Privacy
Unganisha exists because the alternative — posting a patient's name, condition and a family phone number to a public group — cannot be undone. So the most useful thing this page can tell you is what we never collect at all.
Draft, not yet final. Unganisha is not launched. The sections below describe exactly what the software does today, which is verifiable. Items marked [like this] depend on registrations still in progress and will be completed before anyone is asked to rely on this.
What we never collect
- No test results, ever — Not HIV status, not any other screening result. There is no column for them anywhere in our database, so there is nothing to disclose, leak or be compelled to produce.
- No diagnosis, and no patient age — Neither helps find a donor. We do not ask.
- No exact location — A donor's location is rounded to roughly a 500-metre grid before it is stored, by the database itself rather than by the app. The smallest search radius is 5km, so this costs nothing and means we never hold a map of where donors sleep.
What we collect, and why
If you register as a donor: your phone number (encrypted), your blood group if you know it, an approximate area, and your donation eligibility date. That is the minimum needed to work out whether a nearby request is one you could actually answer.
If you post a request: the hospital, blood group, units and deadline, plus your name and phone number so the hospital can identify who arranged it. Your name and number are encrypted and are never shown publicly.
We also keep a record of alerts sent, so that we do not message you more often than you agreed to, and an audit log of who accessed what.
Who can see what
A shared request link shows a fixed, deliberately short list: blood group, component, units needed and still needed, urgency, status, the facility and its town, county and location, any ward note, the deadline, and how many donors have been alerted. Nothing else is reachable from that page — the public view is a single database function that enumerates those fields, so adding one is a deliberate, reviewable change.
A patient's first name appears only if the person posting explicitly chose to show it. Most leave it off.
Contact details move in stages, and never automatically:
- The alert carries no personal data — A donor is told a blood group, a hospital and a distance. Not who the patient is, and not who posted it.
- Committing to donate still reveals nothing — The donor sees the facility, the ward and a reference code to quote on arrival. In most cases that is the whole exchange and no numbers are shared at all.
- A number is shared only if both sides agree — Only when a donor asks and the requester consented at posting time. It is logged, and the access expires.
A donor's phone number is never revealed to anyone. Not to hospitals, not to families, not to other donors.
How long we keep it
Patient and requester identity — the name, phone number and any clinical note attached to a request — is hard-deleted 90 days after the request is posted. Not anonymised, deleted. The request itself remains as an operational record with nothing personal left in it.
Your donor account lasts until you delete it. You can pause alerts instead, or leave entirely, at any time.
Where it is stored
On servers in Nairobi. Your data does not leave Kenya in the ordinary course of running the service. Phone numbers and names are encrypted with keys held separately from the database.
Your rights
Under the Data Protection Act 2019 you can ask us to show you what we hold, correct it, delete it, or stop using it. You can also object to processing and withdraw consent.
Withdrawing consent never overwrites the original record — we add a new one — so we can always show you exactly what you agreed to, in the wording you were shown, and when.
We will also show you who has seen your data. That is not required by the Act. We do it because fear of disclosure is the single biggest reason Kenyans give for not donating, and an answer you can check beats a promise.
We respond to requests within [statutory period — to be confirmed against the 2021 Regulations].
Blood group is sensitive data
Your blood group is health data, which the Act treats as sensitive personal data requiring explicit consent. We ask for it separately and specifically. It is never bundled into accepting terms, and you can use Unganisha without telling us — about four in ten Kenyans do not know theirs.
Who is responsible, and how to complain
The data controller is [registered entity name — company registration in progress], registered with the Office of the Data Protection Commissioner under [ODPC registration number — application pending].
Data protection contact: [contact address — pending the final domain].
If we get it wrong you can complain to the Office of the Data Protection Commissioner directly. You do not need our permission, and you do not have to come to us first.
Last updated 27 July 2026. See also our about page, which explains in plain language what Unganisha does and does not do.