Skip to content
HealthRadar
PlatformHow it worksAbout
Request a demoLog in

Privacy policy

Last updated pending publication

HealthRadar is the visitor health-surveillance service operated by Lagos State Ministry of Health. This policy explains what personal and health data we process, why we process it, how we protect it, and the choices available to you.

On this page

  1. 01Who we are
  2. 02Scope of this policy
  3. 03Information we process
  4. 04Why we process it
  5. 05Legal basis
  6. 06AI-assisted risk evaluation
  7. 07Sharing and processors
  8. 08International transfers
  9. 09Retention
  10. 10Security
  11. 11Your rights
  12. 12Children
  13. 13Changes to this policy
  14. 14Contact and data protection officer
On this page
  1. Who we are
  2. Scope of this policy
  3. Information we process
  4. Why we process it
  5. Legal basis
  6. AI-assisted risk evaluation
  7. Sharing and processors
  8. International transfers
  9. Retention
  10. Security
  11. Your rights
  12. Children
  13. Changes to this policy
  14. Contact and data protection officer

01

Who we are

HealthRadar is operated by Lagos State Ministry of Health, which is the data controller for the processing described here. We use "we" and "us" in this policy to mean the controller.

02

Scope of this policy

This policy covers the HealthRadar public website, the staff console, and the WhatsApp, SMS, and email messages we send to people under monitoring. It does not cover third-party websites or services that we link to.

03

Information we process

In the course of health surveillance we process:

  • Identity and contact: full name, sex, date of birth, passport or national ID number, phone number, and email address.
  • Travel and visit: origin and nationality country, arrival and departure dates, port of entry, flight number, purpose of visit, and locality of stay.
  • Health: your answers to daily check-in questionnaires, symptoms you report, medical conditions you disclose, and any accessibility requirements you tell us about.
  • Messaging and delivery: the messages we send and receive, delivery status, timestamps, and the channel you opted into.
  • Staff accounts: name, work email, phone number, role, and authentication and audit records.

Some of these fields are encrypted at rest, as described in the Security section. Where a connected source system sends us additional fields, we store the source record as received.

04

Why we process it

  • Screen arrivals from high-risk origins and decide who enters monitoring.
  • Send daily health check-ins over WhatsApp, SMS, or email.
  • Evaluate responses and triage cases that need a person.
  • Alert authorised health officials and coordinate referral.
  • Keep an audit trail of access and actions.
  • Operate, secure, and improve the service.

05

Legal basis

We process personal data under the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive (GAID) 2025. Our main legal bases are:

  • Public interest and public health: monitoring and responding to health risks at population level.
  • Legal obligation: public-health and disease-surveillance record-keeping and reporting.
  • Vital interests: protecting life where a case needs urgent clinical follow-up.
  • Consent: where we rely on it, such as your WhatsApp opt-in, you can withdraw it at any time without affecting monitoring required by law.

Where we process health data, we do so for public-health purposes and treat it as sensitive personal data.

06

AI-assisted risk evaluation

When you reply to a check-in, your answers are parsed and scored by deterministic rules, then classified by an AI provider. The AI provider receives the disease context, your answers, and your origin country. It does not receive your name, passport or national ID number, date of birth, phone number, email address, or address.

The more severe of the AI result and the rule score sets the risk level. AI assists triage only. It does not diagnose disease and does not replace a clinician, who makes the follow-up decision.

07

Sharing and processors

We do not sell personal data. We share it only with:

  • Authorised public-health officials and designated referral facilities acting on the surveillance programme.
  • Service providers that process data on our behalf under contract: messaging providers (WhatsApp and SMS), email delivery providers, an AI risk-scoring provider, and managed hosting and database providers.

We may disclose data where the law requires it.

08

International transfers

Some providers may process data outside Nigeria. Where that happens, we transfer data only under a lawful transfer mechanism and with the safeguards required by the NDPA 2023 and NDPC guidance. You can ask us for the current processor categories and the countries involved.

09

Retention

We keep monitoring records for the active surveillance window and for any further period required by public-health and record-keeping rules. When that period ends, we delete or anonymise the data. Audit records are kept longer so we can demonstrate accountability. Retention is applied as part of programme operations and reviewed periodically.

10

Security

  • Field-level encryption at rest (AES-256-GCM) for names, passport and national ID numbers, email addresses, dates of birth, and contact numbers.
  • One-way hashes for lookup and de-duplication, so search does not expose the underlying value.
  • Encryption in transit for data sent between your device and the service.
  • Role-based access, least privilege, and short-lived sessions for staff.
  • Append-only audit logging of access and material actions.
  • Geographic intelligence aggregated to local government area or community level, never individual locations.

11

Your rights

Under the NDPA 2023 you have the right to:

  • be informed about how we use your data;
  • access the personal data we hold about you;
  • ask us to correct inaccurate data;
  • ask us to delete or restrict data, where the law allows;
  • object to processing, where the law allows;
  • withdraw consent where processing relies on it;
  • lodge a complaint with the Nigeria Data Protection Commission.

Public-health and record-keeping obligations can limit some of these rights. We will tell you if that applies and why. To exercise a right, use the request path on the Your data rights page or email us.

12

Children

The service monitors travellers of all ages where public-health rules require it. We do not profile children and we do not use their data for marketing. Where a child is under monitoring, a parent or guardian can exercise the child's rights on their behalf.

13

Changes to this policy

We may update this policy. When we do, we change the last-updated date and, for material changes, tell affected users through the channels we already use.

14

Contact and data protection officer

For privacy questions, requests, or complaints, contact hello@healthradar.health or use the contact form. If your request concerns a data-protection right, please say so in the subject line.

HealthRadar

Visitor health surveillance for public-health authorities: ingest arrivals, run daily WhatsApp and SMS check-ins, evaluate risk, and coordinate case response.

hello@healthradar.health

Product

  • Platform
  • How it works
  • About
  • Request a demo

Legal

  • Privacy
  • Terms
  • Cookies
  • Your data rights
  • Accessibility
  • Security

© 2026 HealthRadar, a Lagos State Bioshield service. Monitoring, triage, and response, not clinical diagnosis.

Staff sign in