This Service Agreement (“SA” or “Agreement”) is entered into by and between:
Banda Health (“Banda Health”, “we”, “us”), a US registered entity providing the BandaGo software-as-a-service solution.
AND
The Clinic/Healthcare Facility (“Client”, “you”), subscribing to the BandaGo service.
(Each a “Party” and collectively, the “Parties”)
The effective date of this Agreement is the earlier of the date on which the Client completes the registration process and fully executes all agreement addenda, or otherwise accesses or uses all or any part of the BandaGo Service (“Effective Date”).
RECITALS
WHEREAS, Banda Health develops, operates, and distributes the BandaGo online clinic management system (the “Service”), including hosted applications (“Apps”);
WHEREAS, the Client desires to subscribe to and use the Service for its clinic management, patient registration, electronic medical records (EMR), billing, and inventory management needs;
WHEREAS, the Parties wish to set forth the terms and conditions under which Banda Health will provide the Service to the Client.
NOW, THEREFORE, in consideration of the mutual covenants contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
Capitalized terms not otherwise defined in this SA shall have the meanings given to them in the Service Level Agreement (SLA) and the Data Processing Addendum (DPA) attached hereto.
2.1. The Client acknowledges and agrees to be bound by all the terms and conditions of this SA, including the Service Level Agreement, the Data Processing Addendum, the Privacy Policy, and the Terms of Service, all of which are incorporated by reference herein and form an integral part of this Agreement.
2.2 The Client’s consent to this Service Agreement, including all incorporated Exhibits and Addenda, is provided through the completion of the registration process, the written or electronic acceptance of these terms (which may include clicking an “I Agree” button or similar electronic affirmation). The Parties agree that electronic acceptance, following review of the terms and conditions herein, shall constitute written consent for the purposes of this Agreement and applicable law.
2.3. If the Client does not agree to these terms, or if the Client is not eligible or authorized to enter into this Agreement, or if the use of this Service is not permitted by the laws of the country in which it will be used, then the Client must not register for, download, access, or use the Service.
3.1. Description of Service: BandaGo is an online clinic management system designed to help healthcare facilities manage cash flow and inventory, improve information documentation and reporting, and enhance patient care. The Service provides features including but not limited to role-based user access, inventory management, point-of-sale and expense tracking, patient visit management (registration, clinical notes, lab orders, billing, and scheduling).
3.2. Eligibility: The Client represents and warrants that the individual executing this Agreement on its behalf is at least 18 years of age and legally authorized to bind the Client to these terms. Furthermore, the Service is intended for use by individuals who are at least 18 years of age, and under no circumstances may the Service be knowingly used by individuals under 18 years of age. The Client shall ensure that all of its Users meet these age requirements.
3.3. Registration and Account Management: To establish an account, register for and use the Service, certain information about the healthcare facility or provider may be required, including name, address, telephone number, email address, username, and password. Banda Health may refuse to accept the Client’s application to register for the Service, in its sole discretion. Upon acceptance, Banda Health will activate the access credentials for the Client’s account. The Client is solely responsible for maintaining the confidentiality of its access credentials and other account information and will be solely liable for any and all activities under its account. The Client agrees to notify Banda Health immediately of any unauthorized use of its account or any other breach of security related to the Service.
3.4. Not Healthcare Services: The Service is only intended as an information tool to aid healthcare providers and must not be used as a substitute for professional healthcare services. Banda Health does not provide professional healthcare services and has no control over how a healthcare provider uses the Service.
3.5. Client Indemnification: The Client agrees to defend, indemnify, and hold harmless Banda Health, its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or in connection with:
3.6. Customization: Banda Health uses a lean iterative approach to incorporating user and stakeholder needs. New features are released to all clients simultaneously, and BandaGo is not customized for individual clinic needs.
4.1. Subscription Plans: Banda Health offers one or more subscription plans for Services (each a “Plan”). Specific prices and plans are listed on Banda Health’s official pricing page available at www.bandahealth.org, which is incorporated by reference herein.
4.2. Payment Terms: Clients must select a Plan and, where applicable, pay for Services in advance before the Client and the Users they approve access BandaGo. Plan fees may change from time to time, with new fees applying to a Client when a new subscription period commences. Payments are not cancellable, and fees paid are non-refundable. Payments are primarily accepted via mPesa. However, the Parties may mutually agree upon alternative payment methods in writing.
4.3. Subscription Renewal: Subscription periods may differ based on the Plan selected at the time of payment. At the end of a subscription period, Plans will automatically renew with fees assessed according to the fee and subscription schedule active at the time of renewal. Subscription renewal fees are due within 7 calendar days of renewal.
4.4. Suspension and Closure for Non-Payment: Failure to pay in accordance with this Section 4 may lead to suspension or termination of the Service as detailed in Section 9 (Term and Termination). Client and User will not have access to data in accounts suspended or closed for non-payment unless the Client has submitted a written payment dispute requesting continued access during resolution discussions and is cooperating with Banda Health in good faith to resolve the dispute.
4.5. Price Stability and Increases: Banda Health commits to not increasing subscription prices for the first two years from the effective date of this agreement, conditional on uninterrupted and punctual fee payments.
4.6. Taxes: Subscription fees do not include any taxes, levies, duties, or other governmental assessments such as value-added, sales, use, or withholding taxes assessed by any jurisdiction whatsoever (collectively “Taxes”). The Client is responsible for paying all Taxes associated with its use of Services. If Banda Health is found to have a legal obligation to pay or collect Taxes for which the Client is responsible, Banda Health will send the Client an invoice for the Taxes due, and the Client must pay the amount unless the Client provides Banda Health with a valid tax exemption certificate authorized by the appropriate taxing authority.
The Service Level Agreement (SLA), attached hereto as Exhibit A and incorporated into this Agreement; outlines Banda Health’s commitments regarding Service availability, performance, and support services. The Client agrees to the terms and conditions set forth in the SLA.
The Data Processing Agreement (DPA), attached hereto as Exhibit B and incorporated into this Agreement, outlines the obligations of both Parties with respect to the processing of Personal Data and Service Data. The Client agrees to the terms and conditions set forth in the DPA.
Banda Health’s Privacy Policy, available on the Site and incorporated by reference herein, explains our online information practices and the choices the Client and Users can make about the way information is collected and used when visiting the Site or using the Service. By using the Service, the Client accepts the terms of the Privacy Policy.
8.1. Compliance with Laws: The Client agrees to abide by all applicable local, state, national, and international laws, regulations, and rules, including without limitation data protection and privacy laws, in connection with its access and use of the Service, and shall ensure that its Users also comply with all such laws.
8.2. User Compliance with Terms of Service: The Client acknowledges that access and use of the Service by its Users are subject to Banda Health’s Terms of Service, available on the Site and incorporated herein by reference. The Client agrees to ensure that all of its Authorized Users comply with the Terms of Service. The Client shall be responsible for any breach of the Terms of Service by its Users, and Banda Health reserves the right to suspend or terminate the access of any User or the Client’s entire account for such breaches, in accordance with the Terms of Service and this SA. The Client further agrees to inform its Users of the existence and content of the Terms of Service and to obtain any necessary consents from its Users for the processing of their data in accordance with the Terms of Service and Privacy Policy.
9.1. Term of Agreement: This Agreement shall commence on the Effective Date and shall continue in effect for the subscription period selected by the Client as per Section 4.1. The Agreement shall automatically renew for successive subscription periods unless terminated earlier in accordance with the terms herein.
9.2. Termination for Convenience:
9.2.1. By Client: The Client may terminate this Agreement by providing written notice to Banda Health. Such termination will be effective at the end of the then-current subscription period, provided notice is given at least 7 calendar days prior to the end of the current subscription period. No refunds will be provided for any prepaid fees for the remainder of the current subscription period.
9.2.2. By Banda Health: Banda Health may terminate this Agreement for convenience by providing at least 30 calendar days’ written notice to the Client. In such an event, Banda Health will refund any prepaid fees for the remaining portion of the subscription period after the effective date of termination.
9.3. Termination for Cause:
9.3.1. By Either Party: Either Party may terminate this Agreement with immediate effect by written notice to the other Party if the other Party:
9.3.2. Other Client Breaches: Banda Health may also terminate this Agreement immediately upon written notice if the Client (or any of its Users) breaches Section 8.1 (Compliance with Laws) or 8.2 (User Compliance with Terms of Service).
9.. Effects of Termination:
9.4.1. Upon termination of this Agreement for any reason, all rights and licenses granted to the Client hereunder shall immediately cease, and the Client and its Users must immediately cease all use of the Service.
9.4.2. Termination of this Agreement shall not affect any rights, remedies, obligations, or liabilities of the Parties that have accrued up to the date of the effective date of termination.
9.4.3. Data Handling upon Termination:
9.5. Survival
Sections 1 (Definitions), 3.4 (Not Healthcare Services), 3.5 (Client Indemnification), 4 (Fees and Payments – for accrued but unpaid fees), 9.4 (Effects of Termination), 11 (Dispute Resolution and Governing Law), and any other provisions which by their nature are intended to survive termination, shall survive the termination of this Agreement.
10.1. Our Commitment to Improvement
To ensure the BandaGo system remains effective and secure, we may need to amend this Agreement from time to time, such as to comply with new laws, address security needs, or reflect improvements and new features in our service.
10.2. Notice of Material Changes
For any material change, we promise to give you at least 30 days’ advance notice. We will notify you via the email or WhatsApp number associated with your account, or through a clear notification within the BandaGo system. A “material change” is a significant alteration that affects the system’s functionality, availability, security, support, or your core obligations.
10.3. Your Acceptance of Changes
Your continued use of the BandaGo service after the 30-day notice period will signify your acceptance of the new terms.
However, for any update that:
we will require your explicit, affirmative consent (for example, by asking you to click an “I Agree” button within the system) before the change is applied to your account.
10.4. Your Right to Disagree
We respect your right to choose. If you do not agree with the proposed changes, you may reject them by terminating your agreement with us without penalty before the changes take effect. You can do this by providing us with written notice of your decision to terminate.
This Agreement and any dispute arising out of it shall be governed by and construed in accordance with the laws of the Republic of Kenya. The parties agree to attempt to resolve any dispute amicably through negotiation. If the dispute cannot be resolved through negotiation, it shall be referred to arbitration in Nairobi, Kenya, in accordance with the Arbitration Act, 1995.
Please enroll my health facility in the BandaGo online clinic management system according to the terms and conditions outlined in this Service Agreement, including all incorporated addenda and policies, which I have read, understood, and agree to be bound by.
Facility Name: _______________________________________________________________
Facility Address/Location: _______________________________________________________________
Full name of legally authorized representative of the health facility:
_______________________________________________________________
Title: __________________________________________________________
Email address: _______________________________________________________________
Mobile Phone: _______________________________________________________________
Signature: _______________________________________________________________
Signature of legally authorized representative of the health facility
Date: _______________________________________________________________
This Service Level Agreement (SLA) is entered into between Banda Health (“Banda Health”, “we”, “us”) and the client health facility (“Client”, “you”) and outlines the terms and conditions for the provision of the BandaGo online clinic management system (“Service”). This SLA should be read in conjunction with the Banda Health Solutions Terms of Service, Data Processing Agreement, and Privacy Policy.
BandaGo is an online clinic management system designed to help healthcare facilities save money by managing cash flow and inventory, save time through efficient information documentation and reporting, and improve patient care with more complete and accessible records. The service provides a robust set of features including role-based user access, inventory management, point-of-sale and expense tracking, and patient visit management (registration, clinical notes, lab orders, billing, and scheduling).
Uptime: our target is 99.9% uptime outside of scheduled maintenance.
Banda Health maintains industry-standard security measures to protect client data, details of which are provided in the Terms of Service and its associated Data Processing Agreement (DPA).
The Client agrees to:
This Data Processing Agreement (“DPA”) is entered into between:
The Controller: The Clinic or Healthcare Facility subscribing to the BandaGo service (“the Clinic” or “Controller”).
and
The Processor: Banda Health, the provider of the BandaGo software-as-a-service solution (“Banda Health” or “Processor”).
This DPA is incorporated into and forms an integral part of the Service Agreement (“the Agreement”) between the Clinic and Banda Health for the use of the BandaGo platform (“the Service”).
For the purposes of this DPA, the following terms shall have the meanings set out below. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.
2.1. Processing Activities. Banda Health shall process Personal Data on behalf of the Clinic for the sole purpose of providing, maintaining, and improving the BandaGo Service as described in the Agreement.
2.2. Details of Processing Clinic, patient, and staff data:
3.1. Processor’s Obligations. Banda Health, as the Data Processor, agrees to:
3.2. Controller’s Obligations. The Clinic, as the Data Controller, agrees to:
Banda Health shall promptly notify the Clinic if it receives a request from a Data Subject to exercise their rights under Data Protection Laws (e.g., right of access, rectification, erasure, etc.). It is the Clinic’s obligation to respond to data subject requests. Banda Health shall not respond to any such request itself, except required by applicable laws. Banda Health will provide the Clinic with reasonable cooperation and assistance.
5.1. Authorization. Banda Health from time to time utilizes sub-processors to provide and maintain the Services and the Sites. By signing this Agreement, the Clinic agrees and consents to Banda Health’s use of Sub-processors to process Personal Data. Banda Health shall maintain an up-to-date list of its Sub-processors, which shall be made available to the Clinic upon request.
5.2. Obligations. Banda Health shall:
Banda Health’s hosting provider may be located in a country or territory outside of Kenya and therefore Banda Health may need to transfer Personal Data outside of Kenya to provide the Services. Clinic agrees to such data transfer. Banda Health will ensure that the transfer is compliant with Data Protection Laws and that appropriate safeguards are in place to protect the Personal Data.
7.1. Overall Security Program: Banda Health maintains industry-standard security measures to protect Personal Data, Service Data and the BandaGo Platform. Banda Health’s overall security program includes the following key components:
7.1.1. Secure Software Development Lifecycle: Banda Health is responsible for implementing and maintaining a secure software development lifecycle for all updates, enhancements, and maintenance of the BandaGo Platform to minimize security vulnerabilities.
7.1.2. Incident Response Plans: Banda Health is responsible for establishing and maintaining comprehensive incident response plans for the detection, investigation, containment, and remediation of any Security Incident or Data Breach affecting the BandaGo Platform, Personal Data, or Service Data. Banda Health shall notify the Client without undue delay upon becoming aware of a Data Breach affecting the Client’s Personal Data, in accordance with the Data Processing Addendum and applicable Data Protection Laws.
7.1.3. Physical Security of Data Centers: Banda Health utilizes third-party cloud service providers to host the BandaGo Platform. As such, the physical and environmental security of the servers and infrastructure is the responsibility of these providers. Banda Health commits to engaging reputable cloud providers who maintain industry-standard security certifications (such as ISO 27001, SOC 2, or equivalent) and who implement robust measures to protect against unauthorized access, damage, and environmental hazards.
7.1.4. Network Security Practices: Banda Health implements robust network security practices, which include, but are not limited to:
7.1.5. Access Controls: Banda Health implements strict access control mechanisms, including role-based access controls, to limit access to the BandaGo Platform, Personal Data and Service Data only to authorized individuals based on the principle of least privilege, in accordance with the requirements of the Data Processing Addendum for limiting access to Personal Data.
7.1.6. Compliance by Design: Banda Health warrants that the BandaGo Platform is and will continue to be designed and operated with data protection principles such as data minimization, privacy by design, and privacy by default at its core, in alignment with applicable Data Protection Laws.
7.1.7. Alignment with Data Protection Laws: Banda Health’s overall security program, including the measures detailed in this Section 5, is designed and implemented to comply with the requirements of the Kenya Data Protection Act, 2019, and other applicable data protection laws, particularly with regard to the protection of Personal Data.
7.1.8. Data Retention and Disposal Policies: Banda Health maintains and adheres to policies for the retention and secure disposal of Service Data and Personal Data. Service Data and Personal Data. will be securely disposed of when no longer necessary for the provision of the BandaGo Platform or upon the Client’s request, subject to legal and regulatory requirements.
7.1.9. Employee Training and Awareness: Banda Health commits to providing regular security training and awareness programs for all employees who have access to the BandaGo Platform, Service Data or Personal Data to ensure they understand their responsibilities regarding data security and protection.
7.1.10. Client’s Security Obligations: The Client acknowledges and agrees to be responsible for maintaining the security of its access credentials, implementing appropriate security measures on its end-user devices, and promptly reporting any suspected security incidents or unauthorized access to Banda Health. Further Client obligations are detailed in Section 8 (Client Obligations and Conduct).
7.1.11. Sub-Processor Security: Where Banda Health engages sub-processors in the provision of the BandaGo Platform that process Service Data and Personal Data, Banda Health shall ensure that such sub-processors are bound by written agreements that require them to maintain security measures no less protective than those set forth herein and in compliance with applicable Data Protection Laws.
7.1.12. Audit Rights: Upon reasonable written request and no more than once per year, Banda Health shall cooperate with Client’s reasonable requests for information to demonstrate compliance with this Security Section, which may include providing executive summaries of security audits or certifications. Any direct audit rights of the Client shall be limited to third-party audits arranged and overseen by Banda Health, at Client’s reasonable expense, to ensure the confidentiality and integrity of Banda Health’s systems and data.
7.2 Personal Data: Banda Health shall implement and maintain appropriate technical and organisational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures shall include, as appropriate:
In the event of a Personal Data Breach, Banda Health shall notify the Clinic without delay after becoming aware of the breach. Banda Health shall provide the Clinic with sufficient information to enable the Clinic to meet its obligations to report the Personal Data Breach to the Data Protection Commissioner and notify affected Data Subjects.”
The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.
This DPA shall commence on the date of the Agreement and shall continue until the Agreement is terminated by the client or by Banda Health. Upon termination, the Clinic may request the return of all Personal Data within 90 days. If requested within this period, Banda Health shall return all Personal Data to the Clinic in CSV format after the end of the provision of services relating to processing. At the 90-day mark following termination, all identified Personal Data will be deleted, and within the subsequent 90 days, identified Personal Data will be removed from all backup copies, unless and to the extent the law permits or requires its retention.
The Processor may retain data for research and analytics only if it has been irreversibly anonymized to a standard where individuals are no longer identifiable, at which point it ceases to be personal data.
This DPA shall be governed by and construed in accordance with the laws of the Republic of Kenya.
Sarah is a seasoned business leader who spent 14 years in tech—at a startup, Google, and most recently as a Vice President at Intuit, where she held senior leadership roles in Strategy, Business Operations, and Product. Born and raised in Kenya, and the daughter of a nurse who runs a clinic in rural eastern Kenya, Sarah is passionate about leveraging technology to improve access, efficiency, and equity in healthcare across Africa.
Paul starts your BandaGo journey, walks with you and makes sure you enjoy every step. Before joining Banda he worked as an adult educator. He holds a Bachelor’s degree in Computer Science.
His healthcare hero is Joseph, a retired ‘trained on the job’ medical personnel who used to circumcise boys at his rural home at Ithanga village, Masii Machakos county.
Kinya, our corporate storyteller, has lived and worked in Africa, Asia and North America. She’s met people from almost every part of the world and believes everybody has a story worth listening to.
Kinya’s personal healthcare hero is Dr. Shelley Machuta, a Radiation Oncologist in Alpharetta, GA.
Julie does whatever Steve asks her to do! In the early years before joining Banda Health, Julie put her passion for helping people through technology to use as an education-focused, data systems engineer. After spending a few years volunteering as an NGO Treasurer in Kenya, she returned to the USA and fine-tuned her passion to simply focus on adult learning.
Julie’s healthcare hero is the on-call ortho surgeon whose name she can’t remember, but whose skills saved her foot after a car accident.
Ian facilitates the growth of effective partnerships that address the pressing social concerns of the communities where Banda client clinics work. Before joining the Banda Health team, Ian practiced as a social justice and environmental lawyer in Australia.
Ian’s personal healthcare heroes are Dr Norval & Dorothy Christy, an ophthalmologist & nurse who spent 50 years restoring eyesight to vulnerable communities in Pakistan & China.
Developer
Analyst
Theano is a pediatrics nurse from Australia who brings energy and enthusiasm as our clinical impact coordinator. She’s been a lecturer, research coordinator and humanitarian and now works with Banda Health predominantly in Nairobi slums. She says “Africa is in her blood.” Her healthcare hero is Australia Obstetrician Dr Katherine Hamlin who worked in fistula repair in Ethiopia.
Nelly is our “concepts expert.” She ensures that all the necessary terms for our clinical modules are mapped and submitted to CIEL (concept dictionary). She’s a clinical epidemiologist with a master’s degree in epidemiology and disease control.
Nelly’s personal healthcare hero is Dr. Steve Letchford at Kijabe Hospital.
Margaret Gibson is the Director of Development at BLESS.world. She has spent the past 12 years helping build strategic, innovative, mission-minded organizations that impact the most complex problems of our day. Previously, she was Director of Operations at CrowdHealth, a healthcare technology startup. Her prior professional fundraising experience includes Living Water International, The Gospel Coalition, and The Source for Women.
Ann is a seasoned leader with 12+ years of experience in strategy, innovation, and operational excellence. She was the Senior Director of Strategy and Alignment for Global Impact at McDonald’s Corporation. Before that, she was a Director of Strategy & Innovation for Global Delivery, where she spearheaded new operating models and digital products. Ann began her career as a consultant at The Boston Consulting Group, advising clients on growth strategies and innovation.
Lawrence markets BandaGo in new areas and onboards clinics who are ready to get started. He joined Banda Health first as an Ambassador, gaining experience in surveying, IT and sales.
His personal healthcare hero is Dr. Steve Letchford at Kijabe Hospital.
Michael helps clinics get started with BandaGo. He joined Banda Health after gaining initial work experience in IT support and data management. He graduated from Jomo Kenyatta University of Agriculture and Technology with a bachelors in mathematics and computer science.
Michael’s personal healthcare hero is Dominic Ngalo, a data analyst at Kenyatta National Hospital in Nairobi.
Jeremy is our on-the-ground man, making sure the pilot sites have what they need to use our software. He previously worked as a systems analyst and team lead after getting his bachelors degree in computer science at Africa Nazarene University.
Jeremy’s personal healthcare hero is Isabella Muturi, a nurse at AIC Marira Clinic in Kenya.
David’s personal healthcare heroes are the doctors, nurses and physical therapists in his own family.
Steve is the visionary behind Banda Health. After two decades working as a doctor and hospital administrator in Africa, he has stories that will convince even the biggest skeptic of the impact that IT can have on African healthcare.
Steve’s personal healthcare hero is Irene Mundia, a licensed practical nurse at Mushima Rural Health Centre in Zambia.
Kevin is a passionate data enthusiast. He ensures that Banda Health can tell a story through their data. His vision is to serve as a gatekeeper for Banda’s data so that stakeholders can understand data and use it to make strategic business decisions. He has a bachelor’s degree in Computer Science from Strathmore University.
Kevin’s personal healthcare hero is all the doctors and nurses giving it their all during the pandemic.
Kevin is undoubtedly our most outgoing developer! Before joining Banda Health, he spent 5 years in software consulting, working as a developer and manager at Pariveda Solutions. He completed his bachelor’s in aerospace enginnering at the University of Texas.
Kevin’s personal healthcare hero is Kate B., a physical therapist at Evangel VVF Center in Jos, Nigeria.
Jessica keeps the team organized. Whether it’s filing tax forms or preparing board reports, she makes sure it gets done on time! Before joining Banda Health, Jessica used her organization skills at a soccer start-up in Germany. She graduated from Yale University with a bachelor’s in Ethics, Politics and Economics and completed her master’s in International Relations at the Free University of Berlin.
Jessica’s personal healthcare hero is Jairos Fumpa, a cataract surgeon at Mukinge Mission Hospital in Zambia.
Andrew makes sure the Nairobi team stays on track. He may seem quiet, but don’t underestimate his passion and expertise when it comes to health technology. He’s worked with leading businesses both in Kenya and internationally.
Andrew’s personal healthcare hero is Benedetta, a cashier at AIC Marira Clinic in Kenya.
Wes oversees all things technical. If you want a sneak peek at the roadmap, he’s your man! With 15 years of programming experience in the US private sector plus 5 years of technical consulting and team leadership, he definitely knows what he’s doing.
Wes’ personal healthcare heroes are the Christian medical missionaries working around the world.