Privacy Policy

This policy explains how TrovinaCare collects, uses, stores, and protects your information when you use our Hospital Management System and EHR platform.

Last updated: January 1, 2025  |  ~10 min read
Important Notice for Healthcare Providers

TrovinaCare processes both personal data and sensitive health (medical) data on behalf of hospitals and clinics ("Data Controllers"). If you are a patient, your primary data rights should be exercised directly with your healthcare provider. If you are a healthcare organization, please review our Data Processing Agreement (DPA) which governs our obligations as a Data Processor.

1. Introduction

TrovinaCare ("we", "our", or "us") is a cloud-based Hospital Management System (HMS) and Electronic Health Record (EHR) platform operated by TrovinaCare Ltd., a company incorporated and operating across Africa. We are committed to protecting the privacy and security of all personal data processed through our platform.

This Privacy Policy applies to:

  • Visitors to our website at trovinacare.com
  • Administrators, doctors, nurses, and staff who use the TrovinaCare platform
  • Patient data processed on behalf of our healthcare provider clients
  • Anyone who contacts us for support, demos, or inquiries

By accessing or using TrovinaCare, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the platform and contact your healthcare provider or our team at privacy@trovinacare.com.

2. Information We Collect

We collect different categories of information depending on how you interact with TrovinaCare.

A Account & Organization Data

When a hospital or clinic registers on TrovinaCare, we collect:

  • Organization name, address, and contact details
  • Administrator full name, email address, and phone number
  • Staff profiles including names, roles, credentials, and department assignments
  • Billing information (processed securely via our payment processors)
  • Subscription and usage data
B Patient Health Data

Patient records are entered and managed by your healthcare provider. This data may include:

  • Full name, date of birth, gender, nationality, and contact information
  • Medical history, diagnoses (ICD-10 coded), allergies, and chronic conditions
  • Vitals, SOAP clinical notes, and consultation records
  • Prescriptions and medication history
  • Lab test orders and results
  • Billing and insurance claim information
  • Appointment and visit history
C Usage & Technical Data
  • IP address, browser type, and device information
  • Pages visited, features accessed, and session duration
  • Audit logs of actions performed within the platform (for security and compliance)
  • Error and performance logs
D Communications Data
  • Messages sent via our contact forms, live chat, or support tickets
  • Demo requests and sales inquiries
  • Email correspondence with our team

3. How We Use Your Information

We process personal data only for lawful purposes. Below is a summary of our uses:

Purpose Legal Basis
Providing and maintaining the TrovinaCare platform Contractual necessity
Managing user accounts and permissions Contractual necessity
Processing patient records on behalf of healthcare providers Legitimate interests / Contract
Sending appointment reminders via SMS Legitimate interests / Consent
Billing and subscription management Contractual necessity
Platform security, fraud prevention & audit logging Legitimate interests / Legal obligation
Customer support and troubleshooting Contractual necessity
Sending product updates and service announcements Legitimate interests
Improving platform features through usage analytics Legitimate interests
Compliance with applicable laws and regulations Legal obligation

We do not use patient health data for advertising, sell data to third parties, or use data in ways that conflict with the purposes for which it was originally collected.

4. Data Sharing & Disclosure

TrovinaCare does not sell, rent, or trade personal data. We share data only in the following limited circumstances:

Service Providers & Sub-Processors

We engage carefully vetted third-party vendors to help operate our platform — including cloud hosting providers, SMS gateway partners, payment processors, and analytics tools. All sub-processors are bound by data processing agreements and may only use data to perform services on our behalf.

Legal & Regulatory Compliance

We may disclose data when required to do so by law, court order, or government authority, including applicable data protection authorities in countries where we operate. We will notify affected organizations where legally permitted to do so.

Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the acquiring entity. We will notify affected users prior to any such transfer and ensure continuity of data protection standards.

Healthcare Provider Clients

Patient data is shared with and managed by your healthcare provider (the Data Controller). TrovinaCare acts solely as a Data Processor in this context and follows the instructions of the healthcare organization that engaged our services.

5. Data Storage & Security

We take data security seriously and implement industry-standard technical and organizational measures to protect all data processed on our platform.

256-bit AES Encryption
All data is encrypted at rest and in transit using AES-256 encryption and TLS 1.3.
Role-Based Access Control
Granular permissions ensure staff can only access data relevant to their role.
Automated Daily Backups
Your data is backed up daily with point-in-time recovery capabilities.
Audit Logging
All data access and modifications are logged with timestamps and user attribution.
99.9% Uptime SLA
Hosted on redundant, enterprise-grade cloud infrastructure.
Staff Security Training
All TrovinaCare employees undergo data privacy and security training.

While we implement robust security measures, no system is completely immune to security risks. In the event of a data breach that poses a risk to your rights, we will notify affected organizations within 72 hours in accordance with applicable data protection laws.

6. Health & Medical Data

Special Category Data: Health and medical information is classified as "special category data" under most African data protection frameworks (e.g., Nigeria's NDPR, Kenya's Data Protection Act, South Africa's POPIA) and the GDPR. This data receives the highest level of protection under our policies.

TrovinaCare processes patient health data exclusively as a Data Processor, acting on the documented instructions of our healthcare provider clients (Data Controllers). We commit to the following with respect to health data:

  • No secondary use: Patient health records are never used for marketing, profiling, or any purpose beyond operating the platform for the healthcare provider.
  • No sale of health data: We will never sell or monetize patient medical information under any circumstances.
  • De-identification for analytics: Where aggregate analytics are used to improve our platform, all patient-identifying information is removed or anonymized.
  • Access controls: Only authorized healthcare staff can access patient records, governed by role-based permissions set by the healthcare organization.
  • Deletion on termination: Upon termination of a subscription, healthcare provider data is exported and securely deleted from our systems within 30 days.

7. Cookies & Tracking Technologies

We use cookies and similar tracking technologies on our website and platform to enhance your experience and understand usage patterns.

Cookie Type Purpose Can Opt Out?
Essential Required for login sessions, security tokens, and core platform functionality. No
Functional Remember your preferences such as language, dashboard layout, and settings. Limited
Analytics Understand how features are used to improve the platform (anonymized). Yes
Marketing Track effectiveness of our marketing campaigns on the public website. Yes

You can manage your cookie preferences through your browser settings or our cookie consent banner. Please note that disabling essential cookies may affect platform functionality.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. These rights apply to data for which TrovinaCare is the Data Controller (such as account holder and website visitor data). For patient health records, rights must be exercised with the healthcare provider.

Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data where no legal basis exists to retain it.
Right to Restrict Processing
Ask us to pause processing of your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Where processing is based on consent, withdraw it at any time.
Right to Lodge a Complaint
File a complaint with your local data protection authority.

To exercise any of these rights, please email us at privacy@trovinacare.com with the subject line "Data Rights Request". We will respond within 30 days. We may need to verify your identity before processing your request.

9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.

Data Type Retention Period
Active user account data For the duration of the subscription + 30 days after termination
Patient health records Per healthcare provider instructions (typically 7–10 years per local health regulations)
Billing and financial records 7 years (legal/tax obligation)
Audit logs and security logs 2 years
Support communications 3 years from last interaction
Website analytics data 13 months (anonymized after 30 days)
Marketing communications Until unsubscribe or 3 years of inactivity

10. International Data Transfers

TrovinaCare primarily stores and processes data within Africa. Where data is transferred outside the country of origin for cloud infrastructure or support purposes, we ensure appropriate safeguards are in place, including:

  • Data Processing Agreements (DPAs) with all sub-processors
  • Standard Contractual Clauses (SCCs) where applicable
  • Transfers only to countries with adequate data protection frameworks or under binding corporate rules
  • Compliance with the African Union Convention on Cyber Security and Personal Data Protection where applicable

Healthcare organizations can request a data residency arrangement in their country or region under our Enterprise plan. Please contact privacy@trovinacare.com for details.

11. Children's Privacy

The TrovinaCare platform is intended for use by healthcare organizations and their adult staff members. We do not knowingly collect personal data directly from individuals under the age of 18 for account registration purposes.

Pediatric patient records may be created and managed within the platform by healthcare providers. In such cases, the healthcare provider (as Data Controller) is responsible for ensuring appropriate consent is obtained from parents or legal guardians in accordance with local laws and clinical standards.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated policy on this page with a revised "Last updated" date
  • Notify registered users via in-app notification or email at least 14 days before the changes take effect
  • For significant changes involving special category health data, we will seek renewed confirmation from healthcare provider administrators

Your continued use of TrovinaCare after changes become effective constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection team:

Privacy Email
privacy@trovinacare.com
Data Protection Officer
TrovinaCare DPO Team
Registered Address
TrovinaCare Ltd., Africa
Response Time
Within 30 business days

Other Legal & Compliance Resources