Swasps Privacy Policy
Last updated August 2026.
1. Introduction
Swasps ("Swasps", "we", "us", or "our") is a healthcare technology company building infrastructure and software designed to help healthcare organizations coordinate care, automate workflows, and provide patients with connected digital healthcare services.
Our products and services may include:
- Swasps Hospital OS;
- Swasps Health Wallet;
- The Hive and associated platform infrastructure;
- software applications and interfaces;
- APIs and integrations;
- websites and digital services;
- communication and notification services;
- analytics and operational tools; and
- future products and services developed by Swasps.
This Privacy Policy explains how Swasps may collect, receive, use, store, disclose, protect, and retain personal information when you interact with our websites, products, services, applications, APIs, or other systems operated by Swasps.
Because our services may process sensitive personal information, including health information, privacy and responsible data processing are fundamental requirements of our platform.
This Privacy Policy is intended to operate in accordance with applicable privacy and data-protection laws, including the Data Protection Act, 2019 of Kenya, applicable regulations, and guidance issued by the Office of the Data Protection Commissioner ("ODPC").
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed through Swasps services, including information relating to:
- patients;
- prospective patients and users;
- healthcare professionals;
- hospital and healthcare organization personnel;
- administrators;
- customers and their representatives;
- Health Wallet users;
- authorized caregivers and dependents;
- website visitors;
- applicants and business contacts;
- service providers;
- integration partners; and
- other individuals whose information is processed through our services.
Different Swasps products may have additional privacy notices or contractual requirements.
Where a product-specific privacy policy, customer agreement, Data Processing Agreement ("DPA"), or other legally binding agreement applies to particular processing, that document may provide additional or more specific requirements.
3. Who Is Responsible for Your Information?
The organization responsible for personal information depends on the circumstances in which that information is processed.
Swasps may act as a Data Controller where we determine the purposes and means of processing information.
For example, Swasps may act as a Data Controller for information required to:
- manage Swasps accounts;
- communicate with users;
- operate our websites;
- maintain security;
- provide customer support;
- manage business relationships;
- comply with legal obligations; and
- operate and improve our services.
Swasps may also act as a Data Processor when processing personal information on behalf of a hospital, healthcare organization, or other customer.
For example, when a hospital uses Hospital OS to process patient information according to the hospital's instructions, the hospital may determine the purposes and lawful basis for that processing while Swasps processes the information on the hospital's behalf.
The applicable role depends on the particular processing activity, applicable law, and contractual arrangements.
4. Information We May Collect
The information we collect depends on how you interact with Swasps and which services you use.
4.1 Identity and Account Information
We may collect:
- name;
- date of birth;
- telephone number;
- email address;
- identification information where necessary;
- account credentials;
- profile information;
- authentication information;
- emergency contact information;
- communication preferences;
- account settings; and
- information required to verify identity.
We use this information to create and manage accounts, authenticate users, communicate with users, provide services, and protect accounts.
4.2 Health Information
Depending on the product and services used, Swasps may process health information including:
- medical history;
- diagnoses;
- symptoms;
- allergies;
- medications;
- prescriptions;
- laboratory results;
- imaging information;
- clinical notes;
- treatment information;
- vital signs;
- care plans;
- referrals;
- discharge information;
- healthcare encounters;
- appointment information;
- healthcare documents; and
- other information relating to healthcare.
Health information may be provided directly by an individual, by healthcare professionals or organizations, through connected systems, or through authorized integrations.
4.3 Hospital and Operational Information
Hospital OS may process information relating to hospital operations, including:
- appointments;
- queues;
- patient movement;
- admissions;
- capacity;
- beds;
- referrals;
- department workflows;
- tasks;
- operational events;
- system events;
- financial and billing information; and
- information required to coordinate healthcare operations.
Hospital OS is designed to process information according to authorized workflows and user responsibilities rather than providing unrestricted access to all information.
4.4 Financial and Transaction Information
Where Swasps services provide payment or financial functionality, we may process:
- transaction references;
- payment status;
- invoices;
- charges;
- balances;
- purchase information;
- service information; and
- other information necessary to record or reconcile transactions.
Where a third-party payment provider processes sensitive payment credentials, such credentials may be processed directly by that provider under its own privacy terms.
4.5 Technical and Security Information
We may automatically collect technical information such as:
- IP address;
- device information;
- browser type;
- operating system;
- application information;
- access logs;
- audit logs;
- API activity;
- security events;
- error information;
- authentication events; and
- other information necessary to operate and secure our services.
We use this information to maintain reliability, detect security threats, investigate incidents, troubleshoot systems, and protect our users and infrastructure.
5. How We Collect Information
We may collect information:
- directly from you;
- from healthcare organizations;
- from healthcare professionals;
- from hospital systems;
- from authorized representatives;
- through Swasps applications;
- through websites;
- through APIs;
- through integrations;
- through communications with Swasps;
- through connected healthcare systems;
- through payment providers;
- through service providers; and
- automatically through technical systems.
Where required by law, we will seek appropriate consent or rely on another lawful basis for processing.
6. How We Use Personal Information
Depending on the service and applicable law, we may use personal information to:
- provide and operate Swasps services;
- establish and maintain accounts;
- authenticate users;
- coordinate healthcare workflows;
- support healthcare organizations;
- facilitate healthcare services;
- maintain healthcare records and timelines;
- communicate with users;
- provide notifications and reminders;
- process transactions;
- provide customer support;
- maintain security;
- prevent fraud and abuse;
- monitor system performance;
- troubleshoot technical problems;
- comply with legal and regulatory obligations;
- enforce our agreements;
- conduct legitimate business administration;
- improve the reliability and functionality of our services; and
- perform other purposes disclosed at the time information is collected or otherwise permitted by law.
We do not use health information for unrelated purposes simply because it is available to us.
7. Hospital OS and Health Wallet
Swasps operates different products with different responsibilities.
Hospital OS
Hospital OS is healthcare technology infrastructure designed for hospitals and healthcare organizations.
Depending on the implementation, Hospital OS may process patient, clinical, financial, operational, technical, and administrative information.
Where Swasps processes information on behalf of a hospital, our processing will generally be governed by the applicable customer agreement and, where applicable, a Data Processing Agreement.
Health Wallet
Health Wallet is a patient-facing platform designed to help individuals manage, access, organize, and interact with healthcare information and services.
Depending on the features used, Health Wallet may process identity information, healthcare information, documents, appointments, communications, transactions, and other information necessary to provide the service.
8. Sharing and Disclosure of Information
We may disclose personal information where reasonably necessary to provide our services or where permitted or required by law.
Information may be shared with:
- healthcare organizations;
- healthcare professionals;
- authorized hospital personnel;
- laboratories;
- pharmacies;
- imaging providers;
- payment providers;
- technology providers;
- cloud infrastructure providers;
- communications providers;
- integration partners;
- professional advisers;
- regulators or government authorities where legally required; and
- other parties where authorized or legally permitted.
We aim to limit disclosure to information reasonably necessary for the relevant purpose.
We do not sell personal health information for advertising purposes.
9. Health Information and Authorized Access
Healthcare information is sensitive and requires appropriate protection.
Access to health information within Swasps systems may be controlled through mechanisms including:
- role-based access;
- authentication;
- least-privilege principles;
- department-based permissions;
- authorization controls;
- audit logging;
- access reviews; and
- customer-specific permissions.
Not every Swasps or hospital user will automatically have access to every patient's information.
Where Swasps personnel require access for support, security, maintenance, troubleshooting, compliance, or another legitimate purpose, access should be limited to what is reasonably necessary.
10. Artificial Intelligence
Swasps uses artificial intelligence and automated technologies in certain services.
AI may be used for functions such as:
- information organization;
- summarization;
- workflow automation;
- routing;
- prioritization;
- operational analysis;
- documentation assistance;
- decision-support functionality;
- identifying relevant information; and
- other permitted functions.
AI does not automatically replace healthcare professionals or the responsibilities of healthcare organizations.
Where AI is used in clinical or healthcare-related workflows, appropriate human oversight and professional judgment remain important.
AI outputs may be incomplete, inaccurate, or inappropriate in particular circumstances.
Swasps does not treat AI output as an unconditional substitute for professional medical judgment.
11. AI Training and Secondary Use
Swasps does not sell personal health information for advertising.
Where health or personal information is processed through a customer environment, Swasps will not use that information for unrelated purposes merely because it is technically accessible.
Any secondary use of information for research, analytics, product improvement, model development, or similar purposes will be subject to applicable law, contractual obligations, appropriate safeguards, and any required authorization or de-identification.
Where information is appropriately anonymized so that individuals are no longer reasonably identifiable, it may be used for legitimate analytical, research, security, or product-improvement purposes where permitted by law.
12. Data Storage and Security
Swasps uses technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Safeguards may include:
- authentication controls;
- authorization controls;
- encryption where appropriate;
- access controls;
- audit logging;
- monitoring;
- secure infrastructure;
- incident detection;
- backups and recovery procedures;
- least-privilege principles; and
- other security measures appropriate to the nature of the information.
No technology system can guarantee absolute security.
Users and organizations are also responsible for maintaining appropriate security of their accounts, credentials, devices, and authorized users.
13. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide our services, comply with contractual obligations, resolve disputes, maintain security, or satisfy applicable legal and regulatory requirements.
Retention periods may differ depending on:
- the type of information;
- the product;
- the purpose of processing;
- contractual requirements;
- healthcare record requirements;
- legal obligations; and
- security or operational requirements.
Where information is no longer required, we will seek to delete, anonymize, or securely dispose of it where appropriate and permitted by law.
14. Your Rights
Subject to applicable law, individuals may have rights concerning their personal information, including rights to:
- access personal information;
- request correction of inaccurate information;
- request deletion where legally applicable;
- object to certain processing;
- request restriction of processing;
- request information about processing;
- exercise rights relating to automated processing where applicable;
- withdraw consent where processing is based on consent; and
- lodge a complaint with the relevant data-protection authority.
Certain rights may be limited where another lawful requirement applies.
Where information is controlled by a healthcare organization, requests relating to that organization's records may need to be directed to the relevant healthcare organization.
15. Data Portability
Where required by applicable law and technically feasible, you may have the right to receive certain personal information in a structured, commonly used format.
Healthcare information originating from a hospital or healthcare provider may remain subject to that provider's legal and record-management responsibilities.
16. Children and Minors
Certain Swasps services may involve information relating to children or dependents.
Where required, a parent, guardian, caregiver, or legally authorized representative must provide the appropriate authorization.
We will process information relating to children in accordance with applicable law and appropriate safeguards.
17. Third-Party Services and Integrations
Swasps may integrate with third-party services, healthcare systems, payment providers, communication platforms, infrastructure providers, and other technologies.
Third parties may have their own privacy policies and terms.
Where information is processed directly by a third party, that third party may have separate responsibilities under applicable law.
Swasps does not control the privacy practices of independent third parties outside our systems.
18. International Data Transfers
Depending on the infrastructure, service providers, integrations, or operational requirements involved, personal information may be processed or stored outside Kenya.
Where applicable, Swasps will implement appropriate safeguards and comply with applicable requirements governing international transfers of personal information.
19. Cookies and Similar Technologies
Our websites and digital services may use cookies and similar technologies to:
- operate our websites;
- maintain security;
- understand usage;
- remember preferences;
- improve performance; and
- analyze service reliability.
Where required, we will provide appropriate choices or notices concerning non-essential cookies.
20. Data Breaches and Security Incidents
Swasps maintains processes designed to detect, investigate, contain, and respond to security incidents.
Where applicable law requires notification of a data breach or security incident, Swasps will make the required notifications within the applicable legal framework.
Where Swasps processes information on behalf of a healthcare organization, contractual notification requirements may also apply.
21. Privacy by Design
Swasps aims to incorporate privacy and security considerations into the design and development of its services.
Our approach may include:
- data minimization;
- purpose limitation;
- role-based access;
- least-privilege access;
- auditability;
- appropriate retention controls;
- security controls;
- controlled integrations; and
- responsible use of automation and AI.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our services;
- changes in technology;
- changes in applicable law;
- regulatory guidance;
- security improvements; or
- changes to our privacy practices.
When we make material changes, we may provide appropriate notice.
The "Last Updated" date at the beginning of this policy indicates when the policy was most recently revised.
23. Complaints
We encourage individuals to contact Swasps first so that we can attempt to address privacy concerns.
Nothing in this Privacy Policy prevents you from exercising your legal rights or submitting a complaint to the relevant data-protection authority, including the Office of the Data Protection Commissioner in Kenya.
24. Governing Framework
This Privacy Policy is intended to operate consistently with applicable Kenyan data-protection and privacy law, including the Data Protection Act, 2019, applicable regulations, and relevant regulatory guidance.
Where Swasps operates in another jurisdiction, additional privacy requirements may apply to the relevant processing activities.
© 2026 Swasps. All rights reserved.
Swasps