Trust & Legal

Privacy Policy

How MedSpaOS collects, uses, protects, and manages information across our website and practice-management platform.

Last updated: September 2, 2026

1. Scope and roles

MedSpaOS is operated from Nigeria and provides software to clinics and healthcare businesses in Nigeria and, by extension, other African markets. The Nigeria Data Protection Act 2023 (NDPA) is our primary reference point for Nigerian processing; local laws in each country where the service is used may also apply. For clinic records, the clinic usually decides why and how information is processed, while MedSpaOS acts as its service provider or processor. For account, billing, support, and website information, MedSpaOS may act as the controller or business responsible for that processing.

2. Information we collect

Depending on how you use the service, we may collect account and clinic details, staff identity and role data, appointment and operational records, patient information entered by a clinic, transaction and subscription details, support communications, device and browser information, IP addresses, audit events, and information collected through cookies or similar technologies.

Clinics are responsible for providing patients with any notices required by applicable law and for collecting appropriate permissions before entering patient information into the service.

3. How we use information

We use information to provide, secure, maintain, and improve the service; authenticate users and enforce role and device controls; process subscriptions and support requests; communicate service notices; detect abuse and security incidents; comply with law; and produce aggregated, de-identified operational insights where permitted. We do not sell patient information.

4. Service providers and disclosures

We may share information with infrastructure, authentication, email, monitoring, payment, analytics, and AI service providers that process it on our instructions or as needed to deliver a requested integration. We may also disclose information to comply with law, protect rights and safety, investigate abuse, or support a corporate transaction. Current provider and subprocessor details should be confirmed in the applicable customer agreement.

5. AI features

When a user activates MedSpaGPT or another AI feature, relevant prompts and context may be sent to the configured model provider to return the requested output. Clinics must review outputs before relying on them, avoid entering information they are not authorized to disclose, and configure or disable AI features according to their policies. AI outputs are assistance only, not medical advice or a substitute for professional judgment. Model retention and training settings are governed by the applicable provider terms and customer agreement.

6. Security and retention

We use administrative, technical, and organizational safeguards such as authentication, access controls, tenant-aware database policies, audit logging, secure hosting, and device restrictions where configured. No service can guarantee absolute security. We retain information for as long as needed to provide the service, meet contractual and legal obligations, resolve disputes, and enforce agreements, then delete or anonymize it according to our retention schedule and customer instructions.

7. Your choices and rights

Under the NDPA and other applicable African data-protection laws, individuals may have rights to access, correct, delete, restrict, export, or object to certain processing, and to withdraw consent where consent is the legal basis. Requests about clinic patient records should normally be directed to the clinic. Account holders may contact us at privacy@medspaos.com. We may need to verify identity and may retain limited information where law permits or requires.

8. Cross-border processing and complaints

MedSpaOS may process information in Nigeria or another country where we or an approved provider operates. For Nigerian data, we use the transfer mechanism and safeguards required by the NDPA and applicable regulations. Where local law provides a right to complain to a regulator, Nigerian individuals may contact the Nigeria Data Protection Commission (NDPC), and individuals in other African jurisdictions may contact their local supervisory authority.

9. Contact and changes

Questions about this policy can be sent to privacy@medspaos.com. We may update this policy as the service or legal requirements change and will post the revised version with a new effective date.

This page is provided for product and operational transparency. It is not legal advice. Have qualified counsel review the applicable agreement before relying on it in a live service.