CRW

Data processing and confidentiality

Written to be handed to whoever asks the question inside your organisation.

Last updated July 2026

So your data protection obligations are met rather than merely discussed, this sets out in one place how CRW handles information belonging to your facility and to your patients.

It is written to be handed to whoever asks the question inside your organisation, and it is the document to read before you engage us. CRW processes personal information in accordance with the Kenya Data Protection Act 2019, the Data Protection (General) Regulations 2021, and other applicable Kenyan law.

Who is who, in data protection terms

This distinction decides almost everything that follows, so it comes first.

RoleWho holds itWhat it means
Data controllerYour facility You decide why the patient information exists and what happens to it. The record remains yours.
Data processorCRW We act on your written instruction and nothing more. We do not decide to keep a record, do not decide to release one, and never use any of it for our own purposes.

CRW is a controller in its own right only for a narrow set of things: our own staff records, our own accounting records, the contact details of people at client facilities, and enquiries that arrive through this website. For those, the decisions are ours and so is the responsibility.

What we will sign

So there is nothing left to trust, every commitment below is available in writing before you engage us.

Separation between clients

Your information is separated from every other client's at the database level, not by procedure.

Each facility's records sit under its own organisation identifier, and access is enforced by the database itself rather than by a rule someone has to remember. A member of staff working on another facility cannot reach your records even by mistake. Scanned documents are held in per-facility storage under the same rule.

Access, and the record of it

Access is limited to the people who need it to do the work. Every account is named and authenticated, and every material action is stamped with who did it and when.

On medical records specifically, nothing is released without a recorded authority. The basis relied on, the identity document seen, who checked it and on what date are all captured before release, and the release itself is logged with what went and to whom. So a release can be defended if it is ever questioned, that record is what we would produce.

Patient rights, and one thing we will not do

A patient asking for their own records is exercising a right of access under the Data Protection Act. It is not a service being sold and it is not billed.

Our system will not raise an invoice against a patient for their own file.

This is enforced in the software rather than left to whoever is at the desk that day. The fee field locks to zero the moment a request is recorded as coming from the patient, the check is repeated when the record is saved, and the invoice function refuses outright. Where a facility engages us to run its records desk, the party who asked for the file is billed and the patient never is.

The seven day clock

The Data Protection (General) Regulations 2021 set a seven day window for responding to a data access request. Every request we handle is logged with its deadline on the day it arrives and tracked against it, so the clock is never discovered late.

Retention and deletion

We hold your information for the period agreed in your engagement and for any longer period the law requires, then delete it securely or anonymise it. Where the Digital Health Act and its regulations impose a longer retention period on the underlying clinical record, that record is yours and remains with you. We do not retain copies beyond what our agreement allows.

If something goes wrong

We maintain a written breach response procedure. Where a personal data breach occurs, we notify your facility without undue delay so that you can meet your own obligation to notify the Office of the Data Protection Commissioner within the period the Regulations require. We will tell you what happened, what was affected and what we have done about it, in writing.

Sub-processors

We use a small number of service providers to run the platform, including a database and storage provider and a hosting provider. We will name them on request and tell you where the data sits. We do not add a sub-processor that touches your information without telling you first.

Ask for it before you sign anything

The processing agreement, the confidentiality undertaking and the supplier declaration are all available to read before you engage us. Most facilities never ask. The ones that do get them the same day.

Request the documents