Privacy Policy
This is a health data platform. The information you provide about your body, pain, and health history is sensitive personal data and is treated as such throughout this policy. Please read it carefully before using the Service.
Introduction
Fesera Health Technologies ("Fesera," "we," "us," or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, why we collect it, how we use it, who we share it with, and what rights you have over your data.
By creating an account and using the Service, you agree to the practices described here.
1. Data Controller
The data controller responsible for your personal information is:
Fesera Health Technologies
Email: privacy@fesera.com
Website: fesera.com
For all privacy questions, requests, or complaints, contact us at the address above.
2. Legal Basis for Processing
We process your personal data under the following legal bases, as defined by the Nigeria Data Protection Act (NDPA) 2023, NDPR 2019, and the GDPR where applicable:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Contract performance |
| Delivering the assessment and programme | Contract performance |
| Processing payments | Contract performance |
| Platform safety and fraud prevention | Legitimate interest |
| Research using anonymised, aggregated data | Legitimate interest (anonymised data) |
| Research involving your identifiable data | Explicit, separate consent (opt-in only) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
3. Information We Collect
3.1 Account and Identity Information
- Email address: authentication, communications, account recovery
- Password: stored in hashed form; never stored in plaintext
- Name and profile details: to personalise your experience
- Timezone and locale preferences: to schedule sessions correctly
3.2 Health and Clinical Assessment Data
This is the most sensitive category of data we collect. It is treated as special category personal data under applicable data protection law and is subject to heightened protections.
- Pain metrics: intensity, duration, trajectory
- Red flag screening responses: to identify serious pathology risk
- Back pain subtype classification: to personalize your movement protocols
- Daily pain check-in scores and pre/post-session telemetry
- STarT Back risk score and psychological risk stratification
3.3 Payment Information
We do not collect or store your card number, CVV, expiry date, or bank account details. All card data is processed directly by Paystack under their PCI-DSS compliance programme. We only store transaction references and status.
4. Special Health Data Commitment
🔒 Zero Selling of Health Data
In addition to the security measures above, Fesera commits that your health data will never be shared with insurers, employers, financial institutions, or government bodies except as required by law. Your health data will never be sold, licensed, or shared with third parties for commercial or advertising purposes.
5. Research Use of Your Data
5.1 Anonymised Research (Default)
Fesera intends to use de-identified, aggregated data from the platform for health outcomes research, programme effectiveness evaluation, and the development of future rehabilitation programmes. "De-identified" means all direct identifiers (your name, email) have been removed or irreversibly transformed. Data of this kind does not constitute personal data under the NDPA.
You may object to even anonymised research use of your data by contacting privacy@fesera.com.
5.2 Identifiable Research (Opt-In Only)
If we ever wish to conduct research involving your identifiable personal or health data, we will contact you separately with a full description of the study and obtain your explicit, written, informed consent. Access to the Service is never conditional on participation in identifiable research.
6. Data Sharing and Infrastructure
We do not sell your personal data to any third party. We share data only with infrastructure providers acting as data processors under our instructions:
- Supabase: Encrypted cloud database & authentication. Fesera applies Row-Level Security (RLS) ensuring your data is only accessible to authenticated requests from your own account.
- Paystack: PCI-DSS compliant payment processing.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (name, email) | Duration of account + 2 years |
| Health and assessment data | Duration of account + 5 years |
| Payment records | 7 years (accounting/legal obligation) |
When you delete your account, we will permanently delete all personal and health data identifiable to you within 30 days, except where legally required to retain it or where data has been irreversibly anonymised.
8. Data Security
Our security measures include:
- Encryption: Data uses TLS (HTTPS) in transit and is encrypted at rest by Supabase.
- Row-Level Security (RLS): Database policies ensure authenticated queries can only access the requesting user's own data.
- Hashed passwords: Passwords are never stored in plaintext.
- Access controls: Internal access to user data is restricted on a need-to-know basis.
9. Your Privacy Rights
Fesera provides the same core set of privacy rights to all users, regardless of location:
- Access & Portability: Request a copy of the personal data we hold about you in a machine-readable format.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion where data is no longer necessary.
- Object & Withdraw Consent: Object to processing based on legitimate interests and withdraw any consent-based processing at any time.
To exercise any of these rights, email privacy@fesera.com with the subject line "Data Subject Request." We respond within 30 days.
Jurisdictional Rights
- Nigeria (NDPA 2023): You may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
- European Union (GDPR) / UK GDPR: You have the right not to be subject to solely automated decision-making. You may request human review of any automated classification. For EU data transfers, Fesera relies on Standard Contractual Clauses (SCCs).
- California, USA (CCPA/CPRA): Health data is sensitive personal information under CPRA. Fesera does not sell or share personal information for cross-context behavioural advertising.