Who this policy applies to. This Privacy Policy governs the LyfeLine OPUS platform — a professional dispatch and operations management tool for licensed emergency operations centres, hospitals, and their authorised staff. OPUS is not a consumer product. If you are a patient, please refer to the MyLyfeLine Privacy Policy. For the complete LyfeLine group privacy policy, see lyfelineservices.com/legal/privacy-policy.
1. Data Controller
The data controller for personal data processed through OPUS is:
LyfeLine Technologies Ltd
Nairobi, Kenya
Privacy: privacy@lyfelineservices.com
DPO: dpo@lyfelineservices.com
Registered with the Kenya Data Protection Commissioner (ODPC)
Your employing organisation (the "Subscriber Organisation") is a joint data controller for the staff and operational data it manages within OPUS. The relationship between LyfeLine Technologies and each Subscriber Organisation is governed by a Data Processing Agreement (DPA) incorporated into the OPUS Subscription Agreement.
2. What OPUS Does
OPUS is a professional-grade web application that enables emergency operations centres and hospital administrations to:
- Coordinate ambulance dispatch, unit tracking, and incident management in real time
- Manage staff rosters, access permissions, and role assignments across the organisation
- View and manage patient care handoff data from field responders (Nexus platform)
- Monitor organisation-level analytics, operational metrics, and billing
- Administer prescription co-sign workflows and controlled substance oversight
- Receive live fleet status, unit positions, and incident feeds via WebSocket push
OPUS operates in a business-to-business (B2B) context. All users are professional staff acting within the scope of their employment. OPUS processes no consumer personal health data; brief operational patient references (location, incident type, assigned unit) are received from the Nexus platform to coordinate care, and are treated as Protected Health Information (PHI).
3. Categories of Personal Data We Process
| Category | Specific data elements | Source |
|---|---|---|
| Staff identity | Full name, work email, employee / badge ID, role title | Subscriber Organisation (on invite) |
| Authentication credentials | Cognito user ID, hashed password, session tokens, MFA configuration | Collected at account setup / login |
| Role and access data | Staff role (dispatcher, org admin, clinical coordinator, LyfeLine admin), permission set, org membership, scope-of-access flags | Subscriber Organisation assignment via admin console |
| Operational activity | Incidents dispatched, unit assignments made, dispatch timestamps, resolution times, actions taken in the console | Generated during platform use |
| Audit logs | Timestamps, IP addresses, user-agent strings, and descriptions of all admin operations — user invites, role changes, data exports, prescription co-signs, billing access | Automatically generated per platform action |
| Session and device data | Browser type, operating system, IP address, session duration, screen resolution | Collected automatically on login |
| Billing data | Organisation subscription tier, seat count, usage metrics, invoice history, payment references | Platform billing system |
| Patient encounter references (operational only) | Incident IDs, triage category, unit assigned, receiving hospital — sufficient for dispatch coordination; full patient medical records are not stored in OPUS | Received from Nexus platform integration |
| Prescription co-sign records | Prescribing clinician ID, pharmacist co-sign ID, medication and dose, controlled substance classification, co-sign timestamp | Generated via prescription co-sign workflow |
Patient data in OPUS. OPUS dispatchers receive brief operational patient references (location, incident type, assigned unit) to coordinate care — not full medical records. All patient encounter references received from Nexus are treated as PHI and processed under the Kenya Health Act (Cap 241) and the clinical data protection obligations of the Subscriber Organisation.
4. Legal Basis for Processing
| Processing activity | Legal basis (KDPA s.30) | Notes |
|---|---|---|
| Staff authentication and account management | Performance of contract | Employment + platform subscription; necessary to deliver platform access |
| Operational dispatch and incident coordination | Legitimate interests; vital interests of patients | Coordinating emergency medical response; assessed proportionate |
| Audit logging of all privileged administrative actions | Legal obligation; legitimate interests | Kenya health sector regulatory compliance; internal security and accountability |
| Prescription co-sign workflow | Legal obligation; vital interests | Kenya Pharmacy and Poisons Board requirements; patient safety |
| Analytics and platform improvement (pseudonymised) | Legitimate interests | Service quality improvement; data minimisation applied; no PHI included |
| Billing and licensing management | Performance of contract | Subscription agreement obligations; Kenya Tax Procedures Act record-keeping |
| Security incident detection and response | Legitimate interests; legal obligation | Protecting platform integrity and patient data from unauthorised access |
5. How We Use Your Data
- Platform access. To authenticate your identity, establish your session, and present the features and data appropriate to your assigned role and organisation
- Dispatch operations. To display the real-time tactical map, unit status, and incident feeds that enable dispatchers to coordinate emergency response
- Security and compliance. All privileged actions are logged to an immutable, tamper-evident audit trail retained for 7 years. This protects patients, staff, and the organisation
- Prescription oversight. Controlled substance dispense requests from Nexus field medics are routed through OPUS for pharmacist co-sign. Co-sign records are permanent audit entries
- Analytics. Aggregated, pseudonymised usage events (feature interactions, response time metrics) are sent to PostHog. No PHI is included in analytics events
- Support. Staff email and session data may be reviewed by LyfeLine support engineers to diagnose technical issues at your organisation's written request
- Notifications. Operational alerts (incident triggered, unit assigned, prescription co-sign required) are delivered via in-app WebSocket push and, where configured, SMS via Twilio
- Billing. Usage metrics and seat counts are used to generate invoices and usage reports for your organisation's administrator
6. Data Sharing
We share data only where there is a clear operational, legal, or contractual justification:
- Within OPUS to authorised roles: Dispatchers see unit positions and incident summaries; org admins see staff rosters and billing; LyfeLine support staff see audit logs and session metadata only when responding to a reported incident
- With Nexus field units: Incident assignments, routing instructions, and patient handoff references are shared with assigned Nexus units in real time
- With receiving hospitals: Patient triage category and ETA — pre-alert only; detailed clinical records are shared by the treating Nexus medic directly
- With your Subscriber Organisation: Organisation administrators have access to all staff records, audit logs, and operational data within their organisation's account
- With law enforcement or regulators: Where required by a valid court order, subpoena, or regulatory demand. We will notify you where legally permitted before complying
- In connection with a business transfer: If LyfeLine is acquired, merged, or subject to a business transfer, data may be transferred to the successor entity subject to equivalent data protection obligations
We never sell, rent, or share your personal data or patient encounter references with advertising networks, data brokers, or insurance underwriters.
7. Third-Party Sub-Processors
| Sub-processor | Purpose | Data transmitted | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud compute (Lambda), database (DynamoDB), object storage (S3), identity (Cognito), CDN (CloudFront), monitoring (CloudWatch) | All personal and operational data at rest and in compute | EU West 1 (Dublin, Ireland) |
| Twilio Inc. | Outbound SMS — incident alerts, one-time passwords, co-sign notifications | Recipient phone number, message content | United States (SCCs in place) |
| PostHog Inc. | Product analytics — pseudonymised staff usage events; no PHI transmitted | Session events, feature interactions, error codes | EU (GDPR-compliant region) |
| Amazon CloudFront | CDN delivery of the OPUS web application assets | Anonymised access logs; no personal data in CDN origin | Global edge (data origin: EU West 1) |
| Google Cloud (Vertex AI / Gemini) | AI observation generation — where AI features are active in dispatch or co-sign workflows | De-identified operational context; no staff names, IDs, or PHI | EU processing region (Vertex AI EU) |
All sub-processors are bound by Data Processing Agreements requiring data protection standards equivalent to or exceeding the KDPA. An up-to-date processor list is available on request at privacy@lyfelineservices.com. Subscriber Organisations will be notified at least 14 days before a new sub-processor is engaged to process their data.
8. International Data Transfers
Your personal and operational data is stored in AWS eu-west-1 (Dublin, Ireland). Data processing by Twilio and Google Cloud AI that occurs outside Kenya and the EEA is covered by:
- Standard Contractual Clauses (SCCs) — 2021 European Commission version, recognised by the Kenya ODPC as providing adequate safeguards
- Data minimisation: All data sent to AI sub-processors is de-identified before transmission
- Annual Transfer Impact Assessments (TIAs) for sub-processors in jurisdictions without an ODPC adequacy decision
You may request copies of applicable SCCs by contacting our DPO at dpo@lyfelineservices.com.
9. Data Retention
| Data type | Retention period | Basis |
|---|---|---|
| Active staff account data | Duration of employment within Subscriber Organisation + 30 days post-deactivation | Contract performance |
| Deactivated / revoked staff records | 3 years from revocation date | Audit purposes; potential legal claims |
| Audit logs (all privileged actions) | 7 years | Kenya health sector regulatory compliance; legal obligation |
| Incident and dispatch operational records | 7 years | Clinical record obligation; potential civil legal claims |
| Prescription co-sign records | 10 years from co-sign date | Kenya Pharmacy and Poisons Board Act requirements |
| Session authentication tokens | Rolling 24-hour expiry; revoked immediately on logout | Security |
| Authentication event logs | 90 days | Security; fraud detection |
| Analytics events (pseudonymised) | 12 months rolling | Legitimate interests — proportionate to improvement purpose |
| Billing records | 7 years | Kenya Tax Procedures Act, 2015 |
At expiry, data is cryptographically purged from active databases and all backup stores within 30 days.
10. Security
- All data in transit encrypted with TLS 1.2 minimum (TLS 1.3 preferred and enforced for all API endpoints)
- All data at rest in DynamoDB and S3 encrypted with AES-256 using AWS-managed keys
- Authentication via AWS Cognito with short-lived JWT access tokens (24-hour expiry) and refresh token rotation
- Role-based access control (RBAC) enforced at the Lambda API layer — client applications have no direct database access
- API Gateway with WAF rules protecting against OWASP Top 10 attacks
- DynamoDB Point-in-Time Recovery (PITR) enabled on all critical tables; 35-day recovery window
- Immutable audit trail: all privileged admin actions written to a tamper-evident append-only log
- Secrets stored in AWS Secrets Manager — never in source code or client-accessible environment variables
- Security incidents reported to affected Subscriber Organisations within 24 hours of discovery
11. Your Rights Under the Kenya Data Protection Act, 2019
As a data subject, you have the following rights under KDPA Part V. We will respond to verified requests within 30 calendar days:
- Right of access (s.26): Request a copy of personal data we hold about you — including your account metadata, role history, and audit log entries relating to your account
- Right to rectification (s.27): Request correction of inaccurate or incomplete personal data. Contact your Subscriber Organisation admin for profile data; contact us for audit-level metadata
- Right to erasure (s.27): Request deletion where no overriding legal basis for retention exists. Audit logs, prescription co-sign records, and billing records cannot be erased during mandatory retention periods
- Right to data portability (s.28): Receive your personal data in a structured, machine-readable format (JSON or CSV)
- Right to object (s.35): Object to processing based on legitimate interests, including product analytics
- Right to restrict processing (s.36): Request that we limit use of your data while accuracy or legal basis is disputed
- Right to lodge a complaint (s.42): Lodge a complaint with the Kenya ODPC at odpc.go.ke · info@odpc.go.ke
To exercise your rights, contact your Subscriber Organisation administrator or email privacy@lyfelineservices.com.
12. Cookies and Local Storage
OPUS is a progressive web application. We use browser localStorage and sessionStorage — not third-party tracking cookies — to persist your authentication session across page reloads. This is essential for dispatcher workflows; a page refresh during an active incident should not log you out.
PostHog uses a first-party analytics cookie for usage event collection. No cross-site or advertising cookies are used. No user data is transmitted to third-party advertising networks.
13. AI Processing
OPUS may display AI-generated observations derived from incident data, operational patterns, or prescription volume analysis. All AI outputs:
- Are labelled "AI observation aid — not a clinical diagnosis"
- Are generated from de-identified operational context — no staff names, patient IDs, or direct personal identifiers are transmitted to AI sub-processors
- Are advisory only — no AI output automatically triggers any action, access change, or clinical decision without human review
- Are generated by Google Gemini (primary) and Anthropic Claude (secondary), both bound by sub-processor DPAs with data use restrictions
14. Changes to This Policy
We will notify Subscriber Organisation administrators of material changes to this policy at least 14 days before they take effect, via email and in-app banner. The "Last revised" date at the top of this page always reflects the most current version. Previous versions are available on request at privacy@lyfelineservices.com.
15. Contact
| Contact type | Details |
|---|---|
| Privacy enquiries | privacy@lyfelineservices.com |
| Data Protection Officer | dpo@lyfelineservices.com |
| Security reports | security@lyfelineservices.com |
| Platform | app.lyfelineservices.com |
| Full group privacy policy | lyfelineservices.com/legal/privacy-policy |