CareThanks is committed to protecting the personal data of platform clients, end users, and website visitors. This Policy explains what data we collect, how we use it, and the rights available to data subjects under applicable law.
1. Who We Are
CareThanks is a trading name of Flywave Technology Limited, a company registered in England and Wales. CareThanks operates a rewards infrastructure platform for healthcare organisations across African markets. References to "CareThanks", "we", "our", or "us" in this Policy refer to Flywave Technology Limited trading as CareThanks. For data protection enquiries, contact: privacy@carethanks.net
2. Scope of This Policy
This Privacy Policy applies to: (a) visitors to the CareThanks website (carethanks.net); (b) clients and authorised users of the CareThanks platform and APIs; and (c) end users (patients, plan members, employees) who receive and redeem rewards through campaigns operated by CareThanks clients. This Policy does not apply to the data practices of CareThanks clients in their own operations โ clients are independent data controllers responsible for their own compliance.
3. Data We Collect
For platform clients and users: name, email address, job title, organisation name, and usage data generated through interaction with the dashboard and APIs. For end users of reward campaigns: mobile phone number (for SMS/WhatsApp delivery), reward redemption history, and geographic location at the market level. We do not collect clinical health data from end users. Underlying medical records, prescription data, and clinical identifiers remain with the healthcare organisation operating the campaign. For website visitors: standard server log data (IP address, browser type, pages visited) and, where consented, analytics cookies.
4. How We Use Personal Data
We process personal data to: (a) operate and improve the CareThanks platform; (b) deliver rewards to end users on behalf of client campaigns; (c) provide analytics and reporting to clients; (d) communicate with clients about platform updates, support, and commercial matters; (e) comply with legal obligations. We do not sell personal data to third parties. We do not use end-user data for advertising or profiling outside the scope of the campaign that generated it.
5. Legal Basis for Processing
For platform clients: processing is based on the performance of a contract and our legitimate interests in operating a commercial platform. For end users of reward campaigns: processing is based on the legitimate interests of the client healthcare organisation in operating a compliant reward program, and CareThanks' role as a data processor acting on client instructions. For website analytics: processing is based on consent where required, and legitimate interests for essential analytics.
6. Data Sharing
Personal data is shared with: (a) technology sub-processors required to operate the platform (cloud infrastructure, messaging providers, payment processors), each bound by data processing agreements; (b) CareThanks clients, in the form of campaign analytics and redemption data relating to their own programs; (c) competent authorities where required by applicable law. All sub-processors are evaluated for compliance with applicable data protection standards. A list of key sub-processors is available on request.
7. International Data Transfers
CareThanks operates across multiple African markets and its infrastructure involves international data transfers. All cross-border transfers are conducted in compliance with applicable data protection frameworks, including Standard Contractual Clauses where required under UK GDPR and equivalent mechanisms under Nigerian and Kenyan data protection law.
8. Data Retention
Platform client data is retained for the duration of the client relationship and for a period of 7 years thereafter for legal and financial record-keeping purposes. End-user reward redemption data is retained for the duration of the campaign and for 12 months thereafter for fraud prevention and audit purposes, unless a shorter period is agreed with the client. Website analytics data is retained for 24 months.
9. Your Rights
Data subjects have the right to: access personal data held about them; request correction of inaccurate data; request deletion of data where there is no legitimate basis for continued retention; object to processing based on legitimate interests; request restriction of processing; and data portability where applicable. To exercise any of these rights, contact privacy@carethanks.net. We will respond within the timeframe required by applicable law (typically 30 days).
10. Cookies
The CareThanks website uses essential cookies necessary for operation and, with consent, analytics cookies. Cookie preferences can be managed through the cookie consent tool on the website or through browser settings. We do not use advertising or tracking cookies.
11. Changes to This Policy
This Policy may be updated periodically. Material changes will be communicated by email to registered clients and by prominent notice on the website. The date of the most recent update is displayed at the top of this Policy.
12. Contact
For privacy-related enquiries or to exercise data subject rights: privacy@carethanks.net CareThanks, c/o Flywave Technology Limited, England and Wales.