Privacy Policy

Last updated: 26 September 2026

Krikdex (Pty) Ltd ("Krikdex", "we") publishes Rota, a mobile app in which staff at South African hospitals share their departments' call rosters. This policy explains what personal information Rota processes, why, and what your rights are under the Protection of Personal Information Act 4 of 2013 ("POPIA"). It applies to the Rota app for iOS and Android and to the Rota pages on krikdex-sa.com, and to rosters sent to Rota by email (rota.roster@gmail.com).

1. Who is responsible

Krikdex (Pty) Ltd, Church Street, Graaff-Reinet, Eastern Cape, 6280, South Africa, is the responsible party. Our Information Officer is Leo Scheepers, reachable at krikdex@gmail.com.

2. What Rota is

Rota is a shared notice board. A signed-in, verified user uploads a department's monthly on-call roster as a photo, PDF, Word or Excel file, and other signed-in users open it. Rota does not process patient information and is not connected to any hospital's own systems.

3. Information we collect

Account information. Your email address, the display name you enter, whether the address is verified, an account identifier issued by Firebase Authentication, and the dates you created the account and last used it.

One-time codes. When you sign in or reset your password we generate a short-lived code and send it to your email address. The code expires within minutes and its record is purged automatically shortly after.

Content you upload. The roster file itself, plus the hospital, department, month and year you chose, the file's name, type and size, and the time of upload. Each upload is linked to your account identifier.

Rosters sent by email. A roster can be emailed to rota.roster@gmail.com instead of uploaded in the app. When you do that we process the email: your address and the name shown with it, the subject, the message, the attached files, and the delivery information your mail provider adds (which is how we check that the email really came from your address). We read the hospital, department and month from the subject, the message and the file names; no person reads it, and we do not read what is inside the roster. If something is missing we email you a question, and we keep the roster until you answer. A short record of each email (your address, the subject, the first few hundred characters of your message, the file names, and what Rota did with it) is kept so that a mistake can be traced. The email itself also remains in the rota.roster@gmail.com mailbox, which is a Google account we control.

An account made by email. If you email a roster from an address that has no Rota account, we ask you first, and nothing is published until you reply YES. Your YES creates a Rota account for that address: verified, with no password, named as your email names you, with the hospital and department of that roster. It is an ordinary account: you can set a password for it in the app with a code sent to the address, and you can delete it by replying STOP to any email from Rota, or in the app.

Activity records. Rota keeps a history of changes for each hospital: who uploaded, replaced, deleted or restored which roster and when, and whether it arrived by email. This is what lets department admins undo damage and see who did what.

Admin information. If you request admin access we store your request and the message you write (up to 300 characters). Admin roles, blocks and temporary pauses are stored against your account identifier.

Support correspondence. Emails you send to krikdex@gmail.com.

Crash reports. When the app crashes, or meets an error it cannot recover from, it sends a report to Firebase Crashlytics: what went wrong and where in Rota's code, the phone's model and operating system version, the app version, and an identifier for this installation of the app. Rota does not add your name, email address or account identifier to these reports, and they do not contain your rosters. They are how we find and fix faults.

Information stored only on your device. Downloaded roster files, the cached hospital and roster lists, your default hospital, recent hospitals, sync timestamps and the counters behind the occasional "rate this app" prompt live on your phone and are not sent to us. Settings › Downloaded rosters clears the files; deleting the app clears everything.

What we do not collect. Location, contacts, device identifiers for advertising, or usage analytics. Rota contains no advertising or analytics software.

4. Information about other people

A call roster names colleagues and their duty dates, and sometimes more. When you upload one you are sharing other people's personal information, and you must be entitled to do so: a roster your department has already put on its notice board normally qualifies. Do not upload patient information, personal (non-work) phone numbers, home addresses or anything else that does not belong on a notice board. If you are named on a roster in Rota and object to it, tell the department's admin or email us; we will remove it.

5. Why we process your information and on what basis

PurposeInformationBasis under POPIA
Creating and securing your account, verifying your emailaccount information, one-time codesperformance of our agreement with you (the Terms)
Publishing rosters to other userscontent you uploadperformance of our agreement; the uploader's lawful basis for the roster's contents
Attributing changes and moderating abuseactivity records, admin informationour legitimate interest in keeping the service honest and usable, and users' interest in an accurate roster
Answering yousupport correspondenceour legitimate interest in supporting users
Complying with law and enforcing the Termsany of the abovelegal obligation; legitimate interest

We do not use your information for marketing and we do not sell it.

6. Who can see what

  • Other users. Any signed-in, verified Rota user can open any roster and see its department, month and the display name of the person who uploaded it. Rota is not a private channel between members of one department.
  • Hospital admins. Admins of a hospital see the history of changes at that hospital with uploaders' names, and may delete rosters, block users and lock the hospital's rosters.
  • Krikdex. Our superadministrator can see everything above across all hospitals, approves admin requests, and receives an email when the system pauses an account for excessive activity.

7. Service providers (operators)

We use the following operators, each bound by contract to process your information only on our instructions:

  • Google LLC (Firebase). Authentication (accounts and sign-in), Cloud Firestore (hospital, roster and history records), Cloud Storage (roster files), Cloud Functions (server logic such as sending codes and writing the history), Crashlytics (crash reports) and Firebase Hosting. Firestore and Storage data is held in the africa-south1 (Johannesburg) region. Authentication, Cloud Functions and Crashlytics run in the United States.
  • Resend, Inc. Delivers our one-time codes and notification emails, and receives the rosters emailed to Rota and the replies to Rota's questions. Resend processes your email address and the email content, attachments included, in the United States and the European Union.
  • Google LLC (Gmail). The address rosters are emailed to is a Gmail mailbox, which forwards each email to Resend and keeps a copy. Google processes those emails under its own terms.
  • Apple Inc. and Google LLC distribute the app through their stores and operate the optional in-app rating prompt under their own privacy policies.

8. Transfers outside South Africa

Where an operator processes information in the United States (section 7), the transfer relies on section 72(1)(a) of POPIA: the operator is bound by contractual terms that provide protection substantially similar to POPIA's conditions for lawful processing.

9. How long we keep information

InformationRetention
Roster files and recordsdeleted automatically 125 days after upload, or 21 days for a daily roster (replaced or retired rosters on the same schedule); files deleted with their records
A roster emailed in and waiting for your answerdeleted 14 days after it arrived if you have not answered; the stored file within 30 days
The record of each email sent to Rota30 days
Emails in the rota.roster@gmail.com mailboxuntil we clear the mailbox, at least once a year
History of changes365 days
One-time codesexpire within minutes; records purged automatically shortly after
Account information, admin roles, blocks, pausesuntil you delete your account
Admin requestsuntil decided, then as part of the history until you delete your account
Crash reports90 days
Support emailsas long as needed to resolve the matter

Replying STOP to any email from Rota stops Rota from accepting rosters from, or writing to, that address; we keep the address itself on a list for that purpose only. If your account was made by email, STOP also deletes it.

What happens to your information when you delete your account is set out in section 12.

10. Security

Traffic between the app and our operators is encrypted in transit and stored encrypted at rest. Access to roster files and records requires a signed-in, verified account and is enforced by server-side rules on every request. Every write records who made it and when, and a limit on changes per day pauses accounts that behave like scripts. No system is perfectly secure; if we learn of a breach affecting your information we will notify you and the Information Regulator as POPIA requires.

11. Your rights

You may ask us to confirm whether we hold personal information about you, to give you access to it, to correct it, or to delete it; you may object to processing based on our legitimate interests; and you may withdraw consent where processing relied on it. Most of this you can do yourself in the app (Settings › Account details, Settings › Delete my account). For anything else email krikdex@gmail.com. We answer within a reasonable time and without charge unless the law allows one.

12. Deleting your account

You can delete your Rota account in the app or without it.

In the app. Open Settings › Delete my account and enter your password to confirm. The account is deleted at once, together with the recent hospitals and downloaded rosters on that phone.

Without the app. Email krikdex@gmail.com with the subject "Delete my Rota account", sent from the email address you use for Rota; that is how we know the request is yours. We delete the account and confirm by email. If your account was made by email (section 3), replying STOP to any email from Rota also deletes it.

Deleted at once: your sign-in, email address and display name, admin roles, blocks, pauses, admin requests and verification records.

Kept after deletion:

InformationHow long
Rosters you uploaded, which stay up for your colleaguesuntil they expire: 125 days after upload, or 21 days for a daily roster
The history of changesits entries run out 365 days after each change
The record of each email you sent to Rota30 days
Those emails in the rota.roster@gmail.com mailboxuntil we clear the mailbox, at least once a year
Crash reports90 days
Support emails you sent usas long as needed to resolve the matter
Your email address, if you replied STOPkept on the STOP list only, so Rota neither writes to it nor accepts rosters from it

Rosters and history entries refer only to an account identifier that no longer resolves to your name or email address. Crash reports never contained either.

Deleting some information but keeping your account. Email krikdex@gmail.com from your Rota address and say what you want removed, a roster you uploaded for example.

13. Complaints

If you believe we have processed your information unlawfully you may lodge a complaint with the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; complaints.IR@inforegulator.org.za; www.inforegulator.org.za. We would appreciate the chance to resolve the matter first.

14. Children

Rota is for people aged 18 and over. We do not knowingly collect information from anyone younger; if you believe a minor has an account, tell us and we will delete it.

15. Automated decisions

The only automated decision Rota makes is to pause an account temporarily when it makes more changes in a day than our limit allows. A pause is lifted automatically and can be lifted sooner by emailing us.

16. Links

The app links to the Apple App Store, Google Play, our other apps and this website. Those services have their own privacy policies.

17. Changes to this policy

We may update this policy as Rota changes. The date at the top shows the latest version; material changes will be pointed out in the app.

18. Contact

Krikdex (Pty) Ltd
Church Street, Graaff-Reinet, Eastern Cape, 6280, South Africa
krikdex@gmail.com

← Back to Rota