Privacy Policy

Last Updated: February 16, 2026

Pre-Launch Notice: Docplan is currently in beta. We are launching in Kenya first, with expansion to Tanzania, Oman, UAE, and USA planned for 2026. Select your country above to view the relevant privacy policy.

Features in Development:

While this Privacy Policy describes our complete data protection framework, some features are currently in active development and will be available soon:

  • Email Notification Preferences: Granular email notification controls in account settings (currently in development)
  • Self-Service Data Export: Automated data portability tools (currently in development - contact legal@docplan.app to request your data)
  • Cookie Consent Banner: Enhanced cookie management interface (in development)

In the meantime, you can exercise all your data rights by contacting our Privacy Officer at legal@docplan.app. We are committed to responding within the legally required timeframes.

Docplan ("we," "us," or "our") is committed to protecting your privacy and the confidentiality of your health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our healthcare appointment scheduling platform.

This policy complies with the Kenya Data Protection Act, 2019 and other applicable privacy laws.

Kenya Data Protection Notice

This notice describes how your personal and health information may be used and disclosed in accordance with the Kenya Data Protection Act, 2019.

Healthcare providers using Docplan are required by law to protect your personal data. Docplan is registered as a Data Controller with the Office of the Data Protection Commissioner and processes your information in accordance with Kenya's data protection regulations.

1. Information We Collect

Personal and Health Information

When you use Docplan, we may collect and process the following types of information:

  • Personal identifiers (name, email address, phone number, date of birth)
  • Appointment details (date, time, healthcare provider, organization)
  • Medical services requested or received
  • Communication preferences
  • Payment information (processed securely through third-party payment processors) - Coming soon in Q1 2026

Technical Information

We automatically collect certain technical information:

  • Device information (browser type, operating system)
  • IP address and general location
  • Usage data (pages viewed, features used)
  • Cookies and similar tracking technologies

Consent Records and Audit Trail

To comply with healthcare regulations and maintain legal proof of your consent, we automatically record the following when you create an account or accept our Terms of Service or Privacy Policy:

  • Date and time of acceptance
  • IP address at the time of signup or acceptance
  • Version of the policy you accepted (identified by date)
  • Consent type (Terms of Service, Privacy Policy, or other consents)

Purpose: These records serve as legal documentation that you have reviewed and agreed to our policies, and they help us comply with healthcare regulations including HIPAA (USA), Kenya Data Protection Act, and other applicable laws.

Retention: Consent records are retained for 7 years after your account is closed to meet legal obligations, regulatory requirements, and statute of limitations for potential claims.

Your Rights: You can request to view your complete consent history at any time by contacting legal@docplan.app. Please note that due to legal and regulatory requirements, consent records may not be deleted even if you delete your account, though they will be isolated from other personal data.

2. How We Use Your Information

Healthcare Services

We use your information for:

  • Appointment Management: Facilitating your appointments with healthcare providers
  • Payment Processing: Processing payments and billing for services - Coming soon in Q1 2026
  • Platform Improvement: Improving our platform, quality assurance, and customer support

Communications

  • Sending appointment confirmations and reminders
  • Notifying you of reschedules or cancellations
  • Requesting feedback about your healthcare experience
  • Providing customer support

Email Security Notice: Email communications may not be fully encrypted in transit or storage. We minimize the amount of health information included in emails. For maximum security, we recommend accessing your appointment information through your secure Docplan account.

3. How We Share Your Information

With Your Healthcare Providers

We share your information with the healthcare organizations and providers you book appointments with to facilitate your care.

Service Providers

We may share information with trusted third-party service providers who assist us in operating our platform, including:

  • Cloud hosting providers (for secure data storage)
  • Email service providers (for appointment notifications)
  • Payment processors (for billing) - Coming soon in Q1 2026
  • Analytics providers (for platform improvement)

All service providers are required to maintain data protection compliance and protect your information.

Legal Requirements

We may disclose your information when required by law, such as:

  • In response to court orders or legal processes
  • To comply with regulatory requirements
  • To protect public health and safety
  • To prevent or investigate potential fraud or violations of law

We Will NOT Share Your Information

We will never sell, rent, or share your health information for marketing purposes without your explicit written authorization.

4. Your Privacy Rights

You have the following rights regarding your personal and health information:

Right to Access

You have the right to view and obtain a copy of your personal information maintained by Docplan.

Right to Correction

You may request corrections to your personal information if you believe it is incorrect or incomplete.

Right to Erasure

You may request deletion of your personal information, subject to legal retention requirements.

Right to Restrict Processing

You may request limitations on how we use or disclose your personal information.

Right to Data Portability

You may request a copy of your data in a structured, commonly used format.

Right to Object

You may object to certain types of data processing, including direct marketing.

Right to Opt Out of Email Notifications

You can disable email notifications at any time in your account settings while still maintaining access to your appointment information through your secure account.

To exercise any of these rights, please contact our Privacy Officer at legal@docplan.app or through your account settings.

5. How We Protect Your Information

We implement industry-standard security measures to protect your personal and health information, including:

  • Encryption: Data is encrypted in transit (SSL/TLS) and at rest
  • Access Controls: Strict authentication and authorization protocols
  • Monitoring: Continuous security monitoring and logging
  • Regular Audits: Periodic security assessments and compliance reviews
  • Employee Training: Staff are trained on data protection and security best practices
  • Vendor Agreements: All vendors handling personal data sign data protection agreements

While we take extensive measures to protect your information, no system is completely secure. We encourage you to use strong passwords and protect your account credentials.

6. Data Retention

We retain your personal and health information for as long as necessary to provide our services and comply with legal requirements. Healthcare records are typically retained for a minimum of 6 years from the date of last service, as commonly required by healthcare regulations.

If you wish to delete your account, you may do so in your account settings. Please note that we may retain certain information as required by law or for legitimate business purposes.

7. International Data Transfers

Docplan operates primarily in Kenya. If we transfer your data internationally, we ensure appropriate safeguards are in place as required by the Kenya Data Protection Act, 2019, including data transfer agreements and ensuring the recipient country has adequate data protection standards.

8. Children's Privacy

Docplan is not intended for use by children under 13 years of age without parental consent. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

For minors aged 13-17, we require parental or guardian consent for account creation and use of our services.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending you an email notification if you have an account with us
  • Displaying a prominent notice on our platform

We encourage you to review this Privacy Policy periodically. Your continued use of Docplan after changes are posted constitutes your acceptance of the updated policy.

10. Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will notify you and any relevant authorities as required by applicable data protection laws. Notification will be provided without unreasonable delay.

11. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Kenya. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the Kenyan courts.

12. Contact Us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how your information is handled, please contact us:

Privacy Officer - Kenya

Email: legal@docplan.app

Support: support@docplan.app

Website: https://docplan.app

You also have the right to file a complaint with the Office of the Data Protection Commissioner of Kenya if you believe your privacy rights have been violated.

13. Acknowledgment

By using Docplan, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use our services.