Effective Date: October 20, 2025
Last Updated: October 15, 2025
The purpose of this Data Retention & Security Policy ("Policy") is to outline how MyDocki Digital Healthcare ("MyDocki", "we", "our", "us") collects, stores, protects, and manages user data throughout its lifecycle — from creation to deletion.
This policy ensures that all medical, financial, and personal information shared through the MyDocki App and Web Platform is handled responsibly, securely, and in full compliance with the Nigeria Data Protection Act (NDPA 2023) and other applicable global privacy laws.
This Policy applies to:
We retain data necessary for service delivery, compliance, and performance monitoring. These include:
We retain personal and medical data only for as long as it is legally or operationally required. The following categories define our standard retention durations:
| Data Category | Retention Duration | Purpose / Legal Basis |
|---|---|---|
| Account details & profile data | Active period + 2 years | Service continuity & legal reference |
| Consultation & medical records | 7 years | Medical documentation and dispute reference |
| Payment & transaction data | 5 years | CBN, NDPC, and audit compliance |
| Communication & chat logs | 2 years | Quality assurance & dispute resolution |
| Cookies & analytics data | 6–12 months | Performance tracking & user behavior analysis |
| Backup archives | 12 months | System recovery & disaster protection |
Once data exceeds its retention period, it will be securely deleted, anonymized, or archived in accordance with NDPA standards.
To ensure maximum protection of user data, MyDocki employs multi-layered security controls both at the application and infrastructure levels:
MyDocki may share limited user data with verified third-party partners (e.g., pharmacies, labs, logistics providers, payment processors) strictly for operational purposes.
All third-party partners must sign a Data Processing Agreement (DPA) ensuring compliance with NDPA 2023 and GDPR principles.
Partners are prohibited from using MyDocki data for independent marketing or unrelated services.
Users reserve full control and transparency over their personal data. At any time, you may:
Requests should be sent to privacy@mydocki.com, and MyDocki will respond within 30 business days.
When data is no longer required or upon user request:
MyDocki conducts periodic internal audits to ensure full compliance with NDPA and international standards.
Any staff or partner found breaching this policy will face disciplinary or legal action.
We maintain up-to-date documentation of all data processing and storage systems.
By using the MyDocki platform, you acknowledge that you have read and understood this Policy and consent to the secure processing and retention of your data as described herein.
For any questions, concerns, or requests regarding these Terms or your personal data, please contact our Data Protection Officer (DPO) at:
MyDocki Digital Healthcare
125 Olusegun Osoba Way, Oke Ilewo, Abeokuta, Ogun State, Nigeria
Email: support@mydocki.com
Phone: +234 901 615 31384