Back to AIMS

AIMS privacy policy

Privacy Policy

Initial market: Nigeria. Effective date: May 31, 2026. Last updated: May 31, 2026.

AIMS is designed to help patients, providers, and care teams coordinate healthcare with privacy, security, and appropriate access controls in mind. AIMS uses a HIPAA-grade privacy and security posture while supporting initial use in Nigeria and future international expansion.

1. Who this policy is for

This policy explains how AIMS may collect, use, disclose, retain, and protect information when patients, caregivers, providers, care teams, administrators, and visitors use AIMS websites, applications, and related services.

AIMS is initially intended for use in Nigeria and is designed with healthcare privacy and security expectations that align with HIPAA-grade practices, the Nigeria Data Protection Act, 2023, and other applicable healthcare, consumer protection, cybersecurity, telecommunications, and professional obligations.

AIMS may later expand to other countries. When AIMS operates outside Nigeria, additional privacy notices, country-specific terms, data transfer safeguards, consent requirements, or healthcare privacy obligations may apply, including HIPAA in the United States where AIMS acts for covered entities or business associates.

This policy does not replace any privacy notice, consent form, patient rights document, or professional duty maintained by a hospital, clinic, provider, health maintenance organization, insurer, employer, public authority, or other organization using AIMS.

2. Information we may collect

Account and identity information, such as name, email address, phone number, role, organization, credentials, authentication details, and account recovery information.

Health and care coordination information, such as appointments, care plans, medications, reminders, messages, provider relationships, insurance or payment workflow details, and other information entered into supported product workflows.

Provider and professional information, such as practice details, specialty, license-related information, availability, care team assignments, and provider profile content.

Device, usage, and security information, such as IP address, browser type, device identifiers, log data, session activity, audit events, cookie or similar technology data, and information used to protect accounts and detect misuse.

Communications with AIMS, including support requests, feedback, administrative messages, and other correspondence.

3. How we use information

To provide, operate, maintain, and improve AIMS services, including patient dashboards, provider workflows, appointments, care plans, messaging, reminders, account recovery, and support.

To authenticate users, verify account ownership, enforce access controls, protect sessions, prevent fraud or abuse, and maintain audit logs.

To support treatment, payment, healthcare operations, and other permitted healthcare workflows where authorized by applicable law, contract, user role, or provider direction.

To communicate service updates, security notices, account messages, support responses, and other operational information.

To develop and improve product quality, reliability, accessibility, safety, and security using information in a manner consistent with applicable contracts and laws.

4. How information may be shared

With your healthcare providers, care teams, authorized caregivers, or organizations when needed to provide the AIMS services or when you direct or authorize the sharing.

With vendors and service providers that help operate AIMS, such as hosting, authentication, analytics, communications, security, support, and infrastructure providers, subject to appropriate contractual, privacy, and security safeguards.

With an organization that sponsors, administers, or manages your AIMS access, such as a provider group, clinic, or healthcare organization, consistent with your role and applicable agreements.

When required or permitted by law, legal process, regulatory request, safety obligation, security investigation, or to protect the rights, privacy, safety, or security of AIMS, users, providers, or others.

In connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, or transfer of assets, subject to appropriate confidentiality and continuity protections.

5. Health information, HIPAA-grade safeguards, and Nigeria privacy law

AIMS is designed to support privacy-conscious healthcare workflows in Nigeria. Public pages are intended for general product information and should not be used to submit personal health information or other sensitive personal data.

AIMS applies a health-information-first approach that emphasizes minimum necessary access, role-based permissions, secure transmission, auditability, confidentiality, integrity, availability, and appropriate administrative, technical, and physical safeguards.

Where HIPAA applies, AIMS will use and disclose protected health information only as permitted by applicable law, contract, business associate obligations, user role, provider direction, or patient authorization.

Where the Nigeria Data Protection Act, 2023 applies, AIMS processes personal data in a fair, lawful, transparent, and accountable manner and supports data subject rights, appropriate notices, security safeguards, breach response, retention controls, and applicable controller or processor obligations.

Health information, biometric identifiers, account credentials, and other sensitive information should be handled only through supported AIMS workflows and only where there is an appropriate lawful basis, authorization, contract, consent, legal obligation, vital interest, public interest, healthcare purpose, or other legally permitted ground.

Users should only access information they are authorized to view and should not enter, upload, or share sensitive information outside approved AIMS workflows.

6. Security

AIMS uses reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, and loss.

Security controls may include encryption in transit, access controls, authentication, audit logging, vulnerability management, monitoring, secure development practices, and incident response procedures.

No system can be guaranteed to be completely secure. Users are responsible for protecting their credentials, using supported devices and browsers, and promptly reporting suspected unauthorized access.

7. Your choices and rights

Depending on your location, role, relationship with AIMS, and applicable law, you may have rights to be informed, access your personal data, request correction, request deletion, restrict or object to processing, request portability, withdraw consent where consent is the lawful basis, and complain to a supervisory authority.

For users in Nigeria, privacy rights and remedies may be available under the Nigeria Data Protection Act, 2023 and guidance from the Nigeria Data Protection Commission.

If your information is held by a healthcare provider, clinic, hospital, insurer, or organization through AIMS, requests involving health information may need to be directed to that organization or handled according to that organization's privacy notice and professional obligations.

AIMS will not display whether an account exists during account recovery or password reset flows. Recovery details are used to help match a verified account and route reset or retrieval instructions through an approved channel.

8. Cookies and analytics

AIMS may use cookies, local storage, and similar technologies to keep users signed in, remember preferences, protect sessions, measure performance, understand usage, and improve reliability.

Where required, AIMS will provide applicable notices or choices for non-essential cookies and analytics technologies.

9. Retention

AIMS retains information for as long as needed to provide services, maintain security and audit records, comply with legal and contractual obligations, resolve disputes, and support legitimate business and healthcare operations.

Retention periods may vary based on the type of information, user role, provider requirements, contractual commitments, and applicable law.

10. Children and caregivers

AIMS may support care coordination involving minors or dependents only through authorized workflows and appropriate provider, parent, guardian, caregiver, or organizational permissions.

Users should not create accounts for children or submit information about minors unless they are authorized to do so and the workflow is supported by AIMS.

11. International use

AIMS is initially intended for use in Nigeria. If AIMS expands globally or allows users, providers, vendors, or infrastructure outside Nigeria, privacy rights, healthcare rules, data localization requirements, and cross-border transfer safeguards may vary by country.

As AIMS expands, it will apply additional country-specific requirements where required, including lawful basis, consent, localization, international transfer mechanisms, supervisory authority notices, patient rights, and healthcare-sector requirements.

12. Changes to this policy

AIMS may update this policy from time to time. Material changes may be communicated through the product, email, or other appropriate channels.

13. Contact

Questions, privacy requests, or security concerns should be directed to the AIMS privacy or compliance contact made available through the service, your account, or your healthcare organization.

If your request concerns information maintained by a healthcare provider, clinic, hospital, insurer, employer, or other organization using AIMS, AIMS may direct you to that organization so the request can be handled by the appropriate data controller, healthcare provider, or responsible party.