Browser-local QC
The current QC demo processes selected FASTQ files in your browser. It does not upload them to Kmeggie+.
PRIVACY & DATA HANDLING
This notice explains what the current Kmeggie+ website and official messaging channels collect, why we use it, how long we keep it, and the choices available to you.
Last updated:
AT A GLANCE
The current QC demo processes selected FASTQ files in your browser. It does not upload them to Kmeggie+.
The official WhatsApp bot accepts support and pilot-intake text only. Do not send sequencing files or patient data.
We do not use submitted contact details, messages, sequence files, reports, or metrics to train Kmeggie+ or third-party AI models.
You may ask to access, correct, restrict, export, or delete personal data held by Kmeggie+.
CURRENT PRODUCT BOUNDARY
The website demo analyses files locally. The WhatsApp bot and contact form do not accept sequence files. If remote sequence processing is introduced, Kmeggie+ will provide a separate, just-in-time notice and institutional data-processing terms before the first upload.
01 — SCOPE AND ROLES
This notice applies to kmeggieplus.com, the browser-local QC demonstration, pilot and contact requests, official Kmeggie+ email, and the official Kmeggie+ WhatsApp support bot.
It is intended to explain our processing in line with Kenya's Data Protection Act, 2019, and applicable data-protection regulations.
For contact, website, and bot records, Kmeggie+ determines how the information is used and acts as the data controller. If a future institutional service processes laboratory data on a laboratory's instructions, the laboratory and Kmeggie+ will define their controller and processor roles in a written agreement before processing begins.
This notice does not cover unofficial accounts, copied bots, third-party websites, or services that are not linked from kmeggieplus.com.
02 — WHAT WE COLLECT
When you submit a request, we collect the request type, name, work email, organization, country, role, connectivity context, current sequencing workflow, pilot or demonstration goal, consent time, submission time, reference number, and request status.
We receive the WhatsApp account or phone identifier, phone number, language choice, message identifier and type, timestamps, temporary conversation state, and any contact or workflow details you intentionally submit. We do not store a general-purpose transcript of ordinary menu conversations.
Our hosting and security provider may process technical request information such as an IP address, browser type, requested URL, timestamp, and security signals needed to deliver and protect the site.
The public website does not currently use advertising or behavioural-analytics cookies. The private administrator area uses a strictly necessary, HTTP-only session cookie to protect access to submitted requests.
03 — SEQUENCE DATA
When you select a FASTQ or FASTQ.GZ file in the current browser demo, analysis runs on your device. The file and generated report are not sent to the Kmeggie+ server. A report leaves your device only if you choose to download or share it yourself.
Do not send raw sequence data through the pilot form, WhatsApp, or ordinary email. Do not include patient names, patient identifiers, sample identifiers that reveal a person, or other confidential clinical information.
Human genomic data can sometimes be connected back to an individual or biological relatives even after names and obvious identifiers have been removed. Institutional authorization and appropriate safeguards may still be required.
Any future remote-upload workflow will state its storage location, permitted data types, access controls, retention period, deletion process, subprocessors, and transfer safeguards before files are accepted. This notice by itself does not authorize Kmeggie+ to receive human genomic or patient-linked sequence data.
04 — MESSAGING CHANNELS
The official Kmeggie+ WhatsApp bot is a text-only information and pilot-intake channel. WhatsApp protects messages in transit to the business service, after which Kmeggie+ processes the text needed to reply and save an intentionally submitted request. Meta also processes messaging and account metadata under its own privacy terms.
Do not send documents, images, audio, FASTQ files, passwords, secrets, or patient-identifiable information through the bot. Unsupported attachments are rejected and are not downloaded by Kmeggie+.
Kmeggie+ does not currently operate a public Telegram bot. If one is introduced, this notice will be updated before launch. Standard Telegram bot chats are not end-to-end encrypted, so Telegram must not be used for raw sequencing data, patient data, passwords, or other highly sensitive material.
05 — WHY WE USE DATA
| Purpose | Information involved | Ground relied on |
|---|---|---|
| Respond to enquiries and arrange pilots or demonstrations | Contact and workflow details | Your consent and steps taken at your request |
| Send a confirmation and notify the Kmeggie+ team | Email address and request summary | Your consent and delivery of the requested response |
| Maintain security, prevent duplicate submissions, and diagnose failures | Technical logs, message identifiers, timestamps, and limited metadata | Legitimate interests in operating a secure and reliable service |
| Meet applicable legal obligations and respond to valid legal requests | Only the information legally required | Compliance with law |
We do not use pilot-request or messaging information for unrelated marketing. If Kmeggie+ later introduces newsletters or promotional messaging, those communications will use a separate opt-in.
07 — RETENTION
| Record | Current retention approach |
|---|---|
| FASTQ files selected in the browser demo | Not received or retained by Kmeggie+ |
| Downloaded QC reports | Remain under the user's control; Kmeggie+ receives no server copy |
| Abandoned WhatsApp session state and webhook-event metadata | Eligible for deletion after 30 days and removed during routine automated maintenance |
| Completed website or WhatsApp pilot requests | Kept while the request is active and ordinarily for no more than 12 months after the last meaningful contact |
| Transactional-email delivery records and essential security logs | Kept only as long as reasonably needed for delivery, security, troubleshooting, or applicable legal requirements |
We may keep a limited record longer where required by law, needed to investigate misuse, or necessary to establish, exercise, or defend legal claims. You may request earlier deletion, subject to those limited exceptions.
08 — SECURITY
Kmeggie+ uses measures appropriate to the current service, including secure transport, signed WhatsApp webhook verification, limited administrator access, HTTP-only session protection, input validation, request-size limits, and restricted access to stored pilot records.
Authorized personnel may view contact and workflow details when reviewing or supporting a request. No internet service is completely risk-free, so please use the browser-local workflow for sequence files and avoid sending sensitive material through messaging or ordinary email.
If a personal-data incident creates a risk to affected people, Kmeggie+ will investigate, contain, document, and make the notifications required by applicable law.
09 — YOUR RIGHTS
Subject to applicable law and appropriate identity verification, you may ask Kmeggie+ to:
Send requests to hello@kmeggieplus.com. We may request enough information to verify your identity and locate the relevant submission. You may also raise a concern with Kenya's Office of the Data Protection Commissioner.
10 — INTERNATIONAL TRANSFERS
Cloud and messaging providers may process technical, contact, or messaging information in countries outside Kenya. Kmeggie+ will use appropriate contractual, organizational, and technical safeguards for such processing. Sensitive personal data will not be accepted for a future remote service until the applicable Kenyan requirements for processing and cross-border transfer have been addressed in the service design and institutional agreement.
11 — CHANGES AND CONTACT
We will update the date at the top when this notice changes. Material changes affecting an active pilot will also be communicated through an appropriate pilot contact.
Kmeggie+
Nairobi, Kenya
hello@kmeggieplus.com
support@kmeggieplus.com
This public notice describes current data handling. An institutional pilot involving sensitive or controlled data may also require a separate data-processing agreement, security schedule, and approved data-flow assessment.