Who this policy applies to. This Privacy Policy governs the LyfeLine Nexus platform — a professional field operations tool provided exclusively to licensed emergency medical service providers, paramedics, medics, pharmacists, and their authorised support staff. Nexus is not a consumer product. If you are a patient, please refer to the MyLyfeLine Privacy Policy. For the complete LyfeLine group privacy policy, see lyfelineservices.com/legal/privacy-policy.
Nexus processes highly sensitive clinical data. Because Nexus is used at the point of emergency care, it processes patient vital signs, clinical assessments, prescription records, telemedicine sessions, and real-time location data. We apply heightened safeguards to all patient health data processed through Nexus, as detailed in this policy.
1. Data Controller
The data controller for personal data processed through Nexus is:
LyfeLine Technologies Ltd
Nairobi, Kenya
Privacy: privacy@lyfelineservices.com
DPO: dpo@lyfelineservices.com
Registered with the Kenya Data Protection Commissioner (ODPC)
Your employing EMS organisation (the "Subscriber Organisation") is a joint data controller for staff and patient encounter data managed within Nexus. The relationship is governed by a Data Processing Agreement (DPA) incorporated into the Nexus Subscription Agreement. The Subscriber Organisation is the clinical record holder for patient encounter records under the Kenya Health Act.
2. What Nexus Does
Nexus is the field-facing companion to the LyfeLine OPUS dispatch platform. It enables field EMS and medical responders to:
- Receive and acknowledge dispatch assignments in real time and navigate to incident locations with flood-risk-aware routing
- Record patient vital signs, triage assessments, chief complaint, mechanism of injury, AVPU neurological score, and care notes in the field
- Manage prescriptions and controlled substance dispense records with pharmacist co-sign workflow
- Access hospital pharmacy catalogues and submit electronic prescriptions for remote co-sign
- Conduct telemedicine video/audio consultations with hospital-based clinicians for remote clinical guidance
- Communicate via encrypted push-to-talk (PTT) with other field units and OPUS dispatch
- View live tactical maps with unit locations, hospital capacity, and satellite imagery
- Receive alerts for nearby incidents, flood-risk zones, and road hazards in real time
Nexus processes more sensitive clinical data than any other LyfeLine platform because it is used at the point of care. We apply the highest level of data protection controls to data processed through Nexus.
3. Categories of Personal Data We Process
| Category | Specific data elements | Source |
|---|---|---|
| Staff identity | Full name, work email, badge/licence number, EMS certification level (EMT, paramedic, clinical officer, nurse, pharmacist), scope-of-practice flags | Subscriber Organisation (on invite) |
| Authentication credentials | Cognito user ID, hashed password, session tokens, MFA configuration | Collected at account setup / login |
| Role and access data | Clinical role assignment, permissions, scope-of-practice restrictions, organisation membership | Subscriber Organisation assignment via OPUS admin console |
| Real-time staff location | High-precision GPS coordinates of field units during active duty shifts | Device GPS while Nexus is open and duty status is active |
| Patient vital signs | Heart rate, SpO2 (blood oxygen), blood pressure, respiratory rate, temperature, blood glucose, ECG trace segment, AVPU neurological score | Manually entered or device-connected during patient encounter |
| Patient encounter data | Triage category (START/SALT), chief complaint, mechanism of injury, physical examination findings, treatment administered, drug doses, transport destination, handoff summary | Field responder data entry during encounter |
| Prescription records | Medication name, dose, route of administration, batch number, date/time of administration, prescribing clinician ID, pharmacist co-sign ID, controlled substance schedule classification, administration confirmation | Responder entry + pharmacist co-sign action |
| Telemedicine session data | Session start/end timestamps, clinician and patient/medic identifiers, session outcome note; audio/video encrypted in transit — not retained by LyfeLine unless Subscriber Organisation enables recording | Session participants during active consultation |
| PTT communication metadata | Call duration, unit IDs, channel, timestamp; audio is not recorded or stored by LyfeLine | Automatically generated per PTT call |
| Session and device data | Browser / device type, operating system, IP address, session duration | Collected automatically on login |
| Audit logs | Timestamps and descriptions of all clinical actions, prescription events, dispatch acknowledgements, and login events | Automatically generated per platform action |
4. Location Tracking
When we track your location and why. Nexus tracks the real-time GPS location of field units while the application is in active use and your duty status is set to "on duty." Location data is shared with your OPUS dispatch centre to enable unit assignment, routing, and crew safety tracking. Location data is not collected when the app is closed, when you are not on an active duty assignment, or when your duty status is set to "off duty." You may disable location sharing at the operating system level; doing so will impair dispatch coordination features and must be reported to your supervisor as it may affect crew safety protocols.
GPS location history during duty shifts is retained for 12 months on a rolling basis and is accessible only to your Subscriber Organisation's administrators and to LyfeLine security engineers investigating a reported safety incident. Location data captured during a specific SOS event or patient encounter becomes part of the permanent incident record.
5. Legal Basis for Processing
| Processing activity | Legal basis (KDPA s.30) | Notes |
|---|---|---|
| Staff authentication and account management | Performance of contract | Employment + platform subscription; necessary to deliver platform access |
| Patient vital signs and clinical data entry | Vital interests (emergency medical care); legitimate interests of Subscriber Organisation in providing care | Emergency care context overrides normal consent requirements |
| Real-time staff GPS location tracking | Legitimate interests (dispatch coordination, crew safety); contractual necessity | Assessed proportionate to emergency-response context; active duty only |
| Prescription and controlled substance records | Legal obligation (Pharmacy and Poisons Board regulations); vital interests (patient safety) | Permanent audit records required by Kenyan law |
| Telemedicine audio/video sessions | Explicit consent of the patient | Consent obtained and documented by field responder before initiating session |
| Audit logging of all clinical actions | Legal obligation (Kenya Health Act); legitimate interests (clinical accountability) | Mandatory under clinical record-keeping obligations |
| Analytics (pseudonymised response time events) | Legitimate interests | Platform improvement; no PHI included; data minimisation applied |
6. Sensitive Health Data — Heightened Safeguards
Patient vital signs, clinical assessments, and prescription records are Special Category data under KDPA s.46. We apply the following additional safeguards:
- All patient health data is encrypted at rest (AES-256) and in transit (TLS 1.3)
- Access to patient encounter records is limited to responders assigned to the specific incident and authorised clinical reviewers within the same Subscriber Organisation — enforced at the API layer, not just the UI
- Patient data is never used to train AI models without explicit, documented, written consent from the Subscriber Organisation
- AI clinical observations (vital sign trends, triage suggestions, drug interaction flags) are labelled "AI observation aid — not a clinical diagnosis" and do not override responder judgement
- Telemedicine audio and video is not retained by LyfeLine after session close unless the Subscriber Organisation has explicitly enabled session recording — and if enabled, recordings are treated as clinical records (10-year retention)
- PTT audio is not recorded by LyfeLine at any time under any configuration
We never sell, rent, license, or share patient health data, clinical records, or prescription records with advertisers, insurers, data brokers, or any commercial third party.
7. How We Use Your Data
- Platform access. To authenticate your identity and present features appropriate to your clinical role and scope of practice
- Dispatch coordination. Your GPS location and duty status are shared with your OPUS dispatch centre to enable unit assignment, routing, and crew tracking
- Patient care. Clinical data you enter is associated with the active incident record, shared with the receiving hospital via handoff, and retained in the encounter log for continuity of care
- Prescription safety. Controlled substance dispense records are logged against your credentials and the patient encounter, routed to OPUS for pharmacist co-sign, and retained for regulatory audit
- Routing and hazard alerts. Your GPS location is used to calculate optimal routes to incidents and hospitals, and to alert you to flood-risk zones or road hazards in real time
- Analytics. Aggregated, pseudonymised response time and operational data is used to improve platform performance. No patient identifiers are included in analytics events
- Notifications. Incident assignments, prescription co-sign approvals, and operational alerts are delivered via in-app push and, where configured, SMS
8. Data Sharing
- With OPUS dispatch: Your GPS position, duty status, incident assignment, and patient triage category are shared in real time to enable coordinated emergency response
- With receiving hospital: Pre-alert (ETA, triage category, chief complaint); full encounter record and vitals transmitted at handoff for continuity of care
- With your Subscriber Organisation: Clinical supervisors and org admins have access to encounter records, audit logs, and prescription records within their organisation's account
- With pharmacist co-signers (OPUS): Prescription details are transmitted to the co-signing pharmacist in OPUS for review and approval
- With patient emergency contacts (where MyLyfeLine user): Where the patient has the MyLyfeLine app, their emergency contacts may receive status updates via the MyLyfeLine notification system
- With law enforcement or regulators: Where required by a valid court order, coroner's order, or regulatory demand
9. Third-Party Sub-Processors
| Sub-processor | Purpose | Data transmitted | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud compute (Lambda), database (DynamoDB), object storage (S3), identity (Cognito), CDN (CloudFront), monitoring (CloudWatch) | All personal, clinical, and operational data | EU West 1 (Dublin, Ireland) |
| Twilio Inc. | Outbound SMS — incident alerts, one-time passwords, patient notifications (where configured) | Recipient phone number, message content | United States (SCCs in place) |
| PostHog Inc. | Product analytics — pseudonymised staff usage events; no PHI transmitted | Session events, feature interactions, error codes | EU (GDPR-compliant region) |
| Amazon CloudFront | CDN delivery of Nexus web application assets | Anonymised access logs; no PHI in CDN layer | Global edge (data origin: EU West 1) |
| OpenStreetMap / ESRI / Carto | Map tile rendering for tactical map, navigation, and routing | Tile URL coordinates only — no patient names, IDs, or PHI transmitted to tile providers | Varies — CDN edge (coordinates only) |
| Google Cloud (Vertex AI / Gemini) | AI observation generation — vital sign trend analysis, triage suggestions, drug interaction flags | De-identified clinical context (e.g., "SpO2 88%, HR 140, BP 80/50") — no patient names, IDs, or contact data | EU processing region (Vertex AI EU) |
An up-to-date processor list is available on request at privacy@lyfelineservices.com. Subscriber Organisations will be notified at least 14 days before a new sub-processor that will process clinical data is engaged.
10. International Data Transfers
Patient and staff data is stored in AWS eu-west-1 (Dublin, Ireland). Where processing occurs outside Kenya and the EEA (specifically Twilio in the United States), we rely on:
- Standard Contractual Clauses (SCCs) — 2021 European Commission version, recognised by the Kenya ODPC as providing adequate safeguards
- Strict data minimisation before transfer: All data sent to AI sub-processors is de-identified — all direct patient identifiers are stripped before transmission; AI models receive only clinical context parameters
- Annual Transfer Impact Assessments (TIAs) for sub-processors in jurisdictions without an ODPC adequacy decision
Map tile requests to OpenStreetMap/ESRI/Carto contain coordinates only — no personally identifying information is transmitted to map tile providers.
11. Data Retention
| Data type | Retention period | Basis |
|---|---|---|
| Active staff account data | Duration of employment within Subscriber Organisation + 30 days post-deactivation | Contract performance |
| Deactivated staff records | 3 years from deactivation | Audit purposes; potential legal claims |
| Patient encounter / clinical records | 10 years from date of encounter | Kenya Health Act (Cap 241) minimum for clinical records |
| Prescription and controlled substance records | 10 years from dispense date | Kenya Pharmacy and Poisons Board Act requirements |
| Audit logs (all clinical actions) | 7 years | Kenya health sector regulatory compliance; legal obligation |
| GPS duty-shift location history | 12 months rolling | Incident reconstruction; crew safety investigations |
| GPS location during a specific incident | Permanent (part of incident record) | Clinical record; legal obligation |
| Telemedicine session recordings | Not retained by LyfeLine unless Subscriber Organisation enables recording — if enabled, treated as clinical record (10 years) | Clinical record obligation |
| PTT audio | Not retained — relay-only architecture | N/A |
| PTT call metadata | 90 days | Security; operational logs |
| Session authentication tokens | Rolling 24-hour expiry; revoked immediately on logout | Security |
| Authentication event logs | 90 days | Security; fraud detection |
| Analytics events (pseudonymised) | 12 months rolling | Legitimate interests |
At expiry, data is cryptographically purged from active databases and all backup stores within 30 days.
12. Security
- All data in transit encrypted with TLS 1.2 minimum (TLS 1.3 enforced for all API endpoints)
- All data at rest in DynamoDB and S3 encrypted with AES-256 using AWS-managed keys
- Authentication via AWS Cognito with short-lived JWT access tokens (24-hour expiry) and refresh token rotation
- Role-based access control (RBAC) enforced at the Lambda API layer — patient data access is restricted to the assigned incident responder at the API level, not just the UI
- DynamoDB Point-in-Time Recovery (PITR) enabled on all clinical data tables; 35-day recovery window
- API Gateway WAF rules protecting against OWASP Top 10 attacks
- Immutable audit trail: all clinical actions logged to a tamper-evident append-only record
- Security incidents reported to affected Subscriber Organisations within 24 hours of discovery
- Patient data never used to train AI models without explicit, documented, written consent
13. Your Rights Under the Kenya Data Protection Act, 2019
As a data subject, you have the following rights under KDPA Part V. We will respond to verified requests within 30 calendar days:
- Right of access (s.26): Request a copy of personal data we hold about you — including your account metadata, role history, GPS history, and audit log entries relating to your account
- Right to rectification (s.27): Request correction of inaccurate personal data. Clinical records are annotated (not overwritten) to preserve audit integrity
- Right to erasure (s.27): Request deletion where no overriding legal basis for retention exists. Clinical records, controlled substance logs, and audit trails cannot be erased during mandatory retention periods
- Right to data portability (s.28): Receive your personal data in a structured, machine-readable format (JSON or CSV)
- Right to object (s.35): Object to processing based on legitimate interests, including product analytics. Note: GPS tracking during active duty cannot be objected to without operational consequence
- Right to withdraw consent: Where processing relies on consent (telemedicine sessions, analytics). Withdrawal does not affect prior lawful processing
- Right to lodge a complaint (s.42): Lodge a complaint with the Kenya ODPC at odpc.go.ke · info@odpc.go.ke
To exercise your rights, contact your Subscriber Organisation administrator or email privacy@lyfelineservices.com.
14. AI Processing
Nexus may display AI-generated clinical observations generated from vitals data, triage inputs, or prescription context. All AI outputs:
- Are labelled "AI observation aid — not a clinical diagnosis"
- Are generated from de-identified clinical context — patient names, IDs, and contact data are stripped before transmission to AI sub-processors
- Require clinician confirmation before being recorded as a clinical decision (triage suggestions, drug interaction flags are never auto-accepted)
- Are not the output of a regulatory-approved medical device and must not be treated as equivalent to a clinical assessment
- Are generated by Google Gemini (primary) and Anthropic Claude (secondary), both bound by DPAs restricting data to observation generation only
15. Cookies and Local Storage
Nexus uses browser localStorage — not third-party tracking cookies — to persist your authentication session across page reloads. This is essential for clinical workflows; a page refresh during an active patient encounter must not log you out and interrupt care.
PostHog uses a first-party analytics cookie for pseudonymised usage event collection. No cross-site or advertising cookies are used. No patient data is transmitted to any analytics system.
16. Changes to This Policy
We will notify Subscriber Organisation administrators of material changes to this policy at least 14 days before they take effect, via email and in-app banner. The "Last revised" date at the top of this page always reflects the most current version. Previous versions are available on request at privacy@lyfelineservices.com.
17. Contact
| Contact type | Details |
|---|---|
| Privacy enquiries | privacy@lyfelineservices.com |
| Data Protection Officer | dpo@lyfelineservices.com |
| Security reports | security@lyfelineservices.com |
| Platform | nexus.lyfelineservices.com |
| Full group privacy policy | lyfelineservices.com/legal/privacy-policy |