LyfeLine Nexus · Field EMS Platform

Privacy Policy

How LyfeLine Nexus handles the highly sensitive clinical data of field EMS professionals and their patients.

Effective: 14 June 2026 Last revised: 14 June 2026 Version: 3.0 Applies to: nexus.lyfelineservices.com

Who this policy applies to. This Privacy Policy governs the LyfeLine Nexus platform — a professional field operations tool provided exclusively to licensed emergency medical service providers, paramedics, medics, pharmacists, and their authorised support staff. Nexus is not a consumer product. If you are a patient, please refer to the MyLyfeLine Privacy Policy. For the complete LyfeLine group privacy policy, see lyfelineservices.com/legal/privacy-policy.

Nexus processes highly sensitive clinical data. Because Nexus is used at the point of emergency care, it processes patient vital signs, clinical assessments, prescription records, telemedicine sessions, and real-time location data. We apply heightened safeguards to all patient health data processed through Nexus, as detailed in this policy.

1. Data Controller

The data controller for personal data processed through Nexus is:

LyfeLine Technologies Ltd
Nairobi, Kenya
Privacy: privacy@lyfelineservices.com
DPO: dpo@lyfelineservices.com
Registered with the Kenya Data Protection Commissioner (ODPC)

Your employing EMS organisation (the "Subscriber Organisation") is a joint data controller for staff and patient encounter data managed within Nexus. The relationship is governed by a Data Processing Agreement (DPA) incorporated into the Nexus Subscription Agreement. The Subscriber Organisation is the clinical record holder for patient encounter records under the Kenya Health Act.

2. What Nexus Does

Nexus is the field-facing companion to the LyfeLine OPUS dispatch platform. It enables field EMS and medical responders to:

Nexus processes more sensitive clinical data than any other LyfeLine platform because it is used at the point of care. We apply the highest level of data protection controls to data processed through Nexus.

3. Categories of Personal Data We Process

CategorySpecific data elementsSource
Staff identityFull name, work email, badge/licence number, EMS certification level (EMT, paramedic, clinical officer, nurse, pharmacist), scope-of-practice flagsSubscriber Organisation (on invite)
Authentication credentialsCognito user ID, hashed password, session tokens, MFA configurationCollected at account setup / login
Role and access dataClinical role assignment, permissions, scope-of-practice restrictions, organisation membershipSubscriber Organisation assignment via OPUS admin console
Real-time staff locationHigh-precision GPS coordinates of field units during active duty shiftsDevice GPS while Nexus is open and duty status is active
Patient vital signsHeart rate, SpO2 (blood oxygen), blood pressure, respiratory rate, temperature, blood glucose, ECG trace segment, AVPU neurological scoreManually entered or device-connected during patient encounter
Patient encounter dataTriage category (START/SALT), chief complaint, mechanism of injury, physical examination findings, treatment administered, drug doses, transport destination, handoff summaryField responder data entry during encounter
Prescription recordsMedication name, dose, route of administration, batch number, date/time of administration, prescribing clinician ID, pharmacist co-sign ID, controlled substance schedule classification, administration confirmationResponder entry + pharmacist co-sign action
Telemedicine session dataSession start/end timestamps, clinician and patient/medic identifiers, session outcome note; audio/video encrypted in transit — not retained by LyfeLine unless Subscriber Organisation enables recordingSession participants during active consultation
PTT communication metadataCall duration, unit IDs, channel, timestamp; audio is not recorded or stored by LyfeLineAutomatically generated per PTT call
Session and device dataBrowser / device type, operating system, IP address, session durationCollected automatically on login
Audit logsTimestamps and descriptions of all clinical actions, prescription events, dispatch acknowledgements, and login eventsAutomatically generated per platform action

4. Location Tracking

When we track your location and why. Nexus tracks the real-time GPS location of field units while the application is in active use and your duty status is set to "on duty." Location data is shared with your OPUS dispatch centre to enable unit assignment, routing, and crew safety tracking. Location data is not collected when the app is closed, when you are not on an active duty assignment, or when your duty status is set to "off duty." You may disable location sharing at the operating system level; doing so will impair dispatch coordination features and must be reported to your supervisor as it may affect crew safety protocols.

GPS location history during duty shifts is retained for 12 months on a rolling basis and is accessible only to your Subscriber Organisation's administrators and to LyfeLine security engineers investigating a reported safety incident. Location data captured during a specific SOS event or patient encounter becomes part of the permanent incident record.

5. Legal Basis for Processing

Processing activityLegal basis (KDPA s.30)Notes
Staff authentication and account managementPerformance of contractEmployment + platform subscription; necessary to deliver platform access
Patient vital signs and clinical data entryVital interests (emergency medical care); legitimate interests of Subscriber Organisation in providing careEmergency care context overrides normal consent requirements
Real-time staff GPS location trackingLegitimate interests (dispatch coordination, crew safety); contractual necessityAssessed proportionate to emergency-response context; active duty only
Prescription and controlled substance recordsLegal obligation (Pharmacy and Poisons Board regulations); vital interests (patient safety)Permanent audit records required by Kenyan law
Telemedicine audio/video sessionsExplicit consent of the patientConsent obtained and documented by field responder before initiating session
Audit logging of all clinical actionsLegal obligation (Kenya Health Act); legitimate interests (clinical accountability)Mandatory under clinical record-keeping obligations
Analytics (pseudonymised response time events)Legitimate interestsPlatform improvement; no PHI included; data minimisation applied

6. Sensitive Health Data — Heightened Safeguards

Patient vital signs, clinical assessments, and prescription records are Special Category data under KDPA s.46. We apply the following additional safeguards:

We never sell, rent, license, or share patient health data, clinical records, or prescription records with advertisers, insurers, data brokers, or any commercial third party.

7. How We Use Your Data

8. Data Sharing

9. Third-Party Sub-Processors

Sub-processorPurposeData transmittedLocation
Amazon Web Services (AWS)Cloud compute (Lambda), database (DynamoDB), object storage (S3), identity (Cognito), CDN (CloudFront), monitoring (CloudWatch)All personal, clinical, and operational dataEU West 1 (Dublin, Ireland)
Twilio Inc.Outbound SMS — incident alerts, one-time passwords, patient notifications (where configured)Recipient phone number, message contentUnited States (SCCs in place)
PostHog Inc.Product analytics — pseudonymised staff usage events; no PHI transmittedSession events, feature interactions, error codesEU (GDPR-compliant region)
Amazon CloudFrontCDN delivery of Nexus web application assetsAnonymised access logs; no PHI in CDN layerGlobal edge (data origin: EU West 1)
OpenStreetMap / ESRI / CartoMap tile rendering for tactical map, navigation, and routingTile URL coordinates only — no patient names, IDs, or PHI transmitted to tile providersVaries — CDN edge (coordinates only)
Google Cloud (Vertex AI / Gemini)AI observation generation — vital sign trend analysis, triage suggestions, drug interaction flagsDe-identified clinical context (e.g., "SpO2 88%, HR 140, BP 80/50") — no patient names, IDs, or contact dataEU processing region (Vertex AI EU)

An up-to-date processor list is available on request at privacy@lyfelineservices.com. Subscriber Organisations will be notified at least 14 days before a new sub-processor that will process clinical data is engaged.

10. International Data Transfers

Patient and staff data is stored in AWS eu-west-1 (Dublin, Ireland). Where processing occurs outside Kenya and the EEA (specifically Twilio in the United States), we rely on:

Map tile requests to OpenStreetMap/ESRI/Carto contain coordinates only — no personally identifying information is transmitted to map tile providers.

11. Data Retention

Data typeRetention periodBasis
Active staff account dataDuration of employment within Subscriber Organisation + 30 days post-deactivationContract performance
Deactivated staff records3 years from deactivationAudit purposes; potential legal claims
Patient encounter / clinical records10 years from date of encounterKenya Health Act (Cap 241) minimum for clinical records
Prescription and controlled substance records10 years from dispense dateKenya Pharmacy and Poisons Board Act requirements
Audit logs (all clinical actions)7 yearsKenya health sector regulatory compliance; legal obligation
GPS duty-shift location history12 months rollingIncident reconstruction; crew safety investigations
GPS location during a specific incidentPermanent (part of incident record)Clinical record; legal obligation
Telemedicine session recordingsNot retained by LyfeLine unless Subscriber Organisation enables recording — if enabled, treated as clinical record (10 years)Clinical record obligation
PTT audioNot retained — relay-only architectureN/A
PTT call metadata90 daysSecurity; operational logs
Session authentication tokensRolling 24-hour expiry; revoked immediately on logoutSecurity
Authentication event logs90 daysSecurity; fraud detection
Analytics events (pseudonymised)12 months rollingLegitimate interests

At expiry, data is cryptographically purged from active databases and all backup stores within 30 days.

12. Security

13. Your Rights Under the Kenya Data Protection Act, 2019

As a data subject, you have the following rights under KDPA Part V. We will respond to verified requests within 30 calendar days:

To exercise your rights, contact your Subscriber Organisation administrator or email privacy@lyfelineservices.com.

14. AI Processing

Nexus may display AI-generated clinical observations generated from vitals data, triage inputs, or prescription context. All AI outputs:

15. Cookies and Local Storage

Nexus uses browser localStorage — not third-party tracking cookies — to persist your authentication session across page reloads. This is essential for clinical workflows; a page refresh during an active patient encounter must not log you out and interrupt care.

PostHog uses a first-party analytics cookie for pseudonymised usage event collection. No cross-site or advertising cookies are used. No patient data is transmitted to any analytics system.

16. Changes to This Policy

We will notify Subscriber Organisation administrators of material changes to this policy at least 14 days before they take effect, via email and in-app banner. The "Last revised" date at the top of this page always reflects the most current version. Previous versions are available on request at privacy@lyfelineservices.com.

17. Contact

Contact typeDetails
Privacy enquiriesprivacy@lyfelineservices.com
Data Protection Officerdpo@lyfelineservices.com
Security reportssecurity@lyfelineservices.com
Platformnexus.lyfelineservices.com
Full group privacy policylyfelineservices.com/legal/privacy-policy