How PinKenya collects, uses, stores and shares your personal data, and what you can make us do about it. This notice is written against Kenya's Data Protection Act, No. 24 of 2019.
Last updated 4 October 2026
PinKenya is the data controller for the personal data described here. That means we decide why and how it is processed, and we are the ones answerable for it under the Act.
Section 18 of the Act says no one may act as a data controller or data processor unless registered with the Data Commissioner. PinKenya has not completed that registration yet. This page will carry the certificate number as soon as it is issued.
We only hold what the service actually needs.
The Act treats health status and health data as sensitive personal data. That covers anything you tell us about a condition, anything in a home care request, and every clinical note from a consultation.
We process it to provide the care you asked for, and for nothing else. We do not sell it, we do not use it for advertising, and we do not hand it to an employer, an insurer or anyone else without your consent or a court order.
Supabase. Hosting our database and files, and signing you in.
What it sees: Everything stored in your account, bookings and requests.
Where: Germany (eu-central-1).
Daily. Video consultations.
What it sees: Your video and audio during the call, the name shown on your video tile, your IP address and your device and browser details.
Where: A company based in the United States. We route the call through Daily's Cape Town servers in South Africa, so it leaves Kenya but stays on the continent. Calls are not recorded.
Paystack Payments Kenya Limited. Taking payment by M-Pesa, card or bank transfer.
What it sees: Your email address, the amount, and the phone number or card you pay with. Card numbers and M-Pesa PINs go to Paystack and never reach PinKenya.
Where: Incorporated in Kenya and licensed by the Central Bank of Kenya. It may store data with Amazon Web Services in Ireland, and the law requires it to keep transaction records for at least seven years.
Vercel. Running the website.
What it sees: Your IP address, your device and browser details, and the pages you open.
Where: A company based in the United States. Pages are served from its servers nearest to you, and the part that reads our database runs in Frankfurt, Germany.
Resend. Sending our emails: sign-up and password links, booking and payment updates.
What it sees: Your email address and the contents of the email, such as a booking time or the name of your doctor.
Where: A company based in the United States. PinKenya's emails are sent from its servers in Ireland.
Google. Signing in, only if you choose Continue with Google.
What it sees: Your email address, name and profile picture, which Google sends to us.
Where: United States and elsewhere, under Google's own privacy policy.
We do not sell your personal data. We do not share it with advertisers.
Our database and files are hosted by Supabase in Germany (eu-central-1). So your personal data is stored outside Kenya, and sections 25(h) and 48 of the Act apply to that transfer.
A video consultation also leaves Kenya: we route the call through Daily’s servers in Cape Town, South Africa, and Daily is a United States company. Paystack is a Kenyan company but may store payment data in Ireland. Each one is listed with what it sees in section 5.
We rely on what the Act allows: each transfer is necessary to perform our contract with you, whether that is storing your booking, connecting your call or taking your payment, and you are told about it here so it is not something you find out afterwards.
Section 26 of the Act gives you the right:
Section 38 also gives you the right to receive your data in a structured, commonly used, machine-readable format, and to have it sent to another provider.
Exercising any of these is free and we will answer as quickly as we can. We may ask you to confirm who you are first, so that nobody else can use these rights to get at your records.
Account data stays until you close your account. Home care and biomedical engineer requests are kept while they are being worked and for a reasonable period afterwards so we can answer questions about them. A provider’s licence and identity documents are kept while they are listed, so the check can be shown to have been made, and deleted when they leave.
Clinical records are the exception: a health provider is required by law to keep them for a set period, so a consultation note survives your account being closed. Paystack is also required by law to keep its own record of a payment for at least seven years, whatever we delete on our side. Everything else is deleted or anonymised once the purpose it was collected for has passed.
Closing your account. You can close it yourself from Your details. It is switched off at once and deleted 7 days later, so you can sign in and keep it if you change your mind. On that day we delete your login, your name, phone and address, the contact details in your requests, and any documents or photos you uploaded. Your consultation records, doctors’ notes, consent records and payment records are kept with your name removed, for the legal reasons above.
Access is controlled at the database itself, row by row, so a signed in user can reach their own records and not anyone else’s. Traffic is encrypted in transit. Provider phone numbers and email addresses are not published, and patient contact details are not readable by anonymous visitors.
If personal data is accessed by someone who should not have it and there is a real risk of harm to you, section 43 requires us to notify the Data Commissioner within 72 hours and to tell you in writing. We will.
An account is for people aged 16 and over. Sign-up asks for your age and stores it once; you cannot change it from your account afterwards. If you are under 16, a parent or guardian can request care for you from their own account, and the Act requires consent from them rather than from you.
Come to us first and we will try to fix it. If you are not satisfied, section 56 of the Act lets you take it straight to the regulator, and you do not need our permission to do so.
Office of the Data Protection Commissioner
Britam Towers, 12th Floor, Hospital Road, Upperhill, Nairobi
P.O. Box 30920-00100 GPO, Nairobi
Complaints: complaint@odpc.go.ke
Telephone: 020 780 1800
odpc.go.ke
Data protection requests: info@pinkenya.com
General enquiries: info@pinkenya.com
Ongata Rongai 00511, Kajiado County, Kenya
See also our terms, cookie policy and how we verify providers.