Data Protection Privacy Policy
Total Wellness International Ltd Privacy Policy
Last Updated: 25th June 2026 · ODPC Registration Number: 208-5652-3A60
At Total Wellness International, we provide mental health support, teletherapy, and wellness services. Because we process highly sensitive information about your mental and physical health, we are committed to protecting your privacy in strict compliance with the Kenya Data Protection Act (DPA), 2019 and the Data Protection (General) Regulations, 2021.
1. Identity of the Data Controller & Data Protection Officer (DPO)
Under the DPA, 2019, Total Wellness International is the Data Controller. Because we process sensitive health data, we have appointed a designated Data Protection Officer (DPO).
- Physical Address: Daykio Plaza, Ngong Lane, Ngong Road.
- Postal Address: P.O Box 21839
- Compliance Email: privacy@nzuricare.co.ke
- DPO Contact: Ronald@nzuricare.co.ke
2. The Personal and Sensitive Data We Collect
We do not collect any clinical or personal data without your knowledge. We categorize the data we collect as follows:
| Category | Specific Data Collected | Lawful Basis for Processing (under DPA 2019) |
|---|---|---|
| Standard Personal Data | Name, phone number (for M-Pesa/billing), email, emergency contact details, and date of birth. | Contractual Necessity (Section 30): To set up your account and schedule sessions. |
| Sensitive Personal Data (Health Data) | Clinical intake forms, therapist session notes, psychiatric history, diagnostic codes, and prescribed plans. | Explicit Consent (Section 30(1)(a)): Obtained via a separate, un-ticked opt-in checkbox during registration. Medical/Healthcare Purpose (Section 32): For provision of care. |
| Technical Data | IP addresses, browser types, session durations, and cookie data. | Legitimate Interest: To maintain website security and optimize platform performance. |
3. How We Use (Process) Your Data
Your mental health data is strictly protected. We use your data only to:
- Provide clinical counseling, psychological assessments, and therapy sessions.
- Process payments securely through our approved Kenyan payment gateways (e.g., M-Pesa).
- Contact your designated emergency contact only in the event of an active, life-threatening crisis (permissible under Section 30(2)(b) for "vital interests").
- Send you appointment reminders via SMS or email.
Absolute Prohibition: We will never sell, rent, or share your clinical details, diagnosis, or session attendance with third-party advertisers, insurance companies, or employers without your explicit, written authorization.
4. Third-Party Sharing and Data Processors
We share minimal data with trusted third-party Data Processors who help us run our services. Every partner has signed a legally binding Data Processing Agreement (DPA) in line with Section 42 of the Kenyan Act.
- Telehealth Video Platforms: Jitsi, Zoom/Google Meet & Microsoft Teams. Session audio and video are end-to-end encrypted (E2EE); our providers cannot view or record your sessions.
- Payment Gateways: Pesapal/M-Pesa API. They receive only your name, phone number, and transaction amount. They never receive therapeutic or clinical details.
- Cloud Hosting: Blue Host. Our databases are hosted in secure, encrypted cloud facilities.
5. Cross-Border Data Transfers (Section 48)
To comply with Kenyan law, your sensitive health data is ideally stored locally within Kenya. Where we utilize secure cloud servers located outside Kenya (Blue Host), we guarantee that:
- The destination country has an adequate level of data protection laws equivalent to Kenya's DPA.
- We have executed Standard Contractual Clauses (SCCs) with the cloud host to safeguard your data.
- Your data is fully encrypted both at rest and in transit prior to leaving Kenyan borders.
6. How Long We Keep Your Data (Data Retention)
In accordance with the Mental Health Act (Cap 248, Laws of Kenya) and the DPA, 2019:
- Clinical Records: We retain therapy notes and psychiatric records for a minimum of 10 years from the date of your last session to satisfy medical record-keeping regulations.
- Non-Clinical Accounts: If you delete your account and have never had a clinical session, your personal data is permanently deleted from our servers within 30 days.
7. Your Rights as a Data Subject (Section 26)
As a Kenyan citizen or resident, you have the following guaranteed legal rights. You can exercise these by emailing privacy@nzuricare.co.ke:
- Right to be Informed: To know exactly how we collect, store, and use your mental health data.
- Right of Access: To request a copy of your personal data and clinical records (subject to clinical safety exemptions where viewing notes might cause psychological harm).
- Right to Rectification: To correct inaccurate or incomplete health information.
- Right to Erasure ("Right to be Forgotten"): To request deletion of your account (subject to our statutory clinical retention periods).
- Right to Object/Withdraw Consent: To withdraw your consent to data processing at any time.
8. Data Security and Breach Management
We employ industry-leading security controls to protect your sensitive clinical data:
- Advanced Encryption: All communications and databases are encrypted using AES-256 (at rest) and TLS 1.3 (in transit).
- Access Control: Only your assigned therapist has access to your clinical files. Internal administrative staff can only see your billing and contact details.
- 72-Hour Breach Notification: In the highly unlikely event of a data breach, we are legally required to notify the ODPC within 72 hours of detection, and we will notify you directly without delay if the breach poses a high risk to your rights.
9. How to File a Complaint
If you believe we have mishandled your sensitive personal data, please contact our DPO first at Ronald@nzuricare.co.ke so we can resolve the issue.
You also have the legal right to lodge a formal complaint directly with the regulator:
- Website: www.odpc.go.ke
- Email: complaints@odpc.go.ke