LyfeLine OPUS · Professional Platform

Privacy Policy

How LyfeLine OPUS collects, uses, and protects the data of professional dispatch staff and the organisations they serve.

Effective: 14 June 2026 Last revised: 14 June 2026 Version: 3.0 Applies to: app.lyfelineservices.com

Who this policy applies to. This Privacy Policy governs the LyfeLine OPUS platform — a professional dispatch and operations management tool for licensed emergency operations centres, hospitals, and their authorised staff. OPUS is not a consumer product. If you are a patient, please refer to the MyLyfeLine Privacy Policy. For the complete LyfeLine group privacy policy, see lyfelineservices.com/legal/privacy-policy.

1. Data Controller

The data controller for personal data processed through OPUS is:

LyfeLine Technologies Ltd
Nairobi, Kenya
Privacy: privacy@lyfelineservices.com
DPO: dpo@lyfelineservices.com
Registered with the Kenya Data Protection Commissioner (ODPC)

Your employing organisation (the "Subscriber Organisation") is a joint data controller for the staff and operational data it manages within OPUS. The relationship between LyfeLine Technologies and each Subscriber Organisation is governed by a Data Processing Agreement (DPA) incorporated into the OPUS Subscription Agreement.

2. What OPUS Does

OPUS is a professional-grade web application that enables emergency operations centres and hospital administrations to:

OPUS operates in a business-to-business (B2B) context. All users are professional staff acting within the scope of their employment. OPUS processes no consumer personal health data; brief operational patient references (location, incident type, assigned unit) are received from the Nexus platform to coordinate care, and are treated as Protected Health Information (PHI).

3. Categories of Personal Data We Process

CategorySpecific data elementsSource
Staff identityFull name, work email, employee / badge ID, role titleSubscriber Organisation (on invite)
Authentication credentialsCognito user ID, hashed password, session tokens, MFA configurationCollected at account setup / login
Role and access dataStaff role (dispatcher, org admin, clinical coordinator, LyfeLine admin), permission set, org membership, scope-of-access flagsSubscriber Organisation assignment via admin console
Operational activityIncidents dispatched, unit assignments made, dispatch timestamps, resolution times, actions taken in the consoleGenerated during platform use
Audit logsTimestamps, IP addresses, user-agent strings, and descriptions of all admin operations — user invites, role changes, data exports, prescription co-signs, billing accessAutomatically generated per platform action
Session and device dataBrowser type, operating system, IP address, session duration, screen resolutionCollected automatically on login
Billing dataOrganisation subscription tier, seat count, usage metrics, invoice history, payment referencesPlatform billing system
Patient encounter references (operational only)Incident IDs, triage category, unit assigned, receiving hospital — sufficient for dispatch coordination; full patient medical records are not stored in OPUSReceived from Nexus platform integration
Prescription co-sign recordsPrescribing clinician ID, pharmacist co-sign ID, medication and dose, controlled substance classification, co-sign timestampGenerated via prescription co-sign workflow

Patient data in OPUS. OPUS dispatchers receive brief operational patient references (location, incident type, assigned unit) to coordinate care — not full medical records. All patient encounter references received from Nexus are treated as PHI and processed under the Kenya Health Act (Cap 241) and the clinical data protection obligations of the Subscriber Organisation.

4. Legal Basis for Processing

Processing activityLegal basis (KDPA s.30)Notes
Staff authentication and account managementPerformance of contractEmployment + platform subscription; necessary to deliver platform access
Operational dispatch and incident coordinationLegitimate interests; vital interests of patientsCoordinating emergency medical response; assessed proportionate
Audit logging of all privileged administrative actionsLegal obligation; legitimate interestsKenya health sector regulatory compliance; internal security and accountability
Prescription co-sign workflowLegal obligation; vital interestsKenya Pharmacy and Poisons Board requirements; patient safety
Analytics and platform improvement (pseudonymised)Legitimate interestsService quality improvement; data minimisation applied; no PHI included
Billing and licensing managementPerformance of contractSubscription agreement obligations; Kenya Tax Procedures Act record-keeping
Security incident detection and responseLegitimate interests; legal obligationProtecting platform integrity and patient data from unauthorised access

5. How We Use Your Data

6. Data Sharing

We share data only where there is a clear operational, legal, or contractual justification:

We never sell, rent, or share your personal data or patient encounter references with advertising networks, data brokers, or insurance underwriters.

7. Third-Party Sub-Processors

Sub-processorPurposeData transmittedLocation
Amazon Web Services (AWS)Cloud compute (Lambda), database (DynamoDB), object storage (S3), identity (Cognito), CDN (CloudFront), monitoring (CloudWatch)All personal and operational data at rest and in computeEU West 1 (Dublin, Ireland)
Twilio Inc.Outbound SMS — incident alerts, one-time passwords, co-sign notificationsRecipient phone number, message contentUnited States (SCCs in place)
PostHog Inc.Product analytics — pseudonymised staff usage events; no PHI transmittedSession events, feature interactions, error codesEU (GDPR-compliant region)
Amazon CloudFrontCDN delivery of the OPUS web application assetsAnonymised access logs; no personal data in CDN originGlobal edge (data origin: EU West 1)
Google Cloud (Vertex AI / Gemini)AI observation generation — where AI features are active in dispatch or co-sign workflowsDe-identified operational context; no staff names, IDs, or PHIEU processing region (Vertex AI EU)

All sub-processors are bound by Data Processing Agreements requiring data protection standards equivalent to or exceeding the KDPA. An up-to-date processor list is available on request at privacy@lyfelineservices.com. Subscriber Organisations will be notified at least 14 days before a new sub-processor is engaged to process their data.

8. International Data Transfers

Your personal and operational data is stored in AWS eu-west-1 (Dublin, Ireland). Data processing by Twilio and Google Cloud AI that occurs outside Kenya and the EEA is covered by:

You may request copies of applicable SCCs by contacting our DPO at dpo@lyfelineservices.com.

9. Data Retention

Data typeRetention periodBasis
Active staff account dataDuration of employment within Subscriber Organisation + 30 days post-deactivationContract performance
Deactivated / revoked staff records3 years from revocation dateAudit purposes; potential legal claims
Audit logs (all privileged actions)7 yearsKenya health sector regulatory compliance; legal obligation
Incident and dispatch operational records7 yearsClinical record obligation; potential civil legal claims
Prescription co-sign records10 years from co-sign dateKenya Pharmacy and Poisons Board Act requirements
Session authentication tokensRolling 24-hour expiry; revoked immediately on logoutSecurity
Authentication event logs90 daysSecurity; fraud detection
Analytics events (pseudonymised)12 months rollingLegitimate interests — proportionate to improvement purpose
Billing records7 yearsKenya Tax Procedures Act, 2015

At expiry, data is cryptographically purged from active databases and all backup stores within 30 days.

10. Security

11. Your Rights Under the Kenya Data Protection Act, 2019

As a data subject, you have the following rights under KDPA Part V. We will respond to verified requests within 30 calendar days:

To exercise your rights, contact your Subscriber Organisation administrator or email privacy@lyfelineservices.com.

12. Cookies and Local Storage

OPUS is a progressive web application. We use browser localStorage and sessionStorage — not third-party tracking cookies — to persist your authentication session across page reloads. This is essential for dispatcher workflows; a page refresh during an active incident should not log you out.

PostHog uses a first-party analytics cookie for usage event collection. No cross-site or advertising cookies are used. No user data is transmitted to third-party advertising networks.

13. AI Processing

OPUS may display AI-generated observations derived from incident data, operational patterns, or prescription volume analysis. All AI outputs:

14. Changes to This Policy

We will notify Subscriber Organisation administrators of material changes to this policy at least 14 days before they take effect, via email and in-app banner. The "Last revised" date at the top of this page always reflects the most current version. Previous versions are available on request at privacy@lyfelineservices.com.

15. Contact

Contact typeDetails
Privacy enquiriesprivacy@lyfelineservices.com
Data Protection Officerdpo@lyfelineservices.com
Security reportssecurity@lyfelineservices.com
Platformapp.lyfelineservices.com
Full group privacy policylyfelineservices.com/legal/privacy-policy