NotisCare
Privacy Policy
Last updated July 2026
Who this applies to
This policy covers how NotisCare (“we”, “us”) collects, stores, and processes data through the NotisCare platform, operated for care homes in Nigeria. It applies to residents, their substitute decision-makers, and staff (Personal Support Workers, Clinicians, and Administrators) at facilities using NotisCare.
What we collect
- Resident observation data: free-text and structured notes submitted by care staff, category and severity classification, timestamps, and AI-generated triage output (Fine / Watch / Urgent).
- Resident profile data: name, room number, date of birth, admission date, pre-existing conditions, and consent records — entered by facility administrators, not collected directly from residents by us.
- Staff account data: name, email, role, and login activity for each person your facility registers.
- Audit and security data: IP address, user agent, and a timestamped log of every action taken in the system, retained for regulatory audit purposes.
Legal basis and consent
Observations containing resident health information are only recorded once your facility has obtained and recorded consent under NDPA 2023 s.27. NotisCare provides the consent-recording workflow; the facility, as data custodian, is responsible for obtaining valid consent from the resident or their substitute decision-maker before any observation is logged.
Where your data lives
Data stored securely · Nigeria Data Protection Act 2023 compliant.
We do not transfer resident health data outside this region for storage. Where a processing step temporarily uses infrastructure outside Nigeria (for example, before a regional AI or transcription provider is fully activated for your market), this is disclosed to your facility in advance and is limited to processing, not storage.
Who else sees it
We use a small number of sub-processors to run the platform. None of them can access resident data outside the purpose listed:
- Cloud hosting and database (AWS, eu-west-1) — storage and compute.
- Email delivery (Resend) — DOC/RM alert emails.
- WhatsApp alerts (Twilio) — urgent notification delivery; message content is limited to resident first name and room, never full notes.
- AI triage classification — urgency scoring of observation text.
We never sell resident or staff data, and we never use it to train third-party AI models without your facility’s written agreement.
Security
- AES-256 encryption at rest, TLS 1.3 in transit.
- Role-based access — staff only see the facility and residents they are authorised for.
- Every read and write action is logged permanently with staff name, timestamp, and action type.
- Session tokens expire automatically and are invalidated on logout.
Retention and deletion
Observation and audit data is retained for as long as your facility is an active NotisCare customer, to preserve the clinical and audit history regulators expect. If your facility stops using NotisCare, we delete all resident and facility data within 30 days and send written confirmation once deletion is complete.
Your rights
Residents, substitute decision-makers, and staff can request access to, correction of, or deletion of their personal data by contacting their facility administrator, who can action most requests directly, or by emailing opeyemi@undauntedlab.com. You may also lodge a complaint with Nigeria Data Protection Commission (NDPC).
Cookies
The NotisCare marketing site uses only the cookies required to load the booking widget (Cal.com) used to schedule demo calls. We do not run advertising trackers or third-party analytics on this site.
Changes to this policy
If we make a material change to how we handle resident or staff data, we will notify your facility administrator by email before the change takes effect.
Contact
Questions about this policy or a specific data request: opeyemi@undauntedlab.com