← Back to home

Privacy Policy

Version 1.2Effective 02 Jul 2026

Privacy Policy

Effective Date: 10-06-2026

Platform Name: Doctolara.com

Company Name: Laras Medicaid Limited

Website: https://doctolara.com

Privacy Policy

Doctolara.com, alongside its parent corporate structures and affiliates (collectively, the "Platform," "we," "our," or "us"), operates under a strict mandate to safeguard your personal, clinical, and sensitive health information.

This Privacy and Data Protection Policy ("Policy") governs how we collect, use, disclose, process, store, and cryptographically protect your information across our website, mobile applications, telehealth platforms, regional healthcare coordination networks, communication channels, and proprietary APIs (collectively, the "Services").

Statutory Framework & Consent: This Policy is explicitly constructed in compliance with the Nigeria Data Protection Act (NDPA), the National Health Act (NHA), and all prevailing national healthcare privacy standards. By accessing the Platform as an Account Holder, Sponsor, or Care Recipient, you grant your explicit consent to the data practices described herein.

1. Information We Collect

The Platform collects and processes fundamental personal data required to authenticate identities, establish communication, and manage user accounts. This includes, but is not limited to, the following distinct data categories:

1.1 Personal Information

Including but not limited to:

  • Demographic & Profile Data: Full legal name, date of birth, and biological gender.
  • Core Communication Anchors: Physical residential or business address, active mobile telephone numbers, and verified email addresses.
  • Statutory Identity Verification: Government-issued identification media (including national identity numbers, international passports, or driver's licenses) required to fulfill compliance and prevent fraudulent registrations.
  • Auxiliary Risk Management: Designated emergency contact details, next-of-kin identifiers, and third-party health insurance coverage records where applicable.

1.2 Health and Medical Information

To facilitate accurate telehealth consultations, laboratory diagnostics, and care coordination, the Platform collects and processes the following health data:

  • Medical History & Symptoms: Documented symptoms, health history, previous diagnoses, and known allergies.
  • Medications & Prescriptions: Current and historical medications, along with digital platform prescriptions.
  • Consultation & Care Records: Telehealth consultation records, care notes, and ongoing treatment plans.
  • Laboratory & Diagnostic Data: Laboratory test results, diagnostic imaging information, and referral documents.

1.3 Clinician and Provider Information

For clinicians, healthcare providers, and commercial partners using our network, we collect and process the following business and professional data:

  • Credentials & Licensing: Professional medical licenses, specialized certifications, and official business registration information.
  • Financial & Operations Data: Corporate or personal banking and payment information for processing transactions.
  • Operational Details: Availability calendars, scheduling parameters, and professional profile details for public or network visibility.

1.4 Technical and Device Information

When you interact with our platform, we may automatically collect technical and diagnostic data from your device, including:

  • Device & System Identifiers: Your IP address, browser type, device identifiers, device type, and operating system.
  • Usage & Analytics Data: Session information, crash logs, access timestamps, and general app usage analytics.
  • Location Data: Precise or general geolocation data, collected only where you have explicitly permitted access on your device.

1.5 Payment Information

All financial transactions on our platform are processed securely through authorized third-party payment gateways. We only collect limited payment-related data, including:

  • Transaction Logs: Transaction identifiers, billing references, and real-time payment status updates.
  • Account Plan Data: Active subscription details and billing tier information.

Critical Card Safety Note: The Platform does not store your full credit or debit card details on our local servers under any circumstances, unless explicitly stated and lawfully permitted.

2. How We Use Information

We use the categories of information we collect to manage our platform, deliver clinical care, and maintain system security. This includes using your data to:

Core services and Care: Provide telehealth and healthcare services, coordinate consultations and referrals, facilitate prescriptions, and maintain accurate medical records.

Operations & Support: Verify identity and eligibility (such as sponsor authorization or insurance coverage), process payments, communicate with users, and provide customer support.

Security & Compliance: Conduct quality assurance, detect fraud or abuse, maintain platform security, and comply with legal and regulatory obligations.

Improvement & Analytics: Improve healthcare delivery, analyze platform performance, and improve products and services.

3. Legal Basis for Processing

Depending on applicable laws, we may process information based on the following grounds:

  • Consent & Agreements: User consent, contractual necessity, and healthcare delivery obligations.
  • Legal & Protection: Compliance with legal obligations and the protection of vital interests.
  • Operations: Our legitimate operational interests.

4. Sharing of Information

We may share information with the following categories of recipients:

4.1 Healthcare Professionals and Providers

To ensure proper care coordination, data is shared only as reasonably necessary for healthcare delivery with:

  • Clinicians, hospitals, and referral partners.
  • Pharmacies, laboratories, and diagnostic centers.
  • Home-care providers.

4.2 Service Providers

We may use third-party providers who process information on our behalf under contractual confidentiality obligations for:

  • Cloud hosting, video consultations, and notifications.
  • Payment processing, security monitoring, and infrastructure management.
  • Analytics and customer support.

4.3 Legal and Regulatory Authorities

We may disclose your information where explicitly required by:

  • Law, court orders, or government requests.
  • Healthcare regulations and public health obligations.
  • Fraud prevention investigations.

4.4 Business Transfers

If the corporate entities operating the Platform undergo a merger, acquisition, restructuring, asset sale, or corporate reorganization, user information may be transferred as part of the transaction subject to applicable legal protections.

5. Health Information and Confidentiality

We recognize that healthcare information requires the highest level of privacy and protection. Because safeguarding this data is of critical importance, we implement commercially reasonable administrative, technical, and organizational safeguards designed to protect medical information from unauthorized access, disclosure, loss, misuse, or alteration.

Important Security Context: While we maintain these rigorous safeguards to protect your health data, no system can guarantee absolute security.

6. Data Retention

We retain information for as long as necessary to fulfill our service, legal, and operational requirements. Retention periods may vary depending on jurisdiction and healthcare regulations, based on our need to:

  • Provide services and maintain healthcare records (Care & Continuity).
  • Comply with laws, resolve disputes, and enforce agreements (Legal & Protection).
  • Maintain operational integrity (Platform Operations).

7. User Rights

Depending on applicable laws, users may have specific statutory rights regarding their personal data. Some rights may be limited by overriding healthcare, legal, or regulatory record-keeping obligations. Subject to these local laws, users may have rights to:

  • Data Access & Correction: Access personal and medical information, and correct inaccurate information.
  • Processing Control: Request deletion, restrict processing, or object to certain processing activities.
  • Portability & Consent: Request data portability and withdraw consent where applicable.

Formal Request Process: To protect patient privacy and comply with regulatory standards, certain actions (such as data deletion or record portability) must be formally requested and processed through our verification channels.

Requests to exercise these rights may be submitted using the contact information provided at the end of this policy.

8. Cookies and Tracking Technologies

To optimize your digital experience, we use cookies, pixels, analytics tools, session storage, device identifiers, and similar technologies. These automated tools help us:

  • Improve platform functionality and maintain security (Platform Operations).
  • Analyze usage patterns and personalize user experiences (Performance & Analytics).

Users may adjust their individual browser settings to manage cookie preferences, though some platform functionality may be affected as a result.

9. International Data Transfers

Your information may be processed or stored in countries outside your jurisdiction. Where international transfers occur, we are mindful to strictly respect applicable data protection laws by implementing the necessary legal and technical safeguards required for cross-border data transfers.

10. Children's Privacy

The Platform's services—including both online video consultations and in-person medical appointments—are not intended for use by minors without explicit parental or guardian authorization. Where legally required, verified parental or guardian consent must be obtained before collecting, storing, or processing any personal or medical information relating to minors across all delivery methods.

Consultation Requirement, Welfare & Safety Compliance: As detailed in our Patient Terms of Service, a parent, legal guardian, or authorized adult must generally be present for a minor's consultation. Exceptions to this requirement are strictly limited to emergency clinical circumstances or legal safety obligations, during which any confidential information collected will be handled in strict accordance with overriding medical privacy and mandatory reporting laws.

11. Third-Party Links and Services

The Platform may contain links or integrations with third-party websites, applications, or services. We are not responsible for the privacy practices or content of these independent services, and users should review their privacy policies independently.

Limitation of Liability: The Platform is not liable for data handling or security breaches occurring on third-party systems. This includes, without limitation, examples such as:

  • External Health Networks: Independent pharmacies, labs, or diagnostic centers.
  • Integrated Tools: Third-party mapping tools, calendar invites, or external payment gateways.
  • Informational Links: External medical resources or educational websites.

12. Security Measures

We implement commercially reasonable security measures designed to safeguard your information, including access controls, encryption where appropriate, authentication mechanisms, secure infrastructure, monitoring and logging, role-based access controls, and data backup and recovery procedures.

Systemic Limitations & Liability Exclusions: Despite these rigorous measures, no data transmission or storage system is completely secure. The Platform is not liable for data interruptions, exposures, or security failures resulting from events beyond our reasonable control. This includes, but is not limited to:

  • Infrastructure & Network Failures: Global or local internet latency, network routing dropouts, and telecommunication failures.
  • Operational Downtime: Scheduled or emergency website maintenance and hosting provider service outages.
  • Force Majeure Cyber Events: Highly sophisticated cyberattacks, zero-day exploits, or system breaches that occur despite industry-standard, reasonable security protocols being actively in place.

13. AI and Automated Systems

The Platform may use automated technologies, artificial intelligence (AI) systems, machine learning, or workflow automation tools to support and optimise our services. These technologies are strictly deployed to assist with:

  • User Experience: Support automation, user notifications, and recommendation systems.
  • Operational Efficiency: Triage assistance, automated scheduling, and care coordination.

Clinical Disclaimer & Liability Separation: Automated and AI systems do not replace professional medical judgment and are not engaged in the practice of medicine. All definitive clinical decisions, diagnoses, and treatment plans remain the absolute and sole responsibility of independent, licensed healthcare professionals.

14. Communications

We may contact users through various automated and manual channels to ensure the effective management of services.

14.1 Communication Categories

Our communications are divided into essential operational updates and transactional messaging, including:

  • Care & Scheduling: Appointment confirmations, reminders, care updates, and support responses.
  • Account Security: Critical platform updates, security alerts, and billing/transaction information.

14.2 Delivery Channels

Where enabled or permitted by user preferences, communications may occur via:

  • Email, SMS text messaging, and direct phone calls.
  • In-app messaging, system push notifications, or authorised third-party messaging channels (such as WhatsApp).

Opt-Out Control: Users may opt out of non-essential marketing or promotional communications at any time via their account settings. Essential transactional, security, and medical appointment notifications cannot be disabled, as they are required to maintain account integrity and patient care delivery.

15. Data Breach and Incident Response

In the event of a data breach or security incident, we are committed to swift action to protect user information. We may take any of the following steps:

  • Investigate the Incident: Promptly assess the nature, scope, and source of the breach or unauthorised access.
  • Mitigate Risks: Take immediate technical and operational measures to contain the incident and secure affected systems.
  • Notify Affected Users: Inform users whose personal data may have been compromised, in accordance with applicable legal timelines.
  • Notify Regulators: Inform relevant data protection authorities and regulatory bodies where required by governing law.
  • Remediation Measures: Implement enhanced security protocols, system patches, and operational changes to prevent future occurrences.

16. Limitation of Liability

To the fullest extent permitted by applicable law, the Platform, its directors, and its affiliates shall not be liable for any losses, claims, or damages resulting from:

  • Unauthorised Access: System breaches or data exposures caused maliciously or unlawfully by independent third parties.
  • Infrastructure Failures: Internet disruptions, telecommunication dropouts, and routing latencies outside our direct management.
  • User Negligence: Security lapses resulting from users failing to safeguard their login credentials, sharing account access, or ignoring security alerts.
  • Service Interruptions: Necessary platform downtime for scheduled emergency maintenance or hosting provider service outages.
  • Force Majeure Events: Security failures, zero-day exploits, or data losses occurring entirely beyond our reasonable control.
  • Indirect Damages: Any indirect, incidental, special, exemplary, or consequential damages arising out of your use or inability to use the Platform.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our operational practices, technological enhancements, or legal obligations.

  • Effective Date of Updates: Updated versions of this Privacy Policy shall become effective immediately upon being posted on the Platform, unless a specific future date or additional transition period is expressly required by applicable law.
  • Deemed Acceptance: Your continued use of the Platform, services, or applications after any updates have been published constitutes your explicit acceptance of the revised Privacy Policy and its terms.

18. Contact Information

For any privacy-related questions, data access requests, or regulatory matters, please contact us through the following dedicated channels to ensure your inquiry is routed correctly:

19. Governing Law and Jurisdiction

This Privacy Policy and any disputes or claims arising out of or in connection with it shall be governed by, and construed in accordance with, the laws of the Federal Republic of Nigeria.

  • Dispute Resolution: In the event of any dispute, controversy, or claim arising out of or relating to this policy, the parties shall first attempt to resolve the matter amicably through good-faith consultations.
  • Jurisdiction: If an amicable settlement cannot be reached, any legal proceedings or actions arising out of this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts of Nigeria.

20. Consent

By using the Platform, creating an account, accessing telehealth services, or otherwise interacting with the Services, you acknowledge that you have read, understood, and agreed to this Privacy Policy.