Organisation and Insurer Data Terms

Last updated 29 Sep 2026

These terms apply to hospitals, clinics and health centres that use the organisation portal, and to insurers that use the insurer portal or insurer API. They set out what you may do with the patient and prescriber data you see, how you must protect it, and what happens if something goes wrong.

About these terms

DukadawaRx is operated by Afya Intelligence, of Dar es Salaam, Tanzania. "We" and "us" mean Afya Intelligence. "You" means the organisation or insurer that has an account, and includes your staff who use it.

These terms apply together with our Privacy Policy. The person who registers or activates your account confirms that they have authority to accept these terms for you.

Roles

We are the data controller for DukadawaRx and the data in it.

You are an independent data controller for the data you receive through the portal or API and then use or store in your own systems. You are responsible for meeting the data protection law that applies to you, including registering with the Personal Data Protection Commission in Tanzania, or the regulator in your country, where required.

What you can see

  • Organisations see the prescribers linked to them and the prescriptions issued under them, including patient name, phone, age, sex, diagnoses, medicines, status and fees.
  • Insurers see prescriptions for patients who use their cover, dispensing details and the claims created from them.
  • Neither organisations nor insurers ever see the prescriber's clinical note.

Permitted purposes

You may use the data only for these purposes:

  • Organisations: supervising prescribers who work with you, managing prescriber links and administering consultation fees.
  • Insurers: verifying membership and processing claims for medicines dispensed to your members.

Any other use needs our written agreement and a lawful basis of your own.

What you must not do

  • Do not try to identify people in data that has been masked or made anonymous.
  • Do not use the data for marketing, sales or profiling.
  • Do not sell, rent or give the data to anyone else, except where the law requires it. If the law requires disclosure, tell us first unless the law forbids it.
  • Do not use the data to refuse care or make decisions about a patient that are not part of the permitted purposes.
  • Do not copy or download data in bulk except as the portal or API allows for the permitted purposes.
  • Do not try to access prescriptions or data you are not allowed to see.

Confidentiality

Treat all patient and prescriber data as confidential health information. Only staff who need it for the permitted purposes may see it, and they must be bound by a duty of confidentiality.

Access control

Your account has two roles. Managers can see everything, take actions and manage the team. Viewers can see the same lists and prescriptions but cannot take actions.

You must:

  • give each person their own account and never share sign-ins;
  • give the manager role only to people who need it;
  • keep your team list current, and deactivate a person's account on the day they leave or no longer need access;
  • make sure your staff keep their phones secure, since sign-in uses SMS codes.

Access logging and audits

We record every time your staff open a prescription: who, which prescription and when. We also record team changes and other actions.

We may review these records, and ask you questions about access, to check that you follow these terms. You must answer within a reasonable time and give us the information we reasonably need. We may share relevant records with a regulator where the law requires it.

API keys, secrets and webhooks

For insurers that use the API:

  • Your key secret is shown once. Store it in a secure secret store and share it only with the people who run your systems.
  • Sign every API request as our documentation explains. Never put the secret in client apps, emails or code repositories.
  • If a secret may have been exposed, issue a new one in the portal at once. The old one stops working immediately.
  • Your membership check URL and claims webhook URL must use HTTPS, must check our signature on each request, and must be run by you or under your control.
  • Protect the data your systems receive from us to at least the standard these terms require.

Security incidents

If you know or suspect that data from DukadawaRx has been lost, stolen, or accessed or used without permission, you must tell us at privacy@afyarx.co.tz within 24 hours of finding out.

Tell us what happened, what data is affected and what you are doing about it. Work with us to contain the incident and to notify regulators and affected people where the law requires.

Member lists

Insurers that upload member lists must keep them accurate and current, including end dates of cover. Upload only the data needed to check membership. Remove members whose cover has ended. You are responsible for the results of checks based on your list or your membership check URL.

Claims

A claim in DukadawaRx is a record of medicines a pharmacy says it dispensed, with quantities and prices. It is not approval of payment, and it is not a guarantee by us that the claim is valid. You decide on cover and payment in your own systems, under your own rules and contracts. Marking a claim as received only records that you have it.

Retention and deletion

Keep data you take from DukadawaRx only as long as you need it for the permitted purposes or as the law requires.

When your account ends, you must stop using the portal and API, delete or return data from DukadawaRx that you no longer need, and confirm this to us in writing if we ask. You may keep records the law requires you to keep, and these terms continue to apply to them.

We keep our own records as our Privacy Policy explains.

Suspension and termination

We may suspend or close your account, with notice where possible, if you break these terms, if we have good reason to believe data is at risk, if your registration or licence is no longer valid, or if a regulator or court requires it. Suspension ends your staff's sessions at once.

You may close your account by writing to support@afyarx.co.tz.

Liability

Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not allow to be limited.

You are responsible for losses we suffer because you or your staff break these terms or data protection law. We are not liable for decisions you make using data from DukadawaRx, or for indirect losses that were not reasonably foreseeable.

Governing law and disputes

These terms are governed by the laws of the United Republic of Tanzania. We will first try to settle any dispute by negotiation in good faith within 30 days. If it is not settled, either of us may take it to the courts of Tanzania.

Changes and acceptance

We may change these terms. We will tell your managers at least 30 days before an important change takes effect, unless the change is needed sooner by law or for security. We record which version your account accepted, who accepted it and when.