Header Logo
PDPA 2022 Compliant

Privacy Policy

Your privacy and the security of your health data are our absolute priorities. Read how we protect your personal and clinical records under the Tanzania Personal Data Protection Act, 2022.

Official Compliance Policy v1.3.6 / Updated: August 22, 2026

1. Legal Basis & PDPA Compliance

At Tabibu Health Services, our platform is fully compliant with the Tanzania Personal Data Protection Act (PDPA), 2022 (Act No. 11 of 2022). Under the supervision of the Tanzania Personal Data Protection Commission (PDPC), we process, store, and safeguard your clinical information in accordance with national regulations.

2. Information We Process

We collect and process only the minimum personal data required to manage your healthcare appointments and provide clinic discovery services:

Personal Identity & Demographics

Full name, normalized telephone number, email address, secure cryptographically hashed credentials, and optional insurance registration provider details.

Appointment & Scheduling Data

Healthcare centers, clinics, or pharmacies searched, appointment history, preferred clinicians, dates/times, and optional clinic booking triage notes.

3. TLS/SSL & Infrastructure Security

We utilize industry-leading security controls and defense-in-depth infrastructure standards to ensure your sensitive records are never intercepted or compromised:

Encryption in Transit (TLS/SSL)

All traffic between your browser and our platform is encrypted using modern TLS 1.3 and TLS 1.2 protocols. We strictly enforce HTTP Secure (HTTPS) and utilize **HSTS (HTTP Strict Transport Security)** to eliminate protocol downgrade exploits.

Encryption at Rest

Patient credentials, personal identity variables, and clinical appointment histories are stored securely in distributed clusters protected by robust **AES-256 bit encryption** at rest.

Isolated Network VPC

Database storage and application core microservices are hosted inside isolated Virtual Private Clouds (VPC) protected by firewalls and access lists. Databases have absolutely no direct exposure to the public internet.

Session & CSRF Guard

User logins are authenticated using secure, cryptographically signed JSON Web Tokens (JWT). All stateful portals enforce strict anti-CSRF (Cross-Site Request Forgery) protection and rate limiting to prevent unauthorized access.

4. Data Sharing & Containment

We enforce strict data isolation parameters governing who can interact with your patient information:

  • No Advertising and Third-Party Trackers: We do not sell, rent, or lease clinical patient records, contact variables, or appointment files to advertising networks or external brokers. We have zero third-party trackers enabled.
  • Clinic Isolation: Your personal identity details are only visible to verified medical practitioners at the specific healthcare centers or clinics where you choose to book appointments. No other clinic in the directory has visibility into your file.
  • Auditable Staff Accountability: Any profile query or administrative file access by clinical staff is logged to an immutable security audit trail to prevent unauthorized access.

5. Your Patient Rights under Tanzania PDPA, 2022

01

Right to Information & Portability (Articles 31-33)

You have the right to request a complete, readable export of all patient profile and booking records registered on the platform.

02

Right to Rectification (Article 36)

You can modify or update any inaccurate or incomplete details in your portal profile at any time.

03

Right to Erasure (Article 37)

You may request the deletion of your account and credentials, subject to statutory medical record archiving laws.

04

Right to Lodge a Complaint

You have the explicit right to report any suspected privacy violation directly to the Personal Data Protection Commission (PDPC) of Tanzania.

6. Frequently Asked Questions

Have questions about your data?

Our Data Protection Officer is here to help you understand your rights.

Contact Privacy Team