Legal

Privacy Policy

Last updated: June 2026

1. Who we are

Physela Technologies Ltd. (“Physela”, “we”, “our”) is the data controller for personal data processed through this platform. We are registered in Nigeria and operate under the Nigeria Data Protection Regulation (NDPR) 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).

This policy applies to all individuals whose personal data Physela processes: patients who book or manage appointments, healthcare professionals (doctors, nurses, and clinical staff) who use the platform to deliver care, and hospital administrators who operate a hospital account.

Contact: privacy@physela.com

2. Data we collect

The data we collect depends on how you use the platform.

Patients

  • Identity data: name, date of birth, government ID (optional)
  • Contact data: email address, phone number
  • Health data: blood type, allergies, chronic conditions, vaccination records, appointment notes, prescriptions, lab results
  • Financial data: payment method tokens (we do not store full card numbers), transaction history
  • Insurance data: HMO provider, policy number, copay rate
  • Usage data: login timestamps, feature interactions, device/browser type

Healthcare professionals and clinical staff

  • Professional data: name, email, professional licence number, specialty, and qualifications
  • Schedule data: availability, appointment calendars, leave periods
  • Clinical activity: consultation notes created within the platform, associated with patient records
  • Usage data: login timestamps, feature interactions

Hospital administrators and managers

  • Identity and contact data: name and email address
  • Role data: assigned permissions and access level
  • Usage data: login timestamps, administrative actions recorded in the audit log

4. Who we share your data with

We share your data only with:

  • Partner hospitals and physicians: to deliver the appointment and care you booked
  • Payment providers: certified payment processors that complete online transactions and refunds
  • Communication providers: trusted vendors that deliver appointment reminders and notifications
  • Cloud and hosting providers: secure service providers that host and protect the platform

We do not sell your personal data to third parties.

5. Data retention

We retain personal data for as long as your account is active, plus 7 years to meet healthcare record-keeping obligations under Nigerian law. You may request deletion of your account data at any time by emailing privacy@physela.com. We will anonymise your profile within 30 days of a verified request, subject to legal holds.

6. Your rights

Under GDPR and NDPR you have the right to:

  • Access: request a copy of your personal data by emailing privacy@physela.com
  • Rectification: correct inaccurate data via your profile page
  • Erasure: request deletion of your account by emailing privacy@physela.com
  • Restriction: ask us to pause processing while a dispute is resolved
  • Portability: receive your data in a machine-readable format on request
  • Object: opt out of direct marketing at any time

To exercise any right, email privacy@physela.com. We respond within 30 days.

7. Cookies

We use session cookies (strictly necessary) only. No third-party advertising cookies are set. You can delete cookies via your browser settings at any time; doing so will sign you out. See our Cookie Policy for the full list.

8. Changes

Material changes to this policy will be communicated by email at least 14 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.