1. Introduction
Creswave Limited (“Creswave”, “we”, “us”, “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, how long we keep it, and the rights you have. It is issued in line with the Kenya Data Protection Act, 2019 (the “Act”) and the Data Protection (General) Regulations, 2021.
Please read it together with any privacy notice provided by the healthcare facility you attend, which explains how that facility uses your health information.
2. Who we are and how to contact us
| Item | Details |
|---|---|
| Company | Creswave Limited |
| Postal address | P.O. Box 50548-00515, BuruBuru, Nairobi, Kenya |
| Telephone | +254 754 001 605 |
| General email | [email protected] |
| Data Protection Officer | Jessee Gitaka — [email protected] |
| Registration with the Office of the Data Protection Commissioner | Registered as a data controller and data processor — Registration No. 613-0110-B460 |
3. Our role: data controller and data processor
Under the Act, a data controller decides why and how personal data is processed, and a data processor processes personal data on behalf of a controller. Creswave acts in both roles, depending on the data:
| Situation | Our role |
|---|---|
| Patient records and other data entered into Ecare HMIS by a healthcare facility (registration details, clinical notes, test results, prescriptions, billing and insurance information) | Data processor. The healthcare facility is the data controller. We process this data only on the facility’s documented instructions, under a written agreement, to provide, support and secure Ecare HMIS. Questions or requests about these records should be directed to the facility first; we will help the facility respond. |
| Accounts of facility staff who use Ecare HMIS | Data processor for the facility, and data controller for the limited account and security information we need to operate and protect the service (for example login and audit records). |
| Our website, enquiries, sales and support contacts, contracts with clients and suppliers, marketing | Data controller. |
| Our employees, contractors and job applicants | Data controller. |
4. Personal data we collect
Patient data processed in Ecare HMIS (on behalf of healthcare facilities)
Depending on the services a facility uses, this may include:
- Identity and contact details: name, date of birth, sex, national ID, passport or birth certificate number, patient number, phone number, email, residence, county and ward, occupation, next of kin;
- Health data: visits, symptoms and history, vital signs, diagnoses, laboratory and radiology results and images, prescriptions and dispensing, admissions, maternal and child health, immunisation, nutrition and other clinical records;
- Financial and insurance data: bills, receipts, payments (including M-PESA references), insurance scheme and membership numbers, SHA / SHIF numbers and claims;
- Other sensitive data where recorded by the facility: marital status, religion and family details;
- Appointment, referral, telemedicine and online booking information, and SMS notification records.
Health data and the other items above are “sensitive personal data” under the Act and receive extra protection.
Data about facility users of Ecare HMIS
- Name, username, contact details, designation (role), staff or professional registration number, branch and facility;
- Security data: password (stored only as a one-way hash), multi-factor authentication settings, login times, IP address, device and browser information, and an audit record of actions taken in the system.
Data about clients, prospects and website visitors
- Names, job titles, organisation, phone, email and correspondence when you contact us, request a demonstration or sign a contract;
- Technical data when you visit our website: IP address, browser type, pages visited and cookie data (see Cookies).
Data about job applicants and staff
CVs, qualifications, references, identification, and employment and payroll information, handled under our internal HR privacy notice.
5. How we collect personal data
- From healthcare facilities and their staff, who enter patient data into Ecare HMIS during care and administration;
- Directly from patients who use online booking, patient app registration or telemedicine features made available by their facility;
- From connected systems at the facility’s request — laboratory analysers, imaging systems (PACS), insurance claims platforms and payment services;
- Directly from you when you contact us, use our website, apply for a job or enter into a contract with us;
- Automatically, through system logs and cookies, when you use Ecare HMIS or our website.
6. Why we use personal data and our lawful basis
We process personal data only where the Act allows it. The main purposes and lawful bases are:
| Purpose | Lawful basis under the Act |
|---|---|
| Providing Ecare HMIS to healthcare facilities so that they can register, treat and bill patients, manage appointments and referrals, and submit insurance claims | Performance of our contract with the facility. The facility relies on its own lawful basis — including the provision of health care by or under the responsibility of a health care provider — for processing patient health data. |
| Sending appointment reminders and service messages by SMS or email on the facility’s behalf | Facility’s instructions and lawful basis; performance of contract. |
| Securing the system: authentication, access control, audit trails, fraud and misuse detection, incident response | Legitimate interests in protecting data and systems; legal obligation to implement security safeguards. |
| Backups and disaster recovery | Performance of contract; legal obligation to protect data integrity and availability. |
| Customer support and system maintenance | Performance of contract; legitimate interests. |
| Statutory reporting prepared by facilities (e.g. Ministry of Health reports), KRA eTIMS and SHA integrations | Legal obligations of the facility, carried out on its instructions. |
| Managing client and supplier relationships, invoicing and contracts | Performance of contract; legal obligation (tax records). |
| Responding to enquiries and demonstration requests | Legitimate interests; your consent where required. |
| Marketing communications about our products | Your consent — you can withdraw it at any time. |
| Recruitment and employment | Steps before entering a contract; performance of contract; legal obligation. |
| Complying with laws, regulatory requests and legal claims | Legal obligation; establishment, exercise or defence of legal claims. |
We do not sell personal data. We do not use patient data for our own purposes — including marketing, profiling, or training analytics or artificial intelligence models — unless the facility has instructed us in writing and a lawful basis exists. Where data is used for statistics, it is anonymised first.
8. Where your data is stored and international transfers
Ecare HMIS production databases and their backups are hosted on servers in Nairobi, Kenya. Some service providers — for example Cloudflare, which protects and speeds up our websites and stores some documents and images — operate global networks, so limited data may pass through or be stored in data centres outside Kenya.
Where personal data is transferred outside Kenya, we do so only as permitted by the Act and the Regulations: to countries or providers with appropriate safeguards for the security and protection of personal data, under contractual protections and — for sensitive personal data — with the additional safeguards the law requires. You may ask the Data Protection Officer for details of the safeguards used.
9. How we protect personal data
We use technical and organisational measures appropriate to the sensitivity of health data, including:
- encryption of data in transit (TLS 1.3, with TLS 1.2 only where an approved external system requires it);
- role-based access control, so each user sees only the functions and records their role requires, with separation of data between facilities;
- multi-factor authentication, strong password rules, account lockout after repeated failed logins, and automatic logout after inactivity;
- passwords stored only as one-way Bcrypt hashes; passwords, one-time codes and tokens are never recorded in logs;
- a complete audit trail of activity in Ecare HMIS, continuous security monitoring and alerting;
- network isolation (databases have no public internet access), firewalls, a web application firewall and DDoS protection;
- daily and hourly backups, regular restore testing and a tested disaster recovery plan;
- regular vulnerability scanning and independent penetration testing;
- staff confidentiality agreements, security and privacy training, and strict rules on handling patient data;
- a continuing programme of improvements, including encryption of stored databases and backups, scheduled for completion by mid-2027.
No system is completely secure. If a personal data breach occurs, we will act immediately to contain it and will notify the affected facility within 48 hours, and the Office of the Data Protection Commissioner and affected individuals where the law requires.
10. Your rights
Under the Act, you have the right to:
| Right | What it means |
|---|---|
| Be informed | Know how your personal data is used — this policy and your facility’s notice do that. |
| Access | Obtain a copy of the personal data held about you. |
| Rectification | Have inaccurate, out-of-date, incomplete or misleading data corrected. |
| Deletion (erasure) | Ask for data to be deleted where it is no longer needed or was processed unlawfully. Health records may have to be kept by the facility for legal and clinical reasons, so this right may be limited. |
| Object | Object to processing of all or part of your data, including processing for direct marketing. |
| Restrict processing | Ask that processing be restricted while accuracy or lawfulness is checked. |
| Data portability | Receive data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically possible. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time, without affecting earlier processing. |
| Not be subject to automated decisions | Not be subject to decisions based solely on automated processing that significantly affect you. Ecare HMIS does not make such decisions; clinical and financial decisions are made by people. |
| Complain | Lodge a complaint with the Office of the Data Protection Commissioner (see Complaints). |
How to exercise your rights
- Patients: contact the healthcare facility that holds your records, since it is the data controller. If you contact Creswave, we will pass your request to the facility within 7 days and help it respond.
- Everyone else: write to our Data Protection Officer using the details in Who we are and how to contact us.
We may need to verify your identity before acting on a request. We respond without undue delay and within the timelines set by the Data Protection (General) Regulations, 2021. Requests are free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline as the law permits, and tell you why.
11. How long we keep personal data
We keep personal data only as long as necessary for the purpose it was collected for, or as the law requires:
| Data | Retention |
|---|---|
| Patient records in Ecare HMIS | As decided by the healthcare facility under applicable health-records rules, for as long as it uses Ecare HMIS. When a facility leaves, its data is returned and then deleted from our live systems within 90 days; backup copies expire within 12 months. |
| Database backups | Up to 12 months, in rotation. |
| Audit and security logs | 3 years (access records) to 5 years (records of changes and administration). |
| SMS delivery records | 12 months. |
| Client, supplier and contract records | Duration of the relationship plus 6 years. |
| Financial and tax records | 5 years from the end of the relevant reporting period. |
| Enquiries and marketing contacts | Until you withdraw consent, or 2 years after last contact. |
| Unsuccessful job applications | 6 months. |
When data is no longer needed, it is securely deleted or anonymised.
13. Marketing communications
We send marketing messages about our products only to business contacts who have agreed to receive them. Every message includes a way to unsubscribe, and you can also opt out at any time by contacting us. We never use patient data for marketing, and we do not send marketing to patients.
14. Children
Healthcare facilities record information about children as patients (for example in child health and immunisation services). Such data is processed on the facility’s instructions, with the consent of a parent or guardian or another lawful basis, and in the best interests of the child. Our own websites and services are not directed at children, and we do not knowingly collect children’s data for our own purposes.
15. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on individuals. Reports and dashboards in Ecare HMIS support decisions made by facility staff.
16. Complaints
If you have a concern about how your personal data is handled, please contact the healthcare facility (for patient records) or our Data Protection Officer first so that we can try to resolve it. You also have the right to lodge a complaint with the regulator:
| Regulator | Details |
|---|---|
| Office of the Data Protection Commissioner (ODPC), Kenya | Website: www.odpc.go.ke Contact details: [email protected] |
17. Changes to this policy
We review this policy at least annually and update it when our services, the law or our practices change. The date at the top shows when it was last updated. Significant changes will be communicated to client facilities and posted on this page before they take effect.