Privacy policy.

Last updated: April 2026

This Privacy Policy explains how Aquasoft (Pty) Ltd (registration 2019/371371/07, trading as "Likertly") ("we," "us," "Likertly") collects, uses, shares, and protects personal information when you use likertly.com and likertly.co.za (together, "the Platform").

This policy is governed by South Africa's Protection of Personal Information Act, 2013 (POPIA) and, where applicable, the EU/UK General Data Protection Regulation (GDPR).

1. Who this policy applies to

Two groups of people interact with the Platform:

  • Practitioners — coaches, therapists, counsellors, HR professionals, and other practitioners who sign up for an account and use the Platform to send screening assessments to their clients. Practitioners are our customers.
  • Clients — the individuals who receive a screening link from a Practitioner and complete an assessment. Clients do not create accounts and do not have a direct contractual relationship with us.

The roles under POPIA / GDPR are:

  • For Practitioner account data (your name, email, payment, business details): we are the Responsible Party (POPIA) / Controller (GDPR).
  • For Client screening data (the responses, scores, and reports generated when a Client completes an assessment): the Practitioner is the Responsible Party / Controller. We are the Operator (POPIA) / Processor (GDPR), processing the data only on the Practitioner's behalf and only as necessary to provide the Platform.

If you are a Client and have questions about how your data is being used, contact your Practitioner directly — they decide why your data was collected and how long it is kept. We will support them in responding to your request.

2. Information we collect

From Practitioners

  • Account information: email address, business name, optional logo and brand colour, country of residence.
  • Authentication information: one-time login links sent to your email (no passwords are stored).
  • Billing information: name, billing address, and the last 4 digits and brand of your payment card. Full card numbers are processed by PayFast and are never stored on our servers.
  • Client roster: the names and email addresses you add as Clients in your dashboard.
  • Usage information: which assessments you send, when, to whom (within your own roster), and aggregated logs needed to operate the service.
  • Support correspondence: messages you send us by email or contact form.

From Clients (on behalf of Practitioners)

  • Identifying information the Practitioner enters into their roster: typically a first name (or initials) and an email address.
  • Assessment responses submitted via the screening link the Practitioner sends.
  • Derived scores and reports computed from those responses.
  • Technical metadata when a Client opens a screening link: IP address, browser, device type, completion timestamp. This metadata is used for security, abuse prevention, and to detect technical errors.

Special categories of personal information

Some of our screening instruments (PHQ-9, GAD-7, ASRS, AQ-50, OCI-R, DASS-21, SPIN, ISI, ECR-R, and others) collect responses that relate to mental and physical health, emotional state, and personal beliefs. Under POPIA section 26 and GDPR Article 9, this is "special personal information" that requires a higher standard of protection. We treat all Client assessment data as special personal information by default. The lawful basis for processing this data is the Practitioner's professional engagement with the Client and the Client's explicit consent given to the Practitioner before the assessment is sent.

3. How we use information

Practitioner data

  • To create and authenticate your account.
  • To process subscription payments and issue receipts.
  • To provide the dashboard, scoring, and reporting features you pay for.
  • To send service-related emails (billing, security, important product changes).
  • To respond to support requests.
  • To detect, prevent, and respond to fraud, abuse, or security incidents.
  • To meet our legal obligations (tax records, regulator requests).

Client data (processed for the Practitioner)

  • To deliver the assessment to the Client via a one-time-use link.
  • To score the responses and produce a report visible to the Practitioner.
  • To handle critical-item flags (e.g. a non-zero response to PHQ-9 item 9 about self-harm) by surfacing them in the Practitioner's dashboard so the Practitioner can fulfil their duty of care.
  • To retain history within the Practitioner's account so they can review longitudinal results.

We do not use Client data for advertising, analytics across Practitioners, machine-learning training, research publication, or any purpose beyond providing the service to the Practitioner.

4. Critical-item handling

Some screening instruments — most notably the PHQ-9 — contain items that, if positively endorsed, suggest possible risk of self-harm. When a Client's responses include such an item, our system:

  1. Flags the result prominently in the Practitioner's dashboard.
  2. Displays crisis-resource information (international and South African helplines) on the Client's screen immediately after they submit the assessment, regardless of total score.

We do not automatically contact emergency services or third parties on the Client's behalf. The Practitioner is responsible for clinical follow-up. By using the Platform, Practitioners confirm they understand and accept this responsibility.

5. How we share information

We share personal information only with the categories of recipients listed below, only to the extent necessary, and only under written processing agreements.

RecipientPurposeLocation
PayFastPayment processingSouth Africa
ResendTransactional and login emailsUnited States
RailwayApplication hosting and databaseUnited States / European Union
CloudflareDNS, transactional email routingUnited States

Each of these subprocessors is contractually bound to process personal information only as instructed and to protect it with appropriate security measures. We will publish a current list of subprocessors and update it before adding any new subprocessor that processes personal information.

We do not sell personal information. We do not share Client assessment responses with anyone other than the Practitioner who initiated the assessment.

We may disclose information if required by law (a valid court order, subpoena, or regulator request), or to protect our rights, property, or safety, or that of our users or the public — but only to the minimum extent necessary.

6. International data transfers

Some of our subprocessors are located outside South Africa and outside the EU/EEA. When personal information is transferred internationally, we rely on:

  • For POPIA: the recipient being subject to a law, binding code, or agreement that provides protection substantially similar to POPIA, or the data subject's consent, in line with section 72.
  • For GDPR: Standard Contractual Clauses (SCCs) or an adequacy decision where applicable.

By using the Platform you acknowledge that your data, and your Clients' data, may be processed outside South Africa.

7. How long we keep information

  • Practitioner account data: for as long as your account is active, plus a reasonable period after closure for tax, legal, and dispute-resolution purposes (typically 5 years for financial records as required by the South African Revenue Service).
  • Client assessment data: retained within the Practitioner's account for as long as the Practitioner keeps the Client in their roster. Practitioners can delete a Client (and all their assessment data) at any time. On deletion, data is removed from active systems within 30 days and from backups within 90 days.
  • Account closure: when a Practitioner closes their account, they may export their data within 30 days, after which all account data is deleted on the timeline above.
  • Transactional emails (Resend logs): typically 30 days.
  • Server logs: typically 30–90 days.

8. Your rights

If you are a Practitioner

You have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete your account and associated data (subject to retention obligations in section 7).
  • Export your data in a machine-readable format.
  • Object to certain types of processing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority (see section 12).

To exercise any of these, email info@likertly.com. We respond within 30 days.

If you are a Client

Your rights with respect to your assessment data are exercised primarily through your Practitioner, who is the Responsible Party for that data. We will assist your Practitioner in fulfilling your request promptly. You may also contact us directly at info@likertly.com if your Practitioner is unresponsive or if you have concerns about how the Platform itself handled your data.

9. Security

We protect personal information using industry-standard measures, including:

  • HTTPS/TLS encryption for all data in transit.
  • Encryption at rest for databases.
  • Magic-link authentication (no passwords stored or transmitted).
  • One-time-use Client links that expire after use.
  • Access controls limiting who on our team can view production data.
  • Logging of administrative access.
  • Regular security updates to our software dependencies.

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you and the Information Regulator (where required by POPIA section 22 or GDPR Articles 33-34) without undue delay.

10. Cookies and tracking

The Platform uses a minimal set of cookies necessary for the service to function:

  • Authentication cookies to keep Practitioners logged in.
  • Security cookies to prevent CSRF attacks.

We do not use advertising cookies, third-party tracking, or cross-site behavioural analytics.

11. Children

The Platform is intended for use by professionals with adult Clients. We do not knowingly collect personal information from children under 18 without verifiable parental or guardian consent obtained by the Practitioner. Practitioners working with minors are responsible for obtaining the necessary consents and ensuring such use complies with their local laws and professional ethics.

12. Information Officer and complaints

Our designated Information Officer (POPIA) is:

Werner Swanepoel
Aquasoft (Pty) Ltd (Reg. 2019/371371/07)
PO Box 38114, Garsfontein East, Pretoria, Gauteng, 0060, South Africa
Email: info@likertly.com

If you have a complaint about how we handle personal information that we cannot resolve directly, you have the right to lodge a complaint with:

13. Changes to this policy

We may update this Privacy Policy as the Platform evolves and as the law changes. When we make material changes, we will notify Practitioners via email and via a notice in the dashboard at least 14 days before the changes take effect. The "Last updated" date at the top of this document indicates the most recent revision. Continued use of the Platform after the effective date of a change constitutes acceptance.

14. Contact

For privacy questions, requests, or complaints:

Email: info@likertly.com
Postal: Aquasoft (Pty) Ltd, PO Box 38114, Garsfontein East, Pretoria, 0060, South Africa
Information Officer: Werner Swanepoel — info@likertly.com

For crisis resources, see /crisis.