Data Processing Agreement
Records that the Clinic is the data controller of its patient records and AfyaIQ is the processor, and sets out what we may and may not do with that data. Required by section 42 of the Kenya Data Protection Act, 2019.
Effective 21 July 2026
1. Parties and status
This agreement is between the clinic subscribing to AfyaIQ (the Controller) and Hansel Technologies ([exact registered name and company registration number]) of 12th Floor, Westpark Towers, Mpesi Lane, Nairobi, Kenya (the Processor).
It forms part of, and is governed by, the Terms of Service. It takes effect when the Clinic starts using AfyaIQ and lasts as long as we process personal data for the Clinic.
The Controller determines the purpose and means of processing patient personal data. The Processor acts only on the Controller’s documented instructions. Using AfyaIQ in the ordinary way — creating patients, recording visits, dispensing, invoicing, sending reminders, running an AI feature on a consented patient — is a documented instruction for the purposes of this agreement.
2. Subject matter of the processing
- Subject matter — provision of the AfyaIQ clinic management service.
- Duration — the term of the subscription, plus the 90-day post-termination window in section 8.
- Nature and purpose — storage, organisation, retrieval, transmission and erasure of patient and operational records so the Clinic can deliver and bill for care.
- Categories of data subject— patients of the Clinic, including children; guardians of child patients; and the Clinic’s own staff.
- Categories of personal data — identity and contact details; dates of birth; guardian relationships; appointment and visit records; payment and insurance records; and staff account records.
- Sensitive personal data — health data: symptoms, diagnoses, consultation notes, prescriptions and dispensing, laboratory orders and results, immunisation records, growth and nutrition measurements, and chronic-disease registry metrics.
3. Processor obligations
We will:
- process personal data only on the Controller’s documented instructions, unless Kenyan law requires otherwise — in which case we will tell the Controller before processing, unless that law forbids it;
- never process patient data for our own purposes — no resale, no profiling, no advertising, and no use of Clinic data to train artificial-intelligence models;
- ensure everyone we authorise to access personal data is under a binding duty of confidentiality;
- implement the technical and organisational measures in section 5;
- assist the Controller in responding to data subject requests, as set out in section 6;
- assist the Controller with breach notification, data protection impact assessments, and prior consultation with the Data Commissioner, to the extent the information is ours to give;
- make available the information reasonably necessary to demonstrate compliance with this agreement, and allow audits as set out in section 9;
- tell the Controller promptly if we believe an instruction infringes the Data Protection Act.
4. Controller obligations
The Clinic will:
- have and maintain a lawful basis for the personal data it enters into AfyaIQ, including for sensitive health data under section 45 of the Act;
- provide its patients with the required privacy information;
- obtain and record any consent required — in particular, a patient’s consent to AI processing must be recorded in AfyaIQ before an AI feature is used on that patient’s data;
- issue accounts only to people entitled to access patient data, and remove them promptly when entitlement ends;
- keep its instructions to us lawful.
5. Security measures
- Tenant isolation — every record is scoped to a single clinic, enforced on every request in the application layer. One clinic’s account cannot read another clinic’s data.
- Role-based access control — access within a clinic is limited by role, so staff see only what their role requires.
- Authentication — passwords are hashed, never stored in readable form; sessions use signed tokens with expiry.
- Encryption in transit — all traffic is served over TLS.
- File access — attachments are served through expiring signed links, not public URLs.
- Audit logging — access to and changes of patient records are logged with the acting user and time, retained 12 months.
- Backups — the database is backed up for disaster recovery, subject to the deletion timelines in section 8.
- Encryption at rest — database. Railway encrypts all customer data at rest at the storage layer, and applies a further layer of encryption to service environment variables. This covers the PostgreSQL database holding patient records.
- Encryption at rest — file attachments. Backblaze B2 supports server-side encryption (SSE-B2, AES-256), but it is disabled by default on a new bucket and does not apply retroactively to files uploaded before it is switched on. [Confirm SSE-B2 is enabled on the patient files bucket, and re-upload any attachments stored before it was enabled — until both are done, patient attachments are not encrypted at rest and this clause must not claim otherwise].
These measures may evolve as the service develops. We will not reduce the overall level of security during the term.
6. Data subject requests
Patients should direct requests to the Clinic, which controls the record and can act on it directly in AfyaIQ. If a patient contacts us instead, we will not respond substantively — we will redirect them to the Clinic and tell the Clinic without undue delay.
We will provide reasonable assistance, at no charge, where the Clinic needs our help to fulfil a request within its statutory deadline.
7. Sub-processors
The Controller gives general authorisation for the sub-processors below. We remain fully liable to the Controller for their performance.
- Railway — application hosting and PostgreSQL database.
- Vercel — web application hosting.
- Backblaze B2 — patient file storage.
- Safaricom (M-Pesa Daraja) — payment processing.
- Celcom Africa — SMS delivery.
- Meta Platforms (WhatsApp Business) — WhatsApp delivery, where enabled by the Clinic.
- OpenRouter— AI model routing. Configured to route only to providers that do not train on or retain prompts; this is an account setting, not OpenRouter’s default. [Verify the setting is enabled before relying on this clause].
We will give the Controller at least 30 days’ notice before adding or replacing a sub-processor. If the Controller reasonably objects on data protection grounds within that period and we cannot offer an alternative, the Controller may terminate without penalty and receive a refund of the unused portion of its current period.
Transfers outside Kenya. None of our hosting providers operates a Kenyan region, so personal data is stored outside Kenya. Railway — which holds the database and therefore the patient records — offers regions only in the United States (California, Virginia), the Netherlands and Singapore. Backblaze B2 stores our attachments bucket in its US East region. Vercel serves the application globally and holds no patient records.
We make such transfers only where section 48 of the Act is satisfied. [Record the specific safeguard relied on for each sub-processor, and confirm the Railway region in use from the dashboard].
8. Return and deletion
- The Controller can export its data at any time during the term.
- On termination, we retain the data for 90 days so the Controller can export or reinstate.
- After 90 days we permanently delete it from live systems, and purge it from backups within a further 30 days.
- We will confirm deletion in writing on request.
- We retain only what Kenyan law requires us to keep — principally billing records for tax purposes — and that retained data stays subject to this agreement.
Medical-record retention obligations rest with the Controller. The Controller must export whatever it is required to retain before the 90-day window closes.
9. Breach notification and audit
- We will notify the Controller without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting its data — so the Controller can meet its own 72-hour duty to the Data Commissioner under section 43.
- Our notice will describe what happened, the categories and approximate number of records affected, the likely consequences, and the steps taken.
- The Controller may audit our compliance with this agreement once in any 12-month period, on 30 days’ notice, during business hours, without disrupting the service or exposing another clinic’s data. A regulator may audit at any time on lawful demand.
10. Precedence
Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.
Status of this document
This is a draft prepared for review by a Kenyan data-protection advocate. It reflects how AfyaIQ actually works today, but it has not been reviewed by a lawyer and is not legal advice. Highlighted passages are facts that must be filled in or verified before this document is published or relied on.