Privacy Policy
Prescenca — Therapist Portal
Effective Date: 26 September 2026
Prescenca is a therapy practice management platform designed to help therapists, psychologists, counsellors, and other mental health practitioners manage their practices.
We understand that the information handled through a therapy practice can be highly personal and sensitive. This Privacy Policy explains how Prescenca collects, uses, stores, protects, and otherwise processes personal data when you use our website, platform, applications, and related services.
Prescenca is designed to operate in accordance with applicable data protection laws, including the Data Protection Act, 2019 of Kenya and applicable regulations and guidance issued by the Office of the Data Protection Commissioner (ODPC). Kenya's data protection framework requires personal data to be processed lawfully, fairly and transparently, for specified purposes, and only for as long as necessary for those purposes.
1. WHO WE ARE
Prescenca provides software and technology infrastructure for mental health practitioners and practices.
For purposes of data protection law, Prescenca may act in different capacities depending on the information and the purpose for which it is processed.
When Prescenca processes client information on behalf of a practitioner
Where a therapist, psychologist, counsellor, or practice uses Prescenca to store or manage information about their clients, the practitioner or practice will generally determine why and how that client information is processed.
In these circumstances:
- the practitioner or practice is generally the Data Controller;
- Prescenca generally acts as the Data Processor;
- Prescenca processes the information on the practitioner's instructions and in accordance with the applicable Data Processing Agreement; and
- the practitioner remains responsible for their professional relationship with the client, including determining the appropriate purposes and lawful basis for processing client information.
The ODPC describes a data processor as an entity that processes personal data on behalf of a data controller.
When Prescenca processes information for its own purposes
Prescenca may act as a Data Controller where we determine the purposes and means of processing information for our own business activities.
This may include information relating to:
- practitioner accounts;
- subscriptions and billing;
- customer support;
- website visitors;
- marketing communications;
- security and fraud prevention;
- service improvement;
- legal and regulatory compliance; and
- administration of the Prescenca business.
2. INFORMATION WE COLLECT
The information we collect depends on how you interact with Prescenca.
2.1 Practitioner and account information
When a practitioner or practice creates an account, we may collect:
- full name;
- professional information;
- practice name;
- professional registration or licence information where provided;
- email address;
- telephone number;
- practice contact details;
- login credentials;
- account preferences;
- subscription information; and
- other information necessary to establish and manage the account.
2.2 Client information
Where a practitioner uses Prescenca to manage client records, the platform may process information entered by the practitioner or client, including:
- name;
- contact information;
- date of birth or age;
- emergency contact information;
- appointment information;
- intake forms;
- consent forms;
- questionnaires;
- assessments;
- clinical notes;
- treatment plans;
- progress information;
- information concerning mental or physical health;
- information relating to a client's circumstances or wellbeing;
- communications between the practitioner and client where the relevant functionality is used;
- invoices, receipts and payment information; and
- other information that the practitioner determines is necessary for providing professional services.
Some of this information may constitute sensitive personal data or health data under Kenyan law and therefore requires additional protection. The ODPC's health data guidance specifically addresses digital health platforms and electronic health records.
2.3 Payment information
Where payments are made through Prescenca, we may process information such as:
- payer name;
- amount paid;
- transaction reference;
- invoice information;
- payment status;
- payment date; and
- information provided by the relevant payment service provider.
Where M-PESA or another payment service is used, the applicable payment provider may separately process transaction information under its own privacy terms.
Prescenca does not request or store your M-PESA PIN.
2.4 Technical and usage information
When you use Prescenca, we may automatically collect certain technical information, such as:
- IP address;
- browser type;
- device type;
- operating system;
- login information;
- authentication information;
- application activity;
- timestamps;
- security logs;
- error reports; and
- information about how the platform is accessed and used.
We use this information primarily to operate, secure, troubleshoot, and improve the service.
2.5 Website information
If you visit the Prescenca website, we may collect information you voluntarily provide through forms, enquiries, newsletter subscriptions, demo requests, or other interactions.
Our use of cookies and similar technologies is explained in our Cookie Policy.
3. HOW WE USE PERSONAL DATA
We process personal data only for appropriate and lawful purposes.
Depending on the circumstances, we may process personal data to:
- provide and operate Prescenca;
- create and manage practitioner accounts;
- provide client-facing functionality;
- store and organise client records on behalf of practitioners;
- facilitate scheduling and appointments;
- facilitate forms and consent processes;
- generate invoices, receipts and payment records;
- provide customer support;
- authenticate users and protect accounts;
- maintain the security of the platform;
- detect and prevent fraud, abuse, and unauthorised access;
- troubleshoot technical problems;
- maintain backups and recover information where necessary;
- communicate with practitioners and customers about the service;
- process subscriptions and payments;
- improve and develop Prescenca;
- comply with legal and regulatory obligations;
- respond to lawful requests from competent authorities; and
- establish, exercise, or defend legal claims.
Where Prescenca processes client information on behalf of a practitioner, we process that information primarily to provide the services requested by the practitioner and in accordance with the practitioner's instructions and our Data Processing Agreement.
4. LAWFUL BASES FOR PROCESSING
The lawful basis for processing depends on the particular information and processing activity.
Depending on the circumstances, Prescenca may rely on:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- legitimate interests, where permitted by law;
- protection of vital interests;
- public interest where applicable; or
- another lawful basis recognised under applicable data protection law.
We do not treat consent as the lawful basis for every processing activity.
Where consent is required, we will request it in an appropriate manner and provide information about what the consent relates to.
Where a practitioner is the Data Controller for client information, the practitioner is responsible for determining the appropriate lawful basis for their processing activities and obtaining any required consents or other authorisations from their clients.
5. HEALTH AND SENSITIVE PERSONAL DATA
Therapy and mental health services may involve information that is particularly sensitive.
This may include information concerning:
- mental health;
- physical health;
- medical history;
- family circumstances;
- sexual or reproductive health;
- biometric information where applicable;
- financial circumstances;
- or other information classified as sensitive personal data under applicable law.
Prescenca does not use client clinical information for targeted advertising.
We design the platform to limit access to sensitive information to authorised users and to support practitioners in handling client information securely.
The ODPC's health data guidance emphasises confidentiality, appropriate security measures, transparency, and careful management of health information, including when digital platforms are used.
6. CLIENT RECORDS AND CLINICAL INFORMATION
Prescenca provides the infrastructure through which practitioners may create, store, and manage client records.
The practitioner remains responsible for:
- determining what client information is collected;
- determining why that information is collected;
- ensuring that the collection and use of client information has an appropriate lawful basis;
- providing clients with appropriate privacy information;
- obtaining consent where consent is required;
- maintaining appropriate professional and clinical records;
- determining appropriate retention periods for clinical records, subject to applicable law and professional requirements; and
- responding to client requests relating to information for which the practitioner is the Data Controller.
Prescenca does not independently determine the clinical purposes for which a practitioner collects or uses client information.
7. THE PRESCENCA CLIENT APP
Prescenca may provide clients with access to a client-facing application or portal.
Through the client application, clients may be able to:
- create or access their account;
- complete intake forms;
- review documents;
- review or provide consent where applicable;
- manage appointments;
- view invoices or payment information;
- communicate with their practitioner where the relevant functionality is available; and
- access information made available to them by their practitioner.
Clients will be provided with relevant privacy information during onboarding.
A client is not required to accept the practitioner Data Processing Agreement. That agreement governs the relationship between Prescenca and the practitioner or practice.
Where the practitioner provides their own consent forms, privacy notices, treatment documents, or other client-facing documents, those documents remain the responsibility of the practitioner.
8. WHO CAN ACCESS PERSONAL DATA?
Access to personal data is limited to people and organisations that need access for legitimate purposes.
Depending on the circumstances, information may be accessed by:
- the practitioner who provides your services;
- authorised members of the practitioner's practice;
- authorised Prescenca personnel who require access to provide support, maintain, secure, or operate the platform;
- technical service providers acting on behalf of Prescenca;
- payment providers where relevant;
- professional advisers where necessary;
- regulators, courts, law enforcement agencies, or other authorities where legally required; or
- other parties where you have authorised the disclosure or where disclosure is otherwise permitted by law.
We do not sell client clinical information.
We do not provide identifiable client clinical information to advertisers for targeted advertising.
9. THIRD-PARTY SERVICE PROVIDERS AND SUBPROCESSORS
Prescenca may use carefully selected third-party service providers to operate parts of the platform.
These may provide services such as:
- cloud hosting;
- database infrastructure;
- authentication;
- email and communications;
- payments;
- analytics;
- customer support;
- security;
- monitoring;
- backups; or
- other technical infrastructure.
Where a third party processes personal data on behalf of Prescenca, we seek to ensure that appropriate contractual and data protection requirements apply.
Where Prescenca engages a subprocessor to process client information, the relevant processing is governed by applicable contractual and data protection requirements.
We will maintain appropriate records of relevant subprocessors and update them as our technology stack changes.
10. INTERNATIONAL DATA TRANSFERS
Some Prescenca service providers may operate outside Kenya.
Where personal data is transferred outside Kenya, Prescenca will take appropriate steps to ensure that the transfer is conducted in accordance with applicable Kenyan data protection requirements, including applicable requirements relating to safeguards, contractual protections, adequacy, or consent.
Where a practitioner is the Data Controller, the practitioner remains responsible for considering any international transfers associated with their own processing activities where applicable.
We will provide additional information about material international processing arrangements where appropriate.
11. DATA SECURITY
Prescenca takes the security of personal data seriously.
We implement appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unauthorised disclosure;
- accidental loss;
- destruction;
- alteration;
- misuse; and
- other unlawful or unauthorised processing.
Depending on the relevant system and information, these measures may include:
- access controls;
- authentication mechanisms;
- role-based permissions;
- encryption where appropriate;
- secure software development practices;
- security monitoring;
- logging;
- backup procedures;
- vulnerability management;
- incident response procedures; and
- staff confidentiality obligations.
No online service can guarantee absolute security. Users are also responsible for protecting their account credentials and using Prescenca through secure devices and connections.
12. DATA RETENTION
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law.
The appropriate retention period depends on factors including:
- the type of information;
- the purpose for which it is processed;
- whether the information is part of a clinical record;
- legal and regulatory requirements;
- professional record-keeping obligations;
- contractual requirements;
- dispute resolution or legal claims;
- security and audit requirements; and
- whether the information is still required to provide the service.
Client clinical information
Where Prescenca stores client clinical information on behalf of a practitioner, the practitioner generally determines the appropriate retention period because the practitioner is responsible for the clinical record.
Closing a practitioner account does not necessarily mean that all information is immediately deleted. Depending on the circumstances, information may first be exported, returned to the practitioner, retained for a legally required period, or securely deleted in accordance with applicable requirements and the practitioner's instructions.
Deletion
When personal data is no longer required and there is no legal or legitimate reason to retain it, we will take appropriate steps to delete, anonymise, or otherwise securely dispose of it.
Backups may continue to contain information for a limited period while they are securely overwritten or otherwise removed through our backup lifecycle.
We maintain internal procedures governing retention and deletion and periodically review the information we hold.
13. DATA BREACHES AND SECURITY INCIDENTS
Prescenca maintains procedures for identifying, assessing, containing, investigating, and responding to suspected personal data breaches and other security incidents.
If we become aware of a breach involving personal data processed on behalf of a practitioner, we will notify the relevant practitioner in accordance with our Data Processing Agreement and applicable law.
Where Prescenca is acting as a Data Controller, we will assess the incident and make any notifications required by applicable law.
Where notification to the ODPC or affected individuals is legally required, we will take reasonable steps to make the notification within the applicable statutory timeframe.
Under Kenya's Data Protection Act, specific notification obligations apply to controllers and processors in the event of qualifying personal data breaches.
We may also take steps to:
- contain the incident;
- secure affected systems;
- investigate what happened;
- assess the information involved;
- mitigate potential harm;
- preserve relevant evidence;
- cooperate with affected practitioners and relevant authorities; and
- implement measures designed to prevent recurrence.
14. DATA SUBJECT RIGHTS
Depending on the applicable law and circumstances, individuals may have rights relating to their personal data, including the right to:
- be informed about the use of their personal data;
- access their personal data;
- request correction of inaccurate or misleading information;
- request deletion or erasure where applicable;
- object to certain processing;
- request restriction of processing where applicable;
- request portability of personal data where applicable; and
- withdraw consent where processing is based on consent.
The ODPC identifies rights including the right to be informed, access personal data, object to processing, correct false or misleading data, and request deletion of false or misleading data.
If your information is held by your therapist
Where the practitioner is the Data Controller, requests relating to your clinical records should generally be directed to your therapist or practice first.
Prescenca may assist the practitioner in responding to the request where the information is stored within Prescenca.
If your information is controlled by Prescenca
For information that Prescenca controls directly, you may contact us using the details provided below.
We may need to verify your identity before responding to a request.
15. CHILDREN AND VULNERABLE CLIENTS
Mental health services may involve children and other vulnerable individuals.
Where client information concerns a child or another person who cannot exercise their rights independently, the relevant practitioner is responsible for ensuring that information is collected and processed in accordance with applicable law and professional requirements, including any requirements concerning parental authority, guardianship, consent, or authorisation.
Prescenca provides technology infrastructure and does not replace the practitioner's professional or legal responsibilities.
16. COOKIES AND SIMILAR TECHNOLOGIES
Prescenca may use cookies, local storage, device identifiers, authentication technologies, and similar technologies to:
- keep users signed in;
- maintain security;
- remember preferences;
- operate the website and application;
- understand service usage;
- diagnose technical problems; and
- improve the service.
Our use of these technologies is explained in our Cookie Policy.
Where consent is legally required for a particular technology, we will provide an appropriate consent mechanism.
17. MARKETING COMMUNICATIONS
Where we send marketing or promotional communications, we will do so in accordance with applicable law.
You may unsubscribe from marketing communications using the unsubscribe mechanism provided or by contacting us.
Transactional, service-related, security, and account communications may still be sent where necessary to provide the service or manage your account.
Prescenca does not use identifiable client clinical information to create targeted advertising audiences.
18. AGGREGATED AND DE-IDENTIFIED INFORMATION
Prescenca may use information that has been appropriately aggregated, anonymised, or de-identified for legitimate purposes such as:
- understanding platform usage;
- improving functionality;
- monitoring service performance;
- developing new features;
- security and fraud analysis;
- research and statistical analysis; and
- understanding general trends.
We will not use de-identified information in a way that is intended to identify individual clients.
Where information cannot reasonably be considered anonymous or de-identified, we will continue to treat it as personal data and apply the relevant protections.
19. DISCLOSURE REQUIRED BY LAW
Prescenca may disclose personal data where reasonably necessary to:
- comply with a legal obligation;
- respond to a lawful request from a court, regulator, or government authority;
- protect the rights, property, or safety of Prescenca, our users, or others;
- investigate fraud, security incidents, or misuse of the platform;
- establish, exercise, or defend legal claims; or
- comply with applicable regulatory requirements.
We will seek to limit such disclosures to information that is reasonably necessary for the relevant purpose.
20. YOUR RESPONSIBILITIES
Users of Prescenca also have responsibilities in protecting personal information.
Practitioners should:
- keep account credentials secure;
- provide access only to authorised team members;
- use appropriate role permissions;
- avoid sharing client information through insecure channels where avoidable;
- comply with applicable professional and data protection requirements;
- provide clients with appropriate privacy information;
- obtain consent where required; and
- notify Prescenca of suspected unauthorised access or security incidents.
Clients should:
- keep their login information confidential;
- use a secure device;
- avoid sharing their account with another person;
- provide accurate information;
- notify their practitioner or Prescenca if they believe their account has been compromised; and
- log out of shared or public devices.
21. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
- changes to Prescenca;
- changes to our services;
- changes in technology;
- changes in applicable law;
- regulatory guidance; or
- changes to our data processing practices.
When we make material changes, we will take reasonable steps to bring those changes to your attention.
The effective date at the beginning of this Privacy Policy indicates when it was most recently updated.
22. QUESTIONS, REQUESTS AND COMPLAINTS
If you have questions about this Privacy Policy, want to exercise a data protection right in relation to information controlled by Prescenca, or have concerns about how Prescenca handles personal data, please contact us using the contact details below.
PrescencaPrivacy / Data Protection Contact : compliance@prescenca.comWebsite: www.prescenca.comCountry: Kenya
If you believe your personal data has been processed in a manner that violates your rights and your concern cannot be resolved directly with the relevant data controller, you may also contact the Office of the Data Protection Commissioner (ODPC).
The ODPC is responsible for regulating the processing of personal data and protecting data subjects' rights in Kenya.
23. GOVERNING LAW
This Privacy Policy is governed by the laws of Kenya, including the Data Protection Act, 2019, applicable regulations, and other applicable Kenyan laws.
Where Prescenca processes information on behalf of a practitioner or practice, the relevant Data Processing Agreement will also apply to that processing.
End of Privacy Policy
