Wispivas Ltd
Clinical registry privacy notice
Effective 13 September 2026 · Version 1.4
Wispivas Ltd is responsible for deciding how information in this registry is used. We collect information needed to coordinate vasectomy-related care, document informed choice and clinical services, follow patients safely, monitor semen-analysis completion, and improve service quality.
Purpose limited
Information is used for care, administration, safety, audit and authorised programme reporting.
Restricted access
Identifiable records are available only to approved staff with a legitimate role and authorised patient or facility scope.
Your rights
You may ask to access or correct your information, object to or restrict some uses, or raise a privacy concern.
Who this notice covers
Patients and prospective patients who are referred by an approved healthcare or community partner, book an appointment, submit a registration or informed-choice form, receive a Wispivas-coordinated service, or whose legacy clinical information is migrated into this registry after quality review. It also covers clinic representatives who submit a clinic registration application.
Information collected
For a network referral, the referring organisation submits the patient’s name and email, identifies its named referrer, and confirms that the patient wants the referral and invitation. The patient later supplies their own registration and clinical information. The wider registry may hold identity and contact information, demographic details, relevant health history, referral and funding information, consent responses, appointments, clinical procedures, follow-up findings, complications and semen-analysis results. A clinic application holds the clinic name, location, booking email and review status.
Why Wispivas uses it
To receive and route an authorised referral; send a private clinic invitation; respond to a request for care; support counselling and informed choice; assess, book and document services; conduct postoperative and semen-analysis follow-up; protect patient safety; manage authorised providers, facilities and referral partners; maintain an audit trail; and produce aggregated or de-identified quality and programme reports. Some clinical information may also need to be retained or used to meet healthcare, legal, safety or accountability duties.
Optional clinic updates
A clinic representative may separately opt in during clinic registration to receive three optional product-update emails after the clinic is approved. This choice is not required for approval. These emails use only the clinic name and booking email, do not use patient or clinical records, and include a link to unsubscribe at any time. Operational and security messages are handled separately.
Sharing and reporting
Referral contact information is available to authorised staff at the receiving clinic and to contracted email and technology services needed to deliver and secure the invitation. The approved partner that submitted the referral receives only its submission reference and delivery status, not the patient’s later clinical record. Wispivas oversight staff see de-identified programme summaries by default and have no standing right to browse another institution’s identifiable reports. Routine identifiable access requires a stated purpose, approval by an authorised institution administrator and an automatic end time. A short exceptional window may be used only for an immediate patient-safety emergency, binding legal obligation or statutory public-health duty; it creates an institution-visible notice and can be revoked. The facility involved in care and contracted technology services may use identifiable information only within their authorised role and scope. Identifiable information is not used for public reporting. A sponsor or subscriber does not receive unrestricted access merely because it funded care or paid for the service.
Storage and transfers
The registry uses controlled cloud infrastructure. Where a service stores or processes information outside Kenya, Wispivas must apply contractual, technical and organisational safeguards appropriate to health information and applicable data-protection requirements.
Retention and safeguards
Clinical and referral information is retained only for as long as required by the approved health-record, referral, legal, safety and data-protection schedule, then securely deleted or de-identified where appropriate. Access is role and institution scoped. Sensitive record views, reports and exports are audit logged; approved Wispivas access expires automatically and may be revoked. No online system can promise absolute security.
Your choices and rights
You may request information about how your data is used, access a copy, ask for inaccurate information to be corrected, object to or request restriction of some processing, and request deletion where the law permits. Wispivas may need to verify your identity before acting on a request. If you receive an unexpected referral invitation, do not open it; contact the referring professional or Wispivas.
Optional postoperative photographs
A patient may actively consent to upload optional wound-healing photographs through the private recovery link. Supported browsers first create a smaller copy and remove camera metadata. Photos are available only to clinical staff acting within an authorised patient or facility scope; viewing, review and removal are audited. Photos are not attached to alert emails or included in routine programme reports or data-exchange exports. A patient can remove a pending photograph before clinical review; after review, health-record retention duties may apply and the patient should contact the clinic about correction or deletion.
Questions or requests
Contact Wispivas at charles@wispivas.com or +254 721 547 978. If a concern is not resolved, you may contact Kenya’s Office of the Data Protection Commissioner.