1. Introduction
AAR Health Care (Kenya) Limited (“Company,” “we,” “our,” or “us”) is a healthcare service provider in Kenya committed to protecting the privacy, confidentiality, and data protection rights of every patient, employee, contractor, business partner, and any other individual who interacts with us.
This Privacy Policy explains how we collect, use, disclose, transfer, retain, and protect personal data in compliance with Article 31 of the Constitution of Kenya, 2010, Kenya’s Data Protection Act (2019), The Health Act, 2017, The Digital Health Act, 2023, the Data Protection (General) Regulations, 2021, and applicable Kenyan law.
AAR Healthcare (Kenya) Limited is registered with the ODPC as a data controller and data processor.
2. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person, including a name, identification number, location data, an online identifier, or one or more factors that are specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
“Sensitive Personal Data” means data revealing a natural person’s race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (including the names of a person’s children, parents, spouse, or spouses), sex, or sexual orientation. Sensitive Personal Data expressly includes health data such as medical history, physical, or mental health status, diagnoses, treatment records, prescriptions, laboratory results, imaging, blood group, reproductive health information, and disability information.
“Personal Health Information” means the subset of Sensitive Personal Data relating to a data subject’s physical or mental health, and includes information specific to the provision of healthcare to that person.
“Data Controller” means a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purpose and means of processing personal data.
“Data Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of a data controller.
“Data Subject” means an identified or identifiable natural personal whose personal data we process.
“Processing” means any operation performed on personal data including collection, recording, organization, storage, use, disclosure, transfer, or destruction.
“Consent” means any freely given, specific, informed, and unambiguous indication of a data subject’s wishes by which they, by a statement or clear affirmative action, signify agreement to the processing of their personal data.
3. Scope
This policy applies to the Personal Data and Sensitive Personal Data of patients, employees, contractors, business partners, visitors, and any other data subject whose personal data we process in the course of our operations, regardless of whether that data is collected in person, online, by telephone, or through a third party.
4. Categories of Data We Collect
4.1. Patients
We collect both personal data and sensitive personal data. We collect this data for diagnosis, treatment, clinical care management, regulatory and statutory compliance reporting in line with the contract with the patient, vital interests during emergencies, and fulfilment of legal obligations.
We may process patient data for medical research and quality-of-care analysis. Where we process patient data we obtain consent and utilize anonymized data where applicable.
4.2. Employees and Contractors
Contact details, referee information, nationality, national ID number, NSSF and SHIF numbers, KRA PIN, bank details, marital status, spouse and dependent information, next of kin contacts, and background and pre-employment medical assessment information as permitted by law.
We collect this data for HR management, payroll, statutory deductions, and administration of benefits in line with contractual obligations and fulfilment of legal obligations.
4.3. Business Partners and Suppliers
We collect personal data of the directors, shareholders, and representatives of our business partners and suppliers. This information is collected and used for contract formation and management, supplier onboarding, and due-diligence checks to ensure we engage reputable qualified counterparts and fulfilment of legal obligations.
4.4. Security and Premises
We collect CCTV footage of visitors to our premises. This data is collected and processed solely for security and monitoring purposes in the legitimate interest of our operations.
4.5. Website and Digital Channels
Through our web-based enquiries, appointment bookings, and registration for our patient portal or loyalty programme, we collect name, age, gender, physical, and postal address, national ID number, phone number, email address, and functionality cookies, and where you choose to provide it, blood group and medical reports.
Where we may collect blood group and medical report information, we only process this information where you give explicit, separate consent at the point of submission. We apply enhanced security measures to it as described in Section 13 of this Privacy Policy.
4.6. Correspondence
We may collect name, contact details, and content of your question, complaint, comment, or feedback you send us. We use this information only to respond to and resolve that communication. We collect this information to legitimately handle complaints, respond to comments, and also address concerns.
4.7 Non-Personal Information
We also collect non-personal data such as IP addresses, browser types, and general usage patterns when you visit our website. This data helps us improve our services and provide a better user experience.
5. Processing of Sensitive Personal Data
Given the nature of healthcare services, we process significant volumes of Sensitive Personal Data including health data. We process Sensitive Personal Data only where at least one of the following conditions under Section 44 of the DPA 2019 is met;
- You have given your explicit consent to the processing;
- Processing is necessary for preventive or occupational medicine, medical diagnosis, the provision of health care or treatment, or the management of health-care systems, and is carried out by, or under the responsibility of, a health-care professional or another person subject to an equivalent duty of confidentiality;
- Processing is necessary to protect your vital interest, or those of another person, where you are physically or legally incapable of giving consent;
- Processing is necessary for compliance with a legal obligation to which we are subject, including public-health reporting obligations; or
- Processing is necessary for the establishment, exercise, or defence of a legal claim.
Where we process Sensitive Personal Data, we apply additional safeguards including restricted, need-to-know access, encryption, and enhanced audit logging.
6. Consent
Where we rely on your consent, we will ask for it clearly, specifically, and separately from other terms, before we process your personal data for that purpose.
You may withdraw your consent at any time by contacting our Data Protection Officer at dpo@aar-healthcare.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
In some cases, withdrawing consent may mean we are unable to continue providing certain services, for example, we cannot provide a diagnosis without processing the relevant health data.
7. Marketing Communications
With your consent, or as otherwise permitted by applicable law, we may send you newsletters, press releases, event announcements, appointment reminders, and similar communications by SMS, email, WhatsApp, or other channels, and may use your personal information to promote our services or seek your feedback.
You have an unconditional right to object to the processing of your personal data for direct marketing at any time, without needing to give a reason and free of charge. You may exercise this right by clicking “unsubscribe” on any marketing communication or by contacting dpo@aar-healthcare.com.
8. Children and Vulnerable Persons
Where we provide healthcare services to a person under the age of 18 (“a minor”), we process the minor’s personal data, including health data, on the basis of consent given by a parent or legal guardian.
Where we become aware of information suggesting a minor may be at risk of harm, we may process and share relevant personal data with the appropriate authorities or child-protection agencies in accordance with our safeguarding obligations, even without consent, to the extent necessary to protect the minor.
We apply equivalent care to the personal data of other vulnerable persons, including patients who lack capacity, by relying on the vital interest basis or the involvement of an authorized representative.
9. Emergency and Public Health Processing
In emergencies, including where a patient is unconscious or otherwise unable to give consent for data processing, we may process personal data, including Sensitive Personal Data, on the basis of the vital interests of the patient or another person, to the extent necessary to provide urgent treatment.
We may also process and disclose personal data without consent where required by law, including for mandatory public-health reporting (for example, notifiable diseases) under the Health Act, 2017 and related regulations.
10. Personal Data Integrity
While you are responsible for the accuracy of all personal information that you provide to us, we will use reasonable efforts to maintain its accuracy and integrity and update it as appropriate. We will take reasonable steps to ensure that the personal information we collect from you is relevant to its intended use and is used only in ways compatible with the purposes for which it was collected or otherwise authorized by you.
11. Data Sharing and Disclosure
11.1 Internal Sharing
Personal data may be shared within AAR Health Care (Kenya) Limited for necessary operational purposes.
11.2 Sharing with Independent Controllers
We share personal data with organizations that act as independent data controllers of the data we share with them. This means they determine their own purposes for processing it, including insurers, pension administrators, government health-financing and identity systems, regulators, professional advisers such as external legal counsel and auditors.
Where we share this data we share only what is necessary for the relevant purpose and, where feasible enter into information-sharing agreements with these recipients.
11.3 Sharing with Data Processors
We engage data processors including IT and cloud service providers, billing and collection agents, and outsourced laboratory or diagnostic providers, who process personal data solely on our documented instructions, under written data processing agreements that impose confidentiality, security, and sub-processing restrictions consistent with this Policy and a Data Processing Agreement.
11.4. Legal and Regulatory Disclosures
We may access, use, and disclose data to comply with applicable laws, respond to legal processes, protect the security and rights of AAR Health Care (Kenya) Limited and third parties, prevent fraud, and address security risks.
12. Cross-Border Data Transfers
We transfer personal data outside Kenya only where at least one of the following applies, applied in the order of preference set out in the Data Protection (General) Regulations, 2021;
- You have consented to the transfer of the data.
- The transfer is to a country, territory, or sector that the ODPC has confirmed has an adequate level of data protection.
- Appropriate safeguards are in place, such as binding corporate rules, standard contractual clauses, or a legally binding and enforceable instrument between public authorities.
- The transfer is necessary for one of the specific circumstances recognized under the DPA, including your explicit consent, the performance of a contract with you, or the establishment or defence of a legal claim.
- The transfer has been specifically approved by the ODPC.
We conduct a transfer impact assessment before adopting any new service that involves a cross-border transfer of personal data.
13. Protection of Personal Information
At AAR Healthcare, we implement robust safeguards and measures that adhere to internationally recognized information security standards to protect your personal information from misuse, unauthorized access, disclosure, alteration, destruction, or loss. Our framework includes comprehensive policies, procedures, technical and organizational measures, and training programs focused on data protection, confidentiality, and security.
We take special precautions to safeguard particularly sensitive information, especially data classified as sensitive under applicable data protection laws including access control, encryption, monitoring, and incident response training.
While we are committed to ensuring the security of your personal information, we cannot warrant or guarantee that this information will be protected under all circumstances, including those beyond our reasonable control.
14. Website, Cookies, and Tracking Technologies
When you visit our website, we use the following categories of cookies:
- Strictly necessary cookies, required for the website to function;
- Performance and analytics cookies, which help us understand how visitors use our website;
- Functionality cookies, which remember your preferences;
You can manage your cookie preferences through your browser settings. Disabling certain cookies may limit your ability to use some website features.
15. Online Telemedicine Services and Digital Health Services
In providing online telemedicine services, such as Dial-A-Doc, Dial-A-Lab/Dial-A-Dawa, and Wemakili, we may collect personal information, such as health-related data, contact details, and other necessary information, to facilitate healthcare services. This data is collected securely, processed in line with applicable healthcare privacy regulations, and used solely for medical consultation and care delivery purposes.
This data is transmitted and stored using encryption in transit and at rest, and is used solely for medical consultation and care delivery purposes.
Where the telemedicine platform is hosted or supported outside Kenya, the cross-border transfer safeguards in Section 12 apply.
16. Use of Third-Party Digital Services
To support service delivery and protect the confidentiality, integrity, availability, and security of personal information, we may use carefully selected third-party software, cloud-based platforms, and technology service providers. These services may facilitate secure communication, document creation and storage, document conversion, encryption, password protection, digital signing, collaboration, virtual meetings, electronic mail, secure file sharing, backup, disaster recovery, and other business operations.
Examples may include secure cloud storage platforms, productivity and collaboration suites, document processing applications, communication platforms, and other technologies that help us provide services efficiently and securely.
Before adopting a third-party service that processes personal information, we conduct a risk-based assessment of its security, privacy, legal, and operational controls. Where appropriate, we also assess compliance with applicable data protection laws and internationally recognized information security standards.
When selecting and managing third-party service providers, we consider whether they:
- Implement appropriate technical and organizational measures against unauthorized access, disclosure, alteration, loss, or destruction;
- Use industry-standard encryption and secure communication protocols for data in transit and, where applicable, at rest;
- Maintain appropriate authentication, access control, monitoring, logging, backup, and recovery capabilities;
- Maintain documented data-retention and secure-deletion practices appropriate to the services provided;
- Provide contractual commitments regarding confidentiality, privacy, and security where applicable;
- Maintain recognized information-security certifications or demonstrate compliance with internationally accepted frameworks, where appropriate; and
- Support compliance with applicable data-protection and privacy laws.
17. Automated Decision-Making and Artificial Intelligence
We may use automated systems or technologies to support certain decision-making processes. However, where a decision is made solely through automated processing and is likely to significantly affect you, appropriate safeguards will be implemented, including meaningful human review and intervention before the decision takes effect, where applicable.
You also have the right to object to or request not to be subject to certain forms of automated decision-making, including profiling, in accordance with applicable data protection laws. You may contact us to request human intervention, express your views, or challenge a decision made through automated processing.
18. Data Retention
We do not retain personal information longer than necessary for the purposes for which it was collected, except where retention is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims. Our principal retention periods are governed by an internal data-retention policy guided by applicable laws.
After the applicable retention period expires, personal data is securely destroyed, deleted, or anonymised, unless further retention is mandated by law or required for a legal claim.
19. Data Breach Notification
We maintain a comprehensive data breach management process. Where we become aware of a breach of personal data that is likely to result in a real risk of harm to the affected data subject(s), we will notify the ODPC within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, without undue delay, describing the nature of the breach, its likely consequences, and the measures we have taken or propose to take to address it.
We maintain an internal breach register and incident response plan to guide our response to any suspected or confirmed breach.
20. Your Rights as a Data Subject
Subject to the conditions and limitations set out in the DPA, you have the right to:
- Be informed of the use to which your personal data is to be put;
- Access your personal data in our custody;
- Request the correction or updating of inaccurate, out-of-date, incomplete, or misleading personal data;
- Object to the processing of all or part of your personal data;
- Request the restriction of processing of your personal data;
- Request the erasure of your personal data, subject to our legal and regulatory obligation to retain certain records. Where erasure is not immediately possible, we will explain why and, where applicable, restrict further processing of that data instead.
- Obtain your data in a shareable format where applicable and technically feasible.
- Withdraw consent at any time, where processing is based on consent;
- Not be subject to a decision based solely on automated processing.
- Lodge a complaint with the Office of the Data Protection Commissioner.
To exercise any of these rights, contact us at dpo@aar-healthcare.com
Employees may also raise requests through the Human Resources department. We will respond within the timeframe required by the DPA and its Regulations.
21. Governance
We have designated a Data Protection Officer (DPO) responsible for overseeing our compliance with the DPA and this Policy. You may contact our DPO at:
- Email: dpo@aar-healthcare.com
- Postal address: AAR Health Care (Kenya) Limited, George Williamson House, Fourth Ngong Avenue, Nairobi, Kenya
AAR Health Care (Kenya) Limited is registered with the ODPC as a data controller and data processor.
22. Monitoring and Enforcing This Policy
We conduct periodic internal compliance audits and assessments of our privacy practices to verify adherence to this Privacy Policy.
23. Policy Revision
This Privacy Policy is kept under regular review and is therefore subject to change. The effective date of this Policy indicates the version currently in force.
24. Our Contacts
AAR Health Care (Kenya) Limited,
George Williamson House,
Fourth Ngong Avenue,
Nairobi, Kenya.
Tel: +254 709 701 000 | +254 730 701 000
