Skip to content
Patient360

Privacy policy

Last updated: 11 August 2026

In short: we collect only what we need to contact you and run the service, we never sell your data, and patient records belong to the hospital that holds them — not to us.

Who we are

Patient360 provides hospital records management software to healthcare providers in Nigeria. In this policy, "we" and "us" mean Patient360. You can reach us at support@patient360.health.

Two different roles

It matters which of our activities we are describing, because our responsibilities differ:

  • This website. When you browse patient360.health or send us a demo request, we are the data controller for the details you give us.
  • The Patient360 application. When a hospital uses Patient360 to manage patient records, the hospital is the data controller and we act as its data processor. We process patient data only on that hospital's instructions and for the purpose of providing the service.

What we collect on this website

  • Details you submit. When you request a demo we collect your name, role, hospital name, email address, phone number, hospital size and any message you write.
  • Limited technical information. Your browser's user agent and a one-way cryptographic hash of your IP address. We hash rather than store the address because we need it only to detect abuse, not to identify you.

We do not use advertising cookies, and we do not run third-party tracking or profiling on this site.

Why we use it, and our lawful basis

  • To respond to your enquiry and arrange a demo — on the basis of steps taken at your request before entering a contract.
  • To keep the site secure and prevent spam and abuse — on the basis of our legitimate interest in protecting the service.
  • To meet legal obligations where a law requires us to retain or produce information.

Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers to run the service — hosting and content delivery, database hosting, file storage, and email delivery — and they process data only on our instructions under a contract. We will disclose data to an authority only where we are legally required to.

How long we keep it

We keep demo requests for as long as we are in contact with you about Patient360, and for up to 24 months afterwards so we can pick up the conversation if you come back. Ask us and we will delete yours sooner. Patient records inside the application are retained according to the policy set by the hospital that controls them.

Your rights

Under the Nigeria Data Protection Act you may ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct data that is wrong or incomplete;
  • delete data we no longer have a good reason to keep;
  • restrict or object to how we use it;
  • provide it in a portable form.

Email support@patient360.health and we will respond within 30 days. If your request concerns records held by a hospital using Patient360, contact that hospital directly — it controls those records — and we will support them in responding. If you are not satisfied with our response, you may complain to the Nigeria Data Protection Commission.

How we protect data

Data is encrypted in transit and at rest, access is restricted to those who need it, each hospital's data is isolated from every other hospital's at the database level, and access is logged. Our security page describes the controls in detail. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authority as the law requires.

Changes

If we change this policy we will update the date at the top of this page, and tell you directly where the change is significant.