Your Data Rights
Submit access, correction, erasure or objection requests under the Kenya Data Protection Act, 2019.
Under the Kenya Data Protection Act, 2019, you may exercise the following rights over personal data processed by LOGICODE Systems Limited on this website and Medico Connect:
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion where applicable
- Restriction — limit processing in certain cases
- Objection — object to processing based on legitimate interests
- Withdraw consent — for consent-based processing (including cookies)
Hospital or employer records
If your request concerns patient records or payroll data held by a hospital or employer using LOGICODE software, that organisation is usually the data controller. Contact them first; we will assist our customers as processor where contractually required.
Response timeline
We acknowledge requests promptly and respond within 30 days, extendable only as permitted by law.
Alternative channel
Email the DPO directly: privacy@logicodesystems.co.ke with subject line Data Subject Request.
Secure data rights request form
Submissions are transmitted over HTTPS, logged with a reference number, and routed to our Data Protection Officer. Do not include passwords or full medical records in this form.
Report a personal data breach
If you believe personal data processed by LOGICODE has been lost, accessed or disclosed without authority, notify us immediately at privacy@logicodesystems.co.ke with subject line Data Breach Report.
Our internal workflow:
- Contain the incident and preserve evidence (logs, affected systems, timeline).
- Notify the Data Protection Officer immediately at the breach contact email.
- Assess whether personal data was accessed, lost, or disclosed without authority.
- Where required, notify the Office of the Data Protection Commissioner (Kenya) within 72 hours of becoming aware of the breach.
- Notify affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
- Document remediation, root cause and preventive measures in an internal breach register.
Where the Kenya Data Protection Act requires it, we notify the ODPC within 72 hours of becoming aware of a notifiable breach, and affected individuals without undue delay when high risk is likely.