Privacy Policy
Last updated: 6 June 2026 · Responsible party: FlightMed (PTY) Ltd, South Africa · Contact: privacy@flightmed.software
Heartbeat ("we", "us") is operated by FlightMed (PTY) Ltd. We process your personal information in line with the Protection of Personal Information Act, 2013 (POPIA). This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have over it.
1. What we collect and why
- Account details, full name, email, password (hashed). Required to create and secure your account.
- Optional profile fields, organisation, role/title, timezone. Used to personalise your workspace and reminders.
- "How did you hear about us?", optional. Used only in aggregate to understand which channels bring people to Heartbeat; never shared with third parties and never used to target you individually. You can leave it blank.
- Marketing opt-in, off by default; only used to send product news if you tick it. You can unsubscribe at any time.
- Your content, tasks, notes, events, meetings, transcripts, attachments, reminders, AI preferences, and similar work data you create.
- Operational data, login history, notification preferences, and basic usage/audit logs needed to keep the service secure and reliable.
2. Lawful basis
We process your personal information to perform our contract with you (running your account), to comply with legal obligations, for our legitimate interest in keeping the service secure, and, where relevant, based on your consent (e.g. marketing emails, meeting recordings).
3. Meeting recordings & transcripts
When you upload meeting audio, the file is transcribed and summarised on your behalf. The audio is only retained if you explicitly tick "Keep the audio recording for this meeting", otherwise only the transcript and summary are stored. You are responsible for ensuring every attendee has consented to being recorded before uploading audio.
4. Operators (processors) we use
We use the following operators to deliver Heartbeat. Each is bound by contractual confidentiality and security obligations.
- Supabase, database, authentication, and file storage hosting (EU/US regions).
- Cloudflare, application hosting, CDN, and DDoS protection (global edge).
- Anthropic and OpenAI, AI processing for summaries, transcripts, and assistant features. Content is only sent when you invoke an AI feature, and providers are contractually prohibited from training on your data.
- Google, only when you connect Google Calendar, to read/write your calendar events.
- Resend, sending transactional and (opt-in) marketing emails.
5. Cross-border transfers
Several operators above process data outside South Africa (typically in the EU and US). Under POPIA s72 these transfers rely on the operator's binding contractual commitments providing a level of protection substantially similar to POPIA, and/or your consent through your use of those features.
6. Your rights under POPIA
You have the right to:
- Access a copy of the personal information we hold about you ("Export my data" in Settings → Privacy & Data).
- Correct or update your information from your profile.
- Delete your account and all associated data ("Delete my account" in Settings → Privacy & Data).
- Object to processing or withdraw consent (e.g. unsubscribe from marketing).
- Lodge a complaint with the Information Regulator (South Africa).
7. Retention
We keep your data while your account is active. When you delete your account, your personal information and content are removed from our active systems; backups are rotated out within 30 days.
8. Security
Access to your data is protected by row-level security policies, encrypted in transit (TLS), and admin access is logged. We never sell your data.
9. Contact
For any privacy request or question, email privacy@flightmed.software.
← Back to Heartbeat