Privacy Policy
Last updated July 26, 2026
This policy explains how personal information and health information are handled when you use Homnics. It is not a substitute for the privacy notice of your healthcare facility.
Who we are and our privacy roles
Homnics Inc., Québec business number 1178668894, registered April 26, 2023, is located at 12-5720 AV. Trans Island, Montréal, Québec H3W 3B2, Canada. Homnics Inc. operates the platform. It is a service provider or subprocessor for facility-controlled clinical data and a controller for its own account administration, security, support, legal, and compliance data.
Homnics Health Limited, registration number 8582370, is located at Aliyu Bisiriyu Drive, off Dele Orisabiyi Street, Ago, Okota, Oshodi-Isolo, Lagos State, Nigeria. It is the Nigerian contracting entity and processes facility-controlled clinical data for participating facilities. It may control its own contractual, support, security, and compliance records.
Each participating Nigerian healthcare facility or care provider controls its patients' clinical records. Homnics processes those records on the facility's instructions. Contact your facility about its clinical-record practices or contact Homnics for platform privacy questions.
Who may use Homnics
The applications may be downloaded in Nigeria, Canada, the United States, the European Union, and other regions. Patient care through Homnics is restricted to people registered with participating healthcare facilities located and licensed in Nigeria. Some professionals may provide remote care from the United States or Canada while acting through a participating Nigerian facility.
Information we collect
Depending on the services you use, we may process:
- identity and contact details, date of birth, gender, address, and profile image;
- emergency contacts, dependants, beneficiaries, and guardian relationships;
- professional identity, licence documents, role, and facility affiliation;
- appointments, telemedicine participation, and patient-professional messages;
- symptoms, diagnoses, allergies, medical history, treatment, prescriptions, clinical notes, and uploaded health records;
- camera and microphone activity when you use supported capture or consultation features;
- push-notification tokens and delivery metadata;
- authentication, security, device, IP address, audit, and application activity;
- support, consent, privacy-request, account-closure, and deletion records;
- payment, invoice, and transaction information when payment features are enabled; and
- operational logs, metrics, and traces after configured sensitive-data filtering.
Homnics does not retain video-consultation recordings or transcripts.
Where information comes from
Information may come from patients; authorised parents or guardians; professionals and participating facilities; authorised remote professionals associated with those facilities; account, device, application, and security activity; integrations and service providers used for requested functionality; support interactions; and security investigations.
Why we process information
Depending on the jurisdiction and activity, we process information to provide the platform under a user, facility, or service contract; support healthcare delivery and management; meet legal, regulatory, tax, insurance, and professional obligations; secure the service, prevent fraud, investigate incidents, and maintain reliability; act with explicit consent where required; pursue legitimate interests not overridden by individual rights; protect vital interests in an emergency; and send marketing only with a separate opt-in where required.
Downloading or using the application is not blanket consent for all processing. We do not sell clinical data, provide it to data brokers, use it for behavioural advertising, or build advertising profiles from it.
Healthcare facilities and care providers
Professionals access patient information through their participating Nigerian facility. Access is restricted by role and facility association. Your facility determines the clinical purpose, permitted professional access, and retention period for your clinical record. Clinical-record requests may therefore need to be handled by that facility.
Service providers and disclosures
We disclose information only as needed to operate the service, deliver care, or meet legal duties:
- AWS for infrastructure, PostgreSQL databases, S3 object storage, and self-hosted observability services;
- Cloudflare for website and network delivery;
- self-hosted Duende Identity on AWS for identity and authentication;
- Apple, Google, Expo, and supporting infrastructure for app distribution and notifications;
- Jitsi/JaaS for video consultations;
- SendGrid, Twilio, and Resend for email and SMS;
- Stripe and Paystack for payments where enabled; and
- self-hosted Loki and Grafana on AWS for operational telemetry.
We may also disclose information to a participating facility, authorised care provider, professional adviser, regulator, law-enforcement authority, or successor organisation where permitted or required by law. Service providers are limited by contract and purpose.
International access and transfers
Data is hosted primarily in AWS. Authorised professionals may access patient information from Nigeria, the United States, or Canada while acting through the patient's Nigerian facility. Homnics uses role-based access controls and contractual, organisational, and technical safeguards for cross-border processing. Where required, Homnics completes privacy impact assessments and uses written transfer safeguards.
Security and operational telemetry
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including authenticated access, role and facility restrictions, encryption, monitoring, audit records, backups, and incident procedures. No security measure eliminates all risk. Sensitive data is filtered before OpenTelemetry data is exported to self-hosted Loki and Grafana on AWS. Telemetry supports security, reliability, troubleshooting, and performance, not advertising.
Camera, microphone, and notifications
Camera permission supports profile images, document or record capture, and video consultations. Microphone permission supports video consultations. Notification permission supports appointment, care, account, and security notifications. These permissions are requested when relevant, and denying one does not block unrelated features. Consultation audio and video are transmitted for the call but are not recorded or transcribed by Homnics.
Children and dependants
Independent Homnics accounts are for people aged 18 or older. A parent or guardian may add a child or other dependant as a beneficiary and manage that person's interactions and privacy requests. A minor does not receive an independent login. Turning 18 does not automatically create or transfer an account; a separate identity and authority verification process is required.
Retention and deletion
| Data category | Retention rule |
|---|---|
| Facility-controlled clinical records | Facility-defined period; preserved if no approved period is configured |
| Active patient profile and account data | While the account remains active |
| Eligible account data after verified deletion or approved closure | Deleted or anonymised within 30 days |
| Clinical authorship, care messages, and audit attribution | Facility clinical-record period |
| Non-clinical notification delivery metadata | 12 months |
| Filtered logs, metrics, and traces | 90 days |
| Support requests | 2 years after resolution |
| Consent, privacy-request, and deletion audit | 6 years |
| Payment, invoice, and tax records | 6 years after the relevant fiscal year, or longer if required |
| Temporary uploads and failed fragments | 7 days |
| Deleted production data remaining in backups | No longer than 35 days |
A legal, complaint, insurance, audit, or active-care hold may extend these periods. Account deletion and clinical-record retention are separate. Closing an account disables access and starts deletion or anonymisation of eligible Homnics-controlled data, but it does not require a facility to erase clinical records it must retain.
Delete a patient account
- Open the Homnics patient app and sign in.
- Open More and select Delete Account.
- Review the notice and confirm deletion.
Patient access is disabled immediately. Eligible Homnics-controlled account data is deleted or anonymised within 30 days. If you have forgotten your password, use Reset password and then return to the deletion screen.
If you cannot access the patient app, email support@homnics.com from the address registered to your account.
Close a professional account
- Open the Homnics professional app and sign in.
- Open Settings and select Request account closure.
- Review the notice and submit the request.
Professional access is disabled immediately. Homnics reviews the request because clinical records, prescriptions, signatures, and audit history may need to remain attributable to the professional. Eligible non-clinical account data is deleted or anonymised within 30 days after approval. If you have forgotten your password, use Reset password.
If you cannot access the professional app, email support@homnics.com from the address registered to your account.
Your rights
Subject to applicable law, identity verification, and clinical-record obligations, you may request information and access, correction, deletion, restriction or objection, portability, withdrawal of consent, human review of a qualifying automated decision, and information about international transfers and recipients. We aim to respond within 30 days unless law permits or requires another period. Contact your facility for rights concerning its clinical records or contact Homnics for platform-controlled information.
Complaints
Please contact us first so we can address your concern. Depending on the matter and applicable law, you may also complain to the Nigeria Data Protection Commission, the Commission d'accès à l'information du Québec, your healthcare facility, or the privacy regulator where you live.
Changes to this policy
We may update this policy as services, providers, or legal requirements change. We will update the effective date and provide additional notice when a change is material.
Contact us
Privacy lead: Lawrence Eze, CTO and Co-founder, Homnics Inc.
Email: lawrence.eze@homnics.com
Address: 12-5720 AV. Trans Island, Montréal, Québec H3W 3B2, Canada