Tsor MedGet the app

For organisations

Privacy Policy

Version 1.0 · Effective 4 August 2026

This notice explains how Tsor Med Ltd collects, uses and protects personal information relating to organisations that use the Tsor Med Organisation app to book locum cover — and the rights the individuals behind those accounts have over it.

It also sets out your responsibilities for the worker information you receive through the platform. If anything here is unclear, email privacy@locum-aid.com.

1. Who we are

Tsor Med Ltd (“Tsor Med”, “we”, “us”) operates the Tsor Med platform, which connects organisations that need temporary cover with the locum healthcare workers who can provide it. We are the data controller for the personal information described in this notice, which means we decide how and why it is used.

  • Registered company: Tsor Med Ltd, company number 00000000
  • Registered office: TODO: Registered office line 1, TODO: Town, TODO: Postcode, United Kingdom
  • ICO registration: TODO: ZA000000
  • Data protection contact: privacy@locum-aid.com

We handle personal information in line with the UK GDPR and the Data Protection Act 2018.

2. Who this notice is for

This notice is for organisations — the clinics, practices, pharmacies and care providers that use the Tsor Med Organisation app to post shifts and book locum cover — and for the individuals who administer those accounts.

If you are a locum worker looking for shifts, the privacy notice for workers applies to you instead.

Company information and personal information

Much of what an organisation gives us — a trading name, a CQC registration number, a VAT number — is company information rather than personal information, and data protection law does not apply to it. But details identifying a person, such as a named contact, their work email address or their direct phone number, are personal information. This notice covers the latter, and explains the rest for completeness.

3. The information we collect

Account holder details

  • The name, email address, mobile number and password (stored only as a secure hash) of the person who administers the account.
  • A profile photograph, if uploaded.
  • Whether the email address has been verified, and the account status.
  • The date your organisation accepted our Terms & Conditions, and which version.

Organisation profile

  • Organisation name, description and logo.
  • Address, city, postcode and the map coordinates derived from them.
  • Contact telephone number and website.
  • The name of your authorised representative or clinic contact.
  • Business Identification Number (BIN), CQC registration number and VAT number.
  • Any additional locations or branches you add, with their addresses and coordinates.

Verification documents

The documents we ask for to confirm your organisation is what it says it is — for example CQC registration, employer’s liability or public liability insurance, and other regulatory paperwork. We store the file, its original filename, any expiry date, its review status, and the reviewing staff member’s notes and decision.

Shifts and bookings

  • Shifts you post, including dates, times, rates, location, required documents and whether the shift is urgent.
  • Applications received, workers assigned, and timesheets submitted and approved.
  • Cancellations, including when they happened relative to the shift and any fee that resulted.
  • Ratings and reviews your organisation leaves about workers, and any decision to block a worker.

Billing

  • Invoices raised to your organisation, for shift work and for cancellation fees.
  • Platform, emergency and deduction fee rates applying to your account, and their payment status.

AI assistant configuration

If you enable the in-app assistant, we store the knowledge base you write for it — your services, opening hours, contact details, FAQs and policies — together with the conversations it handles and the messages exchanged.

Messages, support and technical information

  • In-app chat messages, including conversations with our support desk.
  • Support tickets you raise and our responses.
  • A push notification token identifying your device, and whether push notifications are switched on.
  • Standard server logs generated when the app talks to our servers.

4. Where the information comes from

Almost all of it comes directly from you. We also receive:

  • Information from Google, if your administrator signs in with a Google account.
  • Activity generated by our own systems as you use the platform — application history, invoice records and audit logs of administrative actions.

6. Worker information you receive — your responsibilities

This is the part organisations most often overlook, so it is worth stating plainly.

When a worker applies for one of your shifts or is booked onto it, you receive personal information about them: their name, photograph, professional registration, biography, ratings and the status of their compliance documents. From the moment you receive it, your organisation is a separate and independent data controller for what it does with that information. You are not our processor, and we are not yours.

That means your organisation is responsible for:

  • Having its own lawful basis for holding and using worker information.
  • Telling workers how your organisation uses it, through your own privacy notice.
  • Keeping it secure, and only for as long as you genuinely need it.
  • Using it solely to assess, book and manage the cover you requested — not for unrelated recruitment, marketing, or sharing with third parties.
  • Answering any data subject request a worker makes to you directly, and reporting any breach affecting it.

Please do not repurpose worker information

Approaching workers outside the platform to avoid fees, adding them to mailing lists, or passing their documents to another organisation are all misuses of that information. They breach our Terms & Conditions and may breach data protection law. We may suspend accounts that do this.

7. Who we share your information with

We do not sell your information and we do not share it for anyone else’s marketing.

Workers on the platform

Workers see your organisation name, logo, description, location and the details of the shifts you post, together with ratings you have received. Your billing details, verification documents and internal fee arrangements are not shown to workers.

Service providers acting on our instructions

ProviderWhat they doWhat they receive
Our UK hosting and database providerRuns the servers and stores the platform's dataAll platform data, at rest
Email delivery providerSends verification codes, booking updates and invoicesContact name, email address and the message content
Push notification provider (Expo)Delivers notifications to your deviceYour device push token and the notification text
Google (Gemini)Powers the AI assistant, if you enable itThe knowledge base you configure and the messages the assistant handles
OpenStreetMap / NominatimConverts your address into map coordinatesThe address text being looked up

Others

  • Our professional advisers — accountants, insurers and lawyers — where they need it.
  • Regulators, HMRC, the police or other authorities where the law requires it, or where it is necessary to establish or defend a legal claim.
  • A buyer or successor, if the business is sold or reorganised. We would tell you first.

8. Automated decisions

We do not make decisions about your organisation by automated means that produce legal or similarly significant effects.

The platform does apply rules automatically — matching your shifts to suitable workers, calculating cancellation fees from the published fee ladder, and flagging documents that are close to expiry. These follow settings you can see, and a member of our team reviews any account suspension before it takes effect.

9. Sending information outside the UK

Our platform and its database are hosted in the United Kingdom. Some of the service providers listed above process information outside the UK — in particular Google (for the in-app assistant) and our push notification and email providers.

Where information leaves the UK, we rely on one of the safeguards permitted by the UK GDPR: an adequacy decision covering the destination country, or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) together with a transfer risk assessment. You can ask us for a copy of the safeguard that applies to a particular transfer by emailing privacy@locum-aid.com.

10. How long we keep your information

WhatHow longWhy
Your active organisation profile and locationsWhile your account is openTo provide the service
Verification documentsUp to 6 years after your account closesTo evidence that an organisation was verified at the time it booked workers
Invoices, payments and cancellation fee records6 years from the end of the relevant financial yearTax and accounting law
Shift, booking and cancellation historyUp to 6 yearsTo resolve disputes and defend legal claims within the limitation period
AI assistant knowledge base and conversationsWhile the assistant is enabled, then up to 12 monthsTo provide the feature and investigate issues with its answers
Support tickets and chatUp to 3 years after the conversation closesTo handle follow-up questions and complaints
Audit logs of administrative actionsUp to 6 yearsAccountability and security

What happens when you close your account

Closing your account removes your organisation and its shifts from the platform, and workers can no longer find or apply to you.

We do not immediately erase the underlying record. Shifts, timesheets, invoices and audit logs refer to it, and we have to be able to explain historical staffing and payments to HMRC, an auditor, a regulator or a court. We keep the minimum needed for that, for the periods above, and then delete or anonymise it.

You can ask us to erase specific information sooner by emailing privacy@locum-aid.com.

11. Your rights

Under UK data protection law you have the right to:

  • Be informed about how your information is used — which is what this notice is for.
  • Access a copy of the personal information we hold about you.
  • Rectification — have inaccurate information corrected. Most details can be corrected yourself in the app.
  • Erasure — ask us to delete your information. This right is not absolute; see the retention section for what we must keep and why.
  • Restrict processing — ask us to pause using your information while a concern is resolved.
  • Data portability — receive information you gave us in a structured, commonly used, machine-readable format.
  • Object — object to processing based on our legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time where we rely on consent, without affecting processing already carried out.
  • Not be subject to solely automated decisions that produce legal or similarly significant effects — see the automated decisions section.

How to exercise a right

Email privacy@locum-aid.com. We respond within one month. If a request is complex we may extend this by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act, so that we do not disclose your information to somebody else.

12. How we keep information secure

We take appropriate technical and organisational measures to protect personal information, including:

  • Encrypted connections (HTTPS/TLS) between the apps and our servers.
  • Passwords stored only as salted one-way hashes — we cannot read your password, and nobody at Tsor Med can tell you what it is.
  • Access controls in the admin portal, so staff only reach the areas their role requires, with sensitive actions written to an audit log.
  • Email verification at sign-up and one-time codes for password resets.
  • Uploaded documents served only to the account that owns them and to authorised staff reviewing them.

No online service can be completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you directly where the law requires it.

13. Cookies and analytics

This website does not set advertising or analytics cookies, and does not track you across other sites.

The mobile apps store a login token and your preferences on your own device so you stay signed in. That storage is necessary to provide the service you asked for; clearing it signs you out. If we introduce optional analytics in future, we will ask for your consent first and update this notice.

14. Children

The Tsor Med platform is intended for people aged 18 and over, and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe a child has given us personal information, contact privacy@locum-aid.com and we will delete it.

15. Changes to this notice

We review this notice regularly and may update it as the platform changes. The version number and effective date at the top of this page always tell you which version you are reading. Where a change materially affects how we use your information, we will tell you in the app or by email before it takes effect, rather than relying on you to re-read this page.

16. Contact us and how to complain

Contact us first

If you have a question or a concern about how we handle your information, please contact us — we would rather hear about it and put it right.

Complaining to the regulator

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can do so at any time — you do not have to contact us first.

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF