Privacy Policy

Last Updated: September 2026

1. About e’Clat

e’Clat Healthcare Limited is a wholly-owned Nigerian medical services company that aims to improve healthcare delivery in Africa using technological innovative frameworks. We specialize in assisting healthcare service providers in planning, designing, and operating their unique practices. Our products and services are essential building blocks for successful healthcare. We are a member of the Interswitch Group.

2. About Interswitch

Interswitch is an Africa-focused integrated digital payments and commerce company that facilitates the electronic circulation of money as well as the exchange of value between individuals and organizations on a timely and consistent basis.

This privacy policy will explain how our organization uses the personal data we collect from our customers and related partners when you use our website or subscribe to use any of our products and services.

3. Introduction

Interswitch conducts business in a responsible and sustainable manner and ensures customer information is securely collected, processed, and stored based on business requirements. In furtherance of this and compliance with industry regulations, Interswitch has made appropriate documentation, which includes a privacy policy. Interswitch, therefore, provides notice about this policy, applicable procedures, and identifies the purposes for which personal information is collected, used, processed, disclosed, retained, and disposed of.

Throughout this Privacy Policy, we use the term “personal information or data” to describe information that can be associated with a specific person and can be used to identify that person. We do not consider personal information to include information that has been made anonymous so that it does not identify a specific user.

As a Customer, you accept this Privacy Policy when you sign up for, access, or use our products, services, content, features, technologies, or functions offered on our website and all related sites, applications, and services (collectively referred to as “Interswitch Services”).

This Privacy Policy is intended to govern the use of Interswitch Services by users (including, without limitation, those who use these Interswitch Services in the daily course of their trade, practice, or business) unless otherwise agreed through contract. Users reserve the right to exercise their data protection rights as listed under the Customer Data Protection Rights.

5. Collection of Personal Information

We collect Personally Identifiable Information (PII), otherwise known as Personal Information or Personal Data, which includes Protected Health Information (PHI), otherwise known as health-related personal data. This may include but is not limited to:

  • General identifiers: name, email address, phone number, contact address, and limited financial information.
  • Health information: medical history, diagnoses, treatments, laboratory results, health conditions, billing information related to healthcare services, hospital numbers, and patient IDs.
  • Technical and location data: location data, device data, and other related information.

6. How We Collect Personal Information

Customers’ data is collected electronically and manually when they visit our website and register to use any of our services. This is collected electronically through exchanges between your system (computer, server, mobile device) or service provider’s system and our system.

We collect customers’ data manually when they complete our product and services registration forms to register for any of our services. Similar data are also collected when customers or visitors visit our physical locations for inquiries or business relationships.

We collect information from or about customers from other sources, such as through your contact with us, including our customer support interfaces — email, portal, phone calls, social media, and other communication channels; customer support teams; customer responses to surveys; training programs; corporate social responsibility events; promotional events; and interactions with members of the Interswitch Group or other companies (subject to their privacy policies and applicable law).

We also collect patient data when your doctors, hospitals, laboratories, insurers, or other authorized entities share information with us as part of providing you with healthcare-related services.

We may also obtain information about you from third parties such as credit bureaus and identity verification services.

7. How We Use Collected Information

We collect personal information to provide users of our services with a secure, smooth, efficient, and customized experience. The information collected may also be used to:

  • Provide Interswitch Services and customer support, provide healthcare-related services, and verify your identity, including during account creation and password reset processes.
  • Resolve disputes, collect fees, and troubleshoot problems.
  • Manage risk, or detect, prevent, and/or remediate fraud or other potentially prohibited or illegal activities, including violations of policies or applicable user agreements.
  • Improve Services by customizing your user experience; measure the performance of Interswitch Services and improve their content and layout.
  • Manage and protect our information technology infrastructure.
  • Provide targeted marketing and advertising, service update notices, and promotional offers based on your communication preferences.
  • Contact you at any telephone number, by voice call, text (SMS), or email messaging.
  • Perform creditworthiness and solvency checks, and compare information for accuracy and verify it with third parties.

We may also contact you via electronic means to notify you regarding your account, troubleshoot problems, resolve a dispute, collect fees or monies owed, poll your opinions through surveys or questionnaires, or as otherwise necessary to service your account. We may also contact you to offer coupons, discounts, and promotions, and to inform you about Interswitch Services or its group services.

Finally, we may contact you as necessary to enforce our policies, applicable law, or any agreement we may have with you. When contacting you via phone, to reach you as efficiently as possible we may use, and you consent to receive, auto-dialled or prerecorded calls and text messages. Where applicable and permitted by law, you may decline to receive certain communications.

8. Lawful Basis for Collecting and Processing Personal Data

In line with applicable data protection laws, we process your personal information based on the following legal grounds:

  1. Consent: Where you have given us permission to collect, use, and process your personal information and health-related information. You can withdraw your consent at any time.
  2. Contractual Obligation: We require certain personal information or health-related information to enter into and perform our contractual obligations with you. Without this data, we are unable to provide you with our services.
  3. Legal Obligation: We are legally required to process certain personal data to comply with applicable laws and regulations, such as Anti-Money Laundering and Counter-Terrorist Financing laws, and to prevent fraud, money laundering, or terrorist financing.
  4. Legitimate Interest: We process your personal information to pursue our legitimate business interests, provided such processing does not override your data subject rights. Examples include:
    • Fraud prevention and identity verification
    • Securing our systems and services
    • Understanding how you interact with our sites to improve user experience
    • Communicating relevant updates, offers, or campaigns
  5. Vital Interests (Health and Safety): In limited circumstances, we may process your PHI to protect your vital interests or those of another person — for example, providing critical health information to emergency services in a medical emergency to protect your life or health.

9. Protection and Storage of Personal Information

We store and process your personal information on our computers in Lagos, Nigeria, and anywhere else where our facilities are located. We protect your information using physical, technical, and administrative security measures to reduce the risks of loss, misuse, unauthorized access, disclosure, and alteration.

Some of the safeguards we use are firewalls and data encryption, physical access controls to our data centers, and information access authorization controls. We have also taken additional measures to ensure our systems comply with industry information security standards.

10. Marketing

We do not sell or rent your personal information to third parties for their marketing purposes without your explicit consent. We may combine customer information with information collected from other companies and use it to improve and personalize Interswitch services, content, and advertising. We have also provided an opportunity for customers who initially subscribed to receiving notifications or information about their activities in relation to Interswitch’s services to unsubscribe or request removal from applicable databases.

When transacting with others, we may provide those parties with information to complete the transaction, such as your name, account ID, contact details, shipping and billing address, or other information needed to promote the reliability and security of the transaction. If a transaction is held, fails, or is later invalidated, we may also provide details of the unsuccessful transaction.

To facilitate dispute resolution, we may provide a buyer with the seller’s address so that goods can be returned to the seller. The receiving party is not allowed to use this information for unrelated purposes, such as direct marketing, unless you have agreed to it. Contacting users with unwanted or threatening messages is not authorized by Interswitch.

We may provide or display customer information to a third party while consummating transactions to validate that those transactions are being exchanged with valid receivers.

We work with third parties, including merchants, to enable them to accept or send payments from or to customers using Interswitch Services. In doing so, a third party may share information about customers with us, such as email address or mobile phone number, to inform such customers that a payment has been sent. We use this information to confirm that users are Interswitch customers and that Interswitch as a form of payment can be enabled, or to send customer notification of payment status. We may also fulfill requests to validate that a customer transacts business with Interswitch.

Customers’ card information may be available for subsequent reuse if they chose for it to be remembered at a previous attempt. Note that merchants, sellers, and users involved in transactions may have their own privacy policies, and Interswitch does not allow the other transacting party to use this information for anything other than providing Interswitch Services; Interswitch is not responsible for their actions, including their information protection practices.

Interswitch will not disclose your credit/debit card number or bank account number to anyone, or to third parties that offer or use Interswitch Services, except with customers’ express permission or if we are required to do so to comply with credit/debit card rules, a subpoena, law enforcement, or other legal processes.

We may share customers’ personal information with:

  1. Members of the Interswitch group, to provide joint content, products, and services (such as registration, transactions, and customer support), to help detect and prevent potentially illegal acts and violations of our policies, and to guide decisions about their products, services, and communications. This information will only be used for marketing communications if customers have requested the service.
  2. Institutions that we partner with to jointly create and offer products, services, promotions, and rewards, as well as institutions that we partner with to run events.
  3. Credit bureaus and collection agencies, to report account information, as permitted by law.
  4. Banking partners, as required by credit/debit card association rules for inclusion on their list of terminated merchants.
  5. Companies that we plan to merge with or are acquired by. Should such a combination occur, we will require that the new combined entity follow this Privacy Policy with respect to customer personal information. Customers will receive prior notice if personal information would be used contrary to this policy.
  6. Law enforcement, government officials, or other third parties pursuant to a subpoena, court order, or other legal process or requirement applicable to Interswitch or one of its affiliates; when we need to do so to comply with law or credit/debit card rules; or when we believe, in our sole discretion, that disclosure is necessary to prevent physical harm or financial loss, to report suspected illegal activity, or to investigate violations of our User Agreement.

We may also share your personal information with other unaffiliated third parties for the following purposes:

  • Fraud Prevention and Risk Management: to help prevent fraud or assess and manage risk.
  • Customer Service: for customer service purposes, including to help service your accounts or resolve disputes.
  • Shipping: in connection with shipping and related services for purchases made using Interswitch Services.
  • Legal Compliance: to help comply with anti-money laundering and counter-terrorist financing verification requirements, and Central Bank of Nigeria regulations on Know Your Customer (KYC).
  • Service Providers: to enable service providers under contract with us to support our business operations, such as fraud prevention, bill collection, marketing, customer service, address verification, and technology services. Our contracts require these service providers to use customer information only in connection with the services they perform for us, not for their own benefit.
  • Other third parties, with your consent or direction to do so.

Please note that these third parties may be in other countries where laws on processing personal information may be less stringent than in our country of primary jurisdiction. If customers open any of our products, services, or related wallet accounts directly on a third-party website or via a third-party application, any information entered on such systems (and not directly on an Interswitch website) will be shared with the owner of the third-party website or application. These sites are governed by their own privacy policies, and customers are encouraged to review them before providing personal information. Interswitch is not responsible for the content or information practices of such third parties.

Where services involve healthcare or related support, we may also share customers’ Protected Health Information (PHI) with authorized third parties strictly for the purposes of healthcare delivery, billing, and compliance. These third parties may include:

  • Hospitals, clinics, and healthcare providers supporting diagnosis, treatment, or care delivery.
  • Health Maintenance Organizations (HMOs) and insurers, for claims processing, accounts, and billing.
  • Laboratories and diagnostic centers, for tests and reporting.
  • Regulators or government authorities, where required by law.

We ensure that such third parties are bound by confidentiality and data protection obligations and may not use PHI for unrelated purposes such as marketing, unless the customer has expressly consented.

13. Cross-Border Transfers of Personal Information

Interswitch is committed to adequately protecting customers’ personal information regardless of where the data resides, and to providing appropriate protection where such data is transferred across borders, including outside of Nigeria. We have taken measures to ensure our relationships are with countries governed by data protection regulations similar to our own, and we continue to assess other entities to provide reasonable assurance of the safety of customers’ information.

14. Customer Data Protection Rights

Our customers have data protection rights and are entitled to the following:

  • The right to access: Customers have the right to request copies of their personal data. Interswitch may charge a fee for this service if it requires a substantial amount of resources.
  • The right to rectification: Customers have the right to request that Interswitch correct any information they believe, and have proven, has been captured inaccurately, or complete information they believe is incomplete.
  • The right to erasure: Customers have the right to request that Interswitch erase their personal data, under certain conditions — including regulatory requirements, law enforcement agencies, or where such action may cause disruption to our systems.
  • The right to restrict processing: Customers have the right to request that Interswitch restrict the processing of their personal data, under certain conditions.
  • The right to object to processing: Customers have the right to object to our processing of their personal data, under certain conditions.
  • The right to data portability: Customers have the right to request that Interswitch transfer the data we have collected to another organization, or directly to them, under certain conditions.
  • The right to object to automated decision-making: Customers have the right not to be subject to decisions made solely on automated processing of their personal data, including profiling, where such decisions have legal or similarly significant effects on them. This right does not apply if the decision is necessary for entering into or performing a contract, is authorized by law with appropriate safeguards, or is based on the customer’s consent.

If we collect your personal data directly from you, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) in accordance with Section 46(1) of the Nigeria Data Protection Act. We recommend that this right be exercised if:

  • The concern relates to a potential breach of your data privacy rights, or we have used your personal data in a manner different from the purpose outlined in this Privacy Policy;
  • You have first raised the concern with us by contacting our Data Protection Office using the communication channel provided in Section 20 of this Privacy Policy; and
  • We do not respond to your complaint within 2 to 4 working weeks from the date of your complaint.

Customer requests based on any of the rights above will be handled within 2 to 4 working weeks. Customers may contact us by email or in writing using the details in Section 20.

15. The Use of Cookies and Similar Technologies

When customers access our websites or use Interswitch Services, we may place small data files on your computer or other devices. These data files may be cookies, pixel tags, “Flash cookies,” or other local storage provided by your browser or associated applications (collectively, “Cookies”). These technologies are used to recognize users as customers; customize Interswitch Services, content, and advertising; measure promotional effectiveness; help ensure account security is not compromised; mitigate risk and prevent fraud; and promote trust and safety across Interswitch Services and related sites.

Users can decline our Cookies if their web browser or browser add-on permits it, unless our Cookies are required to prevent fraud or ensure the security of websites we control. However, declining our Cookies may interfere with your use of our websites and Interswitch Services.

16. Privacy Policies of Other Websites

This privacy policy applies only to the Interswitch Group and not to any other brands mentioned on our websites. Nor does it apply to our merchants, vendors, or other related partners.

Please refer to the end of this notice for providing your consent. Your consent to personal data collection and processing may be revoked by notifying us via our contact page. For users below the age of 13, consent should be provided by the holder of parental responsibility for the child.

Please note that if you choose not to provide consent, or withdraw your consent at any point, we will not be able to provide the services described in Section 4 of this policy.

18. Available Remedies

In the event of a violation of this policy by the Company, we will, immediately upon becoming aware of such violation, assess the extent of the violation and take specific actions such as correction, modification, or transfer of the data, subject to the lawful demands of the data subject. Corrective actions will be effected within 30 days, subject to external factors not within the reasonable control of the Company.

19. Changes to Our Privacy Policy

We review our privacy policy periodically and whenever there is a substantial change to business or regulatory requirements. At minimum, we review this policy annually and communicate changes via our communication channels, such as our newsletter, website, and social media accounts.

20. How to Contact Us

Customers who have concerns or questions about this privacy policy, or would like to exercise their data protection rights, can contact us through the following channels:

Central Bank of Nigeria

Interswitch is regulated by the Central Bank of Nigeria