Last updated 23 July 2026
How data protection is built into Heyrafiki. The Privacy Policy sets out your rights and our grounds; this page sets out the controls behind them.
Identity data and clinical data are held in different stores, under different access rules. Reaching one does not reach the other, and no single role holds both by default. This is a property of how the Platform is built rather than a promise about how we behave.
Every account holds a role, and each role reaches only what that work requires. Your Practitioner reaches your Care; an Organization administrator reaches aggregate reporting and never a person; our own Team reaches operational systems, not clinical content.
Access to clinical information is written to an audit trail that cannot be quietly edited.
Information does not travel between Practitioners, Organizations or Insurers because it is convenient. It travels because you allowed it, for the purpose you allowed, and you can withdraw that.
Claims carry what a Claim needs. They do not carry your Session content.
Encryption in transit and at rest. Secrets held outside the codebase. Least-privilege service credentials. Clinical records and financial ledgers kept in systems built for records of authority, with reconciliation rather than trust.
We build to the security guidance published for health data interoperability and to recognized application security standards, and we design to stay in scope for independent testing against them.
Insurers, Employers, Universities and NGOs receive a data processing agreement that names what we hold, what they receive, and what neither of us may do with it. Aggregate reporting is the only reporting they receive.
Send security reports to security@heyrafiki.space, and privacy questions to hello@heyrafiki.space. Do not include passwords, private keys or clinical records in the first message. We acknowledge reports and work with the reporter on a fix and a disclosure timeline.
Questions? Write to hello@heyrafiki.space or hello@heyrafiki.space.