Privacy Policy

Version date: 18th October, 2023

This privacy policy applies to Medbury Medical Services (https://www.medburymedicals.com/) mobile application – Medbury Medical Services owned and operated by Medbury Medical Services Limited. This policy aptly describes how Medbury Medical Services (“we,” “us”) collects personal information from you, your rights to your personal information and your choices regarding how your personal information should be used by us when you sign up for our services.

Please take some minutes to read our privacy policy as this would enlighten you on the type of personal information, we collect from you. It will also help you understand how we use and share your personal information which you provided to us through our mobile application. Your use of our mobile application signifies your acceptance of this privacy policy and our use of your personal information as described in the policy.
We might review and make changes to this privacy policy from time to time, so we strongly recommend that you regularly check this policy.

Your personal data: How we collect it
When you register for our services, we collect certain types of information from you. As a User, our services cannot be made available to you if you do not avail us with certain types of information. The following are the types of information you provide to us and we collect from you:

First and Last name

While using our services, we will ask you for your first name and last name to set up your account and enable us to identify you.

Phone Number
While using our Services, we will ask you for your phone number to set up your account.
Email address
We would ask you for your email address when you register for our services to set up your account, this will enable us to send you a verification pin before you can use our services.

Geolocation

The app would request for location access from the user for better accuracy of their location when there is an emergency request for efficient and prompt medical services

Nationality, Date of Birth, Address and Passport number

Due to the nature of the services (medical services) we provide, we would also collect your Nationality, Address, Date of Birth, and Sex when you edit your profile, this information would enable us to provide efficient medical services to you.

Shipping Address

While purchasing our products and services, we would require you to select or add your shipping address to get the products delivered to you.

Photo/Image
You may deliberately provide us with your photo or image as your profile picture when you register for our services for identification purposes only.

Biometric information

We would require and collect the biometric information on your passport for identification purposes.

User communications and Email address

When you chat with us via email, we collect your full name and email address and when you chat with us via WhatsApp, we collect your phone number. We may retain your chats to process your inquiries, respond to your requests and improve our services.
Information we automatically collect
We use technology to collect information about your behaviour on our App and about your mobile device.
When you sign in, some data are collected automatically from your mobile devices such as unique identifiers associated with your device and other data such as your network location. This data is used to analyse and improve services to you. We automatically use your device storage to write files to enable us save your test result certificate on your device when you request to download your test results. However, we do not download or access and process the images or videos or other personal information on your device storage.

WE DO NOT COLLECT THE FOLLOWING TYPES OF PERSONAL DATA:
Credit card information: We do not collect your credit card information although our payment service provider collects and processes this information when you purchase our products and services for the sole purpose of deducting payments which you have authorised it to deduct.

Personal information from third parties: We do not collect your personal information from third party sources. All your personal information is collected directly from you.
Personal data: How we use it
● To provide our medical services such as Emergency response, Telemedicine, book appointments, provide test results and provide corporate health services to you;
● To develop and enhance our App through research to provide excellent services to you;
● To adhere to the provisions of the law;
● For the development of enhanced products and services and to advise you about new products and services.
● To safeguard us including our employees and third-party affiliates who we transact with.
● To promptly respond to your complaints, requests and inquiries.
● To improve user experience.
● To inform you and communicate your test results to you.
Sharing your personal information
We have “zero-tolerance” policy on sharing your personal information. We do not divulge or transfer your personal information to third parties for a fee. However, there are certain instances where we transfer or disclose your personal information:
● We might disclose and transfer your personal information to an acquiring entity. (This will only happen when our business is acquired by another entity such as during a merger and acquisition process.) In such an event the acquiring entity shall be bound by the provisions of this privacy policy.
● We disclose and sometimes transfer your personal information to third parties who are affiliated with us or our service providers who provide billing services and email services to us. However, we do not share your sensitive personal data with such third parties.
● In response to legal proceedings or regulatory authorities – to comply with the law, a judicial proceeding, subpoena, court order, or other legal process. In this instance, in compliance with the relevant authority we might be compelled to share your sensitive personal data.
In the event that we share your personal data, applicable safeguards will be put in place and your personal data sharing to third parties will be done in accordance with data protection laws.

Data Security

The security of your personal information is of utmost importance to us, so we do not share (except in instances mentioned above), borrow, sell or even rent your personal information as part of our security measures all WhatsApp messages including pictures and videos are end to end encrypted. All phone numbers are stored on the server for functionality purpose only. In other words, the Medbury Medical App has been developed with industry standard and advanced technology for end-to-end encryption. Consequently, all messages shared on Medbury Medical can only be viewed at the sender and at the receiver’s end. Other personal information provided to us such as images/photos and videos are not stored or saved on the App and are solely on your mobile device.

Links to third party sites

Our Service does not contain links to other sites that are not operated by us except for our payment service provider. Once you click on “Pay with card” you will immediately leave our App to our payment service provider (Flutterwave)’s site. Kindly read the Privacy policy of our payment service provider which binds the use of your personal information as it pertains to payment made with card.

Legal Basis for Collecting and Using Information

In certain instances, we may have a legal basis for collecting and using your information, these instances are:
a) The use is obligatory in order to fulfill our obligations to you under our Terms and Conditions or
b) The use is in accordance with a legal duty; or
c) The use is obligatory to safeguard your pertinent interests or interests of others; or
d) We have an honest interest in using your information–for instance to provide enhanced services to you.
e) You have given us your consent to use your information to provide our services to you.

Personal Data Retention

We retain your personal data for as long as it is needed and in accordance with the Nigerian Data Protection Regulation (NDPR) and other applicable data protection laws.

Data Storage

To secure your personal information, we use advanced technology such as my SQL database to restrict the number of people in our organisation with access to your personal information. Your personal information is only accessed on “a need-to-know basis” that is why we set up roles and permission to ensure your personal data is secure. We also use an encryption layer to segregate data to avoid your personal information being mixed up.
While registering for our services you have chosen a password which gives you to access to the App, you are solely responsible for keeping your password private. In the unlikely event that there is a security breach because the internet is not 100% safe, we shall promptly inform you and take out necessary security measures and steps to investigate the breach while we shall report same to the relevant authorities.

Compliance
Our data policy is in compliance with the Nigeria Data Protection Regulation (NDPR) and other relevant data protection laws in force.

Data Rights
1. You have the right to request for your data.
2. You have the right to be forgotten by requesting that we should erase your data. In cases where we have shared your data with third parties, we shall inform them about the erasure of your data, except it is not possible to do so.
3. You have the right to correct your data, if it is incorrect. If we have shared the data with anyone else, we will inform them about the correction wherever possible. Where it is impossible to comply with your request to alter your data, we shall inform you accordingly with reasons on why we could not alter your data.
4. You have the right to data portability i.e the ability for your personal data to be transferred easily from one IT system or computer to another through a safe and secure means in a standard format.
5. You have the right to ask us to restrict the processing of your personal data by opting out of our marketing emails or newsletters.
6. You have the right to withdraw consent at any time without affecting the lawfulness of processing your data based on consent before its withdrawal.

Where it is impossible to process your request, we shall promptly inform you or we shall inform you within one month of receipt of your request with reasons on why we could not process your request. Your requests as it pertains to your rights shall be carried out without charge to you except where it is excessive and unfounded, then we shall charge a reasonable fee for administrative costs of providing the information or communicating or taking the requested action or we shall write a letter to you stating our refusal to act on your request and we shall copy the Agency on such occasion.

Children’s Privacy
We do not intentionally collect personally identifiable information from children without their Parent’s or Guardian’s permission. Please contact us, if you are a parent or guardian and you are aware that your child has provided us with their personal information. We shall immediately delete the personal data of the child once we are aware of such information.

Contact Us
All questions concerning this privacy policy, requests for personal data or the enforcement of any personal data rights should be sent to info@medlinkr.com