AwaDoc
AwaDoc CDST

Privacy Policy

Last updated: September 17, 2026

AwaDoc Healthcare Limited

1. Introduction

AwaDoc Healthcare Limited and its subsidiaries and affiliates (“AwaDoc,” “we,” “us,” or “our”) owns and operates the AwaDoc CDST clinical decision support platform, including its website, software, applications, APIs, integrations, and related services (collectively, the “Platform”). Your access to and use of the Platform, any part of it, and anything associated with it, including its content, products, or services made available through the Platform or otherwise by AwaDoc, and any affiliated website, software, or application that we own or operate (collectively with the Platform and its content, the “Service”), are subject to this Privacy Policy unless we specifically state otherwise. Capitalized terms not defined in this Privacy Policy have the meanings given in the AwaDoc CDST Terms of Service (the “Terms of Service”).

AwaDoc is an artificial intelligence and healthcare technology company. The Service uses artificial intelligence and machine learning to provide clinical decision support, documentation, care-navigation, health-record, workflow, and related professional tools principally to licensed, registered, credentialed, or otherwise authorized healthcare professionals and healthcare organisations (“Clinicians” and “Healthcare Organizations”).

For Clinicians, the Service is intended to support, and not to replace, the Clinician’s own professional judgment. Clinicians remain solely responsible for clinical decisions, diagnosis, treatment, referrals, prescriptions, documentation, and the care of their patients. AwaDoc CDST does not itself create a physician-patient or other treatment relationship with any patient.

AwaDoc CDST is a professional clinical decision-support service. It is not intended for, and may not be used by, patients or members of the general public as a substitute for direct professional medical advice, diagnosis, treatment, or emergency care.

Relationship to other agreements. Except as otherwise required by applicable law, this Privacy Policy governs and controls with respect to the information practices it describes. To the extent applicable law, or a separate written agreement between AwaDoc and you or between AwaDoc and an organisation through which you access the Service (such as an employer, healthcare provider, hospital, health system, HMO, insurer, government body, NGO, or other healthcare organisation), in each case addressed to the subject matter of this Privacy Policy (each, a “Separate Agreement” — which may include an enterprise agreement, subscription agreement, order form, data processing agreement, data processing addendum, or other written agreement), conflicts with this Privacy Policy, then applicable law or the Separate Agreement controls to the extent of the conflict and this Privacy Policy otherwise continues to apply.

This Privacy Policy explains how AwaDoc collects, uses, stores, protects, and discloses information in connection with the Service. By creating, registering, or logging into an account, or otherwise accessing or using the Service, you acknowledge the most recent version of this Privacy Policy. We will update this Privacy Policy when necessary to reflect changes in the Service or our practices and as required by applicable law.

If you use the Service on behalf of another individual, Clinician, patient, Healthcare Organization, or other entity, you represent that you are authorised to act on that person’s or entity’s behalf and that you have the authority required under applicable law and any applicable professional or organizational rules.

2. Limitations on Use by Minors

The Service is intended for use only by individuals who are at least eighteen (18) years of age, or such older age as may be required by applicable law in the jurisdiction in which the individual uses the Service. The Service is not designed or intended for, and is not directed to, children.

If you are under eighteen (18) years of age, do not access or use the Service or submit any information to us. Where a patient’s information is processed through the Service by an authorised Clinician or Healthcare Organization, responsibility for lawful processing and appropriate safeguards remains with the relevant Customer, subject to applicable law.

3. Health Information and the Nature of Your Information

AwaDoc CDST is designed to process professional and clinical information, which may include personal data and sensitive personal data, including health information, relating to patients and other individuals. The fact that information is processed through AwaDoc CDST does not, by itself, determine which legal framework applies to that information. AwaDoc processes information in accordance with applicable Nigerian and African data-protection, confidentiality, cybersecurity, healthcare, and professional-regulatory requirements, together with any applicable Separate Agreement.

Where AwaDoc processes patient information on behalf of a Clinician or Healthcare Organisation, the relevant Customer may determine the purposes and means of processing and may act as a data controller or equivalent responsible party, while AwaDoc may act as a data processor, service provider, or other legally recognised role, depending on the circumstances and applicable law.

Where AwaDoc determines the purposes and means of a particular processing activity independently, AwaDoc may act as a data controller or equivalent responsible party for that processing activity. The applicable role will depend on the nature of the Service, the relevant Customer relationship, and applicable law.

Nothing in this Privacy Policy is intended to exclude or waive mandatory privacy, confidentiality, professional, or data-protection obligations that cannot lawfully be excluded or waived.

4. Information You Bring From Outside Sources

The Service may allow authorised users to input, upload, connect, import, or otherwise provide information originating from or maintained by sources other than AwaDoc, including patient records, laboratory results, diagnostic reports, prescriptions, clinical notes, referral information, messages, histories, images, or other healthcare information (“Outside Information”). Outside Information, together with information and content you input or otherwise make available through the Service, is part of “Your Data” and is treated as described in this Privacy Policy and any applicable Separate Agreement.

Your Representations. By submitting, uploading, inputting, connecting, importing, or otherwise making available any Outside Information, you represent and warrant that you have the right and authority, and have obtained any required consents, notices, permissions, or other lawful basis, necessary to provide that information to AwaDoc and to permit its processing as described in this Privacy Policy, the Terms of Service, and any Separate Agreement. You are responsible for ensuring that your provision of Outside Information does not violate applicable law, professional obligations, confidentiality duties, or the rights of any third party.

Confidentiality and prior protections. Information may be subject to confidentiality, privacy, privilege, or professional secrecy protections while held by the source from which it originates. Submission of such information to AwaDoc does not automatically eliminate those protections. AwaDoc will handle information in accordance with applicable law, this Privacy Policy, the Terms of Service, and any applicable Separate Agreement.

Information about other people. Some information you provide may describe individuals who are not the person submitting the information, including patients, family members, dependants, or other persons. Before providing information about another person, you must ensure that you are authorised to do so and that the processing is lawful under applicable data-protection and healthcare requirements.

5. Information We Collect

The information we collect depends on how you interact with us, the features you use, the role in which you access the Service, and the choices made by you or the Healthcare Organisation with which you are associated. We may collect information you provide directly, information collected automatically, information we infer or generate, and information obtained from third-party sources.

Information you provide directly.

  • Contact and account information, such as your name, professional email address, phone number, username, password, and other credentials, organisation details, and billing information.
  • Professional identity and credential information, such as professional registration or license number, professional council or regulatory body, specialty, qualification, role, practice details, and verification information.
  • Clinical content and inputs, such as clinical questions, patient encounter information, symptoms, histories, diagnoses, treatment information, medications, laboratory and diagnostic information, clinical notes, documents, images, audio recordings, transcripts, and other content you input or upload.
  • Patient and other individual information, such as names, identification details, demographic information, contact details, medical history, clinical records, and other information supplied by an authorised Customer.
  • Preferences and settings, such as saved templates, documentation styles, workflow preferences, and configuration choices.
  • Payment and transaction information, such as billing details and transaction identifiers. Payment-card information may be processed directly by third-party payment processors.
  • Communications, such as messages, support requests, feedback, and other communications you send to us or through the Service.

Information we collect automatically.

  • Identifiers and device information, such as IP address, device identifiers, device type, operating system, browser, application version, language, settings, and configuration.
  • General location information, such as location inferred from an IP address or approximate location where technically available and lawfully collected.
  • Usage data, such as pages and features viewed or used, access times, links clicked, referring pages, system interactions, and other details about use of the Service.
  • Cookies and similar technologies, as described below.

Information we infer or generate.

We may infer or generate information from other information we collect, including through automated means and our AI Technologies. This may include operational, technical, workflow, clinical-support, or other inferences generated to provide or improve the Service. We will handle such information in accordance with applicable law and any restrictions contained in a Separate Agreement.

Information we obtain from third-party sources.

  • Healthcare Organisations, employers, hospitals, clinics, laboratories, pharmacies, HMOs, insurers, government or NGO programmes, and other Customers through which you access the Service.
  • Third-party systems and applications that you or a Customer authorise or connect to the Service.
  • Service providers acting on our behalf, such as identity-verification, security, analytics, infrastructure, and support providers.
  • Publicly available professional or corporate information where lawfully obtained and used.

Where your information comes from.

AwaDoc records and Service environments may combine information from several sources, including information you provide, information submitted by a Customer, information generated by the Service, information from integrated systems, and Outside Information. Where technically feasible and appropriate, we may retain or display the source of information within the relevant record or workflow.

What is required.

If you decline to provide, or ask us to delete, information that is necessary for the Service or a feature, we may be unable to provide that Service or feature. Where patient or clinical information is required for a particular clinical workflow, the relevant Clinician or Healthcare Organisation may also determine what information is necessary for lawful and safe use of that workflow.

6. Cookies, Mobile IDs, and Similar Technologies

We and our analytics, security, and technology partners may use cookies, web beacons, software development kits, mobile identifiers, and similar technologies to operate the Service and collect information such as usage data, identifiers, and device information.

These technologies may be used to maintain sessions, store preferences, analyze Service performance, improve security, understand interactions, measure product performance, and support other legitimate business purposes. We do not use patient clinical information for third-party advertising purposes except where expressly permitted by applicable law and, where required, with appropriate consent.

7. How We Use Your Information

We use the information we collect for the purposes described in this Privacy Policy, applicable Separate Agreements, or as otherwise disclosed to you. Principal purposes include:

  • Providing and operating the Service. To provide, maintain, and deliver AwaDoc CDST; create and administer accounts; generate AI-assisted outputs, summaries, documentation, and clinical-support information; troubleshoot; secure; and improve the Service.
  • Clinical decision-support and workflow support. To provide authorised Clinicians and Healthcare Organisations with clinical decision-support, documentation, care-navigation, record-management, and workflow functionality.
  • AI development, validation, and improvement. To develop, test, validate, evaluate, benchmark, operate, and improve our AI Technologies and Service, subject to applicable law, contractual restrictions, data-protection requirements, and any limitations contained in a Separate Agreement.
  • Product development and research. To develop, test, analyse, and improve features, products, and services and to conduct lawful healthcare technology research and development.
  • Customer support. To provide support, respond to requests, investigate issues, and fulfil Customer or user requests.
  • Communications. To send service notices, security alerts, updates, administrative communications, and other messages related to your account or use of the Service.
  • Business operations. To operate, secure, and protect our business and Service, including billing, accounting, fraud prevention, identity verification, information security, compliance, and enforcement of our agreements.
  • De-identification and aggregation. To create de-identified or aggregated information where permitted by law and to use such information for lawful analytics, research, product development, quality improvement, and other purposes.
  • Legal, safety, and compliance. To comply with applicable law and lawful requests; protect rights, property, and safety; and detect, prevent, investigate, and respond to fraud, abuse, security incidents, or unlawful activity.

We may combine information from different sources where necessary and lawful to provide a more seamless and secure Service. Where applicable law requires consent before particular categories of sensitive personal data are processed for a particular purpose, we will obtain consent where required or rely on another lawful basis permitted by applicable law.

8. Artificial Intelligence; Training and Development of Our Models

AwaDoc is an artificial intelligence and healthcare technology company, and an important purpose of the Service is the development, validation, operation, safety evaluation, and improvement of our artificial intelligence and machine learning models, algorithms, software, and related technologies (collectively, “AI Technologies”).

Where you or a Customer provides data to the Service, AwaDoc may process that data to provide the Service, maintain and secure the platform, conduct quality assurance, troubleshoot, validate system performance, and develop and improve our AI Technologies, but only to the extent permitted by applicable law and any Separate Agreement.

Where Customer Data is processed on behalf of a Healthcare Organisation or other Customer, the rights of AwaDoc to use that Customer Data for model training, development, or other secondary purposes may be limited by the Customer Agreement, Data Processing Agreement, applicable law, or the instructions of the Customer. AwaDoc will not rely on a general licence in this Privacy Policy to override a contractual restriction or mandatory legal requirement.

We may create de-identified or aggregated information from data where legally permitted. De-identified or aggregated information may be used for model development, product improvement, research, analytics, quality assurance, and other lawful purposes, provided that the information is not used in a manner prohibited by applicable law.

To the extent permitted by applicable law and applicable agreements, models, algorithms, model parameters, system improvements, and other technology developed by AwaDoc remain the property of AwaDoc or its licensors. Nothing in this section transfers ownership of Customer Data or patient records to AwaDoc.

We will not knowingly use identifiable patient information for AI training or development where such use is prohibited by applicable law, a binding Customer Agreement, or a lawful instruction from the relevant Customer. Where consent or another legal safeguard is required, AwaDoc will implement the applicable requirement.

9. Additional Provisions for Clinicians

This section provides additional information about how this Privacy Policy applies to Clinicians and supplements the other provisions of this Privacy Policy. It applies to individual Clinicians who register for and use clinician-facing features of AwaDoc CDST, except to the extent superseded by a Separate Agreement, including an agreement between AwaDoc and the Clinician’s employer, healthcare provider, hospital, clinic, health system, HMO, insurer, government body, NGO, or other Healthcare Organization.

Clinician information we collect.

  • Professional identity and contact information, such as your name, work email address, phone number, and organizational affiliation.
  • Professional credentials, such as registration or licence number, professional council or regulatory body, specialty, qualifications, and other credentials.
  • Practice information, such as your practice, employer, healthcare organisation, role, department, or professional responsibilities.
  • Verification information, such as information used to verify identity and professional credentials.
  • Content and inputs, such as clinical questions, patient encounter information, audio recordings and transcripts where documentation features are used, notes, documents, images, and other content you input or upload.
  • Preferences and settings, such as saved templates, documentation styles, and workflow preferences.
  • Usage data, such as information about your use of clinician-facing features.

Patient and other information you input.

As a Clinician, you may input, upload, connect, or otherwise make available information about your patients and other individuals in connection with your use of the Service. You are responsible for ensuring that you have the right and authority, and have obtained any required consents, notices, permissions, or other lawful basis, necessary to provide that information to AwaDoc and permit its processing under this Privacy Policy, the Terms of Service, applicable law, and any Separate Agreement.

Data-protection roles for patient information.

Where AwaDoc processes patient information on behalf of a Clinician or Healthcare Organisation, the relevant Customer may be the controller or equivalent responsible party and AwaDoc may be the processor or equivalent service provider. The precise allocation of responsibilities depends on the Service, the applicable agreement, and the law governing the relevant processing.

Where a Customer requires a Data Processing Agreement or similar arrangement, AwaDoc will enter into and comply with such agreement where applicable.

Use of Clinician information to develop and improve our AI Technologies.

Subject to applicable law and any Separate Agreement, we may use information provided by Clinicians to operate, secure, evaluate, validate, improve, and develop AwaDoc CDST and related technologies. Patient information submitted by Clinicians will be subject to the applicable contractual and legal restrictions described above.

Marketing to Clinicians.

We may market and promote AwaDoc CDST to Clinicians and prospective professional users using professional contact information, subject to applicable law and communication preferences. We do not use confidential patient clinical information for direct marketing.

10. How We Disclose Your Information

We disclose information as necessary to provide the Service, complete transactions, fulfil requests, protect the Service, comply with law, or for other purposes permitted by this Privacy Policy, applicable law, or a Separate Agreement. Categories of recipients may include:

  • Service providers. Vendors and agents that perform services on our behalf, such as hosting, cloud infrastructure, analytics, identity verification, customer support, communications, payment processing, cybersecurity, and technical support.
  • AI and technology providers. Providers of AI, computing, storage, software, and related infrastructure supporting operation, security, development, and improvement of the Service, subject to appropriate contractual and data-protection safeguards.
  • Affiliates. Subsidiaries, affiliates, and related companies where necessary to operate shared systems, provide the Service, or conduct legitimate business operations.
  • Healthcare organizations and Customers. The organisation or professional through which you access the Service, where disclosure is necessary to provide the Service or permitted by the applicable Customer relationship.
  • Financial and payment partners. Banks, payment processors, and other entities necessary for payment processing, fraud prevention, reconciliation, and related financial services.
  • Corporate transactions. Counterparties and their advisers in connection with financing, merger, acquisition, reorganisation, insolvency, dissolution, transfer, divestiture, or sale of all or part of our business or assets.
  • Legal and regulatory authorities. Courts, regulators, law-enforcement bodies, professional councils, government agencies, and other authorities where disclosure is required or permitted by applicable law or valid legal process.
  • Safety and protection of rights. Other persons or entities where disclosure is reasonably necessary to protect safety, prevent fraud or security incidents, enforce agreements, or protect rights or property.

We do not disclose patient clinical information to third parties for their independent advertising purposes except where expressly permitted by applicable law and, where required, with appropriate consent. We may disclose de-identified or aggregated information where permitted by law.

11. Your Choices and Controls

  • Access, correction, and deletion. Depending on applicable law and your role, you may request access to, correction of, or deletion of personal information by contacting us at cdst@awadoc.com. Where AwaDoc processes information solely on behalf of a Customer, requests may need to be directed to that Customer.
  • Restriction and objection. Where provided by applicable law, you may have rights to object to or request restriction of certain processing.
  • Withdrawal of consent. Where processing is based on consent, you may withdraw consent, subject to lawful exceptions and the effect this may have on the Service.
  • Communications preferences. You may opt out of promotional communications by following the instructions in the communication or contacting us. Service-related and administrative communications may still be sent where necessary.
  • Complaint. You may have the right to lodge a complaint with the relevant data-protection or regulatory authority, including the Nigeria Data Protection Commission where applicable.

To the extent permitted by law, we may decline a request where fulfilling it would be prohibited by law, adversely affect another person’s rights, reveal confidential information or trade secrets, interfere with legal retention obligations, or where we cannot reasonably verify the requester’s identity or authority. Where required by law, we will provide information about applicable appeal or review mechanisms.

12. Browser and Platform Controls

  • Cookie controls. Most browsers accept cookies by default. You can adjust browser settings to delete or reject cookies, although doing so may affect certain Service features.
  • Mobile controls. Mobile operating systems provide settings that may limit certain identifiers or tracking technologies.
  • Device and account controls. You may manage certain account, notification, and privacy settings through the Service where those controls are made available.

13. Data Retention

We retain information for as long as necessary to provide the Service, fulfil transactions, support Customers, maintain security, comply with legal and professional obligations, resolve disputes, enforce agreements, conduct permitted research and product improvement, and for other legitimate purposes. Actual retention periods vary according to the nature of the data, the Service, the Customer relationship, applicable law, and any contractual retention requirements.

Where AwaDoc processes patient information on behalf of a Healthcare Organisation, retention may be determined by the Customer’s instructions and applicable healthcare and record-retention requirements. De-identified or aggregated information may be retained for longer where permitted by law.

14. Security

We use reasonable physical, technical, administrative, and organizational measures designed to protect information against unauthorized access, use, disclosure, alteration, loss, destruction, or other unlawful processing. Measures may include encryption in transit and at rest where appropriate, access controls, authentication, logging, monitoring, segregation of environments, vulnerability management, backups, incident-response processes, and personnel confidentiality obligations.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Users are responsible for maintaining the confidentiality of account credentials and for promptly notifying AwaDoc if they believe an account or security control has been compromised.

15. Payments and Transactions

In connection with transactions conducted through the Service, you or the relevant Customer may be asked to provide information necessary for the transaction, such as billing details and transaction identifiers. Payment-card and other financial information may be processed by third-party payment processors. Those providers operate under their own terms and privacy notices and may process information as necessary to complete and secure transactions.

16. Jurisdictional Issues

The Service is principally operated from Nigeria and is intended for professional healthcare use in Nigeria and other African jurisdictions where the Service is lawfully offered. This Privacy Policy is intended to operate in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, and other applicable Nigerian laws and regulations.

Where the Service is used in another African jurisdiction, AwaDoc will process personal information in accordance with mandatory data-protection, privacy, healthcare, professional, cybersecurity, and other applicable requirements of that jurisdiction. Where applicable law provides stronger or additional protections, those mandatory requirements will prevail to the extent required.

17. Nigeria Data Protection Rights

Subject to applicable law, individuals may have rights in relation to their personal data, including rights to information about processing, access, rectification, erasure in appropriate circumstances, restriction or objection to certain processing, data portability where applicable, withdrawal of consent where consent is the lawful basis, and the right to lodge a complaint with the Nigeria Data Protection Commission.

Some rights are subject to statutory exceptions, including where retention or processing is required by law, necessary for legal claims, required for public interest or regulatory purposes, or otherwise permitted under applicable law.

Where AwaDoc processes information solely on behalf of a Customer, we may refer a request to the relevant Customer or assist that Customer in responding, as required by applicable law and the applicable agreement.

18. African Data Protection and Privacy Laws

Africa includes multiple national and regional data-protection frameworks, and requirements vary by jurisdiction. Depending on where a user, patient, Clinician, Healthcare Organisation, or other data subject is located, applicable requirements may include national data-protection legislation, regional frameworks, sector-specific healthcare requirements, professional confidentiality rules, and cross-border transfer restrictions.

Examples of jurisdictions with data-protection frameworks include Nigeria, Ghana, Kenya, South Africa, Rwanda, Uganda, Tanzania, Egypt, Morocco, and other African countries. AwaDoc does not represent that a single privacy standard applies identically in every African jurisdiction. We will apply mandatory local requirements to processing activities to which they apply.

19. International and Cross-Border Transfers

AwaDoc and its service providers may process or store information in Nigeria and other countries where we or our service providers operate, subject to applicable law. Where personal information is transferred across borders, AwaDoc will implement applicable legal safeguards, contractual protections, transfer mechanisms, security measures, and other requirements required by the relevant jurisdiction.

Where a Customer requires a specific cross-border transfer mechanism or contractual safeguard, the applicable Separate Agreement may establish the requirements governing that transfer.

20. De-identification and Aggregation

Where permitted by applicable law, AwaDoc may de-identify, anonymise, pseudonymise, or aggregate information for purposes such as analytics, service improvement, safety evaluation, quality assurance, research, benchmarking, and product development. We will apply the relevant legal standard applicable to the transformation and intended use of the information.

Where information has been properly anonymised under applicable law, it may no longer be treated as personal data under that law. We will not knowingly attempt to re-identify properly anonymised information except where permitted or required by law.

21. Clinical Decision-Support Outputs

AwaDoc CDST may generate suggestions, summaries, documentation, differential considerations, care-navigation information, alerts, or other outputs. Such outputs are generated with the assistance of AI Technologies and may contain errors, omissions, or inaccuracies.

Clinicians must independently review and validate outputs before relying on them in clinical practice. AwaDoc CDST is not a substitute for professional judgment, patient examination, appropriate diagnostic testing, clinical guidelines, local protocols, or applicable professional standards.

AwaDoc does not assume responsibility for a clinical decision solely because a Clinician received or considered an output from the Service.

22. Automated Decision-Making

The Service may use automated processing to generate clinical-support or operational outputs. AwaDoc CDST is designed as a decision-support tool and is not intended to make final medical decisions on behalf of Clinicians. Where applicable law grants individuals rights relating to solely automated decision-making or profiling, AwaDoc will address those rights in accordance with the requirements applicable to the relevant processing.

23. Third-Party Systems and Services

The Service may integrate with or depend on third-party systems, including electronic medical records, laboratory systems, pharmacy systems, payment providers, cloud infrastructure, communications platforms, identity providers, analytics tools, and AI technology providers. Information shared with or received from such systems may be subject to their own terms and privacy practices. AwaDoc will use appropriate contractual and technical safeguards where required, but cannot control the independent privacy practices of third parties.

24. Professional Confidentiality

AwaDoc recognises that healthcare information may be subject to professional confidentiality, patient confidentiality, ethical obligations, and statutory privacy requirements. AwaDoc personnel and service providers with authorised access to confidential information are expected to handle such information in accordance with applicable contractual, security, confidentiality, and legal requirements.

Nothing in this Privacy Policy replaces a Clinician’s or Healthcare Organisation’s professional, statutory, ethical, or contractual obligations to patients.

25. Customer Responsibility for Patient Information

Healthcare Organisations and Clinicians are responsible for determining whether and how patient information may lawfully be submitted to the Service, including obtaining any required consent, providing required notices, establishing appropriate access controls, maintaining accurate records, and complying with applicable healthcare, privacy, professional, cybersecurity, and record-retention requirements.

Customers should not submit information to AwaDoc CDST where they lack the authority or lawful basis to do so.

26. Data Minimisation

AwaDoc seeks to collect and process information that is reasonably necessary for the relevant Service, workflow, security, legal, or business purpose. Customers and Clinicians should avoid submitting information that is unnecessary for the intended workflow.

27. Research and Healthcare Innovation

Where permitted by law and applicable agreements, AwaDoc may conduct or support research, evaluation, safety studies, quality improvement, and healthcare technology innovation using appropriately authorised, de-identified, aggregated, or otherwise lawfully processed information. Where research activities require ethics approval, consent, institutional authorisation, or another safeguard, AwaDoc will implement the applicable requirement.

28. Security Incidents and Data Breaches

If AwaDoc becomes aware of a confirmed or reasonably suspected security incident affecting personal information, we will assess and respond in accordance with our incident-response procedures and applicable law. Where notification to a Customer, data subject, regulator, or other authority is legally required, AwaDoc will make or support such notification within the applicable timeframe and subject to the applicable legal requirements.

Where AwaDoc processes personal information on behalf of a Customer, notification and cooperation obligations may also be governed by the applicable Data Processing Agreement or other Separate Agreement.

29. Marketing Communications

We may send professional or business communications about AwaDoc CDST, product updates, educational materials, events, and related services where permitted by applicable law. You may opt out of promotional communications at any time using the unsubscribe mechanism provided or by contacting cdst@awadoc.com. Service-related, security, transactional, and administrative communications may continue where necessary.

30. Children

AwaDoc CDST is not designed for direct use by children. Patient information concerning minors may nevertheless be processed by authorised Clinicians or Healthcare Organizations where necessary for legitimate healthcare purposes and where permitted by applicable law.

31. Changes to This Privacy Policy

We may supplement, amend, or otherwise modify this Privacy Policy from time to time. We will post changes on the Service or another appropriate location and update the “Last updated” date. Where applicable law requires notice of material changes, we will provide such notice through appropriate means.

32. Contacting Us

If you need to contact us, have a question about this Privacy Policy, wish to exercise an applicable data-protection right, or need to raise a privacy or data-protection concern, please write to:

AwaDoc Healthcare (Limited)
Attn: Privacy / Data Protection
14B Imman Dauda Street, Surulere, Lagos - Nigeria.
Data Protection Officer: dpo@awadoc.com
Email: cdst@awadoc.com

For requests concerning patient information processed through a Healthcare Organisation or other Customer, we may ask you to contact that Customer or may coordinate with the Customer to address the request, depending on the applicable legal and contractual roles.