Full legal review in progress
This policy accurately describes how MediBY currently handles your data. A DPCO-accredited firm is conducting a formal NDPA compliance audit. Questions? Contact our Data Protection Officer at medibytechnologies@gmail.com.
Your rights at a glance
Download your data
Settings → Export
Correct your data
Profile settings
Delete your account
Settings → Delete
Withdraw consent
Settings → Privacy
Portable data export
JSON format
Lodge a complaint
ndpc.gov.ng
MediBY is the data controller responsible for your personal data. We are a health technology company registered in Nigeria under the Corporate Affairs Commission (CAC). Our Data Protection Officer can be contacted at medibytechnologies@gmail.com. We process your data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR).
Tier 1 — Health data (most sensitive, AES-256-GCM encrypted)
Symptoms you describe to the AI doctor, AI triage results and recommendations, your consultation notes from doctors, voice transcripts generated during consultations, post-consultation medical reports (PDF), pre-call notes you submit before an appointment, and secure messages exchanged with your doctor after a consultation. This data is encrypted at rest. Access is strictly controlled — see Section 5 for exactly who can access what.
Tier 2 — Identity data
Your name, email address, phone number, and MediBY ID (MBY-XXXXXXXX). Used to create your account, identify you to hospitals you book with, and send appointment reminders and medical reports.
Appointment and payment data
Hospitals visited, doctors consulted, appointment dates and times, consultation type (video, phone, or in-person), and Paystack payment references. We never store your card number — Paystack handles that securely.
Technical data
IP address, browser type, operating system, and pages visited. Used for platform security, fraud prevention, and rate limiting. Stored in our immutable audit log.
Explicit consent (NDPA Article 2.1(a))
We ask for your explicit consent before collecting any health data. You gave this consent during sign-up. You can withdraw it at any time from your account settings — withdrawal does not affect the lawfulness of processing before withdrawal.
Contractual necessity
Processing your identity and appointment data is necessary to fulfil the consultation booking contract between you and the doctors or hospitals on our platform.
Healthcare provision — AI triage and doctor access
When you use our AI Doctor to describe your symptoms and subsequently book an appointment with a real doctor, we share the AI triage summary from that specific session with your booked doctor. This sharing is necessary to provide continuity of care — it is the digital equivalent of a referral note. This is covered by your initial consent and the healthcare provision lawful basis. See Section 5b for the precise details of what is shared and what is not.
Legitimate interests
We process technical data (IP addresses, audit logs) to protect the platform from fraud, unauthorised access, and abuse. This is proportionate and does not override your privacy rights.
Health records and consultation notes
7 years — required by Nigerian health records regulations.
Post-consultation medical reports (PDF)
7 years in encrypted storage. The download link in your email is valid for 30 days, but the report itself is retained for 7 years in line with health records law.
Post-appointment message threads
7 days after the consultation is completed. Messages expire automatically. After expiry they are read-only and eventually purged.
Pre-call patient notes
Retained with the appointment record for 7 years.
AI triage sessions
7 years. Linked to your appointment record.
Account data
Until you request deletion of your account.
Payment records
6 years — required by FIRS tax regulations.
Audit logs
5 years — required for NDPA accountability compliance. These logs are immutable and cannot be deleted even on account deletion request.
Consent records
Permanently — we must be able to prove consent was obtained.
Your booked doctor — appointment data only
When you book a consultation, your assigned doctor sees: your name, the date and time of your appointment, and your consultation type (video, phone, or in-person). They do not see your full health history, your AI triage history, your other appointments, or data from other doctors.
Your booked doctor — AI triage summary (if applicable)
If you used our AI Doctor before booking your appointment and that specific session is linked to your booking, your doctor can view the AI triage summary for that session only. This includes: your reported chief complaint, symptoms, duration, severity rating, and the AI's recommendations. Your doctor cannot see any other AI sessions you have had. If you did not use the AI Doctor before booking, no AI data is shared.
Your booked doctor — pre-call notes
If you submit a pre-call note or attach files (images, PDFs) before your appointment, your assigned doctor sees them when they open your appointment. These are visible only to the doctor assigned to that specific appointment.
Your booked doctor — consultation note and SOAP record
After your consultation, the doctor writes a clinical note and SOAP record. This is stored in your permanent medical record. You can view it on your appointment detail page.
Hospitals (sub-admins)
Hospital staff (sub-admins) can see appointment status, booking details, and patient email for appointments at their hospital. They cannot see your health data, AI triage summaries, doctor notes, or messages.
Paystack
Payment processing. Paystack receives your email and payment amount. They do not receive your health data. Paystack is PCI-DSS certified.
Twilio
Video call infrastructure. Twilio facilitates the video connection. MediBY does not record video calls. Audio recorded for AI SOAP note generation is processed immediately by Groq Whisper and discarded — it is never stored by MediBY or Twilio.
Groq (AI processing)
Groq processes the text of your AI Doctor conversations and, when you opt in to audio recording during a consultation, the audio transcript. Groq does not retain this data after processing. Their privacy policy is available at groq.com.
WHO ICD-11 API (World Health Organization)
When you describe your symptoms to the AI Doctor, the text of your symptom description is sent directly to the World Health Organization's ICD-11 diagnostic classification service, to help ground the AI's response in recognised diagnostic categories. The WHO does not receive your name, contact details, or any other identifying information — only the symptom text itself.
AWS S3
Encrypted file storage for post-consultation medical reports, pre-call note attachments, and secure message files. Files are stored in a private S3 bucket in the EU West region. Access requires a time-limited signed URL.
Resend
Email delivery. Resend receives your email address and the content of appointment confirmation, cancellation, and medical report emails.
Clerk
Authentication. Clerk manages your login credentials and session. They do not have access to your health data.
Africa's Talking
SMS reminders. They receive your phone number and appointment reminder text.
Upstash
Rate limiting and AI response caching. Upstash stores anonymised request identifiers (hashed IP addresses) and cached AI responses temporarily. No personal health data is stored in Upstash.
No data sales — ever
We will never sell, rent, or trade your personal data to any third party for commercial purposes. This is a permanent commitment.
What the AI Doctor knows
When you use the AI Doctor, your conversation is processed in real time by Groq's AI models, and your symptom description is also sent to the World Health Organization's ICD-11 API to help ground the response in recognised diagnostic categories (see "Who we share your data with" above). MediBY stores a structured summary of each session (chief complaint, symptoms, severity, AI recommendations) in your account. Your full conversation history is stored in our database, accessible only to you.
What your real doctor sees — and does not see
If you book an appointment after an AI triage session, we link that session to your booking. Your doctor can view the triage summary for that session only — chief complaint, symptoms, duration, severity, and AI recommendations. They cannot read your full conversation transcript. They cannot access any other AI sessions you have had. If you did not use the AI Doctor before booking, nothing is shared.
Your control
You can export all your AI triage data from Settings → Export my data. You can request deletion of your AI triage history by contacting medibytechnologies@gmail.com. Note that if a triage session is linked to a completed appointment, the summary may be retained as part of the medical record for 7 years.
Audio during video consultations
During a video call, if you and your doctor use the optional audio recording feature to generate a SOAP note, both sides of the conversation are captured, transcribed by Groq Whisper, sent to Groq for SOAP generation, and then the audio is discarded immediately. The resulting SOAP note is stored in your medical record. The raw audio is never stored.
Some of our service providers (Twilio, Resend, Clerk, Groq, AWS S3 EU West, Upstash, and the World Health Organization's ICD-11 API) operate servers outside Nigeria. Where data is transferred internationally, we rely on the provider's compliance certifications and Standard Contractual Clauses to ensure your data is protected to a standard equivalent to Nigerian law. A full list of sub-processors is available on request at medibytechnologies@gmail.com.
Right to access
Download a copy of all your personal data from Settings → Export my data, or email us at medibytechnologies@gmail.com.
Right to rectification
Correct inaccurate data from your profile settings at any time.
Right to erasure
Permanently delete your account and all associated data from Settings → Delete account. Some data (payment records, audit logs, medical records linked to completed consultations) must be retained for legal compliance even after account deletion.
Right to withdraw consent
Withdraw consent for health data processing from Settings → Privacy. This will disable the AI doctor and health data features but will not close your account.
Right to data portability
Receive your data in a structured, machine-readable format (JSON) via Settings → Export my data.
Right to object
Object to the sharing of your AI triage summary with your doctor by not using the AI Doctor before booking, or by contacting us at medibytechnologies@gmail.com before your appointment.
Right to lodge a complaint
If you believe we have mishandled your data, you can lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
MediBY uses only strictly necessary cookies — specifically, the Clerk session cookie that keeps you logged in. We do not use advertising, tracking, or analytics cookies. No cookie consent banner is required for strictly necessary cookies under NDPA 2023. If this changes we will update this policy and notify you.
MediBY is not directed at children under 18. We do not knowingly collect personal data from children without verifiable parental consent. If you believe a child has provided us with data without consent, please contact us at medibytechnologies@gmail.com and we will delete it promptly.
We implement the following technical and organisational measures to protect your data: AES-256-GCM encryption for all Tier 1 health data at rest; TLS 1.3 for all data in transit; role-based access control (doctors only see their own patients' records; hospital sub-admins only see appointment status, not health data); immutable audit logging of all health data access; Neon PostgreSQL with connection pooling and row-level isolation; rate limiting on all public API endpoints; private S3 bucket with signed URLs for all file access; and regular security reviews.
We will notify you by email at least 30 days before any material changes to this Privacy Policy take effect. The date at the top of this page shows when it was last updated. Continued use of MediBY after the effective date of changes constitutes acceptance of the updated policy.
For any privacy questions, data requests, or complaints, contact our Data Protection Officer at medibytechnologies@gmail.com. We will respond within 30 days. If you are not satisfied with our response, you may escalate to the Nigeria Data Protection Commission at ndpc.gov.ng.
Data Protection Officer: medibytechnologies@gmail.com