Privacy Policy
Effective Date: January 1, 2026 • Last Revised: March 15, 2026
1. Introduction and Overview
Curvia Care ("Company", "we", "us", or "our"), operated by Kister Inc, provides cloud and on-premise Electronic Health Record (EHR) systems, hospital management software, clinic operations, and diagnostic management solutions across Africa.
This Privacy Policy is designed to comply with applicable data protection legislation worldwide, including:
- Ghana Data Protection Act, 2012 (Act 843);
- Nigeria Data Protection Act (NDPA, 2023);
- General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR) and UK GDPR;
- Health Insurance Portability and Accountability Act (HIPAA) security standards governing Protected Health Information (PHI);
- The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention).
Because healthcare data is among the most sensitive categories of personal information ("Special Category Data" under GDPR Art. 9 and Section 37 of Act 843), we enforce the highest administrative, technical, and physical safeguards in the industry.
2. Legal Roles: Data Controller vs. Data Processor
Under modern data protection law, legal obligations differ depending on whether an organization acts as a Data Controller (deciding the purposes and means of processing) or a Data Processor (processing data strictly on behalf of the controller).
We act as the Data Controller with respect to:
- Facility administrator, physician, and staff registration credentials.
- Subscription contracts, quotation details, and payment histories.
- Sales inquiries, website lead captures, and AI chatbot conversations.
- Website telemetry, performance monitoring, and authorized cookie data.
We act as a Data Processor on behalf of the Healthcare Facility (Hospital, Clinic, Pharmacy, Laboratory), which is the Data Controller for:
- All Patient Health Information (PHI) and clinical records.
- Diagnostic test orders, medical prescriptions, and doctor consultation notes.
- Patient billing, national health insurance claims (e.g. NHIS), and demographics.
Patients wishing to access, correct, or delete their hospital records should contact their healthcare provider directly. We assist providers in executing those requests.
3. Lawful Bases for Processing Personal Data
In accordance with Section 18 of Act 843 and Article 6 of the GDPR, we process personal data only when there is a recognized lawful basis:
- Contractual Necessity: To fulfill our service agreement with your medical facility, provision user accounts, license EHR modules, process invoices, and provide continuous technical support.
- Legal Obligation: To comply with statutory requirements under healthcare laws, national medical records retention directives, tax authorities, and anti-fraud regulations.
- Vital Interests:In critical emergency healthcare scenarios where access to a patient's medical history (allergies, blood type, chronic diagnoses) is required to protect human life.
- Legitimate Interests: To detect security threats, prevent unauthorized access to patient records, troubleshoot server stability, and enhance clinical software performance, provided these interests do not override individual fundamental rights.
- Explicit Consent: Where required by law for optional cookies, direct marketing communications, or specific clinical research integrations authorized by patients.
4. Categories of Data Collected & Processed
We maintain an exhaustive, itemized disclosure of every single database field, table, and data asset we save. For full technical details, please see our dedicated Data Transparency & Retention Policy.
5. Technical & Organizational Security Measures (TOMs)
In compliance with Section 28 of Act 843, Article 32 of GDPR, and HIPAA Security Rule provisions, we implement stringent defense-in-depth safeguards:
All data in transit is encrypted using TLS 1.3 / SSL with strong cipher suites. All data at rest is secured using AES-256 bit encryption across database volumes and file storage buckets.
Our database enforces multi-tenant Row-Level Security policies ensuring strict physical and logical data isolation. No hospital can ever query or view records belonging to another facility.
Access is restricted strictly on a need-to-know basis. Pharmacists only see prescription queues, laboratory staff see test orders, and doctors see their clinical charts.
Every chart view, update, export, or patient record modification triggers an unalterable audit log entry recording the user identity, timestamp, IP, and action performed.
We do NOT sell, lease, or monetize patient or provider data to third parties, advertisers, or data brokers under any circumstances.
6. Rights of Data Subjects
Under the Ghana Data Protection Act 2012, NDPA 2023, and GDPR, individuals have powerful statutory rights regarding their personal data:
- Right to be Informed: Clear, transparent information about how your data is collected and processed (fulfilled by this policy and our Data Policy).
- Right of Access: You can request a complete copy of all personal data held about you in our systems.
- Right to Rectification: You may request the immediate correction of inaccurate, incomplete, or out-of-date records.
- Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data where retention is no longer necessary, subject to statutory healthcare retention requirements.
- Right to Restrict Processing: You have the right to request that we freeze processing of your personal data while a dispute or verification is pending.
- Right to Data Portability: Healthcare facilities and patients have the right to receive their records in a structured, commonly used, machine-readable format (JSON, CSV, or clinical standard format).
- Right to Object: You can object at any time to processing based on legitimate interests or for direct marketing.
- Rights Related to Automated Profiling: We do not conduct automated medical decision-making or algorithmic profiling that produces legal effects without licensed medical practitioner oversight.
7. International & Cross-Border Data Transfers
In compliance with Section 35 of the Ghana Data Protection Act and Chapter V of the GDPR, Curvia Care prioritizes African data sovereignty and cloud security.
Where data is processed across borders (e.g. cloud hosting in ISO 27001-certified regional centers), we ensure:
- Appropriate contractual safeguards, including standard contractual clauses (SCCs) approved by supervisory authorities.
- Strict end-to-end data encryption in transit and at rest.
- The receiving jurisdiction provides comparable, adequate data protection legislation.
8. Incident Response & Breach Notification
In the unlikely event of a security incident compromising personal data:
- Curvia Care will notify the Data Protection Commission (DPC) and relevant national authorities within 72 hours of becoming aware of the breach, where required by law.
- We will notify affected healthcare facility administrators without undue delay, providing full incident assessments, remediation steps, and technical mitigation guidance.
- We will assist facilities in notifying affected patients whenever high risks to individual rights are identified.
9. Data Retention & Secure Disposal
We do not keep personal data longer than legally mandated:
- Clinical Medical Records: Retained in accordance with national health guidelines (typically 10 years from the last consultation, or until age 21 for pediatric patients).
- Financial & Invoicing Records: Retained for 7 years to satisfy statutory tax and commercial accounting regulations.
- Account Deletion: Upon subscription termination, facilities are granted a 30-day grace period to export all medical files, after which database partitions and storage buckets are cryptographically sanitized.
10. Cookies & Consent Management
Our platform uses strictly necessary cookies to keep clinical sessions authenticated and safe. Optional analytics and functional cookies are only activated with your informed consent.
Read our full Cookie Policy for detailed tables of active cookies, lifespan, and purpose.
11. Data Protection Officer & Contact Details
We have appointed a designated Data Protection Officer (DPO) to oversee compliance with privacy laws and handle data subject inquiries: