Privacy Policy
Last updated 7 August 2026
Dashlead is management software for health facilities. This policy explains what personal data passes through the platform, why, and the choices people have. We keep it short because we want it read.
1. Two kinds of data
- Facility data, the patient records, appointments, prescriptions, results and invoices a health facility enters while running on Dashlead. The facility is the custodian of this data; Dashlead processes it on the facility's behalf and instructions, and for nothing else.
- Platform data, the accounts, contact details and messages of the people who sign up, use or contact Dashlead itself. For this data, Dashlead is responsible directly.
2. What we collect
- Account details: name, email address, and where provided, a phone number.
- Facility details: the organization's name and settings, and everything its staff enter in the course of their work.
- Payment references for mobile money transactions, the phone number charged and the transaction reference. We never see or store mobile money PINs.
- Technical logs: sign-ins and significant actions are recorded in an audit trail visible to the facility's owner.
3. How patient data is protected
- Every facility's records are isolated: staff of one facility cannot reach another facility's data.
- Within a facility, role-based permissions decide who sees what: a receptionist books appointments but cannot open the facility's finances, and a lab technician sees the laboratory, not billing.
- Patients using the portal see their own records only, after verifying their identity with a code sent to them.
- Passwords are stored hashed, and sign-in verification codes expire within minutes.
4. Messages
Facilities can send appointment reminders, results notifications and similar messages to patients by email, SMS or WhatsApp. These are sent only to patients whose records carry consent for that channel, and every email carries a one-click unsubscribe that stops future messages immediately.
5. Cookies
Dashlead uses essential cookies only: a session cookie that keeps you signed in and a token that protects forms against forgery. There are no advertising or cross-site tracking cookies.
6. Sharing
We do not sell personal data, to anyone, ever. Data leaves the platform only where the service requires it: our mobile money aggregator processes payment requests, and email, SMS and WhatsApp providers deliver the messages a facility sends. Each receives the minimum needed to do its job. A facility's public page appears in the public directory only after the facility opts in.
7. Retention and deletion
Facility data is kept for as long as the facility maintains its account. When an account is closed, data is deleted or returned on written request, subject to records that health-care and financial law require to be kept. Patients seeking correction or deletion of their records should contact their facility, which controls them; we assist facilities in honouring such requests.
8. Your rights
Under the Data Protection and Privacy Act, 2019 of Uganda, you have the right to know what personal data is held about you, to have inaccuracies corrected, and to object to processing that lacks a lawful basis. To exercise these rights for platform data, reach us through the contact page; for medical records, contact your facility.
9. Changes
If this policy changes in a way that matters, we will say so in the app or by email before the change takes effect.
10. Contact
Questions about privacy are welcome any time through the contact page or the WhatsApp numbers in the footer.