This page is deliberately easy to find. It is our full notice of privacy practices, written to HIPAA-aligned standards and Kenya's Data Protection Act, in plain language and with no small print.
What we collect
A contact email, your institution, a display name, your notification preferences, and the details you choose to give when booking — preferred format, preferred time and an optional note. For paid sessions we store an amount, a method and a transaction reference, never a card number or M-Pesa PIN. Clinical content lives only in session notes written by your counsellor. We do not ask for your national ID number, home address, next of kin, religion or sexual orientation unless you volunteer it, and nothing on this platform requires it.
Why we collect it
Four purposes only, matching the HIPAA notion of treatment, payment and operations: to confirm you are a student entitled to the service, to arrange and remind you about appointments, to keep clinical care safe and continuous between sessions, and to process payment where a fee applies. We do not sell data, we do not run advertising or third-party trackers, and we never use your identifiable information for research or marketing without separate written authorisation that you can refuse or withdraw.
Who can see it — minimum necessary
Access follows the HIPAA minimum-necessary principle: each role sees the least it needs. You see everything of your own. Your counsellor sees your appointment and the notes they authored. A clinical supervisor may review notes for practitioners they supervise. Peer counsellors see a display name, requested support areas and a time — never clinical notes or payments. Administrators manage bookings, refunds and accounts but are blocked at the database level from opening counselling notes or messages. Nobody in your department, faculty or family is given access.
How it is protected
Everything travels over HTTPS (TLS), and data is encrypted at rest (AES-256) in Google Cloud. Every account is individual, protected by a strong password (at least 10 characters with upper- and lower-case letters and a number) or by Google sign-in, and you are signed out automatically after 30 minutes without activity. Browsers cannot read or change the database directly at all: every request goes through our server, which checks who you are and refuses anything that isn't yours, and payments are confirmed directly with M-Pesa or Paystack before a session is marked paid. Administrative safeguards include role-based access for staff, confidentiality agreements for every counsellor and peer counsellor, and vetted processors bound by written data-protection terms.
Website analytics
With your permission only, we use Google Analytics to count visits to our public pages so we can see what helps people. It never runs on your dashboard, sessions, sign-in or any staff page, receives only the page address (never your answers, messages, bookings or health information), and has Google signals and ad personalisation switched off. You can change your choice at any time with “Analytics settings” at the bottom of every page.
Audit logging
Every creation, change and access to a sensitive record writes an immutable audit entry recording who acted, what they did, which record was touched and when. Audit logs are readable only by authorised administrators, cannot be edited or deleted through the application, and are reviewed for unusual access patterns. If you ever want to know who has looked at your record, you can ask for an accounting of disclosures.
Keeping and deleting data
Clinical records are retained for the period professional and legal standards require — commonly six years from the last session, or until the age of majority plus six years where the client was a minor — then securely destroyed. Appointment and payment records follow financial-record requirements. Everything else, including account and preference data, is deleted when it is no longer needed or on your request. Deleted data is removed permanently from our database.
When confidentiality may need to be broken
This is rare, and we will talk it through with you first wherever it is safe to do so. Your counsellor may need to share limited information when:
There is a serious and imminent risk to your life or safety.
There is a risk of serious harm to another identifiable person.
There is reasonable suspicion of abuse or neglect of a child or vulnerable adult.
We are required to disclose by law, subpoena or a court order.
Even then, we disclose the minimum necessary, to the specific people who can keep someone safe, and we log the disclosure so you can be told about it afterwards. Never to your family, lecturers or classmates by default.
Your rights
These are rights, not favours. Exercising any of them takes one email and costs nothing.
Your consent
We ask for your consent before you submit anything sensitive, and you can withdraw it at any time from your account privacy preferences. Withdrawing consent does not affect your right to book support.
Notice last updated 1 September 2026. Data Protection Officer: support.campuswell@gmail.com · +254701203242.
Struggling right now? You are not alone.Need help now?