Skip to content

Data protection

What we do with personal data, in plain language, and what you can ask of us. This page summarises our Privacy Policy and the procedures we submitted to Kenya's regulators. Where the two differ, the Privacy Policy prevails.

Summarises
Privacy Policy XR-PP-015 v1.0 and the policies listed at the end of this page
Last reviewed
2 September 2026

Who is responsible for your data

XR RUPHASOFT LTD builds and operates RUPHAsoft HMIS. When you are treated at a hospital that uses RUPHAsoft, that hospital is the data controller of your health record. We process the record on the hospital's behalf, and for a small number of our own purposes, such as keeping the system secure, we act as a controller too.

Our Data Protection Officer handles every question and request about personal data. You can reach the DPO at support@ruphasoft.co.ke.

We are registered with the Office of the Data Protection Commissioner of Kenya as a data controller and a data processor. Our system documentation has been submitted to the Digital Health Agency for certification review.

What we collect and why

If you are We hold So that
A patient Identity and contact details, next of kin, your SHA/SHIF beneficiary number, and your health record: diagnoses, notes, vital signs, results, prescriptions, allergies and bills Your hospital can identify you, treat you, bill you and claim on your behalf
Hospital staff Name, professional licence number, role, contact details, login credentials and the log of what you did in the system Your facility can give you the access your job needs and stay accountable for it
A business contact Name, organisation, contact details and contract or payment details We can work with you and pay or invoice you
A website visitor IP address, device and browser type, pages visited We can keep the site secure and see how it is used, in aggregate only

We do not sell personal data. We do not use it for marketing unless you have separately opted in. Research on de-identified or aggregated data happens only with your separate, explicit consent.

Who sees it

Only people with a reason to. Inside your hospital, access follows the role a person holds, down to the level of individual fields. Outside your hospital, data goes only to:

  • the Social Health Authority, for eligibility and claims;
  • the Kenya Health Information Exchange, where the law provides for your record to be available;
  • another facility, only when you are referred there;
  • a payment service provider, only to process a payment you chose to make electronically; and
  • our hosting provider, only to store and run the system, under a binding data processing agreement.

Each hospital's data is kept separate from every other hospital's. Each site has its own credentials and exchanges data with national systems independently; there is no cross-site visibility.

Where it is stored

RUPHAsoft runs on Frappe Cloud, a managed platform operated by Frappe Technologies Pvt Ltd, our infrastructure processor. Production sites are in Frappe Cloud's Germany region. Encrypted backup copies are additionally held in Frappe Cloud's offsite backup region in India. We also keep our own encrypted backup copies on storage under our direct control.

Because this means personal data leaves Kenya, we rely on the safeguards the Data Protection Act, 2019 requires for cross-border transfers: binding contractual protection with our hosting provider and the security measures below.

Frappe Technologies holds ISO/IEC 27001:2022 certification and a SOC 2 Type II attestation. These are the processor's certifications, not ours; they cover the platform and physical infrastructure our sites run on.

How it is protected

  • All traffic to and from RUPHAsoft is encrypted in transit using TLS 1.2 or 1.3.
  • Backup files are protected with Fernet authenticated encryption (AES-CBC with HMAC-SHA256), under a key held by us.
  • Credential and secret fields are encrypted at the application layer.
  • Access is controlled by role-based permissions with field-level restrictions.
  • Multi-factor authentication, whether application-, SMS- or email-based, is required for administrative and privileged accounts.
  • Database and cache services are reachable only over a private network and are never exposed to the public internet.
  • System activity on patient, encounter and claims records is logged for accountability.
  • Every member of staff and every contractor signs a confidentiality undertaking, and every sub-processor is under a data processing agreement.

No system can be guaranteed completely secure. These measures are designed to protect your data against unauthorised access, loss or misuse.

How long we keep it

What How long Why
Patient clinical records At least 7 years after your last encounter; longer where clinically material or under a litigation hold Health Act 2017; limitation periods; continuity of care
SHA/SHIF claims and billing records 7 years from settlement of the claim Tax Procedures Act; SHA audit requirements
Staff HR and payroll records 7 years after employment ends Employment Act, 2007; Income Tax Act
Consent records For as long as the processing continues, plus 7 years Evidence of consent, Data Protection Act s.32
System audit and access logs 24 months live, then archived for 5 years Security monitoring and incident investigation
Marketing consent records Until you withdraw consent, plus 12 months Accountability
Backup snapshots Rolling schedule of 7 daily, 4 weekly, 12 monthly and 10 yearly copies Business continuity

Clinical and healthcare records are not deletable. When other data reaches the end of its retention period and no legal hold applies, it is removed from active use through the system's deleted-documents mechanism, and the action is logged.

Your rights, and how to use them

Under the Data Protection Act, 2019 you can ask to be told how your data is used, to see the data we hold about you free of charge, to have inaccurate or misleading data corrected, to have data deleted where we are not legally or clinically required to keep it, to object to certain processing, to receive your data in a portable form where that applies, and to withdraw consent where processing relies on it.

Three ways to ask. Use our online forms to request a copy of your data or request deletion; write to the DPO at support@ruphasoft.co.ke; or ask at the records office of the hospital that treated you.

What happens next

Step When
We acknowledge your request Within 3 business days
We verify your identity (national ID or passport, or authorised-representative documents for a minor or dependant) Within 5 business days
We respond, and provide the data where that is what you asked for Within 30 days of your request. For a complex request we may take up to 30 more days, and we will tell you in writing if so
If you are not satisfied You may complain to the Office of the Data Protection Commissioner at www.odpc.go.ke

We may limit or refuse a request where it would reveal another person's data without their consent, where another law prohibits disclosure, or where the record is a clinical record under statutory retention. Any refusal is given in writing with reasons and with notice of your right to complain to the ODPC.

If something goes wrong

If personal data is lost, exposed or misused, we act on a fixed timetable:

Who we tell By when
The hospitals whose data is affected Within 24 hours
The Digital Health Agency, for breaches involving health data Within 24 hours of discovery
The Office of the Data Protection Commissioner Within 72 hours of becoming aware, as the Data Protection Act, 2019 requires
You, where the breach is likely to put your rights and freedoms at high risk Without undue delay, directly or through your hospital

The root cause is fixed and verified within 14 days and a post-incident review is completed within 30 days.

This website

When you visit our websites, we may collect technical information, meaning your IP address, device and browser type, and the pages you view, to keep the site secure and to understand how it is used. This information is used in aggregate and is not used to build a profile of you. Where our sites use cookies or similar technologies, you can control them through your browser settings; disabling them may affect how the site works.

The documents behind this page

This page is a summary. The governing documents, each formally approved and reviewed annually, are:

  • Privacy Policy, XR-PP-015, version 1.0, effective 17 July 2026
  • Data Protection Policy
  • Data Retention and Disposal Policy, XR-DRDP-002
  • Data Subject Access Request Procedure, XR-DSAR-008
  • Data Transfer Policy
  • Incident Response and Breach Notification Procedure
  • Consent Form, XR-CF-010

Copies of the internal policies are available on request to the DPO.