1. Who we are
XO Technologies Ltd ("XO Technologies", "we", "us") is a company registered in Nigeria, registered as RC 1761601, with its registered office at Alexandria Crescent, Wuse 2, Abuja, FCT, Nigeria. We build operational software for Nigerian organisations. Our first product, XO Continuity, is an appointment reminder and follow-up platform used by private healthcare facilities.
Questions about this policy or about your personal data can be directed to XO Technologies Ltd in writing at our registered office address above.
2. Our role: processor and controller
Where a healthcare facility uses our platform to manage its own patients, that facility decides what patient data is collected and why. The facility is the data controller; XO Technologies acts as a data processor on its instructions. We process patient data only to deliver the service the facility has asked for.
For data collected directly by us, for example when you email us or a facility signs up for an account, XO Technologies is the controller.
3. Personal data we process
- Patient data entered by a facility: name, phone number, appointment date, time and type, attendance status, assigned clinician, and notes recorded by clinic staff.
- Message records: the appointment messages sent to a patient, the channel used, delivery status, and any reply such as a confirmation or an opt-out request.
- Account data for facility staff: name, work email address, role, and access log entries.
- Technical data: log records needed to keep the service secure and available.
We do not collect payment card details, and we do not process clinical diagnostic records beyond the notes a facility chooses to store against an appointment.
4. How we use personal data
- To send appointment reminders and missed-appointment follow-up messages on behalf of the facility.
- To record whether an appointment was confirmed, attended, missed, or rebooked.
- To produce attendance and recovery reporting for the facility's own management.
- To operate, secure, support, and improve the platform.
- To comply with legal obligations that apply to us.
We do not sell personal data. We do not use patient contact details for advertising or marketing, and we do not share them with third parties for their own marketing purposes.
5. Messaging, consent, and opt-out
Appointment messages are transactional: they relate to a booking the patient has already made with the facility. Patients provide their phone number to the facility at registration and are informed that appointment messages will be sent to it. Facilities are responsible for obtaining and recording that consent.
A patient may opt out at any time by replying STOP to any message, or by asking the facility directly. Once a number is opted out, our platform stops sending automated messages to it. Patients may also contact the facility to correct or delete their details.
Messages are delivered through WhatsApp Business Platform and, where WhatsApp delivery is unavailable, through an SMS gateway. These providers process the message and the recipient number in order to deliver it, under their own terms and privacy policies.
6. Legal basis
We process personal data under the Nigeria Data Protection Act 2023. Depending on the situation, the basis is the consent given by the patient to the facility, the performance of a contract with the facility, our legitimate interest in operating and securing the platform, or compliance with a legal obligation.
7. Service providers
We use a small number of established providers to run the platform, including cloud hosting and database services, messaging providers for WhatsApp and SMS delivery, transactional email delivery, and error monitoring. Each is engaged under terms that require them to protect the data they process and to use it only to provide their service to us.
8. International transfers
Some of our providers operate infrastructure outside Nigeria. Where personal data is transferred outside Nigeria, we take steps to ensure it remains protected to a standard consistent with the Nigeria Data Protection Act 2023, including contractual protections with the provider.
9. Retention
Patient and appointment data is retained for as long as the facility maintains an account with us and requires it for patient care and record keeping. When a facility leaves the platform, its data is deleted on request within a reasonable period, subject to any retention we are legally required to observe.
10. Security
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption of data in transit, encryption of personal data at rest, role-based access control, separation of each facility's data from every other facility's data, and restricted, logged administrative access.
11. Your rights
Subject to Nigerian data protection law, you have the right to request access to your personal data, to have inaccurate data corrected, to request deletion, to object to certain processing, and to withdraw consent. If you are a patient, contact the facility that holds your record in the first instance; you may also write to us at our registered office address and we will assist the facility in responding. You may lodge a complaint with the Nigeria Data Protection Commission.
12. Children
Our platform is used by healthcare facilities and their staff. Where a facility records an appointment for a minor, the contact details held are ordinarily those of a parent or guardian, and consent is the responsibility of the facility.
13. Changes to this policy
We may update this policy as the platform develops. The date at the top of this page shows when it was last revised. Material changes will be communicated to the facilities using our platform.
