Privacy Policy
How LOGICODE Systems Limited processes personal data in line with the Kenya Data Protection Act, 2019.
Last updated: 27 June 2026
1. Who we are
LOGICODE Systems Limited (“LOGICODE”, “we”, “us”) is the data controller for personal data collected through logicodesystems.co.ke and related online services including Medico Connect and Medico Meeting.
- Registered address: Muthaiga Square, Block A, 3rd Floor No. 1320, Nairobi, Kenya
- General enquiries: info@logicodesystems.co.ke
- Privacy & data rights: privacy@logicodesystems.co.ke
- Data Protection Officer: Data Protection Contact — privacy@logicodesystems.co.ke · +254 717 59 49 32
1a. ODPC registration
LOGICODE Systems Limited assesses its obligations under the Kenya Data Protection Act, 2019 and engages with the Office of the Data Protection Commissioner (Kenya) regarding registration as a data controller and/or processor where required for our products and services. For registration status enquiries, contact privacy@logicodesystems.co.ke.
2. Scope
This policy applies to visitors, prospective customers, registered Medico Connect users, and participants in meetings or consultations hosted through our platforms. It does not replace the privacy notices of hospital or enterprise customers who deploy our software on their own infrastructure.
2a. Sensitive personal data in our products
Our enterprise products — including Medico HMS, PACS, HRMS & Payroll, and biometric attendance integrations — may process sensitive personal data such as health records, employee records and biometric identifiers when deployed for customers. Under the Kenya Data Protection Act, such data requires heightened safeguards, lawful basis, purpose limitation and additional care.
This marketing website does not host live patient or employee production databases. Demo access uses isolated sandboxes with synthetic or de-identified data. Customer deployments are governed by separate contracts and data processing agreements. See our Data Security & Sensitive Data page for product-level controls.
3. Legal bases under the Kenya Data Protection Act, 2019
We process personal data only where a lawful basis applies. General bases include consent, contract, legitimate interests and legal obligation. For sensitive categories in our products:
| Processing context | Typical data | Lawful basis | Data controller |
|---|---|---|---|
| Patient health records (Medico HMS, PACS, LIMS — customer deployments) | Clinical records, imaging studies, lab results, billing linked to care | Contract with the healthcare facility; vital interests / public health duties of the hospital; explicit consent or another lawful basis determined by the hospital as data controller | The hospital or clinic deploying the system (LOGICODE typically acts as data processor) |
| Employee & payroll records (HRMS & Finance) | Staff identity, payroll numbers, salary, attendance, leave, tax and statutory deductions | Contract of employment; legal obligation (tax, labour and statutory filings); legitimate interests in workforce administration balanced against employee rights | The employer organisation (LOGICODE as processor when hosted/managed under contract) |
| Biometric attendance data | Biometric identifiers, check-in/out events, device logs, payroll number matching | Explicit consent or another lawful basis documented by the employer; necessary for employment administration where permitted by law | The employer; LOGICODE provides integration/API services as processor |
| This website (marketing, demo requests, Medico Connect) | Contact details, account data, cookies, chat and meeting metadata | Consent, contract (responding to enquiries), and legitimate interests (security and service operation) | LOGICODE Systems Limited |
4. Personal data we collect (this website)
| Activity | Data types |
|---|---|
| Contact & demo requests | Name, organisation, email, phone, message content, product interest |
| Medico Connect registration | Name, email address, password (stored hashed), session identifiers |
| Global chat (no account) | Display name you choose, chat messages, guest session ID |
| Private messages & calls | Account data, message content, call signalling metadata |
| Meetings | Display name, meeting chat, optional file attachments, session tokens |
| Website technical data | IP address, browser type, device information, server logs, cookie identifiers |
Please do not submit special-category data (such as detailed health records) through general contact forms or public chat unless we have expressly invited you to do so through a secure channel.
5. How we use personal data
- Respond to enquiries, demos and support requests
- Provide Medico Connect, meetings and related features you choose to use
- Secure our systems, prevent fraud and enforce acceptable use
- Comply with legal and regulatory obligations
- Improve our websites and products (aggregated or anonymised where possible)
We do not sell your personal data. When you submit forms, register an account, or save cookie preferences, we also record consent evidence (timestamp, policy version and limited technical metadata) in our secure audit logs for regulatory accountability.
6. Cookies and similar technologies
We use cookies, session storage and browser local storage. Non-essential technologies are only activated after you provide consent through our cookie banner. See our Cookie Policy for details and to manage your preferences.
7. Sharing and processors
We share personal data only with trusted service providers who process data on our instructions, or when required by law. Key processors include:
- Hosting provider (cPanel / Truehost) — Website and application hosting (Kenya / as contracted)
- Jitsi / 8x8 (JAAS) — Video meetings when you use Medico Meeting (May process outside Kenya — see cross-border section)
- jsDelivr CDN — Delivery of open-source front-end libraries (Global CDN — IP address may be processed)
- Google Fonts — Web typography when you consent to external content (Google LLC — may process outside Kenya)
8. Cross-border transfers
Some processors may store or process data outside Kenya. Where this occurs, we implement appropriate safeguards under the Kenya Data Protection Act — including contractual protections and, where required, your explicit consent before activating optional third-party services (such as external fonts or video infrastructure).
9. Retention
- Contact enquiries: 24 months from last interaction, unless a longer period is required by law or an active contract
- Marketing consent: Until you withdraw consent or 24 months of inactivity, whichever is sooner
- Connect accounts: For the life of your account plus 12 months after deletion, unless law requires longer retention
- Connect messages: 12 months from the date sent, unless you delete your account sooner
- Meeting chat: 90 days from the meeting date
- Server logs: 90 days
- Cookie consent records: 12 months from the date consent was given or updated
- Form consent records: 24 months for audit and regulatory evidence
10. Security
We apply technical and organisational measures including HTTPS (TLS), security headers, access controls, password hashing, CSRF protection, consent audit logging and restricted server access. Deployed products support role-based access, audit trails and encryption in transit; customer environments should implement encryption at rest, backup protection and incident response in line with our Data Security documentation.
11. Your rights
Under the Kenya Data Protection Act, 2019 you have the right to:
- Be informed about processing (this policy)
- Access personal data we hold about you
- Request correction of inaccurate data
- Request erasure where applicable
- Object to or restrict certain processing
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with the Office of the Data Protection Commissioner (Kenya)
See Your Data Rights to submit an access, erasure or correction request via our secure form or DPO email. We aim to respond within 30 days.
11a. Personal data breach notification
If a personal data breach affects systems controlled by LOGICODE, we follow our incident response procedure including:
- Contain the incident and preserve evidence (logs, affected systems, timeline).
- Notify the Data Protection Officer immediately at the breach contact email.
- Assess whether personal data was accessed, lost, or disclosed without authority.
- Where required, notify the Office of the Data Protection Commissioner (Kenya) within 72 hours of becoming aware of the breach.
- Notify affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
- Document remediation, root cause and preventive measures in an internal breach register.
Report suspected breaches to privacy@logicodesystems.co.ke. Where required under the Kenya Data Protection Act, we notify the ODPC within 72 hours of becoming aware of a notifiable breach.
12. Children
Our services are intended for adults and organisations. We do not knowingly collect personal data from children under 18 without parental or guardian consent. Contact us if you believe a child has provided data through our site.
13. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated date. Where required, we will seek fresh consent.
14. Contact
Privacy enquiries: privacy@logicodesystems.co.ke
Data Protection Contact: privacy@logicodesystems.co.ke · +254 717 59 49 32