Privacy Policy
How AfyaIQ handles personal data, and the rights you have over it. This policy is written to the Kenya Data Protection Act, 2019.
Effective 21 July 2026
1. Who we are
AfyaIQ is a clinic management platform operated by Hansel Technologies, a company registered in Kenya ([exact registered name as it appears on the certificate of incorporation, and company registration number]), with its principal place of business at 12th Floor, Westpark Towers, Mpesi Lane, Nairobi, Kenya.
In this policy, “we”, “us” and “AfyaIQ” mean Hansel Technologies. “You” means the person reading this — whether you are a clinic that subscribes to AfyaIQ, a member of clinic staff who logs in, or a patient whose records a clinic keeps in AfyaIQ.
You can reach us about anything in this policy at info@hanseltechnologies.co.ke or +254 787 600 403.
Registration status. We are [not yet registered] with the Office of the Data Protection Commissioner. We will publish our registration number here once issued.
2. The most important thing to understand
Patient records in AfyaIQ belong to the clinic, not to us.When a clinic uses AfyaIQ to record a patient’s visit, diagnosis, prescription or payment, the clinic is the data controller — it decides what to collect and why. We are the data processor: we store and process that data on the clinic’s instructions and for no purpose of our own.
This matters for patients. If you are a patient and you want to see, correct or delete your records, ask your clinic first— they control the record and can act immediately. If your clinic does not respond, contact us and we will help, but we cannot alter a clinic’s records without their instruction except where the law requires it.
For data we decide the purpose of ourselves — clinic account details, billing, support conversations, and website analytics — we are the controller, and this policy describes that directly.
3. What we collect
Data a clinic puts into AfyaIQ (clinic is the controller)
- Patient identity — name, phone number, date of birth, sex, and the guardian link for a child.
- Clinical data — symptoms, diagnoses, consultation notes, prescriptions, lab orders and results, immunisations, growth measurements, and registry metrics such as HbA1c or nutrition status.
- Financial data — invoices, payments, M-Pesa transaction references, and insurance claims.
- Files — documents and images a clinic attaches to a patient record.
Clinical data is sensitive personal data under section 2 of the Data Protection Act and is treated accordingly throughout this policy.
Data we collect as controller
- Clinic and staff accounts — clinic name, staff names, email addresses, phone numbers, roles, and hashed passwords. We never store a password in a readable form.
- Billing — subscription and setup fees, AI credit purchases, and the M-Pesa number used to pay.
- Security and audit logs — who logged in, from what IP address, and which records they viewed or changed. We keep these to detect misuse of patient data; they are a safeguard, not a marketing tool.
- Support correspondence — what you tell us when you ask for help.
What we do not collect
- We do not sell personal data. Ever. There is no version of AfyaIQ where your patient list is a product.
- We do not use patient data to advertise to anyone.
- We do not use patient data to train artificial-intelligence models, ours or anyone else’s. See section 6.
4. Why we process it, and our lawful basis
- To provide the service — performance of our contract with the clinic (DPA 2019, s.30(1)(b)).
- To keep the service secure, including audit logging and fraud detection — our legitimate interest in protecting patient data, which does not override anyone’s rights (s.30(1)(f)).
- To bill and get paid — performance of our contract, and compliance with tax law (s.30(1)(c)).
- To send appointment, immunisation and follow-up reminders on a clinic’s behalf — on the clinic’s instruction and lawful basis as controller. A patient can opt out with their clinic at any time.
- To process sensitive health data — permitted because it is necessary for the provision of health care by or under the responsibility of a health professional (s.45).
5. Who we share it with
We use the following service providers to run AfyaIQ. Each processes data only to deliver its part of the service, under contract.
- Railway — application hosting and the PostgreSQL database holding clinic and patient records.
- Vercel — hosting for the web application you interact with.
- Backblaze B2 — storage for files attached to patient records.
- Safaricom (M-Pesa Daraja) — payment processing. Receives the payer’s phone number and amount, not clinical data.
- Celcom Africa — SMS delivery for reminders. Receives the recipient’s phone number and the message text.
- Meta Platforms (WhatsApp Business) — WhatsApp message delivery, where a clinic enables it.
- OpenRouter — routes requests to the AI model providers behind our AI features. See section 6.
We also disclose data where the law compels us to — a court order, or a lawful demand from a regulator. Where we are permitted to tell the affected clinic, we will.
Transfers outside Kenya.There is no data centre in Kenya in our hosting providers’ networks, so patient data is stored outside Kenya:
- Railway — which holds the database, and therefore the patient records themselves — operates regions in the United States (California and Virginia), the Netherlands, and Singapore. No African region is offered.
- Backblaze B2 — which holds patient file attachments — stores our bucket in its US East region.
- Vercel serves the web application from a global network. It holds no patient records; the data you see in the browser is fetched from Railway.
Section 48 of the Act permits transfers outside Kenya where appropriate safeguards exist and the data subject has been informed of the risks — which is the purpose of this section. [Record the specific transfer safeguard relied on for each provider, and confirm the Railway region actually in use from the Railway dashboard].
6. Artificial intelligence
AfyaIQ includes AI features — triage support, consultation summaries, and operational insights. These are subject to strict rules:
- An AI feature runs on a patient’s data only where consent for AI processing has been recorded against that patient in AfyaIQ. No consent, no AI.
- We do not use patient data to train our own models — we build none. AI requests are routed through OpenRouter, which is configured to route only to model providers that do not train on or retain prompts. [Verify in the OpenRouter account settings that training and prompt logging are disabled and that requests are restricted to zero-retention providers — this is opt-out, not the default, and this sentence is only true once it is set].
- AI output is decision support, never a diagnosis. A qualified clinician reviews everything before it affects patient care. No clinical decision in AfyaIQ is automated.
- Because no decision with legal or similarly significant effect is made solely by automated means, section 35 of the Act is not engaged. If that ever changes, we will say so here before it does.
7. How long we keep it
- While a clinic subscribes — we keep its data for as long as the clinic wants it kept. The clinic decides.
- After a subscription ends — we keep the clinic’s data for 90 days, so the clinic can export its records or reinstate the account, and then we permanently delete it. Backups containing it are purged within a further 30 days.
- Kenyan medical-record retention obligations sit with the clinic, not with us. A clinic must export the records it is required to retain before that 90-day window closes.
- Audit and security logs — retained for 12 months.
- Billing records — retained for 7 years, as tax law requires.
8. How we protect it
- Every record is scoped to a single clinic. One clinic cannot query another clinic’s data — this is enforced in the application on every request, not left to convention.
- Access within a clinic is limited by role. A pharmacist does not see what a doctor sees.
- Traffic is encrypted in transit. Passwords are hashed. File access uses expiring signed links rather than public URLs.
- Access to patient records is logged, so misuse can be traced to an individual account.
No system is perfectly secure. If a breach occurs that poses a real risk of harm, we will notify the Data Commissioner within 72 hours of becoming aware of it, and notify affected clinics without undue delay, as section 43 of the Act requires.
9. Your rights
Under the Data Protection Act you have the right to:
- be told how your data is used — this document;
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data deleted, where there is no lawful reason to keep it;
- object to processing, and to withdraw consent where consent is the basis;
- receive your data in a portable format;
- complain to the Office of the Data Protection Commissioner.
Patients: contact your clinic first — they hold and control your record. Clinic staff and account holders: email info@hanseltechnologies.co.ke. We respond within 30 days. Exercising a right costs nothing.
You can complain to the Office of the Data Protection Commissioner at odpc.go.ke at any time, including before raising it with us.
10. Children
AfyaIQ is used for paediatric care, so children’s data is processed by design — growth measurements, immunisation records, and guardian links. A child’s record is created and managed by the clinic under the guardian’s authority, as section 33 of the Act requires. Reminders about a child go to the guardian’s phone number.
11. Changes to this policy
If we change this policy materially, we will notify subscribing clinics by email at least 30 days before the change takes effect. The effective date at the top of this page always reflects the current version.
Status of this document
This is a draft prepared for review by a Kenyan data-protection advocate. It reflects how AfyaIQ actually works today, but it has not been reviewed by a lawyer and is not legal advice. Highlighted passages are facts that must be filled in or verified before this document is published or relied on.