Creswave logo Ecare HMISby Creswave Limited

Privacy Policy

How Creswave Limited and Ecare HMIS collect, use, share and protect personal data, and the rights you have under the Kenya Data Protection Act, 2019.

Effective date: 15 September 2026  |  Last updated: 24 September 2026  |  Version 1.0

At a glance

Who we are
Creswave Limited, a Kenyan company that builds and runs Ecare HMIS for clinics and hospitals.
If you are a patient
Your health records belong to the facility that treats you. We process them only on the facility’s instructions. Read more
Where your data is kept
Ecare HMIS patient data and its backups are hosted in Nairobi, Kenya.
We never sell your data
Patient data is not used for marketing or to train analytics or AI. Read more
Your rights
Access, correct or delete your data, object, withdraw consent and more. How to use them
Contact our Data Protection Officer
[email protected] or +254 754 001 605

1. Introduction

Creswave Limited (“Creswave”, “we”, “us”, “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, how long we keep it, and the rights you have. It is issued in line with the Kenya Data Protection Act, 2019 (the “Act”) and the Data Protection (General) Regulations, 2021.

Please read it together with any privacy notice provided by the healthcare facility you attend, which explains how that facility uses your health information.

2. Who we are and how to contact us

ItemDetails
CompanyCreswave Limited
Postal addressP.O. Box 50548-00515, BuruBuru, Nairobi, Kenya
Telephone+254 754 001 605
General email[email protected]
Data Protection OfficerJessee Gitaka — [email protected]
Registration with the Office of the Data Protection CommissionerRegistered as a data controller and data processor — Registration No. 613-0110-B460

3. Our role: data controller and data processor

Under the Act, a data controller decides why and how personal data is processed, and a data processor processes personal data on behalf of a controller. Creswave acts in both roles, depending on the data:

SituationOur role
Patient records and other data entered into Ecare HMIS by a healthcare facility (registration details, clinical notes, test results, prescriptions, billing and insurance information)Data processor. The healthcare facility is the data controller. We process this data only on the facility’s documented instructions, under a written agreement, to provide, support and secure Ecare HMIS. Questions or requests about these records should be directed to the facility first; we will help the facility respond.
Accounts of facility staff who use Ecare HMISData processor for the facility, and data controller for the limited account and security information we need to operate and protect the service (for example login and audit records).
Our website, enquiries, sales and support contacts, contracts with clients and suppliers, marketingData controller.
Our employees, contractors and job applicantsData controller.

4. Personal data we collect

Patient data processed in Ecare HMIS (on behalf of healthcare facilities)

Depending on the services a facility uses, this may include:

  • Identity and contact details: name, date of birth, sex, national ID, passport or birth certificate number, patient number, phone number, email, residence, county and ward, occupation, next of kin;
  • Health data: visits, symptoms and history, vital signs, diagnoses, laboratory and radiology results and images, prescriptions and dispensing, admissions, maternal and child health, immunisation, nutrition and other clinical records;
  • Financial and insurance data: bills, receipts, payments (including M-PESA references), insurance scheme and membership numbers, SHA / SHIF numbers and claims;
  • Other sensitive data where recorded by the facility: marital status, religion and family details;
  • Appointment, referral, telemedicine and online booking information, and SMS notification records.

Health data and the other items above are “sensitive personal data” under the Act and receive extra protection.

Data about facility users of Ecare HMIS

  • Name, username, contact details, designation (role), staff or professional registration number, branch and facility;
  • Security data: password (stored only as a one-way hash), multi-factor authentication settings, login times, IP address, device and browser information, and an audit record of actions taken in the system.

Data about clients, prospects and website visitors

  • Names, job titles, organisation, phone, email and correspondence when you contact us, request a demonstration or sign a contract;
  • Technical data when you visit our website: IP address, browser type, pages visited and cookie data (see Cookies).

Data about job applicants and staff

CVs, qualifications, references, identification, and employment and payroll information, handled under our internal HR privacy notice.

5. How we collect personal data

  • From healthcare facilities and their staff, who enter patient data into Ecare HMIS during care and administration;
  • Directly from patients who use online booking, patient app registration or telemedicine features made available by their facility;
  • From connected systems at the facility’s request — laboratory analysers, imaging systems (PACS), insurance claims platforms and payment services;
  • Directly from you when you contact us, use our website, apply for a job or enter into a contract with us;
  • Automatically, through system logs and cookies, when you use Ecare HMIS or our website.

6. Why we use personal data and our lawful basis

We process personal data only where the Act allows it. The main purposes and lawful bases are:

PurposeLawful basis under the Act
Providing Ecare HMIS to healthcare facilities so that they can register, treat and bill patients, manage appointments and referrals, and submit insurance claimsPerformance of our contract with the facility. The facility relies on its own lawful basis — including the provision of health care by or under the responsibility of a health care provider — for processing patient health data.
Sending appointment reminders and service messages by SMS or email on the facility’s behalfFacility’s instructions and lawful basis; performance of contract.
Securing the system: authentication, access control, audit trails, fraud and misuse detection, incident responseLegitimate interests in protecting data and systems; legal obligation to implement security safeguards.
Backups and disaster recoveryPerformance of contract; legal obligation to protect data integrity and availability.
Customer support and system maintenancePerformance of contract; legitimate interests.
Statutory reporting prepared by facilities (e.g. Ministry of Health reports), KRA eTIMS and SHA integrationsLegal obligations of the facility, carried out on its instructions.
Managing client and supplier relationships, invoicing and contractsPerformance of contract; legal obligation (tax records).
Responding to enquiries and demonstration requestsLegitimate interests; your consent where required.
Marketing communications about our productsYour consent — you can withdraw it at any time.
Recruitment and employmentSteps before entering a contract; performance of contract; legal obligation.
Complying with laws, regulatory requests and legal claimsLegal obligation; establishment, exercise or defence of legal claims.

We do not sell personal data. We do not use patient data for our own purposes — including marketing, profiling, or training analytics or artificial intelligence models — unless the facility has instructed us in writing and a lawful basis exists. Where data is used for statistics, it is anonymised first.

7. Who we share personal data with

We share personal data only where necessary and under written agreements that require confidentiality and security:

RecipientWhy
The healthcare facility you attend, and its authorised staffPatient data belongs to the facility. Access within Ecare HMIS is limited by role: users see only the functions and records their role allows.
Our service providers (processors)Servercore (cloud hosting and backups, Nairobi); Cloudflare (website and application security, content delivery and file storage); hosting.com (email); Africa’s Talking and Advanta (SMS delivery). They may use the data only to provide their service to us.
Integration partners instructed by the facilityInsurance claims platforms (e.g. M-TIBA, Smart, Slade), the Social Health Authority (SHA), KRA eTIMS, payment and accounting services, laboratory and imaging systems — only where the facility has enabled the integration.
Independent security testers and auditorsTo test and verify our security under strict confidentiality.
Regulators and authoritiesThe Office of the Data Protection Commissioner, the Digital Health Agency, KRA, courts or law enforcement where required by law.
Professional advisersLawyers, auditors and insurers, under confidentiality.
A buyer or successorIf our business is reorganised or sold, subject to equivalent protection and notice to you.

8. Where your data is stored and international transfers

Ecare HMIS production databases and their backups are hosted on servers in Nairobi, Kenya. Some service providers — for example Cloudflare, which protects and speeds up our websites and stores some documents and images — operate global networks, so limited data may pass through or be stored in data centres outside Kenya.

Where personal data is transferred outside Kenya, we do so only as permitted by the Act and the Regulations: to countries or providers with appropriate safeguards for the security and protection of personal data, under contractual protections and — for sensitive personal data — with the additional safeguards the law requires. You may ask the Data Protection Officer for details of the safeguards used.

9. How we protect personal data

We use technical and organisational measures appropriate to the sensitivity of health data, including:

  • encryption of data in transit (TLS 1.3, with TLS 1.2 only where an approved external system requires it);
  • role-based access control, so each user sees only the functions and records their role requires, with separation of data between facilities;
  • multi-factor authentication, strong password rules, account lockout after repeated failed logins, and automatic logout after inactivity;
  • passwords stored only as one-way Bcrypt hashes; passwords, one-time codes and tokens are never recorded in logs;
  • a complete audit trail of activity in Ecare HMIS, continuous security monitoring and alerting;
  • network isolation (databases have no public internet access), firewalls, a web application firewall and DDoS protection;
  • daily and hourly backups, regular restore testing and a tested disaster recovery plan;
  • regular vulnerability scanning and independent penetration testing;
  • staff confidentiality agreements, security and privacy training, and strict rules on handling patient data;
  • a continuing programme of improvements, including encryption of stored databases and backups, scheduled for completion by mid-2027.

No system is completely secure. If a personal data breach occurs, we will act immediately to contain it and will notify the affected facility within 48 hours, and the Office of the Data Protection Commissioner and affected individuals where the law requires.

10. Your rights

Under the Act, you have the right to:

RightWhat it means
Be informedKnow how your personal data is used — this policy and your facility’s notice do that.
AccessObtain a copy of the personal data held about you.
RectificationHave inaccurate, out-of-date, incomplete or misleading data corrected.
Deletion (erasure)Ask for data to be deleted where it is no longer needed or was processed unlawfully. Health records may have to be kept by the facility for legal and clinical reasons, so this right may be limited.
ObjectObject to processing of all or part of your data, including processing for direct marketing.
Restrict processingAsk that processing be restricted while accuracy or lawfulness is checked.
Data portabilityReceive data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically possible.
Withdraw consentWhere processing is based on consent, withdraw it at any time, without affecting earlier processing.
Not be subject to automated decisionsNot be subject to decisions based solely on automated processing that significantly affect you. Ecare HMIS does not make such decisions; clinical and financial decisions are made by people.
ComplainLodge a complaint with the Office of the Data Protection Commissioner (see Complaints).

How to exercise your rights

  • Patients: contact the healthcare facility that holds your records, since it is the data controller. If you contact Creswave, we will pass your request to the facility within 7 days and help it respond.
  • Everyone else: write to our Data Protection Officer using the details in Who we are and how to contact us.

We may need to verify your identity before acting on a request. We respond without undue delay and within the timelines set by the Data Protection (General) Regulations, 2021. Requests are free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline as the law permits, and tell you why.

11. How long we keep personal data

We keep personal data only as long as necessary for the purpose it was collected for, or as the law requires:

DataRetention
Patient records in Ecare HMISAs decided by the healthcare facility under applicable health-records rules, for as long as it uses Ecare HMIS. When a facility leaves, its data is returned and then deleted from our live systems within 90 days; backup copies expire within 12 months.
Database backupsUp to 12 months, in rotation.
Audit and security logs3 years (access records) to 5 years (records of changes and administration).
SMS delivery records12 months.
Client, supplier and contract recordsDuration of the relationship plus 6 years.
Financial and tax records5 years from the end of the relevant reporting period.
Enquiries and marketing contactsUntil you withdraw consent, or 2 years after last contact.
Unsuccessful job applications6 months.

When data is no longer needed, it is securely deleted or anonymised.

12. Cookies and similar technologies

Ecare HMIS uses strictly necessary technologies — such as session tokens and browser storage — to keep you securely signed in, remember your settings and protect against attacks. These cannot be switched off without stopping the system working. Our website may use cookies to operate the site and, only with your consent, to understand how the site is used. You can manage or delete cookies in your browser settings; blocking necessary cookies may affect how the site works.

13. Marketing communications

We send marketing messages about our products only to business contacts who have agreed to receive them. Every message includes a way to unsubscribe, and you can also opt out at any time by contacting us. We never use patient data for marketing, and we do not send marketing to patients.

14. Children

Healthcare facilities record information about children as patients (for example in child health and immunisation services). Such data is processed on the facility’s instructions, with the consent of a parent or guardian or another lawful basis, and in the best interests of the child. Our own websites and services are not directed at children, and we do not knowingly collect children’s data for our own purposes.

15. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on individuals. Reports and dashboards in Ecare HMIS support decisions made by facility staff.

16. Complaints

If you have a concern about how your personal data is handled, please contact the healthcare facility (for patient records) or our Data Protection Officer first so that we can try to resolve it. You also have the right to lodge a complaint with the regulator:

RegulatorDetails
Office of the Data Protection Commissioner (ODPC), KenyaWebsite: www.odpc.go.ke
Contact details: [email protected]

17. Changes to this policy

We review this policy at least annually and update it when our services, the law or our practices change. The date at the top shows when it was last updated. Significant changes will be communicated to client facilities and posted on this page before they take effect.