Pisgah Health — Privacy Policy

Effective 1 June 2026 — Version 1.0

1. About This Policy

This Privacy Policy explains how Pisgah Health Technologies Limited (“Pisgah”, “we”, “us”) collects, uses, stores, and protects personal data when it operates the Pisgah clinical record management platform (“Platform”).

Pisgah operates as a Data Processor — we process patient health information on behalf of the hospitals and clinics that subscribe to the Platform (the Data Controllers). This means your primary data protection relationship is with your hospital or clinic, not with Pisgah. However, we are required by the Nigeria Data Protection Act 2023 (“NDPA”) to be transparent about how we handle data, and this Policy fulfils that obligation.

This Policy applies to: (a) patients whose data is recorded on the Platform; (b) hospital subscribers and their authorised staff; and (c) visitors to Pisgah’s public web properties.

2. Who We Are — Contact Details

  • Company:[PLACEHOLDER: full registered name] (RC [PLACEHOLDER: number])
  • Registered address:[PLACEHOLDER: street address, city, state, Nigeria]
  • Email:legal@pisgahhealth.ng
  • Data Protection Officer:[PLACEHOLDER: DPO full name], dpo@pisgahhealth.ng
  • NDPC registration:[PLACEHOLDER: NDPC data controller registration number, if issued]

3. The Data Controller — Your Hospital

For the purposes of the NDPA, the hospital or clinic that enrolled you on the Pisgah Platform is the Data Controller for your personal and health information. Pisgah processes that information only on the hospital’s instructions and under the terms of a Data Processing Agreement (“DPA”) that each hospital must sign before going live.

If you have questions about why a specific piece of your health information was recorded, or wish to exercise rights such as access or rectification of clinical records, your primary contact is your treating hospital. Pisgah will assist hospitals in responding to data subject requests that involve technical access to the Platform.

4. Personal Data We Collect

The data collected depends on the features the subscribing hospital has enabled and the care pathway you are on. The categories below represent the full scope of data the Platform is capable of processing:

  • Identity data: full name, date of birth, sex, national identification number (NIN), Pisgah patient identifier.
  • Contact data: phone number (encrypted at rest), state, local government area.
  • Guardian / next-of-kin data: name, phone number, relationship — collected where required for minor patients or as emergency contact.
  • Clinical data: presenting complaint, vital signs, diagnoses (ICD-10 coded), prescriptions, laboratory orders and results, imaging requests, procedure notes, SOAP consultation records.
  • Admission data: ward, bed, admission and discharge dates, inpatient clinical observations, maternity and delivery records (where applicable), cause-of-death records (where applicable).
  • Billing and payment data: invoice amounts, payment receipts, billing category — used for administrative record-keeping, not for commercial profiling.
  • Platform usage data: login timestamps, pages visited, actions taken — used for audit trails and security monitoring.
  • Consent records: timestamp, version of terms accepted, and the patient session associated with acceptance.

5. How and Why We Process Your Data

The table below summarises the purposes for which data is processed, the lawful basis relied upon under the NDPA, and the relevant statutory reference.

Category of processingLawful basisNDPA reference
Providing clinical record management to the subscribing hospitalPerformance of contract (Data Processing Agreement between Pisgah and the hospital)§25(1)(b)
Recording patient registrations, consultations, diagnoses, and prescriptionsNecessary for the performance of a task in the public interest (healthcare provision)§25(1)(e)
Processing special-category health dataNecessary for medical diagnosis, provision of health care or treatment, or management of health services — by or under the responsibility of a health professional§30(2)(c)
Research study participation (pilot phase only)Explicit consent of the data subject; ethics committee approval (PACTR202605486348375)§25(1)(a); §30(2)(a)
Sending appointment and result notifications by SMS / WhatsAppLegitimate interest (patient welfare); explicit consent for WhatsApp channel§25(1)(f)
Generating de-identified population health analytics for platform improvementLegitimate interest (after irreversible de-identification, NDPA ceases to apply to the output)§29(1); recital to §2
Maintaining security audit logs and fraud preventionLegitimate interest (platform integrity; protection of patient data)§25(1)(f)
Compliance with regulatory reporting obligations (NHMIS, IDSR)Legal obligation§25(1)(c)

6. Special Category (Sensitive) Health Data

Clinical records — diagnoses, treatment histories, lab results, maternity records — constitute special category data under NDPA Section 30. Processing of special category data on the Platform is carried out:

  • By or under the responsibility of a health professional who is subject to a duty of professional confidentiality (NDPA §30(2)(c)).
  • With the explicit consent of the data subject, where required (for research participation or cross-facility data sharing via referral — NDPA §30(2)(a)).

Special category data is stored encrypted at rest. Access is restricted to Authorised Users of the Subscriber whose role permissions explicitly include the relevant data type. Pisgah staff do not access individual patient clinical records except as necessary to provide technical support, under strict access controls and with full audit logging.

7. Sharing of Personal Data

Pisgah does not sell, rent, or trade personal data. We share data only in the following circumstances:

  • Within the Pisgah network: Patient data may be shared with another Pisgah-connected facility (e.g., a receiving lab or referral hospital) only where the patient has given explicit referral consent and the Subscriber has authorised the transfer.
  • Regulatory disclosures: Aggregate, de-identified data may be submitted to NHMIS, NCDC (IDSR), and other regulatory bodies as required by Nigerian law. Individual identifiable records may be disclosed to public health authorities where required by statute.
  • Legal compulsion: We may disclose data in response to a valid court order or government demand, to the minimum extent required and with notice to the Subscriber where legally permitted.
  • Sub-processors: See the table below.

Sub-processors

Sub-processorPurposeLocationTransfer safeguard
Neon Technology Inc.PostgreSQL database hosting (primary data store)United StatesStandard Contractual Clauses (SCCs) under NDPA §42
Cloudflare Inc.Edge compute, CDN, DDoS protectionGlobal (nearest PoP); data processed in EU/USSCCs; Cloudflare Data Processing Addendum
Anthropic PBCAI-assisted clinical summarisation (where enabled)United StatesSCCs; Anthropic Data Processing Agreement — de-identified inputs only
TermiiOutbound patient notificationsNigeria; WhatsApp messages may route through Meta infrastructureNDPA-aligned processor terms; WhatsApp BSP channel and SMS fallback

The full and current list of sub-processors is maintained at pisgahhealth.ng/legal/sub-processors. Subscribers will receive 14 days’ advance notice of any new sub-processor addition.

8. Data Retention

Pisgah retains Patient Data for the periods required by Nigerian law and good clinical practice. Hospitals, as Data Controllers, are responsible for implementing their own retention policies consistent with these minimum periods.

Data categoryRetention periodLegal basis
Adult patient clinical recordsMinimum 6 years from last clinical contactNHA 2014 §25; MDCN guidelines
Minor patient clinical recordsUntil age 25, or 6 years from last contact (whichever is later)Child Rights Act 2003; NHA 2014 §25
Maternity recordsMinimum 25 years from deliveryNHA 2014 §25; obstetric practice standards
Deceased patient recordsMinimum 6 years from date of deathNHA 2014 §25; Limitation Act
Billing and financial records6 years from transactionCAMA; FIRS requirements
Authorised User account recordsDuration of role + 6 yearsNHA 2014 §29 audit obligations
Platform usage logs12 months (rolling)Legitimate interest
Support communications3 years from ticket closureLegitimate interest

Following termination of a hospital’s subscription, Pisgah will retain data for the above periods (or until the hospital confirms it has taken a complete export, whichever is later), then securely delete it. See Section 9 of the Terms of Service for the specific export and deletion timeline.

9. Cross-Border Data Transfers

The Platform’s primary database is hosted by Neon Technology Inc. on infrastructure located in the United States. This constitutes a transfer of personal data outside Nigeria within the meaning of NDPA Section 42.

We rely on Standard Contractual Clauses (SCCs) as the lawful transfer mechanism. The SCCs are incorporated into our Data Processing Agreement with Neon. A copy of the relevant transfer mechanism documentation is available on request from dpo@pisgahhealth.ng.

In addition, Pisgah applies the following safeguards regardless of where data is stored:

  • Encryption in transit (TLS 1.3 minimum) and at rest (AES-256).
  • Sensitive fields (phone numbers, national ID hashes) encrypted at the application layer before writing to the database, so the hosting provider cannot read them in plaintext.
  • Row-level access controls enforced at the application layer, scoped to the subscribing hospital’s tenant.

NDPA Section 42 requires that Pisgah disclose this transfer to data subjects. This section fulfils that obligation.

10. Your Rights as a Data Subject

The NDPA grants data subjects the following rights. Where Pisgah is the Data Processor, it will assist your hospital (the Data Controller) in responding to these requests. You may also contact Pisgah directly at dpo@pisgahhealth.ng and we will route your request to the appropriate Data Controller.

RightNDPA sectionHow to exercise
Right to be informed§34(1)(a)This Privacy Policy
Right of access§34(1)(b)Contact your hospital or dpo@pisgahhealth.ng
Right to rectification§34(1)(c)Contact your treating clinician
Right to erasure§34(1)(d); §36Contact dpo@pisgahhealth.ng — subject to NHA §25 retention obligations
Right to restrict processing§34(1)(v)Contact dpo@pisgahhealth.ng
Right to data portability§38Contact dpo@pisgahhealth.ng
Right to object§36(3)Contact dpo@pisgahhealth.ng
Right against automated decisions§37Contact dpo@pisgahhealth.ng
Right to withdraw consent§35Contact your hospital

We will respond to rights requests within 30 days of receipt (or 60 days where the request is complex, with written notice of the extension). We will not charge a fee for rights requests unless they are manifestly unfounded or repetitive.

11. Data Security

Pisgah implements technical and organisational measures proportionate to the sensitivity of the data processed. These include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256 at the database layer; additional application-layer encryption for sensitive identifiers).
  • Role-based access controls: each Authorised User can access only the data their role permits; access is scoped to the subscribing hospital’s tenant.
  • Immutable audit logging: all access to Patient Data is logged with a timestamp, user identity, and action type. Audit logs cannot be modified or deleted.
  • Multi-factor authentication for administrative and super-admin accounts.
  • Regular security reviews and penetration testing by independent security professionals.
  • Dependency vulnerability scanning as part of the continuous integration pipeline.

No security measure is perfect. Subscribers are responsible for ensuring that their Authorised Users follow secure practices (protecting credentials, using secure networks, reporting suspicious activity promptly).

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Pisgah will:

  • Notify the affected Subscriber without undue delay, and in any event within 72 hours of becoming aware of the breach, as required by NDPA Section 40.
  • Provide details of the nature of the breach, the approximate number of data subjects affected, the likely consequences, and the measures taken to address it.
  • Assist the Subscriber (as Data Controller) in notifying the Nigeria Data Protection Commission (“NDPC”) and, where required, the affected data subjects.

The Subscriber, as Data Controller, is responsible for determining whether the breach meets the threshold for notification to the NDPC and to individual data subjects.

13. Minor Patients

Where a patient is under 18 years of age, consent to process their personal and health data is obtained from a parent or legal guardian, in accordance with the Child Rights Act 2003 and NDPA Section 31.

Clinical records for minor patients are retained until the patient reaches 25 years of age, or for 6 years from last clinical contact, whichever is later (see Section 8). This extended period reflects the obligation under Nigerian law to preserve records that may be relevant to the patient’s own healthcare and legal rights on reaching adulthood.

The Platform applies a minor flag to patient records and enforces guardian linkage at the point of registration, so that clinicians are alerted to the patient’s age and the applicable consent posture.

14. Cookies and Tracking

The Platform uses session cookies to maintain authenticated provider and patient sessions. These are strictly necessary cookies and cannot be disabled without preventing login from functioning.

We do not use third-party advertising cookies, cross-site tracking pixels, or behavioural analytics tools on the clinical Platform.

The Pisgah public marketing website (pisgahhealth.ng) may use analytics cookies. A separate cookie notice applies to that site.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will publish the updated policy at pisgahhealth.ng/legal/privacy and notify subscribing hospitals by email at least 30 days before the change takes effect.

The version number and effective date at the top of this page allow you to identify which version of the Policy applied at any given time. Hospitals should retain records of the version in force at each patient enrolment date.

16. How to Contact Us and Lodge Complaints

For questions about this Policy, or to exercise a data subject right, contact our Data Protection Officer:

  • Email: dpo@pisgahhealth.ng
  • Post: [PLACEHOLDER: registered address]

If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):

We encourage you to contact us directly first so we have an opportunity to address your concern.

Pisgah Health Technologies Limited — [PLACEHOLDER: RC number] — [PLACEHOLDER: registered address] — Lagos, Nigeria

Data Protection Officer: dpo@pisgahhealth.ng