Data Processing Agreement

Last updated: June 2026

Purpose of this agreement

This Data Processing Agreement ("DPA") governs the processing of personal data by mlooop on behalf of hospitals and healthcare facilities ("Data Controllers") that use the mlooop platform.

This DPA is intended to satisfy the requirements of the Nigeria Data Protection Regulation (NDPR) and any other applicable data protection legislation governing the parties.

1. Roles and responsibilities

The hospital is the Data Controller: it determines the purposes and means of processing patient and staff personal data.

mlooop is the Data Processor: it processes personal data only on the documented instructions of the hospital, and for no other purpose.

2. What data we process

On behalf of hospitals, mlooop may process: patient demographic data (name, date of birth, contact details); clinical records (diagnoses, prescriptions, lab results, notes); billing and insurance information; and staff records necessary for access management.

The categories of data subjects include patients, next of kin, and hospital staff.

3. Purpose limitation

mlooop processes personal data only to provide the services described in your subscription agreement. We do not use your data for analytics, advertising, model training, or any purpose beyond operating the platform on your behalf.

4. Security measures

mlooop implements appropriate technical and organisational measures to protect personal data, including: AES-256 encryption at rest; TLS 1.3 encryption in transit; role-based access controls; immutable audit logs; and regular security assessments.

A full description of our security practices is available at mlooop.com/security.

5. Sub-processors

mlooop may engage sub-processors (e.g. cloud infrastructure providers) to assist in delivering the service. All sub-processors are bound by data protection obligations no less stringent than those in this DPA.

We will notify you of any material changes to our sub-processor arrangements with at least 14 days notice.

6. Data subject rights

As the Data Controller, your hospital is responsible for handling data subject requests (e.g. access, rectification, erasure). mlooop will assist you in fulfilling these obligations by providing tools to locate, correct, or delete specific records within the platform.

7. Data breach notification

In the event of a personal data breach affecting your data, mlooop will notify you without undue delay and no later than 72 hours after becoming aware of the breach. Notification will include the nature of the breach, the categories of data affected, and the measures taken or proposed.

8. Data transfers

mlooop does not transfer your data outside your designated data residency region without your prior written consent. Where transfers are necessary, appropriate safeguards will be in place.

9. Termination and deletion

Upon termination of your subscription, mlooop will retain your data for 30 days to allow for export. Following that period, all data will be permanently deleted from our systems and backups within 90 days.

Contact

To request a signed DPA or for data-related enquiries, contact dev@mlooop.com .