Privacy Policy
How Afya Rejeshi collects, uses, and protects your personal and health information.
Last updated: July 2026
1. Data Controller
Afya Rejeshi is a digital mental health platform operated under the laws of Kenya. We are the data controller for the personal data we collect through this platform, as defined under the Kenya Data Protection Act, 2019 (KDPA).
2. Information We Collect
2.1 Information you provide
- Identity information: Full name, date of birth, national ID or service number, gender, and contact details (phone number, email address).
- Professional information (providers): Professional title, license number, licensing body (CPB or KMPDC), specializations, and institutional affiliation.
- Organization information: Organization name, type, registration number, county, and administrator details.
- Health information: Mental health screening responses, session notes written by your practitioner, and emergency contact details.
- Consent records: Your consent choices and timestamps.
2.2 Information collected automatically
- Authentication data: Login method, session tokens, and authentication timestamps.
- Usage data: Pages visited, features used, and interaction patterns (collected in aggregate).
- Device information: Browser type, operating system, and device identifiers necessary for platform functionality.
3. Sensitive Personal Data
Mental health information is classified as sensitive personal data under Section 44 of the KDPA. We process this data only with your explicit consent, which you provide during onboarding. You may withdraw consent at any time (see Section 8).
4. How We Use Your Information
We use your personal data for the following purposes:
- Providing care: Connecting you with mental health professionals, facilitating chat-based counseling sessions, and maintaining session notes for continuity of care.
- Health education: Delivering curated mental health information relevant to your context.
- Screening and assessment: Administering validated mental health screening tools (practitioner-facing) to support clinical decision-making.
- Platform operations: Managing your account, processing institutional enrollment, and providing technical support.
- Safety: Responding to crisis situations, including PHQ-9 Item 9 elevated responses, as required by our duty of care.
- Compliance: Meeting our obligations under Kenyan law, including the KDPA, Health Act 2017, and Mental Health Act 2022.
5. Chat Confidentiality and Ephemeral Messaging
Counseling sessions on Afya Rejeshi use ephemeral messaging. Chat messages between you and your psychologist are deleted when the session ends. Only the practitioner's session summary notes are retained as part of your care record.
This design protects your privacy by ensuring that sensitive conversations are not stored indefinitely, while maintaining the clinical documentation required for continuity of care.
6. Confidentiality and Its Limits
Your mental health information is treated as strictly confidential. Under Section 18 of the Mental Health Act, 2022, confidentiality may only be breached in the following circumstances:
- You pose an imminent risk of serious harm to yourself or others.
- Disclosure is required by a court order.
- Disclosure is necessary to protect a child or vulnerable person from abuse or neglect.
Your mental health records are separated from employment-accessible health data. Your employer, commanding officer, school administration, or any non-clinical party cannot access your records through this platform.
7. Data Retention
Health records are retained for a minimum of 10 years from the date of the last entry, as required by Section 101 of the Health Act, 2017. After this period, records are securely deleted unless a longer retention period is required by law.
Account and identity information is retained for as long as your account is active. If you request account deletion, your identity data will be removed, but anonymized clinical records may be retained to meet the statutory retention period.
8. Your Rights Under the KDPA
Under Sections 26–31 of the Kenya Data Protection Act, 2019, you have the following rights:
- Right of access (s.26): Request a copy of all personal data we hold about you.
- Right to rectification (s.27): Correct any inaccurate or incomplete personal data.
- Right to deletion (s.28): Request deletion of your personal data, subject to legal retention requirements.
- Right to restrict processing (s.29): Limit how we use your data in certain circumstances.
- Right to data portability (s.30): Receive your data in a structured, machine-readable format.
- Right to object (s.31): Object to processing of your data for specific purposes.
- Right to withdraw consent: Withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at the details provided in Section 12. We will respond within 30 days of receiving your request.
9. Data Security
We protect your data through:
- End-to-end encryption for counseling sessions.
- Encryption at rest for all stored personal data.
- Role-based access controls ensuring only authorized personnel can access your data.
- Audit logging of all data access events.
- Regular security assessments and vulnerability testing.
10. Data Sharing
We do not sell, rent, or trade your personal data. We may share data only in the following circumstances:
- With your care team: Psychologists and psychiatrists assigned to your care can access your session notes and screening results.
- Institutional reporting: Organizations that enrolled you may receive aggregate, de-identified mental health statistics. They never receive individual client data.
- Technology service providers: Vetted processors that operate the platform under contract and may use your data only to provide services to us. These are Google Firebase (sign-in, database, hosting, and product-usage analytics) and Sentry (error and performance monitoring). Our error-monitoring provider receives only anonymised technical fault data, never your name, contact details, or health information.
- Legal requirements: When required by Kenyan law or court order.
- Crisis response: When there is an imminent risk of serious harm, as outlined in Section 6.
International data transfers: Some of our service providers store or process data on servers outside Kenya, including in the European Union and the United States. Where data is transferred outside Kenya, we rely on appropriate safeguards required by Sections 48–49 of the Kenya Data Protection Act, 2019, including contractual data-protection commitments from each provider.
11. Children and Minors
Under the Kenya Data Protection Act, 2019 (Section 33), processing personal data of a child (under 18) requires the consent of a parent or guardian. The following additional safeguards apply:
- Guardian consent required: A parent or legal guardian must provide explicit, informed consent before any data is collected or services are activated for a minor.
- Granular consent: Guardians consent separately for each service type (screening, counseling, data sharing). Consent can be withdrawn per service at any time.
- Session confidentiality: In accordance with the Mental Health Act, 2022 and professional ethics, chat counseling sessions between a minor and their practitioner are confidential. Parents and guardians cannot read session content. Practitioners may share care summaries with guardians to support the child's wellbeing at home.
- Mandatory disclosure: Confidentiality may be breached when the minor poses an imminent risk of serious harm to themselves or others, when disclosure is required by court order, or when necessary to protect the child from abuse or neglect.
- Age-based permissions: As minors grow, their autonomy on the platform increases. At age 18, the account transitions to a full adult account and guardian oversight is removed.
- Data retention: Health records for minors are retained until the patient reaches age 25 or 10 years after last treatment, whichever is longer, per Section 101 of the Health Act, 2017. At age 18, record control transfers to the now-adult user.
- Data minimisation: We collect only the minimum data necessary for the consented services. Default privacy settings for minor accounts are set to the highest restriction level.
12. Contact Us
If you have questions about this privacy policy or wish to exercise your data protection rights, contact us:
- Email: info@afyarejeshi.com
- Data Protection Officer: info@afyarejeshi.com
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated.
13. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated through the platform before they take effect. Your continued use of the platform after changes are published constitutes acceptance of the updated policy.