Drughub Pharmacy operates www.drughubpharmacy.ng and provides pharmaceutical services to customers, patients, and users in Nigeria and internationally. This Privacy Policy explains how we collect, use, disclose, and protect your personal data in compliance with the Nigeria Data Protection Act (NDPA) 2023 and applicable international laws like GDPR for users abroad.
We collect personal data necessary for pharmacy services, including identity (name, date of birth, gender), contact details (address, phone, email), health information (prescriptions, medical history, lab results), payment details, and technical data (IP address, browser type, usage logs). For account registration or orders, we gather exemption details, delivery preferences, and survey responses. Sensitive health data is treated with extra care as "special category data" under NDPA.
Your data is used to process orders, dispense medications, arrange deliveries, provide patient counseling, manage accounts, detect fraud, and improve services (e.g., analytics, surveys). Lawful bases include contract performance (e.g., fulfilling prescriptions), legal obligations (health regulations), consent (marketing), and legitimate interests (security). We may use de-identified data for public health research or regulatory reporting, always minimizing data collected.
Under NDPA, processing follows principles like lawfulness, purpose limitation, data minimization, and accuracy. Bases include consent (freely given, specific, informed), contract necessity, vital interests (health emergencies), and public interest (public health under healthcare professional guidance). For GDPR users, we rely on explicit consent for sensitive data and ensure adequacy.
We share data only as needed: with pharmacies/branches for dispensing, couriers for delivery, payment processors, regulators (e.g., NDPC, health authorities), or legal advisors. Third parties are bound by contracts ensuring NDPA compliance. No sale of data occurs.
For abroad users or services (e.g., cloud hosting), transfers occur only to countries with adequate protection or via safeguards like standard contractual clauses, binding corporate rules, or NDPC-approved mechanisms. We document transfer justifications.
We implement technical (encryption, access controls) and organizational measures (staff training, DPIAs for high-risk processing) to protect data against breaches. Health data receives heightened safeguards per NDPA and National Health Act.
Data is retained only as necessary: order records for 7 years (legal requirement), accounts until deletion requested. Health data follows clinical guidelines. We securely delete or anonymize data post-retention.
You have rights to access, correct, erase, restrict, port, or object to processing (including profiling). Withdraw consent anytime without affecting prior processing. Exercise via privacy@drughubpharmacy.ng; responses within 30 days. Complain to NDPC (ng) or relevant authority (abroad).
We use cookies for site functionality, analytics (Google Analytics), and preferences. Manage via browser settings or our consent banner. Essential cookies are not rejected.
No data collection from children under 18 without parental consent. Parents can request deletion.
We may update this policy; changes post online with date. Continued use implies acceptance.