Privacy Policy
Last updated: 6 October 2026. This document describes the code and data flows in the current Clean Systems release.
1. Scope
This Privacy Policy applies to visits to clean-systems.online and to messages sent through the website contact form. Clean Systems is an informational publishing project about prostatitis and pelvic-health questions. It is not a clinic, pharmacy, patient portal or telemedicine service. The current release does not create patient records and does not ask visitors to submit medical histories.
No legal company name, registration number, tax identifier, verified operator street address or verified operator phone number has been supplied for this release. This policy therefore does not invent those details.
2. Kenya privacy framework
Kenya's Data Protection Act, 2019 regulates processing of personal data and gives data subjects rights in relation to that processing. The Data Protection (General) Regulations, 2021 provide additional rules on areas including notices, consent, direct marketing and data-subject requests. The Office of the Data Protection Commissioner (ODPC) is the supervisory authority.
Health status is treated as sensitive personal data under the Kenyan framework. This website is deliberately designed so that its general contact form is not a clinical intake form. Visitors are asked not to send health records or detailed medical information.
3. Data the current site can receive
3.1 Contact-form data
If you submit the form, the website receives the name, email address, subject and message you enter. A server-side session stores a temporary CSRF token and a recent-submission timestamp to protect the form. A hidden honeypot field is used to reduce automated spam.
3.2 Server and security logs
The hosting environment may create technical logs containing IP address, time, requested path, HTTP status, browser or user-agent information and similar diagnostic data. The exact log configuration and retention depend on the hosting provider, which has not been specified for this build.
3.3 Data you should not submit
Do not send diagnoses, laboratory results, prescriptions, medical images, identification documents, detailed sexual-health information or other sensitive records through the general contact form. If you need clinical care, use a secure channel provided by your healthcare provider.
4. Purposes
Contact information is used to respond to editorial corrections, privacy requests, accessibility concerns, technical feedback and other non-clinical enquiries. Technical data may be processed to deliver pages, troubleshoot faults, maintain security, detect abuse and protect the service.
5. Legal basis and consent
The appropriate lawful basis depends on the nature of a particular processing activity and the operator's actual legal position. Where consent is used, it should be voluntary, informed and specific. The contact form acknowledgement is limited to the submitted website enquiry and is not consent to marketing, health profiling or unrelated processing.
6. Sensitive health data
The topic of the site is health, but the site does not infer a visitor's diagnosis from pages viewed and does not provide an account where health history is stored. Interactive elements such as accordions operate in the browser and do not send symptom selections to a server.
Kenyan law places additional controls around processing personal data relating to health. Because Clean Systems is not presented as a healthcare provider, it intentionally avoids collecting health records through the general form.
7. Cookies and browser storage
In this release, GA4, GTM, Cookiebot, reCAPTCHA, Google Maps, advertising pixels and affiliate tracking scripts are not active because no valid configuration IDs or partner destinations were supplied. A small sessionStorage preference may remember that the basic storage notice has been acknowledged during the current browser session. Server-side PHP sessions are used for form security.
See the Cookie Policy for the detailed storage inventory.
8. Analytics, advertising and profiling
No analytics or advertising tag is intentionally loaded by the supplied code while integration fields remain empty. The site does not use automated decision-making to decide eligibility for treatment, credit, insurance, employment or other significant outcomes. It does not intentionally build health advertising profiles.
9. Affiliate tracking
The declared business model is affiliate publishing, but the current interface contains no live affiliate link, external offer URL, partner redirect or affiliate cookie. If commercial linking is introduced later, this policy and the Affiliate Disclosure should be updated before activation to describe recipients, identifiers, tracking and any transfers involved.
10. Email delivery and processors
When the contact form is successfully submitted, the PHP application attempts to hand the message to the server's configured mail system for delivery to [email protected]. Hosting and email infrastructure may therefore process the message. The specific providers have not been supplied and are not invented here.
11. International transfers
Whether personal data is transferred outside Kenya depends on where the actual hosting, mail and any future service providers process data. The operator should verify processing locations and implement the safeguards required by applicable law. This policy does not claim that data remains only in Kenya.
12. Retention
Messages should be retained only as long as reasonably necessary to answer an enquiry, maintain an appropriate correspondence record, protect legal rights or meet an applicable obligation. No fictional fixed mailbox-retention period is stated because the operational email policy was not provided. Server-log retention is likewise controlled by the actual host.
13. Security
The supplied form includes input length limits, email validation, a CSRF token, a honeypot and a simple repeat-submission interval. Production deployment should use HTTPS, supported PHP versions, timely security updates, restricted file permissions and secure administrative credentials. No internet service can promise absolute security.
14. Data-subject rights
Depending on the circumstances, Kenyan data subjects may have rights to be informed about use of their personal data, request access, object to processing, request correction of false or misleading data, and request deletion where the law provides. Requests concerning this website can be sent to [email protected]. Reasonable identity verification may be necessary before information is disclosed or changed.
15. Direct marketing
The current site has no newsletter signup and the contact form is not used by the supplied code to enrol visitors in marketing. Kenya's Data Protection (General) Regulations contain specific requirements for direct marketing, including notice, consent/other permitted conditions and an accessible opt-out. Those controls must be implemented before any future direct-marketing programme begins.
16. Children
Clean Systems is written for adults and is not designed to create profiles of children. If the operator learns that a child submitted personal data through the general form, it should be reviewed promptly and handled in accordance with applicable law.
17. Third-party links
The current interface intentionally contains no outbound commercial or affiliate links. If reference or commercial links are added later, the destination services will have their own privacy practices.
18. Changes
This policy may be revised when the site's functionality, providers, business relationships or legal requirements change. The “Last updated” date should change when a substantive revision is published.
19. Complaints and contact
Privacy questions can be sent to [email protected]. Individuals may also have the right to raise data-protection concerns with Kenya's Office of the Data Protection Commissioner through its current official channels. Regulator contact details are not hard-coded here so visitors can use the authority's current information.