Privacy

Privacy should be clear before data enters the system.

This website privacy notice explains the public marketing site at umojaehr.com. It does not replace the privacy terms, data-processing agreements or institutional policies required for a production clinical deployment.

Website scope

This notice applies to the public Umoja Afya EHR marketing website and inquiries submitted through it. The live EHR demonstration is a separate application environment and must not be used to enter real patient information.

Information we may receive

When you contact us, we may receive your name, email address, organization, country, inquiry type and the message you choose to provide. Standard web hosting may also process technical information such as IP address, browser type, timestamps and security logs.

Do not submit patient data

Do not send protected health information, patient-identifiable data, credentials, passwords, API keys, clinical documents or other sensitive information through public website forms or ordinary email.

How information is used

Information may be used to respond to inquiries, evaluate potential implementations or partnerships, improve the website, protect the service from abuse and satisfy legal obligations.

Data retention

Contact information should be retained only as long as reasonably necessary for the inquiry, business relationship, security purpose or applicable legal requirement. Production deployments require their own customer-specific retention policy.

Third parties and hosting

The public site may rely on hosting, DNS, email, analytics or security providers selected by the site operator. A production EHR deployment may use an entirely different infrastructure selected by the customer.

Your choices

You may request correction or deletion of contact information where applicable, subject to legal, contractual and security obligations.

Clinical deployments

Healthcare organizations deploying Umoja are responsible for establishing the applicable privacy program, agreements, notices, access controls, retention policies, incident response and regulatory compliance for their environment.