In short
- We collect only what we need to answer you, run your account, and keep the systems we host working.
- We do not sell your data, and we do not share it for anyone else's advertising.
- Patient data in systems we host belongs to the health provider, not to us. We process it on their instructions and nothing else.
- Non-essential cookies stay off until you turn them on. .
- You can ask us for a copy of your data, or for its deletion, at any time.
Who we are
Xeventy2.0 Health Limited is a digital health company registered in Nigeria with the Corporate Affairs Commission. For information you give us directly — a contact form, a newsletter sign-up, a support request — we are the data controller.
For patient and clinical information inside systems we build or host for a hospital, clinic, pharmacy or laboratory, that organisation is the controller and we act as a data processor under a written agreement with them.
What we collect
- Information you give us. Your name, email address, telephone number, organisation, team size, location and whatever you write in a message or support request.
- Account information. For client systems: your username, role, permissions and the record of actions you took inside the system.
- Technical information. IP address, browser and device type, referring page, and pages viewed. Collected in server logs for security and troubleshooting.
- Analytics information. Aggregate usage of this website — but only once you have accepted analytics cookies.
We do not ask for and do not want payment card numbers over email, chat or a web form.
Why we use it
- To answer your enquiry and follow up on it.
- To provide, host, support and improve the software you licence from us.
- To send the newsletter, if you asked for it.
- To meet legal, accounting and regulatory obligations.
- To detect, investigate and prevent abuse of our systems.
We do not use your information to make automated decisions that produce legal effects about you.
Lawful basis
Under the Nigeria Data Protection Act 2023 and, where it applies, the UK and EU GDPR, we rely on:
- Contract — to deliver the services you or your organisation have engaged us for.
- Consent — for the newsletter and for non-essential cookies. You can withdraw it at any time.
- Legitimate interests — to keep our systems secure and to respond to business enquiries, balanced against your rights.
- Legal obligation — where a law or a regulator requires us to retain or disclose information.
Clinical data we process for clients
When we host or support a records, pharmacy or laboratory system, patient information inside it remains under the control of the health provider. We act only on their documented instructions.
- Our engineers do not hold standing access to live clinical data.
- Support access is granted per incident, limited to what the incident requires, time-boxed and logged in an audit trail the provider can read.
- We do not use patient data to train models or to build other products.
- Where we need a sub-processor — for hosting, for example — the provider is told who it is before we engage them.
If you are a patient and want to see, correct or delete your medical record, contact the health facility that treated you. They hold the record; we cannot release it on their behalf.
How long we keep it
- Enquiries — up to 24 months after our last exchange, unless it became a client relationship.
- Newsletter subscriptions — until you unsubscribe, plus a short suppression record so we do not re-add you by mistake.
- Client account records — for the life of the contract and then as long as accounting and limitation rules require.
- Server and security logs — typically 90 days, longer where an incident is under investigation.
- Clinical data processed for a client — under their retention schedule, deleted or returned on their instruction when the contract ends.
How we protect it
- Encryption in transit, and at rest for stored records.
- Role-based access, least privilege by default, and multi-factor authentication for staff.
- Audit logging of reads and edits in clinical systems.
- Backups with tested restores, held in the region the client selects.
- A written incident procedure, with regulator and client notification timelines.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant authority within the periods the law sets, and we will say what actually happened.
Your rights
You can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct anything inaccurate.
- Delete it, where we have no continuing lawful reason to keep it.
- Restrict or object to a particular use.
- Send it to another provider in a portable format.
- Withdraw consent you previously gave, at any time.
Write to hello@xeventy2health.com. We respond within 30 days. There is no charge. If you are unhappy with our answer you may complain to the Nigeria Data Protection Commission, or to the supervisory authority where you live.
Children
This website is not directed at children, and we do not knowingly collect information from them through it. Paediatric records inside client systems are handled under the health provider's own policies and the consent of a parent or guardian.
Changes to this policy
We update this page when our practices change. The date at the top always reflects the current version, and we will give notice of material changes to active clients and newsletter subscribers before they take effect.
Contact us
For anything in this policy, including a data request, reach our Legal and Compliance Unit:
Prefer a form? Use the contact page and mark your message for the Legal and Compliance Unit.

