← Back to enrolment

Privacy policy

Effective date: 20 April 2026 · Public URL: https://healthconnect-api-production-a172.up.railway.app/privacy

1. Who this applies to

This policy describes how the organisation operating this Kareconnect service (“we”, “us”) handles personal information when you use our enrolment page, messaging channels (such as WhatsApp or SMS), and related tools. Your clinic or programme operator is responsible for configuring the system and for answering questions about your care.

2. What we collect

Depending on how you interact with the service, we may process:

3. Why we use it

We use this information to operate the programme you joined: send education and reminders, respond to help requests, manage enrolment (including pausing or resuming messages), and improve reliability and safety of the platform. Automated decisions are limited to scripted messaging flows configured by your operator; clinical decisions remain with qualified professionals.

4. Legal bases

Where applicable law requires a “legal basis”, we rely on your consent when you actively enrol or text join keywords, and on legitimate interests of the operator in delivering contracted health information services, subject to your rights and any stricter rules your jurisdiction imposes.

5. Messaging providers (processors)

Delivery of WhatsApp or SMS may use third-party gateways configured by the operator, for example Meta (WhatsApp Cloud API), Twilio, or Africa’s Talking. Those providers process message content and phone numbers under their own terms and privacy policies. We only send what is needed to deliver the service.

6. Hosting & security

Data is stored on systems chosen by the operator (for example a secured cloud database). We use industry-standard protections such as encrypted transport (HTTPS), access controls for administrative accounts, and hashed passwords for admin access. No method of storage is perfectly secure; we work to reduce risk.

7. Retention

We keep data only as long as needed to run the programme and meet the operator’s legal or clinical record-keeping duties. Retention schedules are set by the operator; contact them if you need deletion or export where the law allows.

8. Your rights

Depending on your country, you may have rights to access, correct, delete, restrict, or object to certain processing, and to complain to a supervisory authority. Submit requests to the organisation that enrolled you or the contact they publish; we will assist the operator where we can.

9. International transfers

Cloud hosting or messaging providers may process data in countries other than yours. The operator is responsible for putting in place appropriate safeguards required by law.

10. Children

Programmes involving minors should be operated only with appropriate parental authority or professional duty of care. The operator is responsible for lawful enrolment of children.

11. Changes

We may update this policy when features or legal requirements change. The effective date at the top will be revised; material changes should be communicated by your operator where required.

12. Contact

For privacy questions, contact the health organisation or programme that directed you to Kareconnect. Technical operators may also publish a contact address in their deployment settings.