For organisations
Privacy Policy
Version 1.0 · Effective 4 August 2026
This notice explains how Tsor Med Ltd collects, uses and protects personal information relating to organisations that use the Tsor Med Organisation app to book locum cover — and the rights the individuals behind those accounts have over it.
It also sets out your responsibilities for the worker information you receive through the platform. If anything here is unclear, email privacy@locum-aid.com.
1. Who we are
Tsor Med Ltd (“Tsor Med”, “we”, “us”) operates the Tsor Med platform, which connects organisations that need temporary cover with the locum healthcare workers who can provide it. We are the data controller for the personal information described in this notice, which means we decide how and why it is used.
- Registered company: Tsor Med Ltd, company number 00000000
- Registered office: TODO: Registered office line 1, TODO: Town, TODO: Postcode, United Kingdom
- ICO registration: TODO: ZA000000
- Data protection contact: privacy@locum-aid.com
We handle personal information in line with the UK GDPR and the Data Protection Act 2018.
2. Who this notice is for
This notice is for organisations — the clinics, practices, pharmacies and care providers that use the Tsor Med Organisation app to post shifts and book locum cover — and for the individuals who administer those accounts.
If you are a locum worker looking for shifts, the privacy notice for workers applies to you instead.
Company information and personal information
Much of what an organisation gives us — a trading name, a CQC registration number, a VAT number — is company information rather than personal information, and data protection law does not apply to it. But details identifying a person, such as a named contact, their work email address or their direct phone number, are personal information. This notice covers the latter, and explains the rest for completeness.
3. The information we collect
Account holder details
- The name, email address, mobile number and password (stored only as a secure hash) of the person who administers the account.
- A profile photograph, if uploaded.
- Whether the email address has been verified, and the account status.
- The date your organisation accepted our Terms & Conditions, and which version.
Organisation profile
- Organisation name, description and logo.
- Address, city, postcode and the map coordinates derived from them.
- Contact telephone number and website.
- The name of your authorised representative or clinic contact.
- Business Identification Number (BIN), CQC registration number and VAT number.
- Any additional locations or branches you add, with their addresses and coordinates.
Verification documents
The documents we ask for to confirm your organisation is what it says it is — for example CQC registration, employer’s liability or public liability insurance, and other regulatory paperwork. We store the file, its original filename, any expiry date, its review status, and the reviewing staff member’s notes and decision.
Shifts and bookings
- Shifts you post, including dates, times, rates, location, required documents and whether the shift is urgent.
- Applications received, workers assigned, and timesheets submitted and approved.
- Cancellations, including when they happened relative to the shift and any fee that resulted.
- Ratings and reviews your organisation leaves about workers, and any decision to block a worker.
Billing
- Invoices raised to your organisation, for shift work and for cancellation fees.
- Platform, emergency and deduction fee rates applying to your account, and their payment status.
AI assistant configuration
If you enable the in-app assistant, we store the knowledge base you write for it — your services, opening hours, contact details, FAQs and policies — together with the conversations it handles and the messages exchanged.
Messages, support and technical information
- In-app chat messages, including conversations with our support desk.
- Support tickets you raise and our responses.
- A push notification token identifying your device, and whether push notifications are switched on.
- Standard server logs generated when the app talks to our servers.
4. Where the information comes from
Almost all of it comes directly from you. We also receive:
- Information from Google, if your administrator signs in with a Google account.
- Activity generated by our own systems as you use the platform — application history, invoice records and audit logs of administrative actions.
5. Why we use this information, and our legal basis
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your organisation account | So your team can sign in and use the platform | Performance of a contract |
| Verify your organisation and its documents | So workers can trust that the places they are sent to are genuine and properly registered | Legitimate interests; legal obligation |
| Publish your shifts to workers | So your vacancies get filled | Performance of a contract |
| Show your organisation name and location to workers | So a worker knows who they would be working for and where | Performance of a contract |
| Raise and settle invoices, including cancellation fees | So we can charge for the service and account for it | Performance of a contract; legal obligation |
| Send service messages — applications, bookings, document expiry, password resets | So you are not caught out by something you needed to know | Performance of a contract; legitimate interests |
| Send push notifications | So you hear about applications and updates promptly | Consent (you can switch these off at any time) |
| Provide the AI assistant | Because you chose to switch it on | Performance of a contract; consent |
| Handle support requests and chat | So we can help you and resolve disputes | Performance of a contract; legitimate interests |
| Prevent fraud and misuse; keep audit logs | To protect the platform, workers and other organisations | Legitimate interests; legal obligation |
| Keep financial and booking records after your account closes | So we can meet tax, accounting and legal claim obligations | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by the rights of the individuals concerned and concluded that it is not. You can ask us for that assessment, and you can object to this processing at any time.
6. Worker information you receive — your responsibilities
This is the part organisations most often overlook, so it is worth stating plainly.
When a worker applies for one of your shifts or is booked onto it, you receive personal information about them: their name, photograph, professional registration, biography, ratings and the status of their compliance documents. From the moment you receive it, your organisation is a separate and independent data controller for what it does with that information. You are not our processor, and we are not yours.
That means your organisation is responsible for:
- Having its own lawful basis for holding and using worker information.
- Telling workers how your organisation uses it, through your own privacy notice.
- Keeping it secure, and only for as long as you genuinely need it.
- Using it solely to assess, book and manage the cover you requested — not for unrelated recruitment, marketing, or sharing with third parties.
- Answering any data subject request a worker makes to you directly, and reporting any breach affecting it.
Please do not repurpose worker information
Approaching workers outside the platform to avoid fees, adding them to mailing lists, or passing their documents to another organisation are all misuses of that information. They breach our Terms & Conditions and may breach data protection law. We may suspend accounts that do this.
8. Automated decisions
We do not make decisions about your organisation by automated means that produce legal or similarly significant effects.
The platform does apply rules automatically — matching your shifts to suitable workers, calculating cancellation fees from the published fee ladder, and flagging documents that are close to expiry. These follow settings you can see, and a member of our team reviews any account suspension before it takes effect.
9. Sending information outside the UK
Our platform and its database are hosted in the United Kingdom. Some of the service providers listed above process information outside the UK — in particular Google (for the in-app assistant) and our push notification and email providers.
Where information leaves the UK, we rely on one of the safeguards permitted by the UK GDPR: an adequacy decision covering the destination country, or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) together with a transfer risk assessment. You can ask us for a copy of the safeguard that applies to a particular transfer by emailing privacy@locum-aid.com.
10. How long we keep your information
| What | How long | Why |
|---|---|---|
| Your active organisation profile and locations | While your account is open | To provide the service |
| Verification documents | Up to 6 years after your account closes | To evidence that an organisation was verified at the time it booked workers |
| Invoices, payments and cancellation fee records | 6 years from the end of the relevant financial year | Tax and accounting law |
| Shift, booking and cancellation history | Up to 6 years | To resolve disputes and defend legal claims within the limitation period |
| AI assistant knowledge base and conversations | While the assistant is enabled, then up to 12 months | To provide the feature and investigate issues with its answers |
| Support tickets and chat | Up to 3 years after the conversation closes | To handle follow-up questions and complaints |
| Audit logs of administrative actions | Up to 6 years | Accountability and security |
What happens when you close your account
Closing your account removes your organisation and its shifts from the platform, and workers can no longer find or apply to you.
We do not immediately erase the underlying record. Shifts, timesheets, invoices and audit logs refer to it, and we have to be able to explain historical staffing and payments to HMRC, an auditor, a regulator or a court. We keep the minimum needed for that, for the periods above, and then delete or anonymise it.
You can ask us to erase specific information sooner by emailing privacy@locum-aid.com.
11. Your rights
Under UK data protection law you have the right to:
- Be informed about how your information is used — which is what this notice is for.
- Access a copy of the personal information we hold about you.
- Rectification — have inaccurate information corrected. Most details can be corrected yourself in the app.
- Erasure — ask us to delete your information. This right is not absolute; see the retention section for what we must keep and why.
- Restrict processing — ask us to pause using your information while a concern is resolved.
- Data portability — receive information you gave us in a structured, commonly used, machine-readable format.
- Object — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time where we rely on consent, without affecting processing already carried out.
- Not be subject to solely automated decisions that produce legal or similarly significant effects — see the automated decisions section.
How to exercise a right
Email privacy@locum-aid.com. We respond within one month. If a request is complex we may extend this by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act, so that we do not disclose your information to somebody else.
12. How we keep information secure
We take appropriate technical and organisational measures to protect personal information, including:
- Encrypted connections (HTTPS/TLS) between the apps and our servers.
- Passwords stored only as salted one-way hashes — we cannot read your password, and nobody at Tsor Med can tell you what it is.
- Access controls in the admin portal, so staff only reach the areas their role requires, with sensitive actions written to an audit log.
- Email verification at sign-up and one-time codes for password resets.
- Uploaded documents served only to the account that owns them and to authorised staff reviewing them.
No online service can be completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you directly where the law requires it.
14. Children
The Tsor Med platform is intended for people aged 18 and over, and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe a child has given us personal information, contact privacy@locum-aid.com and we will delete it.
15. Changes to this notice
We review this notice regularly and may update it as the platform changes. The version number and effective date at the top of this page always tell you which version you are reading. Where a change materially affects how we use your information, we will tell you in the app or by email before it takes effect, rather than relying on you to re-read this page.
16. Contact us and how to complain
Contact us first
If you have a question or a concern about how we handle your information, please contact us — we would rather hear about it and put it right.
- Data protection: privacy@locum-aid.com
- General support: support@locum-aid.com
- Post: TODO: Registered office line 1, TODO: Town, TODO: Postcode, United Kingdom
Complaining to the regulator
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can do so at any time — you do not have to contact us first.
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF