Legal
Privacy Policy
Last updated 23 July 2026
This is a working version published ahead of launch and is being reviewed with legal counsel. It reflects how Medlitics is designed to handle data; the final, binding version will be posted here.
Medlitics (“Medlitics”, “we”, “us”) provides a platform for chronic disease management that connects patients, practitioners, hospitals and insurers. This policy explains what personal and health data we handle, why, and the rights you have over it. We handle personal data under the data-protection law that applies where you are — including Nigeria's Data Protection Act (NDPA) and equivalent regimes in other markets.
Data we collect
Depending on how you use Medlitics, we may handle:
- Account data — name, email, phone number, and the role you hold (patient, practitioner, organisation or insurer).
- Health data — vital readings, conditions, medications, consultations, prescriptions and adherence, for patients using the platform.
- Device data — readings synced from wearables and medical devices you choose to connect.
- Professional data — credentials and licensing, for practitioners undergoing verification.
- Usage and technical data — logs needed to operate, secure and audit the service.
How we use data
We use data to:
- Provide monitoring, alerts, consultations, prescriptions and claims.
- Route an alert to a patient and their assigned practitioner.
- Verify practitioners before they can access any patient record.
- Generate reports and, in anonymised and aggregated form, population insight.
- Secure the service, prevent abuse and meet legal obligations.
We do not sell your personal data. Meddy, our AI assistant, uses your data only to explain your own trends; it does not diagnose or prescribe.
Consent
Where the law requires it, we ask for your consent before processing health data, and you can review and withdraw that consent from your settings. Withdrawing consent may limit features that depend on the data in question.
How we share data
Health data is shared only with a purpose and a relationship:
- With the practitioners on your care team, to deliver care.
- With a hospital or clinic that has enrolled you, where applicable.
- With an insurer, when you submit a claim or buy a policy — with the data attached to that specific transaction.
- With processors who help us run the service (for example payment and communications providers) under contract.
Security
Data is protected in transit with standard encryption, access is scoped by role and relationship, and sensitive actions are logged and auditable. Readings captured offline are queued on your device and synced without loss. See our security & compliance page for detail.
Your rights
Subject to applicable law, you may request access to your data, ask us to correct or delete it, object to certain processing, and receive a copy of it. To exercise a right, contact us at privacy@medlitics.com.
Retention
We keep data for as long as needed to provide the service and to meet legal, clinical and accounting obligations, after which it is deleted or anonymised.
Contact
Questions about this policy or your data can be sent to privacy@medlitics.com.