1. Introduction
AAR Health Care (Kenya) Limited ("Company," "we," "our," or "us") is a healthcare service provider in Kenya committed to protecting patient confidentiality and data privacy. This Privacy Policy outlines our practices for collecting, using, protecting, and managing personal data, in line with Kenya’s Data Protection Act (2019), the Healthcare Act, and applicable industry standards.
This policy applies to personal data from patients, employees, contractors, business partners, and any other persons interacting with AAR Healthcare. It governs the handling of Personal Identifiable Information (PII) and Personal Health Information (PHI) to ensure safe, lawful, and high-quality healthcare services.
2. What Data We Collect
2.1 Personal Identifiable Information (PII)
Personal Identifiable Information (also referred to as personal data in this policy) means any information relating to an identified or identifiable natural person (the data subject). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location information, an online identifier or by one or more factors specific to the physical, psychological, genetic, mental, economic, cultural or social identity of the natural person.
2.2 Personal Health Information (PHI)
We collect and maintain various types of personal information, including PHI, which may include your name, date of birth, contact information, medical records, treatment information, and insurance details. This information is collected when you visit our clinics, communicate with healthcare providers, or use our online services.
2.3 Non-Personal Information
We also collect non-personal data such as IP addresses, browser types, and general usage patterns when you visit our website. This data helps us improve our services and provide a better user experience.
3. Collection of Personal Data and Purpose of Processing
3.1 Medical Data
We collect health information, including medical history, demographic information, and contact details, primarily to ensure accurate diagnosis and treatment, facilitate healthcare services, and manage patient care effectively. This data is processed for purposes such as providing medical treatment, conducting health assessments, ensuring compliance with legal and regulatory requirements, and improving the quality of care through research and analysis.
3.2 Employment and HR Management
AAR Health Care (Kenya) Limited collects various types of personal data during employment application and onboarding, including basic contact details (name, address, phone, email), referee contact information, and nationality. Employment-specific details like national ID number, NSSF and NHIF numbers, KRA PIN, bank information, marital status, spouse and dependent information (including name, birth certificate, passport photos), and next of kin contacts are also gathered. Additionally, background and medical assessment information may be collected during recruitment, as allowed by law.
This data supports human resource functions, such as age verification, payroll processing, statutory deductions, benefits administration, and compliance with employment laws.
3.3 Business Partners
For all counterparties doing business with us, we collect information that might be PII in nature. This could be personal email addresses provided in the course of communications and names and contacts of company representatives. Information collected through these processes is only used for disinfection activities in outpatient centres, formalizing institution rescue services agreements and supplier onboarding procedures.
To ensure we do business with reputable, honest and qualified business partners, we may also conduct due diligence checks on companies and their directors and shareholders to establish the legal status of all potential new business partners and evaluate whether they may be involved in illegal or corrupt practices. Such checks may include the collection of personal identification documents for such directors and shareholders.
3.4 Information Provided Through Our Security Procedures
As part of our security procedures, we obtain information from our visitors. This information may include CCTV footage. Such information is only processed for purposes of security and monitoring.
3.5 Information You Provide Through Our Website
We may collect information you provide through our web-based enquiries, appointment bookings and registration of white members. This includes your name, age, gender, physical and postal address details, national ID number, phone number, blood group, medical report, email address and functionality cookies. This information is only processed for registering and managing patients, administrative purposes, determination of blood group and user preferences.
3.6 Others Who May Get in Touch With Us
We collect personal data when an individual gets in touch with us with a question, complaint, comment or feedback, such as their name, contact details and the content of the communication. We will only use this data to respond to the communication and handle the matter.
4. Use of Personal Information
4.1 For Provision of Healthcare Services
We use medical data primarily to deliver effective patient care, including diagnosing conditions, developing treatment plans, and monitoring health outcomes. Additionally, this data aids in ensuring compliance with regulatory requirements, conducting medical research, improving healthcare services, and enhancing operational efficiency.
4.2 For Business Use
We use your personal information to facilitate our ongoing and proposed business dealings with you. This includes:
- Processing business transactions with us;
- Communicating with you about updates to our services; and
- Responding to questions, inquiries or complaints about our services.
We may use your personal information as required for us to comply with relevant laws and regulations relating to our business.
4.3 Marketing
With your consent or as otherwise permitted by applicable law, we may use your personal information for purposes relating to the marketing of our services. We may:
- Send you newsletters, press releases, event announcements and similar communications regarding our services;
- Market or promote our services to you;
- Solicit your input regarding improvement of our services; and
- Use your personal information for other purposes disclosed when we obtain your consent.
You may opt out of marketing-related communication at any time by contacting us at dpo@aar-healthcare.com.
4.4 Employment
As permitted by applicable laws, we maintain employment records of current and former employees. For current employees, we use personal information for human resource management, determination of employee age, processing statutory deductions, tax compliance, payroll processing, employee benefits, alternative points of contact, pre-employment medical assessments and recruitment.
For former employees, we archive records and only use them on a lawful basis as permitted by law. After the required retention period, in line with the Income Tax Act and Companies Act, the records are destroyed.
4.5 Recruitment
We may use personal information provided through email solely to process your application for a position in which you have shown interest, in accordance with this privacy notice and applicable law. This may include data collected from third parties, such as references, prior employers and educational history, to identify and evaluate candidates. We may conduct vetting for specific roles, including background checks as permitted by local laws. With your consent, we may retain your application and references for one year or six months after the role is filled.
5. Personal Data Integrity
While you are responsible for the accuracy of all personal information that you provide to us, we will use reasonable efforts to maintain its accuracy and integrity and update it as appropriate. We will take reasonable steps to ensure that the personal information we collect from you is relevant to its intended use and is used only in ways compatible with the purposes for which it was collected or otherwise authorized by you.
6. Data Sharing
6.1 Internal Use
Personal data may be shared within AAR Health Care (Kenya) Limited for necessary operational purposes. If data must be transferred outside Kenya, we ensure compliance with local data protection laws, including:
- The appropriateness of data protection safeguards during transfer;
- Whether the destination country ensures an adequate level of protection;
- Whether the transfer is necessary and approved by the Office of the Data Protection Commissioner; or
- Whether you have consented to the transfer.
6.2 External Use
We may share information with external partners such as legal advisors, auditors, service providers, insurance providers, and pension administrators to support operational needs. Before sharing, we formalize agreements with these entities to ensure compliance with this policy and adequate data safeguards.
6.3 Legal and Regulatory Disclosures
We may access, use, and disclose data to comply with applicable laws, respond to legal processes, protect the security and rights of AAR Health Care (Kenya) Limited and third parties, prevent fraud, and address security risks.
7. Protection of Personal Information
At AAR Healthcare, we implement robust safeguards and measures that adhere to internationally recognized information security standards to protect your personal information from misuse, unauthorized access, disclosure, alteration, destruction, or loss. Our framework includes comprehensive policies, procedures, and training programs focused on data protection, confidentiality, and security.
We take special precautions to safeguard particularly sensitive information, especially data classified as sensitive under applicable data protection laws.
While we are committed to ensuring the security of your personal information, we cannot warrant or guarantee that this information will be protected under all circumstances, including those beyond our reasonable control.
8. Website Cookies
When you visit our website, we collect cookies to enhance user experience, monitor website traffic, and analyze browsing behavior. These cookies may include information about your preferences, session data, and activity on the site. You can manage cookie preferences through your browser settings, but disabling cookies may limit your ability to use certain website features.
9. Online Telemedicine Services
In providing online telemedicine services, we may collect personal information, such as health-related data, contact details, and other necessary information, to facilitate healthcare services. This data is collected securely, processed in line with applicable healthcare privacy regulations, and used solely for medical consultation and care delivery purposes.
10. Use of Third-Party Digital Services
To support service delivery and protect the confidentiality, integrity, availability, and security of personal information, we may use carefully selected third-party software, cloud-based platforms, and technology service providers. These services may facilitate secure communication, document creation and storage, document conversion, encryption, password protection, digital signing, collaboration, virtual meetings, electronic mail, secure file sharing, backup, disaster recovery, and other business operations.
Examples may include secure cloud storage platforms, productivity and collaboration suites, document processing applications, communication platforms, and other technologies that help us provide services efficiently and securely.
Before adopting a third-party service that processes personal information, we conduct a risk-based assessment of its security, privacy, legal, and operational controls. Where appropriate, we also assess compliance with applicable data protection laws and internationally recognized information security standards.
When selecting and managing third-party service providers, we consider whether they:
- Implement appropriate technical and organizational measures against unauthorized access, disclosure, alteration, loss, or destruction;
- Use industry-standard encryption and secure communication protocols for data in transit and, where applicable, at rest;
- Maintain appropriate authentication, access control, monitoring, logging, backup, and recovery capabilities;
- Maintain documented data-retention and secure-deletion practices appropriate to the services provided;
- Provide contractual commitments regarding confidentiality, privacy, and security where applicable;
- Maintain recognized information-security certifications or demonstrate compliance with internationally accepted frameworks, where appropriate; and
- Support compliance with applicable data-protection and privacy laws.
11. Data Retention
We will not retain personal information longer than necessary for the purposes for which it was collected, except where retention is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims. We have developed an internal data-retention policy guided by applicable laws.
12. Access, Objection to Processing, Rectification and Data Erasure
To request access to your data, object to processing, or request rectification or erasure, contact us at dpo@aar-healthcare.com.
Employees may communicate requests through the Human Resources department or write to allhrkenya@aar-healthcare.com.
13. Monitoring and Enforcing This Policy
We will conduct periodic internal compliance audits and assessments of our relevant privacy practices to verify adherence to this Privacy Policy.
14. Policy Revision
This Privacy Policy is kept under regular review and is therefore subject to change.
15. Our Contacts
AAR Health Care (Kenya) Limited,George Williamson House,
Fourth Ngong Avenue,
Nairobi, Kenya.
Tel: +254 709 701 000 | +254 730 701 000
