This privacy notice for KRIKDEX (Pty) Ltd (doing business as Krikdex) ('Krikdex', 'we', 'us', or 'our') describes how and why we might collect, store, use, and/or share ('process') your information when you use our services ('Services'), such as when you:
- Download and use our mobile application (Fona), or any other application of ours that links to this privacy notice
- Engage with us in other related ways, including any sales, marketing, or events
IMPORTANT
Fona is a shared phone directory for South African hospitals. It holds workplace contact details: extensions, direct lines, bleepers and email addresses for wards, departments, roles and on-call staff. Fona holds no patient information of any kind. There is no patient record in the app and nowhere to create one. We do not collect your location, your phone's contact list, or a log of the calls you make: when you tap a number, Fona hands it to your phone's own dialler and the call is between you and your network operator. The app contains no advertising and no crash-reporting SDK, and it does not track you across other companies' apps or websites. It does count how many people use it, without recording what they look up: see 'Usage counts' in section 1.
What Fona does store is an account (your email address and name), your starred contacts, and the directory content itself, which is written and corrected by users like you. Because the directory is shared, anything you add to it is visible to every other signed-in user of that hospital's directory, so please read section 6 before adding an entry.
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at krikdex@gmail.com.
SUMMARY OF KEY POINTS
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by using our table of contents below to find the section you are looking for.
What personal information do we process?
We process the information you give us to create an account, being your email address, your name, and optionally your profession and default hospital, together with the directory content you add or edit, and a record of which account made each change.
Do we process any sensitive personal information?
No. We do not process health information, patient information, biometric information, financial information, or any other special personal information as defined by POPIA.
Do we receive any information from third parties?
If you sign in with Google or Apple, we receive your name and email address from them so we can create your account. The contact entries in some directories were imported from directory exports that hospital staff obtained from the directory service they used before it withdrew from South Africa; see section 6.
How do we process your information?
To create and secure your account, to let you search and edit hospital directories, to keep an audit trail of directory changes so bad edits can be traced and undone, to respond to your support requests, and to comply with law. We do not sell your information, and we do not use it for advertising.
In what situations and with which parties do we share personal information?
With Google Firebase, which hosts our authentication and database and counts app usage, with Resend, which delivers our verification emails, and with RevenueCat, which counts new and active accounts. Your name and directory contributions are also visible to other signed-in users, by design.
How do we keep your information safe?
Through platform authentication, database security rules that limit each account to the data it is entitled to, hashed one-time codes, and transport encryption. The Services carry no patient data, which is the strongest safeguard of all.
What are your rights?
Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Under POPIA you may access, correct, or request deletion of your personal information. You can delete your account and everything attached to it from within the app.
How do I exercise my rights?
The easiest way is by contacting us at krikdex@gmail.com. We will consider and act upon any request in accordance with applicable data protection laws.
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect the information you provide when you create an account and when you edit a hospital directory.
We collect personal information that you voluntarily provide to us when you register on the Services, when you participate in activities on the Services, or otherwise when you contact us.
Account Information:
- Email address
- First and last name
- Password (never stored by us in readable form; authentication is handled by Google Firebase, which stores a salted hash)
- Profession, if you choose to set one (for example Registrar, Medical Officer, Nurse, Pharmacist)
- Your default hospital directory, if you set one
- The date your account was created and the date it was last active
If you sign in with Google or Apple, we receive your name and email address from that provider instead of you typing them. We never receive your Google or Apple password. If you use Apple's Hide My Email, we only ever see the relay address it generates.
Your name is visible to other signed-in users, because directory changes are attributed and admin lists show who has access. Your email address is not: it is held in a private area of your account record that only you and our servers can read.
Directory Information You Contribute:
- Contact names, as you type them (for example 'Ward 12 Nurses Station', 'Cardiology Registrar on call', 'Theatre C')
- The extension, phone number, bleeper number or email address for that contact
- Which account created, last edited, or deleted each entry, and when
- Hospital records you create: name, province, type, dialling prefix, switchboard number, admin list and blocked-user list
Your Favourites:
- The contacts you have starred, per hospital, so they follow your account to a new device
Verification Codes:
- When you register or reset a password with an email address, we store a one-way hash of the six-digit code we email you, the time it was sent, and a count of recent sends, so we can check the code and rate-limit abuse. The plain code is never stored. These records delete themselves automatically within an hour.
Sensitive Information. We do not process sensitive personal information. Fona holds no patient records, no clinical information, no health information about you, no biometrics and no payment details.
Information we do NOT collect:
- Patient information of any kind
- Your location
- Your phone's contact list
- A record of the calls or emails you make, or their duration. Fona hands a number to your phone's dialler and takes no further part
- What you search for, which contacts or hospitals you open, or which numbers you dial. The usage counts described below never include them
- Your advertising identifier (IDFA on iPhone, Advertising ID on Android). The app is built without the code that reads it, and contains no advertising SDK and no crash-reporting SDK
- Payment or banking details: Fona is free and has no in-app purchases
Information automatically collected
In Short: Our hosting provider records standard technical information when your app talks to our servers.
Google Firebase, which hosts our authentication and database, records standard operational logs when your device connects, including IP address, timestamps, and the type of request made. These logs exist to run and secure the service. We do not build user profiles from them, and we do not use them for marketing.
Usage counts
In Short: We count installs, active users and which screens get used. We do not record what anybody looks up or calls.
We want to know whether Fona is being used, by roughly how many people, and which parts of it matter, so we know what to fix and whether to keep building it. Two services count this for us:
- Google Analytics for Firebase. Each installation of the app is given a random identifier by Google Analytics, which has nothing to do with your account, and is not your name, your email address or your device's advertising identifier. Against that identifier, Analytics records that the app was installed and opened, how long it was in use, the names of the screens you visited (for example 'Directory', 'Favourites' or 'Settings'), whether you signed in with a password, Google or Apple, your device model, operating system version, app version and language, and the country, region and nearest city your connection appears to come from. Google works that out from your IP address and then discards the address; Fona never asks your phone for its location. We have switched off the collection of advertising and device identifiers and the sharing of data for ad personalisation.
- RevenueCat. When you are signed in, the app gives RevenueCat your internal account identifier, a random string that is not your name or email address, together with your app version, platform and the country your connection appears to come from. This lets us count new and active accounts, rather than installations, alongside our other apps. RevenueCat is a subscription service and Fona has nothing to sell: no purchase is ever made or recorded, and RevenueCat receives no name, no email address and no payment detail.
Neither service receives your name, your email address, anything you type into Fona, the hospitals or contacts you view, your favourites, or any number you dial. We do not use this information to advertise to you, we do not sell it, and we do not combine it with information from other companies to follow you between apps.
Fona also asks the app stores whether a newer version is available, and may ask you to rate the app through Apple's and Google's own rating prompts. Neither sends us information about you.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to run the directory, to keep it honest, and to support you.
We process your personal information for the following reasons:
- To create and manage your account. So you can register, verify your email address, sign in, reset a forgotten password, and keep your account in working order.
- To confirm you can receive mail at the address you gave. Only verified users may edit directory content. This single check is what stands between an openly editable directory and anyone at all.
- To provide the Services. So you can search hospital directories, star contacts, set a default hospital, and dial from the app.
- To keep an audit trail. Every directory entry records which account created, edited or deleted it, and when. This lets a wrong or malicious edit be traced and undone, lets admins see who they are granting access to, and lets us block accounts that abuse the directory. It is the accountability that makes open editing workable.
- To administer hospital directories. So the admins of a directory can manage admins, block abusive users, and restore deleted entries.
- To respond to your enquiries and support requests, including reports of a wrong number, spam or abuse.
- To send you administrative messages, such as changes to these terms or to this notice, and security alerts.
- To protect the Services, including rate-limiting verification codes and investigating misuse.
- To understand, in aggregate, how much Fona is used: how many people install it, how many keep using it, and which screens they use, so we know what to improve. See 'Usage counts' in section 1.
- To comply with our legal obligations, or to establish, exercise or defend a legal claim.
We do not sell your personal information, we do not share it with advertisers, and we do not use it for automated decision-making or profiling.
3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
In Short: With the providers who host the service, and, by design, with the other users of a directory you edit.
Other users of the Services. Fona is a shared directory. The following is visible to other signed-in users:
- Every contact entry you add or edit, in the hospital directory you added it to
- Your name, shown against entries you created and in the admin list of any directory you administer
Your email address, your favourites, your profession and your default hospital are not visible to other users.
Service Providers. We share information with the following providers, who process it on our behalf:
- Google Firebase (Google Ireland Limited / Google LLC): authentication, database, cloud functions and hosting. Firebase holds your account credentials, your profile, your favourites and all directory content.
- Google Analytics for Firebase (Google Ireland Limited / Google LLC): usage counts, as described in section 1. It receives a per-installation identifier and app usage events, and not your name, email address or account.
- RevenueCat, Inc.: counts of new and active accounts, as described in section 1. It receives your internal account identifier, app version, platform and approximate country, and not your name or email address. Fona makes no purchases through it.
- Resend: delivery of verification and password-reset emails. Resend receives your email address and the message we send you.
- Google and Apple: if you choose to sign in with them, they confirm your identity to us.
- Apple App Store and Google Play: distribution of the app itself. They tell us nothing about you as an individual.
Cross-border transfer. Our providers store and process data on Google Cloud infrastructure located outside South Africa, primarily in the United States. Section 72 of POPIA permits this where the recipient is subject to laws or binding agreements providing an adequate level of protection; our providers are bound by data processing agreements to that effect. By using the Services you acknowledge this transfer.
Other situations in which we may share information:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Legal Requirements. We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
4. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: Account data for as long as you have an account; directory content for as long as the directory exists.
- Account information: kept while your account is active. When you delete your account, your profile, your favourites and your private record are deleted immediately, and your authentication record with them.
- Directory content: kept for as long as the hospital directory exists, including after the account that contributed it is deleted. A directory that lost entries whenever a colleague changed jobs would be worse than useless. Deleted entries are retained in a hidden state so an admin can restore an entry removed in error.
- Attribution after deletion: contact entries keep the internal account identifier of whoever wrote them, but once your account is deleted that identifier no longer resolves to any name or email address, in the app or anywhere else.
- Verification codes: hashed codes and their rate-limit counters delete themselves automatically within an hour.
- Support correspondence: kept for as long as needed to resolve your query and to defend against any related claim.
- Usage counts: Google Analytics keeps event-level data for two months, after which only aggregated totals remain. RevenueCat keeps the record of your internal account identifier until we delete it. Once your account is deleted that identifier no longer resolves to any name or email address, and we will delete the RevenueCat record itself if you ask us to at krikdex@gmail.com.
- Operational logs: retained by our hosting provider according to their standard retention periods, typically no more than 30 days for detailed logs.
5. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organisational and technical security measures.
We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. These include:
- Authentication: handled by Google Firebase Authentication. We never see or store your password; Firebase stores a salted hash. Passwords must be at least eight characters and mix upper case, lower case and numbers.
- Email verification: sign-up with an email address requires a six-digit code sent to that address. Codes expire after ten minutes, are stored only as a SHA-256 hash, allow five verification attempts, and are rate-limited to five sends per hour.
- Database security rules: enforced on the server, not in the app. Your email address, your favourites and your private record are readable only by you. Only verified, non-blocked accounts may write directory content. Only admins may restore or permanently remove a contact.
- Attribution enforced server-side: an account cannot write a change stamped with somebody else's identity.
- Transport encryption: all traffic between the app and our servers uses TLS.
- Minimisation: the single most effective safeguard is that Fona holds no patient information and no payment details, so there is none to lose.
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
6. THE SHARED DIRECTORY
In Short: Directory content is written by users, visible to all signed-in users, and meant to hold workplace contact details only. If your details appear and you want them gone, we will remove them.
How the directory works: Fona follows the open editing model that made the hospitals' previous directory service useful. Any verified, non-blocked user may add, correct or delete an entry in a hospital's directory, and every change is attributed to the account that made it. Any verified user may create a new hospital directory and becomes its first admin.
What belongs in a directory: workplace contact details for wards, departments, roles, on-call rotas and switchboards, which is the sort of number printed on a hospital's own internal directory sheet. Entries naming an individual should carry that person's work contact details, in their professional capacity.
What does not belong in a directory:
- Patient names, patient numbers, or any other patient information
- Personal mobile numbers or private email addresses, unless the person concerned has agreed to their being listed
- Any special personal information as defined by POPIA, such as health, race, religion, political affiliation, trade union membership, sexual orientation, or criminal history
- Comments about a colleague, or anything else you would not put on a noticeboard in the ward
Where the first entries came from: the directories that shipped with Fona were built from South African hospital directory exports obtained by hospital staff from the directory service they used before it withdrew from South Africa in 2026. This content was already in circulation as an internal directory in the hospitals concerned. If you find your details there, the removal route below applies just the same.
Removing your details: if your name, extension, number or email address appears in a directory and you would rather it did not, you may:
- Delete the entry yourself in the app
- Ask an admin of that hospital's directory to delete it
- Email us at krikdex@gmail.com and we will remove it, usually within a few working days
We will not require you to justify the request. A hospital admin may re-create an entry for a role, for example the number for 'Cardiology Registrar on call', but not one that names you against contact details you have asked to have removed.
Reporting a problem: Settings contains 'Report a directory problem' for a wrong number, spam or abuse. Where an account is repeatedly adding bad or abusive entries, an admin of that directory may block it and we may suspend it.
7. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at krikdex@gmail.com.
Note: Our Services are intended for people working in or with South African hospitals and are not intended for use by minors.
8. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: You may review, change, or terminate your account at any time.
Account Information: If you would at any time like to review or change the information in your account or terminate your account, you can:
- Update your name, profession and default hospital in the app under Settings, then Account
- Delete your account in the app under Settings, then Delete my account
- Contact us using the contact information provided below
Deleting your account permanently removes your profile, your email record and your favourites from our servers, removes you from the admin and blocked lists of every hospital directory, and deletes your sign-in credentials. Contact entries you contributed remain in their directories, unlinked from your identity, as described in section 4. We may retain a limited record of the deletion itself, and of any support correspondence, to prevent fraud, resolve disputes, enforce our legal terms and comply with applicable legal requirements.
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time by contacting us using the details in the section 'HOW CAN YOU CONTACT US ABOUT THIS NOTICE?' below, or by deleting your account.
However, please note that this will not affect the lawfulness of the processing before its withdrawal, nor when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
If you have questions or comments about your privacy rights, you may email us at krikdex@gmail.com.
9. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ('DNT') feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. In practice this makes little difference to Fona: the app contains no advertising or cross-app tracking technology to disable, and the usage counts described in section 1 are not used to follow you anywhere else.
10. PROTECTION OF PERSONAL INFORMATION ACT (POPIA) COMPLIANCE
In Short: We are committed to complying with South Africa's Protection of Personal Information Act.
Fona is designed with privacy-by-default principles in alignment with the Protection of Personal Information Act (POPIA) of South Africa. As a data subject you have the following rights under POPIA:
- Right to Access: You have the right to request confirmation of, and access to, the personal information we hold about you.
- Right to Correction: You have the right to request correction of inaccurate personal information.
- Right to Deletion: You have the right to request deletion of your personal information, subject to legal retention requirements.
- Right to Object: You have the right to object to the processing of your personal information on reasonable grounds.
- Right to Data Portability: You have the right to request a copy of your personal information in a commonly used format.
- Right to Complain: You have the right to lodge a complaint with the Information Regulator (South Africa) at enquiries@inforegulator.org.za.
Directory entries about you: if a directory entry contains your personal information, such as your name alongside a work extension, you hold these rights in respect of that entry too, whoever created it. See section 6 for how to have it removed.
Your responsibility as a contributor: when you add an entry naming a colleague, you are processing that person's personal information. Please do so only where it is contact information appropriate to a workplace directory, and remove it on request.
To exercise any of these rights, please contact us at krikdex@gmail.com.
11. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated 'Last updated' date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
12. PRICE AND PAID FEATURES
In Short: Fona is free. If that ever changes, you will be told well in advance.
Fona is currently free to download and use. There are no subscriptions, no in-app purchases and no advertising, and we do not collect payment or banking details. The app includes RevenueCat's software, which our other apps use to manage subscriptions; in Fona it only counts users (see section 1) and there is nothing in the app to buy.
We reserve the right to introduce paid features, subscription tiers or pricing in future. If we do:
- We will give at least 30 days' notice by in-app notification, by email to registered users, or both
- We will make clear which features are affected
- You may continue to use any features that remain free, or stop using the Services, rather than pay
- Any payment would be processed by the Apple App Store or Google Play, subject to their terms, and we would not receive your card details
13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at krikdex@gmail.com or by post to:
KRIKDEX (Pty) Ltd
Church Street
Graaff Reinet, Eastern Cape 6280
South Africa
14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances.
In the app, you can:
- Review and change your name, profession and default hospital under Settings, then Account
- Review the email address your account uses under Settings, then Account
- Add and remove your own favourites at any time
- Edit or delete any directory entry you can see
- Delete your account and everything attached to it under Settings, then Delete my account
By email: to request a copy of your personal information, to have it corrected, or to have a directory entry about you removed, contact us at krikdex@gmail.com. We will respond in accordance with applicable data protection law.
15. DISCLAIMERS AND LIMITATION OF LIABILITY
In Short: Directory numbers are contributed by users and may be wrong. Verify anything critical, and never rely on Fona in an emergency.
You acknowledge that you use Fona entirely at your own risk. While every effort is made to ensure the functionality of our app, we cannot guarantee error-free operation.
Directory Accuracy: Fona's contact information is contributed, edited and deleted by its users. We do not verify it, and we cannot guarantee that any number, extension, bleeper or email address is correct, current, or reaches the person or department it names. Numbers change, wards move, and entries go stale. You are responsible for confirming a number before relying on it for anything that matters.
Not an Emergency Service: Fona is not an emergency service and cannot connect you to one. Do not rely on it for cardiac arrest calls, emergency escalation, or any other time-critical contact. Use the numbers and procedures your hospital publishes for those, and know them independently of this app.
Not Clinical Software: Fona is a phone directory. It does not provide medical advice, hold patient records, or take any part in clinical decisions. All clinical decisions and all professional communications remain the sole responsibility of the healthcare professional making them.
Calls and Messages: Fona hands a number or address to your phone's own dialler or mail app. It does not place calls, send email, or record either. Your network operator's charges apply and their terms govern the call.
Availability: Fona depends on Google Firebase and on your device and network. We are not responsible for interruptions, errors, or data loss caused by third-party services, by loss of connectivity, or by your device.
Limitation of Liability: To the maximum extent permitted by applicable law, KRIKDEX (Pty) Ltd shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, use, goodwill, or other intangible losses, resulting from your use of the Services, from any incorrect or out-of-date directory entry, or from any failure to reach a person or department through the Services.
16. USER CONDUCT AND INDEMNIFICATION
In Short: Use Fona lawfully and professionally, and indemnify us against claims arising from your use.
Acceptable Use: You agree that your use of Fona is for lawful purposes only and in accordance with:
- South African law, including POPIA
- Your professional and employment obligations, including any duty of confidentiality
- The guidelines of your regulatory body, where you have one
- These terms and this privacy notice
Prohibited Activities: You may not:
- Add patient information, or any other confidential clinical information, to a directory
- Add a person's private contact details without their agreement
- Add deliberately false, misleading, offensive or abusive entries
- Extract, scrape, copy or export directory content in bulk, whether by automated means or otherwise
- Use directory content for marketing, recruitment, sales or any other unsolicited contact with hospital staff
- Sell, publish or otherwise redistribute directory content
- Share your account credentials, or use somebody else's account
- Attempt to write directory changes attributed to another account
- Interfere with the proper functioning of the Services, or attempt to disable, overburden or impair them
Indemnification: You agree to indemnify and hold KRIKDEX (Pty) Ltd, its subsidiaries, affiliates, agents, officers, employees, and content providers harmless from any claim, demand, or damage, including reasonable attorneys' fees, arising from:
- Your use of Fona
- Your violation of this privacy notice or of our Terms of Service
- Your violation of any rights of a third party, including the privacy rights of any person whose details you add to a directory
- Any breach of patient or workplace confidentiality on your part
17. YOUR RESPONSIBILITIES AS A DIRECTORY EDITOR
In Short: The directory is only as good, and as lawful, as the people editing it.
By adding to or editing a hospital directory, you acknowledge and agree to the following:
Accuracy:
- Add contact details you have reason to believe are correct
- Correct entries you find to be wrong rather than adding a duplicate
- Delete entries for wards, roles or numbers that no longer exist
Other people's information:
- Add work contact details only, in a person's professional capacity
- Do not add a private mobile number or personal email address without that person's agreement
- Remove an entry about a colleague if they ask you to
- Never add patient information
Attribution and accountability:
- Every change you make records your account and the time you made it, and your name is shown against entries you created
- Your account may be blocked from a directory by its admins, or suspended by us, if it is used to add false or abusive content
If you are an admin of a hospital directory:
- Grant admin rights only to colleagues who need them
- Use blocking to stop abuse, not disagreement
- Keep the dialling prefix and switchboard number correct, since every extension in that directory dials through them
Failure to comply with these responsibilities may result in your account being blocked or terminated, and may expose you to liability under POPIA or to your employer.