Skip to content
AfriHealthSys AfriHealthSys

Privacy Policy

How AfriHealthSys collects, uses, stores, and protects facility and patient operational data.

Last updated July 14, 2026

This Privacy Policy explains how AfriHealthSys (“we”, “us”) processes personal and operational data when you visit afrihealthsys.com, request a demo, or use the AfriHealthSys product application. It is written for facilities evaluating or using the platform and for visitors to our public website.

1. Who we are

AfriHealthSys provides multi-tenant healthcare administration software for clinics, hospitals, laboratories, pharmacies, and related care organisations. For contracted customers, the customer facility is typically the data controller for patient and staff records stored in their tenant; AfriHealthSys acts as a processor / service provider under the applicable customer agreement and data processing terms.

2. Data we collect

Website and sales

  • Contact details you submit (name, email, phone, organisation, role).
  • Demo and inquiry form answers about facility size, modules of interest, and message content.
  • Technical logs such as IP address, browser type, referring URL, and approximate location derived from IP.
  • Cookie or similar identifiers used for session integrity, security, and (where enabled) analytics.

Product application (customer tenants)

  • Facility organisation data: tenant/branch configuration, departments, users, roles, and permissions.
  • Operational healthcare data entered by authorised users: patients, appointments, encounters, nursing notes, diagnostic orders/results, pharmacy dispensing, billing, claims, and related audit activity.
  • Authentication and access metadata required to secure accounts and investigate misuse.

3. How we use data

  • To respond to demo, sales, and support requests.
  • To operate, secure, and improve the AfriHealthSys platform for contracted customers.
  • To send transactional messages (security alerts, service notices) and, where permitted, product updates.
  • To meet legal, regulatory, and contractual obligations.

We do not sell personal data. We do not use customer patient records for advertising.

4. Legal bases and confidentiality

Where applicable law requires a lawful basis, we rely on contract performance, legitimate interests in operating a secure B2B platform, consent (for optional marketing), and legal obligation. Healthcare operational data is treated as confidential and accessed only by authorised customer users and by AfriHealthSys personnel under least-privilege need-to-know for support, security, and platform reliability.

5. Sharing

We may share data with:

  • Infrastructure and subprocessors that host, monitor, or deliver the service under written agreements.
  • Professional advisers and auditors under confidentiality.
  • Authorities when required by law or to protect rights, safety, and security.
  • A successor entity in connection with a merger or acquisition, subject to continued protection commitments.

6. Retention

Website inquiry data is retained as long as needed for sales follow-up and compliance. Customer tenant data is retained for the term of the customer agreement and for a defined post-termination window to allow export or secure deletion, unless a longer period is required by law or the facility’s own retention policy.

7. Security

We apply administrative, technical, and organisational measures appropriate to healthcare operations software, including encryption in transit, role-based access, tenant isolation, and auditable actions. See our Security page for a non-confidential overview. Customer administrators remain responsible for managing user access within their tenant.

8. International transfers

Depending on hosting and support arrangements documented in your agreement, data may be processed in countries other than where your facility operates. We use appropriate contractual and technical safeguards for such transfers.

9. Your rights and choices

Website visitors may request access, correction, or deletion of inquiry data we hold about them. Facility patients should generally contact their care provider (the customer) to exercise rights over clinical or billing records. Customer administrators can manage users and export available operational records through the product or by requesting support.

10. Children

The public website is not directed at children. Patient records for minors may be processed inside customer tenants when facilities lawfully provide paediatric care.

11. Changes

We may update this policy to reflect product, legal, or operational changes. Material updates will be reflected on this page with a revised “Last updated” date and, where appropriate, communicated to contracted customers.

12. Contact

Privacy and data protection inquiries: support@afrihealthsys.com. For security questionnaires or DPAs, use the same address with your organisation name and requested documents.

Need something more specific?

Request a security questionnaire, DPA, or facility agreement addendum from support@afrihealthsys.com.