1. WHAT INFORMATION DO WE COLLECT?
Personal Information You Disclose to Us
We collect personal information that you voluntarily provide when you register on the TeleWyse App, express an interest in our services, participate in activities on the App, or otherwise contact us.
The personal information we collect may include the following:
- Identification and Contact Data: Names, phone numbers, email addresses, date of birth, and government-issued identification numbers.
- Health and Medical Data: Medical history, current symptoms, prescription details, doctor's notes, consultation records, diagnostic images, and any other health information you provide during consultations or in your medical profile.
- Payment Data: Billing addresses and debit/credit card numbers. (Note: We use secure, PCI-compliant third-party payment processors. We do not store your full credit card details on our servers).
Sensitive Information
When necessary, with your explicit consent or as otherwise permitted by applicable law for the provision of healthcare, we process the following categories of sensitive information:
- Health Data
- Financial Data (for payment processing)
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information Automatically Collected
We automatically collect certain information when you visit, use, or navigate the TeleWyse App. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our App, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. You can find more details in Section 5.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process your personal information for a variety of reasons, depending on how you interact with TeleWyse. Specifically, we use your information to:
- Facilitate and Provide Telemedicine Services: This is the core of our service. We process your personal and health data to create and manage your secure user account, match you with licensed healthcare professionals, conduct virtual audio/video consultations, and enable electronic prescription services.
- Fulfill and Manage Your Orders and Payments: We process your information, including payment details, to process the financial transactions for your consultations, prescribed medications, and other services.
- Maintain Comprehensive Medical Records: We process your health information to create and maintain your electronic health record (EHR) on the platform.
- Administer User Accounts and Communicate with You: We process your contact information to send you critical administrative messages, such as updates to our terms, conditions, and policies.
- Request Feedback: We may process your information to request feedback and to contact you about your use of our Services.
- Send Marketing and Promotional Communications: We may process the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences.
- Protect Our Services and Users: We process your information as part of our efforts to keep TeleWyse safe and secure.
- Save or Protect an Individual's Vital Interest: We may process your information when necessary to save or protect an individual's vital interest.
- Comply with Legal and Regulatory Obligations: We process your information where we believe it is necessary for compliance with our legal obligations.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
The GDPR and NDPA require us to explain the valid legal bases we rely on to process your personal information. As such, we may rely on the following legal bases:
- Your Explicit Consent: This is our primary basis for processing your sensitive health data.
- Performance of a Contract: We process your non-sensitive personal data because it is necessary to perform the contract we have with you.
- Legal Obligations: We process your information where we believe it is necessary for compliance with our legal obligations.
- Vital Interests: We may process your information where we believe it is necessary to protect your vital interests.
- Legitimate Interests: We may process your information for our legitimate interests.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We may need to share your personal information in the following situations:
- Healthcare Providers for Treatment: Your personal and health information is shared with the doctors, pharmacists, nurses, and laboratory personnel involved in your care through the TeleWyse platform.
- Third-Party Service Providers (Processors): We share data with trusted vendors who provide services on our behalf.
- Business Transfers: We may share or transfer your information in connection with any merger, sale of company assets, financing, or acquisition.
- Legal Requirements: We may disclose your information where we believe it is necessary to comply with applicable law.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
We may use cookies and similar tracking technologies (like web beacons, pixels, and SDKs in our mobile app) to access or store information. Specifically, we use them for:
- Essential Operations: To allow the core functionalities of the TeleWyse web portal.
- Performance and Analytics: To help us understand how you use the App.
- Functionality: To remember your preferences and settings.
You have control over cookies. Most web browsers allow you to refuse or accept cookies. However, if you choose to disable cookies, some parts of our web portal may not function correctly.
6. HOW LONG DO WE KEEP YOUR INFORMATION?
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law.
- Medical Records: As mandated by Nigerian health regulations, we will retain your electronic health record for at least 5 to 7 years.
- Account Information: Your basic account information will be retained while your account is active and for a period thereafter.
- Other Data: Log data, marketing profiles, and other non-essential information will be retained for a shorter period.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it.
7. HOW DO WE KEEP YOUR INFORMATION SAFE?
We have implemented and maintained appropriate technical and organisational security measures tailored to the sensitive nature of health data. These measures include:
- Encryption: We use encryption protocols for data in transit and strong encryption methods for data at rest.
- Access Controls: Strict access controls and authentication measures.
- Secure Development: We follow secure coding practices.
- Staff Training: Our employees and contracted healthcare professionals are trained on data privacy.
- Regular Security Assessments: We conduct periodic audits and penetration tests.
8. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly solicit data from or market to children under the age of 18 without parental consent.
For Minors (Under 18 Years of Age):
- A minor cannot create a TeleWyse account independently.
- A parent or legal guardian must create the account on the minor's behalf.
- By creating an account for a minor, you represent and warrant that you are the parent or legal guardian.
- The personal and health information of the minor will be processed for the same purposes and under the same security measures.
Our Actions upon Discovery:
If we learn that personal information from users less than 18 years of age has been collected without verified parental consent, we will immediately deactivate the account and take reasonable measures to promptly delete such data from our records.
9. WHAT ARE YOUR PRIVACY RIGHTS?
In some regions (like the European Economic Area (EEA), United Kingdom (UK), and Nigeria under the NDPA), you have certain rights under applicable data protection laws. These may include the right to:
- Request Access and Data Portability: You can request access to and a copy of the personal information we hold about you.
- Request Rectification: You can request that we correct any inaccurate or incomplete personal information.
- Request Erasure ('Right to be Forgotten'): You can request the deletion of your personal information.
- Restrict Processing: You can request that we temporarily or permanently stop processing all or some of your personal information.
- Withdraw Consent: You can withdraw your consent at any time.
- Object to Processing: You can object to our processing of your personal information for certain purposes.
Exercising Your Rights:
To exercise any of these rights, please submit a verifiable request to us by contacting our Data Protection Officer (DPO).
Complaints:
If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your local data protection authority.
If you are in Nigeria, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
10. DO WE MAKE UPDATES TO THIS NOTICE?
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Last Updated" date at the top of this page, and the updated version will be effective as soon as it is accessible.
If we make material changes to this privacy notice that affect how we handle your personal data or your rights, we will notify you either by:
- Prominently posting a notice of such changes within the TeleWyse application.
- Directly sending you a notification via email or SMS.
We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
11. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have any questions or comments about this notice, or if you would like to exercise your privacy rights, you may contact our designated Data Protection Officer (DPO) at:
Contact Information
TeleWyse
No.26 ETSL Plaza, off Deco Road
Warri, Delta State, Nigeria (NG).
+2348159792584
info@telewyse.co
12. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country, you may request to review, update, or delete your personal information.
The Process:
- Submit a Request: To initiate this process, please fill out and submit a Data Subject Access Request (DSAR) form, which can be obtained by emailing dpo@telewyse.co.
- Verification: Upon receiving your request, we are required by law to verify your identity before proceeding.
- Response: We will respond to your verifiable request without undue delay.
Please note: As a healthcare provider, we are legally obligated to maintain medical records for a minimum period. Therefore, a request for deletion will be subject to these legal retention requirements.