Privacy
Version 2026-08-01
Short version: the clinic owns its patients' records — not us. We hold them so the clinic can work, we do not sell them, we do not advertise against them, and a clinic can export everything and leave at any time.
Who is responsible for what
Under Uganda's Data Protection and Privacy Act, 2019, the clinic is the data controller — it decides what is collected and why, and it owns the records. CareBoon Health is the data processor: we hold and process that data only to run the service, on the clinic's instructions.
This matters if you are a patient: your clinic, not CareBoon, is who you ask about your records. We cannot give you your records directly, because they are not ours to give.
What is held
Names and contact details; clinical information from visits — symptoms, vital signs, diagnoses, prescriptions, procedures, lab and imaging results; billing and insurance details; and staff account records.
Where it is held
On servers in the United States. That is outside Uganda, so it is a cross-border transfer under the Act, and a clinic agrees to it when it accepts our terms. We are stating it plainly rather than burying it: if your clinic requires data to stay in Uganda, CareBoon is not currently able to promise that.
Backups are encrypted with AES-256 before they leave the server, so the company storing them cannot read them.
AI assistance
AI is off unless a clinic turns it on, and it advises — the clinician decides. When it runs:
- Nothing we send from the record identifies the patient. Not the name, not the patient number, not the phone — only de-identified clinical context: age, sex, findings. That covers everything the assistant does except reading a scan image, which works differently and is set out below. We would rather scope this claim than have you find its exception yourself.
- Every run is logged, with what it cost.
- Scans are the exception, and it is worth reading twice. When you
ask us to read an image, the picture is sent as it was captured. Its hidden
file information is stripped, but we do not inspect pixels and we do not
crop — cropping to hide a name could cover part of the study. Many X-ray
and ultrasound machines print the patient's name or number onto the image
itself. Where yours do, that name is sent with the image, outside
Uganda, to the providers listed below.
We advise setting your machines not to print patient details. Where that is not possible and you still want scan reading, your patient consent notice must say that scans may be sent outside Uganda to be read automatically. You can also leave imaging AI off — the assistant will read the radiographer's written report instead, which carries no identifiers.
Who else touches it
| Provider | Where | What for |
|---|---|---|
| Database Mart | United States | Server hosting — the database and uploaded files. |
| Cloudflare | United States / global | DNS and domain registration. No patient data. |
| Google Drive | United States | Encrypted backup storage. Files are encrypted with AES-256 before upload; Google cannot read them. |
| OpenRouter | United States | Optional AI decision support. Receives de-identified clinical context only — never a name, patient number or phone. Off unless the clinic enables it. |
| Brevo | European Union | Sending email, e.g. insurance claim statements. |
We do not sell data to anyone, ever. Sponsored content inside the product is targeted only by a staff member's role and the clinic's region — never by anything about a patient.
How long it is kept
For as long as the clinic uses CareBoon. If a clinic leaves, it exports its data and we delete our copy within 30 days, backups included.
Getting data out
A clinic can export everything to CSV at any time, from inside the product, without asking us. That is deliberate: it is what makes it safe to put data in.
Visitors to this website
We count visits to these public pages so we know whether anyone is finding us. No IP address is stored and no cookie is set for this. A visitor is recorded as a one-way hash that is re-salted every month, so we can count the same person twice in a week and cannot recognise them the following month. We record the page, the site you arrived from (the site's name only, never the full link, which can carry your search terms), and whether you were on a phone. We do not use Google Analytics or any advertising tracker, and none of this touches the clinical system, which is never counted.
Separately from that counting, our web server keeps an ordinary access log, as almost every web server does. It records the request, the time, and the IP address it came from, because without that we cannot tell an attack from a search engine. These lines are kept for 14 days and then deleted, they are used only for security and troubleshooting, and they are never combined with the visit counting above or with anything in the clinical system.
Security
Encrypted connections; access limited by role; an audit log of who opened which record; one signed-in device per account; encrypted off-site backups that are tested by restoring them.
If something goes wrong
We notify affected clinics of a personal-data breach without undue delay and within 72 hours of becoming aware, with what happened and what we are doing.
Contact
Patients: please contact your clinic — they hold your records.
Clinics: support@careboon.com.
See also the terms of service.