← Back to clinsco.co.zw

Privacy Policy

Last updated 9 October 2026

ClinSCo handles medical records. This policy says plainly what we collect, why, where it is kept, who can reach it and what you can ask us to do about it — in language a clinic manager can act on rather than a page of disclaimers.

  1. Two different roles we play
  2. What we collect
  3. Google and Microsoft accounts
  4. How we use it
  5. Where it is stored
  6. How it is protected
  7. Who else sees it
  8. How long we keep it
  9. Your rights
  10. If you are a patient
  11. Cookies and tracking
  12. Changes, and how to complain

1. Two different roles we play

The distinction below decides who is accountable for what, so it is worth reading before anything else.

In practice: if you are a patient and want your record changed or erased, your clinic is the right place to ask — they control it, and they can act immediately. We will always help a clinic do that, and section 10 explains what to do if you cannot reach them.

2. What we collect

Visitors to this website

Almost nothing. This site sets no cookies, runs no advertising or analytics trackers, and does not profile you. If you fill in the contact form or use the assistant to request a callback, we receive what you type: practice name and type, your name, email, telephone, country and your message. That is used to answer you and for nothing else.

Clinic staff who use the platform

Patient information, held for a clinic

Entered by the clinic, not by us. Depending on what that clinic uses, it may include name, date of birth, gender, medical-aid or member number, telephone, email, address, appointments, clinical notes, and billing and payment records.

3. Google and Microsoft accounts

A clinic may choose to connect their own Google or Microsoft account so that ClinSCo can work with a spreadsheet they nominate, or put appointments in a calendar. This is always optional, always per person, and can be disconnected at any time from Connected accounts inside the platform.

We deliberately ask for the narrowest permissions that do the job:

What we ask forWhat that allows
Google — drive.file Only the specific file you choose, or files ClinSCo itself creates. Not the rest of your Drive.
Google — calendar.app.created Only a calendar ClinSCo creates for your bookings. We cannot read your existing appointments.
Microsoft — Files.ReadWrite.AppFolder and Files.ReadWrite.Selected A folder ClinSCo owns, plus individual files you explicitly hand us. Not your whole OneDrive.
Microsoft — Calendars.ReadWrite Needed to create and update your bookings. Microsoft offers nothing narrower, so we limit ourselves to a calendar ClinSCo creates.
Both — basic profile and email To show you which account is connected.

We never request permission to read your whole Drive, your mail, or your contacts, and we never use these connections for advertising, profiling or any purpose other than the feature you switched on.

Google API Services User Data Policy. ClinSCo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Access tokens are encrypted before they are stored, using a key the database never holds. Disconnecting withdraws the permission at Google or Microsoft, not merely in our records, and we destroy our copy of the token at the same time.

4. How we use it

What we never do. We do not sell personal information. We do not use it for advertising. We do not send patient information to third-party artificial-intelligence or large-language-model services, and we do not use any clinic's records to train models.

5. Where it is stored

All platform data is held on Microsoft Azure in the South Africa North region. Backups are geographically replicated to South Africa West, so a copy survives the loss of a single data centre. Data is not transferred outside southern Africa for storage.

The exception is a connection you choose to make yourself: if a clinic links a Google or Microsoft account, the file or calendar concerned lives on that provider's infrastructure under that provider's own terms. That is why the permissions above are kept as narrow as they are.

Clinics can also take an encrypted copy of their own records onto a computer they control. That file is encrypted with a passphrase only they know — we cannot read it and cannot recover it — and once it leaves our systems it is the clinic's responsibility to look after.

6. How it is protected

7. Who else sees it

We use a small number of service providers, and only these:

WhoWhat forWhere
Microsoft AzureHosting, database and backupsSouth Africa
Azure Communication ServicesSending email, such as appointment remindersMicrosoft infrastructure
Google or MicrosoftOnly where a user has connected their own accountThat provider

We may also disclose information where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over a clinic's data, we will tell that clinic unless we are legally prohibited from doing so.

We do not sell, rent or trade personal information to anyone.

8. How long we keep it

WhatHow long
Patient and clinical recordsAs the clinic instructs, and at least as long as health-records law requires. Default seven years.
BackupsSeven years, then automatically deleted
Audit logKept permanently — it is the record of who did what, and may not be altered
Website enquiriesTwo years from last contact, unless you ask us sooner
Staff accountsFor the life of the account, then retained only as audit entries

When a clinic leaves us, their access ends but their records are not destroyed — retention law outlives the commercial relationship. A departing clinic can export everything before access ends, and we will delete their data on written instruction once their own retention obligations allow it.

9. Your rights

Under Zimbabwe's Cyber and Data Protection Act and, where it applies, South Africa's Protection of Personal Information Act, you may:

Write to admin@clinsco.co.zw. We answer within 30 days. We will ask you to confirm your identity first — a request to disclose someone's medical details is exactly the request an impostor would make.

10. If you are a patient

Your record belongs to your clinic, not to us. Ask them first: they can see it, correct it and explain it, and they can act today. If you have asked your clinic and have had no response, write to admin@clinsco.co.zw and we will raise it with them. We cannot change a clinical record ourselves without the clinic's instruction, because we are not the people who made it.

11. Cookies and tracking

This website sets no cookies and carries no trackers. No Google Analytics, no advertising pixels, no social-media buttons reporting your visit. The only thing stored in your browser is a short-lived flag so the assistant does not greet you twice in one visit, and it disappears when you close the tab.

The ClinSCo platform itself (at app.clinsco.co.zw) sets one essential cookie to keep you signed in. It carries no advertising purpose and cannot be used to follow you elsewhere.

12. Changes, and how to complain

If we change this policy we will update the date at the top, and we will tell clinics directly before any change that materially affects how their data is handled.

If you are unhappy with our answer, you may complain to Zimbabwe's data protection authority (POTRAZ), or to the Information Regulator in South Africa where that law applies to you. We would rather you came to us first, and we will take it seriously.

Contact

ClinSCo — Harare, Zimbabwe
Privacy and data protection: admin@clinsco.co.zw
General support: support@clinsco.co.zw