Skip to content
Back to home
Sentra

Legal

Privacy Policy

Last updated August 2026

Overview

Sentra is operated by Snuggli Health and supports frontline mental health care coordination in Ghana. This policy explains what personal and health information we collect, how we use it, and the rights you have over it.

Sentra handles Protected Health Information (PHI). Access is restricted to authorised clinicians within your institution and is isolated per tenant — one institution cannot see another's records.

Pilot status: Sentra is currently in a pilot evaluation with partner institutions in Ghana. Some features described in this policy are being validated during the pilot and may change as the program matures. Pilot participants should confirm the current feature scope with their institution administrator.

1Information we collect

  • Patient data: demographics, presenting concerns, assessment responses, risk levels, referral and follow-up records, consent records, and session notes.
  • Clinician data: name, email, role, and audit-trail entries for clinical actions you take.
  • Device & usage: anonymised connectivity and performance metrics used to keep the app reliable on low-bandwidth networks.

2Consent is the foundation

Except in a documented emergency or safeguarding override (which is fully audited), assessment, referral, and data sharing require a recorded consent. Consent is scope-specific — granting care consent does not imply data-sharing or research consent. Patients (or their guardians for minors) may withdraw consent at any time, and processing stops for the withdrawn scope. Some referral and emergency flows are still being brought under the governed consent record; where a consent record has not yet been created, the action is audited and flagged for reconciliation rather than silently proceeding.

Where a patient lacks capacity and consent cannot be obtained, clinicians may record a justified override (e.g. emergency care, safeguarding) which is fully audited.

3How we use your information

  • To coordinate screening, triage, referral, and follow-up care.
  • To generate AI-assisted summaries and referral notes — always reviewed by a clinician before use.
  • To fulfil NHIS claims-readiness and reporting obligations.
  • To improve clinical safety, quality, and reliability of the platform.

4Data sharing & sub-processors

We do not sell personal or health data. Data is shared only with: (a) the receiving facility for referrals you authorise, (b) NHIS for claims you submit, and (c) sub-processors providing hosting, SMS, and AI inference under written data-protection terms.

5Retention

Legal basis. Retention follows the Ghana Data Protection Act, 2012 (Act 843) and your institution's clinical record-retention duties. Snuggli Health acts as a data processor on behalf of your institution, which is the data controller.

Configured window. Each institution sets its retention policy — 1, 2, 5, or 7 years, or indefinite — in its governance configuration; the default is 5 years. Your institution administrator can confirm the active window.

Disposal. Records in a terminal status that are older than the retention window are disposed through an admin-only, tenant-scoped retention tool. Disposal is dual-controlled: an administrator first runs a dry-run report, reviews the candidate list, and then confirms disposal by re-verifying the exact candidate count — there is no blind one-click disposal. A pre-disposal audit record is written first, and if the audit cannot be written, disposal is aborted. The minimum disposal horizon is 365 days to protect recent records.

Exceptions. Consent records and care-episode records are long-term legal records and are never automatically disposed; they are retained unless individually deleted under a verified data-subject request.

Encounters are only ever closed through an audited closure function with evidence. Records may also be deleted earlier on a verified data-subject request (see §7).

6Security

Access is enforced with row-level security per institution, role-based permissions, and optimistic locking on clinical records through the sanctioned server write path. An immutable audit trail records safety-critical actions; some legacy direct-write paths are being migrated to that path, so audit coverage is being extended rather than complete. Offline data is encrypted at rest in the device store and wiped on logout; if secure encryption cannot be established on a device, sensitive data is not stored offline rather than being written in plaintext.

7Your rights

  • Access, correct, or export (data portability) your data.
  • Withdraw consent for any scope — processing stops for the withdrawn scope.
  • Request deletion (erasure) of records.

How to exercise these rights. Requests are made through your institution administrator or the in-app Data Subject Rights panel. All operations are admin-gated and tenant-scoped — they affect only records within your institution.

Export produces a complete, structured bundle of every record linked to the patient in your institution, which you can download and share.

Erasure requires a documented reason and a typed confirmation. A tamper-evident audit tombstone is written before any record is deleted; if the audit cannot be written, erasure is aborted and no data is destroyed. Consent records are withdrawn in place (not deleted) to preserve the consent ledger's integrity. Erasure is irreversible.

Retention-gated. Records within the active retention window (§5) are retained to meet legal duties. Aged records beyond the window are disposed through the dual-controlled retention tool. All export, erasure, and disposal actions are recorded in the immutable audit trail.

8Children & vulnerable groups

When a patient’s recorded date of birth indicates they are under 18, guardian consent and identity attestation are required and recorded before screening proceeds; the readiness step collects date of birth and will not advance for a minor without a guardian or assent basis. Special safeguards apply to pregnant, postpartum, and school-going patients.

9Contact

Questions about this policy or your data: see the Support page. Data-protection concerns may also be raised with the Ghana Data Protection Commission.

© 2026 Snuggli Health. Sentra is a clinical decision-support tool and does not replace professional clinical judgment.