How your data is protected
HatuaAfya processes health information on behalf of the clinics and doctors you book with. Here is exactly what that means and what it doesn't.
Who controls your data
The clinic or doctor you book with is the Data Controller under the Kenya Data Protection Act, 2019 — they decide how your information is used for your care. HatuaAfya is the Data Processor: we run the booking and reminder system on their behalf, under a written data processing agreement with every clinic and doctor on the platform. We never sell your data, use it for advertising, or share it outside the clinics you've actually booked with.
Isolation between clinics
If a doctor practices at more than one facility, each facility can only see the appointments booked there — a hospital where you've never been treated cannot see your records, even for a doctor who also sees patients there. This is enforced at the database level, not just in the app.
Who else touches your data
- Supabase — hosts the database that stores appointments, profiles, and clinic records.
- Anthropic (Claude)— when a doctor uses an AI-assisted feature (such as drafting visit notes), the text involved is sent to Anthropic's API for that single request only. It is not used to train Anthropic's models.
- Safaricom Daraja — processes M-Pesa payments; HatuaAfya never stores your M-Pesa PIN.
- SMS/WhatsApp provider — delivers appointment reminders and confirmations.
Your rights
You can ask the clinic you booked with to correct or delete your information at any time, consistent with their own record-keeping obligations as your care provider.
ODPC Data Processor certificate: [pending registration — add the certificate number here once issued].