Who we are
This website is run by Cognivex Limited, the company behind SmartCare HMIS. For the personal data described here, Cognivex Limited is the data controller.
Patient records inside a hospital’s own SmartCare system belong to that hospital, which is their controller. We process them only on the hospital’s instructions, under our contract with it, and this policy does not cover them — the hospital’s own privacy notice does.
What this policy covers
- Messages sent through the contact form on this website.
- Applications to become a client, made through our onboarding flow.
- Calls and WhatsApp messages to our sales line.
What we collect
- Through the contact form — your name, work email and facility name, and, if you choose to give them, your role, phone number and message.
- The “I’m not a robot” check — a small calculation your browser does to show it is a person sending the form. It sets no cookies and stores nothing about you.
- When you apply to become a client — your hospital’s details, your contact details, what you need, and the date and version of the policy you agreed to.
Why we use it
- To answer you — replying to your message, calling you about your application, and setting up your facility if you become a client. This is necessary to take the steps you asked us to take.
- To keep the service secure — refusing automated submissions and investigating misuse. This is our legitimate interest, and yours, in a system that cannot be abused quietly.
We do not sell personal data, use it for advertising, or build profiles from it.
Who we share it with
Only with the providers that run the service for us — hosting and email delivery — under contracts that limit them to doing that, and with authorities where the law requires it.
Cookies and storage
This website sets no cookies. If you choose light or dark mode, that choice is kept in your own browser and is never sent to us.
How long we keep it
- Messages and applications that do not lead to a contract: 24 months after our last contact, then deleted.
- Records about a client: for the life of the contract and seven years after, as tax and audit law requires.
Your rights
You can ask to see the data we hold about you, have it corrected, have it deleted where we are not required to keep it, receive it in a portable form, or object to how we use it. Kenya’s Data Protection Act, 2019 gives you these rights. Send your request through our contact page or call +254 716 177 297; we answer within 30 days. You may also complain to the Office of the Data Protection Commissioner.
Security
Everything sent through this website travels encrypted. What reaches us is stored in our own database, kept apart from any hospital’s records, and only named staff can see it, with every change they make logged.
Changes
When this policy changes, the date at the top of this page changes with it.