Privacy policy
Last updated pending publication
HealthRadar is the visitor health-surveillance service operated by Lagos State Ministry of Health. This policy explains what personal and health data we process, why we process it, how we protect it, and the choices available to you.
On this page
01
Who we are
HealthRadar is operated by Lagos State Ministry of Health, which is the data controller for the processing described here. We use "we" and "us" in this policy to mean the controller.
02
Scope of this policy
This policy covers the HealthRadar public website, the staff console, and the WhatsApp, SMS, and email messages we send to people under monitoring. It does not cover third-party websites or services that we link to.
03
Information we process
In the course of health surveillance we process:
- Identity and contact: full name, sex, date of birth, passport or national ID number, phone number, and email address.
- Travel and visit: origin and nationality country, arrival and departure dates, port of entry, flight number, purpose of visit, and locality of stay.
- Health: your answers to daily check-in questionnaires, symptoms you report, medical conditions you disclose, and any accessibility requirements you tell us about.
- Messaging and delivery: the messages we send and receive, delivery status, timestamps, and the channel you opted into.
- Staff accounts: name, work email, phone number, role, and authentication and audit records.
Some of these fields are encrypted at rest, as described in the Security section. Where a connected source system sends us additional fields, we store the source record as received.
04
Why we process it
- Screen arrivals from high-risk origins and decide who enters monitoring.
- Send daily health check-ins over WhatsApp, SMS, or email.
- Evaluate responses and triage cases that need a person.
- Alert authorised health officials and coordinate referral.
- Keep an audit trail of access and actions.
- Operate, secure, and improve the service.
05
Legal basis
We process personal data under the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive (GAID) 2025. Our main legal bases are:
- Public interest and public health: monitoring and responding to health risks at population level.
- Legal obligation: public-health and disease-surveillance record-keeping and reporting.
- Vital interests: protecting life where a case needs urgent clinical follow-up.
- Consent: where we rely on it, such as your WhatsApp opt-in, you can withdraw it at any time without affecting monitoring required by law.
Where we process health data, we do so for public-health purposes and treat it as sensitive personal data.
06
AI-assisted risk evaluation
When you reply to a check-in, your answers are parsed and scored by deterministic rules, then classified by an AI provider. The AI provider receives the disease context, your answers, and your origin country. It does not receive your name, passport or national ID number, date of birth, phone number, email address, or address.
The more severe of the AI result and the rule score sets the risk level. AI assists triage only. It does not diagnose disease and does not replace a clinician, who makes the follow-up decision.
08
International transfers
Some providers may process data outside Nigeria. Where that happens, we transfer data only under a lawful transfer mechanism and with the safeguards required by the NDPA 2023 and NDPC guidance. You can ask us for the current processor categories and the countries involved.
09
Retention
We keep monitoring records for the active surveillance window and for any further period required by public-health and record-keeping rules. When that period ends, we delete or anonymise the data. Audit records are kept longer so we can demonstrate accountability. Retention is applied as part of programme operations and reviewed periodically.
10
Security
- Field-level encryption at rest (AES-256-GCM) for names, passport and national ID numbers, email addresses, dates of birth, and contact numbers.
- One-way hashes for lookup and de-duplication, so search does not expose the underlying value.
- Encryption in transit for data sent between your device and the service.
- Role-based access, least privilege, and short-lived sessions for staff.
- Append-only audit logging of access and material actions.
- Geographic intelligence aggregated to local government area or community level, never individual locations.
11
Your rights
Under the NDPA 2023 you have the right to:
- be informed about how we use your data;
- access the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to delete or restrict data, where the law allows;
- object to processing, where the law allows;
- withdraw consent where processing relies on it;
- lodge a complaint with the Nigeria Data Protection Commission.
Public-health and record-keeping obligations can limit some of these rights. We will tell you if that applies and why. To exercise a right, use the request path on the Your data rights page or email us.
12
Children
The service monitors travellers of all ages where public-health rules require it. We do not profile children and we do not use their data for marketing. Where a child is under monitoring, a parent or guardian can exercise the child's rights on their behalf.
13
Changes to this policy
We may update this policy. When we do, we change the last-updated date and, for material changes, tell affected users through the channels we already use.
14
Contact and data protection officer
For privacy questions, requests, or complaints, contact hello@healthradar.health or use the contact form. If your request concerns a data-protection right, please say so in the subject line.