NDPA 2023 · NDPR 2019 · National Health Act 2014

Privacy Notice

How ProxiHealth collects, processes, stores, and protects personal and health data in accordance with Nigerian law.

Last updated: 1 July 2026

1. Data Controller

The data controller for all personal data processed through the ProxiHealth platform is Symbiosis Health Technologies Ltd. Where a clinic or hospital deploys ProxiHealth for its patients, that institution acts as a joint controller in respect of its own patients' records and must maintain its own patient consent records under the National Health Act 2014.

For all privacy inquiries, data subject requests, or data processing agreements, contact us at: privacy@proxihealth.com.

2. Legal Basis for Processing

ProxiHealth processes personal data on the following lawful bases under the Nigeria Data Protection Act 2023 (NDPA) and the NDPR 2019:

  • Consent — patients provide explicit, informed consent before any family member or third party is granted access to their records.
  • Legitimate interest — processing necessary to deliver the EMR platform, detect security breaches, and maintain audit logs.
  • Legal obligation — retention of medical records for the minimum statutory period under Nigerian medical law and reporting to the NDPC in the event of a notifiable breach.
  • Vital interests — in emergency clinical scenarios where processing is necessary to protect the life of the data subject.

3. Categories of Data Collected

ProxiHealth collects only the minimum data necessary for its clinical and administrative functions (data minimisation principle, NDPA 2023 Section 25):

CategoryExamples
Identity dataFull name, date of birth, gender, preferred language
Contact dataEmail address, phone number, postal address
Health data (special category)Diagnoses, prescriptions, test results, immunisation records, vital signs, doctor's notes, referrals
Insurance dataPolicy number, insurer name, plan name, expiry date, NHIA eligibility status
Account dataAccount type, role, verification status, last active date
Access log dataRecord of every view, create, update, or delete action with actor identity, timestamp, and IP address
Device dataBrowser type, operating system — used for security audit logs only

We do not collect data for advertising purposes. We do not sell, rent, or share personal data with third-party advertisers.

4. Data Storage and Security

  • Encryption in transit: All data is transmitted over TLS 1.3. No health record is sent in plain text.
  • Encryption at rest: All data at rest is encrypted using AES-256.
  • Access control: Role-based access control (RBAC) ensures that doctors, nurses, clinic admins, patients, family members, and pharmacies can only access data within their defined scope.
  • Audit logging: Every record access, creation, update, and deletion is logged with actor identity, timestamp, and IP address. Audit logs are immutable by regular users.
  • Automated security scans: The platform runs scheduled security scans to detect anomalous access patterns, stale credentials, and policy violations.
  • Re-verification: User accounts inactive for 90 or more days are flagged and require re-verification before accessing records.

5. Access Grants and Third-Party Access

No third party (including diaspora family members) can access a patient's records without an explicit, signed invite from the clinic or the patient. Access grants are:

  • Time-limited: they expire automatically after 365 days.
  • Revocable: the clinic or patient can revoke access at any time with immediate effect.
  • Scoped: family members receive view-only access. They cannot create, edit, or delete any record.
  • Logged: every family member access event is recorded in the audit log.

6. Data Retention

Patient health records are retained for the minimum period required under Nigerian medical law. Account data is retained for the duration of the account's active life plus a statutory cooling-off period.

Where a data subject exercises their right to erasure (NDPA 2023 Section 34), ProxiHealth will delete or anonymise personal data within 30 days, except where retention is required by law (for example, statutory medical record retention obligations).

7. Data Subject Rights

Under NDPA 2023, data subjects have the following rights, exercisable by contacting privacy@proxihealth.com:

  • Right to access — request a copy of personal data held about you.
  • Right to rectification — request correction of inaccurate personal data.
  • Right to erasure — request deletion of your personal data (subject to legal retention requirements).
  • Right to restrict processing — request that processing be limited in certain circumstances.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.
  • Right to withdraw consent — withdraw consent for processing at any time without affecting the lawfulness of prior processing.

We will respond to all verifiable data subject requests within 30 days.

8. Breach Notification

In the event of a personal data breach, ProxiHealth will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, where feasible, in accordance with NDPA 2023. Affected data subjects will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

9. International Data Transfers

ProxiHealth is hosted on cloud infrastructure operated by Base44. Data may be processed on servers outside Nigeria. Where personal data is transferred internationally, we ensure appropriate safeguards are in place in accordance with NDPA 2023, including adequacy decisions, standard contractual clauses, or equivalent protections.

10. Cookies and Tracking

ProxiHealth uses only session cookies required for authentication and security. We do not use third-party advertising cookies or behavioural tracking technologies.

11. Regulatory Authority

ProxiHealth's data protection practices are regulated by the Nigeria Data Protection Commission (NDPC). Data subjects who believe their rights have been violated may lodge a complaint directly with the NDPC at: ndpc.gov.ng.

This notice is also aligned with the Nigeria Data Protection Regulation 2019 (NDPR), issued by NITDA, and the National Health Act 2014.

12. Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to registered users by email.

Need a Data Processing Agreement?

Hospital groups, HMOs, and institutional buyers can request a signed Data Processing Agreement (DPA) for procurement and legal review. Contact our compliance team directly.

Request a DPA