Legal
Privacy policy
Effective 11 August 2026
In short
Wardroom is a private, invitation-only platform that connects hospitals with their medical specialists. Your hospital invites you and decides why your information is processed; we process it on the hospital’s behalf. We collect only what the platform needs, we never sell it, and we hold no patient data of any kind.
1. Who we are
Wardroom is operated by Under Bridges Entity (Pty) Ltd, a company registered in South Africa. In this policy, “Wardroom”, “we” and “us” refer to Under Bridges Entity (Pty) Ltd. You can reach us at hello@wardroom.co.za.
This policy explains how personal information is handled on the Wardroom platform at wardroom.co.za and app.wardroom.co.za, in line with the Protection of Personal Information Act, 2013 (POPIA).
2. No patient data
Wardroom does not collect, store or process patient data of any kind. This is a deliberate design decision, not an incidental one. There are no fields for patient names, records, images or case details anywhere on the platform, and nothing in Wardroom connects to a hospital’s clinical systems. The personal information we process belongs to the professionals who use the platform, never to their patients.
3. Your hospital and Wardroom
Wardroom is invitation only. You use it because your hospital has invited you, and it is the hospital that decides why and how its members’ personal information is processed on the platform. In POPIA terms, your hospital is the responsible party for its members’ information, and Under Bridges Entity (Pty) Ltd acts as its operator, processing that information on the hospital’s instructions and under a written agreement with it.
For a small amount of information we determine ourselves, such as visits to this marketing site and direct correspondence with us, we act as the responsible party.
4. What we collect
The platform processes the following categories of personal information.
- Identity and contact details. Your name, email address and, if you choose to add it, a phone number.
- Professional details. Your specialty, department, HPCSA number, qualifications, headshot, press kit details such as biography and notable work, languages spoken, and your stated willingness to take part in media work.
- CPD records. Continuing professional development activities you log, together with any evidence documents you upload, such as attendance certificates.
- Platform activity. Read receipts for hospital notices, your responses to polls and forms, and your responses to media and speaking opportunities.
- Account and device records. Sign-in and session records, and push notification subscriptions for devices where you have switched notifications on.
If a delegate, such as a practice manager, acts on a specialist’s behalf, the platform records which account took each action, so activity is always attributed accurately.
5. Why we use it
We process personal information only to run the platform. That means:
- delivering hospital notices, polls, forms and opportunities to the right people;
- confirming to the hospital that notices have been seen;
- maintaining specialist profiles and press kits the hospital can share when it puts a name forward;
- tracking CPD activity against HPCSA requirements as an informational aid;
- signing you in securely and keeping your session working;
- sending notifications by email and, where you opt in, by push notification.
We do not sell personal information, we do not use it for advertising, and we do not use it to train artificial intelligence models.
6. Who sees what inside Wardroom
Access inside the platform follows the role each person holds.
- Specialists see their own profile, CPD records, and the notices, polls, forms and opportunities addressed to them.
- Delegates see what the specialist they act for has authorised, with every action attributed to the delegate’s own account.
- Hospital admins manage members, send communications, and see responses and read receipts for their own hospital.
- Hospital managers see aggregate views only, not individual records.
Information never crosses between hospitals. Each hospital sees only its own members and its own activity.
7. Where your data lives
Wardroom is built on a small number of carefully chosen service providers, each acting as a sub-operator under our instructions:
- Neon hosts the database, in a European Union region;
- Cloudflare R2 stores uploaded files, such as headshots and CPD evidence;
- Resend delivers email;
- Vercel hosts the application;
- Inngest runs background jobs, such as scheduled reminders;
- web push services operated by your browser vendor deliver push notifications you have opted into.
This means personal information is transferred outside South Africa. We only do so as permitted by section 72 of POPIA: each provider is bound by contractual terms that require a level of protection substantially similar to POPIA’s conditions for lawful processing, and where data rests in the European Union it is also protected by the GDPR.
9. How long we keep it
Account and platform information is kept for the duration of your hospital’s contract with us, after which it is deleted or anonymised within a reasonable period, unless the law requires otherwise.
CPD records deserve a special note. The HPCSA may audit a practitioner’s CPD compliance years after the activities took place, so these records are professionally significant to you. You can export your CPD records and evidence at any time, and we encourage you to do so before your access ends. Once exported, those copies are yours to keep.
You can request deletion of your information at any time, either through your hospital or directly with us, subject to any records we are legally required to retain.
10. Your rights
Under POPIA you have the right to:
- be told what personal information we hold about you, and access it;
- have inaccurate or outdated information corrected;
- have your information deleted, subject to lawful retention requirements;
- object to processing in the circumstances POPIA sets out.
Because your hospital is the responsible party for most of your information on the platform, the quickest route is usually through your hospital admin. You are also welcome to contact us directly at hello@wardroom.co.za and we will act on the request with the hospital. Requests for access to records are handled under POPIA read with the Promotion of Access to Information Act, 2000 (PAIA).
If you believe your information has been handled unlawfully, you may lodge a complaint with the Information Regulator of South Africa at POPIAComplaints@inforegulator.org.za or via inforegulator.org.za.
11. Security
We take reasonable, appropriate technical and organisational measures to protect personal information: encrypted connections throughout, access limited by role, hospital-level data isolation, and infrastructure providers with strong security practices. If a security compromise ever affects your personal information, we will notify your hospital and, where required, you and the Information Regulator, as POPIA requires.
12. Changes to this policy
If we change this policy in a way that matters, we will notify you through the platform before the change takes effect. The effective date at the top of this page always reflects the current version.
13. Contact
Questions about this policy or about your personal information can be sent to hello@wardroom.co.za. We aim to respond within a few business days.