Policies & Terms
iBam Health is committed to transparency, data privacy, and the highest standard of patient care.
Privacy Policy
Effective Date: 20 July 2026 · Version 1.01. Data Controller
iBam Health Technologies Ltd (“iBam”, “we”) is the Data Controller for personal data collected through our web platform, mobile application, and APIs. Our designated Data Protection Officer (DPO) can be reached at dpo@ibamhealth.com.
2. Data We Collect
2.1 Information You Provide
- Identity data: Full name, date of birth, gender, profile photo, National Identification Number (NIN).
- Contact data: Email address, phone number, delivery address.
- Health data: Medical history, symptoms, diagnoses, prescriptions, lab results, blood type, allergies, consultation notes and recordings (where consent is given).
- Financial data: Payment card details (tokenised via Paystack — we never store raw card numbers), bank verification number (BVN) for payouts to doctors.
- Professional data (doctors/partners): Medical licence number, licence document, CAC registration number, qualifications, professional bio.
2.2 Data Collected Automatically
- Usage data: Pages visited, features used, appointment history, session duration.
- Device data: Device type, operating system, IP address, browser type.
- Location data: Approximate location (city/state level) used to suggest nearby pharmacies and labs. Precise GPS is only used with your explicit consent.
- Cookies and analytics: See Section 9.
2.3 Data from Third Parties
- Dojah (KYC provider): NIN biographic data and face-match scores for identity verification.
- Paystack: Payment status and transaction references.
- Agora: Video/audio call metadata (call duration, participant counts). Agora does not retain call content after the session ends.
3. How We Use Your Data
| Purpose | Data Used | Legal Basis (NDPR) |
|---|---|---|
| Create and manage your account | Identity, contact | Contract |
| Facilitate consultations and bookings | Identity, health, contact | Contract / Vital interest |
| Process payments | Financial | Contract |
| Verify doctor and partner identity (KYC) | NIN, face biometric | Legal obligation / Legitimate interest |
| Dispense prescriptions and lab results | Health, identity | Vital interest / Consent |
| Send appointment reminders and notifications | Contact, booking data | Contract / Consent |
| Detect fraud and ensure platform security | Usage, device data | Legitimate interest |
| Comply with legal obligations (NDPR, NDLEA, MDCN) | All categories | Legal obligation |
| Aggregate anonymised health analytics | De-identified health data | Legitimate interest |
| Send marketing emails (opt-in only) | Email, usage | Consent |
We never use your health data to make automated decisions with legal or similarly significant effects without human review.
4. Data Sharing
We share your data only as described below:
4.1 Within the Platform
- Doctors see patient name, relevant health history shared by the patient, consultation notes, and prescriptions for the purpose of providing care.
- Partner pharmacies see prescription details, patient name, and delivery address when an order is placed.
4.2 Service Providers (Data Processors)
We engage the following processors under binding data processing agreements:
- Paystack — payment processing
- Dojah — identity/KYC verification
- Agora — video and audio call infrastructure
- Cloudinary — secure media storage (profile photos, documents)
- MongoDB Atlas — cloud database (hosted in Europe/US with Standard Contractual Clauses)
- Termii — SMS OTP delivery
4.3 Legal Disclosure
We may disclose your data when required by Nigerian law, a court order, or a regulatory authority (e.g., NITDA, NDLEA, NAFDAC, Nigerian Police Force) — and only to the extent strictly required. We will notify you of such disclosures where legally permitted.
4.4 Business Transfer
In the event of a merger, acquisition, or asset sale, your data may be transferred. We will provide notice and continue to honour your privacy rights.
We do not sell your personal data to advertisers, data brokers, insurance companies, or any other third party.
5. Health Data & Confidentiality
Health data is classified as sensitive personal data under the NDPR and NDPA and is afforded the highest level of protection. We process your health data only to provide you with healthcare services or where required by law. All health data is encrypted at rest (AES-256) and in transit (TLS 1.3+).
Consultation transcripts and medical notes are accessible only to the treating doctor and the patient. iBam Health administrators access health data solely for technical support, fraud prevention, or regulatory compliance, and only under strict access controls.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile data | Duration of account + 5 years after closure |
| Medical records and prescriptions | 10 years (National Health Act 2014 requirement) |
| Payment records | 7 years (FIRS / tax compliance) |
| KYC / NIN verification data | 5 years after verification |
| Consultation recordings (if consented) | 90 days, then auto-deleted |
| Server and security logs | 12 months |
| Marketing opt-in records | Until opt-out + 3 years |
7. Your Rights Under the NDPR & NDPA
As a data subject, you have the following rights. To exercise them, email dpo@ibamhealth.com with proof of identity. We will respond within 30 days.
- Right of access: Request a copy of all personal data we hold about you.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure: Request deletion of your data where we have no legal obligation to retain it (note: medical records are subject to mandatory retention periods).
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest, including direct marketing.
- Right to restrict processing: Request that we limit how we use your data during a dispute.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Right to lodge a complaint: File a complaint with NITDA at ndpr.nitda.gov.ng.
8. Security
We implement the following measures to protect your data:
- AES-256 encryption at rest for all stored data.
- TLS 1.3 encryption for all data in transit.
- Multi-factor authentication for administrative access.
- Role-based access controls — staff access only the data needed for their role.
- Regular penetration testing and vulnerability assessments.
- 24/7 intrusion detection monitoring.
- Incident response plan aligned with NDPR breach notification requirements (72-hour NITDA notification where required).
No system is perfectly secure. In the event of a data breach that poses a high risk to your rights, we will notify you directly within 72 hours of becoming aware.
9. Cookies
We use the following types of cookies:
| Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management | Session |
| Preference | Theme, language, UI settings | 12 months |
| Analytics | Anonymous usage statistics (no cross-site tracking) | 6 months |
We do not use advertising or tracking cookies. You can manage cookies through your browser settings. Disabling essential cookies will impair platform functionality.
10. Children’s Privacy
iBam Health does not knowingly collect personal data from children under 13. Users aged 13–17 must have parental/guardian consent. If you believe a child has created an account without consent, contact us immediately at dpo@ibamhealth.com.
11. International Data Transfers
Some of our processors (MongoDB Atlas, Cloudinary, Agora) store or process data outside Nigeria. We ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions recognised under Nigerian law, before any such transfer.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in law or our practices. Material changes will be communicated via email and in-app notification at least 14 days in advance. The current version is always available at ibamhealth.com/legal/privacy.
13. Contact
Data Protection Officer — iBam Health Technologies Ltd
Email: dpo@ibamhealth.com
Postal: Enugu, Nigeria
To exercise your NDPR rights or report a concern, use the above email with the subject line “Data Subject Request”.