← Home
Legal Last updated: April 17, 2026

Privacy Notice

This notice describes how Thamani Dawa collects, uses, and protects your personal information when you use our pharmacy management platform.

Summary of Key Points

  • What we collect. Account credentials, pharmacy/lab operational data you enter, usage logs, and device information.
  • Sensitive data. We do not process sensitive personal information such as health records beyond what you as a licensed operator explicitly enter for dispensing and lab purposes.
  • Third parties. We do not sell your data. We share only with sub-processors required to operate the service (hosting, email, analytics).
  • Your rights. Depending on your location you may access, correct, or delete your data. Submit a request at privacy@example.com.

Table of Contents

  1. 1 What information do we collect?
  2. 2 How do we process your information?
  3. 3 What legal bases do we rely on?
  4. 4 When and with whom do we share your information?
  5. 5 Do we use cookies and other tracking technologies?
  6. 6 How long do we keep your information?
  7. 7 How do we keep your information safe?
  8. 8 Do we collect information from minors?
  9. 9 What are your privacy rights?
  10. 10 Controls for Do-Not-Track features
  11. 11 Do Kenya residents have specific rights?
  12. 12 Do we make updates to this notice?
  13. 13 How can you contact us about this notice?

1

What Information Do We Collect?

In Short: We collect information you provide directly, information generated automatically when you use the platform, and certain device/network metadata.

Information you provide to us

We collect personal information that you voluntarily provide to us when you register for an account, use features of Thamani Dawa, or contact us for support. This includes:

  • Account & identity: Full name, email address, job title, and role (admin, pharmacist, lab technician) within your organisation.
  • Authentication data: Hashed passwords and 4-digit PIN credentials used for PIN-gated dispensing and verification actions.
  • Operational data: Patient visit records, prescription items, lab orders, batch numbers, GS1 barcodes, dispense logs, stock levels, and other pharmacy/lab data you enter as part of your normal workflow. This data belongs to your organisation and is processed on your behalf as a data processor.
  • Communications: Messages you send to our support team or via email.

Information collected automatically

When you access the platform, we automatically collect certain technical information:

  • Log data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps.
  • Device data: Device identifiers, screen resolution, and language preferences.
  • Performance & error telemetry: Aggregated crash reports and performance metrics to help us improve stability.
2

How Do We Process Your Information?

In Short: We process your information to provide, improve, and secure the Thamani Dawa pharmacy management platform.

Specifically, we process your data to:

  • Create and manage your account and your organisation's workspace.
  • Deliver the core features of the platform: GS1 barcode scanning, dispensing workflows, lab order management, prescription tracking, and multi-site stock visibility.
  • Generate audit trails required by the Kenya Pharmacy and Poisons Board for controlled substances.
  • Send transactional emails (account setup, invite links, password resets).
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with applicable law including the Kenya Data Protection Act 2019.
  • Improve the platform using anonymised, aggregated usage analytics.
4

When and With Whom Do We Share Your Information?

In Short: We do not sell your data. We share it only with trusted sub-processors and when legally required.

  • Cloud infrastructure. Our hosting provider stores data on servers located in the European Union or Africa (where available). All sub-processors are bound by data processing agreements.
  • Email delivery. Transactional emails are sent through a third-party email service provider. Only your email address and the content of the specific email are shared for this purpose.
  • Error monitoring. Anonymised crash reports may be processed by an error-tracking service to help us diagnose and fix bugs.
  • Legal requirements. We may disclose information where required by law, court order, or to protect the rights and safety of Thamani Dawa, our users, or the public.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
5

Do We Use Cookies and Other Tracking Technologies?

In Short: We use session cookies for authentication and security. We do not use advertising or cross-site tracking cookies.

Thamani Dawa places a single, HTTP-only session cookie on your browser when you log in. This cookie:

  • Maintains your authenticated session and multi-site context.
  • Is flagged Secure and HttpOnly and cannot be read by JavaScript.
  • Expires when you log out or after a period of inactivity.

We do not use third-party advertising cookies, fingerprinting technologies, or pixel trackers. You can disable cookies in your browser settings, but this will prevent you from logging in.

6

How Long Do We Keep Your Information?

In Short: We keep your information for as long as necessary to provide the service and comply with legal obligations.

Specifically:

  • Account data is retained for the duration of your organisation's subscription and for up to 90 days after account deletion (to allow for recovery).
  • Pharmacy operational records (prescriptions, dispense logs, controlled drug registers) are retained for a minimum of 5 years in line with Kenya Pharmacy and Poisons Board requirements.
  • Lab order data is retained for a minimum of 3 years from the date of the test.
  • Log data is retained for 12 months for security and debugging purposes.
7

How Do We Keep Your Information Safe?

We implement the following technical and organisational safeguards:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Passwords are hashed using bcrypt; PINs are stored hashed and never transmitted in plaintext.
  • Access to sensitive dispensing and verification actions is protected by a secondary 4-digit PIN gate.
  • Role-based access control (admin, pharmacist, lab technician) limits what each user can see and do.
  • Regular automated backups with point-in-time recovery.
  • CSRF protection and HTTP security headers on all requests.

No system is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@example.com.

8

Do We Collect Information from Minors?

Thamani Dawa is a B2B healthcare platform for licensed pharmacy and laboratory operators. We do not knowingly collect personal data from individuals under the age of 18 for account registration. Patient data entered into the system by licensed operators may relate to minors and is subject to applicable healthcare privacy law and your organisation's own data protection policies. If you believe we have inadvertently collected personal data from a minor in error, contact us at privacy@example.com.

9

What Are Your Privacy Rights?

In Short: Depending on your location, you have rights over your personal data including access, correction, deletion, and portability.

Under the Kenya Data Protection Act 2019 and GDPR (where applicable), you may:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your account and associated personal data, subject to legal retention requirements.
  • Port your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent for any consent-based processing at any time.

To exercise any of these rights, email privacy@thamanidawa.com. We will respond within 30 days. Note that some requests may be limited where retention is required by law (e.g. pharmacy audit records).

10

Controls for Do-Not-Track Features

Some browsers and mobile operating systems include a Do-Not-Track ("DNT") feature that signals your preference not to be tracked across websites. Because there is no agreed-upon standard for how to interpret DNT signals, Thamani Dawa does not currently respond to DNT browser signals. However, because we do not conduct cross-site behavioural tracking or advertising, DNT settings do not materially affect how we process your data.

11

Do Kenya Residents Have Specific Privacy Rights?

Yes. Kenya residents have the rights listed in Section 9 above, derived from the Kenya Data Protection Act 2019 (DPA) and enforced by the Office of the Data Protection Commissioner (ODPC). In addition:

  • You have the right to lodge a complaint with the ODPC at odpc.go.ke if you believe your data rights have been violated.
  • We have appointed an internal Data Protection Officer. You may contact them at privacy@thamanidawa.com.
  • Cross-border transfers of data outside Kenya are conducted only to countries with adequate data protection frameworks or under Standard Contractual Clauses.
12

Do We Make Updates to This Notice?

We may update this Privacy Notice from time to time to reflect changes in law, our practices, or the features of the platform. The updated version will be indicated by a revised "Last updated" date at the top of this page. If we make material changes, we will notify you by email or through a prominent notice within the platform. Your continued use of Thamani Dawa after any changes constitutes your acceptance of the revised notice.

13

How Can You Contact Us About This Notice?

If you have questions, concerns, or requests regarding this Privacy Notice or your personal data, please reach out to us:

Thamani Dawa

Nairobi, Kenya
Phone: +254 799 999 999
Email: privacy@example.com

← Back to Thamani Dawa Back to top ↑