Back to home

Legal

Privacy Policy

Last updated 12 September 2026

Effective Date: 12 September 2026
Last Updated: 12 September 2026

This Privacy Policy explains how MedOasis Health Technologies (“MedOasis,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal information when you use the MedOasis website, network, marketplace, forms, communications channels, and related services.

MedOasis processes personal data in accordance with applicable Nigerian data-protection requirements, including the Nigeria Data Protection Act 2023 (“NDPA”) and applicable guidance issued by the Nigeria Data Protection Commission (“NDPC”).

1. Who We Are

MedOasis is a technology-enabled medicine sourcing and transaction facilitation platform operating from Nigeria.

For personal data processing carried out through MedOasis, MedOasis Health Technologies acts as the relevant data controller or processor depending on the nature of the processing activity.

For questions about privacy or your personal data, contact:

Email: medoasishealth@gmail.com
Address: Lagos, Nigeria

2. Information We Collect

Depending on how you interact with MedOasis, we may collect:

Information you provide

This may include:

  • full name;
  • telephone number and WhatsApp number;
  • email address;
  • state and location information;
  • account information;
  • professional or business information;
  • pharmacy or supplier information;
  • licensing or credential information;
  • medicine requests;
  • prescription-related information where required;
  • transaction information;
  • delivery information;
  • communications with MedOasis; and
  • information submitted during verification or onboarding.

Information collected automatically

We may collect technical information such as:

  • IP address;
  • browser and device information;
  • operating system;
  • pages visited;
  • timestamps;
  • referring pages;
  • cookies and similar technologies; and
  • security and usage information.

3. Health and Sensitive Information

Medicine requests, prescriptions, and information relating to a person's health may constitute sensitive personal data.

We will only process such information where there is a lawful basis and where the processing is necessary for the relevant service, transaction, compliance, safety, or other permitted purpose.

Users should avoid submitting unnecessary health information.

4. How We Use Personal Information

We may use personal information to:

  • create and administer accounts;
  • verify users and participating suppliers;
  • process medicine requests;
  • connect eligible buyers and suppliers;
  • facilitate transactions;
  • coordinate delivery;
  • manage payment and transaction records;
  • investigate disputes;
  • detect fraud, abuse, and suspicious activity;
  • communicate with users;
  • provide customer support;
  • maintain platform security;
  • improve our services;
  • comply with legal and regulatory obligations;
  • maintain required business records; and
  • protect the rights, safety, and legitimate interests of MedOasis and platform participants.

We will not use personal information for purposes incompatible with the purpose for which it was collected unless permitted or required by law.

5. Legal Basis for Processing

Depending on the circumstances, MedOasis may rely on one or more lawful bases recognized under applicable data-protection law, including:

  • consent;
  • performance of a contract or steps requested before entering into a contract;
  • compliance with a legal obligation;
  • protection of vital interests;
  • performance of a task carried out in the public interest where applicable; and
  • legitimate interests, where permitted and appropriately balanced against the rights of the data subject.

Where processing is based on consent, you may withdraw consent where legally applicable.

Withdrawal of consent does not affect processing already carried out lawfully before withdrawal.

6. Who We May Share Information With

We may disclose personal information where reasonably necessary to provide MedOasis services or comply with applicable law.

Recipients may include:

  • participating pharmacies and suppliers;
  • authorized representatives;
  • payment or escrow providers;
  • logistics and delivery providers;
  • identity and credential verification providers;
  • technology and hosting providers;
  • professional advisers;
  • auditors;
  • regulators and government authorities where required;
  • law-enforcement authorities where legally required; and
  • other service providers acting on our behalf.

We do not sell personal information as a commercial data product.

Where information is shared with a third party, we will seek to ensure that appropriate contractual, technical, organizational, and legal safeguards apply where required.

7. Supplier and Buyer Visibility

MedOasis is designed to facilitate connections between eligible platform participants.

Depending on the transaction or service involved, certain information may need to be shared with another participant, such as:

  • name;
  • contact information;
  • medicine request information;
  • delivery information; or
  • information reasonably required to complete or support a transaction.

We will seek to limit shared information to what is reasonably necessary for the relevant purpose.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • the nature of the information;
  • the purpose of processing;
  • whether an account or transaction remains active;
  • legal or regulatory obligations;
  • dispute-resolution requirements; and
  • security or fraud-prevention requirements.

Where information is no longer required, we will take appropriate steps to delete, anonymize, or securely dispose of it, subject to applicable retention obligations.

9. Data Security

We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

No internet-based system can be guaranteed to be completely secure.

Users are responsible for protecting passwords, authentication information, and other credentials associated with their accounts.

10. Cookies and Similar Technologies

MedOasis may use cookies and similar technologies to:

  • operate the website;
  • remember preferences;
  • understand website usage;
  • improve performance;
  • maintain security; and
  • support analytics or other legitimate website functions.

Where required, we will request appropriate consent for non-essential cookies.

11. Your Data Protection Rights

Subject to applicable law and any lawful limitations, you may have rights including the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete information;
  • request deletion in appropriate circumstances;
  • request restriction of processing in appropriate circumstances;
  • object to certain processing;
  • request portability where applicable;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with the relevant data-protection authority.

To exercise a right, contact us using the details below.

We may need to verify your identity before processing a request.

12. Direct Marketing

Where required, MedOasis will obtain appropriate consent before sending direct marketing communications.

You may opt out of marketing communications at any time.

You may still receive service-related communications necessary to administer your account, transactions, requests, security, or other services.

13. Children's Data

MedOasis is not intended to be used independently by children.

Where a service involves a minor's personal information, the relevant parent, guardian, healthcare professional, or other authorized person should ensure that the information is provided and processed lawfully.

14. International Data Transfers

Some service providers used by MedOasis may process information outside Nigeria.

Where personal information is transferred internationally, MedOasis will apply the safeguards required by applicable data-protection law.

15. Data Breaches

Where a personal-data breach occurs, MedOasis will assess and respond to it in accordance with applicable legal and regulatory requirements, including notification obligations where applicable.

16. Third-Party Websites and Services

MedOasis may contain links or integrations with third-party websites and services.

Their privacy practices are governed by their own policies.

We encourage users to review those policies before providing personal information.

17. Changes to this Policy

We may update this Privacy Policy from time to time.

The updated version will be published on this page with a revised “Last Updated” date.

Where required by law, we will provide additional notice or obtain consent.

18. Contact and Complaints

For privacy questions, requests, or complaints, contact:

MedOasis Privacy Team
Email: medoasishealth@gmail.com
Address: Lagos, Nigeria

If you are dissatisfied with our response, you may have the right to lodge a complaint with the Nigeria Data Protection Commission.

19. Consent

Where MedOasis relies on consent for a particular processing activity, consent will be requested separately and will not be assumed merely because you use the website.