Data protection
What we do with personal data, in plain language, and what you can ask of us. This page summarises our Privacy Policy and the procedures we submitted to Kenya's regulators. Where the two differ, the Privacy Policy prevails.
Who is responsible for your data
XR RUPHASOFT LTD builds and operates RUPHAsoft HMIS. When you are treated at a hospital that uses RUPHAsoft, that hospital is the data controller of your health record. We process the record on the hospital's behalf, and for a small number of our own purposes, such as keeping the system secure, we act as a controller too.
Our Data Protection Officer handles every question and request about personal data. You can reach the DPO at support@ruphasoft.co.ke.
We are registered with the Office of the Data Protection Commissioner of Kenya as a data controller and a data processor. Our system documentation has been submitted to the Digital Health Agency for certification review.
What we collect and why
| If you are | We hold | So that |
|---|---|---|
| A patient | Identity and contact details, next of kin, your SHA/SHIF beneficiary number, and your health record: diagnoses, notes, vital signs, results, prescriptions, allergies and bills | Your hospital can identify you, treat you, bill you and claim on your behalf |
| Hospital staff | Name, professional licence number, role, contact details, login credentials and the log of what you did in the system | Your facility can give you the access your job needs and stay accountable for it |
| A business contact | Name, organisation, contact details and contract or payment details | We can work with you and pay or invoice you |
| A website visitor | IP address, device and browser type, pages visited | We can keep the site secure and see how it is used, in aggregate only |
We do not sell personal data. We do not use it for marketing unless you have separately opted in. Research on de-identified or aggregated data happens only with your separate, explicit consent.
Who sees it
Only people with a reason to. Inside your hospital, access follows the role a person holds, down to the level of individual fields. Outside your hospital, data goes only to:
- the Social Health Authority, for eligibility and claims;
- the Kenya Health Information Exchange, where the law provides for your record to be available;
- another facility, only when you are referred there;
- a payment service provider, only to process a payment you chose to make electronically; and
- our hosting provider, only to store and run the system, under a binding data processing agreement.
Each hospital's data is kept separate from every other hospital's. Each site has its own credentials and exchanges data with national systems independently; there is no cross-site visibility.
Where it is stored
RUPHAsoft runs on Frappe Cloud, a managed platform operated by Frappe Technologies Pvt Ltd, our infrastructure processor. Production sites are in Frappe Cloud's Germany region. Encrypted backup copies are additionally held in Frappe Cloud's offsite backup region in India. We also keep our own encrypted backup copies on storage under our direct control.
Because this means personal data leaves Kenya, we rely on the safeguards the Data Protection Act, 2019 requires for cross-border transfers: binding contractual protection with our hosting provider and the security measures below.
Frappe Technologies holds ISO/IEC 27001:2022 certification and a SOC 2 Type II attestation. These are the processor's certifications, not ours; they cover the platform and physical infrastructure our sites run on.
How it is protected
- All traffic to and from RUPHAsoft is encrypted in transit using TLS 1.2 or 1.3.
- Backup files are protected with Fernet authenticated encryption (AES-CBC with HMAC-SHA256), under a key held by us.
- Credential and secret fields are encrypted at the application layer.
- Access is controlled by role-based permissions with field-level restrictions.
- Multi-factor authentication, whether application-, SMS- or email-based, is required for administrative and privileged accounts.
- Database and cache services are reachable only over a private network and are never exposed to the public internet.
- System activity on patient, encounter and claims records is logged for accountability.
- Every member of staff and every contractor signs a confidentiality undertaking, and every sub-processor is under a data processing agreement.
No system can be guaranteed completely secure. These measures are designed to protect your data against unauthorised access, loss or misuse.
How long we keep it
| What | How long | Why |
|---|---|---|
| Patient clinical records | At least 7 years after your last encounter; longer where clinically material or under a litigation hold | Health Act 2017; limitation periods; continuity of care |
| SHA/SHIF claims and billing records | 7 years from settlement of the claim | Tax Procedures Act; SHA audit requirements |
| Staff HR and payroll records | 7 years after employment ends | Employment Act, 2007; Income Tax Act |
| Consent records | For as long as the processing continues, plus 7 years | Evidence of consent, Data Protection Act s.32 |
| System audit and access logs | 24 months live, then archived for 5 years | Security monitoring and incident investigation |
| Marketing consent records | Until you withdraw consent, plus 12 months | Accountability |
| Backup snapshots | Rolling schedule of 7 daily, 4 weekly, 12 monthly and 10 yearly copies | Business continuity |
Clinical and healthcare records are not deletable. When other data reaches the end of its retention period and no legal hold applies, it is removed from active use through the system's deleted-documents mechanism, and the action is logged.
Your rights, and how to use them
Under the Data Protection Act, 2019 you can ask to be told how your data is used, to see the data we hold about you free of charge, to have inaccurate or misleading data corrected, to have data deleted where we are not legally or clinically required to keep it, to object to certain processing, to receive your data in a portable form where that applies, and to withdraw consent where processing relies on it.
Three ways to ask. Use our online forms to request a copy of your data or request deletion; write to the DPO at support@ruphasoft.co.ke; or ask at the records office of the hospital that treated you.
What happens next
| Step | When |
|---|---|
| We acknowledge your request | Within 3 business days |
| We verify your identity (national ID or passport, or authorised-representative documents for a minor or dependant) | Within 5 business days |
| We respond, and provide the data where that is what you asked for | Within 30 days of your request. For a complex request we may take up to 30 more days, and we will tell you in writing if so |
| If you are not satisfied | You may complain to the Office of the Data Protection Commissioner at www.odpc.go.ke |
We may limit or refuse a request where it would reveal another person's data without their consent, where another law prohibits disclosure, or where the record is a clinical record under statutory retention. Any refusal is given in writing with reasons and with notice of your right to complain to the ODPC.
If something goes wrong
If personal data is lost, exposed or misused, we act on a fixed timetable:
| Who we tell | By when |
|---|---|
| The hospitals whose data is affected | Within 24 hours |
| The Digital Health Agency, for breaches involving health data | Within 24 hours of discovery |
| The Office of the Data Protection Commissioner | Within 72 hours of becoming aware, as the Data Protection Act, 2019 requires |
| You, where the breach is likely to put your rights and freedoms at high risk | Without undue delay, directly or through your hospital |
The root cause is fixed and verified within 14 days and a post-incident review is completed within 30 days.
This website
When you visit our websites, we may collect technical information, meaning your IP address, device and browser type, and the pages you view, to keep the site secure and to understand how it is used. This information is used in aggregate and is not used to build a profile of you. Where our sites use cookies or similar technologies, you can control them through your browser settings; disabling them may affect how the site works.
The documents behind this page
This page is a summary. The governing documents, each formally approved and reviewed annually, are:
- Privacy Policy, XR-PP-015, version 1.0, effective 17 July 2026
- Data Protection Policy
- Data Retention and Disposal Policy, XR-DRDP-002
- Data Subject Access Request Procedure, XR-DSAR-008
- Data Transfer Policy
- Incident Response and Breach Notification Procedure
- Consent Form, XR-CF-010
Copies of the internal policies are available on request to the DPO.