Privacy Policy
How personal data is collected and used through RUPHAsoft, the choices you have, and how to contact us or the data protection authority.
1. Who We Are
XR RUPHASOFT LTD ("we", "us", "the Company") is a private limited company incorporated in Kenya on 3 August 2025 (Certificate No. PVT-A71MW6EL). We provide the RUPHAsoft Hospital Management Information System (HMIS), a healthcare management platform used by private hospitals in Kenya. This Privacy Policy explains how personal data is collected and used through RUPHAsoft, the choices you have, and how to contact us or the data protection authority.
We are registered with the Office of the Data Protection Commissioner of Kenya (ODPC) as a data controller and a data processor. Where you are a patient, the hospital treating you is also a data controller of your health records, and we process that data on the hospital's behalf as well as, for our own limited purposes, as a controller.
2. Scope of This Policy
This Policy applies to personal data processed through RUPHAsoft and through our websites and patient booking portal. It covers patients and their next-of-kin, hospital staff and clinicians who use the system, our business contacts, and visitors to our websites. It should be read together with the consent you are asked to give at a treating facility and with the specific privacy notice that facility provides at the point of care.
3. The Personal Data We Collect
| Who you are | What we collect |
|---|---|
| Patients | Name, date of birth, sex, national ID or birth-certificate number, phone, address, next-of-kin, marital status and occupation; and health information: diagnoses and clinical notes, vital signs, laboratory and imaging results, prescriptions, allergies, your SHA/SHIF beneficiary number, an optional biometric identifier, and billing records. |
| Hospital staff and clinicians | Name, professional licence number, job title, contact details, employer facility, login credentials, role and permission level, and system audit logs. |
| Business contacts (vendors, partners) | Name, job title, organisation, contact details, and contract or payment details. |
| Website and portal visitors | Technical information such as your IP address, device and browser type, and the pages you visit. See Section 11. |
Health data, biometric data and similar categories are treated as sensitive personal data and are given additional protection under Kenyan law.
4. How We Use Your Data and Our Lawful Basis
We only use personal data for defined purposes, each with a lawful basis under the Data Protection Act, 2019:
| Purpose | Lawful basis |
|---|---|
| Registering and identifying you, and providing clinical care | Provision of healthcare and your vital interests; explicit consent captured at registration |
| Processing insurance and SHA/SHIF claims for your care | Performance of a contract and legal obligation |
| Billing and payment for services | Performance of a contract |
| Managing staff accounts, access and accountability | Performance of an employment contract; legal obligation |
| Optional public-health research using de-identified or aggregated data | Your separate, explicit consent |
| Securing the system and our websites | Our legitimate interest in protecting personal data |
We do not sell your personal data, and we do not use it for marketing without your separate, explicit opt-in consent.
5. Consent
Where we rely on your consent, you give it freely and can withdraw it at any time. Withdrawing consent does not affect the lawfulness of anything done before you withdrew it, and it does not affect care records that we are legally or clinically required to keep. Consent to clinical care, to sharing data with the Social Health Authority for claims, and to optional research is recorded separately so that each choice is yours to make.
6. Who We Share Your Data With
Your data may be shared, on a need-to-know basis, with:
- the clinical and billing staff of the facility treating you, with access restricted to their role;
- the Social Health Authority, for insurance and claims purposes;
- the Kenya Health Information Exchange, so that your care record is available where the law provides for it;
- another health facility, only where you are referred there for further care;
- a payment service provider, where you choose to pay electronically, strictly to process that payment; and
- our hosting provider, strictly to store and operate the system securely, under a binding data processing agreement.
Each hospital's data is kept separate from every other hospital's, with no cross-facility visibility. We do not share your data with anyone else except where the law requires or permits it.
7. Sending Data Outside Kenya
RUPHAsoft is operated on a managed cloud platform whose primary data centres are in Germany, and encrypted backup copies are additionally held in India. Where personal data is processed outside Kenya, we rely on the safeguards required by the Data Protection Act, 2019 for cross-border transfers, including binding contractual protection with our hosting provider and the security measures described in Section 8.
8. How We Protect Your Data
We apply a layered set of technical and organisational safeguards:
- all traffic to and from RUPHAsoft is encrypted in transit using TLS 1.2 or 1.3;
- backup files are protected with Fernet authenticated encryption (AES-CBC with HMAC-SHA256), under a key held by us;
- credential and secret fields are encrypted at the application layer;
- access is controlled by role-based permissions with field-level restrictions, so staff see only what their role requires;
- multi-factor authentication, whether application-, SMS- or email-based, is required for administrative and privileged accounts;
- database and cache services are reachable only over a private network and are never exposed to the public internet; and
- system activity on patient, encounter and claims records is logged for accountability.
No system can be guaranteed completely secure, but these measures are designed to protect your data against unauthorised access, loss or misuse.
9. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes above and to meet our legal obligations. Clinical and healthcare records are retained for at least 7 years after your last encounter, in line with our Data Retention & Disposal Policy (XR-DRDP-002) and Kenyan health-records requirements; these records are generally not deletable. When data is no longer required, it is disposed of securely.
10. Your Rights
Under the Data Protection Act, 2019 you have the right to:
- be informed about how your data is used (this Policy and the notice given at your facility);
- access the personal data we hold about you, free of charge;
- have inaccurate or misleading data corrected;
- ask us to delete personal data that we are not legally or clinically required to keep. Note that clinical and healthcare records are subject to statutory retention and cannot be deleted;
- object to certain processing;
- request your data in a portable form, where applicable; and
- withdraw consent where processing relies on it.
To exercise any of these rights, contact your treating facility's records office or our Data Protection Officer (Section 12). We handle requests under our Data Subject Access Request Procedure (XR-DSAR-008), free of charge, within the timeframe set by law.
Exercise your rights online. You can request a copy of your data or request deletion of data we are not required to keep using our online forms. The data-protection page explains what happens next and how long each step takes.
11. Website Data and Analytics
When you visit our websites or the patient booking portal, we may collect technical information, meaning your IP address, device and browser type, and the pages you view, to keep the site secure and to understand how it is used. This information is used in aggregate and is not used to build a profile of you. Where our sites use cookies or similar technologies, you can control them through your browser settings; disabling them may affect how the site works.
12. How to Contact Us or Make a Complaint
For any question about this Policy, or to exercise your rights, contact our Data Protection Officer:
- Data Protection Officer
- XR RUPHASOFT LTD
- support@ruphasoft.co.ke
If you are not satisfied with how we have handled your data or your request, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (www.odpc.go.ke).
13. Changes to This Policy
We may update this Policy from time to time to reflect changes in our processing, technology or the law. The current version and its effective date are shown at the top of this page, and material changes will be communicated through the platform or our websites.
Revision History
| Version | Date | Summary of change |
|---|---|---|
| 1.0 | 17 July 2026 | Initial issue: published privacy policy for data subjects, compliant with the Data Protection Act, 2019, covering patients, staff, business contacts and website/portal visitors. |