
|---|---|
| Training and certification records | Five years, in line with SETA record-keeping expectations. |
| Electronic visit and attendance registers | Five years. Facilities set their own retention periods for the copies they hold. |
| Health declaration | Five years. |
| Digital photograph and account details | Not accessible to anyone once the account is deactivated. The photograph and entire account contents are removed when the account is deleted. |
| Appointment person details | Not retained. Used to arrange the appointment and not stored in any MTS database. |
| Practitioner booking details given for CABS | Not retained. Used to arrange the appointment and not stored in any MTS database. |
| Doctors named at check-out | Five years, with the visit register — see section 11. |
Section 14 of POPIA requires that records not be retained for longer than is necessary for the purpose they were collected for, unless a law requires or authorises a longer period. Where we cannot delete a record, we de-identify it so that you can no longer be identified from it. MTS owns and maintains the retention schedule behind this table.
Section 4 sets out which ground we rely on for each purpose, and section 12 sets out what your employer must obtain your consent for. Where a purpose depends on your consent, that consent is sought separately and specifically. Using our website or receiving a service does not by itself amount to consent to processing that requires it, and we do not treat it as such.
Requests are handled under POPIA sections 23 to 25 and, where applicable, the Promotion of Access to Information Act 2 of 2000. Our PAIA manual is published at masoom.co.za and crice.co.za.
When you first visit this site you are asked what you allow. Until you answer, the only cookies set are the ones the site cannot function without. Analytics and marketing cookies are held back — the scripts that would set them are prevented from running, rather than merely disclosed to you while they run anyway.
Withdrawing consent must be as easy as giving it, so the Cookie settings link in the footer of every page reopens your choices at any time. If you switch a category off, we do not simply stop setting new cookies — we delete the ones already set in that category.
Your choice is recorded in a single cookie on this site, together with the date you made it and the version of this notice it relates to. We ask again every six months, and sooner if we materially change what our cookies do. Because cookies cannot be shared between different web addresses, a choice made on this site does not carry across to our other sites, and you will be asked separately on each.
You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site working.
If you have opted in, we may use your details to tell you about new services or products that may interest you, by post, email or SMS. Section 69 of POPIA requires opt-in consent for electronic direct marketing to people who are not already our customers, and we apply that standard. Every message carries an unsubscribe option, and you can also contact us to be removed from the mailing list.
MTS will not collect personal information from anyone we know to be under the age of 18 without prior, verifiable consent from a competent person, as required by sections 34 and 35 of POPIA. That person has the right, on request, to view the information provided and to require that it be deleted. CRICE is not intended for use by children.
We may amend this notice from time to time. All amendments are posted on our website, and the version number and date at the top of this page tell you which version is current. Where a change materially affects how we process your information, we will bring it to your attention rather than relying on you to notice it. Unless stated otherwise, the current version supersedes all previous versions.
This log records material changes to this notice. Earlier versions are available on request from the Information Officer.
| Version | Date | Change |
|---|---|---|
| 9 | 27 August 2026 | NAPPI codes removed. NAPPI codes are no longer collected at any facility and the field has been removed from CABS. The appointment record holds the reason for the visit and the product name. |
MTS also recruits for and administers accredited health products learnership qualifications — including the QCTO-accredited Health Products Sales Representative qualification (SAQA ID 118735, NQF Level 5) — through our dedicated website, medsalesrep.co.za. That site publishes its own Privacy Notice & Cookie Policy and PAIA & POPIA Manual; this section incorporates that processing into this notice.
Race, disability status and socio-economic status are special or sensitive categories under POPIA. We collect them only because SETA registration, B-BBEE verification and employment-equity reporting require them; where a candidate declines to provide them, we explain the consequence for the application rather than compelling disclosure. Identity numbers are collected for learnership candidates because SETA registration and certification require them — this differs from the CRICE® Programme described elsewhere in this notice, where we do not collect identity numbers at all.
Learnership information is obtained directly from the data subject with their consent, given when the application form is submitted. Processing is also necessary for the performance of the learnership agreement and to comply with the Skills Development Act and SETA requirements. Consent may be withdrawn at any time by writing to the Information Officer, subject to records we are obliged by law to retain.
Referee details are used solely to verify a candidate’s application. Candidates should make sure their referees are aware of, and agree to, their details being shared with us.
The relevant SETA and the QCTO for registration, verification and certification; the employer or host workplace where a learner is placed; accredited assessors and moderators; and trusted service providers who host or support our systems. It is not sold, and it is not used for marketing.
Learner and assessment records are retained for five years, in line with SETA, QCTO and National Qualifications Framework record-keeping requirements, and thereafter destroyed or de-identified. Applications from candidates who are not enrolled are retained only for as long as the recruitment cycle requires, unless the applicant asks to be kept on file for future opportunities.
That site uses essential cookies, plus optional analytics cookies that are set only after a visitor accepts them in the site’s privacy pop-up. Visitors can change their choice at any time using the “Cookie settings” button on every page there.
Get in touch if you have a question about this notice, want more detail on our privacy practices, wish to withdraw consent, want to set your preferences, or want to access or correct your information.
Masoom Training Solutions (Pty) Ltd — Information Officer
21 Woodlands Drive, Country Club Estate, Woodmead, 2128
Telephone: +27 11 807 2813
Email: info@masoom.co.za
Web: www.masoom.co.za
If you believe MTS has used your personal information contrary to this notice, you have the right to lodge a complaint with the Information Regulator under POPIA. We would ask you to contact us first so that we can try to put it right. If we do not resolve it adequately, you can contact:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Choose what you allow. You can change this at any time using the “Cookie settings” link in the footer.
Keeps the site working — page navigation, secure areas, and remembering this choice. The site cannot function without these, so they cannot be switched off.
Tells us which pages are visited and where people get stuck, so we can improve the site. We do not use this to identify you personally.
Used to measure whether our own campaigns reach the right people. We do not sell your information or share it for third-party advertising.
Your choice is stored in a single cookie on this site, with the date and the version of this policy. If you reject or later switch something off, we delete the cookies in that category. See our Privacy Notice.