The short version
Telafia lets you see a licensed doctor from your phone. To do that we need some personal information (your phone number and name) and, during a consultation, health information. We use it only to give you care, to take payment, and to meet our legal duties. We never sell it and we never put health information in a text message.
This notice is written for people in Uganda. The law that protects you here is the Data Protection and Privacy Act 2019, supervised by the Personal Data Protection Office (PDPO).
What we collect
- Account: phone number, name, country, language, and the time you gave consent.
- Bookings: the doctor, time, consultation type, and anything you choose to write about your reason for booking.
- Health records you add: allergies, conditions, medicines, vitals. Stored encrypted.
- Consultation notes and prescriptions written by your doctor. Notes are stored encrypted.
- Payments: amount, currency, payment reference and status. We never see your card or mobile-money PIN; the payment provider handles that.
- Call signalling: short technical messages that connect your call. The call audio and video go directly between you and the doctor (or through a relay that does not record them) and are never stored by us.
- Activity log: who did what and when (for example “doctor read note”), to protect your records.
Health information
Health data is "special personal data" under the Act and is processed only with your consent and for medical purposes.
Only you and the doctor you booked can read your consultation notes. Administrators can see that an appointment happened and whether it was paid, but not what was discussed. Every time a note is read, we record who read it.
Why we are allowed to use it
- Your consent, which you gave when you created your account and can withdraw at any time.
- Providing the service you asked for (the consultation and payment).
- Legal duties, such as keeping financial records for tax and keeping medical records for the period the Uganda Medical and Dental Practitioners Council (UMDPC) requires.
Who else sees it
We use a small number of service providers, each bound by contract to protect your data:
- Linode (hosting)
- Cloudflare (TURN relay for calls; media is end-to-end between devices and the relay does not store it)
- Paystack / Flutterwave (payments; they see your name, email and amount, never your health data)
- Termii (SMS codes and reminders; messages never contain health information)
Your data is stored on a server in a European data centre (Linode), with daily encrypted backups. Where the law in Uganda requires safeguards for storing data abroad, we rely on contractual protections and encryption.
We share information with authorities only when the law clearly requires it.
How long we keep it
Your account and health records for as long as you use the service. Financial records are kept for the period required by the Uganda Revenue Authority. Clinical notes are kept as required by the UMDPC. When you ask us to delete your account we remove or anonymise everything we are not legally required to keep (see Your rights).
How we protect it
- Encrypted connections (HTTPS) and encrypted storage for notes and health records.
- Sign-in with one-time codes to your phone; no passwords to steal.
- Strict access rules: a doctor can only open the appointments they are part of.
- Daily encrypted backups, logging of access to records, and regular security updates.
If something goes wrong: We must tell the Personal Data Protection Office immediately after we become aware of a breach, and tell you where there is a risk to you.
Your rights
Under the Data Protection and Privacy Act 2019 you can:
- Access the information we hold about you
- Correct or delete inaccurate information
- Object to processing
- Withdraw consent
- Complain to the PDPO
Use them from Your data (download a copy, request deletion) or by writing to privacy@telemed.example. We answer within 30 days. You can complain to the PDPO (pdpo.go.ug), or contact us first.
Children
The service is for adults. A parent or guardian may book for a child under their own account; the child's health information is then held under the guardian's consent.
Changes and contact
If we change this notice in a way that matters, we will tell you in the app before it takes effect. Questions: privacy@telemed.example.
Open points for legal review: Confirm registration with PDPO; Confirm breach-notice deadline in the 2021 Regulations.