Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your personal and health information.
Last updated: April 1, 2026
Arlix Health Technologies Ltd (“Arlix,” “we,” “us,” or “our”) is committed to protecting your privacy and personal data. This Privacy Policy describes how we collect, use, store, and share your information when you use the Arlix telehealth platform (“Service”), including our website, mobile applications, and related services. This Policy is designed to comply with the Nigeria Data Protection Act 2023 and the regulations of the Nigeria Data Protection Commission (NDPC).
1. Information We Collect
We collect information that you provide directly, information generated through your use of the Service, and information from third-party sources. The types of information we collect include:
Personal Information: Full name, email address, phone number, date of birth, gender, home address, and government-issued identification (for doctor verification).
Health Information: Medical history, symptoms, consultation notes, prescriptions, lab results, diagnoses, treatment plans, and other health-related data shared during consultations (collectively, "Protected Health Information" or "PHI").
Payment Information: Payment card details, bank account information, and transaction history. Payment processing is handled by our partner Paystack; we do not store full card numbers on our servers.
Device and Usage Information: IP address, browser type, device type, operating system, app version, pages visited, features used, consultation duration, and interaction patterns.
Location Information: General location data derived from your IP address or, with your consent, more precise location data from your device to connect you with nearby pharmacies and healthcare facilities.
2. How We Use Your Information
We use the information we collect for the following purposes:
(a) Service Delivery: To facilitate telehealth consultations, process prescriptions, manage lab orders, and provide the core healthcare services of the platform; (b) Account Management: To create and manage your user account, verify your identity, and provide customer support; (c) Communication: To send appointment reminders, consultation summaries, health tips, service updates, and respond to your enquiries; (d) Payment Processing: To process consultation fees, manage refunds, and maintain billing records; (e) Platform Improvement: To analyse usage patterns, diagnose technical issues, improve features, and develop new services; (f) Safety and Compliance: To detect and prevent fraud, enforce our Terms of Service, and comply with legal obligations; (g) Research and Analytics: To conduct anonymised, aggregate analysis to improve healthcare delivery (individual health data is never shared without consent).
We will not use your personal information for purposes materially different from those described above without providing you with notice and, where required, obtaining your consent.
3. Health Data (Protected Health Information)
We treat your health data with the highest level of care and security. Your Protected Health Information (PHI) is:
(a) Stored using end-to-end encryption on secure, access-controlled servers; (b) Accessible only to you, your treating healthcare provider, and authorised Arlix personnel on a strict need-to-know basis; (c) Never sold to third parties for marketing or advertising purposes; (d) Never used for automated decision-making that could adversely affect your access to care; (e) Retained in accordance with applicable Nigerian healthcare record-keeping requirements.
Your treating doctor may access your health history on the platform to provide informed care. You may request a complete copy of your health records at any time by contacting us at hello@arlix.net.
For Family Care accounts, the primary account holder may access health summaries for dependants under 18 years of age. Dependants aged 18 and above must provide explicit consent for their health information to be shared with family members.
4. Data Sharing
We may share your information with the following categories of recipients, and only to the extent necessary:
Healthcare Providers: Doctors and specialists on the Arlix platform who are involved in your care.
Partner Pharmacies and Laboratories: To fulfil prescriptions and process lab orders you have authorised.
Payment Processors: Paystack and associated financial institutions to process your payments securely.
Service Providers: Trusted third-party vendors who assist us with hosting, analytics, communication, and customer support, all bound by strict data processing agreements.
Legal and Regulatory: Government authorities, regulatory bodies, or law enforcement agencies when required by Nigerian law, court order, or to protect the safety of our users.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Any third party receiving your data is contractually obligated to protect it in accordance with this Privacy Policy and applicable law.
5. Data Security
We implement robust technical and organisational measures to protect your information, including:
(a) AES-256 encryption for data at rest and TLS 1.3 for data in transit; (b) Multi-factor authentication for all administrative access; (c) Regular security audits and penetration testing; (d) Access controls based on the principle of least privilege; (e) Employee training on data protection and security best practices; (f) Incident response procedures for prompt detection and handling of data breaches; (g) Regular backups stored in geographically redundant, secure facilities.
While we strive to protect your information using industry-standard measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly notifying affected users and the NDPC of any data breach in accordance with legal requirements.
6. Your Rights Under the NDPC
Under the Nigeria Data Protection Act 2023 and regulations of the Nigeria Data Protection Commission (NDPC), you have the following rights regarding your personal data:
Right of Access: You may request a copy of the personal data we hold about you.
Right to Rectification: You may request that we correct inaccurate or incomplete personal data.
Right to Erasure: You may request deletion of your personal data, subject to legal record-keeping requirements for health data.
Right to Restrict Processing: You may request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format.
Right to Object: You may object to the processing of your personal data for direct marketing or profiling purposes.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact our Data Protection Officer at hello@arlix.net. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
7. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfil the purposes described in this Policy. Specific retention periods include:
Account Data: Retained for the duration of your account and for 2 years after account deletion, unless a longer period is required by law.
Health Records: Retained for a minimum of 10 years from the date of the last consultation, in accordance with Nigerian medical record-keeping guidelines.
Payment Records: Retained for 7 years in compliance with Nigerian tax and financial regulations.
Usage Data: Retained in anonymised form for analytical purposes. Identifiable usage data is deleted after 2 years.
When personal data is no longer required, it is securely deleted or anonymised. You may request early deletion of your account data by contacting us, though certain health and financial records may be retained as required by law.
8. Children's Privacy
The Arlix platform is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13.
For children between 13 and 17, a parent or legal guardian must create and manage their account through the Family Care feature. The parent or guardian is responsible for providing consent for the collection and use of the minor's information.
If we become aware that we have collected personal information from a child under 13 without verified parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child under 13, please contact us at hello@arlix.net.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
(a) Update the "Last updated" date at the top of this page; (b) Notify you via email or in-app notification at least 14 days before the changes take effect; (c) Obtain your consent where required by law.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
10. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
Data Protection Officer Arlix Health Technologies Ltd 14 Adeola Odeku Street, Victoria Island, Lagos, Nigeria
Email: hello@arlix.net Phone: +234 901 234 5678
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been violated.
By using the Arlix platform, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please contact our Data Protection Officer at hello@arlix.net.