Statutory Privacy StatementVersion 2026.2

Privacy Policy

Effective Date: January 1, 2026 • Last Revised: March 15, 2026

Governing Legal & Regulatory Frameworks
Act 843 (Ghana)
Data Protection Act
EU GDPR & UK GDPR
Arts. 6, 9 & 28
HIPAA & HITECH
Security & PHI Rules
NDPA & Malabo
Pan-African Privacy

1. Introduction and Overview

Curvia Care ("Company", "we", "us", or "our"), operated by Kister Inc, provides cloud and on-premise Electronic Health Record (EHR) systems, hospital management software, clinic operations, and diagnostic management solutions across Africa.

This Privacy Policy is designed to comply with applicable data protection legislation worldwide, including:

  • Ghana Data Protection Act, 2012 (Act 843);
  • Nigeria Data Protection Act (NDPA, 2023);
  • General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR) and UK GDPR;
  • Health Insurance Portability and Accountability Act (HIPAA) security standards governing Protected Health Information (PHI);
  • The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention).

Because healthcare data is among the most sensitive categories of personal information ("Special Category Data" under GDPR Art. 9 and Section 37 of Act 843), we enforce the highest administrative, technical, and physical safeguards in the industry.

2. Legal Roles: Data Controller vs. Data Processor

Under modern data protection law, legal obligations differ depending on whether an organization acts as a Data Controller (deciding the purposes and means of processing) or a Data Processor (processing data strictly on behalf of the controller).

Curvia Care as Data Controller

We act as the Data Controller with respect to:

  • Facility administrator, physician, and staff registration credentials.
  • Subscription contracts, quotation details, and payment histories.
  • Sales inquiries, website lead captures, and AI chatbot conversations.
  • Website telemetry, performance monitoring, and authorized cookie data.
Curvia Care as Data Processor (Business Associate)

We act as a Data Processor on behalf of the Healthcare Facility (Hospital, Clinic, Pharmacy, Laboratory), which is the Data Controller for:

  • All Patient Health Information (PHI) and clinical records.
  • Diagnostic test orders, medical prescriptions, and doctor consultation notes.
  • Patient billing, national health insurance claims (e.g. NHIS), and demographics.

Patients wishing to access, correct, or delete their hospital records should contact their healthcare provider directly. We assist providers in executing those requests.

3. Lawful Bases for Processing Personal Data

In accordance with Section 18 of Act 843 and Article 6 of the GDPR, we process personal data only when there is a recognized lawful basis:

  • Contractual Necessity: To fulfill our service agreement with your medical facility, provision user accounts, license EHR modules, process invoices, and provide continuous technical support.
  • Legal Obligation: To comply with statutory requirements under healthcare laws, national medical records retention directives, tax authorities, and anti-fraud regulations.
  • Vital Interests:In critical emergency healthcare scenarios where access to a patient's medical history (allergies, blood type, chronic diagnoses) is required to protect human life.
  • Legitimate Interests: To detect security threats, prevent unauthorized access to patient records, troubleshoot server stability, and enhance clinical software performance, provided these interests do not override individual fundamental rights.
  • Explicit Consent: Where required by law for optional cookies, direct marketing communications, or specific clinical research integrations authorized by patients.

4. Categories of Data Collected & Processed

We maintain an exhaustive, itemized disclosure of every single database field, table, and data asset we save. For full technical details, please see our dedicated Data Transparency & Retention Policy.

A. Healthcare Staff & Administrator Account Data
Full name, professional email, phone number, clinic name, facility type, physical address, clinical role (Doctor, Nurse, Pharmacist, Lab Tech, Billing, Admin), login timestamps, and encrypted access credentials.
B. Patient Health Information (PHI) / Clinical EHR Records
Patient identifiers (name, DOB, sex, national health insurance number, emergency contacts), consultation notes, vital signs, ICD-10 diagnostic codes, electronic prescriptions, pharmacy dispensary records, lab test results, radiology imaging metadata, and inpatient ward admission logs.
C. Financial & Subscription Information
Subscription plans, quotation requests, Paystack and Mobile Money transaction references, billing currency, and electronic receipts. We never store raw credit card numbers or CVVs on our servers.
D. Communication & Telemetry Data
Curvia AI chatbot conversation transcripts, demo booking forms, anonymized IP addresses, browser user agents, and authorized functional cookie preferences.

5. Technical & Organizational Security Measures (TOMs)

In compliance with Section 28 of Act 843, Article 32 of GDPR, and HIPAA Security Rule provisions, we implement stringent defense-in-depth safeguards:

End-to-End Encryption

All data in transit is encrypted using TLS 1.3 / SSL with strong cipher suites. All data at rest is secured using AES-256 bit encryption across database volumes and file storage buckets.

Row-Level Security (RLS)

Our database enforces multi-tenant Row-Level Security policies ensuring strict physical and logical data isolation. No hospital can ever query or view records belonging to another facility.

Role-Based Access Control (RBAC)

Access is restricted strictly on a need-to-know basis. Pharmacists only see prescription queues, laboratory staff see test orders, and doctors see their clinical charts.

Immutable Audit Logging

Every chart view, update, export, or patient record modification triggers an unalterable audit log entry recording the user identity, timestamp, IP, and action performed.

We do NOT sell, lease, or monetize patient or provider data to third parties, advertisers, or data brokers under any circumstances.

6. Rights of Data Subjects

Under the Ghana Data Protection Act 2012, NDPA 2023, and GDPR, individuals have powerful statutory rights regarding their personal data:

  • Right to be Informed: Clear, transparent information about how your data is collected and processed (fulfilled by this policy and our Data Policy).
  • Right of Access: You can request a complete copy of all personal data held about you in our systems.
  • Right to Rectification: You may request the immediate correction of inaccurate, incomplete, or out-of-date records.
  • Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data where retention is no longer necessary, subject to statutory healthcare retention requirements.
  • Right to Restrict Processing: You have the right to request that we freeze processing of your personal data while a dispute or verification is pending.
  • Right to Data Portability: Healthcare facilities and patients have the right to receive their records in a structured, commonly used, machine-readable format (JSON, CSV, or clinical standard format).
  • Right to Object: You can object at any time to processing based on legitimate interests or for direct marketing.
  • Rights Related to Automated Profiling: We do not conduct automated medical decision-making or algorithmic profiling that produces legal effects without licensed medical practitioner oversight.
How to Exercise Your Rights: Contact our Data Protection Officer at dpo@curviacare.com. We will respond within 30 calendar days without charge. If you are a patient seeking access to clinical records, please note your request will be coordinated through your treating health facility as required by medical records regulations.

7. International & Cross-Border Data Transfers

In compliance with Section 35 of the Ghana Data Protection Act and Chapter V of the GDPR, Curvia Care prioritizes African data sovereignty and cloud security.

Where data is processed across borders (e.g. cloud hosting in ISO 27001-certified regional centers), we ensure:

  • Appropriate contractual safeguards, including standard contractual clauses (SCCs) approved by supervisory authorities.
  • Strict end-to-end data encryption in transit and at rest.
  • The receiving jurisdiction provides comparable, adequate data protection legislation.

8. Incident Response & Breach Notification

In the unlikely event of a security incident compromising personal data:

  • Curvia Care will notify the Data Protection Commission (DPC) and relevant national authorities within 72 hours of becoming aware of the breach, where required by law.
  • We will notify affected healthcare facility administrators without undue delay, providing full incident assessments, remediation steps, and technical mitigation guidance.
  • We will assist facilities in notifying affected patients whenever high risks to individual rights are identified.

9. Data Retention & Secure Disposal

We do not keep personal data longer than legally mandated:

  • Clinical Medical Records: Retained in accordance with national health guidelines (typically 10 years from the last consultation, or until age 21 for pediatric patients).
  • Financial & Invoicing Records: Retained for 7 years to satisfy statutory tax and commercial accounting regulations.
  • Account Deletion: Upon subscription termination, facilities are granted a 30-day grace period to export all medical files, after which database partitions and storage buckets are cryptographically sanitized.

10. Cookies & Consent Management

Our platform uses strictly necessary cookies to keep clinical sessions authenticated and safe. Optional analytics and functional cookies are only activated with your informed consent.

Read our full Cookie Policy for detailed tables of active cookies, lifespan, and purpose.

11. Data Protection Officer & Contact Details

We have appointed a designated Data Protection Officer (DPO) to oversee compliance with privacy laws and handle data subject inquiries:

Curvia Care / Kister Inc
Attn: Data Protection Officer (DPO)
General Privacy Inquiries: privacy@curviacare.com
Corporate Headquarters: Airport Residential Area, Accra, Ghana
You also have the right to lodge a complaint with your local regulatory authority, such as the Data Protection Commission (DPC) of Ghana (www.dataprotection.org.gh) or your respective national supervisory body.