Privacy Policy
Last updated: 26 August 2026
1. Who this policy covers
HatuaAfya operates the booking and practice-management platform used by the clinic, hospital, or doctor you interact with. Under Kenya's Data Protection Act, 2019 ("the Act"), the clinic or doctor you book with is the Data Controllerfor your information — they decide how it's used for your care. HatuaAfya is the Data Processor: we run the system on their behalf, under a written data processing agreement with every clinic and doctor on the platform. This policy explains what we collect, why, and your rights over it.
2. Information we collect
- Account information — name, phone number, email address.
- Booking information — appointment times, the clinic and doctor you booked with, and answers to any intake questions a doctor has chosen to ask before a visit.
- Payment information — M-Pesa/card transaction references and amounts. We never store your M-Pesa PIN or full card number.
- Clinical information — visit notes and related health information entered by your doctor, where applicable.
- Communications — messages sent through the platform, such as booking confirmations and reminders.
3. Why we process it
On behalf of the clinic or doctor you book with, to: provide and coordinate your care; process appointment payments; send booking confirmations and reminders; respond to reviews and feedback; and meet legal or regulatory obligations. Consistent with the Act, processing is grounded in your consent (captured at the point of booking), contractual necessity (fulfilling the booking you made), or a legal obligation, as applicable.
4. Who we share it with
- The clinic and doctor you book with — this is the point of the platform.
- Supabase — hosts the database that stores your information.
- Safaricom (M-Pesa) / Paystack — process payments you initiate.
- Anthropic (Claude) — only when a doctor uses AI-assisted note drafting; the specific text involved is sent for that single request only, and is never used to train Anthropic's models.
- An SMS/WhatsApp provider, once live, to deliver reminders.
We do not sell your information, and we do not use it for advertising. Some of these providers may process data outside Kenya; where that happens, it is done under contractual safeguards consistent with the Act's requirements for cross-border transfers.
5. Isolation between clinics
If a doctor practices at more than one facility, each facility can only see the appointments booked there. A hospital where you've never been treated cannot see your records, even for a doctor who also sees patients there — enforced at the database level, not just in the app. See our data-trust page for more detail.
6. How long we keep it
Booking and clinical records are retained for as long as the clinic or doctor you booked with is required to keep them under their own recordkeeping obligations as a healthcare provider. You can ask the clinic or doctor to correct or delete your information at any time, consistent with those same obligations.
7. Your rights
Under Section 35 of the Act, you have the right to: be informed how your data is used; access the data held about you; object to its processing; request correction of inaccurate data; request deletion; receive your data in a portable format; and withdraw consent at any time (withdrawal doesn't affect processing that already happened lawfully before it).
Since the clinic or doctor you booked with is the Data Controller, the fastest way to exercise these rights is to contact them directly. You can also reach us at info@hatuaafya.com and we'll route your request appropriately.
8. Children's information
If you are booking an appointment on behalf of a child or other dependant, you confirm you are authorised to provide their information for that purpose.
9. Changes to this policy
We'll update the date at the top of this page if this policy changes materially.
10. Contact
Questions about this policy: info@hatuaafya.com. ODPC Data Processor certificate: [pending registration — add the certificate number here once issued].