Who this notice covers
CounselR is a practice-management application for counselors. This notice covers the public website and the signed-in workspace. Support and privacy enquiries can be sent to support@counselr.co.za. Do not include clinical records or identity documents in an initial email.
The CounselR operator’s legal name, address and designated Information Officer have not yet been confirmed. A practice typically decides why and how its patient records are processed; the platform’s role and instructions must be documented in an appropriate agreement before clinical use.
Information involved
The public landing page does not ask for patient information. Its preview uses fictional, labelled sample records, separate from the database. Choosing a contact link opens your own mail application; information you send is processed by your email provider and the recipient.
A signed-in workspace uses your platform-provided user identifier and email address, with an optional display name, for access checks. Practice records may include patient and guardian contact details, school details, appointments, counseling notes, report drafts, invoices, payment references, tasks and practice settings. Activity history records the actor, action, record identifier and time—not the full clinical note.
Purpose and lawful authority
Workspace information is used to support the practice workflows you request: managing records, sessions, reports, billing, tasks and access. Practices must establish and document the applicable lawful basis, confidentiality duties and permissions for their work. Health information and information about children require particular care under POPIA; consent is not automatically the only or sufficient basis in every situation.
Do not upload live clinical data until the practice has assessed the service, its agreements and its own obligations. CounselR does not provide legal advice, treatment or an automated clinical decision service.
Access, providers and international processing
Patient records are not published on the landing page. Server-side checks limit the workspace to the practice owner and active team members. Roles restrict operations; the Billing role does not receive clinical session notes from the records API.
The current website uses OpenAI Sites hosting, ChatGPT sign-in and Cloudflare-backed application storage. These services may process operational information outside South Africa. Exact processing locations, subprocessor terms and the applicable cross-border safeguards require confirmation before clinical deployment. No data-residency guarantee is made.
Direct mailbox integration is paused. If enabled later, its separate permissions and provider disclosures must be reviewed before connecting an account. Downloads and manually shared reports are outside the application’s access boundary.
Retention, rights and requests
Records remain in the practice workspace until an authorised action removes them, subject to clinical, financial and legal requirements. Linked histories may prevent individual deletion. Payment voids and activity history preserve accountability. There is no automatic retention-expiry or guaranteed deletion of every hosting backup in the current release.
Ask your practice about access, correction, export, objections or deletion of its records. For platform-related enquiries contact support@counselr.co.za. We may need proportionate identity and authority checks through an agreed secure channel. Requests are assessed against applicable obligations, including duties to retain records; deletion is not unconditional.
You may raise concerns with South Africa’s Information Regulator. Follow the Regulator’s published complaint procedure. This draft does not limit your statutory rights.
Website measurement and updates
This landing-page implementation does not load advertising trackers or third-party analytics. The hosting and sign-in providers may use essential cookies and operational logs under their own policies. See Cookies & storage for the distinction.
Material changes to these proposed policies should be communicated before new processing is introduced. The date at the top identifies this draft revision.
Further information
Read the Protection of Personal Information Act and the Information Regulator’s guidance and request procedures.
Questions? Contact support@counselr.co.za.
