Privacy Policy

Version 2026-07-26 · Effective 26 July 2026

AirSpire Health (“AirSpire”, “we”) operates a digital asthma-management service for patients in Nigeria: symptom and peak-flow tracking, an automated zone/action-plan engine, video consultations with physicians, prescriptions, and medication delivery. This policy explains exactly what we collect, why, who else sees it, how long we keep it, and what you can require us to do about it.

We are the data controller for the personal data described here. We process it under the Nigeria Data Protection Act 2023 (NDPA), supervised by the Nigeria Data Protection Commission (NDPC). Health data is sensitive personal data under the NDPA, so we rely on your explicit consent to process it — recorded, dated, and withdrawable (see Consent).

AirSpire is not an emergency service. If you are struggling to breathe, use your rescue inhaler and call 112 (or 199) or go to the nearest emergency room. Do not wait for a reply through the app.

1. What we collect

Everything below is data this application actually stores. We do not collect location beyond the city and state you type, we do not read your contacts or device sensors, and we run no advertising or cross-site tracking.

Account data

Email address, first and last name, phone number, profile photo if you upload one, a one-way hash of your password (never the password itself), whether your email is verified, two-factor authentication settings if you enable them, and sign-in timestamps. A session cookie keeps you signed in for up to 24 hours.

Patient health profile

Date of birth, gender, phone, address, city, state, country, blood type, known allergies, your personal-best peak-flow value, your current zone status, the physician assigned to you, your subscription plan, and an emergency contact’s name, phone number, and relationship to you.

Health records you create

  • Symptom logs — date and time of day, overall severity, coughing, wheezing, shortness of breath, chest tightness, night waking and how often, activity limitation, rescue-inhaler use and number of puffs, and your free-text triggers and notes.
  • Peak-flow readings — the reading in L/min, your personal best at the time, the calculated percentage and green/yellow/red zone, time of day, whether it was taken before or after medication, and your notes.
  • Questionnaires — Asthma Control Test and similar responses, your score, the calculated risk level, and whether a physician has reviewed it.
  • Action plans, zone history, and alerts — the output of our automated engine, the daily zone recalculations it runs, and the alerts it raises for your physician, including what your physician did about each one.

Care and clinical data

Appointments (physician, date and time, status, fee, payment reference, video-room identifier), your physician’s consultation notes (subjective, objective, assessment, plan, follow-up and referral notes), and prescriptions including medication names, dosage, and instructions.

Shop, orders, and payments

Cart contents, orders and their line items, order totals in naira, delivery address, city, state, phone and delivery notes, pharmacy fulfilment status and notes, delivery tracking details, and the Paystack payment reference and status for each payment attempt. We never see or store your card number, CVV, or bank credentials — card details are entered on Paystack’s own payment page and stay with Paystack.

Physician data

If you register as a physician: specialty, medical licence number, issuing body and expiry, years of experience, biography, consultation fee, availability, the credential documents you upload for review, and — so we can pay you — your bank code, account number, account name, and the Paystack subaccount we create for you.

Records-access log and consent log

Designated physician record views, data exports, credential decisions, and selected clinical or operations actions write an audit entry: who, what record, what action, why, and when. This does not mean that every operations-page view is currently logged. While your account is active, we keep a dated, append-only log of each consent grant or withdrawal and the document version involved. An approved account-erasure request removes that subject-linked consent ledger along with the rest of the account data.

Technical data

Our hosting and content-delivery providers process your IP address, browser user-agent, and request timing in order to serve and secure the site. If you accept the cookie banner, the platform sets one anonymous identifier cookie (_bm_vid) used only to count page views and session length. It is stored in our own database, is not shared, and is not used to track you across other websites. Cloudflare also provides cookie-free web analytics and performance monitoring. Its beacon processes the page path, referring site, country, device type, browser, operating system, and page-load timings; Cloudflare states that it does not use this to identify or track an individual across sites. We use no Google Analytics, advertising pixels, or social-media trackers.

2. Why we use it

  • To run your account and authenticate you (performance of our contract with you).
  • To deliver care: track your asthma, calculate your zone, generate and update your action plan, and alert your physician when your readings deteriorate (your explicit consent, and the vital-interests basis where an alert is urgent).
  • To let you book and hold video consultations, and to let your assigned physician read the chart they need in order to treat you (explicit consent).
  • To take payment for consultations and shop orders and to pay physicians their share (contract; legal obligation for financial records).
  • To fulfil and deliver medication orders through pharmacy partners (contract).
  • To send the transactional email you would expect: welcome, appointment confirmation and reminders, medication reminders, order confirmation, and red-zone safety alerts (contract, consent).
  • To keep the service secure, prevent abuse, and maintain the records-access audit trail (legitimate interest, legal obligation).

We do not sell your data, share it with advertisers, or use it to train machine-learning models. The zone and action-plan engine is deterministic clinical logic, not a model trained on other patients’ data.

3. Who else sees it

Inside AirSpire, access is limited by role: you see your own records; the physician assigned to you sees your clinical chart; our operations team sees what it needs to run the service. Designated clinical and operations flows record access as described above. Beyond that, these are the only third parties involved, and what each one receives:

Who What for What they get
Paystack Payments Limited (Nigeria) Card and bank payments in naira; physician payouts Your email, the amount, and our order or appointment reference. Card details go directly to Paystack. For physicians: bank account details, to create the payout subaccount.
Benmore Technologies Application hosting, database, file storage, and the managed email service (delivered via Amazon SES) As our hosting processor, Benmore holds all of the data above on our behalf. Email delivery receives the recipient address and the message content.
Cloudflare Content delivery, TLS termination, protection against attacks, and privacy-focused web analytics/performance monitoring Connection metadata plus aggregate page path, referrer, country, device/browser/operating-system category, and page-load timings. The analytics beacon uses no cookie or local-storage identifier.
Google public STUN server Discovering your network address so a video call can connect Your IP address only. No audio, video, or health data passes through it.
A relay (TURN) server, where configured Carrying video-call media when a direct connection cannot be established Encrypted audio and video packets, which it cannot decrypt. Nothing is recorded.
Pharmacy and delivery partners Dispensing and delivering the medication you order Your name, delivery address and phone, and the items on that order, including the prescription where one is required.

We may also disclose data where the law requires it — a court order, a lawful regulatory request, or to protect someone’s life.

4. Video consultations

Video visits connect your browser directly to your physician’s browser (peer-to-peer WebRTC). The audio and video stream is encrypted in transit and AirSpire does not record it. What persists afterwards is what your physician writes down: consultation notes, prescriptions, and any change to your action plan.

5. Transfers outside Nigeria

Paystack is a Nigerian company and processes payments in Nigeria. Our hosting, content-delivery, and email providers operate global infrastructure, so your data — including health data — may be stored or processed outside Nigeria. Where that happens we rely on the transfer conditions in sections 41 to 43 of the NDPA and require each provider by contract to protect the data to the standard this policy describes. If you would like the current list of processing locations, ask us using the contact details below.

6. How long we keep it

  • Clinical records (symptom logs, peak-flow readings, questionnaires, action plans, consultation notes, prescriptions) are kept while your account is open, and after it closes for the period required by Nigerian medical-records and tax law. We are finalising those exact periods with legal counsel; until they are fixed we retain rather than delete, and your right to erasure below still applies.
  • Order and payment records are kept for the period required by Nigerian tax and financial-record law.
  • The records-access audit log is kept long-term: it is the evidence that access to your chart was proper, so it survives even the erasure of the record it refers to, with your identity removed from it (see below).
  • Your consent log is kept for as long as your account exists, so we can always show what you agreed to and when.
  • Account and session data are kept while your account is open. Sessions expire after 24 hours.

We are honest about one gap: deletion at the end of a retention period is currently performed by our operations team on request or on review, not by an automated job. That is a limitation we are closing, and it does not affect your ability to require erasure now.

When you create an account you are asked to accept the Terms of Service, this Privacy Policy, and the Health Data Protection Notice, and separately to consent to us collecting and processing your health data. Each of those is recorded as a dated entry noting which version of the document you accepted.

You can withdraw any consent at any time under Settings → Consent Controls. Withdrawal is recorded as a new entry rather than by deleting the original — that way the record of what you agreed to, and of your decision to withdraw, both survive. Withdrawing consent to health-data collection takes effect immediately: AirSpire stops accepting new symptom, peak-flow, and questionnaire entries until you grant it again. Withdrawing acceptance of the Terms, this policy, or the Health Data Protection Notice means we can no longer operate the service for you, so you will be asked to accept them again or to close your account.

When we materially change one of these documents we publish a new version and ask you to review and accept it the next time you open the portal. Withdrawing consent does not undo processing that already, lawfully, happened.

8. Your rights under the NDPA

You have the right to:

  • Access your data. Patients can download everything we hold immediately via Settings → Export Data, and can view their own records-access log in the same place.
  • Correct anything inaccurate. Most of your profile is directly editable in Settings; ask us for the rest.
  • Erasure of your data. The next section sets out exactly what that does.
  • Portability — the Settings export is machine-readable JSON.
  • Restrict or object to processing, and to withdraw consent as described above.
  • Not be subject to a decision based solely on automated processing. Our zone engine flags risk and alerts your physician; it does not diagnose you, prescribe for you, or refuse you care. A clinician reviews and decides.
  • Complain to the NDPC. You can raise a complaint with the Nigeria Data Protection Commission directly, and you do not have to come to us first.

We answer requests within 30 days. We will not charge you, and you do not have to justify the request.

9. Erasure — what actually happens

Ask us to erase your data and our operations team runs a built-in erasure procedure. Concretely:

  • Deleted outright: your symptom logs, peak-flow readings, questionnaire responses, action plans, zone history, action logs, alerts, consultation notes, appointments, prescriptions and their line items, cart, orders and their line items, and your consent log.
  • Scrubbed to a blank tombstone: your health profile — date of birth, gender, phone, address, emergency contact, blood type, allergies, personal best, assigned physician — is emptied, and the row is kept only so that the remaining links do not dangle.
  • Anonymised and locked: your login record. Your name, email, phone, photo, and password are removed, the email is replaced with a non-routable address that cannot receive mail, and the account is deactivated so it can no longer be used to sign in.
  • Retained but de-linked: the records-access audit entries. The events stay — they are how we can show that access to your chart was proper — but they are detached from you and the description is replaced with a note that the record was erased under the NDPA right to erasure.
  • The erasure itself is logged, including who ran it and when, because the NDPA requires us to be accountable for it.

This is irreversible. Where a specific clinical or financial record must be retained by law, we will tell you which one and why rather than quietly keeping it.

10. How we protect it

The full technical detail — which fields are encrypted at rest, how access control and audit logging work, and what we deliberately do not claim — is in the Health Data Protection Notice. In summary: traffic is encrypted with TLS, the most sensitive free-text clinical fields are encrypted at rest, access is restricted by role and to your own rows, record access is audited, passwords are hashed, repeated failed sign-ins lock the account temporarily, and two-factor authentication is mandatory for physician and administrator accounts (and available to patients).

11. If there is a breach

If personal data we hold is breached, we will notify the NDPC within 72 hours of becoming aware of it, as the NDPA requires. Where the breach is likely to result in a high risk to you, we will tell you directly and without undue delay, and explain what happened, what data was involved, what we have done, and what you should do.

12. Children

Asthma is common in children, but AirSpire accounts are for adults. If the patient is under 18, the account must be held and operated by a parent or legal guardian, who provides consent on the child’s behalf. Tell us if a child has registered without that consent and we will erase the account.

13. Changes to this policy

Each version of this policy carries a version label and effective date. When we change it materially, we publish the new version and ask you to review and accept it the next time you open the portal, and your acceptance is recorded against that version.

14. Contact us

For any data-protection question, or to exercise any right above — access, correction, erasure, portability, restriction, objection, or a complaint — contact our data protection contact at [email protected]. Tell us what you want and which account it concerns; we do not need a form or a reason.

You can also complain to the Nigeria Data Protection Commission (NDPC), the supervisory authority for the NDPA, at any time.