Privacy Policy
This policy explains what personal data DukadawaRx collects, why we use it, who can see it and how long we keep it. It covers prescribers, patients, hospital and clinic staff, insurer staff, pharmacy partners, people who receive our reports and visitors to our public doctor directory. It also explains your rights under Tanzania's Personal Data Protection Act, 2022 and how to use them.
Who we are
DukadawaRx is a digital prescribing service at dukadawarx.co.tz. It is operated by Afya Intelligence, of Dar es Salaam, Tanzania. In this policy, "we", "us" and "our" mean Afya Intelligence. "You" means the person reading this policy.
We are the data controller for the personal data we process to run DukadawaRx. This means we decide why and how that data is used, and we are responsible for it under the Personal Data Protection Act, 2022 of Tanzania (the Act).
We have appointed a data protection officer. You can contact our data protection officer at privacy@afyarx.co.tz. For general help with the service, write to support@afyarx.co.tz.
Who this policy covers
This policy covers everyone whose personal data we process through DukadawaRx:
- Prescribers: doctors and other licensed health workers who write prescriptions in the web app.
- Patients: people for whom a prescription is written. Patients do not sign in to the web app. They receive SMS messages and may use our patient app.
- Organisation staff: people who work for a hospital, clinic or health centre and use the organisation portal.
- Insurer staff: people who work for a health insurer or health scheme and use the insurer portal.
- Pharmacy and point of sale (POS) partners: pharmacies and the POS systems they use to read and dispense prescriptions.
- Report recipients: people who receive reports or summaries from us by email.
- Directory visitors: anyone who uses our public doctor directory without signing in.
What data we collect
The data we hold depends on how you use DukadawaRx.
Prescribers:
- Identity and contact details: name, title, phone number and country of practice.
- Professional details: council registration number (for example with the Medical Council of Tanganyika), cadre, licence expiry date, specialisations and the hospitals or clinics you work with.
- Verification documents: registration certificate, practising licence and photo ID.
- Profile details: an optional photo, a short introduction, the area you serve and its location, your service radius and whether you are taking requests.
- Account security data: a hashed PIN, sign-in codes (stored only as a keyed hash), and records of your signed-in devices.
- Financial data: your consultation fee, payments received, the platform fee, wallet balance, and the mobile money number and network you use for payouts.
- Prescriptions you write, including the clinical note you keep for yourself.
Patients:
- Name, phone number, sex, date of birth or age, and weight when given.
- Payment type, and for insured patients the insurer or scheme and membership number.
- Health data in the prescription: diagnoses, medicines, doses and instructions, and the prescriber's clinical note.
- Dispensing data: which pharmacy dispensed which medicines, when, and at what price.
- Payment data for consultation fees or medicines paid by mobile money: the paying phone number, network, amount and status.
- In the patient app: the people registered under the phone (the account holder and any dependants), requests for consultations or refills, and the symptoms described in them.
Organisation and insurer staff:
- Name, phone number, role (manager or viewer), the organisation or insurer you work for, and records of your sign-ins.
- A record of each prescription you open in the portal and the actions you take.
- For organisations: registration details such as name, type, address, registration number, registration certificate and operating licence.
Insurers also give us member lists: membership numbers, member names and end dates of cover.
Pharmacy and POS partners: the pharmacy's name, location, products and prices, and records of prescriptions read, locked, dispensed or returned. We also hold contact details for the people who manage the partnership.
Report recipients: name, email address, the reports you receive and how often, and records of emails sent to you.
Directory visitors: if you choose to share your location to find nearby prescribers, we use it only to answer that search and do not store it. Like any website, our servers receive your IP address and basic browser information when you visit.
Everyone who uses the service: technical data such as IP address, device and browser type, and the time of each request. See our Cookies and device storage notice for what the web app stores on your device.
Where the data comes from
- From you, when you register, fill in your profile or use the service.
- From prescribers, who enter patient details and write prescriptions. For children and other dependants, details usually come from the parent or caretaker through the prescriber or the patient app.
- From patients, when they use the patient app.
- From pharmacies and their POS systems, when they read and dispense prescriptions.
- From insurers, through member lists or a membership check.
- From hospitals and clinics, when they confirm or remove prescriber links and manage their team.
- From our payment provider, which tells us whether a payment or payout succeeded.
- From public registers, when we check a prescriber's registration against the relevant council's register or an organisation against the facility registry.
Why we use data and our lawful bases
The Act only lets us process personal data when we have a lawful reason. We rely on these:
- Contract: to provide the service you signed up for. For example, to create and secure your account, deliver prescriptions, collect consultation fees and pay prescribers.
- Legal obligation: to keep records the law requires, including tax and financial records, to answer lawful requests from regulators or courts, and to report personal data breaches.
- Legitimate interests: to keep the service secure, prevent fraud and misuse, verify prescribers and organisations, fix faults and improve the service. We only rely on this when our interest is not outweighed by your rights.
- Consent: for things you choose, such as a public directory profile, sharing your location in the directory, or optional emails. You can withdraw consent at any time. This does not affect what we did before.
We use personal data to:
- register and verify prescribers, organisations and insurers;
- let prescribers write, sign and send prescriptions;
- send patients their pickup code and prescription updates by SMS;
- let pharmacies find, dispense and return prescriptions;
- take and record payments, and pay prescribers;
- check insurance membership and create claims for insured patients;
- show organisations and insurers the prescriptions they are allowed to see;
- run the public doctor directory for prescribers who choose it;
- send reports and account messages by email and SMS;
- keep the service secure and keep records of who did what.
Health data
Health data is sensitive personal data under the Act. The general rule is that sensitive data needs written consent. Section 30 of the Act allows an exception for medical purposes, where the processing is done by a health professional or under the supervision of one.
Prescriptions on DukadawaRx are written by licensed prescribers as part of patient care. We process health data on the medical purposes basis, under the supervision of those prescribers, to deliver the prescription, have it dispensed and paid for, and keep the record.
Prescribers must tell patients that the prescription is created and shared through DukadawaRx, as set out in our Prescriber Terms of Use.
Service providers
These providers process personal data for us under our instructions. They may not use it for their own purposes.
- Hosting: our servers and database run on DigitalOcean, a cloud provider based in the United States.
- SMS: Beem sends our SMS messages, such as sign-in codes and pickup codes, through mobile networks. Beem and the mobile network operators see the phone number and the message.
- Payments: Selcom, a payment service provider, processes mobile money payments and prescriber payouts. Selcom and the mobile money operators see the phone number, network, amount and reference.
- Email: Resend, an email delivery service based in the United States, sends our emails. We may instead use another email provider through standard email (SMTP). The provider sees the email address and the message.
- Maps: map images in the web app are loaded from OpenStreetMap's tile servers, run by the OpenStreetMap Foundation. Your browser requests the images directly, so the tile server sees your IP address and the map area you view.
- Exchange rates: we fetch daily exchange rates from ExchangeRate-API to show amounts in another currency. We do not send any personal data to it.
We may change providers. If we add a new kind of provider, we will update this policy.
International transfers
Some of our providers, including our hosting and email providers, are based or store data outside Tanzania. This means personal data, including health data, may be transferred to and stored in other countries.
Sections 31 and 32 of the Act set conditions for transferring personal data outside Tanzania. We transfer data only as those sections and the regulations under them allow. We choose providers that commit by contract to protect the data and to use it only for our instructions. Where the regulations require approval or a permit from the Personal Data Protection Commission, we will seek it.
You can ask us for more information about transfers at privacy@afyarx.co.tz.
How long we keep data
The Act says we must not keep personal data longer than we need it for its purpose. These are our periods:
- Prescriptions, clinical notes, dispensing records and claims: 10 years after the last activity on the prescription, unless a law requires longer. Ministry of Health guidance on medical records suggests longer periods for some patient records. If a longer period applies to us, we follow it.
- Patient details: as long as we keep the prescriptions or requests linked to them.
- Prescriber verification documents and professional details: as long as we keep any prescription the prescriber signed, because they show who was allowed to prescribe.
- Audit logs, including portal access records: 10 years, the same as the prescriptions they relate to.
- Sign-in codes: each code expires after 5 minutes and can be used once. We delete code records within 30 days.
- Signed-in device records: deleted within 90 days after the session ends.
- SMS and email delivery logs: 12 months.
- Financial records, such as payments, payouts and the platform fee: at least as long as tax law requires.
- Organisation and insurer staff accounts: until the account is closed, plus 12 months. Records of what the account did stay in the audit log for the period above.
- Insurer member lists: until the insurer updates or removes them, or our agreement with the insurer ends.
- Directory visitor location: not stored.
- Backups: our nightly database backups are kept for 14 days and then deleted.
When the period ends, we delete the data or make it anonymous so it no longer identifies anyone.
How we protect data
We use these measures to protect personal data:
- All traffic between your device and our servers is encrypted with HTTPS.
- Prescribers sign each prescription with a PIN. We store only an argon2id hash of the PIN, never the PIN itself. After 5 wrong tries, PIN use is locked for 15 minutes.
- Sign-in uses a one-time code sent by SMS. Codes expire after 5 minutes, allow 5 attempts, and are stored only as a keyed hash.
- Sessions use short-lived access tokens. Refresh tokens are stored as hashes and replaced each time they are used. On a shared computer, the session ends when the browser tab closes.
- Organisation and insurer portal sessions last up to 12 hours. Suspending an organisation, or deactivating an insurer or a user, ends their sessions at once.
- Signing secrets for POS partners and insurers are encrypted at rest (AES-256-GCM). Their systems must sign every request.
- The clinical note is stored separately from the rest of the prescription and is never included in what organisations, insurers, pharmacies or patients receive.
- Pharmacies see a masked patient phone number.
- We keep an audit log of verification decisions, money movements and each time portal staff open a prescription.
- Profile photos are decoded and re-encoded when uploaded. This removes hidden data such as the GPS position where the photo was taken.
- Locations in the public directory are rounded to about 1 km.
- The database accepts connections only from the server it runs on. We limit how many requests each client can make.
- Our staff access personal data only when they need it to run the service, for example to verify a prescriber or answer a support request.
No system is completely secure. If you think your account or data is at risk, contact us at once at support@afyarx.co.tz.
Your rights
Under the Act you have these rights:
- Access (section 33): to ask whether we hold data about you and to get a copy of it.
- Rectification, blocking and erasure (section 38): to ask us to correct wrong data, block it, or delete it.
- Objection (section 35): to ask us to stop processing that is likely to cause you damage or distress.
- Automated decisions (section 36): to know about decisions made about you only by automated means. We do not make decisions with legal or similar effects about you by automated means alone. Checks shown during prescribing, and insurance membership checks, are aids: a person makes the decision.
- Compensation (section 37): to claim compensation if you suffer damage because we broke the Act.
We may not be able to delete data that the law requires us to keep, such as prescription and financial records. In that case we will tell you why and may block the data instead.
To use your rights, write to privacy@afyarx.co.tz. Tell us who you are and what you want. We may ask you to confirm your identity, for example with a code sent to your phone. A parent or caretaker can ask on behalf of a child. Patients can also ask the prescriber who wrote their prescription.
We will acknowledge your request within 72 hours. We will act on a request to correct or delete data within 14 days, and answer other requests as quickly as we can within the time the law allows.
Complaints
If you are unhappy with how we handle your data, please contact us first at privacy@afyarx.co.tz so we can try to fix it.
You also have the right to complain to the Personal Data Protection Commission (PDPC) of Tanzania at pdpc.go.tz.
If you live in another country where DukadawaRx is offered, you can also complain to the regulator there:
- Kenya: Office of the Data Protection Commissioner.
- Uganda: Personal Data Protection Office.
- Rwanda: National Cyber Security Authority.
- Nigeria: Nigeria Data Protection Commission.
- Ghana: Data Protection Commission.
- South Africa: Information Regulator.
- Zambia: Office of the Data Protection Commissioner.
- Malawi: Malawi Communications Regulatory Authority (MACRA).
- Ethiopia: the authority responsible under the Personal Data Protection Proclamation No. 1321/2024.
If there is a data breach
If a security breach affects personal data, we will act to contain it and find out what happened. We will notify the Personal Data Protection Commission without undue delay, as section 27(5) of the Act requires, and other regulators within the time their laws set.
If the breach is likely to harm you, we will also tell you, and explain what you can do to protect yourself.
Children
Patients may be children. Their details are usually given by a parent or caretaker, or by the prescriber treating them. SMS messages about a child's prescription go to the phone number given, which is usually the caretaker's. In the patient app, a caretaker can manage dependants registered under their phone.
We protect children's data in the same way as other health data. A parent or caretaker can use the child's rights on the child's behalf.
Prescribers, portal users and partners must be adults.
Emails from us
If you give us your email address, we will send a link to confirm it before we send anything else to it.
Summary and report emails are sent monthly by default. You can change this to weekly or turn them off in your settings. Every summary email has an unsubscribe link, and you can unsubscribe at any time.
If you turn off summaries, we may still send emails you need about your account or security.
Changes to this policy
We may update this policy when the service or the law changes. We will show the date of the latest version. If we make an important change, we will tell you in the app, by SMS or by email before it takes effect.
When you accept this policy or our terms, we record which version you accepted and when.