AfyaConnect Privacy Policy

Registered with Kenya's Office of the Data Protection Commissioner as a Data Controller & Data Processor. Reg. No. 805-7801-3679.

AfyaConnect is a hospital, clinic and pharmacy management system provided by Neurobyte Technologies Ltd. This policy explains what personal data AfyaConnect processes, why, who it is shared with, how it is protected, and the rights you have under the Kenya Data Protection Act, 2019.

1. Who we are and our registration

AfyaConnect is provided by Neurobyte Technologies Ltd ("Neurobyte", "we").

AfyaConnect is a Neurobyte product. Neurobyte is registered with Kenya's Office of the Data Protection Commissioner (ODPC) as a Data Controller & Data Processor, registration number 805-7801-3679 (certificate serials 25934, Data Controller, and 25933, Data Processor; valid 2 September 2026 to 2 September 2028).

2. Our role: controller and processor

  • Patient records. A hospital, clinic or pharmacy that uses AfyaConnect decides why and how its patients' data is processed, so the facility is the data controller. Neurobyte processes that data on the facility's documented instructions, as its data processor, and for no other purpose.
  • Accounts, facility subscriptions, demo requests, support and this website. Neurobyte decides how this data is processed and is the data controller.
  • If you are a patient, your first point of contact for your health record is the facility that treated you. You may also contact us, and we will pass your request to the facility or help it respond.

3. Personal data we process

  • Identity and contact details: name, date of birth, sex, phone, email, residence (county, sub-county, ward), next of kin and their relationship.
  • Identifiers: National ID, Maisha Namba, passport, birth certificate or notification number, SHA membership number, Kenya Health Information Exchange client registry identifier.
  • Health data (sensitive personal data): visits, triage and vital signs, diagnoses and problem lists, allergies, prescriptions and dispensing, laboratory and imaging orders and results, immunisations, referrals, admissions and discharge summaries, uploaded clinical documents.
  • Billing and insurance data: charges, payments (including M-Pesa references) and insurance or SHA claims.
  • Staff and account data: name, role, facility, login and security events, and the actions each user performs in the system (the audit trail).
  • Technical data: device and browser information and security logs. Website analytics are collected without identifying visitors.

4. Why we process it and on what basis

  • To provide health care: health data is processed only by or under the responsibility of health care providers and staff bound by confidentiality, for the diagnosis, treatment and care of the patient.
  • To meet legal obligations: mandatory disease notification and surveillance (IDSR, and International Health Regulations events), Ministry of Health routine reporting to KHIS, and record-keeping required by law.
  • To perform our contracts: running the service facilities subscribe to, including billing, support and security.
  • With consent where the law requires it: for example sharing a patient's record through the Kenya Health Information Exchange, and telemedicine consultations. Consent can be withdrawn.
  • For our legitimate interests, where they do not override your rights: keeping the service secure, detecting misuse and improving the service with de-identified or aggregate data.
  • We do not sell personal data, and we do not use patient data for advertising.

5. Who we share it with

  • Staff of the treating facility, limited by their role (role-based access), and only within their own facility.
  • The Kenya Health Information Exchange and the Digital Health Agency, when a facility exchanges a patient record, subject to the patient's consent where required.
  • The Ministry of Health (KHIS/DHIS2): aggregate reports that do not name patients.
  • Public health authorities (sub-county, county and national disease surveillance officers): the minimum information required to notify a reportable disease or public health event.
  • SHA and other insurers: the information needed to process a patient's claim.
  • Service providers acting for us under contract (sub-processors): Supabase (database and storage hosting), Vercel (web application hosting), Africa's Talking (SMS alerts) and Resend (email).
  • Courts, regulators or law enforcement only where the law requires it.

6. Where the data is stored (transfers outside Kenya)

The AfyaConnect database and file storage are hosted by Supabase in the European Union (Stockholm, Sweden). Encrypted backup copies of the database, which cannot be read without our key, are held by GitHub, which may store them in the United States or other countries where it operates. The web application is delivered by Vercel's global network. Personal data is therefore transferred outside Kenya.

We make these transfers under the Data Protection Act, 2019 and its regulations, to providers bound by contract to protect the data, in a jurisdiction with data protection law of a comparable standard (the EU General Data Protection Regulation). Data is encrypted in transit and at rest.

7. How we protect it

  • Encryption in transit (TLS 1.2 or higher, HTTPS only) and at rest (AES-256).
  • Multi-factor authentication, account lockout after repeated failed sign-ins, automatic sign-out after inactivity, and role-based access.
  • Facility isolation enforced in the database: one facility cannot read another's records.
  • An append-only, tamper-evident audit trail of who created, read, changed or deleted clinical records.
  • SHA-256 integrity checks on uploaded documents, and digital signatures on critical documents such as prescriptions and discharge summaries.
  • Encrypted off-site backups every three hours, restore-tested every week, and a disaster recovery plan.

8. How long we keep it

  • Clinical records: for as long as the facility is required to keep them under the Health Act and Ministry of Health records-retention requirements.
  • Audit logs: at least five years.
  • Accounts: while the account is active, then for as long as needed to resolve disputes and meet legal obligations.
  • When data is no longer needed it is deleted or anonymised.

9. Your rights

Under the Data Protection Act, 2019 you have the right to:

  • be informed of how your personal data is used;
  • access your personal data;
  • object to the processing of all or part of it;
  • have false or misleading data corrected;
  • have false, misleading or unlawfully processed data deleted;
  • data portability: receive your data in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent;
  • not be subject to a decision based solely on automated processing that significantly affects you. AfyaConnect's clinical decision support only advises clinicians; every clinical decision is made by a person.

10. How to exercise your rights

  • Patients: ask the facility that holds your record, or write to us at privacy@afyaconnect.africa. We will pass your request to the facility or help it respond.
  • Everyone else: write to privacy@afyaconnect.africa or call +254 727 686 606.
  • We will confirm your identity before acting, record the request, and respond within the time limits set by the Data Protection (General) Regulations, 2021. Reasonable requests are free of charge.
  • Corrections to a clinical record are made by the facility, and the record keeps a history of what changed.
  • If you are not satisfied, you may complain to the Office of the Data Protection Commissioner (www.odpc.go.ke).

11. Personal data breaches

If a breach of personal data creates a real risk of harm, we notify the Data Protection Commissioner within 72 hours of becoming aware of it and inform the affected facilities and people, as the Data Protection Act, 2019 requires.

12. Children

Children's health records are created by the treating facility. Rights in respect of a child are exercised by the child's parent or guardian.

13. Cookies and local storage

AfyaConnect uses essential browser storage to keep you signed in and to remember settings. Website analytics are anonymous. We do not use advertising cookies.

14. Changes to this policy

We will post any change on this page with a new effective date and tell facilities of material changes.

Contact

Neurobyte Technologies Ltd, Olenguruone Avenue, Lavington, Nairobi. P.O. Box 17888 – 00100, Nairobi, Kenya. Email privacy@afyaconnect.africa, phone +254 727 686 606.

Effective 30 September 2026.