Loading…
Loading…
How we collect, use, and protect your personal data
Lymph & Pelvic Care Kenya Limited ("we", "us", "our", or "the Clinic") is a specialist physiotherapy clinic in Parklands, Nairobi. We have been treating pelvic health, lymphatic, and post-cancer conditions since 2003.
This Privacy Policy explains how we collect, use, share, and protect personal data when you visit lymphpelviccare.com (the "Site"), book an appointment, or otherwise interact with us. It is written to comply with the Kenya Data Protection Act 2019 (the "KDPA") and the Data Protection (General) Regulations 2021. Where you reach us from outside Kenya, we apply equivalent protections under the EU General Data Protection Regulation (GDPR).
By using our Site or services, you confirm you have read and understood this Policy.
The Data Controller for personal data processed via this Site is:
Lymph & Pelvic Care Kenya Limited
Park Medical Centre, Opposite Aga Khan Hospital
3rd Parklands, 2nd Floor, Room 205
Nairobi, Kenya
Email: info@lymphpelviccare.com
Phone: +254 743 669 653 / +254 722 356 053
ODPC Registration Number: [VERIFY WITH LEGAL — pending registration confirmation]
Data Protection Officer (DPO): For questions about your data or this Policy, contact us at info@lymphpelviccare.com. [VERIFY WITH LEGAL — formal DPO appointment pending]
When you complete the booking form on our Site, we collect:
When you contact us via the contact form, email, phone, or WhatsApp, we collect the contact details and message content you share.
When you visit the Site we collect technical information through standard server logs and (with your consent) analytics tools, including:
Health information shared during booking, contact, or treatment is "sensitive personal data" under KDPA Section 25. We process this category only with your explicit consent or where a legal basis under KDPA Section 30 applies (for example, the provision of healthcare).
We do not knowingly collect data from children under 18 via the Site without parental or guardian consent. Paediatric patients are treated with the consent and presence of a parent or legal guardian; their treatment records are governed by clinic policy rather than this Site Privacy Policy.
We rely on the following lawful bases under KDPA Section 30 and, where applicable, GDPR Article 6:
| Purpose | Lawful basis |
|---|---|
| Responding to your booking or enquiry | Performance of a contract or steps prior to entering one (KDPA s.30(b)) |
| Providing physiotherapy treatment | Provision of healthcare under explicit consent (KDPA s.30(d), s.32) |
| Sending appointment reminders | Performance of a contract |
| Site analytics (with consent) | Consent (KDPA s.30(a)) |
| Marketing communications (with consent) | Consent (KDPA s.30(a)) |
| Complying with legal obligations (records retention, regulatory reporting) | Legal obligation (KDPA s.30(c)) |
| Protecting Site security and detecting misuse | Legitimate interests (KDPA s.30(f)) |
We use your personal data to:
We share personal data only where necessary and with the following categories of recipients:
The clinical staff treating you (named physiotherapist, supporting clinical team) access your data on a need-to-know basis to provide care.
We use third-party services to operate the Site and clinic. Each is bound by a data processing agreement (where required):
Where you ask us to bill an insurer or refer you to another medical practitioner, we share the minimum necessary data with that party with your consent.
Where required by law, court order, or to protect our or others' rights, life, or property, we may disclose data to the Office of the Data Protection Commissioner (ODPC), the Kenya Medical Practitioners and Dentists Council (KMPDC), tax authorities, or law enforcement.
We do not sell, rent, or trade your personal data to third parties for their own marketing.
Some of our service providers (e.g. Vercel, Resend, Cal.com) are based outside Kenya. When personal data is transferred outside Kenya, we apply safeguards under KDPA Section 49, which may include:
You can ask us for a copy of the safeguards in place by contacting info@lymphpelviccare.com.
| Data type | Retention period |
|---|---|
| Booking enquiry that does not lead to treatment | 12 months from last contact |
| Treatment and clinical records | 7 years from last treatment (per KMPDC guidance) or longer where law requires |
| Marketing contact list | Until you withdraw consent |
| Site analytics (aggregate) | 24 months |
| Web server logs | 90 days |
| Tax and accounting records | 7 years (Kenya Tax Procedures Act) |
After these periods we securely delete or irreversibly anonymise the data.
Under KDPA Section 26 you have the right to:
To exercise any of these rights, email info@lymphpelviccare.com. We will respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya:
Office of the Data Protection Commissioner
Britam Tower, Hospital Road, Upper Hill
Nairobi, Kenya
Email: info@odpc.go.ke
Website: www.odpc.go.ke
We use cookies and similar technologies to operate the Site and (with your consent) to understand how it is used.
We group cookies into three categories:
You can change your cookie preferences at any time by clicking "Cookie preferences" in the Site footer.
We protect your personal data with appropriate technical and organisational measures, including:
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ODPC within 72 hours of becoming aware, and we will inform you without undue delay where the breach is high risk, in accordance with KDPA Section 43.
We treat patients of all ages, including paediatric patients. Treatment of children is provided only with the consent and presence of a parent or legal guardian. The Site is not directed at children under 18 without parental supervision; if you are under 18 please ask a parent or guardian to interact with the Site on your behalf for booking purposes.
We may update this Policy from time to time. The "Last Updated" date at the top of the page tells you when. Where changes are material — for example, new categories of data, new processors, or changes to the legal basis — we will tell you by email (where we hold one) or by a prominent notice on the Site before the change takes effect. The cookie consent banner will also re-prompt where the analytics or marketing categories meaningfully change.
If you have questions about this Policy or how we handle your data:
Email: info@lymphpelviccare.com
Phone: +254 743 669 653 / +254 722 356 053
Post: Park Medical Centre, Opposite Aga Khan Hospital, 3rd Parklands, 2nd Floor, Room 205, Nairobi, Kenya
— Lymph & Pelvic Care Kenya Limited