Privacy Policy
Version 2026-08-16
1. Who we are
pima is a product of Health Intel Ltd, a company registered in Kenya.
- Registered address: 90 JGO, James Gichuru Road, Lavington, Nairobi, Kenya
- Contact: hello@pima.co.ke
Health Intel Ltd is the data controller for the information described in this policy.
2. What this policy covers
This policy covers three sites we operate:
| Site | What it is |
|---|---|
| pima.co.ke | this website |
| docs.pima.co.ke | our public product documentation |
| app.pima.co.ke | our evaluation demo of pima |
It does not cover pima installations run by someone else. pima is normally deployed by a health facility or ministry onto infrastructure they control. In those deployments they are the data controller, they hold the data, and their privacy policy applies — not this one. We have no access to those installations.
3. When you browse these sites
We do not use analytics, advertising, tracking pixels, or third-party scripts of any kind. These sites make no requests to any other company's servers. There is no cookie banner because there are no tracking cookies to consent to.
What does happen, as on any web server:
- Server access logs. Our web server records the request: your IP address, the page requested, the time, the browser's user-agent string, and the response status. These are kept for security and troubleshooting — investigating errors, abuse, or attacks. They are not used to build a profile of you and are not combined with anything else.
- pima.co.ke sets no cookies and stores nothing in your browser.
- docs.pima.co.ke may store a light/dark theme preference in your browser's local storage. It stays on your device and is never sent to us.
- app.pima.co.ke, being an application you log into, stores a session token and interface preferences in your browser. These are necessary for you to stay signed in.
4. When you request evaluation access
To ask for access to our demo, we collect:
- Required: your name and email address.
- Optional, if you choose to give them: company, job title, industry, country, and what you want to use pima for.
- Recorded automatically: the page you applied from, your IP address and browser user-agent, the time you accepted the evaluation terms, and which version of this policy was in force.
Why. To decide whether to grant access, to create your account if we do, to contact you about your request, and to keep a record of the decision.
Where it is stored. In a separate database from the pima application itself. Information about our commercial relationships never sits inside a pima instance — not ours, and never one belonging to a customer. This is an architectural rule for us, not a preference.
Marketing is separate and opt-in. The registration form has an unticked box for occasional product updates. Leaving it unticked has no effect on your application. If you tick it you can unsubscribe at any time, and we will still send you the transactional email described in section 7.
5. When you sign in with Google
You may request access or sign in using a Google account. If you do:
We ask Google for two things only: your email address and basic profile
information (email and profile). Google classifies both as
non-sensitive.
We cannot see, and never request, your Gmail, Google Drive, Calendar, Contacts, photos, or any other Google service. The permission we ask for does not grant access to them.
From Google we receive your Google account identifier, email address, and display name. We use them to:
- match you to an existing pima account, if you already have one; or
- create a pending access request for a human to review.
Signing in with Google does not create an account. An unrecognised Google identity produces a request awaiting approval, and nothing more. There is no automatic sign-up.
We do not use Google user data for advertising or profiling, and we do not sell it, share it, or transfer it to anyone, except to the infrastructure providers in section 9 who process it on our instructions.
6. Evaluation accounts and the demo
If your request is approved, we create an account on app.pima.co.ke with:
- read-only access, and no permission to view personal identifiers — patient identifiers are masked for evaluation accounts;
- an automatic expiry after 90 days, after which the account stops working.
The demo contains synthetic data only. The patient records you will see are computer-generated for demonstration. No real patient's information is present in the demo, and none is ever loaded into it.
7. Email we send you
We send only transactional email connected to your request or account:
- acknowledgement that we received your request;
- our decision;
- account set-up and password-reset messages.
Product-update email is sent only if you opted in (section 4). Our hosted services send mail through Microsoft Azure Communication Services.
8. How long we keep things
| What | How long |
|---|---|
| Declined or dormant access requests | 30 days, then deleted |
| Approved evaluation accounts | expire after 90 days |
| Records of approved applications | kept while the account exists, and afterwards as a record of the decision |
| Server access logs | a short operational period, then rotated and discarded |
| Marketing-list membership | until you unsubscribe |
9. Who else is involved
We keep this list short deliberately. Your information is handled by:
- Microsoft Azure — hosting for our own instances, and the service that delivers our email.
They act on our instructions and may not use your information for their own purposes.
We do not sell personal information. We have never done so and have no plans to.
10. Your rights
You may ask us to:
- tell you what information we hold about you;
- correct anything inaccurate;
- delete it;
- stop using it for a given purpose, including marketing;
- give you a copy in a portable form.
Write to hello@pima.co.ke and we will respond. If you are unsatisfied, you may complain to your national data-protection authority — in Kenya, the Office of the Data Protection Commissioner.
Deleting a demo account is straightforward: ask, and we will remove it. You do not need a reason.
11. How we protect information
- Traffic to all three sites is encrypted in transit (HTTPS).
- Access to the demo is decided by a policy engine, and personal identifiers are masked from accounts that hold no permission to see them — evaluation accounts hold none.
- Passwords are stored hashed. Password-reset links are single-use, expire, and are only ever sent over an encrypted connection.
- Commercial records are held in a database separate from the application (section 4).
No system is perfectly secure, and we do not claim otherwise. If a breach affects you we will tell you and the relevant authority as required by law.
12. Changes to this policy
This policy carries a version. When it changes materially we will publish a new version and update the date. Where you have given us information, we record which version was in force at the time.
Version 2026-08-16. Superseded versions are available on request.