Privacy Policy & Data Protection Statement
At SupaHR, we take the confidentiality, privacy, and integrity of workforce and healthcare data with paramount seriousness. Because our platform processes sensitive personal records—including clinician licensing numbers (KMPDC, NCK), Kenya Revenue Authority Personal Identification Numbers (KRA PINs), National Identification numbers, and M-PESA mobile payment endpoints—we have engineered our data protection practices to strictly adhere to the Kenya Data Protection Act, 2019 (KDPA) and the Kenya Employment Act (Cap. 226).
1. Data Controller vs. Data Processor Roles
Under Section 2 of the KDPA 2019:
- Our Client (Your Organization): The hospital, security firm, manufacturing enterprise, or commercial company that subscribes to SupaHR acts as the Data Controller. Your organization determines the purpose and legal basis for collecting employee, contractor, and clinician data.
- SupaHR Africa: Acts strictly as the Data Processor, processing personal data only on documented lawful instructions from the Data Controller to provide duty rostering, fatigue monitoring, statutory tax calculations, and bulk disbursement execution.
2. Categories of Personal Data Collected & Processed
We process only data strictly necessary for workforce scheduling and payroll fulfillment:
- Personal Identity Data: Full legal names, national identification numbers, passport numbers, email addresses, and phone numbers.
- Professional Regulatory Credentials: KMPDC numbers (medical practitioners), Nursing Council of Kenya (NCK) PINs, Private Security Regulatory Authority (PSRA) credentials, and NTSA driver licenses.
- Statutory Tax & Health Identification: KRA PIN numbers, Social Health Insurance Fund (SHIF) registration IDs, and National Social Security Fund (NSSF) numbers.
- Financial Disbursement Data: Safaricom M-PESA registered mobile numbers and bank account coordinates for salary payment clearing.
- Shift Attendance & Fatigue Telemetry: Clock-in/out timestamps, shift swap audit logs, fatigue rest intervals, and overtime equity records.
3. Lawful Basis for Processing
4. Data Sovereignty & Technical Security Safeguards
- Data Encryption: All personal data is encrypted at rest using AES-256 and in transit using TLS 1.3 cryptographic protocols.
- Multi-Tenant Isolation: Every subscribing organization operates in a strictly partitioned tenant container with role-based access control (RBAC). No tenant can access or view another organization’s clinician or payroll records.
- Kenyan Financial Integration: Payment transactions utilize Safaricom Daraja API endpoints with encrypted credentials and asynchronous webhook validation.
5. Employee Data Rights (KDPA Part IV)
In accordance with Sections 26 through 40 of the Kenya Data Protection Act, every employee whose data is held in SupaHR maintains:
- Right to be Informed: To know what personal data is collected and how it is utilized.
- Right of Access: To view their payslips, shift schedules, and statutory deduction statements at any time.
- Right to Rectification: To have outdated or inaccurate personal data amended without undue delay.
- Right to Data Portability: To export comprehensive employment and tax archives in standard interoperable formats (CSV/JSON/PDF) per SOP-011.
6. Contact the Data Protection Officer (DPO)
For any inquiries, requests for data export, or audit clarifications, please contact our Data Protection Compliance Officer at:
Email: privacy@supahr.co.ke
Physical Address: SupaHR Africa Compliance Office, The Oval, Ring Road Parklands, Westlands, Nairobi, Kenya.