HealOSPatient

Legal

Privacy policy

How HealOS Patient collects, uses and protects your personal and health information.

Last updated 6 August 2026 · Applies to the HealOS Patient mobile app and this website.

1. Who we are

HealOS Patient is operated by DORM Limited (“we”, “us”), a company registered in Nigeria. We build and run the HealOS platform, which hospitals use to keep electronic medical records, and this app, which lets patients of those hospitals see their own record.

If you have a question about this policy or about your data, write to greatattai442@gmail.com.

2. Your hospital’s role

This is the most important thing to understand about your data, so we’ve put it near the top.

Your clinical record — diagnoses, clinical notes, lab results, prescriptions, admissions — belongs to and is controlled by the hospital treating you. That hospital decides what goes into your record, who on its staff may read it, and how long it must be kept under Nigerian medical-records law. We host and process that data on the hospital’s behalf.

Your app account — your login, the vitals you record yourself, your emergency contacts, your reminders, your device settings — is controlled by us so that we can provide the app to you.

In practice: if you want a clinical entry corrected or removed, that request goes to your hospital, because we are not permitted to alter a medical record on our own. If you want your app account closed, that request comes to us. Here’s how to do that.

3. What we collect

Information you give us

  • Account details: your name, email address, date of birth and gender. Optionally a phone number, home address, blood type and genotype.
  • Profile photo, if you choose to add one.
  • Vitals you record: blood pressure, blood sugar, weight and any note you attach to a reading.
  • Emergency contacts: the name, relationship, phone number and optional email of the people you nominate. Please only add someone who is content for you to share their details with us.
  • Health documents you upload, and any advance directive or living will you record.
  • Insurance details you enter.
  • Messages you send during a video consultation, and questions you put to the in-app assistant.

Information from your hospital

  • Your visit and admission history, clinical notes and doctor’s summaries.
  • Lab and diagnostic test results.
  • Medications prescribed and dispensed to you.
  • Vitals recorded by clinical staff.
  • Billing statements and your hospital wallet balance.

Information collected automatically

  • Device and app data: a push-notification token, device name, operating system and app version, so notifications reach the right phone.
  • Access records: a log of when your chart is opened and by whom. You can read this log yourself in the app.
  • Approximate or precise location — only at the moment you press the Emergency button. See device permissions.

4. How we use it

  • To show you your medical record and keep it in sync with your hospital.
  • To let you record vitals and pass them to your care team as patient-reported readings.
  • To connect video consultations between you and your clinicians.
  • To send the reminders and notifications you’ve asked for.
  • To generate the QR code that identifies you at a hospital desk.
  • To find nearby hospitals with available beds when you use the Emergency button.
  • To process hospital wallet top-ups and show you billing statements.
  • To keep the service secure, investigate abuse, and fix faults.
  • To meet legal, regulatory and medical record-keeping obligations.

We do not sell your data. We do not use your health information for advertising, and we do not share it with advertisers or data brokers.

5. Legal basis for processing

Where the Nigeria Data Protection Act and, for users in Europe, the GDPR apply, we rely on the following grounds:

PurposeBasis
Providing the app to you under our termsPerformance of a contract
Handling health informationYour explicit consent, and the provision of health care by or under the responsibility of a health professional
Location at the Emergency buttonYour consent, given by the system permission prompt, and your vital interests
Security, fraud prevention, service improvementOur legitimate interests
Medical record retentionCompliance with a legal obligation

Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect processing already carried out, and some features will stop working without it.

6. Who we share with

We share your information only with the following, and only for the purposes described.

RecipientWhat they receiveWhy
Your hospital and its clinical staffYour record, and vitals you logTo treat you. Staff access is recorded in your access log.
Anyone you grant a share linkRead access to your record, for one hourBecause you chose to share it. The link expires automatically.
MongoDB AtlasHosts our databaseStorage of the platform’s data
CloudinaryProfile photos and uploaded documentsImage and file storage and delivery
PaystackPayment details you enter at checkout, and transaction amountsTo process wallet top-ups. Card details go to Paystack, not to us.
OpenRouter and the model providers it routes toThe excerpt of your record relevant to a question you ask the assistantTo generate the assistant’s answer. See section 7.
Apple and Google push servicesA device token and the notification textTo deliver reminders and call alerts
Emergency responders, where you have granted emergency accessThe parts of your record you allowedTo treat you in an emergency

We may also disclose information where the law requires it, where a court orders it, or where it is necessary to protect someone’s life.

7. The AI assistant

The app includes an assistant that answers questions about your own record in plain language. To do that, the relevant part of your record is sent to a third-party language model provider, currently routed through OpenRouter, and the answer is returned to you.

If you would rather your health information never left our systems for this purpose, do not use the assistant. Every other feature in the app works without it.

The assistant explains what is already in your chart. It does not diagnose, prescribe or replace advice from your clinician, and you should not rely on it in an emergency.

8. Device permissions

PermissionWhen it’s used
CameraOnly during a video consultation you join.
MicrophoneOnly during a video or audio consultation you join.
Location, while using the appOnly when you press the Emergency button, to rank nearby hospitals by distance. We do not track your location in the background.
Notifications and alarmsTo deliver medication and vitals reminders you set, and to alert you to an incoming call.

You can withdraw any of these in your device settings. The related feature will stop working, but the rest of the app will not.

9. How long we keep it

  • Clinical records are kept for as long as your hospital is required to keep them under Nigerian law and its own retention policy. We cannot delete these on your request alone; see section 2.
  • Your app account and profile are deleted when you close your account, other than records we must keep for legal, billing or audit reasons.
  • Access logs are retained as an audit record, because their whole purpose is to show historic access.
  • Share links expire one hour after creation.

10. Your rights

Subject to the limits described above, you may ask us to:

  • give you a copy of the personal data we hold about you;
  • correct data that is wrong or incomplete;
  • delete your app account and associated profile data;
  • restrict or object to certain processing;
  • withdraw a consent you previously gave;
  • receive your data in a portable format.

Write to greatattai442@gmail.com and we will respond within 30 days. If you are not satisfied, you may complain to the Nigeria Data Protection Commission, or to your local supervisory authority if you are in the EU or UK.

11. Security

We protect your information with, among other measures:

  • encryption of all traffic between the app and our servers using HTTPS;
  • passkey sign-in, so you can use Face ID or Touch ID instead of a password, and hashed storage of passwords where you use one;
  • role-based access controls, so hospital staff see only what their role permits;
  • an access log you can inspect yourself;
  • short-lived, self-expiring share links.

No system is perfectly secure. If a breach affects your data and is likely to put your rights at risk, we will tell you and the relevant regulator as the law requires.

12. Children

The app is intended for people aged 16 and over. A parent or legal guardian may hold an account on behalf of a child in their care, and is responsible for that account. If you believe a child has registered without appropriate consent, contact us and we will remove the account.

13. International transfers

Some of the providers listed in section 6 store or process data outside Nigeria. Where that happens, we rely on the safeguards those providers offer, including standard contractual clauses and their own regulatory commitments, to keep your data protected to an equivalent standard.

14. Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how your health information is handled, we will tell you in the app before it takes effect.

15. Contact us

DORM Limited
Email: greatattai442@gmail.com

For anything concerning the content of your clinical record, contact the medical records department of the hospital treating you.