+LifeLink AI
Features Services How it works For Providers
Portal Login

Privacy Policy

Effective: 1 January 2026 · Last updated: 1 January 2026

1. Introduction

LifeLink AI ("we", "us", or "our") is a healthcare connectivity platform operated in Zimbabwe and available across Africa. This Privacy Policy explains how we collect, use, store, protect and share personal information when you use the LifeLink AI mobile application, web portal and related services (collectively, the "Platform").

By creating an account, using the Platform, or otherwise providing us with your information, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Platform.

We comply with the Zimbabwe Data Protection Act (2021), the POPIA (South Africa) where applicable, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), and all other relevant data protection laws in the jurisdictions where we operate.

2. Information We Collect

2.1 Information you provide directly

  • Account details: full name, email address, phone number, date of birth, gender, password (stored as a salted hash, never in plain text).
  • Profile information: profile photograph, bio, city, languages spoken, organisational affiliation.
  • Health and medical data: medical history, prescriptions, laboratory results, consultation notes, and any health records you choose to store or share through the Platform.
  • Provider credentials: professional licence number, issuing council/regulator, licence expiry, qualifications, years of experience, specialisations, and verified status.
  • Animal and agricultural data: species treated, veterinary specialisations, agricultural consultation types, and related professional information for providers in the Animal Health and Agricultural Advisory categories.
  • Payment information: consultation fees, payment method, and transaction records. We do not store full credit or debit card numbers on our servers.
  • Communications: messages exchanged through the in-app chat, appointment notes, and any content you share with providers or support.
  • Emergency data: GPS location shared during Emergency SOS activations, and any emergency contact details you have provided.
  • Counselling records: substance-use assessments, care plans and session notes. These are subject to enhanced confidentiality protections (see Section 7).

2.2 Information collected automatically

  • Device information: device model, operating system version, unique device identifiers, and app version.
  • Usage data: pages viewed, features used, search queries, appointment history, session duration, and interaction patterns within the Platform.
  • Location data: approximate location (city-level) for provider search; precise GPS location only when you activate Emergency SOS or explicitly consent to location sharing.
  • Network information: IP address, mobile carrier, and connection type.
  • Push notification tokens: used solely to deliver appointment reminders and emergency alerts.

2.3 Information from third parties

  • Provider verification: licence verification results from medical councils, nursing boards and pharmaceutical authorities.
  • Organisation data: hospital, clinic and pharmacy details provided during provider onboarding.
  • Patient reviews: ratings and written reviews submitted through the Platform.

3. How We Use Your Information

We use your personal information for the following purposes:

  • Providing the service: matching patients with providers, facilitating bookings, enabling teleconsultations, and supporting emergency response.
  • Provider verification: verifying professional credentials, confirming licence status, and displaying verified badges.
  • Personalisation: tailoring search results, recommendations, and content to your preferences and location.
  • Communication: sending appointment confirmations, reminders, emergency alerts, and important service updates.
  • Platform improvement: analysing anonymised usage patterns to improve features, reliability and user experience.
  • Safety and security: detecting fraud, preventing unauthorised access, and protecting the safety of patients and providers.
  • Legal compliance: meeting regulatory requirements, responding to lawful requests from authorities, and maintaining audit logs.
  • Research: generating anonymised, aggregated insights for healthcare research. Individual identities are never disclosed in research outputs.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Consent: when you create an account, share health data, or opt into optional features (e.g., marketing, analytics).
  • Contractual necessity: to provide the services you have requested (e.g., booking an appointment, processing a payment).
  • Legal obligation: to comply with healthcare regulations, court orders, and data retention requirements.
  • Legitimate interest: to improve the Platform, ensure security, and prevent fraud — balanced against your rights and reasonable expectations.
  • Vital interest: to share your location during an Emergency SOS activation when there is a risk to your life or the life of another person.

5. How We Share Your Information

We do not sell your personal information. We share data only in the following circumstances:

  • With your provider: when you book an appointment or initiate a consultation, your name, relevant medical history, and any records you choose to share are made available to that provider for the purpose of care delivery.
  • With your consent: when you explicitly authorise sharing with a specific third party (e.g., a specialist referral, a laboratory, or an insurance provider).
  • Emergency services: when you activate Emergency SOS, your location and relevant health information may be shared with nearest responders and emergency contacts.
  • Service providers: with trusted third-party processors who support Platform operations (e.g., cloud hosting, email delivery, analytics) under strict data processing agreements.
  • Legal requirements: when required by law, regulation, court order, or to protect the rights, property or safety of LifeLink AI, our users, or the public.

6. Data Storage and Security

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Passwords are stored as bcrypt salted hashes — plain-text passwords are never stored or logged.
  • Database access is restricted by role-based access control (RBAC) and audit-logged.
  • Regular security reviews, vulnerability assessments and penetration testing are conducted.
  • Data is hosted on secure, SOC 2-compliant infrastructure with geo-redundant backups.
  • We maintain an incident response plan and will notify affected users within 72 hours of a confirmed data breach, as required by law.

7. Special Categories — Counselling Records

Substance-use counselling records, care plans and session notes are subject to enhanced confidentiality protections:

  • Counselling data is stored in a separate, access-controlled data partition.
  • Access is restricted to the assigned counsellor and the patient. Platform administrators cannot view counselling session content.
  • Counselling records are never shared with employers, insurers, law enforcement, or any third party without the patient's explicit written consent, except where required by court order.
  • Patients may request deletion of counselling records at any time, subject to anonymised retention for mandatory reporting obligations.

8. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Restriction — limit how we process your data in certain circumstances.
  • Data portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest or direct marketing.
  • Withdraw consent — withdraw previously given consent at any time, without affecting the lawfulness of processing prior to withdrawal.

You can do this yourself, without contacting us. Use the Delete Account & Data page to close your account and erase your data, or to delete selected data while keeping your account. It works even if you have lost your password.

To exercise any of these rights, contact us at privacy@lifelink.ai. We will respond within 30 days.

9. Data Retention

  • Account data: retained for the lifetime of your account plus 12 months after deletion.
  • Medical records: retained for 7 years from the last consultation, in accordance with healthcare regulations.
  • Payment records: retained for 5 years for financial audit purposes.
  • Counselling records: retained for 5 years from the last session, or until the patient requests deletion, whichever is sooner.
  • Emergency logs: retained for 2 years for safety review and incident investigation.
  • Usage analytics: anonymised after 12 months and retained indefinitely in aggregate form.

10. Children's Privacy

The Platform is not intended for users under the age of 16. We do not knowingly collect personal information from children. If a parent or guardian becomes aware that their child has provided us with personal data, they should contact us immediately at privacy@lifelink.ai and we will delete the data.

For paediatric healthcare services, the parent or legal guardian must create and manage the child's account.

11. International Data Transfers

When data is transferred across borders (e.g., for medical tourism coordination), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and compliance with the destination country's data protection laws. We will not transfer your data to a jurisdiction with inadequate protection without your explicit consent.

12. Cookies and Tracking

The LifeLink AI mobile application does not use cookies. The web portal uses strictly necessary cookies for authentication sessions and theme preferences only. We do not use third-party advertising trackers or sell browsing data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification and/or email at least 30 days before they take effect. The "Last updated" date at the top of this page will always reflect the current version.

14. Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy or our data practices, please contact:

Data Protection Officer
LifeLink AI (Pvt) Ltd
Harare, Zimbabwe
Email: privacy@lifelink.ai
Phone: +263 77 000 0000

+LifeLink AI

Connecting patients to the right healthcare professional at the right time. Secure, verified and built for everyone.

Product

Features Services How it works

Company

About Careers Contact

Legal

Privacy Policy Terms of Service Cookie Policy Delete Account
© 2026 LifeLink AI. All rights reserved. Patients · Providers · Emergency · Tourism · Counselling