Privacy Policy โ€” MediSeen HMS

Hospital Management System ยท app.mediseenhms.com

Effective: 2 March 2025   Version 1.0

1. Data Controller & Contact

CompanyMediSeen Health Systems Limited
RC Number9352905
TIN2620199413538
Data Protection OfficerKalu Ifeanyi Mba
Email[email protected]
3, Inyima Lane, Ebem, Abia State, Nigeria
Phone+234 816 516 0797

2. Scope

This Privacy Policy explains how MediSeen Health Systems Limited ("we", "us", "our") collects, processes, stores, and protects personal data through our hospital management system accessible at app.mediseenhms.com ("the Platform"). It applies to all users including patients, healthcare providers, hospital administrators, and staff.

3. Personal Data We Collect

3.1 Patient Data

CategoryExamplesLawful Basis
Identity DataFull name, date of birth, gender, photograph, national ID numberPerformance of contract; Legal obligation
Sensitive Health DataMedical history, diagnoses, prescriptions, lab results, treatment plans, allergies, vitalsExplicit consent (NDP Act s.30); Vital interests; Medical purposes (NDP Act s.31)
Contact DataPhone number, email, residential address, next-of-kin detailsPerformance of contract
Financial/Billing DataInvoice records, payment history, HMO details, insurance informationPerformance of contract; Legal obligation

3.2 Staff Data

CategoryExamplesLawful Basis
Employment DataName, role, qualifications, professional licence numbers, contact detailsPerformance of employment contract; Legal obligation
Access & Activity LogsLogin timestamps, actions performed, IP addressesLegitimate interest (security & audit)

3.3 Technical Data

Browser type, device information, IP address, cookies, and usage analytics collected automatically when you access the Platform.

4. How We Use Your Data

5. Sensitive Personal Data

Health data is classified as sensitive personal data under Section 30 of the Nigeria Data Protection Act 2023. We process health data only where:

6. Third-Party Processors & Cross-Border Transfers

ProcessorPurposeLocation
DigitalOcean, LLCCloud hosting & infrastructureLondon, United Kingdom (LON1)
Paystack Payments LimitedPayment processingNigeria / International
Flutterwave Technology Solutions LimitedPayment processingNigeria / International

Cross-border transfer: Your data is stored on DigitalOcean servers in London, UK. This constitutes a cross-border transfer from Nigeria. We ensure adequate safeguards pursuant to Section 43 of the NDP Act 2023, including:

7. Data Retention

Data TypeRetention PeriodBasis
Patient medical records10 years from last interactionMedical record-keeping standards; NDP Act
Financial & billing records7 yearsTax & financial regulations (FIRS)
Staff employment dataDuration of employment + 2 yearsEmployment law; legitimate interest
Technical logs12 monthsSecurity & operational necessity

After the retention period, data is securely deleted or irreversibly anonymised.

8. Your Rights as a Data Subject

Under the NDP Act 2023 and GDPR (where applicable), you have the right to:

To exercise any right, contact our DPO at [email protected]
3, Inyima Lane, Ebem, Abia State, Nigeria
. We will respond within 30 days.

9. Security Measures

10. Cookies

The Platform uses cookies for:

TypePurposeDuration
EssentialAuthentication, session management, securitySession / 24 hours
FunctionalUser preferences, language settingsUp to 12 months
AnalyticsAnonymised usage statistics to improve the PlatformUp to 12 months

We do not use advertising or tracking cookies. You may manage cookie preferences through your browser settings.

11. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

12. Complaints

If you are dissatisfied with how we handle your data:

  1. Contact us first: Email our DPO at [email protected]
    3, Inyima Lane, Ebem, Abia State, Nigeria
    or call +234 816 516 0797.
  2. Lodge a complaint with the NDPC:
    Nigeria Data Protection Commission
    Website: https://ndpc.gov.ng
    Email: [email protected]
  3. For EU/UK residents: You may also lodge a complaint with your local supervisory authority.

13. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via the Platform and/or email. The "Effective" date at the top indicates the latest revision. Continued use after changes constitutes acceptance.

14. Governing Law

This Privacy Policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, the NDPA 2019 Implementation Framework, and โ€” for international users โ€” the EU General Data Protection Regulation (GDPR) and UK GDPR where applicable.