Skip to content
Legal

Privacy Policy & Data Protection

Last updated: July 2026 · Aligned with the Kenya Data Protection Act, 2019

We treat your account, case, and clinical data with strict confidentiality and reasonable technical safeguards. We do not sell your data, and we do not use identifiable clinical data to train third-party AI models. All AI outputs must be reviewed by a licensed doctor before any clinical use.

1. Who we are

MedBiCare ("we", "us", "our") operates the MedBiCare clinical decision-support platform. This Privacy Policy explains how we collect, use, disclose, protect, and retain personal and clinical data.

This page is maintained by MedBiCare and describes practices we operate today; it is not an independent certification. It should be read together with our Terms of Service.

2. Data controller & contact

For personal data you submit as an individual user, MedBiCare acts as data controller. For patient data submitted by an institutional customer (hospital, clinic, medical school), the institution is the data controller and MedBiCare acts as data processor under a Data Processing Agreement (DPA).

Data protection contact: privacy@medbicare.com.

3. What we collect

Account data: name, email, professional role, institution, and (where applicable) student status or licence number for verification.

Case data: the clinical inputs you enter (age, sex, presenting complaint, vitals, uploaded files) and the AI outputs generated for you.

Usage & security data: log-in events, IP address, device and browser info, page views, feature usage, and audit-trail actions used to secure and improve the service.

Payment data: processed by our payment providers (M-Pesa, Stripe, PayPal, DPO). We do not store full card details on our servers.

4. Legal bases for processing

We process personal data on the following bases under the Kenya Data Protection Act, 2019 and comparable frameworks: (a) performance of a contract with you; (b) our legitimate interests in operating, securing, and improving the Service; (c) your consent, where required; (d) compliance with legal obligations.

You are responsible for establishing an appropriate legal basis (consent, legitimate interest, or public-interest task) for any patient data you enter, and for providing patients with the required privacy notices.

5. How we use data

To deliver the Service (generate AI outputs, save your case history, provide support).

To maintain security, audit trails, and abuse prevention, and to meet legal obligations.

To improve MedBiCare using de-identified, aggregated metrics. We do not use identifiable clinical data to train third-party foundation models.

6. What we do not do

We do not sell personal or clinical data.

We do not share your case data with other users, hospitals, or third parties, except designated administrators on institutional plans or where legally compelled.

We do not use identifiable case data for advertising or marketing.

7. Data protection & security

We apply administrative, technical, and organisational safeguards designed to protect personal and clinical data, including: encryption in transit (TLS 1.2+) and at rest (AES-256); role-based access control; two-factor authentication for staff access to production systems; least-privilege service accounts; audit logging; secret rotation; hardened cloud infrastructure; regular backups; and vulnerability monitoring.

Access to case data is limited to authorised personnel with a legitimate operational need. Staff are subject to confidentiality obligations.

No system is perfectly secure. While we take reasonable steps to protect data, we cannot guarantee absolute security and you use the Service at your own risk.

8. Sub-processors & sharing

We rely on a limited number of reputable sub-processors for cloud hosting, AI model inference, email delivery, error monitoring, analytics, and payment processing. Each is bound by confidentiality and data-protection obligations.

A current list of sub-processors is available on request to institutional customers under a DPA. We may update this list from time to time.

We may disclose data where required by law, court order, or regulatory authority, or to protect the rights, safety, or property of MedBiCare, our users, or the public.

9. International transfers

Data may be processed in jurisdictions outside Kenya, including where our sub-processors operate. Where such transfers occur, we rely on appropriate safeguards such as contractual clauses and provider-level certifications. By using the Service you consent to such transfers where lawful.

10. Retention

Account data is retained while your account is active and for a reasonable period thereafter to meet legal, tax, and audit obligations.

Case data is retained by default so you can return to past cases; you can delete individual cases or request full account deletion at any time.

After account deletion, personally identifiable data is removed or irreversibly anonymised within 30 days, except where retention is required by law. De-identified aggregate metrics may be retained indefinitely.

11. Your rights

Under the Kenya Data Protection Act, 2019 and other applicable law, you may request: access to your personal data; correction of inaccurate data; deletion; restriction of processing; portability; and objection to processing. You may also withdraw consent where processing is based on consent.

To exercise these rights email privacy@medbicare.com. We will respond within the timeframes required by applicable law. You have the right to lodge a complaint with the Office of the Data Protection Commissioner (Kenya) or your local supervisory authority.

12. Patient identifiers & clinical use

MedBiCare is designed for de-identified or minimally-identified clinical inputs. Do not enter direct patient identifiers (full name, national ID, phone number, address) unless your institution has explicitly authorised identified use, a lawful basis exists, and the patient has been informed as required by law.

All AI outputs are provisional. Every output must be reviewed and approved by a licensed doctor before being acted upon, entered into a medical record, or shared with a patient. See our Terms of Service, Section 3.

You are solely responsible for the lawfulness of any patient data you upload and for ensuring appropriate consent, confidentiality, and clinical governance.

13. Cookies & analytics

We use strictly necessary cookies to operate the Service (authentication, security). We may use privacy-respecting analytics to understand aggregated usage. You can control cookies through your browser settings; disabling essential cookies may break the Service.

14. Children

MedBiCare is not directed to persons under 18. We do not knowingly collect personal data from children. Clinical data about paediatric patients may be entered by authorised clinicians under appropriate legal bases.

15. Breach notification

In the event of a personal-data breach likely to result in a risk to affected individuals, we will notify the Office of the Data Protection Commissioner and affected users in accordance with applicable law and reasonable operational timelines.

16. Changes

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-product notice. Continued use after the effective date constitutes acceptance.

17. Contact

Data protection questions: privacy@medbicare.com. Security reports: security@medbicare.com.