MedxGo Privacy Policy
Effective Date: June 24, 2026
Last Updated: June 24, 2026
Company: MedxGo Technologies Limited
Jurisdiction: Federal Republic of Nigeria (Primary) | Expanding African
Operations
Website: https://medxgoapp.com/
App: MedxGo Mobile Application
1. DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings assigned to them:
"Account" means a registered user profile created on the MedxGo platform to access our services.
"AI" or "Artificial Intelligence" refers to Lexi AI, MedxGo's proprietary intelligent health assistant and automated processing system.
"Applicable Law" means the Nigeria Data Protection Act 2023, the Nigeria Data Protection Regulation 2019 (as amended), subsidiary legislation issued by the Nigeria Data Protection Commission (NDPC), and any other relevant data protection laws in jurisdictions where MedxGo operates.
"Child" means any natural person below the age of 18 years under Nigerian law, or the applicable age of majority in the jurisdiction where the user is located.
"Consent" means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, through a statement or clear affirmative action, signify agreement to the processing of personal data relating to them.
"Controller" means MedxGo Technologies Limited, which determines the purposes and means of processing personal data.
"Customer" means any individual who registers on the MedxGo platform to purchase pharmaceutical products, access healthcare services, order meals, or utilize any other service offered through the MedxGo application.
"Data Subject" means an identified or identifiable natural person whose personal data is processed by MedxGo.
"Healthcare Data" means any personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveals information about their health status, medical history, diagnoses, treatments, prescriptions, and biometric data.
"Health Institution" means any hospital, clinic, diagnostic center, laboratory, or other healthcare facility registered with the relevant regulatory authorities in Nigeria or other African jurisdictions.
"Merchant" means any business entity partnered with MedxGo to offer goods or services through the platform, including pharmacies, restaurants, grocery stores, and wellness providers.
"NDPA" means the Nigeria Data Protection Act 2023 and all subsidiary regulations, guidelines, and codes of practice issued thereunder.
"NDPC" means the Nigeria Data Protection Commission established under the NDPA.
"Partner Pharmacy" means a licensed pharmacy registered with the Pharmacists Council of Nigeria (PCN) or equivalent regulatory body in other jurisdictions, which operates on the MedxGo platform.
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to name, address, email, phone number, identification numbers, location data, online identifiers, and factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
"Pharmacy" means a licensed pharmaceutical retail or wholesale establishment registered on the MedxGo platform.
"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of MedxGo.
"Restaurant" means a food service establishment registered on the MedxGo platform to provide meal delivery services.
"Rider" means an independent contractor or employee engaged by MedxGo or a delivery partner to transport goods and services to Customers.
"Sensitive Personal Data" means personal data relating to religious or other beliefs, sexual orientation, health, race or ethnic origin, political opinions, membership of a professional association, genetic data, biometric data, criminal proceedings, or data relating to children, as defined under Section 30 of the NDPA.
"Service" means any product, feature, functionality, or benefit offered by MedxGo through its mobile application, website, or affiliated platforms.
"Special Category Data" has the same meaning as Sensitive Personal Data under the NDPA.
"Third-Party Service Provider" means any external vendor, contractor, or service provider engaged by MedxGo to facilitate the delivery of services, including but not limited to payment processors, cloud infrastructure providers, analytics services, and verification agencies.
"User" means any individual or entity that accesses, uses, or interacts with the MedxGo platform, including Customers, Pharmacies, Restaurants, Riders, Merchants, and Healthcare Providers
2. SCOPE AND APPLICABILITY
2.1 Coverage
This Privacy Policy applies to all personal data collected, processed, stored, and transmitted by MedxGo Technologies Limited, its subsidiaries, affiliates, and partners in connection with the provision of services through:
- The MedxGo mobile application (iOS and Android)
- The MedxGo website (https://medxgoapp.com/)
- Any affiliated web portals, APIs, or digital interfaces
- Offline interactions where data is subsequently digitized
- Customer support channels, including telephone, email, and chat
2.2 Geographic Scope
MedxGo is incorporated in the Federal Republic of Nigeria and primarily operates under Nigerian law. As we expand operations across Africa, this Privacy Policy applies to all data processing activities regardless of the user's physical location, subject to the data protection laws of the specific African jurisdiction where services are rendered.
2.3 Binding Nature
By downloading, installing, accessing, or using the MedxGo application or website, or by otherwise providing your personal data to us, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with any provision herein, you must immediately discontinue use of our services.
2.4 Updates and Amendments
MedxGo reserves the right to modify this Privacy Policy at any time to reflect changes in legal requirements, our business practices, or technological advancements. Material changes will be communicated to Users via email, in-app notifications, or prominent website postings at least 30 days before the effective date of such changes. Continued use of our services after such modifications constitutes acceptance of the revised Privacy Policy.
2.5 Relationship with Terms of Service
This Privacy Policy operates in conjunction with the MedxGo Terms of Service, End-User License Agreement, and any other applicable agreements. In the event of any conflict, the provisions most protective of User privacy shall prevail.
3. DATA COLLECTION
3.1 Principles of Data Collection
MedxGo adheres to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability in all data collection activities, as mandated by Section 24 of the NDPA.
3.2 Methods of Collection
We collect personal data through the following means:
- Direct Collection: Information voluntarily provided by Users during account registration, profile completion, service requests, and communications with our support team.
- Automated Collection: Technical data automatically collected through cookies, log files, device identifiers, and similar technologies when Users interact with our platforms.
- Third-Party Sources: Information obtained from verification agencies, payment processors, healthcare providers (with consent), and publicly available registers.
- Inferred Data: Data derived from analysis of User behavior, preferences, and interactions with our platform.
3.3 Legal Basis for Processing
Under Section 25 of the NDPA, we process personal data based on one or more of the following legal grounds:
- Consent: Explicit, informed consent obtained from the Data Subject.
- Contractual Necessity: Processing necessary for the performance of a contract to which the Data Subject is a party or to take steps at the request of the Data Subject prior to entering into a contract.
- Legal Obligation: Processing necessary for compliance with a legal obligation to which MedxGo is subject.
- Vital Interests: Processing necessary to protect the vital interests of the Data Subject or another natural person.
- Public Interest: Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
- Legitimate Interests: Processing necessary for the purposes of legitimate interests pursued by MedxGo or a third party, except where such interests are overridden by the fundamental rights and freedoms of the Data Subject.
3.4 Categories of Data Collected
The specific categories of data collected vary depending on the type of User and the services utilized. Detailed breakdowns are provided in Sections 4 through 9 below.
4. CUSTOMER DATA
4.1 Identity and Contact Information
- Full name (first, middle, and last)
- Date of birth and age
- Gender
- National Identification Number (NIN), International Passport Number, or other government-issued identification
- Residential address and delivery addresses
- Email address and telephone number(s)
- Profile photograph
- Emergency contact information
4.2 Account and Transaction Data
- Username and encrypted password
- Account registration date and activity history
- Order history, including products purchased, quantities, dates, and amounts
- Payment methods and transaction records
- Loyalty program participation and rewards data
- Reviews, ratings, and feedback submitted
4.3 Health and Medical Information
- Self-reported health conditions and allergies
- Medication history and current prescriptions
- Preferred pharmacies and healthcare providers
- Health goals and wellness preferences
- Insurance information (where applicable)
4.4 Behavioral and Preference Data
- Browsing history within the MedxGo app
- Search queries and filter preferences
- Device type, operating system, and browser information
- IP address and geolocation data
- App usage patterns and session duration
- Communication preferences
4.5 Communication Data
- Records of interactions with customer support
- Chat transcripts with Lexi AI
- Email correspondence
- Telephone call logs and recordings (with prior notification)
- Survey responses and feedback
5. PHARMACY DATA
5.1 Business and Licensing Information
- Registered business name and trading name
- Pharmacy license number issued by the Pharmacists Council of Nigeria (PCN) or equivalent authority
- Corporate Affairs Commission (CAC) registration number
- Tax Identification Number (TIN)
- Physical address and operational locations
- Contact details of authorized representatives
5.2 Personnel Data
- Names, qualifications, and professional registration numbers of pharmacists and pharmacy technicians
- National Identification Numbers of key personnel
- Contact details of owners, directors, and managers
- Employment verification documents
- Background check results
5.3 Operational Data
- Inventory records and product catalogs
- Pricing information and promotional data
- Sales performance metrics
- Customer ratings and reviews
- Delivery radius and operational hours
- Integration data with MedxGo's pharmacy management system
5.4 Financial Data
- Bank account details for settlement purposes
- Transaction history and commission records
- Tax documentation
- Invoicing and payment records
5.5 Compliance Data
- Regulatory inspection reports
- Adverse event reporting records
- Quality assurance documentation
- Insurance and indemnity coverage details
6. RESTAURANT DATA
6.1 Business Registration Information
- Registered business name and brand name
- Food business permit and license numbers
- CAC registration details
- Tax Identification Number
- Physical address and kitchen locations
- Halal, kosher, or other dietary certification (where applicable)
6.2 Personnel and Management Data
- Names and contact details of owners, managers, and authorized signatories
- NIN and identification documents of key personnel
- Food handler's medical certificates
- Staff training and certification records
6.3 Menu and Operational Data
- Menu items, ingredients, allergen information, and nutritional data
- Pricing and promotional information
- Preparation and delivery time estimates
- Customer feedback and ratings
- Operational hours and availability status
6.4 Financial and Settlement Data
- Bank account information for payment processing
- Transaction history and revenue reports
- Commission and fee calculations
- Tax withholding records
7. RIDER DATA
7.1 Identity and Verification Data
- Full name, date of birth, and photograph
- NIN, driver's license number, and vehicle registration details
- Residential address and contact information
- Next of kin and emergency contact details
- Biometric data (facial recognition for identity verification)
7.2 Vehicle and Equipment Data
- Vehicle type, make, model, and year
- Vehicle registration and insurance documents
- Safety equipment verification records
- Maintenance and inspection reports
7.3 Performance and Location Data
- Real-time GPS location during active delivery sessions
- Delivery route history and timestamps
- Order acceptance and completion rates
- Customer ratings and feedback
- Earnings and incentive records
7.4 Background and Compliance Data
- Criminal background check results
- Driving history and violation records
- Drug and alcohol test results (where required by law)
- Training completion certificates
- Incident and accident reports
8. MERCHANT DATA
8.1 General Merchant Information
MedxGo partners with various merchants beyond pharmacies and restaurants, including:
- Grocery and retail stores
- Wellness and fitness centers
- Medical equipment suppliers
- Health insurance providers
- Diagnostic laboratories
8.2 Data Collected from All Merchants
- Business registration and licensing documentation
- Tax Identification Number and VAT registration (where applicable)
- Physical and mailing addresses
- Authorized representative details and contact information
- Product catalogs, pricing, and inventory data
- Financial settlement information
- Performance metrics and customer interaction data
- Compliance and certification records specific to their industry
9. HEALTHCARE DATA
9.1 Nature of Healthcare Data
Healthcare Data constitutes Sensitive Personal Data under Section 30 of the NDPA and receives the highest level of protection. MedxGo processes Healthcare Data strictly in accordance with the principles of necessity, proportionality, and lawful basis.
9.2 Categories of Healthcare Data Processed
Medical History: Past illnesses, surgeries, chronic conditions, and family medical history.
Diagnostic Information: Laboratory results, imaging reports, and diagnostic assessments.
Treatment Records: Medication regimens, therapy protocols, and treatment outcomes.
Prescription Data: Medication names, dosages, frequencies, prescribing physicians, and dispensing records.
Vital Signs: Blood pressure, temperature, blood glucose levels, and other biometric measurements.
Mental Health Information: Counseling records, psychiatric assessments, and therapy notes (only where explicitly consented).
Insurance and Billing: Health insurance policy details, claims history, and medical billing information.
9.3 Sources of Healthcare Data
- Directly from Customers through health questionnaires and symptom checkers
- From Partner Pharmacies upon prescription fulfillment
- From Healthcare Providers (hospitals, clinics, laboratories) with explicit patient consent
- From wearable devices and health apps integrated with MedxGo (with user authorization)
- From Lexi AI interactions where Users voluntarily disclose health information
9.4 Special Protections for Healthcare Data
Healthcare Data is encrypted at rest and in transit using AES-256 encryption.
Access is restricted to authorized medical professionals and support staff with a legitimate need.
All processing of Healthcare Data requires explicit, informed consent, except where necessary for vital interests or legal compliance.
Healthcare Data is never used for marketing purposes without separate, explicit consent.
Data retention periods for Healthcare Data are strictly limited and subject to medical records retention requirements.
10. PRESCRIPTION HANDLING
10.1 Prescription Collection and Verification
Customers may upload prescription images or documents through the MedxGo app.
Prescriptions are verified by licensed pharmacists employed or contracted by MedxGo.
Verification includes confirming the prescribing physician's registration, prescription validity, and medication appropriateness.
10.2 Data Captured from Prescriptions
Patient name and identification details
Prescribing physician's name, registration number, and contact information
Medication name, strength, dosage form, and quantity prescribed
Dosage instructions and duration of treatment
Date of prescription and number of authorized refills
Pharmacy stamp and dispensing records
10.3 Prescription Processing
Verified prescriptions are transmitted electronically to Partner Pharmacies for fulfillment.
All transmission occurs over encrypted channels.
Prescription data is logged for regulatory compliance, drug interaction checking, and refill management.
10.4 Controlled Substances and Restricted Medications
Prescriptions for controlled substances (narcotics, psychotropics, etc.) are subject to additional verification protocols in compliance with the National Agency for Food and Drug Administration and Control (NAFDAC) regulations.
Such prescriptions require physical presentation at the dispensing pharmacy and cannot be fulfilled solely through digital submission.
Additional identity verification is mandatory for controlled substance prescriptions.
10.5 Prescription Retention
Prescription records are retained for a minimum of seven (7) years or as required by the Pharmacists Council of Nigeria and NAFDAC regulations.
After the retention period, prescription data is securely anonymized or destroyed in accordance with our Data Retention Policy.
11. AI (LEXI AI) PRIVACY
11.1 Overview of Lexi AI
Lexi AI is MedxGo's proprietary artificial intelligence system designed to provide health information, medication guidance, symptom assessment, and personalized wellness recommendations. Lexi AI operates as a supportive tool and does not replace professional medical advice, diagnosis, or treatment.
11.2 Data Processed by Lexi AI
Conversational Data: Text, voice, and image inputs provided by Users during interactions with Lexi AI.
Contextual Data: User profile information, health history, medication records, and previous interactions to personalize responses.
Behavioral Data: Interaction patterns, feature usage, and response feedback to improve AI performance.
Diagnostic Inputs: Symptoms, vital signs, and health concerns described by Users.
11.3 Data Use for AI Training and Improvement
Anonymized and aggregated interaction data may be used to train, fine-tune, and improve Lexi AI's algorithms and response accuracy.
Personal identifiers are removed or tokenized before use in training datasets.
Users may opt out of having their data used for AI model improvement through their privacy settings, without affecting their access to Lexi AI services.
11.4 Limitations and Disclaimers
Lexi AI does not provide definitive medical diagnoses.
All AI-generated health information is reviewed against established medical databases and guidelines.
Users are always directed to consult licensed healthcare professionals for serious, persistent, or emergency health concerns.
Lexi AI interactions are logged for quality assurance, safety monitoring, and regulatory compliance.
11.5 Automated Decision-Making
Lexi AI may provide automated recommendations regarding medication reminders, health tips, and lifestyle suggestions.
No automated decision is made that produces legal effects concerning the User or similarly significantly affects them without human oversight, except where explicitly authorized by law or with explicit User consent.
Users have the right to contest any AI-generated recommendation and request human review.
11.6 Third-Party AI Components
Lexi AI may incorporate third-party natural language processing, machine learning, or medical knowledge base components.
All third-party AI providers are bound by data processing agreements that ensure compliance with the NDPA and this Privacy Policy.
No personal data is shared with third-party AI providers for their independent purposes.
12. COOKIES AND TRACKING TECHNOLOGIES
12.1 What Are Cookies
Cookies are small text files placed on your device when you visit our website or use our application. They help us recognize your device, remember your preferences, and understand how you interact with our services.
12.2 Types of Cookies We Use
Essential Cookies: Necessary for the core functionality of the MedxGo platform, including user authentication, session management, and security features. These cookies cannot be disabled.
Functional Cookies: Enable enhanced functionality and personalization, such as remembering your preferred pharmacy, delivery address, and language settings.
Analytics Cookies: Collect information about how Users interact with our platform, including pages visited, time spent, and features used. This data helps us improve user experience and platform performance.
Marketing Cookies: Used to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. These cookies track your browsing habits across websites.
Health Preference Cookies: Remember your health interests, medication reminders, and wellness goals to provide a personalized experience.
12.3 Third-Party Cookies
We may allow trusted third-party service providers to place cookies on your device for analytics, advertising, and social media integration purposes. These third parties include:
Google Analytics and Firebase
Facebook Pixel and Meta Business Tools
Mixpanel and Amplitude
Adjust and Branch (mobile attribution)
12.4 Cookie Consent and Management
Upon first visit to our website or app, you will be presented with a cookie consent banner allowing you to manage your preferences.
You may modify your cookie preferences at any time through your account settings or browser settings.
Disabling certain cookies may limit the functionality of our services.
For detailed cookie management, please contact privacy@medxgoapp.com.
12.5 Other Tracking Technologies
In addition to cookies, we use:
Web Beacons: Small graphic images embedded in emails and web pages to track engagement.
Local Storage: Browser-based storage for caching data and improving app performance.
Device Fingerprinting: Collection of device characteristics for fraud prevention and security.
SDKs (Software Development Kits): Integrated into our mobile apps for analytics, crash reporting, and push notifications.
13. LOCATION TRACKING
13.1 Purpose of Location Data
MedxGo collects location data to:
Accurately match Customers with nearby pharmacies, restaurants, and healthcare providers
Calculate delivery distances, estimated times of arrival, and delivery fees
Track Rider locations during active delivery sessions for operational efficiency and safety
Provide location-based health alerts and service recommendations
Detect and prevent fraudulent transactions
13.2 Types of Location Data
Precise Location: GPS coordinates obtained through your device's location services, accurate to within a few meters.
Approximate Location: Broader geographic area derived from IP address, cell tower triangulation, or Wi-Fi network data.
Geofencing Data: Notifications triggered when you enter or exit defined geographic boundaries (e.g., pharmacy pickup zones).
13.3 Consent and Control
Location tracking requires explicit permission granted through your device settings.
You may enable or disable location services at any time through your device settings or MedxGo app permissions.
Certain features, such as real-time delivery tracking and nearby pharmacy search, require location services to function.
Background location tracking for Riders is only active during scheduled delivery shifts and requires separate consent.
13.4 Location Data Retention
Real-time location data is retained only for the duration necessary to complete the service (e.g., active delivery session).
Historical location data is anonymized and aggregated for analytics after 90 days.
Individual location trails are retained for a maximum of 12 months for dispute resolution, safety investigations, and legal compliance, after which they are securely deleted.
13.5 Location Data Sharing
Customer delivery addresses are shared with the assigned Rider and Partner Pharmacy/Restaurant solely for order fulfillment.
Rider location data is shared with the Customer in real-time during active deliveries.
Aggregated, anonymized location data may be shared with public health authorities for disease surveillance and health planning, where permitted by law.
14. PAYMENT PROCESSING
14.1 Payment Methods
MedxGo supports multiple payment methods, including:
Debit and credit cards (Visa, Mastercard, Verve)
Bank transfers and USSD payments
Mobile money wallets (where available)
MedxGo Wallet (stored value account)
Cash on delivery (limited locations)
Health insurance direct billing (partnered insurers)
14.2 Payment Data Collection
When you make a payment, we collect:
Card number, expiry date, and CVV (temporarily, for transaction authorization only)
Cardholder name and billing address
Bank account details (for transfers)
Mobile money wallet identifier
Transaction amount, date, and reference number
Device information and IP address for fraud detection
14.3 Payment Security
MedxGo does not store full card numbers or CVV codes on our servers.
All payment data is transmitted using Transport Layer Security (TLS) 1.3 encryption.
Payment processing is handled by PCI-DSS Level 1 compliant third-party providers, including:
Paystack
Flutterwave
Interswitch
Remita
Tokenization technology replaces sensitive card data with non-sensitive equivalents.
14.4 Fraud Prevention
We employ advanced fraud detection algorithms to identify suspicious transactions.
Machine learning models analyze transaction patterns, device fingerprints, and behavioral biometrics.
Users may be required to complete additional verification steps (OTP, 3D Secure) for high-risk transactions.
Suspected fraudulent activity may be reported to relevant financial authorities and law enforcement.
14.5 Payment Data Retention
Transaction records are retained for seven (7) years in compliance with Nigerian tax laws and financial regulations.
After the retention period, payment details are securely deleted or anonymized.
Chargeback and dispute records may be retained for longer periods as required by payment networks and regulators.
15. DATA RETENTION
15.1 Retention Principles
MedxGo retains personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agrements, in accordance with Section 26 of the NDPA.
15.2 Retention Periods by Data Category
Table
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account registration data | Duration of account + 3 years | Contract performance, legal claims |
| Transaction records | 7 years | Tax compliance, financial regulations |
| Prescription records | 7 years | PCN/NAFDAC regulatory requirements |
| Healthcare data | Duration of care + 7 years | Medical records retention standards |
| Location data (active) | Duration of service + 90 days | Operational needs, dispute resolution |
| Location history | 12 months | Safety, fraud investigation |
| Communication records | 3 years | Customer service, legal compliance |
| Cookie and tracking data | 13 months | Analytics, marketing effectiveness |
| AI interaction logs | 2 years | Quality assurance, safety monitoring |
| Rider performance data | Duration of engagement + 3 years | Employment/contractor records |
| Merchant financial data | 7 years | Tax and audit compliance |
15.3 Account Deletion and Data Erasure
Users may request account deletion through the app settings or by contacting privacy@medxgoapp.com.
Upon account deletion request, we will initiate a 30-day grace period during which the account can be reactivated.
After the grace period, personal data is securely deleted except where retention is required by law or for legitimate business purposes (e.g., financial records, prescription history).
Anonymized, aggregated data that cannot identify you may be retained indefinitely for research and analytics.
15.4 Secure Disposal
When personal data reaches the end of its retention period, MedxGo ensures secure disposal through:
Cryptographic erasure of digital records
Physical destruction of paper records (where applicable)
Verification of deletion through audit trails
Certification of destruction for sensitive Healthcare Data
16. CHILDREN'S PRIVACY
16.1 Age Restrictions
MedxGo services are not intended for use by Children under the age of 16 without verifiable parental or guardian consent. Users under 18 but above 16 may use certain services with restricted functionality and enhanced privacy protections.
16.2 Parental Consent Mechanism
For Children under 16:
Account creation requires explicit consent from a parent or legal guardian.
The parent/guardian must provide their own identification and contact information.
A verification process, including document review and potential telephone confirmation, is conducted.
The parent/guardian retains the right to review, modify, or delete the Child's data at any time.
16.3 Data Minimization for Children
We collect only the minimum necessary data from Children, including:
Name and age (for age-appropriate content filtering)
Parent/guardian contact information
Health information strictly necessary for service provision (e.g., allergies for meal orders, pediatric prescriptions)
16.4 Prohibited Activities
We do not target marketing or advertising to Children.
We do not sell or share Children's personal data for commercial purposes.
Lexi AI interactions with Children are restricted to general health information and always include prompts to consult a parent, guardian, or healthcare professional.
Location tracking for Children is disabled by default and requires explicit parental authorization.
16.5 Discovery of Underage Users
If we discover that we have inadvertently collected personal data from a Child without appropriate consent, we will:
Immediately suspend the account
Delete all associated personal data within 72 hours
Notify the parent/guardian if contact information is available
Review and enhance our age verification processes
17. THIRD-PARTY SERVICES
17.1 Categories of Third-Party Service Providers
MedxGo engages the following categories of third parties to support our operations:
Cloud Infrastructure: Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure for data storage and computing resources.
Payment Processors: Paystack, Flutterwave, Interswitch, and Remita for transaction processing.
Communication Services: Twilio, SendGrid, and Africa's Talking for SMS, email, and voice communications.
Analytics and Marketing: Google Analytics, Mixpanel, Facebook Business, and Adjust for user behavior analysis and campaign management.
Verification Services: Smile Identity, YouVerify, and VerifyMe for identity verification and KYC compliance.
Healthcare Integrations: Hospital information systems, laboratory management systems, and electronic health record providers (with patient consent).
Logistics Partners: Independent delivery companies and fleet management services.
17.2 Data Processing Agreements
All third-party service providers are bound by written Data Processing Agreements (DPAs) that:
Restrict processing to specified purposes
Require compliance with the NDPA and this Privacy Policy
Mandate appropriate technical and organizational security measures
Prohibit unauthorized subcontracting
Require prompt notification of data breaches
Ensure return or destruction of data upon contract termination
17.3 Third-Party Links
The MedxGo platform may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices or content of such third parties. We encourage Users to review the privacy policies of any third-party sites they visit.
17.4 Social Media Integration
If you choose to connect your MedxGo account with social media platforms (Facebook, Google, Apple), we may receive certain information from those platforms subject to your privacy settings on those services. We do not post to your social media accounts without explicit permission.
18. INTERNATIONAL DATA TRANSFERS
18.1 Cross-Border Operations
As MedxGo expands across Africa, personal data may be transferred between Nigeria and other African countries where we operate, including but not limited to Ghana, Kenya, South Africa, Egypt, and Rwanda.
18.2 Legal Basis for International Transfers
Under Section 41 of the NDPA, international transfers of personal data are permitted where:
The recipient country has been deemed adequate by the NDPC.
Appropriate safeguards are in place, such as standard contractual clauses approved by the NDPC.
The transfer is necessary for the performance of a contract or implementation of pre-contractual measures.
The Data Subject has provided explicit consent after being informed of the risks.
The transfer is necessary for important reasons of public interest, vital interests, or legal claims.
18.3 Safeguards Implemented
All international data transfers utilize encryption and secure transmission protocols.
Standard Contractual Clauses (SCCs) approved by the NDPC are executed with all international recipients.
Data localization requirements of host countries are respected where mandated.
Regular audits are conducted to ensure ongoing compliance with transfer safeguards.
18.4 African Data Localization
MedxGo is committed to African data sovereignty. Primary data storage for Nigerian Users remains within Nigeria. Where expansion requires local data centers, we prioritize:
In-country data centers where commercially viable
Regional African cloud infrastructure over extra-continental alternatives
Compliance with local data localization laws (e.g., South Africa's POPIA, Kenya's Data Protection Act).
19. USER RIGHTS
19.1 Rights Under the NDPA
Pursuant to Sections 34 through 40 of the NDPA, Data Subjects have the following rights regarding their personal data:
Right to be Informed: The right to be informed about the collection and use of your personal data, including the purposes, legal basis, retention periods, and third-party recipients.
Right of Access: The right to obtain confirmation from MedxGo as to whether your personal data is being processed, and if so, access to that data and supplementary information.
Right to Rectification: The right to have inaccurate or incomplete personal data corrected or completed without undue delay.
Right to Erasure ("Right to be Forgotten"): The right to request the deletion of your personal data where there is no compelling reason for its continued processing, subject to legal retention requirements.
Right to Restrict Processing: The right to request the restriction of processing of your personal data in specific circumstances, such as when you contest its accuracy or object to its processing.
Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
Right to Object: The right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: The right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint: The right to lodge a complaint with the Nigeria Data Protection Commission if you believe your data protection rights have been violated.
19.2 Exercising Your Rights
To exercise any of your rights:
In-App: Navigate to Settings > Privacy > Data Rights
Email: Send a request to privacy@medxgoapp.com with the subject line "Data Rights Request"
Postal Mail: MedxGo Technologies Limited, Data Protection Officer, [Registered Address], Nigeria
Phone: +234-XXX-XXX-XXXX (Monday–Friday, 9:00 AM–5:00 PM WAT)
19.3 Response Timeline
MedxGo will respond to all data rights requests within 30 days of receipt. Complex requests or multiple requests may require an extension of up to 60 days, of which you will be notified.
19.4 Verification
To protect your privacy, we will verify your identity before processing any data rights request. This may require submission of government-issued identification or answers to security questions.
19.5 Fees
We do not charge a fee for the first request in a 12-month period. Subsequent requests or manifestly unfounded or excessive requests may incur a reasonable administrative fee.
20. NDPA COMPLIANCE
20.1 Compliance Framework
MedxGo maintains a comprehensive data protection compliance framework aligned with the Nigeria Data Protection Act 2023, including:
Appointment of a Data Protection Officer (DPO) registered with the NDPC
Maintenance of a Data Protection Impact Assessment (DPIA) register
Regular data protection training for all staff
Annual compliance audits by independent assessors
Incident response procedures compliant with NDPC guidelines
20.2 Data Protection Officer
Name: Prince Dafe-Mike Ederagobor
Email: dpo@medxgoapp.com
Phone: +234-XXX-XXX-XXXX
Registration: NDPC Registration Number [XXXXX]
The DPO is responsible for:
Monitoring compliance with the NDPA and this Privacy Policy
Providing advice on data protection obligations
Cooperating with the NDPC
Serving as the point of contact for data subjects and the NDPC
20.3 Data Protection Impact Assessments (DPIAs)
MedxGo conducts DPIAs for all high-risk processing activities, including:
Processing of Healthcare Data at scale
Use of AI (Lexi AI) for health-related recommendations
Large-scale location tracking of Riders
Integration with third-party health information systems
Introduction of new technologies or processing methods
20.4 Registration with NDPC
MedxGo is registered as a Data Controller with the Nigeria Data Protection Commission. Our registration details are available upon request and published on the NDPC public register.
20.5 Cooperation with Regulatory Authorities
MedxGo cooperates fully with the NDPC and other relevant regulatory bodies, including:
Pharmacists Council of Nigeria (PCN)
National Agency for Food and Drug Administration and Control (NAFDAC)
Corporate Affairs Commission (CAC)
Federal Competition and Consumer Protection Commission (FCCPC)
State and federal health ministries
21. SECURITY MEASURES
21.1 Technical Security Measures
MedxGo implements industry-standard technical safeguards, including:
Encryption:
AES-256 encryption for data at rest
TLS 1.3 for data in transit
End-to-end encryption for sensitive communications
Access Controls:
Role-based access control (RBAC) with principle of least privilege
Multi-factor authentication (MFA) for all administrative accounts
Biometric authentication options for Users
Regular access reviews and revocation procedures
Network Security:
Web Application Firewalls (WAF)
Intrusion Detection and Prevention Systems (IDPS)
DDoS protection and traffic filtering
Regular vulnerability scanning and penetration testing
Application Security:
Secure Software Development Lifecycle (SSDLC)
Regular code reviews and static analysis
Dependency scanning for known vulnerabilities
Bug bounty program for responsible disclosure
21.2 Organizational Security Measures
Comprehensive Information Security Policy reviewed annually
Data classification and handling procedures
Employee background checks and confidentiality agreements
Regular security awareness training and phishing simulations
Physical security controls for offices and data centers
Secure disposal procedures for hardware and media
21.3 Security Certifications
MedxGo maintains or is actively pursuing the following certifications:
ISO/IEC 27001:2013 (Information Security Management)
ISO/IEC 27701:2019 (Privacy Information Management)
PCI-DSS Level 1 (Payment Card Industry Data Security Standard)
SOC 2 Type II (Service Organization Control)
22. INCIDENT RESPONSE
22.1 Breach Notification Obligations
Under Section 40 of the NDPA, MedxGo has a legal obligation to notify the NDPC and affected Data Subjects of personal data breaches without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
22.2 Incident Response Procedure
Detection and Assessment:
24/7 security operations center (SOC) monitoring
Automated breach detection systems
Rapid assessment of breach scope, severity, and affected data subjects
Containment and Eradication:
Immediate isolation of affected systems
Forensic investigation to determine root cause
Remediation of vulnerabilities and restoration of secure operations
Notification:
Notification to NDPC within 72 hours of discovery
Notification to affected Data Subjects without undue delay where the breach poses a high risk to their rights and freedoms
Public notification where required by the NDPC or where necessary to protect Data Subjects
Post-Incident Review:
Comprehensive post-incident analysis
Identification of systemic improvements
Update of security measures and incident response plans
22.3 Breach Notification Content
Notifications will include:
Nature of the personal data breach
Categories and approximate number of affected Data Subjects
Likely consequences of the breach
Measures taken or proposed to address the breach
Contact details for further information
Recommendations for affected individuals to mitigate potential harm
23. VENDOR OBLIGATIONS
23.1 Vendor Selection and Due Diligence
All vendors, suppliers, and service providers engaged by MedxGo undergo rigorous data protection due diligence, including:
Assessment of data protection policies and practices
Review of security certifications and audit reports
Evaluation of subcontracting and international transfer practices
Background checks on key personnel
23.2 Contractual Requirements
All vendor contracts include mandatory data protection clauses requiring:
Compliance with the NDPA and this Privacy Policy
Implementation of appropriate technical and organizational measures
Confidentiality obligations for personnel with data access
Restrictions on use of MedxGo data for purposes other than contract performance
Prompt breach notification (within 24 hours of discovery)
Right to audit and inspect security controls
Return or secure destruction of data upon contract termination
Indemnification for data protection breaches caused by the vendor
23.3 Ongoing Monitoring
Annual security assessments of critical vendors
Continuous monitoring of vendor security posture
Regular review of vendor access logs and data handling practices
Termination rights for material data protection violations
24. REGULATORY COMPLIANCE
24.1 Nigerian Regulatory Framework
MedxGo complies with all applicable Nigerian laws and regulations, including:
Nigeria Data Protection Act 2023 and NDPC regulations
Pharmacists Council of Nigeria Act and PCN guidelines
National Agency for Food and Drug Administration and Control Act
Companies and Allied Matters Act 2020
Federal Competition and Consumer Protection Act 2018
Cybercrimes (Prohibition, Prevention, etc.) Act 2015
National Health Act 2014
Lagos State Health Sector Reform Law (and equivalent state laws)
Tax Regulations (FIRS, state IRS requirements)
24.2 African Expansion Compliance
As MedxGo expands to other African nations, we commit to complying with local data protection and sectoral regulations, including:
Ghana: Data Protection Act, 2012 (Act 843); Food and Drugs Authority regulations
Kenya: Data Protection Act, 2019; Pharmacy and Poisons Board guidelines
South Africa: Protection of Personal Information Act (POPIA); Health Professions Council regulations
Egypt: Personal Data Protection Law; Ministry of Health pharmaceutical regulations
Rwanda: Law No. 058/2021 on Data Protection and Privacy; Rwanda FDA guidelines
Other Jurisdictions: Applicable local data protection, health, and consumer protection laws
24.3 Regulatory Reporting
MedxGo submits required reports to regulatory authorities, including:
Annual data protection compliance reports to NDPC
Adverse drug reaction reports to NAFDAC
Financial reports to FIRS and state revenue services
Any other reports required by applicable law
25. CONTACT INFORMATION
25.1 General Inquiries
MedxGo Technologies Limited
Website: https://medxgoapp.com/
Email: privacy@medxgoapp.com
Support: support@medxgoapp.com
Phone: +234-XXX-XXX-XXXX
Business Hours: Monday–Friday, 8:00 AM–8:00 PM WAT; Saturday–Sunday, 9:00 AM–5:00 PM WAT
25.2 Data Protection Officer
Name: Prince Dafe-Mike Ederagobor
Email: dpo@medxgoapp.com
Phone: +234-XXX-XXX-XXXX
Address: Lagos, Nigeria
25.3 Regulatory Authority
Nigeria Data Protection Commission (NDPC)
Website: https://ndpc.gov.ng/
Email: info@ndpc.gov.ng
Phone: +234-XXX-XXX-XXXX
Address: Abuja, Nigeria
25.4 Complaint Resolution
If you have concerns about our data protection practices:
Contact our DPO at dpo@medxgoapp.com
If unresolved, lodge a complaint with the NDPC at info@ndpc.gov.ng
You may also seek judicial remedies under Section 55 of the NDPA
26. LEGAL NOTICES
26.1 Governing Law
This Privacy Policy and all matters arising from it are governed by the laws of the Federal Republic of Nigeria. Any disputes shall be subject to the exclusive jurisdiction of the courts of Nigeria, unless otherwise required by applicable law.
26.2 Severability
If any provision of this Privacy Policy is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be severed, and the remaining provisions shall continue in full force and effect.
26.3 No Waiver
Failure by MedxGo to enforce any right or provision of this Privacy Policy shall not constitute a waiver of such right or provision unless acknowledged and agreed to by MedxGo in writing.
26.4 Language
This Privacy Policy is drafted in English. In the event of any conflict between the English version and any translated version, the English version shall prevail.
26.5 Entire Agreement
This Privacy Policy, together with the MedxGo Terms of Service and any other referenced agreements, constitutes the entire agreement between you and MedxGo regarding the subject matter herein.
26.6 Force Majeure
MedxGo shall not be liable for any failure or delay in performing its obligations under this Privacy Policy where such failure or delay results from circumstances beyond our reasonable control, including but not limited to acts of God, war, terrorism, civil unrest, government actions, epidemics, pandemics, or technical failures of third-party infrastructure.
26.7 Assignment
MedxGo may assign its rights and obligations under this Privacy Policy to any affiliate or in connection with a merger, acquisition, or sale of assets, provided that the assignee agrees to be bound by the terms herein. Users may not assign their rights without prior written consent from MedxGo.
26.8 Copyright and Trademarks
All content on the MedxGo platform, including text, graphics, logos, and software, is the property of MedxGo Technologies Limited or its licensors and is protected by Nigerian and international intellectual property laws. The MedxGo name, logo, and Lexi AI are registered trademarks.
26.9 Electronic Communications
By using MedxGo services, you consent to receive electronic communications from us, including notices, agreements, and disclosures. You agree that such communications satisfy any legal requirement that communications be in writing.
© 2026 MedxGo Technologies Limited. All Rights Reserved.
This Privacy Policy is effective as of June 24, 2026, and supersedes all previous versions.
Document Version: 1.0
Review Date: June 24, 2027 (or earlier if required by regulatory changes)
Approved By: Board of Directors, MedxGo Technologies Limited
DPO Certification: Certified compliant with NDPA 2023 and NDPC guidelines