Skip to content
PrimegalaMedical Centre

Policies

Privacy Policy

How Primegala Medical Centre collects, uses, shares and protects personal and health data under Kenya's Data Protection Act, 2019, the Health Act, 2017 and the Digital Health Act, 2023.

Primegala Medical Centre ("Primegala", "we", "us") respects your privacy. This policy explains how we handle personal data collected through this website, WhatsApp, phone and our facility, and what rights you have.

It is written to meet our obligations under the Constitution of Kenya, 2010 (Article 31), the Data Protection Act, 2019 ("DPA"), the Data Protection (General) Regulations, 2021, the Health Act, 2017, the Digital Health Act, 2023 and the Office of the Data Protection Commissioner's Guidance Note on the Processing of Health Data.

1. Who we are

Data controllerPrimegala Medical Center and Nursing Home
AddressNakuru–Nyahururu Road, Maili Sita Centre, opposite Kiamaina Primary School, Kabatini Ward, Nakuru County, Kenya
In personOur front desk at the address above, open 24 hours a day
Emailinfo@primegala.co.ke
ODPC registrationAvailable on request
Data protection enquiriesData Protection Officer, info@primegala.co.ke

As a health service provider, Primegala is required to register with the Office of the Data Protection Commissioner (ODPC) as a data controller under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021. You may ask us for our registration details at any time.

2. What we collect

Through this website and our messaging channels

  • Contact details: your name, phone number and (optionally) email address.
  • Your request: the service you're interested in, preferred date and time, preferred contact channel and any short message you choose to send.
  • Consent records: what you agreed to, when, and which version of this policy applied.
  • Marketing source: the page you arrived on and campaign tags (for example, "utm_source"), so we know which information helps people find us.
  • Technical data: IP address, browser and device type, and pages visited, collected by our hosting provider for security, and by analytics tools only if you accept analytics cookies (see our Cookie Policy).

Please don't send detailed medical history through website forms or WhatsApp. Share it with a clinician during your visit, where it is recorded securely.

When you receive care

Your clinical record, which includes health data, a category of sensitive personal data under section 2 of the DPA: identification details, SHA membership details, medical history, diagnoses, test results, treatment, and billing information. This is recorded in our Health Management Information System (HMIS).

PurposeLegal basis (DPA)
Responding to appointment, callback and enquiry requestsYour consent (s.30, s.32)
Providing medical care and keeping clinical recordsNecessary for health care, by professionals under a duty of confidentiality (s.30, s.46)
Checking SHA eligibility, pre-authorisation and claimsLegal obligation and performance of a contract (s.30)
Protecting someone's life in an emergencyVital interests (s.30)
Public health reporting required by law (e.g. notifiable diseases)Legal obligation; public interest (s.30)
Health tips, reminders about services and newslettersYour separate, optional consent (s.37)
Website security and fraud preventionLegitimate interests (s.30)
Website analyticsYour consent via the cookie banner

We process health data only for purposes permitted by sections 44–46 of the DPA, and only by people under a duty of confidentiality.

4. Who we share it with

We never sell your data. We share only what is necessary with:

  • Our HMIS and IT service providers, who process data on our behalf under written data processing agreements (s.42).
  • The Social Health Authority (SHA) and the Digital Health Agency (DHA), through the national Health Information Exchange, to verify eligibility and submit claims, as required by law.
  • Laboratories, imaging centres and hospitals we refer you to, for your continuing care.
  • WhatsApp (Meta), only when you choose to contact us via WhatsApp. Messages are subject to WhatsApp's own terms.
  • Regulators and authorities, such as the Ministry of Health, the County Department of Health, professional councils or courts, when the law requires it.
  • Your nominated next of kin, only with your consent or where necessary to protect your life.

5. Transfers outside Kenya

Patient health records are stored in line with the Digital Health Act, 2023 and regulation 26 of the Data Protection (General) Regulations, 2021, including requirements to process and store health data within Kenya. Where a website or messaging service provider processes non-clinical contact data outside Kenya, we do so only with appropriate safeguards under sections 48–50 of the DPA.

6. How long we keep it

  • Website enquiries that don't become a visit: up to 12 months, then deleted or anonymised.
  • Clinical records: for the periods required by Ministry of Health records-management guidelines and applicable law.
  • Consent records: for as long as the consent is relevant, plus the period needed to show we complied with the law.
  • Marketing preferences: until you opt out.

7. How we protect it

  • Encryption of data in transit (HTTPS/TLS) and, in our HMIS, at rest
  • Role-based access with the principle of least privilege, as required by the Digital Health (Health Information Management Procedures) Regulations, 2025
  • Audit logs of access to patient records
  • Signed confidentiality undertakings for all staff
  • Regular backups and staff training

If a personal data breach poses a real risk of harm, we will notify the ODPC within 72 hours of becoming aware of it and inform affected people without undue delay, as required by section 43 of the DPA.

8. Your rights

Under the DPA, including sections 26, 32, 34, 35, 36, 38 and 40, you have the right to:

  • Be informed about how your data is used (this policy)
  • Access your personal data
  • Object to processing, including direct marketing, at any time
  • Correct inaccurate or misleading data
  • Delete data that is no longer needed or was processed unlawfully (clinical records we're legally required to keep are an exception)
  • Data portability: receive your data in a structured, machine-readable format
  • Withdraw consent at any time, without affecting earlier lawful processing
  • Not be subject to decisions based solely on automated processing that significantly affect you

To exercise your rights, email us at info@primegala.co.ke or ask at our front desk, which is open 24 hours. We may need to verify your identity, for example by asking to see your national ID. We respond within the timelines set by the Data Protection (General) Regulations, 2021.

9. Children's data

We process the personal data of children (under 18) with the consent of a parent or guardian, and in the child's best interests, as required by section 33 of the DPA.

10. Complaints

If you're unhappy with how we've handled your data, please contact our Data Protection Officer first, at info@primegala.co.ke. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner at www.odpc.go.ke.

11. Changes to this policy

We may update this policy. The latest version is always on this page, with the date it was last updated. Significant changes will be highlighted on our website.

Last updated: 4 October 2026

Questions about this policy?

Email info@primegala.co.ke or speak to our front desk, which is open 24 hours. All policies.