Privacy Policy

How IASO Medipark collects, uses, and protects your personal information.

Data Controller: IASO Medipark Limited  ·  Operated by: Iwosan Lagoon Hospital  ·  Contact: mediparkconsultants@iaso.ng

Overview

Privacy matters to IASO Medipark Limited (IASO), so we follow a privacy framework that helps us to manage and protect your information in our medical services, products, and websites. Please take the time to get to know our practices — and if you have any questions, contact us.

This Privacy Notice ("Notice") describes how we collect, use, store, handle and secure personal information (sometimes referred to as "Personal Information", "Personally Identifiable Information" or "PII") because IASO is dedicated to protecting the confidentiality and privacy of information entrusted to us by staff, customers and all stakeholders.

IASO Medipark is operated by Iwosan Lagoon Hospital, a pioneer in the field of Healthcare in Nigeria running a chain of Multi-Specialty Hospitals and other healthcare facilities in Nigeria, providing healthcare services through its hospitals owned and managed at various locations in Nigeria, and offering Diagnostic, Investigations, Consultation/Opinion, Nursing & Pharmacological, Counselling, Procedural & Surgical Treatment, Dietary Service and other Emergency Services.

Our Privacy Notice may be updated from time to time, but such updates will be reflected on our website. Your continued use of our online platforms will mean that you agree to the changes.

Privacy Notice – Scope

Our Data Protection Policy including this Privacy Notice applies to personal information processed by the Medipark as a data controller as described in this Notice. It explains what information we collect about our clients and visitors, how we use that information, who we share it with, the circumstances under which we may share it, and what steps are taken to ensure it remains private and secure. The policy also clearly outlines the rights of clients in respect of information collected in the course of their engagement with our facilities and services.

It is important to know that this policy continues to apply notwithstanding the fact that the agreement between IASO and the party using our services ends. It covers every service which customers (Private, Corporate, HMO) have with IASO.

Collection and Use of Personal Information

What We Collect

IASO obtains personal information about you if you choose to provide it — for example, to fulfil your request and to provide the requested and/or agreed services. By submitting personal information to IASO, you are acknowledging that IASO may use this information in accordance with its Data Protection Policy including this Notice. Your personal information is not used for purposes other than those listed in this document, unless we obtain your permission or unless otherwise required by law.

In general, we collect and generate the following categories of information:

Type of Personal Data Details
Personal data Such as name, surname, ID card number, face image, gender, date of birth, passport number or other identifiable numbers, CCTV in and around IASO Medipark (these may collect photos or videos of you).
Contact data Such as address, telephone number, e-mail address.
Financial data Such as billing information, credit or debit information, receipt information, invoice information.
Marketing data Such as registration information used for subscription and marketing participation, details of the services we offer and your preferences.
Technical data Such as IP address, browser type, cookie information, time zone setting, operating system, platform and technology of devices used for accessing our website and Online Appointment System.

Sources of Personal Data

IASO collects and gathers your personal data from the following sources:

  • Network health providers, where you have given consent to the network health provider for disclosure of your personal data
  • Any person, juristic person or agency of any government, private sector, or state enterprise who refers you for investigation services to IASO or is a payer for your service expense

Why We Collect It and the Legal Grounds

IASO generally collects only the personal information necessary to fulfil your request and to provide the requested and/or agreed services. The applicable law allows us to process personal information so long as we have a ground under the law to do so. When we process your personal information, we will rely on one of the following processing conditions:

  • Performance of a contract — when the processing of your personal information is necessary in order to perform our obligations under a contract or to complete our acceptance procedure
  • Legal obligation or for public interest — when we are required to process your personal information to comply with a legal obligation, such as keeping records for tax obligations, regulatory purposes, or providing information to a public body or law enforcement organisation
  • Legitimate interests — where necessary, we may process information about you where there is a legitimate interest for us or a third party with respect to your health interests, except where such interests are overridden by your interests, fundamental rights and freedoms
  • Consent — we may occasionally ask you for specific permission to process some of your personal information for specific purposes such as research and studies, and we will only process your personal information in this way if you agree

What constitutes consent? Your consent is given when you consume our services, navigate our website, tick our online forms or boxes, subscribe to our email alerts, attend our online/offline events, or when you voluntarily submit your personal data to us.

How do you withdraw your consent? You may withdraw your consent at any time by unsubscribing from our email alerts or other digital platforms, or by contacting IASO's Data Protection Officer (DPO) via mediparkconsultants@iaso.ng.

Retention of Information

We retain your personal information for as long as we have a relationship with you, subject to applicable laws and regulations. When deciding how long to keep your personal information, we consider our legal and regulatory obligations and internal personal information management policies. We retain records to investigate or defend against potential legal claims or where required by law. We will only retain your personal data for as long as, or until such time that, you request and/or exercise your right to deletion/destruction.

Storage and Security of Information

We implement and maintain organisational, technical, and administrative security measures designed to safeguard the information we process within our organisation against unauthorised access, destruction, loss, alteration, or misuse. These measures are aimed at providing ongoing integrity and confidentiality for your personal information. We evaluate and update these measures on an ongoing basis.

Your information is only accessible to personnel who need access to the information to perform their duties. However, while we take precautions to safeguard your information, we cannot guarantee the security of the networks, systems, servers, devices, and databases we operate or that are operated on our behalf.

Sharing Information

We do not share personal information with unaffiliated third parties, except if necessary for our legitimate professional and business needs, to carry out your requests, and/or as required or permitted by law. These include:

  • Service providers — IASO works with reputable partners and service providers so they can process your personal information on our behalf where required. IASO will only transfer personal information to them when they meet our standards set in our policy on the processing of data and security.
  • Courts, law enforcement or regulatory bodies — IASO may disclose personal information in order to respond to requests of courts, government or law enforcement entities, or where it is necessary to comply with applicable laws, court orders, or government regulations.
  • Audits — disclosures of personal information may also be needed for data privacy or security audits and/or to investigate or respond to a complaint or security threat.

IASO will not transfer the personal information you provide to any third parties for their own direct marketing use.

Children's Privacy

Please note that our services apply to children irrespective of age. We knowingly collect personally identifiable information from children under the age of 18 only under the strict supervision and consent of the child's parent, guardian or legal custodian.

Cookies Policy

When you visit our website, IASO uses cookies to ensure you receive a good experience. A cookie is a small file that stores information and records it onto computer devices or communication tools when you access the website via your chosen web browser.

In some instances, IASO and its service providers use cookies and other technologies to automatically collect certain types of information when you visit IASO online platforms, as well as through email exchange. The collection of this information allows IASO to customise your online experience, improve the performance, security, usability and effectiveness of IASO's online presence, and to monitor our overall activities.

Although most browsers automatically accept cookies, you can choose whether or not to accept cookies via your browser's settings (often found in your browser's Tools or Preferences menu). You may also delete cookies from your device at any time. However, please be aware that if you do not accept cookies, you may not be able to fully experience some of our website features.

Cookies by themselves do not tell us your email address or otherwise identify you personally. IASO may also collect and use the geographical location of your computer or mobile device for the purpose of providing you with information regarding services which we believe may be of interest to you based on your geographic location.

Data Subject Rights

As a personal data owner, you have the following rights to request IASO to process your personal data according to the scope allowed by applicable laws:

  • Right to withdraw consent — you have the right to withdraw your consent for personal data processing at any time throughout the period your personal data is stored at IASO
  • Right of access — you have the right to access your personal data and request IASO for a copy of that personal data, including requesting disclosure of the acquisition of your personal data you did not consent to
  • Right to rectification — you have the right to request IASO to correct incorrect data or add to incomplete data
  • Right to erasure — you have the right to request IASO to erase your data for certain reasons (depending on the circumstances and agreements in place). We may continue to process your information if another legitimate reason for doing so exists.
  • Right to restriction of processing — you have the right to request IASO to suppress the use of your personal data, for example the right to ask us not to process your personal data for marketing purposes
  • Right to data portability — you have the right to transfer your personal data maintained by IASO to other data controllers or yourself
  • Right to object — you have the right to object to your personal data processing for certain reasons

Privacy Concerns

If you have questions, requests, or complaints related to your privacy or would like to exercise your data protection rights, please contact us at mediparkconsultants@iaso.ng.