Public policy
Privacy Policy
Effective and last updated: 21 July 2026
This Privacy Policy explains how the CareSignal project team ("CareSignal", "we", "us") handles information when people interact with the CareSignal web prototype or its WhatsApp test channel. The project is operated in Zimbabwe and can be contacted at privacy@techdemo.co.zw.
1. Information we process
Depending on how the prototype is used, we may process:
- WhatsApp identifiers and metadata, such as a phone number, profile name supplied by WhatsApp, provider message identifier, timestamps, and delivery status.
- Message content submitted to the prototype, including synthetic blood-pressure values, measurement time, medication-taken status, optional context, and language preference.
- Structured information extracted from a message, the user's confirmation or cancellation, and the resulting fictional follow-up workflow record.
- Limited technical and security information needed to operate and troubleshoot the demo, such as request time, error category, and service status. We design logs to avoid message content, access tokens, and unnecessary identifiers.
2. Why we use this information
We use information only to:
- provide and demonstrate the CareSignal conversation and web workflows;
- extract structured fields for the user to review before anything is recorded;
- save a confirmed synthetic reading and demonstrate deterministic follow-up rules;
- send fixed service responses or clinician-approved demonstration messages;
- secure, test, diagnose, and improve the prototype; and
- respond to privacy, access, correction, and deletion requests.
We do not sell personal information or use it for advertising or unrelated marketing.
3. AI-assisted processing and clinical boundaries
CareSignal may send message content to the OpenAI API to extract a limited set of structured fields. Application-level response storage is disabled for these requests. OpenAI states that API data is not used to train its models by default, although eligible API inputs and outputs may be retained for a limited period for service delivery, safety, and abuse monitoring under OpenAI's applicable terms and privacy commitments.
An AI extraction remains an unrecorded draft until the user explicitly confirms it. AI does not diagnose, prescribe, recommend medication changes, determine clinical priority, override deterministic rules, or send patient-directed AI drafts without clinician approval.
4. When information is shared
We disclose information only as needed to operate the prototype, including to:
- Meta and WhatsApp, which transmit messages and provide message and delivery metadata under their own terms and privacy policies;
- OpenAI, when the constrained extraction feature is used;
- hosting, security, and infrastructure providers that support the prototype;
- authorised project team members who need access for testing or support; and
- authorities or other parties when required by applicable law or necessary for security.
These providers may process information outside Zimbabwe. Their handling of information is also governed by their respective terms and privacy notices.
5. Confirmation, correction, and minimisation
Conversational values are not entered into reading history until confirmation. Cancelling or correcting an unconfirmed conversational draft erases its raw message and extracted clinical values from the pending submission record. The prototype separates patient records and limits clinician actions through role and ownership checks.
6. Retention
During prototype testing, conversation and workflow records may remain in the demonstration datastore until the environment is reset, the test is decommissioned, or a verified deletion request is completed. The current prototype does not promise a fixed automatic deletion schedule. We retain only what is reasonably needed for the purposes described above and may keep minimal security or audit records where required to protect the service or comply with law.
7. Your choices and requests
You may ask us to access, correct, or delete information associated with your test use. Email privacy@techdemo.co.zw. We may need to verify that you control the relevant WhatsApp number before acting. Please do not include blood-pressure values, medication information, access tokens, or other sensitive content in the email.
See the CareSignal Data Deletion Instructions for the exact request process.
8. Security
We use reasonable technical safeguards appropriate to a limited hackathon prototype, including encrypted transport, server-side secret handling, webhook signature verification, mapped test senders, role checks, and reduced logging. No system is completely secure. Do not use the prototype for real patient care or submit real health information.
9. Adults only and emergencies
CareSignal is designed only as a demonstration of follow-up for adults already diagnosed with hypertension. It is not intended for children. Do not use CareSignal for urgent or emergency situations; contact an appropriate local emergency service or healthcare professional.
10. Changes and contact
We may update this policy as the prototype changes. The effective date above will be updated when material changes are published. Questions or complaints may be sent to privacy@techdemo.co.zw.
This policy describes a hackathon prototype and is not a representation that CareSignal is a clinically validated, regulated, or production-ready health service.