Data Security & Sensitive Data
How we protect health, workforce and biometric information across LOGICODE products.
Last updated: 27 June 2026
LOGICODE Systems Limited develops systems that may process sensitive personal data under the Kenya Data Protection Act, 2019 — including health information (HMS, PACS, LIMS), employee and payroll records (HRMS), and biometric attendance data. The ODPC expects additional safeguards for such categories.
1. Website vs. deployed products
- This website provides marketing, demo requests and Medico Connect collaboration tools. It does not store hospital EMR or payroll production databases.
- Deployed customer systems (on-premise or hosted) are operated under customer agreements, role-based access and — where applicable — signed Data Processing Agreements (DPAs).
- Demo sandboxes use synthetic or de-identified data. Credentials are issued individually and are never published on this website.
2. Technical safeguards (products)
| Control area | LOGICODE approach |
|---|---|
| Encryption in transit | HTTPS/TLS for web applications; secure API transport for integrations |
| Encryption at rest | Supported in customer deployments per infrastructure design (database/OS-level encryption recommended) |
| Access control | Role-based permissions, least-privilege accounts, separated clinical/finance modules |
| Authentication | Strong password policies; MFA available/recommended for production deployments |
| Audit trails | User activity and clinical/financial transaction logging in enterprise modules |
| Backups | Customer-configured backup schedules with encrypted storage recommended |
| Biometric data | Attendance API transmits workforce events — customers must secure devices, networks and payroll matching |
3. Organisational measures
- Privacy-by-design in product development and customer onboarding
- Data Processing Agreements for hospital and enterprise customers where LOGICODE acts as processor
- Incident response procedures and ODPC breach notification readiness
- Staff confidentiality and access restrictions on production environments
- Regular review of demo sandbox access and credential expiry
4. Demo and evaluation environments
To reduce security and privacy risk we:
- Do not publish live demo passwords on the public website
- Issue time-limited credentials after demo qualification
- Use isolated sandboxes separate from customer production data
- Instruct evaluators to use synthetic data only
- Log demo access requests and consent
5. Customer responsibilities
Hospitals and enterprises deploying LOGICODE software remain responsible for lawful collection of patient and employee data, staff training, ODPC registration where applicable, and local security policies (MFA, physical access, device control).
6. Personal data breach notification (72-hour ODPC workflow)
Suspected breaches affecting LOGICODE-managed services must be reported immediately to privacy@logicodesystems.co.ke.
- Contain the incident and preserve evidence (logs, affected systems, timeline).
- Notify the Data Protection Officer immediately at the breach contact email.
- Assess whether personal data was accessed, lost, or disclosed without authority.
- Where required, notify the Office of the Data Protection Commissioner (Kenya) within 72 hours of becoming aware of the breach.
- Notify affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
- Document remediation, root cause and preventive measures in an internal breach register.
Where the Kenya Data Protection Act requires notification to the Office of the Data Protection Commissioner, we do so within 72 hours of becoming aware of the breach, and inform affected data subjects without undue delay when the breach is likely to result in high risk.
7. Contact
Data Protection Contact
privacy@logicodesystems.co.ke · +254 717 59 49 32