Effective 2026 · Issued under the Data Protection Act, 2019 (Kenya)
1. Who we are
F360 Admin Central ("we", "us") operates the Facility360
platform that lets healthcare facilities in Kenya invite staff to
receive schedules, announcements and task notifications. We are the
data controller for the personal data described in
this notice, as defined by the Data Protection Act, 2019 (the "Act").
2. What data we collect
When a facility invites you and you accept, we process:
- Your name and email address (provided by your facility);
- Your job title, department and facility affiliation;
- Account credentials you set during sign-up;
-
Technical data needed to secure the account — IP address, device
type and timestamps of invite and login activity.
If you use our mobile application, and only with the device permissions
you grant, we may also process:
-
Location — your approximate or precise device
location, captured only while the app is open and
only at the moment you perform a location-based action
(such as QR-code sign-in or attendance check-in) to confirm you are at
the facility. We do not track your location in the
background.
-
Camera — accessed only when you scan a
QR code within the app. We process the scanned code; we do not
take or store photographs of you.
-
Biometric unlock — if you enable fingerprint or face
unlock, your device performs the check locally. Your biometric data
never leaves your device and is never transmitted to
or stored by us; we only receive a confirmation that the unlock
succeeded.
-
Push notifications — a device notification token, used
to send you schedules, announcements and task alerts. You can disable
notifications in your device settings at any time.
3. Why we process it (lawful basis)
We rely on the following bases under section 30 of the Act:
-
Performance of your employment relationship — to
deliver schedules, announcements and tasks from your facility;
-
Consent — which you give by accepting the invite
and creating an account, and which you may withdraw at any time;
-
Legitimate interest and legal obligation — to keep
an audit trail of invite acceptance and to secure accounts against
misuse.
-
Presence and attendance — location checked at
sign-in or check-in, and QR-code scanning, are carried out on the
basis of your engagement with the facility and our legitimate interest
in accurate attendance records — not solely your consent.
-
Optional convenience features — biometric unlock and
push notifications are used only with your consent, which you may
withdraw at any time in your device settings. Every device feature
requires the relevant device permission, which you may decline or
revoke at any time; declining location or camera only prevents the
specific action that needs it, such as QR sign-in.
4. How we protect it and how long we keep it
Personal data is transmitted over HTTPS and stored with access
restricted to your facility's authorised administrators on a
need-to-know basis. Invite codes expire, are rate-limited, and every
acceptance is logged. We retain your account data only for as long as
your affiliation with the facility is active, plus any period required
by law.
For mobile-app features specifically: we do not retain
raw location coordinates after your presence at a facility has been
confirmed — the coordinate is used to verify presence at the moment of
sign-in or check-in and then discarded. The resulting sign-in or
attendance record (the time and the confirmed facility) is retained for
the duration of your affiliation plus any statutory record-keeping
period. Scanned QR codes are processed to complete sign-in and are not
stored as images.
5. Who we share it with
We do not sell your data. We share it only with the facility that
invited you and with infrastructure providers acting as our data
processors under written contract. We do not disclose your affiliation
with one facility to any other facility.
6. Your rights under the Act
You have the right to:
- Be informed of how your data is used;
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your data ("right to erasure");
- Object to or restrict processing;
- Withdraw consent at any time.
To exercise any of these rights, contact our Data Protection Officer
at
[email protected]. You
also have the right to lodge a complaint with the
Office of the Data Protection Commissioner (ODPC) of
Kenya at
www.odpc.go.ke.
7. Deleting your account and data
You may request deletion of your F360 Admin Central
account and the personal data associated with it at any time. To
request account and data deletion, email our support team at
[email protected] from the
address linked to your account, or include your account email in your
message.
We will verify the request and delete your account and associated
personal data, except any records we are required to retain to comply
with a legal obligation. We aim to complete verified deletion requests
within 30 days and will confirm once the deletion is done.
8. Children
This application is intended for adult healthcare professionals engaged
by a facility. It is not directed at, or intended for use by, children.
9. Changes to this policy
We may update this policy to reflect changes in law or our practices.
The effective year above indicates the current version.