Privacy Policy

Policy

Table of Contents

Introduction
This Privacy Policy (“Privacy Policy”) describes what information Novel Medicare Solutions Private Limited (“Easy Clinic” or the “Company” or “Entity” or “We” / “Us” / “Our”), a company incorporated under the Companies Act, 1956, having its registered office at 188/2, Bankim Mukherjee Sarani, Block J, New Alipore, Kolkata – 700053, West Bengal, India; as the owner and operator of the Platform may collect from a user (“You”, “Your” or “User”), on or through our websites http://easycliniconline.com/ or www.easyclinic.io or www.easyclinic.io (“Site”), directly or in relation to services otherwise rendered by Us (collectively “Platform”), such as provision of a Software for clinic management and maintenance of Electronic Medical Records and other ancillary services through the Platform, as may be provided by us through the Site and how we use, process, disclose and try to protect such information.You agree and understand that the Company is responsible for operation and maintenance of the Platform and all information collected and processed on the Platform is collected and processed by Us strictly in relation to Our business.By using Our Platform, or the Services, you confirm that You have read, understood, and agree with the privacy practices described in this Privacy Policy, and the Terms of Use (the “Terms”) and the collection, storage and processing of Your information in accordance with them.This Privacy Policy is incorporated in reference into the Terms. Any capitalized terms used but not defined in this Privacy Policy have the meaning assigned to them in the Terms.The Platform acts as a clinic management tool for a Doctor (“RMP / Registered Medical Practitioner”) by enabling him / her to schedule appointments, Store Electronic Medical records, create and communicate prescriptions, generate invoices, etc.Therefore, for the purpose of providing Services to the Registered Medical Practitioner, the Entity will be required to collect and host certain data and information of the Registered Medical Practitioner. Any such data and information about the Registered Medical Practitioners, including but not limited to their name, photographs, registration ID (accorded to the Medical Practitioner as per the state or national register) qualifications, experience and specialties, that may be hosted by the Entity, and displayed on the Platform, is for information purposes only and such information shall not be deemed to amount to an advertisement of the Registered Medical Practitioner, and / or the services provided by such Registered Medical Practitioner. We are committed to protecting the personal information of the Registered Medical Practitionerand take all precautionary measures to maintain confidentiality of the Registered Medical Practitioner’s personal information.This Privacy Policy shall apply to the use of the Platform by all Registered Medical Practitioners. Accordingly, a condition of each Registered Medical Practitioner’s use of and access to the Platform and to the other services provided by the Entity to Registered Medical Practitioner is their acceptance of this Privacy Policy and the Terms. All Registered Medical Practitioners are required to read and understand the provisions set out herein prior to submitting any sensitive personal data or information to the Entity, failing which they are required to leave the Platform immediately and forthwith cease the usage of the Platform.This Privacy Policy is published in compliance with, inter alia: (a) Section 43A of the Information Technology Act, 2000 (“IT Act”);(b) Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPD Rules”); and(c) Regulation 3(1) of the Information Technology (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediaries Guidelines”).

General Terms

(a) By accessing or using the Platform or the Service, or by otherwise giving Us Your information, You confirm that You have the capacity to enter into a legally binding contract under Indian law, in particular, the Indian Contract Act, 1872, and have read, understood and agreed to the practices and policies outlined in this Privacy Policy and agree to be bound by the Privacy Policy.(b) You hereby consent to Our collection, use, sharing, and disclosure of your information as described in this Privacy Policy. We reserve the right to change, modify, add or delete portions of the terms of this Privacy Policy, at our sole discretion, at any time, and any continued use of the App, the Services or the Platform, following any such amendments to the Privacy Policy, will be deemed as an implicit acceptance of the Privacy Policy in its amended form. While You are requested to review the Privacy Policy from time to time to keep yourself updated with any changes; modifications made to the terms hereof, We shall notify You as per timelines prescribed under applicable laws about any such amendments to the Privacy Policy.(c) If You are accessing or using Services on the Site from an overseas location, You do so at your own risk and shall be solely liable for compliance with any applicable local laws.(d) If You do not agree with any of the terms and conditions of this Privacy Policy, please do not proceed further to use this Site or any Services.
1. What information About You is collected on the Platform?
When You access the Site or use the Service(s), You may provide, or We may collect information that may specifically identify You or any other individual. Given below are the types of information that we may collect:(a) Information You Give Us: We receive and store any information You enter on Our Platform or provide us in any other way. When You register on the Site, We collect registration details such as name, mobile number, Medical Registration number, email address, name of Clinic and geographical address. We verify Your mobile number with the help of a one-time password sent to Your mobile number. We may also collect health information obtained by You while providing Your Services through the Platform such as the patient’s medical or health history, health status, investigations ordered and laboratory testing results, details of treatment plans and medication prescribed by You, dosage details such as frequency of dosage, alternative medication, diagnostic results, Patients health ids, other health-related information and any other information inferred therefrom. By using the Service, You consent to the recording, storage, and disclosure of such communications You send or receive for these purposes. We may also store and process prescriptions, treatment notes, recommendations and other data generated by You on or through the Platform, etc. and may retain such material for our records for the duration of You availing the Services or for any such period required or permitted under applicable law.(b) Information from Other Sources: The Entity may receive information about the Registered Medical Practitioner’s browsing history including the URL of the site of the Registered Medical Practitioner visited the Platform as well as the Internet Protocol (IP) address, computer operating system and type of web browser the Registered Medical Practitioner is using as well as the name of the Registered Medical Practitioner’s ISP. The Platform may use temporary cookies to store certain data (that is not sensitive personal information or personal information) that is used by the Entity and its third-party service providers for the technical administration of the Platform, research and development etc.(c) Cookies and Other Tracking Technologies: We utilize “cookies” and other tracking technologies. A “cookie” is a small text file that may be used, for example, to collect information about activity on the Site or the App. Some cookies and other technologies may serve to recall information previously indicated or submitted by a User. Most browser settings allow You to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if You receive a cookie, or You may choose to block cookies with your browser. Tracking technologies may record information such as internet domain and host names, internet protocol (IP) addresses, browser software and operating system types, stream patterns, and dates and times that Our Site is accessed. Our use of cookies and other tracking technologies allows Us to improve our Site and Your experience. At all times, You may refuse all cookies on Your browser by changing Your settings to the extent permissible on Your device.(d) Automatic Information: We receive and store certain types of information whenever You interact with Us. For example, We obtain certain types of information when Your web browser accesses the Site such as OS type and version, Device brand, browser and its version details, User agent, etc. to see examples of the information We receive. We may also receive/store information about Your location, including a unique identifier for Your device.The IT Act and the SPD Rules regulate the collection, usage, retention and disclosure of personal information, which is defined under the SPD Rules as any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available to a body corporate, is capable of identifying such person.You agree that You are providing all information, including SPD to us voluntarily. Collection, use and disclosure of personal information and SPD requires Your express consent.You are providing us with your consent to Our use, collection and disclosure of the personal information and SPD. You may choose to not provide Us with personal information and SPD, but in the event that You do so, We will be unable to provide You access to Our Site or provide Services through Our Platform.
2. How do We use the information We collect?
(a) We use the information We collect, in a variety of ways in order to provide the Services on the Site and to operate Our business, including the following:(i) To carry out Our obligations arising from Your requests for the products and Services on the Platform;(ii) To operate and improve the Platform in order to foster a positive user experience and to improve Our business as a whole;(iii) To process and deliver Your service requests with Us;(iv) To enable Your access to Our Site to provide You Services;(v) Analysing data, tracking trends, building algorithms, creating databases for rating systems, recommendations engines, etc.;(vi) Research;(vii) For responding to Your requests, customising Your orders, improving Our Platform or communicating with You;(viii) For non-targeting reasons such as frequency capping, compliance, billing, ad reporting or delivery, market research or product development purposes;(ix) To comply with applicable laws;(x) To conduct audits and quality assessment procedures;(xi) To analyse the use of Our resources, troubleshooting problems and improving Our Products and Services, by using the information regarding Your device and software.(xii) Contacting Users, both during and after an order, for updates, resolution of queries, order details, consultations, follow-up consultations or offering new services;(xiii) To investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of Our Terms, or as otherwise required by law;(xiv) To respond to any queries that You may have, and to communicate information to You, including notifications of any promotions or alerts, any changes / updates to the Site, or the introduction of any future fees or charges that We may collect at the time for purchasing products or provision of our Services to You; or(xv) To contact You, by way of SMS, email and phone calls, from time to time to record Your valuable feedback on Our products and Services, as they currently stand, and / or any potential products and services that may be offered in the future. ‍(b) We may use “cookies” information and “automatically collected” information We collect on the Platform to:(i) personalize Our services, such as remembering Your information so that You will not have to re-enter it during your visit or the next time you avail the Service;(ii) provide customized content and information;(iii) monitor and analyse the effectiveness of the Service and third-party marketing activities;(iv) monitor aggregate site usage metrics such as total number of visitors and pages viewed; and(c) We may access or store Your information if it is necessary to detect, prevent or address fraud and other illegal activity or to protect the safety, property or rights of the Platform or others.(d) We may collect, analyse, use, publish, create and sell de-identified information, of which your personal or sensitive personal information might be a component, for any business or other purpose not prohibited by applicable law, including for research and marketing purposes. (collectively “Purposes”).
3. Do we share the Information we receive?
(a) We may release account and other personal information when we believe in good faith that such release is appropriate to comply with applicable law including to:(i) conform to legal requirements or comply with legal process;(ii) protect rights or property or affiliated companies;(iii) prevent a crime or in interest of national security; or(iv) protect personal safety of Our Users or the public. We may also disclose Your personal information to enforce or apply Our Terms and other agreements; or protect the rights, property or Our safety, safety of Our Users or others. This includes exchanging information with other companies, organisations, government or regulatory authorities for fraud protection and credit risk reduction;(b) Sharing upon merger or amalgamation or intra-group transfer: Any third party to which We transfer or sell Our assets, merge or consolidate with, will have the right to continue to use the information (including SPD) provided to Us by You, in accordance with the Terms and conditions specified in this Privacy Policy. We may disclose information to Our partners, affiliates, subsidiaries, group entities, investors, stakeholders or potential associates in an anonymized and aggregate manner, so that they too may understand how Users use Our Site and enable Us to create a better overall experience for You; and(c) Improving our business: You acknowledge that We have a right to use e-prescriptions generated by you on the platform, for improving Our Services. We may transfer such personal Information and SPD to a third party, including persons outside India, to improve product and Service offerings while taking commercially reasonable steps to try and ensure, that the recipient adheres to the applicable laws for ensuring data protection as is adhered by Us.(d)Transfer to third parties and outside India: Subject to applicable law, We may at Our sole discretion, transfer personal information and SPD to any other body corporate (as definedunder the Information Technology Act, 2000) that ensures at least the same level of data protection as is provided by Us under the terms hereof, located in India or any other country.The Registered Medical Practitioner shall ensure confidentiality of the Registered Medical Practitioner’s account details including without limitation username and password, and the Registered Medical Practitioner shall immediately notify the Us without any delay of any actual or unauthorized use the account details.We shall, in no event, be responsible for the breach of security or of any acts/omissions of the third parties including without limitation acts of Government, breach of security, encryption, computer hacking, unauthorized access to computer data and storage device.By using the Site and the App, You accept the terms hereof and hereby consent to Us, sharing with and / or processing of Your personal information and SPD.
4. How Secure Is Information About Me?
(a) We maintain electronic, physical and procedural safeguards in connection with the collection, storage and disclosure of personal information (including SPD). Our security procedures may warrant that We may occasionally request proof of identity before We disclose personal information to You.(b) We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software, which encrypts information You input in addition to maintaining security of Your information as per the international standards on “Information Technology Security Techniques Information Security Management System-Requirements”.(c) We provide restricted access to personal information, to Our employees and agents who need to know that information in order to process it for Us, and who are subject to strict contractual confidentiality obligations, and may be disciplined or whose relationship with Us may terminate if they fail to meet these obligations.(d) No employee or administrator will have knowledge of Your password of Your account on the Site or the App. It is important for You to protect Your account against unauthorized access to Your password and You must be sure to log off from the Site or when You have finished use thereof. We do not undertake any liability for any unauthorised use of Your account and password.(e) If You suspect any unauthorized use of Your account, You must immediately notify us by sending an email to the contact details indicated in the contact section. You shall be liable to indemnify Us due to any loss suffered by Us due to such unauthorized use of your account or password.(f) Under certain circumstances, We shall not be able to take Your prior consent before disclosing Your information in case the information is demanded by government agencies or otherwise mandated under law to obtain SPD, or during investigation of cyber incidents, prosecution of offenses etc.(g) Further, We shall not be responsible for any breach of security or for any actions of any third parties or events that are beyond our reasonable control including but not limited to acts of government, computer hacking, unauthorised access to computer data and storage device, computer crashes, breach of security and encryption, poor quality of internet service or telephone service of the User, etc.
5. What Information Can I Access?
The Platform gives You access to a broad range of information about Your account and Your interactions with the Platform for the limited purpose of viewing and, in certain cases, modifying, and deleting information provided on the Site. If you are desirous of deleting or erasing Your Information including SDP from the Platform database, the Company reserves the right to process such erasure or deletion after recording Your explicit consent. Once Your request is processed, such deletion shall be final, and the Company disclaims all responsibility for providing You any such deleted Information in the future. Further, the Company shall not be liable for the RMP’s failure to maintain a separate record of such Information as mandated by applicable laws.
6. Are Children Allowed to Use the Platform?
Use of the Site is available only to persons who can form a legally binding contract under the Indian Contract Act, 1872. If You are under 18 years of age, then please do not use or access the Service(s) at any time or in any manner. If We learn that a person under 18 years of age has used or accessed the Platform or Service or any personally identifiable information has been collected on the Platform from persons under 18 years of age, then We will take the appropriate steps to delete this information. If You are a parent or guardian and discover that Your child under 18 years of age has obtained an account on or otherwise accessed the Service, then You may alert us at info@easyclinic.in and request that We delete that child’s personally identifiable information from Our systems.
7. Third-party links
The Site may include hyperlinks to various external websites, and may also include advertisements, and hyperlinks to applications, content or resources (“Third Party Links”). We have no control over such Third-Party Links present on the Site or the App, which are provided by persons or companies other than Us. You acknowledge and agree that We are not responsible for any collection or disclosure of Your information by any external sites, applications, companies or persons thereof. The presence of any Third-Party Links on Our Site or App, cannot be construed as a recommendation, endorsement or solicitation for the same, or any other material on or available via such Third-Party Links.You further acknowledge and agree that We are not liable for any loss or damage which may be incurred by You as a result of the collection and/or disclosure of Your information via Third Party Links, as a result of any reliance placed by You on the completeness, accuracy or existence of any advertising, products services, or other materials on, or available via such Third-Party Links. This will include all transactions, and information transmitted therein, between You and any such third-party sites or applications or resources, such transactions are strictly bi-partite. We shall not be liable for any disputes arising from or in connection with such transactions between You and the aforementioned third parties.Such third-party websites, and external applications or resources, accessible via the Third-Party Links may have their own privacy policies governing the collection, storage, retention and disclosure of Your information that You may be subject to. We recommend that You exercise reasonable diligence, as You would in traditional offline channels and practice judgment and common sense before committing to any transaction or exchange of information, including but not limited to reviewing the third-party website or application’s privacy policy.
8. Retention of Information
(a) We also have measures in place such that your SPD which is in our possession or under our control, is destroyed and / or anonymised as soon as it is reasonable to assume that: (i) the purposes for which your SPD has been collected have been fulfilled; and (ii) retention is no longer necessary for any other reason, or under applicable law.(b) We may, however, reserve the right to retain and store your personal information for our business purposes, whether such personal information has been deleted or not. After a period of time, your data may be anonymised and aggregated and then may be held by us as long as necessary, to enable purchases of products and provision of services or for analytics purposes.(c) If You wish to withdraw Your consent for processing Your personal information and SPD, cancel Your account, or request that We no longer use Your personal information and SPD to deliver Our products or provide You services, please contact Us at details indicated in the contact section. Please note however that Your withdrawal of consent or cancellation of account may result in Us not being able to deliver You products or provide You with Our services or terminate any existing relationship that We may have with You.
9. Changes to Your Information
You may review, correct, update, change the information that You have provided by logging into Your account. However, You are not permitted to delete any part of the personal information or any other information generated on the Platform. You may request Us to delete the same. You may update Your information at any point by writing to Us at the details indicated below in the contact section.Should You choose to update Your personal information or SPD or modify it in a way that is not verifiable by Us, or leads to such information being incorrect, we will be unable to provide You with access to our Site or the Services, as described under the Terms, and such modification may be regarded as the User seeking to discontinue his or her access to Our Site or the Services.We reserve the right to verify and authenticate Your identity and Your personal information in order to ensure accurate delivery of products and services. Access to or correction, updating or deletion of your personal information or SPD may be denied or limited by Us if it would violate another person’s rights and / or is not otherwise permitted by applicable law.
10. Notices
If You have any concern about privacy or grievances on the Site or the App, please contact us with a thorough description and We will try to resolve the issue for You. If You have any concerns or questions in relation to this Privacy Policy, You may address them to us at the details provided in the contact section. ‍We shall endeavour to resolve Your grievances at the earliest.
11. Miscellaneous
(a) Disclaimer: We cannot ensure that all of Your personal information and SPD will never be disclosed in ways not otherwise described in this Privacy Policy. Therefore, although We are committed to protecting Your privacy, We do not promise, and You should not expect, that Your information will always remain private. As a User of the Site or the App, You understand and agree that You assume all responsibility and risk for Your use of the Site / the platform, theinternet generally, and the information You post or access and for Your conduct on and off the Site or the platform. The Company, in no event, shall be responsible and/or liable for the acts/ omissions of the Registered Medical Practitioner. The Registered Medical Practitioner shall always be responsible for compliance with applicable law.(b) Indemnity: You agree and undertake to indemnify Us in any suit or dispute by any third party arising out of disclosure of information by You to third parties either through our Site or otherwise and Your use and access of websites, applications and resources of third parties. We assume no liability for any actions of third parties with regard to Your personal information or SPD which You may have disclosed to such third parties.(c) Severability: Each clause of this Privacy Policy shall be and remain separate from and independent of and severable from all and any other clauses herein except where otherwise expressly indicated or indicated by the context of the Privacy Policy. The decision or declaration that one or more clauses are null and void shall have no effect on remaining clauses of this Privacy Policy.

Table of Contents

Purpose and scope

This Privacy Policy explains how personal data, including health data, is collected, used, stored, disclosed, and protected when a healthcare provider in Kenya uses the Easy Clinic platform.This Policy applies to the Republic of Kenya only. It is issued separately from the Easy Clinic global privacy policy because Kenyan law imposes specific obligations on the processing of health data that do not apply in other markets.Novel Software Solutions Private Ltd has operated in Kenya since its incorporation on 17 September 2025. This is the first Kenya-specific issue of this Policy.It is addressed to three audiences:
  • Healthcare providers (clinics, clinic chains, nursing homes, and hospital outpatient departments) who contract with us and who are the data controllers of their patients’ records.
  • Patients whose health data is recorded in the platform by those providers.
  • The Office of the Data Protection Commissioner, the Digital Health Agency, and any other regulator or auditor reviewing our compliance posture.

Who we are, and our role

Identity

FieldDetail
Trading nameEasy Clinic
Data processor for KenyaNovel Software Solutions Private Ltd, incorporated in Kenya on 17 September 2025 under the Companies Act, 2015. Certificate of Incorporation No. PVT-271JE897. KRA PIN P052470949G. A wholly owned subsidiary of Novel Medicare Solutions Private Limited, India.
Parent companyNovel Medicare Solutions Private Limited, India. Certain group functions, including billing and shared technical services, are performed by the parent. Section 9 describes the resulting transfers.
Registered address1st Floor, Block B, Spring Valley Business Park, Westlands, Nairobi. P.O. Box 13684-00800.
ODPC registrationRegistered with the Office of the Data Protection Commissioner as a Data Processor. Identification 987-106F-72C3, certificate serial 16499, valid 2 December 2025 to 2 December 2027.
Digital Health AgencyCertification application #APP-2026-HLQYV6 submitted and under review.
Data Protection Officerdpo@easyclinic.io

Our role: processor, not controller

This distinction is central to how this Policy operates.The healthcare provider is the data controller. The clinic, hospital, or practitioner determines why and how patient data is collected and used. The clinical record belongs to the provider and to the patient, not to Easy Clinic.Easy Clinic is the data processor. We process patient data solely on the documented instructions of the healthcare provider, for the purpose of delivering the platform and the services agreed in the service contract. We do not determine the purposes of clinical processing.Easy Clinic acts as a data controller in one limited respect only: for the account and contact details of the provider’s own staff users, and for our own business records such as billing and support correspondence.Each provider is required to enter into a written Data Processing Agreement with us, in accordance with section 42 of the Data Protection Act and regulation 48 of the Data Protection (General) Regulations, 2021, before any patient data is processed. That agreement is accepted at provider onboarding by a person warranting that they have authority to bind the provider, and the acceptance is recorded. It is not accepted through the ordinary user login. This Policy is issued in compliance with, and should be read alongside:
  • The Constitution of Kenya, 2010, Article 31 (right to privacy).
  • The Data Protection Act, Cap. 411C (No. 24 of 2019), which classifies data revealing health status as sensitive personal data.
  • The Data Protection (General) Regulations, 2021.
  • The Digital Health Act, No. 15 of 2023, and the Digital Health (Health Information Management) Regulations, 2025.
  • The Health Act, No. 21 of 2017.
  • The Kenya Digital Health Certification Framework and the Kenya Digital Health Standards and Guidelines issued by the Digital Health Agency.
  • The Computer Misuse and Cybercrimes Act, 2018, as amended.
  • Guidance issued by the Office of the Data Protection Commissioner, including the Guidance Note on the Processing of Health Data and the Guidance Note on Cross-Border Data Transfer.

Categories of data processed

CategoryExamplesSensitive under the Act
Patient identity and demographicsName, sex, date of birth, residence, telephone number, national identity number, passport number, birth certificate number, alien registration number, Unique Patient Identifier, next of kin name and relationshipPartly
Clinical dataPresenting complaint, problem list and diagnoses coded to ICD-10 or SNOMED, clinical notes, vital signs, allergies, medication and prescription history, laboratory and imaging orders and results, care plans, referral recordsYes
Billing and payer dataInvoices, receipts, payment method, insurance scheme membership, Social Health Authority claim data, pre-authorisation records, intervention and tariff codesPartly
Provider and user dataPractitioner name, practitioner registration number, facility code, role, username, access permissionsNo
Technical and audit dataAudit logs, login records, IP address, device and browser type, timestamps, records of data created, viewed, amended, or deletedNo
We do not collect patient data directly from patients. All patient data is entered into the platform by the healthcare provider or its authorised staff in the course of providing care.

Purposes and lawful basis

We process personal data only for the purposes set out below. We do not process patient data for any purpose of our own beyond those listed.
PurposeLawful basis
Delivering the platform so the provider can record, retrieve, and manage patient recordsPerformance of the contract with the provider; the provider’s documented instructions as controller
Processing of health data for the provision of healthcare servicesSection 45(2) of the Act, being processing necessary for the provision of health or social care, carried out under the responsibility of a healthcare provider
Billing, invoicing, and claims submission, including to the Social Health Authority and private insurersPerformance of the contract; compliance with a legal obligation; the provider’s instructions
Mandatory public health reporting, including notifiable disease notification and Integrated Disease Surveillance and Response reportingCompliance with a legal obligation under the Health Act and the Digital Health Act
Exchange of data with the Kenya Health Information Exchange and Digital Health Agency enterprise servicesCompliance with a legal obligation under the Digital Health Act, 2023
Security monitoring, audit logging, fraud detection, and incident investigationLegitimate interests of the controller and processor in maintaining the integrity and security of the system; compliance with a legal obligation
Backup, disaster recovery, and business continuityPerformance of the contract; compliance with a legal obligation
Technical support and troubleshooting requested by the providerPerformance of the contract; the provider’s instructions

What we do not do

We state the following expressly, because it materially distinguishes this Policy from generic software privacy notices:
  • We do not sell personal data, health data, or de-identified data derived from health data, to any party, for any purpose.
  • We do not use patient data, identifiable or de-identified, for advertising, marketing, or commercial profiling.
  • We do not use patient data to train artificial intelligence or machine learning models, other than where the provider has given specific, separate, written instruction to do so, and where any such use is governed by a distinct written agreement.
  • We do not disclose patient data to our affiliates, investors, or group entities for their own purposes.
  • We do not use patient data for research without the express written instruction of the provider as controller and the applicable ethical and regulatory approvals.
Under section 45 of the Act, the processing of sensitive personal data, which includes data revealing health status, requires a lawful basis and, in most circumstances, the consent of the data subject.Responsibility for obtaining, recording, and evidencing patient consent rests with the healthcare provider as data controller. Easy Clinic does not obtain consent from patients directly.The platform supports the provider in meeting that obligation by providing:
  • Fields to record that consent has been obtained, by whom, and on what date.
  • Recording of consent for specific processing operations where these are separately consented, including cross-border transfer and claims submission to a payer.
  • An audit record of consent capture and of any subsequent withdrawal.
Where a patient withdraws consent, the provider must action that withdrawal within the platform. We will support the provider in giving effect to it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not override a statutory obligation to retain the clinical record for the period prescribed by law.

Where data is stored, and data localisation

Section 50 of the Act and regulation 26 of the Data Protection (General) Regulations, 2021 provide that personal data processed for the strategic interests of the state must be domiciled in Kenya. Regulation 26 lists the provision of primary or secondary health care for a data subject in the country as such a purpose.The current position is stated plainly. The primary clinical database is hosted on Microsoft Azure, which does not operate a data centre region in Kenya. A Kenyan serving-copy capability is being implemented so that at least one accurate and up-to-date copy of Kenyan patient data is held in a data centre located in Kenya, in accordance with regulation 26.Until that capability is in place, transfers are conducted on the bases set out in section 8. The position is recorded as an open item, with a remediation plan and committed timeline, in our Data Protection Impact Assessment, which is available to healthcare providers and to the Digital Health Agency on request. We state it here rather than presenting the matter as resolved.
ElementDetail
Primary hosting locationMicrosoft Azure, United States region
Kenyan serving copyIn implementation
Backup frequency, recovery objectives and disaster recovery arrangements are service-continuity matters. They are set out in our Backup and Recovery Policy and in the service agreement with each provider, rather than in this Policy.

Cross-border transfer of data

The processing of personal data in a cloud environment with servers located outside Kenya constitutes a cross-border data transfer.Any transfer of Kenyan patient data outside Kenya takes place only on a lawful basis under Part VI of the Act and regulation 40 of the Regulations. Because health data is sensitive personal data, section 49(1) of the Act applies: the explicit consent of the data subject is required and appropriate safeguards must be confirmed, with both reflected in the transfer contract and documentation. Every transfer is covered by a Data Protection Impact Assessment and is documented as regulation 41(2) requires, recording the date and time, the recipient, the justification, and a description of the data, and is made available to the Data Commissioner on request.Onward transfer by any recipient is prohibited without our specific prior written authorisation, and onward transfer for a recipient’s own purposes, including analytics, profiling, product improvement or marketing, is prohibited absolutely.

Current transfer destinations

Kenyan patient data is currently transferred to the following destinations. Each is declared in our registration with the Office of the Data Protection Commissioner.
DestinationData transferredRecipient
United StatesAll categories held in the clinical database, documents and reportsMicrosoft Azure
United StatesDe-identified structured values and clinical text, for one provider only at that provider’s instructionOpenAI
IndiaBilling records, and patient name, mobile number and message content for appointment reminders and clinical communicationsParent company; WATI; TextLocal
Transfers to the parent company are intra-group. The Kenyan company is a wholly owned subsidiary, and the group is accordingly eligible to adopt Binding Corporate Rules as an appropriate safeguard under regulation 42 of the Data Protection (General) Regulations, 2021.

Sub-processors

We engage a limited number of third parties to help deliver the platform. Each is bound by a written agreement imposing obligations no less protective than those in this Policy and in our Data Processing Agreement with the provider, including confidentiality, security, audit rights, breach notification, and a prohibition on processing for their own purposes.The current list of sub-processors engaged for the Kenyan deployment, including the service each provides and the location in which it processes data, is available to providers on request from our Data Protection Officer. We will give providers not less than 30 days’ written notice before adding or replacing a sub-processor, during which the provider may object.Sub-processors that process Kenyan patient data outside Kenya are identified in section 8.1 below, so that the destinations of your data are disclosed in this Policy regardless of the list above being provided on request.

Security measures

We implement technical and organisational measures appropriate to the sensitivity of health data. These measures are aligned to the Security, Privacy and Confidentiality criterion of the Kenya Digital Health Certification Framework.

Access control and authentication

  • Access requires a unique username and password. The system does not permit access without both.
  • Every user is assigned a unique identity. Shared or generic accounts are not permitted.
  • Access is role-based. Permissions are granted by role, and a user may view only the data their role requires. A reception role, for example, cannot view clinical diagnosis data.
  • Multi-factor authentication is required for privileged access.
  • The session locks automatically after a facility-determined period of inactivity, and the record in progress is preserved on unlock.
  • Emergency access, sometimes described as break-glass access, is available where clinically necessary, and every such access is logged and flagged for review.
  • Database accounts are defined individually and are role-based. Default database accounts are disabled and the database is not accessible to operating system superusers.

Encryption

  • Health data is encrypted at rest using AES-256, applied through Transparent Data Encryption on the clinical database and its backups, and storage service encryption on documents, images and reports. Credentials are hashed one-way and are never reversible.
  • Data in transit is encrypted using TLS 1.3 as the minimum accepted version on all public endpoints. Plaintext HTTP is redirected and rejected by application endpoints.
  • Encryption keys are platform-managed. This is a deliberate choice: customer-managed keys move custody to the operator and introduce a failure mode in which a lost or revoked key renders clinical data permanently unreadable, and unavailability of a clinical record is itself a patient-safety event. Secrets are held in a managed vault under role-based access.

Audit trail and integrity

  • Every create, read, update, and delete action on a patient record is logged with the user identity, the terminal, the timestamp, the object changed, and the original value that was changed.
  • Audit logs are tamper-resistant and cannot be edited or deleted by any user, including administrators.
  • Audit logs are retained for not less than five years.
  • Amendments to a clinical record are version-tracked. The original entry is preserved and remains visible.

Resilience and governance

  • Backups are taken on a defined schedule, are encrypted to the same standard as the live system, and are tested by restoration at defined intervals.
  • A documented Disaster Recovery Plan and Backup and Recovery Policy are maintained and tested.
  • Independent penetration testing and vulnerability assessment are carried out at least annually, with documented remediation.
  • A Data Protection Impact Assessment is maintained, and is reviewed at least annually and on material change.
  • Staff with access to production systems are subject to background verification, written confidentiality undertakings, and annual data protection training.
  • Access by Easy Clinic personnel to a provider’s production data is restricted to named support staff, requires a logged business justification, and is auditable by the provider.

Disclosure of data

We disclose patient data only in the following circumstances:
  • To the healthcare provider that is the controller of that data, and to the users it authorises.
  • To the Social Health Authority or a private insurer, where the provider submits a claim and the patient has consented to that submission.
  • To the Ministry of Health, the Digital Health Agency, or a county health department, where disclosure is required for notifiable disease reporting, Integrated Disease Surveillance and Response reporting, or exchange through the Kenya Health Information Exchange, as required by the Digital Health Act, 2023 and the Health Act, 2017.
  • To a sub-processor listed in section 9, strictly to deliver the service.
  • Where we are compelled by a court order, a lawful regulatory demand, or a statutory obligation. Where we are lawfully permitted to do so, we will notify the provider before complying.
We will not disclose patient data in response to an informal request from any third party, including a law enforcement or government body, without lawful process.

Retention and disposal

Retention periods for clinical records are set by the healthcare provider as controller, subject to the minimum periods required by Kenyan law and professional guidance. Where a provider’s own regulatory or professional obligation requires a longer period, that period applies and is configured for that provider. A provider cannot instruct a shorter period than the law requires of it. Retention runs from the trigger stated below rather than from record creation, so a patient seen over many years has one record with one clock.
Data categoryRetention period
Adult clinical records10 years from the last encounter
Paediatric clinical recordsUntil the patient reaches 25 years of age, or 10 years from the last encounter, whichever is later
Clinical records – deceased patient10 years from the date of death
Prescribing and dispensing records10 years from the date of dispensing
Appointment records3 years from the appointment date
Financial and billing records7 years from the end of the financial year
Insurance and SHA claim records7 years from claim closure
Audit logs5 years from the date of the event
Authentication logs1 year from the date of the event
Application and system logs90 days
Communication logs2 years from the message date
BackupsExpire on the backup cycle, after which they are overwritten or securely destroyed
On termination of the service contract, the provider may export its data in a structured, machine-readable format. Following export and a transition period of 30 days, we will securely delete or return all patient data in our possession, including from backups in accordance with the backup cycle, and will certify that deletion in writing on request.Disposal is carried out by cryptographic erasure or secure overwriting in accordance with our Data Retention and Disposal Policy.

Rights of data subjects

Under section 26 of the Act, a data subject has the right:
  • To be informed of the use to which their personal data is to be put.
  • To access their personal data held by a data controller.
  • To object to the processing of all or part of their personal data.
  • To correction of false or misleading data.
  • To deletion of false or misleading data about them.
Patients should exercise these rights with the healthcare provider that holds their record, because the provider is the data controller. The provider’s contact details are available at the facility.Where a patient contacts Easy Clinic directly, we will not act on the request ourselves. We will refer the patient to the relevant provider and notify that provider without undue delay, and we will assist the provider in responding within the statutory timeframe.The right to deletion is qualified. A clinical record may not be deleted where retention is required by law or is necessary for the establishment, exercise, or defence of a legal claim. Where an entry is corrected, the original entry is preserved in the audit trail, as clinical record integrity requires.

Personal data breaches

Where a personal data breach occurs and there is a real risk of harm to the data subject, we will:
  • Notify the affected healthcare provider without undue delay and in any event within 24 hours of becoming aware of the breach.
  • Provide the provider with the information it requires to notify the Data Commissioner within 72 hours of becoming aware, in accordance with section 43 of the Act.
  • Support the provider in communicating with affected data subjects where required.
  • Contain and remediate the breach, preserve evidence, and conduct a documented root cause analysis.
  • Maintain an internal register of all breaches, including those not meeting the notification threshold.
Where required under the Kenya Digital Health Certification Framework, we will also report the breach and the implemented remedy to the Digital Health Agency.Our Incident Response Plan sets out escalation paths, roles and timelines, and is reviewed at least annually.

Children’s data

Patient records within the platform routinely include data relating to children. This is an intrinsic part of clinical care and is processed on the same lawful bases set out in section 5.In accordance with section 33 of the Act, processing of a child’s personal data is subject to safeguards. The healthcare provider is responsible for obtaining the consent of a parent or guardian where required, and for verifying the identity and authority of that person.The platform applies the same access controls, encryption, and audit standards to children’s records as to all other clinical records. It does not present marketing or promotional content to any user.

Clinical decision support and automated processing

The platform may include clinical decision support and other automated features that generate alerts, flags, or suggestions based on recorded clinical data.
  • These features are decision support. They do not make clinical decisions.
  • Every output is advisory and is presented to a qualified practitioner, who retains full clinical responsibility for the decision taken.
  • No patient is subject to a decision producing legal or similarly significant effects based solely on automated processing.
  • The logic and data sources on which each decision support intervention relies are documented and available to the provider.

Complaints

If you have a concern about how your data is handled, please contact the healthcare provider holding your record in the first instance.You may also contact our Data Protection Officer:
ContactDetail
Emaildpo@easyclinic.io
Postal addressNovel Software Solutions Private Ltd, 1st Floor, Block B, Spring Valley Business Park, Westlands, Nairobi. P.O. Box 13684-00800.
We will acknowledge a complaint within 7 days and respond substantively within 30 days.If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner, Britam Tower, Hospital Road, Upper Hill, Nairobi, at info@odpc.go.ke or through the ODPC complaints portal.

Changes to this Policy

We will review this Policy at least annually and whenever there is a material change to our processing activities, our sub-processors, our hosting arrangements, or applicable law. Where a change materially affects providers or patients, we will give providers not less than 30 days’ written notice before it takes effect. The current version and its effective date are stated on the first page. Superseded versions are retained and are available on request.
Scroll to Top