Medlitics handles personal health data — one of the most sensitive categories of information. We take our legal obligations under Nigerian data protection law seriously and have built compliance into the foundation of our platform, not as an afterthought.
This page explains how we comply with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, and what this means for you as a user.
We process personal data only under explicit consent, contract performance, or legitimate interests — documented and auditable.
We collect only the data strictly necessary to deliver the Service. We do not harvest data speculatively.
All health data is encrypted at rest and in transit. No health data is ever stored in plaintext.
Users can access, correct, export, or delete their data at any time. We respond to requests within 30 days.
In the event of a breach, we notify the NDPC and affected users within 72 hours as required by law.
All third-party processors operate under formal DPAs. We are accountable for their handling of your data.
Health data is classified as a "special category" of personal data under Nigerian law, requiring a higher standard of protection. Specifically, we may only process your health data if:
At no stage do we process your health data for advertising, profiling for non-health purposes, or sale to third parties. These uses are prohibited by law and by our own internal policy.
Medlitics has appointed a Data Protection Officer (DPO) responsible for overseeing our compliance programme. Our DPO can be contacted at:
We store all primary health data within Nigeria or in jurisdictions with equivalent data protection standards. Where data is processed outside Nigeria (for example, by a cloud infrastructure provider), we ensure:
The NDPA 2023 gives you the following rights, all exercisable at no cost:
To exercise any right, email privacy@medlitics.com with "Data Rights Request" in the subject line.
If you are unsatisfied with our handling of your data, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):
We encourage you to contact us first at privacy@medlitics.com — most concerns can be resolved quickly and directly.
This compliance statement reflects our obligations under the Nigeria Data Protection Regulation (NDPR) 2019, the Nigeria Data Protection Act (NDPA) 2023, and related NDPC guidelines. We review and update our compliance posture at least annually.