Privacy Policy

Your privacy is our priority. Learn how we collect, use, and protect your health information.

Last Updated: December 3, 2025

Important Notice

This Privacy Policy describes how Red Ribbon Health collects, uses, maintains, and discloses information collected from users. By using our platform, you consent to the data practices described in this policy. We are committed to HIPAA compliance and protecting your sensitive health information with the highest standards of security and confidentiality.

Information We Collect

Personal Information

We collect information you provide directly, including name, email address, date of birth, and contact details when you create an account.

Health Information

With your explicit consent, we collect health-related data including symptoms, medications, appointments, lab results, nutrition, exercise, mood, and stress levels. This information is stored securely and used solely to provide you with personalized health tracking services.

Usage Data

We automatically collect information about how you interact with our platform, including access times, pages viewed, IP address, browser type, and device information.

Cookies and Tracking

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or sell your data to advertisers.

How We Use Your Information

Service Delivery

We use your information to provide, maintain, and improve our health tracking services, including generating insights and recommendations based on your health data.

Communication

We may send you service-related notifications, appointment reminders, and important updates about our platform. You can opt out of non-essential communications at any time.

Research and Analytics

We may use aggregated, de-identified data for research purposes to improve healthcare outcomes. Individual health information is never shared without your explicit consent.

Legal Compliance

We may use or disclose your information when required by law, to protect our rights, or to prevent fraud and ensure platform security.

Data Security

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your health information is protected with enterprise-grade security measures.

Access Controls

We implement strict access controls and authentication mechanisms. Only authorized personnel with a legitimate need can access protected health information.

Regular Audits

Our systems undergo regular security audits and penetration testing to identify and address potential vulnerabilities.

Secure Infrastructure

We host our services on secure, HIPAA-compliant cloud infrastructure with redundant backups and disaster recovery procedures.

Your Rights and Choices

Access and Portability

You have the right to access, download, and export your personal and health information at any time through your account settings.

Correction and Updates

You can update or correct your information directly through the platform. Contact us if you need assistance with data corrections.

Deletion

You have the right to request deletion of your account and all associated data. We will process deletion requests within 30 days, except where retention is required by law.

Consent Withdrawal

You can withdraw your consent for data processing at any time. This may limit your ability to use certain platform features.

Data Portability

You have the right to receive your data in a structured, commonly used, and machine-readable format for transfer to another service.

Information Sharing

Healthcare Providers

With your explicit consent, we may share your health information with healthcare providers you designate for continuity of care.

Service Providers

We may share information with trusted service providers who assist in platform operations, subject to strict confidentiality agreements and HIPAA compliance.

Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change and your rights regarding your data.

Legal Requirements

We may disclose information when required by law, court order, or government request, or when necessary to protect rights, property, or safety.

No Selling of Data

We never sell, rent, or trade your personal or health information to third parties for marketing purposes.

Data Retention

Active Accounts

We retain your information for as long as your account is active and as necessary to provide services.

Closed Accounts

After account closure, we retain certain information for up to 7 years as required by healthcare regulations and legal obligations.

Anonymized Data

We may retain de-identified, aggregated data indefinitely for research and service improvement purposes.

Legal Holds

We may retain data longer when required by legal proceedings, investigations, or regulatory requirements.

Contact Us About Privacy

If you have questions about this Privacy Policy or how we handle your information, please contact our Privacy Officer:

Email

redribbon@doctor4africa.com

We may update this Privacy Policy periodically. We will notify you of significant changes via email or platform notification.