General principles
Kora aims to collect only the data needed to operate directory, claim/listing, booking, support, and security workflows. Kora does not sell patient conversations or provider-submitted information to advertisers.
Kora handles healthcare-adjacent directory and booking coordination data carefully. This page summarizes the current MVP privacy posture and areas that may evolve before production launch.
Kora aims to collect only the data needed to operate directory, claim/listing, booking, support, and security workflows. Kora does not sell patient conversations or provider-submitted information to advertisers.
Patient phone numbers may be used for OTP sign-in, appointment coordination, reminders, account access, and abuse prevention. OTP data should be handled as authentication data.
Booking requests may include name, phone, email, selected service, requested time, and reason for visit. Providers remain responsible for patient care and clinic-side records.
Provider claim/listing submissions may include identity, role, practice, contact, and supporting information needed for Ops review and profile activation.
Kora may log call intent events, such as a user tapping a call action, to understand directory usefulness and booking conversion without treating that event as medical advice or care delivery.
Kora’s MVP analytics should be cookieless and PII-safe by default. Analytics events should avoid patient names, phone numbers, emails, medical details, or free-text clinical content.
Kora may process data across countries as it supports Africa-first directory coverage. Country-specific privacy obligations will be reviewed as launch markets are finalized.
Kora expects market-specific privacy review for Ghana, Kenya, Nigeria, Côte d’Ivoire, and Senegal as coverage and launch operations mature.