Privacy Policy
Effective 26 May 2026
Published by MacWish Medical Centre
1. Who we are
MacWish Medical Centre is a Polyclinic headquartered in Mwanza, Tanzania (the “Centre”, “we”, “us”). We operate Afya Hub — a digital healthcare platform available as a mobile application on the Apple App Store and Google Play Store, and as a web portal at macwishmedicalcentre.co.tz — developed by MacWish AfyaHub, our dedicated research and development entity, solely for the benefit of MacWish Medical Centre’s registered patients and authorised clinical staff.
MacWish Medical Centre is the data controller for all personal and health data processed through the Afya Hub platform. This Privacy Policy explains what data we collect, why we collect it, how we protect it, and the choices available to you.
For privacy questions or to exercise your data-subject rights, write to info@macwishmedicalcentre.co.tz. We respond within 30 days.
2. The information we collect
We collect data you provide directly and data generated through your use of the service:
- Account & identity: full name, salutation, date of birth, gender, phone number, e-mail address, residential location (region, district, ward, street), preferred language (English or Kiswahili), and your relationship to the head of a family account.
- Clinical & health data: blood group, allergies, chronic conditions, current medications and prescriptions, vital signs (blood pressure, pulse rate, temperature, blood glucose, oxygen saturation / SpO₂, weight, height, BMI, respiratory rate), consultation notes and summaries, hospital referral letters, and women’s-health tracking entries (menstrual cycle dates and symptoms, pregnancy journey milestones). Women’s health data is treated with heightened sensitivity and is accessible only by you and your assigned clinician.
- Clinical profile: allergies, known conditions, surgical history, current medications, and lifestyle factors recorded by your treating clinician. Patients may view this profile in read-only mode; only authorised clinical staff may edit it.
- Service-provider data: for doctors and clinical staff, additional fields including medical specialisation, Medical Council of Tanganyika (MCT) registration number and expiry date, profile photograph, consultation pricing, and availability windows.
- Authentication signals: session tokens, device biometric attestations (we never receive the biometric template itself — only a cryptographic yes/no signal from your device’s Secure Enclave or Trusted Execution Environment), and — for web portal users — WebAuthn / passkey credentials stored in your browser or hardware security key. OneSignal push-notification device identifiers are also collected to deliver alerts.
- Payments: the type, amount, and reference number of any subscription or consultation payment, processed through licensed Tanzanian payment gateways (ClickPesa and others). We never store your full card or mobile-money credentials; payment processors handle those directly.
- Conversation history: messages you exchange with our AI assistants Dorah (appointment receptionist) and Nyamizi (clinical assistant), and with your clinician via the in-app chat.
- Barcode identifier: a Code128 barcode generated from a short unique patient identifier, printed on your hospital ID card and used for check-in and clinic session linkage. The barcode is a convenience identifier only; possession of it does not grant access to your clinical records.
- Operational logs: request timestamps, feature usage events, error reports, and — for home-visit bookings only — approximate location at dispatch time.
3. Why we use your data
- To create and maintain your account and verify your identity.
- To deliver in-person appointments, teleconsultations (video and chat via the Agora platform), home visits, vital-signs tracking, clinical profiling, women’s health support, hospital referrals, and doctor ratings.
- To support Family Care Plans where a head-of-family manages dependants, and to administer NCD Care Plan and Home Visit subscriptions.
- To process payments, issue receipts, and manage subscription credits.
- To send appointment reminders, teleconsultation call notifications, and other service alerts you have enabled through OneSignal push notifications.
- To operate our AI assistants: Dorah uses a minimal set of administrative fields to schedule appointments; Nyamizi uses demographic and clinical data — filtered server-side to the minimum necessary — to assist you with health information.
- To generate and store hospital referral PDFs on your behalf.
- To meet our legal, regulatory, and patient-safety obligations under Tanzanian law, including the Electronic and Postal Communications Act and the Tanzania Data Protection Act.
- To detect fraud, abuse, or unauthorised access, and to keep the service running securely.
4. Who we share data with
We share your data only when one of the following applies:
- Your treating clinicians and the Centre’s authorised staff, when needed to provide, coordinate, or document your care. Access is role-gated: only your assigned doctor and authorised clinical staff can view your clinical profile and consultation history.
- Receiving healthcare facilities, when you or your doctor issue a hospital referral. The referral letter (a signed PDF) and the specific clinical fields it contains are shared with the receiving party named in the referral.
- Payment processors, to charge or refund a transaction (ClickPesa and other licensed Tanzanian providers). Only the minimum transactional data required by the gateway is transmitted.
- Infrastructure and service providers operating strictly under our instructions:
- NIDC (National Internet Data Centre, Dar es Salaam, Tanzania) — our primary data hosting partner, selected in compliance with the Tanzania Data Protection Act to ensure patient data is stored within Tanzania.
- Supabase — the database engine and storage layer running within NIDC-hosted infrastructure.
- Agora — video and audio routing for teleconsultation calls only; no clinical records are shared.
- OneSignal — push notification delivery; receives only your device token and notification content.
- ElevenLabs — text-to-speech voice synthesis for Nyamizi; receives only the text of AI-generated responses, never raw patient data.
- Anthropic — the large-language-model provider behind Dorah and Nyamizi. Receives only the already-filtered, minimised context our server prepares; Anthropic does not retain messages to train its models.
- Authorities, when required by Tanzanian law, a valid court order, or to protect the safety of a patient or third party.
We do not sell your personal or health data to any party, and we do not use it to train any AI model.
5. Data hosting and international transfers
Primary data residency: Tanzania. MacWish Medical Centre has partnered with the National Internet Data Centre (NIDC), operated by the Tanzania Communications Regulatory Authority (TCRA) and located in Dar es Salaam, Tanzania (www.nidc.co.tz), as our primary data storage and hosting facility. This ensures that patient data is stored on Tanzanian soil in compliance with the Tanzania Data Protection Act.
Third-party processors outside Tanzania. Certain service components involve processors based outside Tanzania:
- Agora (United States) — teleconsultation video routing. Only real-time media streams transit Agora servers; no clinical records are stored there.
- OneSignal (United States) — push notification delivery. Only device tokens and notification text are processed.
- ElevenLabs (United States) — voice synthesis for Nyamizi. Only the text of AI responses is transmitted; no patient identifiers are included.
- Anthropic (United States) — language model inference. Receives server-filtered, minimised context only.
Where data is transferred outside Tanzania, it travels under the contractual data-processing safeguards of the relevant provider, and only the minimum data required to deliver the specific feature is transmitted.
6. How long we keep your data
- Active accounts: for as long as you use the service.
- Clinical records: retained for the period required by Tanzanian medical-records regulation (currently a minimum of 10 years from the date of last entry), even if you delete your app account.
- Referral letters: stored indefinitely as part of your permanent clinical record.
- Payment records: retained for the period required by Tanzanian tax and anti-money-laundering rules.
- AI conversation history: retained against your account so you and your clinician may refer back to it; you may request deletion of conversation history at any time.
- Operational logs: rolled up or deleted within 13 months.
7. Your rights
Under the Tanzania Data Protection Act and applicable law, you may at any time:
- Access the personal information we hold about you.
- Correct anything that is inaccurate or incomplete.
- Withdraw consent for optional features (e.g. push notifications, women’s health tracking).
- Delete your account. From the mobile app, open Settings → Delete my account; this triggers an atomic, permanent deletion across your authentication credentials, user profile, affiliated doctor record (if applicable), and family-membership links — subject to the clinical-record retention period above.
- Object to processing for purposes beyond those strictly necessary to deliver the service.
- Lodge a complaint with the Tanzania Communications Regulatory Authority (TCRA) or other competent authority.
To exercise any of these rights, write to info@macwishmedicalcentre.co.tz. We respond within 30 days.
8. Security
Security is foundational to Afya Hub. Because we handle sensitive medical data, we have implemented overlapping technical and organisational safeguards at every layer of the system:
Encryption
- TLS 1.3 in transit. Every connection between the mobile app, web portal, our servers, and the database is encrypted with TLS 1.3. No data travels in plaintext over any network.
- Encryption at rest. All data stored at NIDC is encrypted at rest using AES-256. Database backups are encrypted before being written to storage.
Authentication & Access Control
- Biometric authentication (mobile). Afya Hub uses your device’s Secure Enclave (iOS) or Trusted Execution Environment (Android) for fingerprint and Face ID authentication. The biometric template never leaves your device; we receive only a cryptographic attestation (yes/no) from the hardware. This replaces SMS-based OTP for all sensitive actions.
- WebAuthn / Passkeys (web portal). Clinical staff accessing the web portal may register a hardware security key or device passkey using the WebAuthn standard. Passkeys are phishing-resistant and cannot be stolen via social engineering.
- Role-based access control (RBAC). Every user is assigned one of five roles — SuperAdmin, Admin, Doctor, Staff, or Patient — enforced by a CHECK constraint in the database. Each role carries a tightly-scoped set of permissions; a Patient cannot access another patient’s record, and a Doctor can only access the records of patients assigned to them.
- Doctor verification gate. A doctor account cannot access clinical workflows until their MCT (Medical Council of Tanganyika) registration is verified by a Centre administrator. Verification status is enforced in the database through an
is_verified_provider()function checked on every sensitive write operation. - Row-Level Security (RLS). Every database table has RLS policies enabled at the database engine level. No application-layer bug can bypass these policies; a query that violates an RLS rule returns zero rows rather than an error, preventing information leakage.
Infrastructure Security
- Isolated serverless functions. Backend logic (e.g. hospital referral PDF generation, barcode processing) runs in Supabase Edge Functions — Deno-based isolated workers that execute in a sandboxed environment with no persistent file system access.
- SECURITY DEFINER stored procedures. Privileged database operations — such as account deletion across multiple tables, pre-signup duplicate checks, and role provisioning — are implemented as
SECURITY DEFINERRPCs (Remote Procedure Calls). These run with the specific privileges of the procedure owner, not the calling user, ensuring that sensitive cross-table operations cannot be exploited by an attacker who compromises a low-privilege session. - Service-role key isolation. Automated nightly jobs (e.g. credit consumption processing) use a dedicated service-role key with the minimum necessary permissions. This key is never exposed to client-side code.
- n8n automation server. Workflow automations (AI agents, payment processing, subscription activation) run on a dedicated Virtual Private Server (VPS) with restricted network access. The server acts as a privacy filter — it retrieves patient data from the database, strips it to the minimum required for each task, and never exposes raw records to external systems.
AI Agent Security
- Data minimisation enforced in code. Before any data reaches Dorah or Nyamizi, our automation server strips it to only the fields each agent requires — 5 administrative fields for Dorah, demographic plus clinical context for Nyamizi. This is enforced in server-side code, not just policy; it is architecturally impossible for the agents to receive data outside their defined scope.
- Session isolation. Each patient’s AI conversation is keyed to their unique session identifier. No data from one patient’s session is ever visible in another patient’s session.
- Prompt injection defence. Both Dorah and Nyamizi are configured at the system-prompt level to refuse attempts to reveal system internals, patient identifiers, tool names, or any data outside their defined scope, regardless of how the request is phrased.
- No training on patient data. Patient conversations are never used to train or fine-tune any AI model. Anthropic’s Claude processes each request in real time and, under our data-processing agreement, does not retain patient messages.
Audit & Incident Response
- Audit trail. All significant interactions — logins, profile updates, clinical edits, referral generation, AI sessions — are logged server-side with timestamps, user identifiers, and session keys. Logs are retained for 13 months and are accessible to authorised administrators only.
- Breach notification. No internet-connected system is perfectly secure. If a breach affects your data, we will notify you and the relevant Tanzanian authority (TCRA) without undue delay and take immediate steps to contain and remediate the incident.
9. Children
Afya Hub is not designed for unsupervised use by children under the age of 13. Patients aged 13–17 may use the service under the supervision of a parent or legal guardian, who must register and manage the account through the Family Care Plan. A parent or guardian bears full responsibility for the accuracy of information provided on behalf of a dependant minor.
10. AI assistants — Dorah and Nyamizi
Dorah is our AI appointment receptionist; she helps you find available doctors, check appointment slots, and book or reschedule visits. Dorah has access only to your first name, email address, assigned doctor, appointment history, and internal patient identifier — she cannot access your clinical or medical records.
Nyamizi is our AI clinical assistant; she helps you understand your vital signs, symptoms, and general health information. Nyamizi receives filtered demographic data, your recorded vital signs, and your clinical profile fields — never your contact details, home address, insurance information, or any data beyond what is medically relevant to your question.
Both assistants run on top of Anthropic’s Claude, accessed through our secure automation server. Conversation history is stored against your account so you and your clinician can refer back to it. Responses from Dorah and Nyamizi are informational only and do not constitute a medical diagnosis, prescription, or treatment plan.
Nyamizi is also available with a voice interface powered by ElevenLabs text-to-speech. The voice feature sends only the text of AI-generated responses to ElevenLabs; no patient data or identifiers are included.
11. Hospital referrals
When your doctor generates a hospital referral through Afya Hub, a signed PDF is produced by a secure server-side function and stored in encrypted file storage under your account. The referral document contains the clinical fields your doctor selects (diagnosis, urgency, relevant history) and is accessible only to you, your treating clinician, and — when shared — the receiving facility. You may request a copy of any referral concerning you at any time.
12. Women's health data
Menstrual cycle tracking and pregnancy journey data are considered especially sensitive. This data is stored separately from general clinical records and is accessible only by you and your assigned clinician. It is never shared with third parties, never exposed to our AI assistants, and is not included in any referral letter unless you explicitly instruct your clinician to include it.
13. Cookies and analytics
The Afya Hub web portal uses only the cookies necessary for you to remain signed in and to remember your language preference (English or Kiswahili). We do not run third-party advertising cookies, behavioural-tracking pixels, or analytics services that profile individual users.
14. Changes to this policy
We may update this policy from time to time as the service evolves or as regulatory requirements change. The version date at the top of this page reflects the most recent update. Where a change is material — for example, if we add a new data-sharing category or change our data-hosting arrangements — we will notify you in-app or by e-mail at least 14 days before the change takes effect. Your continued use of Afya Hub after that date constitutes acceptance of the updated policy.
15. Contact us
MacWish Medical Centre
Mwanza, Tanzania
info@macwishmedicalcentre.co.tz
www.macwishmedicalcentre.co.tz
Data Protection Officer: info@macwishmedicalcentre.co.tz
See also our Terms & Conditions and Support & Account Deletion page.
© 2026 MacWish Medical Centre. All rights reserved.