Privacy Policy

Privacy Policy

1. Introduction

Co-create Health Limited (“Co-create Health”, “we”, “us”, or “our”) is a digital health solutions company based in Africa, serving healthcare businesses, professionals, and patients through innovative technology platforms. Our official website is https://cocreatehealthafrica.com.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you interact with Co-create Health Limited, our websites, products, platforms, and services, including:

  1. Medics Pathway (https://medicspathway.com) – an eLearning and knowledge management platform.
  2. CarePro AI – a cloud-based electronic health records system
  3. CareMap 360 (https://caremap360.com) – a healthcare directory for patients to find hospitals and doctors.
  4. Custom healthcare applications and web development services.
  5. Healthcare EdTech solutions.

We are committed to protecting privacy and handling personal data in a transparent and secure manner, in compliance with applicable data protection laws, including the Kenya Data Protection Act, 2019, and other relevant international data protection principles.

2. Scope of this policy

This Privacy Policy applies to:

  1. Visitors to our websites.
  2. Healthcare institutions and organizations using our products.
  3. Healthcare professionals registered on our platforms.
  4. Patients and members of the public using CareMap 360 or interacting with our services
  5. Clients engaging us for custom healthcare software, web development, or EdTech solutions

3. Information we collect

3.1 Personal Information

We may collect the following personal information depending on how you interact with our services:

  1. Full name.
  2. Email address.
  3. Phone number.
  4. Professional details (such as profession, specialization, registration number, or employer).
  5. Organization or facility details.
  6. Login credentials and account information.
  7. Billing and payment-related information.
  8. Communication preferences.

3.2 Health and sensitive data

For certain services, particularly CarePro AI, we may process sensitive personal data, including health information, on behalf of healthcare providers. Such data may include:

  1. Patient demographic information.
  2. Medical records and clinical notes.
  3. Laboratory results and prescriptions.
  4. Appointment and treatment histories.

We process health data strictly as a data processor, following the instructions of the healthcare provider who is the data controller.

3.3 Technical and usage data

We automatically collect certain technical information when you use our platforms:

  1. IP address.
  2. Device and browser information.
  3. Operating system.
  4. Log files and access times.
  5. Usage patterns and interactions with our platforms.
  6. Cookies and similar tracking technologies.

4. How we collect information

We collect information through:

  1. Account registration and onboarding forms.
  2. Use of our platforms and services.
  3. Direct communication via email, phone, or contact forms.
  4. Subscription, licensing, and contractual engagements.
  5. Cookies and automated technologies.
  6. Third-party integrations authorized by you.

5. Purpose of data collection and processing

We use personal data for the following purposes:

  • To provide, operate, and maintain our platforms and services.
  • To create and manage user accounts.
  • To deliver eLearning, knowledge management, and healthcare IT services.
  • To support electronic health record functionality for healthcare providers.
  • To enable patients to discover healthcare providers through CareMap 360.
  • To process payments and manage subscriptions.
  • To communicate updates, service notices, and support responses.
  • To improve system performance, usability, and security.
  • To comply with legal, regulatory, and contractual obligations.

6. Legal basis for processing

We process personal data based on one or more of the following legal grounds:

  • Consent from the data subject.
  • Performance of a contract.
  • Compliance with legal obligations.
  • Legitimate interests pursued by Co-create Health, provided such interests do not override individual rights.
  • Processing necessary for medical or healthcare purposes where permitted by law.

7. Cookies and tracking technologies

Our websites and platforms use cookies and similar technologies to:

  • Ensure proper functionality of services.
  • Improve user experience.
  • Analyze usage and performance.
  • Enhance security.

You may manage or disable cookies through your browser settings. Disabling cookies may affect the functionality of some services.

8. Data sharing and disclosure

We do not sell personal data. We may share information only in the following circumstances:

  1. With authorized employees and contractors bound by confidentiality obligations.
  2. With service providers and technology partners who support our operations.
  3. With healthcare institutions who control patient data processed through CarePro AI.
  4. With regulatory authorities where required by law.
  5. In connection with mergers, acquisitions, or restructuring, subject to confidentiality safeguards.

All third parties are required to implement appropriate data protection and security measures.

9. Data storage and security

We implement appropriate technical and organizational measures to protect personal data, including:

  1. Encryption of data in transit and at rest.
  2. Role-based access controls.
  3. Secure cloud infrastructure.
  4. Regular system monitoring and updates.
  5. Data minimization and access logging.

Despite our efforts, no system is completely secure, and we cannot guarantee absolute security of data.

10. Data retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

Patient health data processed through CarePro AI is retained according to contractual agreements with healthcare providers and applicable healthcare regulations.

11. International data transfers

Where personal data is transferred outside your country of residence, we ensure appropriate safeguards are in place to protect the data in accordance with applicable laws.

12. Your rights

Subject to applicable law, you have the right to:

  • Access your personal data.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your personal data.
  • Object to or restrict certain processing activities.
  • Withdraw consent where processing is based on consent.
  • Request data portability where applicable.

Requests can be made by contacting us using the details provided below.

13. Responsibilities of healthcare providers

Healthcare providers using CarePro AI are responsible for:

  • Obtaining lawful consent from patients.
  • Providing patients with appropriate privacy notices.
  • Ensuring accuracy and lawful use of patient data.
  • omplying with applicable healthcare and data protection laws.

14. Children’s privacy

Our services are not intended for children without the involvement of a parent, guardian, or authorized healthcare provider. We do not knowingly collect personal data from children without appropriate authorization.

15. Third-party links and integrations

Our platforms may contain links to third-party websites or services. We are not responsible for the privacy practices of such third parties, and we encourage users to review their privacy policies.

16. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Updated versions will be posted on our websites with a revised effective date.

17. Contact information

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle personal data, please contact:

  1. Co-create Health Limited, Website: https://cocreatehealthafrica.com
  2. Email: info@cocreatehealthafrica.com

By using our websites and services, you acknowledge that you have read and understood this Privacy Policy.