Data Protection
Understanding your data rights and how we protect your personal information.
Last Updated: January 1, 2026
1. Overview
OnLocum is committed to protecting your personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Kenya Data Protection Act 2019.
This Data Protection Policy explains your rights regarding your personal data and how we fulfill our obligations as a data controller.
Applicable Regulations
- General Data Protection Regulation (GDPR) - EU
- Kenya Data Protection Act 2019
- African Union Convention on Cyber Security and Personal Data Protection
2. Data Controller
OnLocum Limited is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal data.
3. Legal Basis for Processing
We process your personal data only when we have a valid legal basis. Under GDPR and Kenya Data Protection Act, these include:
3.1 Consent
You have given clear consent for us to process your personal data for a specific purpose (e.g., marketing communications).
3.2 Contract Performance
Processing is necessary to perform a contract with you (e.g., providing healthcare staffing services).
3.3 Legal Obligation
Processing is necessary to comply with the law (e.g., tax records, regulatory reporting).
3.4 Legitimate Interests
Processing is necessary for our legitimate interests or those of a third party, provided your rights don't override those interests (e.g., fraud prevention, platform security).
3.5 Vital Interests
Processing is necessary to protect someone's life (e.g., emergency medical services coordination).
4. Your Data Rights
Under GDPR and Kenya Data Protection Act 2019, you have the following rights regarding your personal data:
4.1 Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of your request.
4.2 Right to Rectification
You have the right to request correction of inaccurate personal data or completion of incomplete data.
4.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose.
4.4 Right to Restrict Processing
You have the right to request that we limit how we use your data in certain circumstances.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
4.6 Right to Object
You have the right to object to processing of your personal data in certain circumstances, including direct marketing.
4.7 Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of these rights, please contact our Data Protection Officer at privacy@onlocum.com. We will respond within 30 days.
5. International Data Transfers
OnLocum is operated from Kenya. Our cloud infrastructure is hosted outside Kenya, so your data is transferred abroad in the ordinary course of running the service. Where that happens, we rely on the following safeguards:
- Processor agreements incorporating Standard Contractual Clauses: Our infrastructure providers operate under published data processing agreements that incorporate the EU Standard Contractual Clauses. Where we do not yet hold a signed counterpart, we rely on the provider's published terms, and obtaining executed copies is a tracked action.
- Minimisation before transfer: Labelled patient identifiers are stripped from the text of AI-assisted requests before they leave the system, and our transactional email is designed not to carry patient identifiers. This applies to text: identifiers embedded in an uploaded image are not removed by it.
- Encryption: Database backups held outside Kenya are encrypted, and data is encrypted in transit throughout.
Where your data is hosted
Our application servers and primary database run on DigitalOcean in India, with encrypted backups in DigitalOcean Spaces in Singapore and a client-side-encrypted copy on Google Drive; our operations agents run on DigitalOcean in Frankfurt. Transactional email is delivered through Amazon SES in Mumbai. Cloudflare provides DNS, CDN, and TLS termination, and Vercel hosts our web front ends. AI-assisted features send content to external AI providers hosted outside Kenya; this covers billing and operations as well as clinical work, more than one provider is configured, and not every one of those requests is de-identified. We do not claim that no personal data leaves Kenya.
6. Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
6.1 Technical Measures
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access control (RBAC) limiting data access
- Multi-Factor Authentication: Required for administrative access
- Security Monitoring: 24/7 intrusion detection and logging
- Vulnerability Scanning: Regular automated security scanning
6.2 Organizational Measures
- Employee Training: Regular data protection training for all staff
- Data Processing Agreements:Reliance on each provider's published data processing terms; executed counterparts are a tracked action, not yet complete
- Privacy by Design: Data protection built into new features
- Access Reviews: Quarterly review of data access permissions
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach is likely to result in a high risk
- Document the breach, its effects, and remedial action taken
Supervisory Authorities
- Kenya: Office of the Data Protection Commissioner (ODPC)
- EU: Relevant EU Data Protection Authority
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account Data | Account lifetime + 1 year | Contract, Legal obligation |
| Shift/Trip History | 5 years | Legal obligation (tax) |
| Payment Records | 7 years | Legal obligation (audit) |
| Communication Logs | 2 years | Legitimate interest |
| Location Data | 30 days | Contract, Legitimate interest |
| Marketing Preferences | Until consent withdrawn | Consent |
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee compliance with data protection laws and handle your data protection inquiries.
OnLocum Data Protection Officer
10. Complaints
If you are unhappy with how we have handled your personal data or believe we have not complied with data protection law, you have the right to lodge a complaint with a supervisory authority.
Kenya
Office of the Data Protection Commissioner (ODPC)
Website: www.odpc.go.ke
Email: info@odpc.go.ke
European Union
If you are in the EU, you can contact your local Data Protection Authority. A list is available at European Data Protection Board.
Internal Complaints
We encourage you to contact us first at privacy@onlocum.com. We will investigate your complaint and respond within 30 days.