LyfeLine Logo LyfeLine Back to Legal

Privacy Policy

How LyfeLine Technologies collects, protects, and uses your information across our entire ecosystem — MyLyfeLine, OPUS, and Nexus.

Contents

1. Introduction 2. Data Controller 3. Platform Scope 4. Data We Collect 5. Special Category Data 6. Legal Bases 7. How We Use Data 8. Emergency Sharing 9. Third-Party Processors 10. International Transfers 11. AI & Automated Decisions 12. Data Retention 13. Security 14. Your Rights 15. Children's Data 16. Cookies & Tracking 17. Breach Notification 18. Healthcare Compliance 19. KDPA Compliance 20. Third-Party Links 21. Policy Changes 22. Contact & Complaints

Effective: 14 June 2026  ·  Last Revised: 14 June 2026  ·  Version 3.0

Platform key used throughout this document:  MyLyfeLine Consumer emergency app  OPUS Professional dispatch platform  Nexus Field EMS platform. Sections that apply only to specific platforms are labelled accordingly. Platform-specific addenda are at OPUS Privacy and Nexus Privacy.

1. Introduction

LyfeLine Technologies Ltd ("LyfeLine", "we", "us", "our") is an emergency services technology company headquartered in Nairobi, Kenya, building infrastructure for emergency medical response across East Africa. We operate three platforms: MyLyfeLine, a consumer emergency application; LyfeLine OPUS, a professional emergency dispatch and operations management platform; and LyfeLine Nexus, a field EMS documentation and coordination platform for paramedics and clinical staff.

This Privacy Policy sets out, in full, how we collect, use, retain, share, and protect personal information across all three platforms and our corporate website. It explains your rights as a data subject and how to exercise them. We have written it to be readable — not to obscure what we do with your data behind legal jargon.

By creating an account, activating a service, or accessing any LyfeLine platform, you acknowledge that you have read and understood this policy. If you are a professional user whose access was provisioned by a Subscriber Organisation, your employing organisation has accepted our Data Processing Agreement on your behalf; this policy applies to you equally.

If you do not agree with any part of this policy, please discontinue use of our services and contact us at privacy@lyfelineservices.com to request deletion of your data.

2. Data Controller and Data Protection Officer

The primary data controller for all personal data processed across LyfeLine's platforms is:

LyfeLine Technologies Ltd
Nairobi, Kenya
General enquiries: hello@lyfelineservices.com
Privacy: privacy@lyfelineservices.com
Data Protection Officer: dpo@lyfelineservices.com
Security: security@lyfelineservices.com
Phone: +254 733 593 807

We are registered with the Office of the Data Protection Commissioner (ODPC) of Kenya and maintain a Data Processing Register as required by the Kenya Data Protection Act, 2019 (KDPA).

Joint controllership — professional platforms. For OPUS and Nexus, the Subscriber Organisation (the hospital, EMS provider, or emergency services operator that licences our professional platforms) is a joint data controller for the operational and staff data generated within its account. The respective obligations of LyfeLine and each Subscriber Organisation are set out in the Data Processing Agreement (DPA) that forms part of every Subscription Agreement. Where this policy and a Subscriber Organisation's own privacy policy conflict, the DPA governs for operational data; this policy governs for LyfeLine's own processing activities.

3. Scope and Platform Coverage

PlatformAccess pointPrimary usersCore function
MyLyfeLinemylyfe.app · iOS · AndroidGeneral public, individuals, familiesConsumer emergency SOS, health profile, ambulance dispatch, wearable health monitoring
OPUSapp.lyfelineservices.comDispatchers, org admins, hospital coordinators, LyfeLine staffB2B dispatch operations, fleet management, org administration, analytics, billing
Nexusnexus.lyfelineservices.comParamedics, medics, nurses, pharmacists, EMS crewsB2B field documentation, triage, vitals, prescription management, telemedicine, PTT
Corporate websitelyfelineservices.comVisitors, prospective customers, investorsMarketing, sales enquiries, public information

This policy covers all of the above. Product-specific addenda for OPUS and Nexus contain additional detail on professional platform data handling and are incorporated into this policy by reference.

4. Information We Collect

4.1 Information you provide directly

CategorySpecific data elementsApplies to
IdentityFull legal name, date of birth, gender, national ID / passport number, next-of-kin nameMyLyfeLine
Contact detailsMobile number, email address, home or work address, emergency contact name and numberAll platforms
Health profileBlood type, allergies and severity, chronic medical conditions, current medications and doses, vaccination records, surgical history, disability status, mental health disclosures (voluntary)MyLyfeLine
Account credentialsUsername / email used for login; password (irreversibly hashed using bcrypt — never stored in plaintext); MFA method and recovery codes; Cognito user pool identifierAll platforms
Professional informationClinical certification level (EMT, paramedic, clinical officer, nurse, pharmacist), licence number, scope-of-practice flags, employer name, employee / badge IDOPUS Nexus
Payment informationSubscription plan, billing address, M-Pesa / card payment reference; raw card numbers are processed by our PCI-DSS-certified payment processor and are never stored in LyfeLine systemsMyLyfeLine OPUS
User-generated contentNotes, care instructions, or messages you write within the platform (e.g., incident notes, support tickets, prescription comments)All platforms
Support communicationsEmails, chat messages, or call metadata from interactions with our support teamAll platforms

4.2 Information generated through your use of our platforms

CategorySpecific data elementsApplies to
Location dataHigh-precision GPS coordinates during active SOS or field-unit duty; route history; approximate city/region derived from IP for non-SOS useAll (scope varies by platform)
Vital signs (real-time)Heart rate, SpO2 (blood oxygen), blood pressure, respiratory rate, temperature, blood glucose, ECG trace, AVPU neurological scoreMyLyfeLine (wearable) Nexus (field entry)
Patient encounter recordsTriage category, chief complaint, mechanism of injury, interventions administered, drug doses, transport destination, handoff summary, receiving hospital recordNexus
Prescription recordsMedication name, dose, route, batch number, date/time of administration, prescribing clinician ID, pharmacist co-sign ID, controlled substance classificationNexus
Dispatch and incident dataIncident type and priority code, responding unit IDs, dispatch timestamp, ETA, resolution time, outcome classification, incident locationOPUS
Audit and activity logsLogin timestamps, IP address, user-agent string, actions performed (admin invites, data exports, role changes, prescription co-signs), API endpoints calledAll platforms
Telemedicine session dataStart/end timestamps, clinician and patient identifiers, session outcome note; audio/video stream encrypted in transit and not retained by LyfeLine unless Subscriber Organisation enables recordingNexus
PTT communicationsReal-time relay only — audio is not recorded or stored; call metadata (duration, unit IDs, channel) retained for 90 daysNexus
Fleet and vehicle dataVehicle ID, type, registration, GPS position, availability status, maintenance flagsOPUS Nexus

4.3 Information collected automatically

CategorySpecific data elements
Device informationDevice type and model, operating system and version, unique device identifiers, screen resolution, available memory
Network informationIP address, mobile carrier, network connection type (WiFi / 4G / 5G), approximate city derived from IP geolocation
Session behaviourPages and screens visited, features interacted with, time spent per screen, navigation paths, button taps, search queries within the platform
Performance and error dataCrash reports, ANR logs, API error codes, response times, failed authentication attempts
Wearable device dataPassively synced health metrics from paired Apple Watch, Wear OS, or Garmin device — only metrics you have explicitly enabled in the wearable app's privacy settings

4.4 Information we receive from third parties

  • Emergency services and hospitals: Post-incident clinical outcomes, receiving hospital records, ambulance run reports
  • Referring healthcare providers: Medical history, referral letters, lab results — only when you initiate a referral
  • Insurance partners: Eligibility verification, pre-authorisation reference numbers — only when you initiate a claim
  • Government identity services: Name and ID number verification via eCitizen / IPRS for KYC purposes, where required by regulation
  • Subscriber Organisation: Your role, permissions, employment status, and clinical certification — provided by your employer when they provision your account

5. Special Category and Sensitive Data

The following categories receive heightened protection under KDPA s.46:

CategoryWhy we process itAdditional safeguard
Health and medical dataCore to emergency response — enables safer pre-hospital careAES-256 encrypted at rest; access restricted to treating professionals and the data subject; never shared with advertisers or employers without explicit consent
Vital signs and biometric measurementsReal-time patient monitoring, clinical triage, AI-assisted early warningStored separately from identity data; accessible only during active incident or by the patient
Prescription and controlled substance recordsPharmacy Board compliance; patient safety audit trailPermanent audit record; pharmacist co-sign required for Schedule I–IV substances
Mental health informationWhere voluntarily disclosed for first-responder awarenessOnly surfaced to responding clinician during active SOS; excluded from aggregate analytics; never transmitted to employer or insurer
Real-time location during emergenciesNecessary to dispatch help to precise locationHigh-precision location collected only during active SOS or active duty; full history available only to you and authorised responders
Telemedicine audio and videoRemote clinical consultationEnd-to-end encrypted in transit; not retained by LyfeLine after session close unless Subscriber Organisation enables recording; patient consent required
Wearable-sourced biometricsPassive health monitoring for early warningProcessed with explicit, granular consent; revocable per-metric at any time

We do not sell, rent, license, or barter any personal or health data to third parties, data brokers, advertising networks, insurance underwriters, or employers for any commercial purpose.

6. Legal Bases for Processing

We process your personal data only where we have a lawful basis under KDPA s.30:

Processing activityLegal basisNotes
Creating and managing your user accountContract performanceNecessary to deliver the service you signed up for
Dispatching emergency services in response to an SOSVital interests; contract performanceOverriding life-safety purpose; does not require explicit consent at the moment of emergency
Storing your health profile for first-responder accessExplicit consent; vital interestsConsent given when completing your profile; vital interests applies when you cannot consent during an emergency
Clinical documentation — vitals, triage, care notesVital interests; legal obligationPatient care and mandatory clinical record-keeping under Kenya Health Act
Staff authentication and role-based access controlContract performance; legitimate interestsNecessary for platform security and compliance with role restrictions
Real-time GPS tracking of field units during active dutyLegitimate interests; contract performanceDispatch coordination, crew safety, incident routing
Audit logging of all privileged actionsLegal obligation; legitimate interestsKenya health regulatory compliance; internal security
Prescription and controlled substance recordsLegal obligation; vital interestsKenya Pharmacy and Poisons Board regulations; patient safety
Product analytics (pseudonymised events)Legitimate interestsPlatform improvement — no PHI transmitted
Marketing communicationsExplicit consentOpt-in only; unsubscribe link in every message
Subscription billing and payment processingContract performance; legal obligationProcessing payments and maintaining financial records
Telemedicine audio/video sessionsExplicit consentPatient consent obtained and recorded before every session
Wearable biometric syncingExplicit, granular consent per metric typeRevocable at any time in app settings
Compliance with court order or law enforcement requestLegal obligationWe will notify you where legally permitted before complying

7. How We Use Your Information

7.1 Emergency response MyLyfeLine

  • When you activate SOS, we simultaneously transmit your precise GPS location, pre-populated health profile (blood type, allergies, critical medications), and emergency contact list to the nearest available emergency unit and to your designated contacts
  • We display your health profile to the responding paramedic on their Nexus device before they arrive, enabling safer pre-hospital care without requiring you to be conscious or communicate
  • We route the nearest available and appropriately equipped unit to your location using real-time fleet tracking and traffic-aware routing with flood-risk avoidance
  • We create a permanent incident record linking the SOS event, the responding unit, the receiving hospital, and any vitals recorded during transport — accessible to you and your treating team for follow-up continuity

7.2 Platform operation and professional services OPUS Nexus

  • Authenticating staff and enforcing role-based access so that each user can access only features appropriate to their professional role and scope of practice
  • Powering the real-time tactical map, unit tracking, incident feeds, and WebSocket-based live data push for dispatchers and field units
  • Enabling the prescription co-sign workflow, pharmacy catalogue, controlled substance logging, and suspicious-activity monitoring
  • Providing hospital capacity, bed management, patient handoff, and care coordination tools
  • Processing subscription payments and generating billing reports and invoices for Subscriber Organisations

7.3 Safety, security, and fraud prevention

  • Monitoring for account takeover attempts, credential stuffing, and brute-force login attacks
  • Detecting anomalous prescription patterns that may indicate controlled substance diversion
  • Reviewing audit logs for unauthorised data access, privilege escalation, or suspicious admin actions

7.4 Analytics and service improvement

  • Analysing aggregate, pseudonymised response times and operational KPIs to improve system-wide EMS efficiency
  • Supporting anonymised public health research with Kenya health authorities — only under a signed research agreement and using non-recoverable aggregate data

8. Emergency Data Sharing

RecipientData sharedLegal basis
Responding EMS crew (Nexus)Your name, location, blood type, allergies, critical medications, emergency contacts, prior incident history relevant to the current emergencyVital interests
Receiving hospitalPre-alert: incident type, ETA, preliminary triage and vitals. Post-handoff: full encounter record as required for continuity of careVital interests; implied consent in seeking emergency care
Your emergency contactsYour name, real-time location, incident status, receiving hospital name and addressConsent (you configured these contacts)
OPUS dispatch centreUnit GPS, incident ID, patient triage category — sufficient for dispatch coordination, not full PHIContract performance; legitimate interests
Kenya National Ambulance Service / county dispatchIncident location and type only — for interoperability with national EMS networksLegal obligation; vital interests; public task
Law enforcementIncident location and type, in situations involving crime or imminent threat to public safetyLegal obligation
National Disaster Operations Centre (mass-casualty events)Aggregate incident volume and type — no individual patient dataLegal obligation under Kenya National Disaster Management Act

9. Third-Party Sub-Processors

Sub-processorRoleData categoryData location
Amazon Web Services (AWS)Cloud compute (Lambda), database (DynamoDB), object storage (S3), identity (Cognito), CDN (CloudFront), monitoring (CloudWatch)All personal and health dataEU West 1 (Dublin, Ireland)
Twilio Inc.Outbound SMS — emergency alerts, one-time passwords, appointment notificationsPhone numbers, message contentUnited States (SCCs in place)
InfiniReach (Kenya)Inbound SMS gateway — primary inbound SMS routingInbound phone number, message contentKenya
PostHog Inc.Product analytics — pseudonymised usage events; no PHI transmittedPseudonymised session eventsEU (GDPR-compliant region)
Google Cloud (Vertex AI / Gemini)AI clinical observation generation — vital sign trend analysis, triage suggestionsDe-identified vital sign patterns and clinical context; no patient names or IDsEU processing region
Anthropic (Claude)Secondary AI comprehension — complex clinical query handlingDe-identified clinical context; no directly identifying patient dataUnited States (SCCs in place)
ESRI / Carto / OpenStreetMapMap tile rendering for tactical map, navigation, and routingCoordinates only in tile URL parameters — no personal identifiers transmittedGlobal CDN
Payment processorSubscription and consumer plan payment processing (M-Pesa / card)Billing amount, payment reference; raw card numbers never stored by LyfeLineKenya / EU depending on method

An up-to-date list of all sub-processors is available on request by emailing privacy@lyfelineservices.com. We will notify Subscriber Organisations at least 14 days before adding a new sub-processor that will process their data.

10. International Data Transfers

Our primary data storage and compute region is AWS eu-west-1 (Dublin, Ireland). For processing involving sub-processors located outside Kenya and the EEA, we rely on:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission (2021 version) and acknowledged by the Kenya ODPC as a valid transfer mechanism
  • Data Processing Agreements with each sub-processor specifying data use restrictions, security obligations, retention periods, and deletion procedures
  • Data minimisation before transfer: All data sent to AI sub-processors is de-identified — patient names, ID numbers, contact details, and all direct identifiers are stripped before transmission

We conduct Transfer Impact Assessments (TIAs) annually for sub-processors in jurisdictions without an ODPC adequacy decision. You may request a copy of the relevant SCCs or TIA summaries by contacting our DPO at dpo@lyfelineservices.com.

11. AI and Automated Decision-Making

AI functionWhat it doesHuman oversight
Vital sign trend analysisIdentifies deteriorating trends and surfaces alerts to the attending medicMedic reviews and acts; alert labelled "AI observation aid — not a clinical diagnosis"
Triage category suggestionSuggests a START or SALT triage category based on vitals entered in the fieldMedic must confirm or override before category is recorded; suggestion never auto-accepted
Drug interaction flaggingCross-references prescribed medication against the patient's known medication listPrescribing clinician reviews flag and decides; flag is advisory, not a hard block
Route optimisationCalculates fastest ambulance route considering live traffic and real-time flood-risk zonesDriver and dispatcher make final routing decisions
Prescription anomaly detectionIdentifies statistical anomalies in controlled substance dispense volumesAnomalies flagged to LyfeLine compliance team; human review required before any action is taken
SOS routing (consumer)Selects the nearest available and most appropriately equipped unit for dispatchOPUS dispatcher can override unit assignment at any time

No automated decision that produces a legal or similarly significant effect on any individual is made without human review. You have the right to request human review of any AI-generated output that has affected you by contacting dpo@lyfelineservices.com.

12. Data Retention

Data typeRetention periodBasis
Consumer account profile (MyLyfeLine)Active account duration + 30 days after deletion requestContract performance; KDPA minimum
Emergency incident records7 years from incident dateKenya Health Act; potential civil legal claims
Patient encounter / clinical records (Nexus)10 years from date of encounterKenya Health Act minimum for clinical records
Controlled substance / prescription records10 years from dispense dateKenya Pharmacy and Poisons Board Act requirements
Active staff accountsDuration of employment within Subscriber OrganisationContract performance
Deactivated staff accounts3 years from deactivationAudit purposes; legal claims; regulatory compliance
Audit logs (all privileged actions)7 yearsKenya health sector regulatory compliance
GPS duty-shift location history12 months rollingIncident reconstruction; crew safety investigations
GPS location during an SOS eventPermanent (part of incident record)Clinical record; legal obligation
PTT audioNot retained — relay-only architecture; call metadata retained 90 daysOperational logs retained for security
Session authentication tokens24-hour active lifetime; revoked immediately on logoutSecurity
Analytics events (pseudonymised)12 months rollingLegitimate interests
Billing and invoice records7 yearsKenya Tax Procedures Act, 2015
Support communications3 years from resolutionLegitimate interests; potential legal claims

At expiry of any retention period, data is cryptographically purged from active databases and all backup stores within 30 days.

13. Security Measures

13.1 Technical safeguards

  • All data in transit encrypted with TLS 1.2 minimum; TLS 1.3 preferred and enforced for all API endpoints
  • All data at rest in DynamoDB and S3 encrypted with AES-256 using AWS-managed keys
  • Authentication via AWS Cognito: short-lived JWT access tokens (24-hour expiry), refresh token rotation, optional TOTP-based MFA
  • Role-based access control (RBAC) enforced at the Lambda API layer — client applications have no direct database access
  • API Gateway with WAF rules protecting against OWASP Top 10 attacks: SQL injection, XSS, path traversal, rate limiting
  • DynamoDB Point-in-Time Recovery (PITR) enabled on all critical tables; 35-day recovery window
  • CloudWatch alarms on 5XX rate, P95 latency, and authentication failure rate
  • Secrets stored in AWS Secrets Manager — never in source code or environment variables visible to client-side code

13.2 Organisational safeguards

  • Principle of least privilege: all LyfeLine engineers have the minimum production data access necessary for their specific role
  • No engineer has unsupervised, unlogged access to tables containing patient health data in production
  • All staff complete data protection and information security training on joining and annually thereafter
  • Independent penetration testing conducted before major releases and at least annually
  • Responsible disclosure programme at security@lyfelineservices.com

LyfeLine reserves the right to monitor and record all platform activity for security and audit purposes, and such records may be used as evidence in legal proceedings.

14. Your Data Protection Rights

Under the Kenya Data Protection Act, 2019 (Part V) you have the following rights. We will respond to all verified requests within 30 calendar days:

RightWhat it means for youHow to exercise itExceptions
Right of access (KDPA s.26)Obtain a copy of all personal data we hold about youEmail privacy@lyfelineservices.com with proof of identityWe may withhold information that would disclose another person's data or prejudice an ongoing investigation
Right to rectification (KDPA s.27)Request correction of inaccurate, incomplete, or out-of-date personal dataMost profile data: edit directly in the app. Clinical records: contact us — corrections logged alongside originalHistorical clinical records are annotated rather than altered to preserve audit integrity
Right to erasure (KDPA s.27)Request deletion of your personal data where retention is no longer justifiedEmail privacy@lyfelineservices.comClinical records, controlled substance logs, audit trails, and billing records cannot be erased during mandatory retention periods
Right to data portability (KDPA s.28)Receive your personal data in a structured, machine-readable format (JSON or CSV)Request via privacy@lyfelineservices.com — delivered within 30 daysApplies only to data you provided directly or generated through your own activity
Right to object (KDPA s.35)Object to processing based on legitimate interests, including product analyticsEmail privacy@lyfelineservices.com specifying the processing activityWe may continue processing where we can demonstrate compelling legitimate grounds
Right to withdraw consentWhere processing relies on your consent, withdraw at any time without retroactive effectIn-app toggles for each consent type; email privacy@lyfelineservices.comWithdrawal does not affect lawfulness of processing before withdrawal
Right not to be subject to solely automated decisionsRequest human review of any automated decision that significantly affects youEmail dpo@lyfelineservices.com with a description of the decisionNot applicable where safeguards are already in place
Right to complain (KDPA s.42)Lodge a complaint with the Kenya ODPC if you believe your rights have been violatedodpc.go.ke · info@odpc.go.keWe encourage you to contact us first — we will make every effort to resolve complaints before escalation

15. Children's Data

MyLyfeLine may be used by families to create emergency profiles for children. Our approach:

  • A parent or legal guardian must create, own, and manage any account associated with a child under 18
  • We do not intentionally collect personal data directly from unaccompanied children under 13
  • If we become aware that we have collected data from a child under 13 without verifiable parental consent, we will delete it without delay
  • We do not display advertising to users of any age

OPUS and Nexus are professional platforms for employed adults. Staff accounts for individuals under 18 are not permitted.

16. Cookies and Tracking Technologies

TypeTechnologyPurposeOpt-out
Strictly necessaryBrowser localStorage / sessionStoragePersisting your authentication session — essential for clinical workflows and emergency responseCannot be disabled; platform would not function
First-party analyticsPostHog JavaScript SDKFeature usage, error tracking, performance monitoring — pseudonymised; no PHI; no cross-site trackingContact privacy@lyfelineservices.com
Performance monitoringAWS CloudWatch RUM (where deployed)Real-user monitoring for latency and error ratesNot available for opt-out on professional platforms (required for SLA monitoring)

We do not use third-party advertising cookies, social media tracking pixels, or cross-site tracking technologies.

17. Data Breach Notification

In the event of a personal data breach, we will:

  1. Contain the breach and begin preliminary assessment within 24 hours of discovery
  2. Notify the Kenya ODPC within 72 hours of discovery where the breach is likely to pose a risk to individuals (KDPA s.43)
  3. Notify affected individuals directly by email and in-app notification without undue delay where the breach is likely to result in high risk — particularly where health data is involved
  4. For Subscriber Organisations: notify the designated administrator contact within 24 hours of discovery
  5. Provide a follow-up notification within 30 days detailing root cause, full scope, and remediation measures

18. Healthcare Regulatory Compliance

  • Kenya Health Act (Cap 241): Clinical records created via Nexus are subject to Health Act confidentiality and retention obligations. The Subscriber Organisation is the clinical record holder; LyfeLine holds records as a data processor. Clinical decisions remain the professional responsibility of the licensed clinician using the platform.
  • Medical Practitioners and Dentists Act (Cap 253): LyfeLine technology facilitates clinical documentation and coordination — it does not constitute the practice of medicine.
  • Pharmacy and Poisons Act (Cap 244): Prescription and controlled substance records in Nexus comply with Pharmacy and Poisons Board audit requirements. A permanent, tamper-evident co-sign audit trail is maintained for all Schedule I–IV substance dispenses.
  • National Coroners' Service Act: Incident records involving patient deaths may be required for coroner's inquiries. We will release records in response to a valid coroner's order or court subpoena.
  • Kenya National Disaster Management Act: In a declared national disaster, LyfeLine may share aggregate incident volume and type data with the National Disaster Operations Centre. No individual patient data is shared without a valid emergency disclosure order.

19. Kenya Data Protection Act, 2019 — Compliance Statement

  • ODPC registration: We are registered as both a data controller and a data processor with the Office of the Data Protection Commissioner
  • Data Protection Officer: Our DPO is accessible at dpo@lyfelineservices.com
  • Records of Processing Activities (ROPA): We maintain a complete ROPA documenting all processing activities as required by KDPA s.47
  • Data Protection Impact Assessments (DPIAs): We conduct DPIAs for all new processing activities involving health data at scale or automated profiling before deployment
  • Privacy by Design and Default: Data minimisation, storage limitation, purpose limitation, and security are built into our systems architecture
  • Staff Training: All LyfeLine staff complete KDPA awareness training on joining and annually thereafter

20. Third-Party Links

Our platforms and website may contain links to external sites — government services, hospital portals, partner organisations, or reference resources. This Privacy Policy applies solely to data collected and processed by LyfeLine Technologies Ltd. We are not responsible for the privacy practices of third-party sites.

21. Changes to This Privacy Policy

We review this Privacy Policy at least annually. For significant changes:

  • We will notify all registered users by email at least 14 days before the change takes effect
  • We will display a prominent in-app notification for the 14-day notice period
  • We will post the revised policy on this page with an updated "Last Revised" date and version number
  • For Subscriber Organisations: we will notify the designated administrator email on record

Previous versions of this Privacy Policy are available on request by emailing privacy@lyfelineservices.com.

22. Contact and Complaints

Contact typeDetails
General privacy enquiriesprivacy@lyfelineservices.com
Data Protection Officerdpo@lyfelineservices.com
Security incidents / vulnerability reportssecurity@lyfelineservices.com
Legal / regulatory correspondencelegal@lyfelineservices.com
Phone+254 733 593 807
PostLyfeLine Technologies Ltd, Nairobi, Kenya

Office of the Data Protection Commissioner (ODPC)
Nairobi, Kenya
www.odpc.go.ke
info@odpc.go.ke

Services

  • MyLyfeLine
  • LyfeLine Opus
  • LyfeLine Nexus

Enterprise

  • Contact Sales
  • Partners
  • Why LyfeLine

Platform Legal

  • OPUS Privacy
  • OPUS Terms
  • Nexus Privacy
  • Nexus Terms

Legal

  • Privacy Policy
  • Terms of Service
  • Legal Hub
  • Licenses

© 2026 LyfeLine Technologies Ltd. All rights reserved.