NDPR (Nigeria Data Protection Regulation)

HealyNG is designed with Nigerian Data Protection Regulation in mind. We process personal data lawfully, fairly, and transparently. Key practices include:

  • Lawful basis for processing and consent where required
  • Data minimization — we collect only what is necessary
  • Purpose limitation — data is used only for stated purposes
  • Storage limitation — retention policies aligned with NDPR
  • Security measures — encryption, access controls, and monitoring
  • Data subject rights — access, rectification, erasure, and portability

Audit Logging

We maintain comprehensive audit trails for all access to health data. Track who accessed what, when, and from where for compliance and security reviews.

Technical Safeguards

  • End-to-end encryption for video consultations
  • Encryption at rest for stored data
  • Access controls and role-based permissions
  • Audit logging for all sensitive data access
  • Secure authentication and session management
  • WhatsApp Business access tokens encrypted at rest; never returned in API responses

WhatsApp Care

Clinics may connect their own WhatsApp Business number for WhatsApp Care (included on every package while appointment credits remain). Patients message the clinic, not a shared Healy care line. The clinic is the controller of clinical care; HealyNG processes routing, sessions, and encrypted tokens; Meta provides the WhatsApp Cloud API. Payment cards are taken only on Paystack or Flutterwave checkout links. Patients can reply STOP to opt out. Message logs are retained up to 24 months. Request a data processing agreement at hi@healy.ng.

Your Responsibilities

As a clinic or provider using HealyNG, you remain responsible for your clinical practice, patient consent, and compliance with local medical regulations. We provide the technology; you maintain the care standards. Contact us for compliance-specific questions or to request a data processing agreement.