Security Policy
Effective Date: 01-08-2026
Last Updated: 29-06-2026
1. Introduction
Nexa Nurse Limited (“Nexa Nurse”, “we”, “our”, or “us”) is committed to maintaining the confidentiality, integrity, and availability of the information entrusted to us.
This Security Policy outlines the measures we take to protect our website, mobile applications, user accounts, personal information, payment transactions, and technology infrastructure from unauthorized access, misuse, alteration, disclosure, or destruction.
This Policy applies to all users of the Nexa Nurse Platform, including Clients, Registered Nurses, Care Assistants, healthcare institutions, corporate organizations, employees, contractors, and third-party service providers.
2. Our Commitment to Security
We are committed to:
- Protecting personal and medical information.
- Maintaining secure systems and infrastructure.
- Preventing unauthorized access.
- Detecting and responding to security incidents.
- Continuously improving our security controls.
- Complying with applicable data protection and cybersecurity laws.
3. Information We Protect
Our security controls are designed to protect, among other things:
- User account information.
- Identity verification documents.
- Healthcare Professional credentials.
- Personal information.
- Medical-related booking information.
- Payment records.
- Transaction history.
- Communication records.
- System logs.
- Business records.
4. Security Measures
Nexa Nurse implements reasonable administrative, technical, and organizational safeguards, including:
- Secure data transmission using encryption where appropriate.
- Encryption of sensitive information at rest where applicable.
- Secure authentication processes.
- Access controls based on business need.
- Password protection.
- Continuous system monitoring.
- Firewall protection.
- Intrusion detection and prevention mechanisms.
- Secure backups.
- Regular software updates and security patches.
Although we employ industry-recognized security practices, no technology or system can guarantee absolute security.
5. Account Security
Users are responsible for maintaining the security of their accounts.
You must:
- Create a strong password.
- Keep your login credentials confidential.
- Avoid sharing your account with others.
- Log out of shared or public devices after use.
- Notify Nexa Nurse immediately if you suspect unauthorized access to your account.
Users are responsible for all activities conducted through their accounts unless otherwise required by law.
6. Identity Verification
To protect our community, Nexa Nurse may verify the identity of users before granting access to certain services.
Verification may include:
- Government-issued identification.
- Professional licence verification.
- Facial verification.
- Contact verification.
- Bank account verification.
- Other verification measures deemed necessary.
Failure to complete verification may result in restricted access or account suspension.
7. Payment Security
Payments made through the Platform are processed by licensed third-party payment service providers.
Nexa Nurse does not intentionally store complete debit or credit card information on its systems.
All payment-related transactions are subject to the security practices of the applicable payment provider.
8. Data Protection
Personal information is collected, used, stored, and processed in accordance with the Nexa Nurse Privacy Policy and applicable data protection laws.
Access to personal information is restricted to authorized personnel who require it to perform their duties.
9. User Responsibilities
All users share responsibility for maintaining the security of the Platform.
Users must not:
- Share login credentials.
- Attempt unauthorized access.
- Use another person’s account.
- Upload malicious software.
- Circumvent security controls.
- Attempt to exploit system vulnerabilities.
- Interfere with Platform operations.
Users should keep their devices updated with current security software and operating system updates.
10. Prohibited Security Activities
The following activities are strictly prohibited:
- Hacking.
- Reverse engineering.
- Credential theft.
- Password attacks.
- Social engineering.
- Phishing.
- Malware distribution.
- Ransomware attacks.
- Denial-of-service attacks.
- Unauthorized data extraction.
- Network scanning without authorization.
- Security testing without written permission.
Violations may result in immediate account suspension, termination, and referral to law enforcement authorities.
11. Fraud Prevention
Nexa Nurse employs measures to detect and prevent fraudulent activities, including:
- Identity verification.
- Transaction monitoring.
- Login anomaly detection.
- Device recognition.
- Risk-based account reviews.
- Manual investigation where necessary.
Accounts suspected of fraudulent activity may be temporarily restricted while investigations are conducted.
12. Monitoring
To maintain Platform security, Nexa Nurse may monitor:
- Login activity.
- Account access.
- Device information.
- Transaction activity.
- Booking activity.
- Security events.
- System logs.
Monitoring is conducted for legitimate business, operational, and security purposes and in accordance with applicable law.
13. Security Incident Response
If Nexa Nurse becomes aware of a security incident, we may:
- Investigate the incident.
- Isolate affected systems.
- Suspend affected accounts where necessary.
- Notify affected users where required by law.
- Cooperate with regulators and law enforcement authorities.
- Take corrective measures to reduce future risks.
14. Reporting Security Issues
If you discover a suspected security vulnerability, unauthorized access, or other security concern relating to the Platform, you should report it promptly.
Please include:
- A description of the issue.
- The affected page or feature.
- Steps to reproduce the issue (if known).
- Screenshots or supporting evidence where available.
Users must not publicly disclose security vulnerabilities before giving Nexa Nurse a reasonable opportunity to investigate and address them.
15. Third-Party Services
The Platform may rely on third-party providers for services such as:
- Cloud hosting.
- Payment processing.
- Identity verification.
- Analytics.
- Messaging.
- Customer support.
While we select reputable providers, Nexa Nurse is not responsible for security incidents arising solely from systems outside our reasonable control.
16. Data Retention
Information is retained only for as long as necessary to:
- Provide our services.
- Comply with legal obligations.
- Resolve disputes.
- Prevent fraud.
- Enforce our agreements.
When information is no longer required, it will be securely deleted, anonymized, or archived in accordance with applicable laws.
17. Business Continuity
Nexa Nurse maintains procedures intended to support the continuity of essential services in the event of operational disruptions.
These procedures may include:
- Secure data backups.
- Disaster recovery planning.
- System redundancy where appropriate.
- Incident response planning.
Despite these measures, uninterrupted availability of the Platform cannot be guaranteed.
18. Changes to This Policy
Nexa Nurse may update this Security Policy from time to time to reflect changes in technology, security practices, legal requirements, or business operations.
Updated versions will be published on the Platform with a revised “Last Updated” date.
Continued use of the Platform after the effective date of any changes constitutes acceptance of the revised Policy.
19. Governing Law
This Security Policy shall be governed by and interpreted in accordance with the laws of the Federal Republic of Nigeria.
20. Contact Us
For questions regarding this Security Policy or general security matters, please contact:
Legal Department
Email: legal@nexanurse.com
To report security incidents, suspected vulnerabilities, unauthorized access, fraud, or other security concerns:
Security & Violations
Email: violations@nexanurse.com
Nexa Nurse appreciates responsible disclosure of legitimate security concerns and will review all reports in a timely manner.
