SabiCare365 Limited
Data Processing Agreement for Care Coordination
Governing the processing of personal and health-adjacent data in the delivery of SabiCare365's cross-border care coordination services. It should be read together with the Privacy Policy and Terms of Service.
| Effective Date | 1 May 2026 |
| Version | Version 1.1 |
| Issued By | SabiCare365 Limited |
| Governing Law | Laws of the Federal Republic of Nigeria |
| Data Protection Framework | Nigeria Data Protection Act 2023 (NDPA) |
| Contact | legal@sabicare365.com |
family.sabicare365.com
Introduction
SabiCare365 Limited ("SabiCare365") is committed to protecting the privacy and personal information of its users (data subjects). SabiCare365 adheres to strict controls to ensure that the personal data of data subjects is obtained and used in line with the company's privacy principles.
SabiCare365 collects, processes, and stores users' personal data in compliance with the Nigeria Data Protection Act 2023 (NDPA), the regulations and guidelines of the Nigeria Data Protection Commission (NDPC), and other applicable Nigerian laws on data protection. Where relevant, SabiCare365 also has regard to the principles of the General Data Protection Regulation (GDPR).
By providing the data subject's personal information, or the personal information of a Care Recipient or beneficiary connected to the data subject, the data subject acknowledges that SabiCare365 may only use that information in the manner specified in this Agreement and the Privacy Policy.
Recitals
This Data Processing Agreement for Care Coordination ("DPA" or "Agreement") is entered into between SabiCare365 Limited ("Controller" or "SabiCare365") and the Caregiver or Family Subscriber who has accepted the Terms of Service ("Data Subject" or "Participating Party").
WHEREAS:
- SabiCare365 operates a cross-border digital platform that facilitates the coordination of professional in-home care services between Nigerian diaspora Family Subscribers residing abroad and professional caregivers domiciled in Nigeria;
- The delivery of these services necessitates the collection, processing, storage, and cross-border transfer of personal data — including health-adjacent data relating to Care Recipients, financial data relating to Family Subscribers and Caregivers, and operational data relating to care service delivery;
- Both parties have obligations under the Nigeria Data Protection Act 2023 (NDPA), the applicable regulations of the Nigeria Data Protection Commission (NDPC), and, where relevant, the principles of the GDPR;
- This Agreement is entered into to establish clear obligations, rights, and responsibilities with respect to all personal and care-related data processed in connection with the Platform.
General Principles
SabiCare365 respects the privacy rights of its users, business partners, and other individuals whose personal data are in its custody. It is guided by the following principles:
- Respect for Privacy: SabiCare365 upholds the privacy rights of data subjects, ensuring that processing complies with the principles of lawfulness, fairness, and transparency.
- Data Security: SabiCare365 safeguards personal data by implementing appropriate technical and organisational measures to ensure confidentiality and integrity during processing.
- Fair and Legitimate Data Use: SabiCare365 collects personal data lawfully and fairly, processing it strictly for specified, explicit, and legitimate purposes aligned with care coordination and the requirements of the NDPA.
- Accountability and Compliance: SabiCare365 takes full accountability for demonstrating compliance with the NDPA and other applicable frameworks, and ensures its team understand their responsibilities in protecting personal data.
- Data Minimisation: Only data that is adequate, relevant, and limited to what is necessary for the stated purposes is collected and processed.
- Accuracy: Personal data is kept accurate and up to date. Users are empowered to correct inaccurate data through their account settings.
- Storage Limitation: Data is retained only for as long as necessary, as specified in the retention schedule in this DPA and the Privacy Policy.
- Integrity and Confidentiality: Data is processed with appropriate security measures against unauthorised access, loss, or destruction.
Part I — Scope, Definitions, and Principles
1. Scope of This Agreement
This DPA applies to all personal data and care-related data processed by SabiCare365 in connection with:
- The registration and management of Family Subscriber accounts, Caregiver accounts, and Care Recipient profiles;
- The scheduling, delivery, and documentation of Shifts and care services;
- The collection, storage, and display of Care Logs, medication records, vitals data, and incident reports;
- The processing of GPS location data for shift verification purposes;
- Financial transactions, including subscription billing, wallet management, and caregiver payouts;
- The transmission of care-related notifications, alerts, and escalation communications;
- The retention of audit, compliance, and historical care records.
2. Definitions
- "Care Data"
- all data relating directly to the provision of care to a Care Recipient, including Care Logs, vitals measurements, medication administration records, incident reports, and care photographs.
- "Controller"
- the natural or legal person that determines the purposes and means of processing personal data. SabiCare365 is the Controller of platform user data.
- "Cross-Border Transfer"
- any transfer of personal data from Nigeria to a recipient, system, or storage location in another country — including transfers between Family Subscribers residing abroad and Caregivers or Care Recipients in Nigeria, and transfers to sub-processors or infrastructure hosted outside Nigeria.
- "Data Breach"
- a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- "Data Subject"
- the identified or identifiable natural person to whom personal data relates — in this context: Family Subscribers, Family Members, Caregivers, and Care Recipients.
- "Health-Adjacent Data"
- data that relates to the physical or mental condition of a Care Recipient — including vitals readings, medication records, mobility observations, dietary intake, sleep patterns, and mood assessments — processed for the purpose of care coordination.
- "Processing"
- any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, and deletion.
- "Sub-Processor"
- a third-party service provider engaged by SabiCare365 to process personal data on SabiCare365's behalf.
Part II — Categories of Data and Processing Activities
2. Lawful Basis of Processing Personal Data
SabiCare365 shall process personal data of its data subjects only when one or more of the following legal bases apply:
- The data subject has provided consent for the processing of their personal data, and such consent has not been withdrawn. To withdraw consent, an email should be sent to legal@sabicare365.com;
- The processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract;
- The processing is required to comply with a legal obligation to which SabiCare365 is subject;
- The processing is necessary to protect the vital interests of the data subject or a third party;
- The processing is necessary for the purposes of legitimate interests pursued by SabiCare365 or its sub-processors, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
3. Data Categories Processed
| Data Category | Data Subjects | Processing Purpose | Legal Basis |
|---|
| Identity & Contact Data | Family Subscribers, Caregivers | Account management, authentication, communications | Contract; Consent |
| Care Recipient Profile Data | Care Recipients (via Family Subscribers) | Matching caregivers to appropriate care needs | Contract; Legitimate interests |
| Health-Adjacent Care Data | Care Recipients | Documenting care delivery; family oversight; escalation | Contract; Legitimate interests |
| GPS Location Data | Caregivers (active Shifts only) | Verifying caregiver attendance at care site | Contract; Legitimate interests |
| Financial & Payment Data | Family Subscribers | Subscription billing; wallet management | Contract |
| Caregiver Earnings & Banking Data | Caregivers | Weekly payout processing | Contract |
| Verification Documents | Caregivers | Compliance; safeguarding Care Recipients | Legal obligation; Legitimate interests |
| Operational & Audit Data | All users | Security; compliance; dispute resolution | Legal obligation; Legitimate interests |
| Consent Records | All users | Demonstrating lawful basis for processing | Legal obligation |
| Analytics Data (anonymised) | All users | Platform improvement | Legitimate interests |
4. Processing of Health-Adjacent Care Data
SabiCare365 processes health-adjacent data relating to Care Recipients in the form of Care Logs submitted by Caregivers. This data includes vitals (blood pressure, pulse, temperature, blood sugar), general mood, mobility, meals, medications administered, sleep quality, and observations by the Caregiver.
SabiCare365 does not use this data to make medical diagnoses, prescribe treatments, adjust clinical medication regimens, or provide any service that constitutes the practice of medicine or nursing.
Access to Care Data is strictly controlled at the database layer through Row-Level Security policies. Care Data is never used for advertising, sold to any third party, or processed for any purpose other than care coordination and platform operations.
Part III — Cross-Border Data Transfer
5. Cross-Border Transfers
The nature of SabiCare365's services requires the routine transfer of personal data across borders — in particular between Family Subscribers residing abroad and Caregivers and Care Recipients in Nigeria, and between Nigeria and sub-processors or cloud infrastructure that may be located outside Nigeria. These transfers are inherent to the service and are conducted with the following safeguards:
- Regulatory basis: cross-border transfers are conducted in accordance with the NDPA and applicable NDPC guidelines on the transfer of personal data outside Nigeria, relying on adequacy, the data subject's consent, or the necessity of the transfer for performance of the contract, as applicable;
- Transfer necessity: data is transferred only to the extent necessary to deliver the agreed service;
- Infrastructure security: all data in transit and at rest is encrypted;
- Contractual safeguards: SabiCare365 maintains appropriate data processing agreements with all sub-processors involved in cross-border data handling;
- Access minimisation: Caregivers access only the data minimally necessary for their assigned care duties.
Part IV — Sub-Processors
6. Approved Sub-Processors
SabiCare365 engages sub-processors to provide infrastructure, payment, communication, and analytics services. SabiCare365 maintains a current list of sub-processors, which can be made available to data subjects upon request to legal@sabicare365.com. SabiCare365 remains responsible for the acts and omissions of its sub-processors in respect of the personal data they process on its behalf.
Part V — Security, Breach Response, and Audit
7. Technical and Organisational Security Measures
- Transport encryption: all data in transit between users and the Platform is encrypted;
- Data-at-rest encryption: all data stored in the database is encrypted at rest;
- Application-layer encryption: Caregiver bank account numbers are encrypted with a key stored separately from the data;
- Access control: database Row-Level Security (RLS) policies enforce data isolation at the database engine level;
- Authentication: multi-factor authentication via OTP for high-privilege actions;
- Audit log: an immutable, append-only audit log captures all data access and modification events. No user, including administrators, can delete audit log entries.
8. Data Breach Notification
In the event of a confirmed Data Breach, SabiCare365 will:
- Contain the breach and secure affected systems as rapidly as practicable;
- Notify affected data subjects as soon as technically feasible;
- File a breach notification with the Nigeria Data Protection Commission (NDPC) within such time as required by applicable law.
Users who suspect a Data Breach should contact SabiCare365 immediately at legal@sabicare365.com.
Part VI — Data Subject Rights and Consent
9. Consent Framework
SabiCare365 captures explicit, informed, and freely given consent from all users at the point of registration. Consent is recorded with: the date and time of consent; the version of the Privacy Policy and Terms of Service accepted; the user's IP address; and the user agent (browser/device).
GPS location data is collected from Caregivers only during active Shifts and only for the purpose of verifying attendance at the Care Recipient's home.
Users may withdraw consent at any time by contacting legal@sabicare365.com. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
9.1 Consent for Care Recipients and Persons Lacking Capacity
Where a Family Subscriber provides personal or health-adjacent data about a Care Recipient, the Family Subscriber confirms that they are authorised to do so on the Care Recipient's behalf. For Care Recipients who lack the capacity to consent, SabiCare365 relies on the authority of the Family Subscriber acting as their representative and, where applicable, on the necessity of processing to protect the vital interests of the Care Recipient.
10. Data Subject Rights
In accordance with the NDPA, data subjects have the following rights in respect of SabiCare365's use of their personal data:
- Right to access: to obtain a copy of their personal information as maintained by SabiCare365.
- Right to rectification: to request correction of inaccurate or incomplete personal information.
- Right to erasure: to request deletion of their personal information in certain circumstances, subject to SabiCare365's legal and regulatory retention obligations.
- Right to restriction of processing: to request that SabiCare365 restrict processing where accuracy is contested, processing is unlawful, the data is needed for legal claims, or an objection is pending verification.
- Right to data portability: to request that personal information they provided be transferred to another party, after which that party is responsible for safeguarding it.
- Right to object to marketing: to object to the processing of their personal data for marketing purposes.
- Right to lodge a complaint: to complain about how their personal information is used, using the contact details in this DPA, and to lodge a complaint with the NDPC.
Data subjects may exercise their rights by submitting a written request to legal@sabicare365.com. SabiCare365 will acknowledge receipt and respond within the timeframe required by applicable law. Where compliance is not feasible due to legal or regulatory obligations, an explanation will be provided.
Part VII — Special Provisions for the Nigerian Context
11. Nigeria Data Protection Act 2023 Compliance
SabiCare365 will comply with the Nigeria Data Protection Act 2023 to the extent required by the NDPA. In addition to the rights described above, Nigerian data subjects have the right to: be informed, in a language they understand, of how their data is being processed; object to automated decision-making (including GPS check-in determinations) and have their case reviewed by a human SabiCare365 Operations officer; and lodge a complaint directly with the Nigeria Data Protection Commission at www.ndpc.gov.ng.
11.1 Caregiver Data Rights
- Financial data (bank account details) is encrypted and processed only for the purpose of compensation — it is not shared with any party other than the financial institution responsible for payout processing;
- Verification documents are retained only for the period required by law and are not shared with Family Subscribers or any external party;
- Caregiver GPS data is collected only during active Shifts and is not used for any purpose beyond shift verification and dispute resolution.
Part VIII — Review, Audit, and Remedies for Violation
12. Review of the Policy
The Company's Data Protection Officer (DPO) is responsible for ensuring this policy is reviewed and updated at least once every three (3) years, or sooner where required by changes to the Nigeria Data Protection Act 2023 and its Regulations.
13. Audit and Enforcement
The Company shall periodically audit its privacy and data protection practices in accordance with the extant data protection framework, and the Data Protection Officer shall be responsible for monitoring compliance.
14. Remedies for Violation
In the event of a violation of this policy, the Controller shall redress the violation within fifteen (15) days. Where the violation pertains to the disclosure of a data subject's information without consent, such information shall be retracted immediately, and confirmation of the retraction shall be sent to the data subject. Where the violation is caused by any representative of the Controller, such representative shall be subject to appropriate sanction.
Part IX — Termination and Survival
This DPA is effective from the Effective Date and remains in force for the duration of the user's engagement with the SabiCare365 Platform.
Upon termination, SabiCare365 will retain data for the periods specified in the retention schedule in accordance with its legal obligations. Family Subscribers may request a complete data export within ninety (90) days of termination. Data subject to a deletion request will be anonymised within thirty (30) days, subject to legal retention obligations.
Obligations of confidentiality with respect to Care Recipient data survive termination of this DPA and the user's engagement with the Platform.
Contact and Escalation
- Data Protection Officer: legal@sabicare365.com
- Privacy Enquiries: legal@sabicare365.com
- Legal Notices: legal@sabicare365.com
- Regulator (Nigeria): Nigeria Data Protection Commission — www.ndpc.gov.ng
This Data Processing Agreement for Care Coordination was last reviewed and approved on 1 May 2026. It forms part of SabiCare365's suite of legal documents alongside the Terms of Service and Privacy Policy, and is binding on all registered users of the SabiCare365 platform.