Privacy Policy
OnLocum Online Limited — FlowMed HMIS and the OnLocum Platform
- Version
- v1.0 — effective 8 July 2026
- Data Protection Officer
- Eric Mulatya — eric@onlocum.com
- ODPC registration
- Controller cert. 23927 · Processor cert. 23928 (valid 07/07/2026 – 07/07/2028)
- Governing law
- Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021
1. Who we are
OnLocum Online Limited is a Kenyan company that builds trust infrastructure for healthcare. We operate two connected products:
- FlowMed HMIS — a hospital management information system used by healthcare facilities to manage patient care, billing, pharmacy, laboratory, and related clinical operations.
- The OnLocum platform — a workforce platform connecting healthcare facilities with verified healthcare workers for locum shifts and related services.
We are registered with the Office of the Data Protection Commissioner (ODPC) as both a Data Controller (certificate 23927) and a Data Processor (certificate 23928), each valid from 7 July 2026 to 7 July 2028.
Our Data Protection Officer (DPO) is Eric Mulatya, reachable at eric@onlocum.com. He is your first point of contact for any question, request, or concern about your personal data.
2. Our two roles — controller and processor, in plain language
Under the Data Protection Act, 2019, the organisation that decides why and how your data is processed is the controller; an organisation that processes data on the controller's behalf and instructions is the processor. We hold both roles, depending on the data:
- Patient and clinical data in FlowMed. If you are a patient, your relationship is with your healthcare facility — the hospital or clinic treating you. The facility is the data controller of your medical records. OnLocum is the data processor: we store and process that data on the facility's behalf, under a data-processing agreement, and only on the facility's instructions. Questions about how a facility uses your medical records should go to that facility first; we will support them (and you) in answering.
- OnLocum platform data. If you are a healthcare worker, facility staff member, or platform user with an OnLocum account, OnLocum is the data controller of your account and profile data — we decide how it is processed, and we are directly responsible to you for it.
A single person can fall under both roles — for example, a nurse who is a patient at one facility and also a registered locum worker on our platform.
3. What we collect
We collect only what each service needs to work. In plain terms:
Patients (collected by your healthcare facility, processed by us in FlowMed):
- Identity and contact details — name, date of birth, national ID number, phone, email, address, next of kin / emergency contacts
- Clinical and health records — diagnoses, visit and encounter notes, prescriptions, laboratory and radiology results
- Medical imaging — radiology images and their associated study information
- Billing and insurance details — invoices, insurance membership numbers, Social Health Authority (SHA) claim information, payer records
Healthcare workers (on the OnLocum platform):
- Identity and contact details, professional profile, and identity photos
- Professional credentials — licences, registration numbers, qualifications, and their verification status with the relevant regulatory bodies
- Work preferences, availability, location for shift matching, and work history on the platform
- Payment details (such as mobile-money numbers) needed to pay you for completed work
Facility staff and platform users:
- Account details — name, email, phone, role, and the facility or organisation you belong to
- Activity records needed for security and accountability — such as sign-in events and actions taken in the system
We treat health records, medical imaging, national ID numbers, biometric data, and financial details as sensitive personal data and apply our strictest protections to them (see Section 5).
4. Why we process your data, and on what legal basis
The Data Protection Act, 2019 (Section 30, and Sections 44–46 for sensitive and health data) requires a lawful basis for every purpose. Ours are:
| Purpose | What it means | Legal basis |
|---|---|---|
| Clinical care delivery | Keeping accurate medical records so your facility can diagnose, treat, and follow up your care safely | Provision of health services / protection of vital interests, under the health-data conditions of the Act |
| Billing and insurance claims | Preparing invoices and submitting claims to your insurer or the Social Health Authority (SHA) so care is paid for | Legal obligation and performance of contract |
| Statutory public-health reporting | Reporting required health statistics to the Ministry of Health and national health information systems. Only aggregate, de-identified numbers are reported — no names, ID numbers, or other identifiers leave the system in these reports | Legal obligation (public-health statutory reporting) |
| Workforce management and credential verification | Matching workers to shifts, verifying professional licences with regulators, managing timesheets and payments | Performance of contract and legitimate interest |
| Marketing and non-essential communications | News, product updates, and promotional messages | Your consent only — we do not send marketing without it, and you may withdraw consent at any time |
We do not sell personal data, and we do not use patient clinical data for advertising or marketing.
5. How we protect your data
We apply layered technical and organisational safeguards, including:
- Encryption in transit — all connections to our services are encrypted (TLS)
- Encryption at rest, including field-level encryption — databases are encrypted, and direct identifiers in patient records (such as names, ID numbers, and phone numbers) are additionally encrypted at the individual field level, with encryption keys managed and stored separately from the data
- Access controls and multi-factor authentication (MFA) — access is role-based and limited to what each user's job requires; facilities can require MFA for their staff, and idle sessions are automatically signed out
- Tamper-evident audit trails — changes to records are logged in an audit trail designed so that tampering can be detected
- Read-access logging — viewing of patient health information is itself logged, not just changes to it
- Controlled emergency ("break-glass") access — emergency access to a patient record outside normal permissions is time-limited, read-only, requires a recorded justification, and is flagged for administrative review
- Backups and recovery — regular, integrity-checked backups with tested recovery procedures, so records are not lost to technical failure
No system is perfectly secure, but we design for the sensitivity of health data and continuously improve these controls. What we do if something goes wrong is set out in Section 9.
6. Who we share your data with
We share personal data only where the service requires it or the law demands it:
- Your healthcare facility (the controller). Patient data in FlowMed belongs, in legal terms, to the facility treating you — the facility's authorised staff access it to deliver your care.
- Insurers and the Social Health Authority (SHA). Billing and claim details are shared with your insurer or SHA to process claims for your care.
- National health systems. Aggregate, de-identified statistics are reported to the Ministry of Health and national health information systems as required by law. These reports contain numbers only — no patient identifiers.
- Regulatory bodies. For healthcare workers, we verify credentials with the relevant professional regulators (such as nursing, medical, and pharmacy boards).
- Our infrastructure service providers (sub-processors). We use vetted providers, under data-processing agreements, for: cloud hosting and databases, object storage and backups, email delivery, and real-time messaging/notifications. Some of these providers operate outside Kenya. Where data crosses borders, we rely on the safeguards required by Sections 48–49 of the Data Protection Act, 2019 — data-processing agreements with contractual protections equivalent to those of Kenyan law, plus the security measures described in Section 5. We are also progressing a data-residency migration toward a Kenya cloud region.
We never share personal data with third parties for their own marketing.
7. How long we keep your data
| Data | Retention | Why |
|---|---|---|
| Clinical and medical records (including their audit trails) | 7 years | Legal, professional, and public-health record-keeping obligations for medical records. This obligation overrides erasure requests for the duration of the retention period (see Section 8) |
| Platform account and workforce data | For as long as your account is active, then per our retention schedule; erasure requests are honoured within the statutory window | Contract and legal obligations (e.g. financial records) |
| Daily backups | 7 days, then automatic expiry | Disaster recovery |
| Weekly backups | 90 days, then automatic expiry | Disaster recovery |
Backup expiry is automatic — a deleted or erased record also ages out of all backup copies within 90 days at most. When retention ends, data is deleted or irreversibly anonymised. Records for minors and maternity care may be subject to longer statutory retention periods where the law requires.
8. Your rights
Under Part IV of the Data Protection Act, 2019, you have the right to:
- Be informed — this policy exists to tell you how your data is used
- Access — obtain a copy of the personal data we hold about you
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your data deleted. One important exception: clinical and medical records must by law be retained for 7 years (Section 7). During that period an erasure request against clinical records will be formally recorded and declined with written reasons; it is actioned once the retention obligation lapses. Erasure of non-clinical platform data is not subject to this exception
- Data portability — receive your data in a structured, commonly used, machine-readable format
- Object — object to processing, including withdrawing consent to marketing at any time
- Not be subject to solely automated decisions that significantly affect you
How to exercise your rights: email our DPO at eric@onlocum.com. We respond within the timelines set by the Data Protection Act and its Regulations. For patient medical records, we may route your request through your healthcare facility (the controller) — we will tell you if so and help coordinate.
Complaints: you may lodge a complaint at any time with the Office of the Data Protection Commissioner (ODPC) via dataportal.odpc.go.ke. We would appreciate the chance to resolve your concern first, but you are not required to contact us before going to the ODPC.
9. If a data breach happens
We maintain a tested breach-response plan with hard commitments:
- Where we are the processor (patient/clinical data): we notify the affected healthcare facility (the controller) within 48 hours of becoming aware of a breach, so the facility can meet its own legal duties.
- Where we are the controller (platform data): we notify the ODPC within 72 hours of becoming aware of a breach, as required by Section 43 of the Act.
- Where a breach is likely to pose a high risk to you — for example, exposure of health or financial information — affected individuals are notified without undue delay, in plain language, with practical steps to protect yourself.
Every breach is recorded, investigated, and followed by corrective action, whether or not notification thresholds are met.
10. Cookies and analytics
We keep tracking to a minimum:
- FlowMed HMIS (the clinical system) uses no third-party analytics or advertising trackers. It uses only the essential cookies and browser storage required for secure sign-in, session management, and offline operation of the app. Patient data is never shared with analytics providers.
- The OnLocum website and platformuse a privacy-conscious product-analytics tool to understand how the site is used and improve it. It is configured to store its data in your browser's local storage rather than tracking cookies, to respect your browser's "Do Not Track" setting, and with session recording disabled. We also collect anonymous page-performance measurements (load speed) that do not identify you.
- Essential cookies for signing in and keeping your session secure are used across both products; these are necessary for the services to function.
We do not use advertising cookies, and we do not sell or share browsing data with advertisers.
11. Changes to this policy
We may update this policy as our services or the law change. The current version and its effective date always appear at the top. For material changes, we will give notice through the platform or by email before the change takes effect. Significant changes to how we process personal data are also re-notified to the ODPC as required.
This version: v1.0, effective 8 July 2026.
Contact
| Contact | Details |
|---|---|
| Data Protection Officer | Eric Mulatya — eric@onlocum.com |
| Data-subject requests (DSAR) | eric@onlocum.com |
| Regulator | Office of the Data Protection Commissioner (ODPC) — dataportal.odpc.go.ke |