For locum workers
Privacy Policy
Version 1.0 · Effective 4 August 2026
This notice explains how Tsor Med Ltd collects, uses and protects personal information about locum healthcare workers who use the Tsor Med app — and the rights you have over that information.
We have written it in plain English rather than legal shorthand. If anything here is unclear, email privacy@locum-aid.com and we will explain it.
1. Who we are
Tsor Med Ltd (“Tsor Med”, “we”, “us”) operates the Tsor Med platform, which connects locum healthcare workers with the organisations that need temporary cover. We are the data controller for the personal information described in this notice, which means we decide how and why it is used.
- Registered company: Tsor Med Ltd, company number 00000000
- Registered office: TODO: Registered office line 1, TODO: Town, TODO: Postcode, United Kingdom
- ICO registration: TODO: ZA000000
- Data protection contact: privacy@locum-aid.com
We handle personal information in line with the UK GDPR and the Data Protection Act 2018.
2. Who this notice is for
This notice is for locum workers — the healthcare professionals who register on the Tsor Med app to find and take shifts. It explains what we collect about you, why, and what control you have over it.
If you represent a clinic, practice or care provider that posts shifts, the privacy notice for organisations applies to you instead.
A note on the organisations you work with
When you apply for or are booked onto a shift, the organisation receives your details and becomes a separate data controller for what it does with them — including its own record-keeping and staffing obligations. This notice covers our use of your information; the organisation’s own privacy notice covers theirs.
3. The information we collect about you
Account and identity
- Your name, email address, mobile number and password (stored only as a secure hash).
- Your profile photograph, if you upload one.
- Your Google account identifier, if you choose to sign in with Google.
- Whether your email address has been verified, and your account status (for example awaiting approval, approved, suspended).
- The date you accepted our Terms & Conditions, and which version you accepted.
Professional details
- Your professional registration number and the body you are registered with (for example GMC, GDC, NMC, HCPC or GPhC).
- Your professional category and any sub-specialities you select.
- The biography you write about yourself.
Compliance documents
To work through the platform you upload the documents an organisation needs to see before it can book you — for example a DBS certificate, proof of identity or right to work, professional indemnity insurance, qualifications, immunisation records and training certificates. We store the file, its original filename, any expiry date, its review status, and the notes and decision of the member of staff who reviewed it.
Sensitive information
Some of these documents contain special category data (such as health or immunisation information) or criminal offence data (a DBS certificate). We treat these with extra care — see the section on sensitive information below.
Availability, location and rates
- Your working availability by day of the week and the hours you can work.
- The location you set as your base, including its latitude and longitude, and how far you are willing to travel.
- The minimum hourly rate you are prepared to accept.
Location comes from the address or place name you enter, which we convert to map coordinates so we can show you nearby shifts. We do not track your device’s location in the background.
Payment and tax details
- Your bank name, account holder name, account number and sort code, so you can be paid.
- Your National Insurance number.
- Your timesheets, payments, withdrawal requests and any referral or coupon rewards.
Your activity on the platform
- Shifts you view, apply for, are assigned to, complete or cancel.
- Timesheets you submit and whether they were approved.
- Ratings and written reviews organisations leave about you.
- Any record of you being blocked by an organisation or by us, and the reason.
- Cancellation records, including when a cancellation happened relative to the shift.
Messages and support
- Messages you send and receive in the in-app chat, including support conversations.
- Support tickets you raise, and our responses.
- Notifications we have sent you.
- Conversations with the in-app AI assistant, where an organisation has enabled it.
Device and technical information
- A push notification token identifying your device, and whether you have push notifications switched on.
- Standard server logs generated when the app talks to our servers.
4. Where the information comes from
Most of it comes directly from you. We also receive information:
- From Google, if you choose to sign in with your Google account (your name, email address and account identifier).
- From organisations you work with — ratings, reviews, timesheet approvals, cancellations and any decision to block you.
- From our own systems — generated as you use the platform, such as application history and audit records of administrative actions.
5. Why we use your information, and our legal basis
We must have a lawful basis for every use of your personal information. Ours are set out below.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | So you can sign in, be identified and use the app | Performance of a contract |
| Verify your identity, registration and documents | So organisations can rely on the fact that anyone they book is qualified and cleared to work | Legal obligation; performance of a contract; substantial public interest |
| Match you to shifts and show you relevant vacancies | So you see work near you, at your rate, in your speciality | Performance of a contract |
| Share your profile with an organisation when you apply or are booked | So the organisation can decide on your application and manage the booking | Performance of a contract |
| Process timesheets, payments and withdrawals | So you are paid for the work you do | Performance of a contract; legal obligation (tax and accounting) |
| Send service messages — bookings, approvals, document expiry reminders, password resets | So you are not caught out by something you needed to know | Performance of a contract; legitimate interests |
| Send push notifications | So you hear about shifts and updates promptly | Consent (you can switch these off at any time) |
| Handle support requests and chat | So we can help you and resolve disputes | Performance of a contract; legitimate interests |
| Ratings, reviews and blocking | To keep the platform safe and reliable for workers and patients | Legitimate interests |
| Prevent fraud, misuse and duplicate accounts; keep audit logs | To protect the platform, organisations and other workers | Legitimate interests; legal obligation |
| Keep financial and booking records after your account closes | So we can meet tax, accounting and legal claim obligations | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded that it is not. You can ask us for that assessment, and you can object to this processing at any time.
6. Sensitive information: health and criminal records
Some of what you upload needs extra protection under the law, and we need an additional lawful condition to handle it at all.
Special category data
Health-related information — immunisation status, occupational health clearance, or a health condition mentioned in a document — is special category data. We process it under Article 9(2)(b) UK GDPR (obligations in the field of employment and social security law) and Article 9(2)(g) (substantial public interest), relying on the conditions in Schedule 1 of the Data Protection Act 2018 for employment and for regulatory requirements relating to health care.
Criminal offence data
A DBS certificate is criminal offence data under Article 10 UK GDPR. We process it because safe recruitment into healthcare roles requires it, relying on the Schedule 1 conditions covering employment and the safeguarding of individuals. We do not use it for any purpose other than confirming your eligibility to work.
How we limit it
- Only staff whose role requires it can open your compliance documents.
- Organisations see whether your required documents are valid and in date — they do not get an unrestricted copy of every file you upload.
- We keep an appropriate policy document covering our processing of special category and criminal offence data, as Schedule 1 requires. You can request a copy.
8. Automated decisions
Two parts of the platform work automatically, and we want to be straightforward about them.
Shift matching
We rank and filter the shifts you see using your speciality, your location and travel distance, your stated minimum rate and your availability. This decides what you are shown; it does not decide whether you get the work — an organisation does that.
Automatic blocking on low ratings
If your average rating falls below a threshold set by our administrators, and you have received at least a minimum number of reviews, the system can block your account from applying for further shifts automatically. Because this can significantly affect your ability to get work, you have the right under Article 22 UK GDPR to:
- Ask for a human being to review the decision.
- Put your side of it and explain any circumstances behind the ratings.
- Challenge the decision and ask for the block to be lifted.
Email support@locum-aid.com and a member of our team — not the system — will look at it. We do not carry out any other profiling that produces legal or similarly significant effects.
9. Sending information outside the UK
Our platform and its database are hosted in the United Kingdom. Some of the service providers listed above process information outside the UK — in particular Google (for the in-app assistant) and our push notification and email providers.
Where information leaves the UK, we rely on one of the safeguards permitted by the UK GDPR: an adequacy decision covering the destination country, or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) together with a transfer risk assessment. You can ask us for a copy of the safeguard that applies to a particular transfer by emailing privacy@locum-aid.com.
10. How long we keep your information
We keep information only as long as we need it, but some records we are required to keep even after you leave.
| What | How long | Why |
|---|---|---|
| Your active profile, documents and availability | While your account is open | To provide the service |
| Compliance documents | Up to 6 years after your last shift | To evidence that a worker placed on a shift was cleared at the time |
| Timesheets, payments, invoices and withdrawals | 6 years from the end of the relevant financial year | Tax and accounting law |
| Booking and cancellation history | Up to 6 years | To resolve disputes and defend legal claims within the limitation period |
| Support tickets and chat | Up to 3 years after the conversation closes | To handle follow-up questions and complaints |
| Audit logs of administrative actions | Up to 6 years | Accountability and security |
What happens when you delete your account
When you delete your account, we close it, sign you out and stop using your profile — you disappear from the platform and organisations can no longer find or book you.
We do not immediately erase the underlying record. Shifts, timesheets, invoices and audit logs refer to it, and we have to be able to explain historical staffing and payments to HMRC, an auditor, a regulator or a court. We keep the minimum needed for that, for the periods above, and then delete or anonymise it.
You can ask us to erase specific information sooner by emailing privacy@locum-aid.com. We will do so unless we are legally required to keep it, and we will tell you which is which.
11. Your rights
Under UK data protection law you have the right to:
- Be informed about how your information is used — which is what this notice is for.
- Access a copy of the personal information we hold about you.
- Rectification — have inaccurate information corrected. Most details can be corrected yourself in the app.
- Erasure — ask us to delete your information. This right is not absolute; see the retention section for what we must keep and why.
- Restrict processing — ask us to pause using your information while a concern is resolved.
- Data portability — receive information you gave us in a structured, commonly used, machine-readable format.
- Object — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time where we rely on consent, without affecting processing already carried out.
- Not be subject to solely automated decisions that produce legal or similarly significant effects — see the automated decisions section.
How to exercise a right
Email privacy@locum-aid.com. We respond within one month. If a request is complex we may extend this by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act, so that we do not disclose your information to somebody else.
12. How we keep information secure
We take appropriate technical and organisational measures to protect personal information, including:
- Encrypted connections (HTTPS/TLS) between the apps and our servers.
- Passwords stored only as salted one-way hashes — we cannot read your password, and nobody at Tsor Med can tell you what it is.
- Access controls in the admin portal, so staff only reach the areas their role requires, with sensitive actions written to an audit log.
- Email verification at sign-up and one-time codes for password resets.
- Uploaded documents served only to the account that owns them and to authorised staff reviewing them.
No online service can be completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you directly where the law requires it.
14. Children
The Tsor Med platform is intended for people aged 18 and over, and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe a child has given us personal information, contact privacy@locum-aid.com and we will delete it.
15. Changes to this notice
We review this notice regularly and may update it as the platform changes. The version number and effective date at the top of this page always tell you which version you are reading. Where a change materially affects how we use your information, we will tell you in the app or by email before it takes effect, rather than relying on you to re-read this page.
16. Contact us and how to complain
Contact us first
If you have a question or a concern about how we handle your information, please contact us — we would rather hear about it and put it right.
- Data protection: privacy@locum-aid.com
- General support: support@locum-aid.com
- Post: TODO: Registered office line 1, TODO: Town, TODO: Postcode, United Kingdom
Complaining to the regulator
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can do so at any time — you do not have to contact us first.
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF