Privacy Policy
How CaseThread collects, uses, protects and shares personal information, in line with the Protection of Personal Information Act, 2013 (POPIA).
Last updated: Draft — not yet published
Who we are
This Privacy Policy explains how CaseThread (operated by [UPDATE — registered entity name, e.g. Optimiz Solutions (Pty) Ltd], company registration number [UPDATE — CIPC reg no.], of [UPDATE — registered physical address], South Africa) handles personal information when a social-work practice and its clients use CaseThread.
CaseThread is practice-management software for South African social-work practices. This policy is issued under POPIA and should be read with our Terms of Service, our Cookie & Tracking Policy, our Sub-processors list and — for practices — our Data Processing Agreement.
Two roles: when we are the responsible party, and when we are the operator
For account and billing information about the practice and its team members, CaseThread is the responsible party — we decide why and how that information is processed.
For the client case information a practice captures in CaseThread (clients, sessions, notes, assessments, documents, invoices), the practice is the responsible party and CaseThread is the operator: we process that information only on the practice's documented instructions, under our Data Processing Agreement. Questions about a specific client's case record should be directed to the practice that holds it.
Information we process
Account & practice details you provide at sign-up: name, work email, practice name, role, and — for professionals — registration details such as an SACSSP number.
Billing information: your plan, seat count and billing history. Card details are handled by our payment processor (PayFast) and are not stored by CaseThread.
Case information entered by the practice: client identity and contact details, next-of-kin/guardian details, case notes, assessments, care plans, statutory deadlines, documents, scheduling and invoicing data. This may include special personal information and children's information (see below).
Technical & usage information: log data, device/browser information, and pseudonymous product-usage events (opaque user/organisation identifiers only — never case content, names or note text). See our Cookie & Tracking Policy.
Communications: emails and SMS we send on the practice's behalf (booking confirmations, reminders, invoices, invites) and any messages you send us.
Why we use it, and our lawful basis
To provide, secure and support the service, and to administer accounts and team access — on the basis of performing our contract with the practice (POPIA §11(1)(b)) and our legitimate interests in running and protecting the service (§11(1)(f)).
To process subscription payments and meet accounting obligations — contract and legal obligation (§11(1)(c)).
To send transactional email and SMS relating to the service and to bookings/appointments — contract, and, for client-facing SMS reminders, the consent captured at booking (§11(1)(a)).
To detect and prevent abuse, fraud and security incidents, and to comply with law — legitimate interests and legal obligation.
We do not sell personal information, and we do not use case content for advertising or to train any model.
Special personal & children's information
Case records may include special personal information (for example health or social-circumstance information) and children's information. Where CaseThread is the operator, the practice is responsible for establishing the lawful basis for this — including the professional/legal grounds in POPIA §27 and §32, and the competent-person (guardian) consent required under §34–§35 for children.
CaseThread provides in-app consent tools (data-processing, intervention, third-party and guardian consent) to help practices capture and evidence that basis.
Sharing & sub-processors
We share personal information only with the vetted sub-processors that help us run the service, each bound by appropriate data-protection terms. See the Sub-processors page for the current list, their purpose and region.
We may also disclose information where required by law, to protect our rights or safety, or as part of a business transfer — in each case subject to POPIA.
International transfers & hosting
CaseThread runs on managed EU-hosted cloud infrastructure. Because some processing and sub-processors are outside South Africa, cross-border processing relies on the POPIA §72 safeguards — principally data-processing agreements with each sub-processor that impose an adequate level of protection. We do not claim in-country (South African) hosting.
Security
We maintain appropriate technical and organisational measures, including encryption in transit and at rest, row-level access control on every case record so users see only what their role permits, rate limiting and bot defence on public forms, access and admin-action logging, sanitised error handling, and a documented backup and recovery process. No system is perfectly secure, but we work to protect personal information in line with POPIA §19.
Cookies & analytics
CaseThread uses strictly-necessary cookies only (sign-in session, security and, before launch, a preview-access cookie). Our marketing analytics are cookieless and our in-app analytics are server-side and pseudonymous. Full detail is in the Cookie & Tracking Policy.
Your rights
Subject to our legal and professional obligations, you may request access to the personal information we hold about you, ask us to correct or delete it, and object to certain processing (POPIA §23–§25 and §11(3)).
For client case data held by a practice, direct the request to that practice — as operator we assist them through the in-app data-subject-request tooling (export and erase) to a documented schedule.
What deletion means in practice. When a deletion request is actioned we remove the information from our live systems straight away, and it stops appearing in the service immediately. Copies survive in our backups for a short period afterwards — up to seven days for database records and up to 90 days for uploaded documents — and are then erased automatically as those backups age out. We keep it that way on purpose: a backup that deleted whatever the live system deleted would faithfully copy an accidental or malicious wipe and leave nothing to restore from. During that period the copies are used only to recover the service after a failure.
What survives an erasure. Two things outlast the record itself, and both are deliberate. A receipt that the erasure was carried out — its date and the name of the person it concerned — stays on the practice's data-request register, because a practice has to be able to show a request was honoured; it carries no case information. And where messages were sent about that client, the send log row is kept with the mobile number and the message text removed, so the practice's billing history stays intact without holding the content or the number.
You may also lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
Retention
Account and billing records are kept for as long as the account is active and thereafter as required by law (for example tax and accounting rules).
Case records are kept for as long as the practice's own retention schedule and the law require, and are then deleted. CaseThread deletes nothing automatically. Closing a case archives it; no record is removed on a timer, and none is removed unless somebody asks for it. A practice can erase an individual client's record from that client's case file, which permanently removes the case, its notes, documents, invoices and access log (see Backups below for how long a copy may persist in backup). Operating a retention schedule against the applicable periods is the practice's responsibility as the responsible party under POPIA §14; the retention table in Settings is a starting point for that schedule, not something CaseThread enforces. [UPDATE — confirm the statutory minimum retention periods, including for children's records, with counsel/the profession.]
Backups. The database is backed up daily by our hosting provider and retained for approximately seven days. Uploaded case documents are copied nightly to separate encrypted storage in the European Union and retained there for a maximum of 90 days on a rolling basis. Backups exist so the service can be restored after a failure; they are not used for any other purpose, are not consulted to answer day-to-day requests, and are not restored into the live service except as part of recovering from an incident.
Changes to this policy
We may update this policy from time to time. We will change the effective date above and, for material changes, give reasonable notice.
Contact
CaseThread's Information Officer is [UPDATE — Information Officer full name]. For any privacy, access or data-protection query — including data-subject requests and PAIA requests — contact the Information Officer at legal@casethread.co.za, [UPDATE — postal address], [UPDATE — contact phone number].
More: Terms of Service · PAIA Manual · Data Processing Agreement · Cookie & Tracking Policy · Billing, Refund & Cancellation Policy · Acceptable Use Policy · Sub-processors