Legal

Privacy Policy

How Celia Med collects, uses, stores, shares, and protects personal information across our website and healthcare platform.

Effective Date: August 27, 2026
Last Updated: August 27, 2026

1. Introduction

Celia Med ("Celia Med", "we", "us", or "our") provides digital healthcare technology that helps hospitals, clinics, diagnostic centres, pharmacies, and other healthcare organisations manage patient care and healthcare operations.

We recognise that health information is sensitive and should be handled with appropriate confidentiality, security, and accountability.

This Privacy Policy explains how personal information may be collected, used, stored, shared, protected, and otherwise processed when you:

  • visit celiamed.com;
  • communicate with Celia Med;
  • use the Celia Med platform;
  • access Celia Med through a healthcare organisation;
  • use a Celia Med patient-facing service or patient portal;
  • interact with a healthcare organisation that uses Celia Med; or
  • otherwise interact with our products and services.

This Policy should be read together with any privacy notice provided by the hospital, clinic, or healthcare organisation responsible for your care.

2. About Celia Med

Celia Med is a healthcare management platform designed to support connected clinical and administrative workflows.

Depending on the services enabled by a healthcare organisation, Celia Med may support functions including:

  • patient registration;
  • appointment scheduling;
  • queue management;
  • vital signs and nursing workflows;
  • consultations;
  • clinical documentation;
  • laboratory services;
  • imaging and diagnostic workflows;
  • pharmacy;
  • prescriptions and medication management;
  • billing and payments;
  • inventory;
  • admissions;
  • ward and bed management;
  • inpatient clinical records;
  • discharge;
  • patient portals;
  • reporting;
  • staff management;
  • role and permission management;
  • audit logging; and
  • related healthcare and administrative operations.

The exact features available depend on the healthcare organisation, its configuration, and the Celia Med services it uses.

3. Scope of This Privacy Policy

This Privacy Policy applies to personal information processed by Celia Med in connection with:

  • our website;
  • our healthcare platform;
  • patient-facing services;
  • customer support;
  • business enquiries;
  • account administration;
  • security operations; and
  • related services.

It does not replace the privacy responsibilities of a hospital, clinic, or other healthcare provider using Celia Med.

Healthcare organisations may provide their own privacy notices explaining how they collect and use patient information.

4. Who Is Responsible for Your Information?

The organisation responsible for your personal information depends on how Celia Med is being used.

4.1 Healthcare Organisations

When a hospital, clinic, diagnostic centre, pharmacy, or other healthcare organisation uses Celia Med to provide healthcare services, that organisation generally determines:

  • why patient information is collected;
  • what information is required;
  • how the information is used;
  • who may access it;
  • when it may be shared;
  • how long it should be retained; and
  • the lawful basis for processing it.

In these circumstances, the healthcare organisation generally acts as the Data Controller, while Celia Med generally processes the information on its behalf as a Data Processor.

Questions about your medical record, diagnosis, treatment, prescriptions, laboratory results, or other healthcare information should normally be directed to the healthcare organisation responsible for your care.

4.2 Celia Med

Celia Med may act as a Data Controller where we independently determine why and how personal information is processed.

This may include processing relating to:

  • visitors to celiamed.com;
  • customer and business enquiries;
  • Celia Med subscriptions;
  • account administration;
  • customer support;
  • security;
  • fraud and abuse prevention;
  • regulatory compliance;
  • Celia Med financial records; and
  • our own business operations.

5. Applicable Data Protection Requirements

Celia Med seeks to process personal information in accordance with applicable privacy and healthcare requirements.

For services provided in Nigeria, these may include, where applicable:

  • the Nigeria Data Protection Act 2023;
  • applicable regulations, directives, and guidance issued by the Nigeria Data Protection Commission;
  • relevant healthcare confidentiality requirements;
  • applicable provisions of Nigerian healthcare legislation;
  • applicable cybersecurity requirements; and
  • other relevant laws governing digital services and healthcare information.

Where Celia Med provides services in another jurisdiction, additional privacy or healthcare requirements may apply.

Nothing in this Policy should be interpreted as claiming that Celia Med holds a certification, accreditation, or regulatory status that it has not actually obtained.

6. Information We May Process

The information processed through Celia Med depends on how the platform is used.

6.1 Identification and Demographic Information

This may include:

  • full name;
  • patient or medical record number;
  • date of birth;
  • age;
  • sex or gender where relevant to healthcare;
  • photograph;
  • address;
  • telephone number;
  • email address;
  • emergency contact information;
  • next-of-kin information; and
  • other information used to identify a patient or user.

6.2 Health and Clinical Information

Healthcare organisations may process health information through Celia Med including:

  • presenting complaints;
  • symptoms;
  • diagnoses;
  • medical history;
  • surgical history;
  • allergies;
  • medications;
  • prescriptions;
  • vital signs;
  • consultation notes;
  • nursing documentation;
  • treatment plans;
  • laboratory requests and results;
  • imaging and diagnostic information;
  • procedures;
  • clinical orders;
  • medication administration;
  • admission information;
  • ward and bed information;
  • care plans;
  • monitoring information;
  • discharge information;
  • referral information; and
  • other information necessary for healthcare delivery.

Health information may constitute sensitive personal data under applicable law.

6.3 Appointment and Encounter Information

This may include:

  • appointment dates and times;
  • departments;
  • healthcare professionals;
  • visit status;
  • reason for attendance;
  • queue information;
  • referrals; and
  • healthcare encounter history.

6.4 Billing and Financial Information

Depending on the healthcare organisation's configuration, information may include:

  • invoices;
  • charges;
  • discounts;
  • payment amounts;
  • outstanding balances;
  • payment status;
  • transaction references;
  • insurance information;
  • HMO or health-plan information; and
  • related financial records.

Where third-party payment services are used, certain payment information may be processed directly by the payment provider rather than stored by Celia Med.

6.5 Healthcare Personnel Information

For healthcare and administrative users, we may process:

  • name;
  • email address;
  • telephone number;
  • staff identifier;
  • professional role;
  • department;
  • healthcare organisation;
  • branch;
  • account status;
  • permissions; and
  • activities performed through Celia Med.

6.6 Authentication, Security, and Technical Information

We may process information including:

  • account identifiers;
  • authentication information;
  • login activity;
  • session information;
  • IP address;
  • browser information;
  • device information;
  • account-security events;
  • access logs;
  • error information; and
  • other technical information necessary to provide and protect the Services.

6.7 Google Sign-In and Google User Data

Where Celia Med offers Sign in with Google or another Google authentication option, you may choose to use your Google Account to create, access, or connect your Celia Med account.

When you use Google Sign-In, Celia Med may receive the following information from Google, where available and authorised through the Google authentication process:

  • your name;
  • your email address;
  • your Google profile image; and
  • your unique Google Account identifier.

Celia Med uses this Google user data only as reasonably necessary to:

  • authenticate your identity;
  • create, connect, or maintain your Celia Med account;
  • enable secure access to the Services;
  • prevent fraud, abuse, or unauthorised access;
  • provide account support; and
  • maintain the security and reliability of the Services.

Celia Med does not use Google user data obtained through Google Sign-In for advertising, targeted advertising, personalised advertising, or unrelated marketing purposes, and does not sell Google user data.

Celia Med does not access content from Gmail, Google Drive, Google Calendar, Google Contacts, or other Google services merely because you use Google Sign-In. If Celia Med introduces a feature that requires additional Google API access, Celia Med will request the relevant permission, clearly explain the purpose of that access, and update its privacy disclosures where required before using that data.

Service Providers and Sharing of Google User Data

Celia Med may allow trusted service providers that support authentication, hosting, database infrastructure, security, monitoring, and technical operations to process Google user data on our behalf where reasonably necessary to provide and protect the Services. These service providers may process such information only for the services they provide to Celia Med and subject to applicable contractual, confidentiality, security, and data-protection obligations.

Celia Med does not sell Google user data, share it with advertising platforms or data brokers, or use it for targeted or personalised advertising. Celia Med will not otherwise disclose Google user data except where necessary to provide the Services, where you direct or authorise the disclosure, or where disclosure is required or permitted by applicable law.

Google authentication data may be stored for as long as reasonably necessary to maintain your Celia Med account, provide the Services, protect account security, satisfy applicable legal or regulatory requirements, or meet legitimate operational needs. Where legally permitted, you may request deletion of personal information associated with your Celia Med account as described in this Policy. Certain healthcare, audit, security, financial, or legal records may need to be retained even after an account is closed.

You may revoke Celia Med's access to your Google Account through your Google Account permissions or security settings. Revoking Google access stops future access authorised through that connection, but it does not necessarily delete your Celia Med account or information that Celia Med is required or permitted to retain under applicable law.

Celia Med's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

7. How We Collect Information

Personal information may be collected:

  • directly from you;
  • from a healthcare organisation;
  • from doctors, nurses, pharmacists, laboratory personnel, or other authorised healthcare professionals;
  • from an authorised parent, guardian, caregiver, or representative;
  • during patient registration;
  • through patient self-registration;
  • during authorised migration from an existing system;
  • through connected healthcare systems;
  • through authorised third-party integrations;
  • automatically when the Services are used; or
  • from service providers supporting Celia Med.

8. Why We Process Personal Information

Personal information may be processed to:

  • register and identify patients;
  • create and maintain healthcare records;
  • support healthcare delivery;
  • schedule appointments;
  • document consultations;
  • support nursing care;
  • order and manage laboratory or diagnostic investigations;
  • support pharmacy and medication workflows;
  • manage admissions and inpatient care;
  • manage billing and payments;
  • manage healthcare inventory;
  • provide patient-facing services;
  • authenticate users;
  • manage access permissions;
  • administer healthcare organisations;
  • maintain system security;
  • detect fraud or misuse;
  • investigate technical problems;
  • provide customer support;
  • maintain audit and accountability records;
  • improve the reliability and performance of Celia Med; and
  • comply with legal or regulatory obligations.

9. Lawful Basis for Processing

Personal information will be processed only where an appropriate lawful basis exists.

Depending on the circumstances, this may include:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protection of vital interests;
  • legitimate interests;
  • provision or management of healthcare;
  • medical diagnosis;
  • public interest; or
  • another lawful basis recognised under applicable law.

Consent is not necessarily the lawful basis for every healthcare processing activity.

A healthcare organisation may, for example, be legally or professionally required to maintain certain medical records even if a patient later withdraws consent for an unrelated optional activity.

10. Sensitive Health Information

Celia Med may process sensitive health information on behalf of healthcare organisations.

Such information should only be processed:

  • for legitimate healthcare or operational purposes;
  • under an appropriate lawful basis;
  • by authorised persons; and
  • with safeguards appropriate to the sensitivity of the information.

Healthcare organisations are responsible for ensuring that they have lawful authority to enter and use patient information within Celia Med.

11. Access to Patient Information

Access to patient information should be limited to persons with a legitimate and authorised need.

Celia Med provides functionality that allows healthcare organisations to manage access through roles and permissions.

Healthcare organisations are responsible for:

  • assigning appropriate user access;
  • applying appropriate permission levels;
  • reviewing user access;
  • removing access when it is no longer required;
  • protecting administrative privileges; and
  • ensuring that personnel access patient information only for authorised purposes.

Users must not access a patient's information merely out of curiosity or for purposes unrelated to their professional or authorised responsibilities.

12. Security of Personal Information

Celia Med uses technical and organisational safeguards intended to protect personal and health information.

These may include, where appropriate:

  • secure authentication;
  • role-based access controls;
  • organisation-scoped access controls;
  • encryption;
  • protected communications;
  • controlled database access;
  • tenant-separation controls;
  • audit logging;
  • account-security controls;
  • backups;
  • monitoring; and
  • security procedures.

Security is a shared responsibility.

Healthcare organisations and users are responsible for appropriately protecting:

  • passwords and authentication methods;
  • staff accounts;
  • devices;
  • local networks;
  • physical access to systems; and
  • access to patient information.

No information system can be guaranteed to be completely secure.

13. Audit Logs and Accountability

Celia Med may maintain records of activities performed within the platform for purposes including:

  • patient safety;
  • information security;
  • accountability;
  • investigating inappropriate access;
  • investigating errors or incidents;
  • regulatory compliance;
  • dispute resolution; and
  • system administration.

Audit records may include information such as:

  • the user who performed an action;
  • the healthcare organisation;
  • the action performed;
  • the relevant record or resource;
  • the date and time of the activity; and
  • associated technical information where available.

Audit records may be retained for longer periods where required for legitimate security, healthcare, regulatory, or legal purposes.

14. Patient Portal and Proxy Access

Where enabled by a healthcare organisation, Celia Med may provide patients with access to certain information through a patient-facing portal or service.

Depending on the healthcare organisation, patients may be able to access information such as:

  • profile information;
  • appointments;
  • invoices;
  • laboratory information;
  • healthcare communications; and
  • other authorised records.

The healthcare organisation determines what patient information is made available and when it is released.

Celia Med may also support authorised access for:

  • parents;
  • guardians;
  • caregivers; or
  • other authorised representatives.

The healthcare organisation is responsible for determining whether proxy access is legally and clinically appropriate.

A person must not continue to access another individual's healthcare information after their authority has expired or been withdrawn.

15. Children and Minors

Celia Med may process information relating to children where a healthcare organisation uses the platform to provide healthcare to a minor.

The relevant healthcare organisation is responsible for determining:

  • whether parental or guardian consent is required;
  • who has legal authority to act for the child;
  • whether a minor may exercise particular healthcare rights independently; and
  • whether a parent, guardian, or representative should have access to the child's healthcare information

16. Sharing Personal Information

Celia Med does not sell patient medical records or identifiable health information.

Personal information may be shared in the circumstances described below.

16.1 Healthcare Personnel

Information may be made available to authorised healthcare personnel involved in healthcare delivery or legitimate healthcare operations.

16.2 Other Healthcare Providers

A healthcare organisation may share patient information with another healthcare provider where such sharing is:

  • authorised;
  • necessary for care;
  • required for continuity of care;
  • legally permitted;
  • required by law; or
  • otherwise supported by an appropriate lawful basis.

16.3 Service Providers

Celia Med may use trusted service providers to support functions such as:

  • hosting;
  • database services;
  • authentication;
  • file storage;
  • communications;
  • monitoring;
  • backup;
  • cybersecurity; and
  • technical support.

These providers may process information only as reasonably necessary to provide their services and subject to applicable legal and contractual safeguards.

16.4 Authorities

Information may be disclosed where required or permitted by applicable law, including to:

  • courts;
  • regulators;
  • law-enforcement authorities;
  • healthcare authorities;
  • public-health authorities; or
  • competent data-protection authorities.

17. Third-Party Integrations and Independent Controllers

Celia Med may connect with third-party products or services used by healthcare organisations.

These may include:

  • payment providers;
  • laboratories;
  • diagnostic systems;
  • pharmacies;
  • insurers;
  • healthcare applications;
  • communications providers; and
  • authorised government or health-information infrastructure.

Authentication providers, including Google where Google Sign-In is enabled, may process information under their own terms and privacy policies. Celia Med's handling of Google user data is described in Section 6.7 of this Policy.

Where a third party independently determines why and how it processes personal information, that third party may act as a separate Data Controller.

Its own privacy policy and terms may therefore apply to its processing.

Celia Med is not responsible for the independent privacy practices of third parties that operate outside Celia Med's control.

18. International Processing and Transfers

Some technology providers supporting Celia Med may process or store information outside Nigeria.

Where personal information is transferred internationally, Celia Med will take reasonable steps to ensure that the transfer is conducted in accordance with applicable data-protection requirements.

Appropriate safeguards may include:

  • contractual protections;
  • recognised legal transfer mechanisms;
  • technical safeguards;
  • assessments of the relevant processing environment; or
  • another lawful transfer mechanism.

19. Data Retention

Personal information is retained for as long as reasonably necessary for the purposes for which it is processed and to satisfy applicable:

  • healthcare requirements;
  • legal obligations;
  • regulatory obligations;
  • contractual obligations;
  • security requirements;
  • financial-record obligations; and
  • legitimate operational needs.

Retention periods may differ depending on the type of information.

Medical records may need to be retained by a healthcare organisation even after a patient stops using Celia Med or closes a patient portal account.

Audit, financial, security, and backup information may also be retained for appropriate periods.

20. Corrections to Medical Records

Medical records have clinical, professional, and legal significance.

Where information in a medical record is inaccurate, correcting the record may not always involve simply deleting or replacing the original entry.

Depending on applicable healthcare requirements, a healthcare organisation may need to:

  • correct inaccurate information;
  • add an amendment or clarification;
  • preserve the original entry;
  • record who made the correction;
  • record when the correction was made; and
  • preserve an appropriate audit history.

Celia Med will not ordinarily alter or delete a clinical record solely at a patient's request without appropriate authority from the healthcare organisation responsible for that record.

21. Customer Termination and Patient Data

If a healthcare organisation stops using Celia Med, patient and organisational information will be handled in accordance with:

  • the healthcare organisation's obligations;
  • the applicable agreement between Celia Med and the healthcare organisation;
  • applicable healthcare-record requirements;
  • applicable data-protection law; and
  • Celia Med's applicable retention and deletion procedures.

Where appropriate, a healthcare organisation may be provided with an opportunity to export or retrieve information before it is removed from active Celia Med systems.

Termination of a Celia Med subscription does not automatically mean that patient medical records should immediately be destroyed.

Certain information may need to be retained because of legal, healthcare, security, audit, or backup requirements.

22. Aggregated and De-Identified Information

Celia Med may use aggregated or appropriately de-identified information for purposes such as:

  • improving the platform;
  • understanding system performance;
  • improving workflows;
  • operational analytics;
  • service planning;
  • reliability monitoring; and
  • statistical analysis.

Where information has been properly anonymised so that an individual can no longer reasonably be identified, it may no longer constitute personal data under applicable law.

Celia Med will not use identifiable patient health information for unrelated behavioural advertising merely because such information is processed through the platform.

23. Corporate Transactions

If Celia Med is involved in a:

  • merger;
  • acquisition;
  • investment;
  • financing;
  • restructuring;
  • sale of assets; or
  • similar corporate transaction,

relevant personal information may be disclosed to appropriate parties where reasonably necessary for that transaction.

Any such disclosure will remain subject to applicable confidentiality, security, and data-protection requirements.

Where required by law, affected individuals or healthcare organisations will be appropriately informed.

24. Your Privacy Rights

Subject to applicable law, you may have rights including the right to:

  • receive information about how your personal data is processed;
  • access your personal information;
  • request correction of inaccurate information;
  • object to certain processing;
  • request restriction of certain processing;
  • request deletion where legally permitted;
  • withdraw consent where processing relies on consent;
  • request data portability where applicable;
  • exercise rights relating to certain automated decisions where applicable; and
  • lodge a complaint with the appropriate data-protection authority.

These rights are not absolute.

Certain information may need to be retained because of healthcare, legal, regulatory, patient-safety, or security requirements.

25. Requests Concerning Medical Records

Where Celia Med processes a patient's medical information on behalf of a healthcare organisation, requests relating to that medical record should ordinarily be made directly to the healthcare organisation.

If Celia Med receives such a request, we may:

  • refer the request to the appropriate healthcare organisation;
  • assist the organisation in responding; or
  • take another action required by applicable law or contractual obligations.

Because the healthcare organisation generally controls the medical record, Celia Med will not normally make independent clinical changes to that record without appropriate authority.

26. Personal Data Breaches and Security Incidents

Celia Med maintains procedures intended to identify, assess, contain, investigate, and respond to suspected personal-data breaches and security incidents.

Where required by applicable law or contractual obligations, Celia Med may notify:

  • the affected healthcare organisation;
  • a competent data-protection authority;
  • affected individuals; or
  • another relevant authority.

Celia Med may also maintain records of security incidents and personal-data breaches where required for accountability or compliance purposes.

27. Cookies and Similar Technologies

Celia Med websites and applications may use cookies and similar technologies for purposes including:

  • essential functionality;
  • authentication;
  • security;
  • session management;
  • preferences;
  • analytics; and
  • other permitted purposes.

Where consent is required for non-essential cookies, Celia Med will provide appropriate choices.

Further information is available in the Celia Med Cookie Policy

28. Changes to This Privacy Policy

Celia Med may update this Privacy Policy from time to time to reflect:

  • changes to the Celia Med platform;
  • changes in the way information is processed;
  • new services or integrations;
  • changes to legal requirements;
  • security developments; or
  • operational changes.

The latest version will display its effective date and last-updated date.

Where a change materially affects how personal information is processed, Celia Med may provide additional notice where appropriate.

29. Complaints

If you believe that personal information has been processed improperly, you may contact Celia Med using the details below.

Where your complaint relates to a medical record controlled by a healthcare organisation, we may direct the matter to that organisation.

You may also have the right to lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.

30. Contact Us

For privacy enquiries, concerns, or data-protection requests, contact:

Celia Med
General Email: celiamedofficial@gmail.com
Website: celiamed.com

For requests relating specifically to your medical record, please contact the hospital, clinic, or healthcare organisation responsible for your care in the first instance.