1. Introduction
At Kinga Care, your privacy is a priority. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our website (kinga.care), mobile application, Shifa clinical platform, and related health coordination services (collectively, the "Services").By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Services.This document is provided for transparency and does not constitute legal advice. We recommend reviewing it alongside our Terms of Service.
2. Medical Emergencies
Kinga Care and Shifa are not emergency medical services.
The Services are designed for proactive health management, chronic care coordination, and scheduled clinical consultations. They are not intended for use in medical emergencies and do not provide real-time emergency response, ambulance dispatch, or 24/7 urgent care.
If you or someone else is experiencing a medical emergency—such as severe chest pain, difficulty breathing, loss of consciousness, serious injury, stroke symptoms, or any other life-threatening condition—do not use the Services. Instead:
- Call your local emergency number immediately, or
- Go to the nearest hospital emergency department or urgent care facility without delay.
Messages, in-app chats, appointment requests, and AI-generated insights sent through Kinga Care or Shifa are not monitored for emergencies and may not be reviewed in time to assist you in an urgent situation. Do not rely on the Services as a substitute for immediate, in-person emergency medical care.
3. Who We Are
Kinga Care is a digital health company focused on proactive longevity and chronic care management. We help individuals and families build a Health Passport, coordinate care with clinicians and laboratories, and receive personalised health insights—including AI-assisted risk assessments and longevity recommendations.
Shifa is Kinga Care's virtual primary care operating system. It enables clinics and healthcare organisations to deliver nutrition, therapy, psychiatry, and chronic disease programmes through a unified clinical platform—including patient triage, scheduling, care workflows, payments, and clinical communications.
Shifa is Kinga Care's virtual primary care operating system. It enables clinics and healthcare organisations to deliver nutrition, therapy, psychiatry, and chronic disease programmes through a unified clinical platform—including patient triage, scheduling, care workflows, payments, and clinical communications.
4. Scope and User Types
This Privacy Policy applies to all users of the Services. Depending on how you interact with Kinga Care, you may fall into one or more of the following categories:
Kinga Care Members
Kinga Care MemIndividuals who register for or use the Kinga Care mobile application, participate in care programmes, or receive health coordination services through Kinga Care.bers
Clinic Users
Clinicians, consultants, administrators, and staff who access the Shifa platform on behalf of a healthcare organisation.
Patients
Individuals whose health information is managed within a clinic's Shifa workspace, whether or not they also use the Kinga Care mobile app.
Site Visitors
Individuals who browse our website or marketing pages without creating an account or logging in.
Kinga Care Members - Individuals who register for or use the Kinga Care mobile application, participate in care programmes, or receive health coordination services through Kinga Care.
Clinic Users - Clinicians, consultants, administrators, and staff who access the Shifa platform on behalf of a healthcare organisation.
Patients - Individuals whose health information is managed within a clinic's Shifa workspace, whether or not they also use the Kinga Care mobile app.
Site Visitors - Individuals who browse our website or marketing pages without creating an account or logging in.
Where this policy refers to "you", it applies to all of the above unless a section specifies otherwise.
5. Definitions
For the purposes of this Privacy Policy:
- Personal Data means information that identifies you or can reasonably be used to identify you, as defined under the Kenya Data Protection Act, 2019.
- Sensitive Personal Data includes health and medical information, biometric data, and other categories designated as sensitive under applicable law.
- Usage Data means technical information about how you interact with the Services (such as pages visited, session duration, and device identifiers) that does not, on its own, identify you.
- De-identified Data means data that has been processed so that it can no longer reasonably be used to identify you, directly or indirectly.
- Services means the Kinga Care website, mobile application, Shifa clinical platform, and all related features, APIs, and support channels we operate.
6. Information We Collect
We collect information necessary to deliver safe, effective, and personalised health services. The categories below describe the types of data we may process.
Identifiers and contact information
Name, email address, phone number, date of birth, gender, postal address, national ID (where required)
Account and authentication data
Username, password (hashed), Google sign-in identifiers, workspace invitations, role assignments
Kinga Care Members, Clinic Users
Health and medical information
Medical history, symptoms, vitals, laboratory results, medication records, care plans, session notes, diagnoses, treatment records, biometric readings (e.g., blood pressure, glucose)
Kinga Care Members, Patients
Longevity Score, health risk assessments, programme recommendations derived from your health data
Appointment and scheduling data
Appointment dates and times, consultation type, location, notes, reminders, attendee information
Clinic Users, Patients, Kinga Care Members
Calendar list metadata, event details, availability information.
Invoice records, transaction references, M-Pesa payment confirmations, billing addresses. We do not store full payment card numbers on our servers.
Kinga Care Members, Clinic Users
SMS, WhatsApp, in-app messages, email correspondence, support tickets, appointment reminders
Clinic and organisation data
Organisation name, consultant profiles, speciality credentials, service configurations, staff onboarding status
IP address, browser type, operating system, device identifiers, access timestamps, log files, crash reports, analytics events
Feedback and survey responses
Wellness surveys, programme evaluations, product feedback
Information You Provide Directly
We receive information you enter when you:
- Create a Kinga Care or Shifa account, complete onboarding, or accept a workspace invitation
- Complete clinical intake forms, wellness surveys, or care programme assessments
- Book, reschedule, or cancel appointments
- Communicate with your care team, clinic staff, or Kinga Care support
- Submit payment information for fee-based services
- Connect third-party services (such as Google Calendar) that you authorise
Information Collected Automatically
When you use the Services, we and our service providers may automatically collect Usage Data, including:
- Pages and features you access within the website or application
- Date, time, and duration of your sessions
- Referring URLs and navigation paths
- Device and browser characteristics
- Error logs and performance metrics
Information from Third Parties
With your consent or as permitted by law, we may receive information from:
- Healthcare providers, laboratories, and health coaches involved in your care
- Payment processors and mobile money providers (e.g., M-Pesa)
- Authentication providers (e.g., Google, when you choose to sign in with Google)
- Wearable devices or health apps you choose to connect to Kinga Care
- Your employer, insurer, or programme sponsor (where you enrol through a partner organisation)
7. How We Collect Information
We collect Personal Data through the following methods:
Directly from you
When you register, complete forms, book appointments, communicate with us, or configure your account settings.
Automatically
Through cookies, log files, analytics tools, and similar technologies when you access the Services.
From healthcare partners
When clinicians, laboratories, or care coordinators share information with your consent to support your treatment.
From authorised integrations
When you connect third-party services—such as Google Calendar or wearable devices—and authorise us to access data from those services.
From service providers
When payment processors, hosting providers, or communication platforms process data on our behalf and share relevant transaction or delivery information with us.
You may choose not to provide certain information. However, if you decline to provide information that is required for a particular feature (such as calendar access for appointment scheduling), we may be unable to provide that feature.
8. Calendar and Scheduling Integrations
Google Calendar is our primary calendar integration. When Clinic Users sign in to Shifa with Google or connect their Google account through the dedicated calendar connection flow, we request permission to access calendar data on their behalf.
We may support additional calendar providers in the future. If we do, we will request your separate consent before accessing data from any new provider.
8.1 Calendar Provider
Google Calendar is our primary calendar integration. When Clinic Users sign in to Shifa with Google or connect their Google account through the dedicated calendar connection flow, we request permission to access calendar data on their behalf.
We may support additional calendar providers in the future. If we do, we will request your separate consent before accessing data from any new provider.
8.2 Google Workspace / Calendar Limited Use
The use of raw or derived user data received from Google Workspace APIs (including Google Calendar) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used solely to display calendars, determine availability, and create/update/delete appointment events in Shifa.Calendar data is not used for AI/ML. We do not transfer Google Calendar or other Workspace API user data (raw, aggregated, or derived) to any third-party AI/ML service, and we do not use that data to create, train, or improve foundational or generalized AI/ML models. Our AI features (e.g. Longevity Score and health insights) operate on health and care data you provide in Kinga Care / Shifa, not on Google Calendar data.
8.3 When Calendar Access Is Requested
Calendar permissions may be requested or used when you:
- Sign in to Shifa using your Google account (a single consent covers authentication and calendar access)
- Complete the Google Calendar connection step during staff onboarding
- View or manage appointments in the Shifa calendar
- Book, reschedule, or cancel patient appointments
- Schedule follow-up sessions within clinical care workflows
- Check consultant availability for appointment scheduling
8.4 OAuth Permissions Requested
We request only the Google permissions necessary to provide scheduling features. Specifically, we request:
openid and profile
Authenticate your identity and display your name
userinfo.email
Identify your Google account and associate it with your Shifa workspace
calendar.calendarlist.readonly
Read the list of calendars you can access (to discover your primary and subscribed calendars)
calendar.events
Read, create, update, and delete events on calendars you can access
We do not request full calendar administration permissions (such as the ability to share, delete, or modify calendar access controls for other users).
8.5 Calendar Data We Access
When you authorise calendar access, we may access the following information from your Google Calendar:
Calendar list metadata:
- Calendar names and descriptions
- Primary calendar designation
- Time zone settings
- Display colours
Event data (for calendars you can access):
- Event titles and descriptions
- Start and end dates/times (including all-day events)
- Location information
- Recurrence rules and reminders
- Attendee email addresses, display names, and RSVP status
- Video conference links (such as Google Meet)
- Organizer and creator information
- Event status (e.g., confirmed, cancelled)
We use this data solely to display your calendar within Shifa, determine availability for appointment booking, and manage clinical scheduling workflows. We do not use calendar data for advertising, unrelated profiling, or purposes beyond scheduling and care coordination.
8.6 Calendar Data We Create or Modify
When appointments are booked through Shifa, we may create, update, or delete calendar events on your behalf, including:
- Appointment title (consultation type)
- Start and end times with time zone
- Location (including physical address or virtual meeting details)
- Clinical notes associated with the appointment
- Reminders (e.g., one hour before the appointment)
- Attendee invitations sent to patients and scheduling staff
Calendar invitations may be sent to attendees via Google Calendar's standard notification system. Patient email addresses provided during booking are included as event attendees.
8.7 How Calendar Data Is Stored
- OAuth tokens (access and refresh tokens) are stored securely on our backend servers, not in your browser. We use these tokens to communicate with Google Calendar on your behalf.
- Calendar events may be cached locally in your browser (using IndexedDB or local storage) to improve performance and enable offline calendar display. Cached data is tied to your authenticated session.
- Appointment records are stored in our secure backend systems alongside other clinical scheduling data.
We do not store your Google account password. Authentication is handled entirely through Google's OAuth system.
8.8 Revoking Calendar Access
You can disconnect your Google Calendar from Shifa at any time through your account settings within the platform. You may also revoke Shifa's access directly through your Google Account permissions.
Please note that disconnecting calendar access may limit or disable scheduling features that depend on calendar synchronisation, including appointment booking and availability checks.
8.9 Third-Party Calendar Terms
Your use of Google Calendar through Shifa is also subject to Google's Privacy Policy and Google's Terms of Service. Kinga Care is not responsible for Google's data practices. We encourage you to review Google's policies to understand how Google handles your calendar information independently of our Services.
9. How We Use Your Information
We use the information we collect for the following purposes:
Providing and Managing the Services
- Create and maintain your Health Passport and clinical records
- Coordinate care between you, clinicians, laboratories, and health coaches
- Enable appointment scheduling, triage, and clinical workflows through Shifa
- Process payments and generate invoices
- Authenticate your identity and manage your account
Proactive Health and Care Coordination
- Deliver chronic care and longevity programmes tailored to your health profile
- Generate AI-assisted health insights, including your Longevity Score and risk assessments
- Send health alerts, appointment reminders, and care programme updates via SMS, WhatsApp, email, or in-app notifications
Calendar and Scheduling
- Display your calendar and clinic appointments within Shifa
- Calculate consultant availability and suggest appointment slots
- Create, update, and cancel calendar events for booked appointments
- Send calendar invitations and reminders to patients and care team members
Communications
- Respond to your inquiries, feedback, and support requests
- Send service-related announcements and policy updates
- Deliver marketing communications where you have given consent (you may opt out at any time)
Security, Compliance, and Improvementmmunications
- Monitor platform security, detect fraud, and prevent unauthorised access
- Comply with legal and regulatory obligations, including the Data Protection Act, 2019 and the Digital Health Act, 2023
- Conduct internal audits and quality assurance for clinical services
We do not sell your personal or health data.
10. Legal Bases for Processing
Under the Kenya Data Protection Act, 2019, we process your Personal Data only where we have a lawful basis. Depending on the context, our legal bases include:
Performance of a contract
To provide the Services you have registered for, fulfil appointment bookings, process payments, and deliver care programmes you have enrolled in.
Consent
When you connect third-party integrations (such as Google Calendar), opt in to marketing communications, or authorise sharing of health data with specific providers. You may withdraw consent at any time.
Legitimate interests
To improve our Services, ensure platform security, prevent fraud, and communicate about service updates—provided these interests do not override your privacy rights.
Legal obligation
To comply with applicable laws, respond to lawful requests from regulators or courts, and meet medical record-keeping requirements.
Where we process Sensitive Personal Data (such as health information), we rely on your explicit consent, the necessity of processing for healthcare provision, or another lawful basis permitted under applicable law.
11. How We Share Information
We do not sell your personal or health data. We share information only in the circumstances described below.
Healthcare Providers and Care Teams
With your consent, we share relevant health data with doctors, therapists, nutritionists, laboratory technicians, health coaches, and other providers involved in your care. This enables coordinated treatment and follow-up.
Your Clinic Organisation
If you are a Clinic User or Patient within a Shifa workspace, administrators and authorised consultants within that organisation can access information necessary to deliver care, subject to role-based permissions.
Service Providers
We engage trusted third parties who process data on our behalf under contractual safeguards, including:
- Cloud hosting and data storage providers
- Payment processors and mobile money providers
- SMS, WhatsApp, and email delivery services
- Google (for authentication and calendar API access)
- Analytics and error monitoring tools
- Customer support platforms
These providers are contractually required to handle your data confidentially, securely, and only for the purposes we specify.
Programme Sponsors and Partners
If you enrol in Kinga Care through an employer, insurer, or partner organisation, we may share limited enrolment and programme participation data with that organisation as described in your enrolment agreement.
Legal and Regulatory Disclosures
We may disclose Personal Data when required by law, including in response to:
- Court orders, subpoenas, or lawful requests from government authorities
- Regulatory directives from the Office of the Data Protection Commissioner (ODPC) or health regulators
- Situations where disclosure is necessary to protect the rights, safety, or property of Kinga Care, our users, or the public
Business Transfers
If Kinga Care undergoes a merger, acquisition, restructuring, or sale of assets, your Personal Data may be transferred as part of that transaction. We will ensure that any receiving entity upholds privacy safeguards equivalent to those described in this policy and will notify you of any material change in data handling.
With Your Direction
You may instruct us to share information with third parties (such as other health apps or providers). When you do, those third parties are governed by their own privacy policies, not ours.
De-identified and Aggregated Data
We may share de-identified or aggregated data that cannot reasonably identify you with research partners, public health organisations, or for publication in health reports. We will not share identifiable health data for these purposes without your explicit consent.
12. How We Use Artificial Intelligence
Kinga Care uses artificial intelligence and machine learning to enhance your health experience. This section describes how we use AI responsibly.
How Our AI Tools Help
- Calculate your Longevity Score and identify health risk factors based on your profile and health data
- Suggest care programmes, lifestyle changes, and specialist referrals matched to your needs
- Analyse patterns in health metrics (such as vitals trends or activity levels) to provide actionable insights
- Improve care workflow efficiency for Clinic Users
Transfer of user data to third-party AI services
Our application does not transfer Google Workspace or Google Photos user data (raw, aggregated, or derived) to any third-party AI/ML services. We also do not use Google user data to train, fine-tune, or otherwise improve any machine learning or artificial intelligence models.
Google Workspace data accessed by our application (for example, Google Calendar data via OAuth) is used only to provide the user-facing calendar sync and related product functionality, in accordance with the Google Workspace API User Data and Developer Policy, including Limited Use requirements.
AI Transparency and Safeguards
- Our AI tools do not make clinical diagnoses and cannot replace the judgment of a qualified healthcare professional. AI-generated insights are intended to support—not substitute—clinical decision-making.
- Recommendations supported by AI are subject to human oversight by clinicians and care coordinators where appropriate.
- Personal data used by AI systems is processed in accordance with your consent, the privacy protections described in this policy, and applicable security safeguards.
- You may opt out of AI-based personalisation in certain features where an opt-out is available, though this may limit some functionality.
- AI will not be used to discriminate against, unfairly target, or harm users.
We are committed to ongoing monitoring and evaluation of our AI systems to ensure they remain fair, accurate, and aligned with ethical standards in health and wellness.
13. Cookies and Similar Technologies
When you access our website or web-based Services, we and our service providers may use cookies and similar technologies to collect Usage Data automatically.
Types of Technologies We Use
Essential cookies
Enable core functionality such as authentication, session management, and security. The Services may not function properly without these.
Preference cookies
Remember your settings and choices (such as language or display preferences).
Analytics cookies
Help us understand how users interact with the Services so we can improve performance and usability.
Local storage and IndexedDB
Cache calendar events and application data locally in your browser for faster loading and offline access.
Managing Cookies
When you access our website or web-based Services, we and our service providers may use cookies and similar technologies to collect Usage Data automatically.
- View cookies stored on your device
- Delete existing cookies
- Block all or certain types of cookies
- Set your browser to notify you when cookies are placed
If you disable or delete cookies, some features of the Services may not work as intended—for example, you may need to sign in again, or calendar data may not load from local cache.
This section describes cookies used by Kinga Care only. Third-party services integrated into the Services (such as Google authentication) may use their own cookies governed by their respective privacy policies.
We do not use third-party advertising cookies or sell Usage Data to advertisers.
14. Data Security
We implement technical and organisational measures designed to protect the personal and health data we collect and process, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Access controls limiting data access to authorised personnel on a need-to-know basis
- Role-based permissions within Shifa workspaces, ensuring Clinic Users see only the data required for their role
- Audit logging of access to sensitive clinical records
- Secure authentication, including OAuth-based sign-in and hashed password storage
- Regular security reviews and vulnerability assessments
- Staff training on data protection and confidentiality obligations
- Incident response procedures to detect, contain, and notify affected parties of data breaches as required by law
Our platform is designed with healthcare-grade security practices appropriate for processing sensitive health information. However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
If you believe your account has been compromised, please contact us immediately at privacy@kinga.care.
15. Data Retention
We retain Personal Data for as long as necessary to fulfil the purposes for which it was collected, including to:
- Provide the Services and maintain your account
- Meet legal, regulatory, and medical record-keeping requirements under Kenyan law
- Resolve disputes and enforce our agreements
- Comply with audit, tax, and accounting obligations
Factors We Consider
We retain Personal Data for as long as necessary to fulfil the purposes for which it was collected, including to:
- Deliver chronic care and longevity programmes tailored to your health profile
- Generate AI-assisted health insights, including your Longevity Score and risk assessments
- Send health alerts, appointment reminders, and care programme updates via SMS, WhatsApp, email, or in-app notifications
Calendar and Scheduling
- The nature and sensitivity of the data
- The purposes for which we process it
- Whether we can achieve those purposes through other means
- Applicable legal retention requirements (including medical record retention periods)
- The potential risk of harm from unauthorised use or disclosure
Deletion and Anonymisation
When we no longer need Personal Data, we will delete it or anonymise it so it can no longer be associated with you. If deletion is not immediately possible (for example, because data resides in backup archives), we will isolate it from further processing and apply security safeguards until deletion is feasible.
Upon account termination or a valid Forget Me request, we will delete or anonymise your data within a reasonable timeframe, subject to legal retention requirements for medical records.
16. International Data Transfers
Your information may be stored and processed in countries outside the Republic of Kenya, including countries where our cloud hosting providers or technology partners maintain facilities.
When we transfer Personal Data internationally, we ensure compliance with the Kenya Data Protection Act, 2019, and the Data Protection (General) Regulations, 2021, by:
- Transferring data only to countries or organisations that maintain adequate data protection standards, as recognised by the ODPC; or
- Implementing appropriate safeguards, such as data transfer agreements or standard contractual clauses, to ensure your information receives equivalent protection.
17. Your Privacy Rights
Under the Kenya Data Protection Act, 2019, you have the following rights in relation to your Personal Data:
Right of access
Request a copy of the Personal Data we hold about you.
Right to rectification
Request correction of inaccurate or incomplete Personal Data.
Right to erasure
Request deletion of your Personal Data.
Right to data portability
Request an electronic copy of Personal Data you have provided to us, in a structured, commonly used format.
Right to restriction
Request that we limit how we use your Personal Data in certain circumstances.
Right to object
Object to processing based on our legitimate interests or for direct marketing purposes.
Right to withdraw consent
Withdraw any consent you have previously given, where processing is based on consent.
Right regarding automated decision-making
Request human review of decisions made solely by automated means that significantly affect you.
How to Exercise Your Rights
To submit a request, contact us at privacy@kinga.care. We will respond within the timeframe required by applicable law (generally within 30 days).
We may need to verify your identity before processing your request. In some cases, we may be unable to fulfil a request where we have a valid legal reason to retain the data (for example, medical record retention requirements).
Clinic Users and administrators can manage many account settings and patient records directly within the Shifa platform.
Complaints to the ODPC
If you are not satisfied with how we handle your data or respond to your request, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the supervisory authority for data protection in Kenya:
18. Forget Me / Account Deletion
In compliance with the Data Protection Act, 2019, you may request that we terminate your account and delete your Personal Data.
How to Request Deletion
Send a deletion request to privacy@kinga.care with the subject line "Forget Me Request" and include:
- Your full name
- The email address or phone number associated with your account
- A brief statement that you wish to delete your account and associated data
We will verify your identity before processing the request.
What Happens When You Request Deletion
Upon verification, we will:
- Deactivate your account and revoke access to the Services
- Delete or anonymise Personal Data that we are not legally required to retain
- Disconnect any third-party integrations (such as Google Calendar) associated with your account
- Confirm deletion in writing within a reasonable timeframe
Exceptions
We may retain certain information where required or permitted by law, including:
- Medical records that must be retained under Kenyan health regulations
- Data necessary to resolve ongoing disputes or enforce our agreements
- De-identified or aggregated data that can no longer identify you
- Information held in backup systems until those backups are rotated and deleted
19. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data directly from children without appropriate parental or guardian consent.
If you are a parent or guardian and believe your child has provided us with Personal Data without your consent, please contact us at privacy@kinga.care. If we become aware that we have collected Personal Data from a minor without appropriate consent, we will take steps to delete that information promptly.
20. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services we offer.
When we make material changes, we will notify you by:
- Posting the updated policy on our website with a revised "Last Updated" date
- Sending an email or in-app notification for significant changes
We encourage you to review this policy periodically. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
CONTACT US
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
- Kinga Care — Data Protection
- Email: privacy@kinga.care
- Website: www.kinga.care
For general support inquiries unrelated to privacy, you may also reach us through the contact options available on our website.