The short version
Telafia lets you see a licensed doctor from your phone. To do that we need some personal information (your phone number and name) and, during a consultation, health information. We use it only to give you care, to take payment, and to meet our legal duties. We never sell it and we never put health information in a text message.
This notice is written for people in Kenya. The law that protects you here is the Data Protection Act 2019, supervised by the Office of the Data Protection Commissioner (ODPC).
What we collect
- Account: phone number, name, country, language, and the time you gave consent.
- Bookings: the doctor, time, consultation type, and anything you choose to write about your reason for booking.
- Health records you add: allergies, conditions, medicines, vitals. Stored encrypted.
- Consultation notes and prescriptions written by your doctor. Notes are stored encrypted.
- Payments: amount, currency, payment reference and status. We never see your card or mobile-money PIN; the payment provider handles that.
- Call signalling: short technical messages that connect your call. The call audio and video go directly between you and the doctor (or through a relay that does not record them) and are never stored by us.
- Activity log: who did what and when (for example “doctor read note”), to protect your records.
Health information
Health data is "sensitive personal data" under the Act. It is processed on the basis of your explicit consent and for the provision of health care by a licensed practitioner.
Only you and the doctor you booked can read your consultation notes. Administrators can see that an appointment happened and whether it was paid, but not what was discussed. Every time a note is read, we record who read it.
Why we are allowed to use it
- Your consent, which you gave when you created your account and can withdraw at any time.
- Providing the service you asked for (the consultation and payment).
- Legal duties, such as keeping financial records for tax and keeping medical records for the period the Kenya Medical Practitioners and Dentists Council (KMPDC) requires.
Who else sees it
We use a small number of service providers, each bound by contract to protect your data:
- Linode (hosting)
- Cloudflare (TURN relay for calls; media is end-to-end between devices and the relay does not store it)
- Paystack / Flutterwave (payments; they see your name, email and amount, never your health data)
- Termii (SMS codes and reminders; messages never contain health information)
Your data is stored on a server in a European data centre (Linode), with daily encrypted backups. Where the law in Kenya requires safeguards for storing data abroad, we rely on contractual protections and encryption.
We share information with authorities only when the law clearly requires it.
How long we keep it
Your account and health records for as long as you use the service. Financial records are kept for the period required by the Kenya Revenue Authority. Clinical notes are kept as required by KMPDC rules. When you ask us to delete your account we remove or anonymise everything we are not legally required to keep (see Your rights).
How we protect it
- Encrypted connections (HTTPS) and encrypted storage for notes and health records.
- Sign-in with one-time codes to your phone; no passwords to steal.
- Strict access rules: a doctor can only open the appointments they are part of.
- Daily encrypted backups, logging of access to records, and regular security updates.
If something goes wrong: We must tell the ODPC within 72 hours of becoming aware of a breach that risks your rights, and tell you in writing within a reasonable time.
Your rights
Under the Data Protection Act 2019 you can:
- Be told how we use your information
- Access the information we hold about you
- Object to processing
- Correct false or misleading information
- Have false or misleading information deleted
- Receive your data in a portable file
- Complain to the ODPC
Use them from Your data (download a copy, request deletion) or by writing to privacy@telemed.example. We answer within 30 days. You can lodge a complaint with the ODPC (odpc.go.ke), or contact us first.
Children
The service is for adults. A parent or guardian may book for a child under their own account; the child's health information is then held under the guardian's consent.
Changes and contact
If we change this notice in a way that matters, we will tell you in the app before it takes effect. Questions: privacy@telemed.example.
Open points for legal review: Confirm data-controller registration with ODPC; Confirm cross-border transfer conditions if servers are outside Kenya.