Privacy Policy

Last updated: 30 July 2026

This notice explains how Yummooh Life handles personal data, including health data, on our website and our iOS and Android apps. It is maintained by Yummooh Life and describes our own practices; it is not an independent certification or audit.

1. Who we are

Yummooh Life ("Yummooh", "we", "us") operates a prepaid health wallet, Digital Health ID and care marketplace connecting members with clinics, doctors, pharmacies, laboratories and delivery partners across Africa.

For members, sponsors and visitors, Yummooh Life is the data controller of account, wallet, device and platform-usage data. For clinical records that a healthcare provider creates about you during care, that provider is the controller of the clinical content and Yummooh Life acts as a processor hosting it on their behalf.

Privacy contact: support@yummooh.com.

2. Scope

This policy applies to yummooh.life, www.yummooh.life, the Yummooh Life mobile apps, the practitioner Health ID scan portal, and our provider, employer, sponsor and admin portals. Links to third-party sites are governed by their own policies.

3. Data we collect

  • Account data: name, email, phone number, password credentials, country, state, city or town, preferred language, and role (member, provider, sponsor, staff).
  • Identity and verification data: Digital Health ID number, date of birth, photo, and documents you or a provider upload for verification.
  • Health data (special category): health questionnaire answers and risk profile, uploaded past medical records, vitals, diagnoses, prescriptions and repeats, lab results, referrals, chronic care plans, appointments, visits and consultation notes.
  • Financial data: wallet balance and currency, top-ups, transfers, subscriptions, activation fees, provider settlements, commissions and payout requests. Card details are handled by our payment processor and are never stored by Yummooh.
  • Dependents and sponsorship data: details of dependents you add, and the link between a diaspora sponsor and a sponsored member.
  • Device and technical data: push notification token, app version, platform, IP address, approximate location derived from your registered country/city for search ranking, and crash and error diagnostics.
  • Support and communications: support tickets and messages you send us.
  • Audit data: logs of who accessed a health record, when, and under which consent or one-time access code.
  • Camera: used only to scan a Health ID QR code. Images are processed on device and are not uploaded or stored.

4. Why we use it and our legal bases

PurposeData usedLegal basis (GDPR-aligned)
Create and secure your accountAccount, identity, devicePerformance of a contract; legitimate interests (security)
Provide care bookings, telehealth and prescriptionsAccount, health, dependentsContract; explicit consent for health data; Art. 9(2)(h) provision of health care
Wallet payments, plans and provider settlementsFinancial, accountContract; legal obligation (accounting, anti-fraud)
Verify identity at the point of careHealth ID, photo, nameExplicit consent (one-time access code); Art. 9(2)(h)
Notifications (appointments, prescriptions, wallet)Account, device tokenContract; consent for marketing messages
Fraud prevention and platform integrityFinancial, device, auditLegitimate interests; legal obligation
Improve reliability and search rankingTechnical, country/cityLegitimate interests
Legal, regulatory and tax complianceFinancial, accountLegal obligation

We do not sell personal data, and we never use health data for advertising or profiling for marketing purposes.

5. Who can see your health records

Your health record is private by default. It becomes visible to a clinician only when one of the following happens:

  • you share your Digital Health ID and approve a one-time access code;
  • you book an appointment or telehealth consultation with that provider;
  • you consent to a sponsor viewing your records and that sponsor holds an active records-access subscription.

Access is time-limited, scoped to the care episode, and written to an audit log you can review in the app. You can withdraw consent at any time; withdrawal stops future access but does not undo lawful past access.

6. Sharing and processors

We share personal data only with:

  • healthcare providers you choose or attend;
  • our payment processor (Stripe) and mobile money partners, to take payments and pay out providers;
  • our cloud hosting, database and file storage provider;
  • our transactional email and push notification providers;
  • your employer or sponsor, limited to coverage and eligibility status — never clinical detail without your consent;
  • professional advisers, regulators, law enforcement or courts where legally required, and acquirers in a merger or restructuring (with equivalent protection).

Processors act only on our documented instructions under written data-processing terms.

7. International transfers

Yummooh operates across multiple African countries and uses cloud infrastructure that may store or process data outside your country of residence, including in the EU and the United States. Where required, we rely on adequacy decisions, the EU/UK Standard Contractual Clauses, or equivalent safeguards under national law, together with encryption in transit and at rest.

8. Retention

CategoryRetention
Medical and clinical recordsAs long as required by applicable health-records law in the country of care (commonly 5–20 years)
Wallet and financial recordsStatutory accounting and tax periods (commonly 7–10 years)
Account profileFor the life of the account, then deleted or anonymised within 30 days of a valid deletion request
Access and audit logsUp to 24 months, or longer where a legal hold applies
Support messages24 months
Device push tokensUntil you sign out, uninstall, or disable notifications

9. Security

We apply encryption in transit and at rest, row-level access rules so each account can reach only its own data, role-based access control for staff and providers, private storage buckets for health documents, audit logging of record access, session idle timeouts, and optional biometric unlock and two-factor authentication in the app. Staff access is limited to what a role needs, and privileged actions are logged.

No system can be guaranteed perfectly secure. Please protect your password and one-time access codes, and report anything suspicious to support@yummooh.com.

10. Your rights

Subject to local law, you may:

  • access a copy of your personal data;
  • correct inaccurate or incomplete data;
  • delete data where no legal retention duty applies;
  • receive a portable, machine-readable export;
  • restrict or object to certain processing;
  • withdraw consent at any time, without affecting prior lawful processing;
  • opt out of marketing messages;
  • lodge a complaint with your national data protection authority.

Email support@yummooh.com from your registered address, or use Support in the app. We respond within 30 days and will tell you if we need an extension or further identity verification.

11. Account and data deletion

To delete your account and associated personal data, email support@yummooh.com with the subject "Delete my account", or open Support inside the app. We action deletion within 30 days. We must retain medical records and financial transaction records for the statutory periods above; those are locked down and used only for legal compliance, then deleted.

12. Region-specific notices

  • Cameroon: we process personal data consistent with Law No. 2010/012 on cybersecurity and cybercriminality and applicable telecommunications and health confidentiality rules, including medical secrecy obligations owed by providers.
  • Nigeria (NDPA 2023): you may contact our privacy team to exercise data subject rights and may complain to the Nigeria Data Protection Commission.
  • South Africa (POPIA): you may object to processing and complain to the Information Regulator.
  • Kenya (Data Protection Act 2019): you may complain to the Office of the Data Protection Commissioner.
  • Ghana (Act 843), Rwanda (Law No. 058/2021), Ivory Coast (Law No. 2013-450): equivalent access, correction, deletion and complaint rights apply.
  • EU/EEA and UK (GDPR): legal bases are set out in section 4; you have the rights in section 10 and may complain to your supervisory authority.
  • California (CCPA/CPRA): we do not sell or share personal information for cross-context behavioural advertising. You may request to know, delete or correct, and you will not be discriminated against for exercising these rights.

13. Cookies and analytics

We use strictly necessary cookies and local storage to keep you signed in, remember your language, and secure sessions. We do not run third-party advertising or cross-site tracking cookies. Any product analytics we use is limited to aggregated reliability and usage measurement and excludes health record content.

14. Mobile app permissions

PermissionWhyOptional?
CameraScan Health ID QR codes; images are not stored or uploadedYes
NotificationsAppointment, prescription and wallet alertsYes
Biometrics (Face/Touch ID)Local app unlock; biometric data never leaves your deviceYes
Photos / filesUpload past medical records you chooseYes
Network stateOffline-first caching of your Health ID and draftsNo

15. Children and dependents

Accounts are for adults aged 18 and over. Dependents, including children, may be added and managed only by a responsible adult member who confirms they have authority to do so. We do not knowingly collect data directly from children. If you believe a child created an account independently, contact us and we will remove it.

16. Automated decision-making

We use automated rules for fraud screening, wallet affordability checks and provider search ranking. These do not produce legal effects about your health care; a clinician always makes clinical decisions. You can ask us to review any automated outcome that blocks a transaction.

17. Breach notification

If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware where required, and notify affected users without undue delay, describing what happened and what to do next.

18. Changes to this policy

We update this notice as the platform evolves. Material changes are announced in the app or by email before they take effect, and the "last updated" date above always reflects the current version.

19. Contact

Privacy, data protection and security reports: support@yummooh.com
General support: the Support widget inside the app.

Back to Yummooh Life