Who we are (data controller)
GoDoctor is operated by Innoedge Technologies Limited (RC [RC number]), registered office [registered address], Nigeria. For the personal data we process to run the platform, Innoedge Technologies Limited is the data controller.
Where an independent provider (a doctor, pharmacy, laboratory or nurse) treats you through GoDoctor, that provider is a separate controller of the clinical records they create about you, and processes your data under their own professional and legal obligations.
You can reach our Data Protection Officer at [email protected] and our privacy team at [email protected].
Scope of this policy
This policy covers personal data we process through the GoDoctor mobile apps and website and the related services we facilitate. It is read together with our Terms of Service, Cookie Policy and Medical Disclaimer. Third parties we link to (for example a payment processor or a provider) have their own privacy notices.
Data we collect
Depending on how you use GoDoctor, we collect:
- Identity data — name, date of birth, gender, and, where required for verification or a regulated service, identifiers such as a government ID or NIN.
- Contact data — email address, phone number and delivery address.
- Health and sensitive personal data — symptoms, medical history, the reason for your consultation, prescriptions, lab requests and results, and notes shared during a consultation. Under the NDPA/NDPR this is sensitive personal data and is given the special handling described below.
- Payment data — the transaction details needed to take payment. Full card details are collected and processed by our payment processor (Paystack), not stored by us.
- Device & technical data — device type, operating system, app version, IP address and similar diagnostic data.
- Usage & location data — how you interact with the Service, and, where you grant permission, approximate or precise location used to match you with nearby pharmacies, labs or delivery.
Lawful basis for processing
We process your personal data under the lawful bases recognised by the NDPA/NDPR, principally:
- Performance of a contract — to provide the Service you have asked for (creating your account, facilitating a consultation, processing a payment, arranging delivery).
- Consent — for processing your health and sensitive personal data, for non-essential cookies and analytics, and for using your location. You may withdraw consent at any time (this does not affect processing already carried out).
- Legal obligation — where we must process data to comply with Nigerian law or a lawful regulatory request.
- Legitimate interests — to secure the platform, prevent fraud and abuse, and improve the Service, balanced against your rights and interests.
How we use your data
We use personal data to:
- create and manage your account and verify eligibility;
- connect you with an independent provider and pass them the information they need to treat you;
- facilitate consultations (including video infrastructure), medicine delivery, lab sample collection, nurse visits and HMO claims;
- process payments and refunds and keep transaction records;
- communicate with you about bookings, results and the Service;
- keep the platform secure, prevent fraud and abuse, and meet our legal and regulatory obligations; and
- with your consent, understand and improve how the Service is used.
Special handling of health data
Your health data is sensitive personal data
We treat the health information you share (your symptoms, history, consultation notes, prescriptions and lab results) as sensitive personal data under the NDPA/NDPR. We process it only with your consent or where otherwise permitted by law for the provision of healthcare, and only to the extent needed to provide the care you have asked for.
We apply heightened safeguards to this data: it is encrypted in transit and at rest, access is restricted on a need-to-know basis, and it is shared with the independent provider treating you so they can deliver care. We do not use your health data for advertising.
How long we keep data
We keep personal data only as long as necessary for the purposes above and to meet legal, regulatory, accounting and dispute-resolution requirements. Health and medical records may be retained for the period required by applicable Nigerian medical record-keeping rules; payment records for the period required by law. When data is no longer needed it is securely deleted or anonymised. You can ask us to delete your data — see your rights below — subject to retention we are legally required to maintain.
Security measures
We are committed to protecting your data and apply technical and organisational measures appropriate to its sensitivity, including encryption in transit and at rest, access controls and least-privilege access, network and application hardening, logging and monitoring, and staff confidentiality obligations. No system can be guaranteed completely secure; if a breach affecting your data occurs, we will act and notify you and the relevant authority where the NDPA/NDPR requires.
Your rights under the NDPR
Subject to the conditions and exemptions in the NDPA/NDPR, you have the right to:
- Access — obtain confirmation of, and a copy of, the personal data we hold about you;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — ask us to delete your data where there is no lawful reason to keep it;
- Restriction — ask us to limit how we process your data in certain circumstances;
- Portability — receive certain data in a structured, commonly-used, machine-readable format, or have it transmitted to another controller where technically feasible;
- Objection — object to processing based on our legitimate interests; and
- Withdraw consent — at any time, where we rely on your consent (including for health data, analytics cookies and location).
To exercise any right, contact [email protected] or our DPO at [email protected]. We will respond within the timeframe required by the NDPA/NDPR. We may need to verify your identity before acting on a request.
Children & dependants
GoDoctor accounts are for adults (18+). We do not knowingly create accounts for children. A parent or legal guardian may use the Service to obtain care for a minor or dependant in their care; in that case the adult is responsible for the information provided. If you believe a child has provided us data without appropriate authority, contact [email protected] and we will take appropriate action.
Cross-border transfers
Some of the service providers we rely on (such as hosting, payment or video infrastructure) may process data outside Nigeria. Where personal data is transferred across borders, we take steps to ensure it is protected to a standard consistent with the NDPA/NDPR — for example by transferring only to recipients in jurisdictions or under arrangements that provide adequate protection, on the basis of your consent, or under appropriate contractual safeguards.
Data Protection Officer & complaints
Our Data Protection Officer oversees our handling of personal data. You can reach the DPO at [email protected] or by post to Innoedge Technologies Limited at [registered address], marked for the attention of the Data Protection Officer.
If you are not satisfied with how we handle your data or a request, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) — the successor to the National Information Technology Development Agency (NITDA) for data-protection supervision — at ndpc.gov.ng. We would, however, appreciate the chance to address your concern first.
Updates to this policy
We may update this policy from time to time. When we make a material change we will update the “Last updated” date above and, where appropriate, notify you. Please review it periodically.