Privacy Policy
Last updated June 2026
This policy explains what information Klinova Health collects, why we collect it, and how we protect it. We aim to be straightforward, no legal walls of text, no surprises.
Who we are
Klinova Health operates the Klinova telemedicine platform at klinova.co and the Klinova mobile application on iOS and Android. We are based in Lomé, Togo.
Questions about this policy? Reach us at contact@klinova.co.
Information we collect
We only collect what we actually need to provide care.
Account details: your name, email address, phone number, and account role (patient, doctor, or clinic).
Health information from your consultations: symptoms, urgency level, and any notes you add voluntarily.
Location at the district or region level, used to suggest nearby clinics or emergency services.
Basic usage data: pages visited, features used, and language preference.
How we use your information
To connect you with doctors and deliver telemedicine consultations.
To route you to nearby clinics or emergency services when urgency requires it.
To generate anonymized, aggregate health statistics for public health authorities. No individual data is ever shared in these reports.
To keep your account running and communicate with you about it.
Data sharing
We do not sell your personal data. Full stop. The only situations where we share information are:
With the doctor you book a consultation with, so they can provide care.
With government health authorities, shared only as anonymized aggregate statistics — never as individual records.
Data retention
We keep your account data for as long as your account is active. You can request full deletion at any time by emailing contact@klinova.co. Anonymized, aggregate health data may be retained for public health research, but it cannot be traced back to you.
Your rights
You have the right to access, correct, or delete your personal data at any time. To exercise any of these rights, contact us at contact@klinova.co and we will respond within 30 days.
Compliance
Klinova is built to meet the most rigorous standards in health data protection across every country we operate in.
EU Regulation 2016/679 — governs how we collect, process, and store personal data for users in the EU and globally.
45 CFR Parts 160 and 164 — governs the handling and safeguarding of protected health information.
We adhere to the health data protection regulations of Togo, Ghana, Benin, and Côte d'Ivoire as applicable to services in each country.
All health records are end-to-end encrypted. You own your data. We act as a data processor, meaning we handle your information solely to deliver care. We are never a data broker.
Security
We operate under a zero-trust security model: no user, system, or service is trusted by default, regardless of where the request originates. In practice, this means:
All connections use HTTPS/TLS. Your data is encrypted in transit, always.
Every database table enforces row-level security. You can only ever access your own records.
API credentials and service keys are managed server-side only and are never exposed to the browser.
Patient data is pseudonymized at the point of collection.
We review access permissions continuously and apply least-privilege principles to every internal role.
Children
Klinova is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us with their information, contact us and we will delete it promptly.
Changes to this policy
We may update this policy as the platform evolves. For significant changes, we will notify you by email or through an in-app notice before the change takes effect.
Klinova Health
Lomé, Togo
