Privacy

Privacy Policy

Last updated:

This policy explains what personal data Vetra collects about you, how we use it, who we share it with, and the rights you have. It applies to everyone who uses vetrainsure.com and our mobile apps.

We've written this to comply with the Nigeria Data Protection Act (NDPA) 2023 and to be clear enough to actually read. If anything here is unclear, email privacy@vetrainsure.com.

1. Who we are

Vetra Insure Limited (“Vetra”, “we”, “our”) is a Nigerian company registered in Nigeria. We operate a health-insurance marketplace and administration platform that connects individuals and organisations with licensed Nigerian Health Maintenance Organisations (HMOs) and healthcare providers.

When you use vetrainsure.com, our mobile applications, or any related service (together, the “Services”), Vetra acts as the Data Controller for personal data you provide to us directly. HMOs and providers you engage through Vetra are separately-controlled organisations and act as independent controllers of the data you share with them.

2. Data we collect

We collect only the data we need to run the Services. That falls into four buckets:

  • Account data — name, email, password hash, and (for Google sign-in) a Google profile identifier. Optional: phone, state, city, date of birth, gender.
  • Marketplace activity — HMOs you save, compare or request quotes from; family members you add; preferences (state, cover type, monthly budget); and health-cover details once an HMO enrols you (member ID, plan name, expiry date).
  • Communications — messages you send us (support tickets, emails), and the replies you send to HMOs through our platform.
  • Technical data — IP address, browser type, device identifiers, pages visited, timing, and error logs. Collected via cookies and standard server logs to keep the Services secure and to fix bugs.

We do not collect clinical records, prescription data, or diagnosis codes. That data lives with your HMO and providers, not with Vetra.

3. How we use your data

We use personal data for the following purposes and no others:

  • To provide, secure and improve the Services.
  • To route quote requests to the HMO you selected — including sharing the fields you filled in on the quote form.
  • To send transactional messages you asked for (quote-request receipts, quote replies, digital card issuance, expiry reminders, security notices).
  • To send product updates and marketing emails, only where you have opted in. You can opt out at any time using the unsubscribe link in any marketing email.
  • To meet legal and regulatory obligations, including responses to lawful requests from regulators or law enforcement.
  • To detect, prevent and investigate fraud, abuse, and violations of these Services.

5. Who we share your data with

We share personal data only in the following circumstances:

  • HMOs you engage — when you submit a quote request, the request payload (name, contact, cover type, budget, state, message) is forwarded to that HMO. From that point, the HMO controls that data. If the HMO you selected has not yet claimed its Vetra profile, we hold the request as a “pending lead” and forward it when the HMO joins Vetra.
  • Service providers — reputable third parties we use to run infrastructure (cloud hosting, email delivery, error tracking, analytics). They act on our instructions and are contractually bound to protect the data. Current key providers include Render, Vercel, Cloudflare, and Postmark.
  • Legal recipients — where compelled by a Nigerian court order or applicable regulator (e.g. NDPC).
  • Business transfers — in the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquirer subject to this policy.

We do not sell personal data to third parties for advertising or any other purpose.

6. International data transfers

Vetra is a Nigerian company and stores data primarily on infrastructure located in Nigeria and the European Union. Where a service provider processes data outside Nigeria, we require them to meet standards equivalent to the NDPA (e.g. GDPR-adequate jurisdictions), use standard contractual clauses, and encrypt data in transit and at rest.

7. How long we keep it

Retention periods depend on the data type:

  • Account data — for as long as your account is active, plus 90 days after deletion (to allow account recovery and to satisfy audit obligations).
  • Quote requests — 24 months, so you can revisit your history, or until you delete your account.
  • Financial records (invoices, receipts, tax records) — 7 years, as required by Nigerian tax law.
  • Server logs — 90 days, then discarded.
  • Marketing preferences — retained until you opt out.

8. Your rights

Under the NDPA you have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and associated data (the mobile app and web /app both expose a self-serve delete option; it cascades to every table that references your account).
  • Withdraw consent for any processing based on consent.
  • Object to processing based on legitimate interest, including direct marketing.
  • Portability — receive a copy of your data in a structured, machine-readable format.
  • Complain to the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

To exercise any of these rights, email privacy@vetrainsure.com. We respond within 30 days.

9. Cookies

We use a small number of cookies and similar technologies:

  • Essential — session cookies for authentication, CSRF tokens, and cookie preferences. These cannot be turned off; the Services do not work without them.
  • Analytics — first-party or privacy-preserving analytics to understand which pages are used. Set only after you consent.
  • Marketing — third-party pixels for measuring the effect of ads. Set only after you consent.

You can withdraw cookie consent at any time from the cookie banner or your browser settings.

10. Children

The Services are not directed at anyone under 18. We do not knowingly collect data from anyone under 18. If you believe we hold data about a minor, contact us and we will delete it. Family members added to a plan (including under-18 dependants) are added by the account holder, who is responsible for that consent.

11. Security

We use encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, least-privilege service accounts, and continuous monitoring. No system is perfectly secure — if you believe your account has been compromised, contact security@vetrainsure.com immediately.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email and via a banner on the site at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the current version.

Contact our Data Protection team

Email: privacy@vetrainsure.com
Post: Vetra Insure Limited, Lagos, Nigeria

See also our Terms of Service and Security page.