Effective as of October 13, 2023
MyDaktari is a virtual healthcare platform that enables individuals to access clinical healthcare services and tools to help manage their healthcare through a mobile app.
We are passionate about the protection of your Personal Information and Personal Health Information and committed to respecting your privacy.
By accessing or using MyDaktari Services, you understand that your information will be treated in accordance with this MyDaktari Privacy Commitment (“Privacy Commitment”). Our Privacy Commitment and practices are consistent with the 10 Fair Information Principles and we strive to apply the principles of Privacy by Design in the development and review of our products and services.
If you do not want us to collect, use or disclose your Personal Information or Personal Health Information in the ways identified in this Privacy Commitment, you may choose not to use MyDaktari Services.
Details
We have developed this Privacy Commitment to provide you with specific details about how MyDaktari collects, uses, discloses and stores your Personal Information, which includes your Personal Health Information, when you use the MyDaktari app or otherwise interact with us. This Privacy Commitment reflects the requirements of applicable Tanzanian privacy legislation, including federal privacy laws, and our own continuing commitment to privacy.
Please read this Privacy Commitment carefully. By accessing or using our Services, you consent to the collection, use, disclosure and storage of Personal Information in accordance with this Privacy Commitment.
Definitions
The following definitions apply to this Privacy Commitment.
You - An individual who uses, or registers to use, our Services.
Medical Record - A record of your Personal Health Information. This may include but is not limited to:
the name(s) of your Healthcare Practitioner(s) at each visit; patient identification (i.e., name, address, phone number, personal health number, contact person in case of emergencies) and a medical history; any photos you upload for use by your Healthcare Practitioner records of examinations carried out by Healthcare Practitioners and clinical notes for each patient encounter; requisitions for treatment or investigation; consents to treatment obtained in writing; records of treatment you receive from Healthcare Practitioners through our Services; reports of investigative procedures and reports of the results of laboratory, pathology, consultations, diagnostic imaging examinations or tests; diagnoses; and a record of missed and/or cancelled appointments. Your Medical Record excludes your MyDaktari account profile.
Healthcare Practitioners – Practitioners that provide or assist in the provision of healthcare through our Services, which may include physicians, nurse practitioners, registered nurses, psychologists, dietitians, and mental health therapists.
Personal Health Information - Any Personal Information regulated under applicable health privacy legislation in the provinces in which we operate, including information that relates to an individual’s physical or mental health and healthcare including health history, the provision of healthcare to the individual, payments or eligibility for healthcare, healthcare provider, substitute decision-maker, health card number or other healthcare-related personal identification numbers, or any other information that is collected in the course of providing health services to the individual, including information contained in your Medical Record. Personal Health Information excludes data obtained through the use of Symptom Checker, Healthcheck, and Monitor, unless specified.
Personal Information - Any information about an identifiable individual, other than business contact information used to contact the individual in their business or professional capacity. Personal Information includes your MyDaktari account profile and Personal Health Information.
Personal Information does not include de-identified or aggregated information that cannot reasonably be associated with a specific individual.
Services - The MyDaktari app.
MyDaktari - In this Privacy Commitment, the words "we", "us", "our" or "MyDaktari" refer to MyDaktari.
MyDaktari Family – In this Privacy Commitment, “MyDaktari Family” means MyDaktari and its subsidiary companies and corporate affiliates, as they may exist from time to time.
Accountability
MyDaktari has overall responsibility for protecting the privacy of your Medical Records and other Personal Information and we are directly accountable to you.
Details
Consultations with Healthcare Practitioners are available in Tanzania. In this country, MyDaktari has overall responsibility for protecting your Personal Health Information, including your Medical Record, and we are directly accountable to you.
Your healthcare providers, such as your physician, also have overall responsibility for the privacy of your Personal Health Information and MyDaktari assists them with that responsibility. More precisely, MyDaktari collects, uses, and discloses Personal Health Information on behalf of healthcare providers who are ‘custodians’.
For all other Personal Information collected through our Services, including through your use of Symptom Checker, Healthcheck, Monitor, MyDaktari has overall responsibility across Tanzania.
Consent
When you access or use our Services, you consent to our collection, use, disclosure, and storage of your Personal Information as described in this Privacy Commitment.
You can withdraw your consent at any time, subject to limited restrictions.
Details
When you use our Services, you consent to our collection, use, disclosure, and storage of your Personal Information in accordance with this Privacy Commitment.
You can withdraw your consent to the collection, use and disclosure of your Personal Information, subject to our legal or contractual restrictions. However, if you refuse to provide certain information or withdraw your consent, this may limit our ability to provide you with certain Services, products and functionalities.
You can close your account at any time. If you wish to close your account or request the deletion of your personal information, you can do so by contacting MyDaktari Support Team. We will close your account or delete your Personal Information promptly and will confirm with you by email when this is completed. If you close your account or request deletion of your Personal Information, we may retain certain information to meet our legal or regulatory obligations; for example, Personal Information that forms part of your Medical Record must be retained for a period of time to meet legal and regulatory obligations. Please review the ‘Retention’ section below for more information on our retention practices.
To collect, use or disclose Personal Information outside of the purposes contemplated in this Privacy Commitment, we will seek your additional consent.
Individuals under the age of 16 may not create an account with MyDaktari, but a parent or legal guardian may book a healthcare consultation appointment or create a user profile for a minor on the parent or legal guardian’s own account.
Collection and Use of Personal Information
We collect only the Personal Information required for us to establish and maintain a responsible healthcare and service relationship with you, to provide our Services, and to develop, enhance or market our products and services (including to send you relevant information about products and services that may be of interest to you) and to maintain and improve the security and functionality of the MyDaktari app.
We collect Personal Information to set up an account for you on the MyDaktari app so that you can access and use the MyDaktari health-related services, including:
Consultations with Healthcare Practitioners virtually. MyDaktari AI-powered Symptom Checker MyDaktari AI-powered Healthcheck MyDaktari Monitor.
We also collect other information from you as you use our Services:
App usage information Website and device information Cookies Payment information or healthcare number We may use Personal Information to send you relevant marketing messages. You can opt out of receiving them at any time.
Details
By creating an account with MyDaktari, you will have access to consultations with Healthcare Practitioners through video conversations and related healthcare and administrative support services (i.e., prescription services, laboratory requisitions, etc.), as well as other tools to help you manage your healthcare through the app, including MyDaktari AI-powered Symptom Checker, MyDaktari AI-powered Healthcheck, and MyDaktari Monitor. Depending on your location, following an initial virtual consultation, you may also be able to access consultations with our Healthcare Practitioners in our physical clinics.
We only collect and use Personal Information for the following purposes:
To establish and maintain our relationship with you
MyDaktari Account Creation: In order to use our Services, you will need to download the MyDaktari app and create an account by providing your first and last name, date of birth, email address, address of residence and a password that you select.
Once you have created an account, you will have access to all of the Services available through the app, including healthcare consultations, Symptom Checker, Healthcheck and Monitor. Creating an account is required to enable MyDaktari to provide you with accurate and relevant information based on your Personal Information and records of your previous interactions with the app, such as your interactions with the health-related tools described below, healthcare consultation summary, and prescription history.
Identity Verification and Confirmation: At the time of booking your first appointment with a Healthcare Practitioner in Tanzania, you may be required to verify your identity and provide details such as your address, phone number, and sex assigned at birth.
We verify your identity in order to prevent someone from creating an account in your name and to help prevent fraud. You can verify your identity by providing a photo of your government-issued identification (either driver’s license, passport, or government-issued photo identification card) and a real-time selfie photo. We use a third-party service provider who matches the photo on your identification card to the selfie you upload and validates the authenticity of the selfie and identification card provided. We do not use this information for any other purpose. You may be required to show your government-issued photo identification manually during your first consultation with a Healthcare Practitioner.
At the time of booking your first consultation appointment with a Healthcare Practitioner in Tanzania, you may be required to provide additional information. For example, you may need to enter your home address and your date of birth (if not already provided). Before each consultation with a Healthcare Practitioner, you may be asked questions to confirm your identity using information from your MyDaktari account profile. For example, you may be asked to confirm your phone number, date of birth, and first and last name.
To provide health-related services and tools to you
Healthcare consultations in Tanzania: You will need to provide information about your current health condition and health history to Healthcare Practitioners, including any relevant photos you choose to provide, in order to enable MyDaktari to provide you with healthcare. This information will also be used to complete and update your Medical Record. The MyDaktari Chief Medical Officer and Medical Directors of our MyDaktari clinics may review Healthcare Practitioners’ work to ensure they are meeting the high standard and quality of care expected of them.
Real-Time Video Conversations in Tanzania: Where you wish to have a virtual consultation with a Healthcare Practitioner, we connect you through a real-time video call. All video calls conducted through the MyDaktari app are confidential. Recordings are never made.
AI Symptom Checker: To use our AI-powered Symptom Checker, you will be asked to provide information about your current health condition, health history and other information including your sex assigned at birth and date of birth (if not already provided). This information will be used by Symptom Checker to analyze your symptoms and provide you with relevant and appropriate information on possible next steps through an AI-powered chatbot.
The Personal Information provided in Symptom Checker is not entered in or considered part of your Medical Record. Healthcare Practitioners do not have access to the information in Symptom Checker (other than your sex assigned at birth and date of birth that will be saved in your MyDaktari account profile if you have not provided them previously). However, we maintain the information you provide to the Symptom Checker and your interactions with the Symptom Checker chatbot so that you can review historical interactions and to assist you in the future without having to re-enter the same information each time you use the Symptom Checker. We may also use this information to contact you if we become aware that the information you received through Symptom Checker is inaccurate, or if we believe there is a risk to your health or safety. If you are using the Symptom Checker for someone else, we collect and maintain the name, sex assigned at birth, date of birth and chat history for that person for the same purposes.
AI Healthcheck: To use our AI-powered Healthcheck, you will be asked to provide information related to activity, nutrition and mood as well as your sex assigned at birth and age (if not already provided) in order for Healthcheck to provide an understanding of how your lifestyle can impact your future health. Results can be explored using your Digital Twin in Healthcheck.
The Personal Information provided in Healthcheck is not entered in or considered part of the Medical Record. Healthcare Practitioners do not have access to the information entered into Healthcheck (other than your sex assigned at birth that will be saved in your MyDaktari account profile if you have not provided it previously).
Monitor: To use Monitor, you will be asked to provide Personal Information related to medication and weight so that you can set up medication reminders and track your overall health such as triggers and events that may impact your well-being. You can also use Monitor to connect to other apps such as the Apple Health App, Fitbit and Garmin. If you choose to use any of these apps, you will be asked for your consent for MyDaktari to read or sync the data in the app(s), such as the number of steps you take.
The Personal Information provided in Monitor is not entered in or considered part of the Medical Record. Healthcare Practitioners do not have access to the information in Monitor.
Payments: For consultations with physicians, you will be required to purchase any Services from us, we collect your payment information such as your payment method, payment card number, CVV code and signature (physical clinics only). This information is used to process your payments. We use a third-party service provider who is Payment Card Industry Data Security Standard (PCI DSS) compliant to facilitate secure payment processing.
Service Messages: We may contact you by SMS, email or push notification to provide you with helpful information related to our Services such as how to prepare for your appointment, reminders, and other important information or updates. You can turn off push notifications at any time in your device settings.
Location-based Services: Certain features of the MyDaktari app request your permission to use GPS technology to collect real-time information about the location of your device so that MyDaktari Health MyCare can help you locate a pharmacy or another healthcare service in your area. This service is provided for your convenience only, and your permission for this use is voluntary. This location data is not retained or used for any other purpose.
MyDaktari Technical Support: In certain circumstances, Personal Information may be required by or accessible to technical support staff in order to resolve technical issues. Where possible, our support team will resolve issues without viewing Personal Information. If you speak to MyDaktari support, all audio conversations are recorded to ensure quality of service to you and for training purposes.
To develop, enhance or market our products and services
Developing and enhancing our services: We analyze Personal Information in your MyDaktari account profile and actions you take on the MyDaktari app (such as your usage patterns on Healthcheck and Monitor) and your ratings or responses to surveys, to better understand how we can improve and what care programs or services to provide. For example, we may use your postal code and aggregate it with all other MyDaktari user postal codes to determine the best location to open a new physical clinic. We do not use information from your Medical Record for this purpose.
Satisfaction and experience surveys and questionnaires: Your name and email address may be used by us to contact you regarding your experience when using our Services. We may ask for additional information to follow-up. We may share this information with our third-party to address an issue or concern and to improve our service offerings.
Sending marketing communications: Your MyDaktari contact details, including your name, phone number, email address and home address, may be used so that MyDaktari can provide you with news and offers by SMS, email or mail about MyDaktari, the MyDaktari Family, and third-party partners. These communications may be tailored based on data in your account profile and app activity, but not information contained in your Medical Record. We may send you offers for a MyDaktari service you may not currently subscribe to, or send you offers for a MyDaktari third-party partner that may be of interest to you. For example, a company that offers fitness or lifestyle services.
We may use your email address or phone number (where available) to digitally deliver ads about our services and offers on third-party websites and apps where we purchase advertising from our partners. We only share anonymized and aggregated information with our third-party partners and will not use information contained in your Medical
Record: You can opt out of receiving marketing messages from us at any time by following the unsubscribe instructions included in each of our marketing messages or by contacting us as set out below.
To maintain and improve the security, performance and functionality of the MyDaktari App
Device Information: As with many applications, certain limited technical data is required for the MyDaktari app to function on your device. The information we collect includes information about your device and operating system, such as the type of device hardware and operating system, unique device identifier, IP address, language settings, and the date and time the app accesses our servers. This information is used to deliver content appropriate for your device’s capabilities, to deliver push notifications and to help ensure a secure experience and detect anomalous behaviour in order to protect Personal Information from unauthorized access. In addition, in the event the MyDaktari app crashes on your mobile device, we may receive information about your mobile device model software version and device carrier, which allows us to identify and fix bugs and otherwise improve the performance of the MyDaktari app.
App Usage Information: We may collect and analyze information about the actions you take on the MyDaktari app (such as your usage patterns on Healthcheck and Monitor) to better understand what care programs or services to provide.
Cookies: Please see our Cookies Notice for information on our use of Cookies.
De-Identification and Aggregation
De-Identifying and Aggregating Information: We may de-identify or aggregate your Personal Information, including information in your Medical Record, such that it cannot reasonably be associated with you, for the following purposes:
(i) To protect your privacy and the security of your Personal Information;
(ii) To conduct analytics and/or research in a privacy protective manner to:
a) better understand and improve our Services;
b) operate and expand our business opportunities; and
c) improve health outcomes.
We may share such de-identified information or insights with our partners to assist in research, planning, or product and service development. Sharing and Disclosure of Personal Information
For continuity of care purposes, we may share Personal Information among your Healthcare Practitioners and others who assist in the provision of healthcare to you.
We will not disclose your Personal Information for any purpose other than what has been outlined in this Privacy Commitment or as permitted under applicable law, unless we obtain your express consent. We disclose only the limited amount of Personal Information necessary to meet these purposes.
We do not sell your Personal Information to any third parties.
We may share your Personal Information with our service providers who are contracted to perform services or functions on our behalf where they require the information to assist us in serving you. We use contractual controls to protect this information and limit its use to what is necessary for the service provider to perform the service.
Details
We may share or disclose Personal Information for the following purposes:
Provision of Healthcare: If you receive healthcare through our Services, we may disclose your Personal Information to and among your Healthcare Practitioners for the purpose of providing or assisting in the provision of healthcare to you. We may also disclose your Personal Information to third parties such as other health professionals, specialists, pharmacists, pharmacies and laboratories for the purpose of providing or assisting in the provision of healthcare to you – this includes, but is not limited to, providing medically appropriate referrals, prescriptions, or lab and imaging requisitions to you. Information will only be shared with your family doctor, hospital, lab or specialist with your consent (unless we are required to do so under applicable laws).
Your Medical Record will be stored in the MyDaktari Clinical Portal and will be accessible to Healthcare Practitioners who provide or assist in the provision of healthcare services to you from our physical clinics or virtual care app. A record of all Tanzanian appointments will be stored in the MyDaktari app.
Service Providers: We may share Personal Information with our suppliers, agents or other organizations or individuals who are contracted to perform services or functions on our behalf, where they require the information to assist us in serving you. For example, we may use service providers to verify identification, process payments, power the app, host our website and store and dispose of information on our behalf. We strive to minimize the amount of Personal Information that we share with our service providers and partners and require that it not be used for any other purpose.
Disclosing Personal Information to Adalo with your express consent: If you give us your express consent, MyDaktari will share with our software provider, Adalo, your Personal Information, including your Medical Record, in order to allow Babylon Partners Limited to improve the performance of the Adalo software technology, which powers the MyDaktari app. Pursuant to their privacy policy, which can be found on their website, Adalo will remove personal identifiers (such as your name, address and date of birth) prior to using or storing the information we disclose. Personal Information you agree to disclose to Adalo will be treated in accordance with the Adalo privacy policy.
Within the MyDaktari Family: Your name, email address, and home address may be shared within the MyDaktari Family and matched to your existing MyDaktari customer profile (if applicable) to identify other services that you have with the MyDaktari Family. This information may be used to:
Perform aggregated reporting and demographic analysis; Ask for your feedback on our Services through surveys or other means; and Help us and the MyDaktari Family provide better recommendations of MyDaktari products and services that may be of interest to you and exclude those that are not relevant. For example, we and the MyDaktari Family will try not to contact you to register for the MyDaktari app if you have already downloaded the MyDaktari app and registered for our Services. Disclosures required or permitted by law or regulation: We may disclose Personal Information to the extent necessary where we are required or permitted under applicable law, such as in the event of an emergency that threatens the life, health or security of an individual. We or our service providers will also share Personal Information with law enforcement, courts, other government agencies or other parties if we are required to do so to meet our legal and regulatory requirements in the jurisdictions in which we or our service providers operate; for example, we are required to provide records to law enforcement in response to a valid court order.
Third Party Links: The MyDaktari app and website may contain links to other websites or platforms that MyDaktari does not own or operate. Also, links to our Services may be featured on third party websites or platforms as advertisements. Except as provided in this Privacy Commitment, we will not provide Information to these third parties without consent. We provide links to third party websites or platforms as a convenience to our users. These links are not intended as an endorsement of, or referral to, the linked websites or platforms. The linked websites or platforms have separate and independent privacy policies, notices and terms of use. We do not have any control over such websites or platforms, and therefore we have no responsibility or liability for the manner in which the organizations that operate such linked websites or platforms may collect, use, disclose, secure and otherwise handle Personal Information. Access, Corrections, and Accuracy of your Personal Information
You can request access to or correction of your Personal Information by contacting us at info.mydaktari@gmail.com.
We rely on you to keep your Personal Information up-to-date and accurate so that we can serve you.
Details You may request access and corrections to the Personal Information we hold about you at any time, subject to limited exceptions. Upon written request, we will also provide you with a list of individuals or entities (e.g. third party service providers) with whom we have shared or disclosed your Personal Information, if applicable. Please contact info.mydaktari@gmail.com for additional information.
We rely on you to ensure that the Personal Information on the MyDaktari app is accurate, complete and up-to-date. You are welcome to make changes or request deletions or corrections to Personal Information we hold about you at any time by updating your account profile on the MyDaktari app or by contacting us at info.mydaktari@gmail.com.
For a copy of your Personal Information, please contact us at info.mydaktari@gmail.com. We will take reasonable steps to verify your identity before granting access or making corrections. In addition, your right to access or correct your Personal Information is subject to certain legal restrictions.
Storage and Location of your Personal Information
Your Personal Information, including your Medical Record for consultations conducted in Tanzania, is stored in Tanzania and cannot be accessed from outside Tanzania, with only a few limited exceptions.
Details
Your Tanzanian Medical Record is stored in data centers in Tanzania. Your Medical Record will only be accessed from outside Tanzania in limited circumstances by our software service provider’s technical support team, including maintaining, repairing, trouble-shooting or upgrading the MyDaktari app software.
We also use service providers who may access or store other Personal Information in Canada, Ireland, the EU, the United States or other jurisdictions.
Retention
We retain Personal Information only for as long as necessary to fulfil the purposes described in this Privacy Commitment or as required to meet legal or regulatory requirements.
Personal Information that forms part of your Medical Record must be retained for a period of time mandated by law.
Details We retain Personal Information only for as long as necessary to fulfil the purposes described in this Privacy Commitment or as required to meet legal or regulatory requirements. We may also create and retain de-identified information, and continue to use this information in accordance with this Privacy Commitment.
At your request, we will delete your Personal Information unless we are required to retain it to meet our legal or regulatory obligations.
Medical Records must be retained in accordance with provincial retention guidelines. In general, for Medical Records, we will follow a retention of 16 years from either the date of last entry or from the age of majority of the individual to whom the information relates, whichever is later.
Audio recordings of the support services you receive are stored for 90 days.
Safeguards
We have implemented a comprehensive information security program.
Details
We understand that data security is a critical issue and we are committed to safeguarding the Personal Information in our custody or control. We have implemented a comprehensive information security program that includes written policies and procedures, and security controls, as well as reasonable administrative, technical and physical safeguards, in an effort to protect against unauthorized access, use, loss, modification, and disclosure of Personal Information in our custody or control.
Our team members must complete privacy and security training before they have access to any Personal Information, and must complete annual privacy and security training for ongoing access to Personal Information.
MyDaktari ensures that the security policies, procedures, and controls of our service providers meet industry and MyDaktari best practices and are regularly tested.
Please keep in mind that no internet or email transmission is ever fully secure or error free and no security system is impenetrable. We cannot fully guarantee the confidentiality of any information that you provide to us but we can assure you that we will use reasonable and appropriate security controls, reflective of the sensitive nature of Personal Health Information.
It is important for you to play an active role in the protection and safeguarding of your Personal Information, and to guard your privacy when you are online. If the MyDaktari app or website contains links to other websites, this Privacy Commitment does not govern those websites. You should read their privacy policies and make an informed decision about whether you want to use those websites or their services.
Changes to this Privacy Statement
We may make changes to this notice and we will notify you of the changes to our information practices.
Details
This Privacy Commitment may be updated from time to time to reflect changes to our practices. Any notices regarding modifications to this Privacy Commitment will be in written form and provided to you on the MyDaktari app and on our website.
If any changes to this Privacy Commitment are significant, we will provide a more prominent notice (including email notification, if appropriate).
We encourage you to periodically review this Privacy Commitment for the latest information on our privacy practices and to contact us if you have any questions or concerns.
Questions, Complaints, and Contact
You can always reach us at info.mydaktari@gmail.com if you have privacy questions, concerns or complaints.
Details
Please contact us at info.mydaktari@gmail.com or the address below if:
you have any questions related to the collection, use or disclosure of your Personal Information; you need to report any privacy or security violations, including any suspected or actual unauthorized access, use, disclosure or loss of Personal Information; you wish to withdraw your consent to the collection, use or disclosure of Personal Information; you have any questions or comments about this Privacy Commitment; or you otherwise have a question or complaint about the manner in which we or our service providers treat your Personal Information, including our policies and practices with respect to the use of service providers outside Tanzania.
If you wish to access, update, and/or correct inaccuracies in your Personal Information, please contact us at info.mydaktari@gmail.com.
If you have concerns with our Privacy Commitment or privacy practices, we encourage you to first bring your concerns to us at info.mydaktari@gmail.com You may also seek advice from the Office of the Privacy Commissioner of Tanzania or the provincial Privacy Commissioner having jurisdiction, and, if appropriate, file a written complaint with the Commissioner's office.