Impilo

Health Operating System

Privacy Policy

Impilo Privacy Policy

Effective Date: 11 April 2026Last Updated: 11 April 2026

Entity: Impilo Technologies Private Limited (“Impilo,” “we,” “us,” or “our”)

1. Introduction

Impilo is a digital health platform designed to support health service delivery, health system operations, coordinated care, communication, and related digital services.

This Privacy Policy explains how Impilo handles personal data and other information in connection with the Impilo platform, websites, mobile applications, portals, interfaces, support services, and related products and services (collectively, the “Platform”).

Impilo is committed to privacy by design, confidentiality, data minimisation, appropriate transparency, and respect for applicable data protection, health information, data residency, and data sovereignty requirements.

By accessing or using the Platform, you acknowledge that you have read this Privacy Policy.

2. Privacy Summary

Impilo Technologies Private Limited is committed to protecting personal data and respecting applicable privacy, data residency, sovereignty, and health information governance requirements. Depending on the deployment and the features used, Impilo may process account information, contact details, device and technical data, usage information, location data where enabled, communications, and certain health or service-related information.

Impilo is designed to apply privacy-by-design principles, including the separation of personally identifiable information from health or clinical information, controlled access, audit capability, and minimum-necessary access safeguards. Impilo does not sell personal data or health-related data.

Where health or clinical information is stored, managed, or retained, this is ordinarily done by authorized healthcare providers, healthcare organizations, or other legally mandated entities for lawful purposes such as care delivery, continuity of care, quality assurance, health administration, legal compliance, and public health. Those providers and organizations remain independently responsible for their own compliance with applicable privacy, health information, and public health laws in relation to the data they control or process.

Impilo may use and disclose information for purposes including account administration, authentication, service delivery, care coordination, platform operations, security, fraud prevention, support, legal compliance, quality improvement, and other lawful and legitimate purposes described in this Privacy Policy. Information may be shared with authorized providers, institutions, service providers acting on Impilo’s behalf, regulators or public authorities where required by law, and other parties where lawfully authorized or instructed.

Users may have rights, subject to applicable law, to access personal data, request correction, request deletion of certain data, object to or restrict certain processing, withdraw consent where consent is the legal basis, and lodge complaints with a competent authority. Requests relating to privacy, data protection, or account deletion may be directed to support@impilo.io or through www.impilo.io.

Account Deletion Summary: Users may request and initiate account deletion directly within Impilo vNext, through other available account settings, through www.impilo.io, or by emailing support@impilo.io. Some information may be retained where required by law or for lawful purposes such as security, audit, fraud prevention, public health, continuity of care, and recordkeeping obligations.

3. Scope

This Privacy Policy applies to personal data and other information processed through the Platform in connection with individual users, including patients, clients, caregivers, and members of the public; healthcare professionals and other authorized users; healthcare providers, healthcare organizations, employers, payers, and institutional users; and visitors to our websites, portals, and support channels.

This Privacy Policy does not replace any provider-specific, employer-specific, insurer-specific, or institution-specific privacy notices that may also apply to a particular implementation of Impilo.

4. Roles and Responsibilities

Depending on the deployment model, Impilo may act as a platform provider, technology provider, processor, service provider, or similar role, while a healthcare provider, healthcare organization, employer, payer, public authority, or other institution may act as the controller, custodian, or legally responsible entity for certain personal data.

Where a provider or organization determines the purposes and means of processing personal data, health information, or related records, that provider or organization remains independently responsible for its own legal compliance, notices, permissions, retention obligations, and governance decisions.

Impilo provides privacy-supporting technical architecture and controls, but does not assume responsibility for the independent acts, omissions, decisions, policies, disclosures, or unlawful processing of third-party providers, institutions, or users beyond Impilo’s own role and legal obligations.

5. Information We May Collect

Depending on the services used and the deployment context, Impilo may process the following categories of information.

5.1 Account and Identity Information

This may include name, username, password credentials, phone number, email address, organization name, role, staff identifier, and account preferences.

5.2 Contact and Support Information

This may include information you provide in support requests, feedback, complaints, contact forms, emails, or customer-service interactions.

5.3 Device and Technical Information

This may include IP address, device type, device identifiers, operating system, browser type, app version, crash logs, diagnostics, and technical usage data.

5.4 Usage Information

This may include how you use the Platform, viewed pages or features, session data, clicks, interactions, dates and times of access, and related activity logs.

5.5 Location Information

Where enabled and legally appropriate, the Platform may process approximate or precise location information for functionality, safety, routing, service optimization, or other lawful operational purposes.

5.6 Communications and User-Submitted Content

This may include content you choose to submit, upload, send, or store through the Platform, including forms, messages, attachments, images, and other materials.

5.7 Health and Service-Related Information

Depending on the deployment, authorized provider users or connected systems may process health, service, clinical, operational, or wellness-related information through the Platform.

Impilo is architected so that personally identifiable information and health or clinical information are separated and not unnecessarily stored together in directly identifiable form. Impilo does not operate as a general-purpose central repository of directly identifiable health records unless a specific lawful deployment, implementation, or approved operating arrangement requires otherwise.

5.8 Cookies and Similar Technologies

Where applicable, we may use cookies, tokens, local storage, or similar technologies for authentication, security, analytics, session management, and performance.

6. How We Collect Information

We may collect information directly from you, from your device or browser, from healthcare providers, employers, institutions, or organizations that authorize your use of the Platform, from integrated systems, applications, or trusted partners, from app permissions you grant, and automatically through your use of the Platform.

7. How We Use Information

We may use information for purposes including:

  • Creating and administering accounts
  • Authenticating users and maintaining secure access
  • Providing the Platform and its features
  • Enabling care delivery, care coordination, referrals, communication, scheduling, support, and related services
  • Facilitating continuity of care and health system functions where applicable
  • Operating, maintaining, troubleshooting, and improving the Platform
  • Securing systems, detecting misuse, preventing fraud, protecting users
  • Responding to support requests, communicating with users
  • Complying with law, regulation, professional obligations, public health requirements, or lawful requests
  • Enforcing our Terms of Use and protecting our rights
  • Conducting analytics, service monitoring, and quality improvement

8. Legal Bases for Processing

Where applicable under law, we may process personal data on one or more of the following grounds:

  • Your consent
  • Performance of a contract
  • Compliance with legal obligations
  • Protection of vital interests
  • Performance of tasks carried out in the public interest
  • Provision and administration of health or care services where permitted by law
  • Legitimate interests, where those interests are not overridden by your rights and interests

Where consent is required, we will seek it in an appropriate manner. Where consent is not the controlling legal basis, processing may still occur where permitted or required for care delivery, legal compliance, patient safety, security, fraud prevention, or public health.

9. Data Residency, Sovereignty, and Privacy by Design

Impilo is designed to respect applicable data residency, data sovereignty, privacy, and health information governance requirements in the jurisdictions where it is used.

Impilo applies privacy-by-design principles, including separation of personally identifiable information from health or clinical information, role-based and purpose-based controls where applicable, minimum-necessary access, audit capability, and other safeguards intended to reduce the risk of unnecessary identification or unauthorized linkage.

Where health or clinical data is stored, managed, or retained, this is ordinarily done by authorized healthcare providers, healthcare organizations, or other legally mandated entities for lawful purposes such as care delivery, continuity of care, quality assurance, health administration, legal compliance, and public health.

10. Sharing and Disclosure

We may share information only where lawful and appropriate, including with:

  • Healthcare providers, healthcare organizations, and authorized institutional users
  • Service providers, hosting providers, infrastructure providers, support providers, and security providers acting on our behalf
  • Analytics or technical partners where permitted and appropriately governed
  • Regulators, courts, law-enforcement agencies, or public authorities where required by law
  • Successor entities in connection with a merger, acquisition, restructuring, or transfer of assets
  • Other parties where you or the responsible institution has authorized or instructed us to do so

We do not sell personal data or health-related data.

11. Provider Responsibility

Each provider, organization, payer, employer, or institution using Impilo remains independently responsible for its own compliance with applicable privacy, health information, professional, confidentiality, retention, and public health laws in relation to the data it collects, accesses, uses, discloses, stores, retains, or otherwise processes through its own operations.

Impilo is not responsible for the independent acts, omissions, decisions, configurations, policies, disclosures, instructions, misuse, or unlawful processing of third-party providers or organizations beyond Impilo’s own role and legal obligations.

12. Data Retention

We retain personal data and related records only for as long as necessary for the lawful purposes for which they are processed, including:

  • Providing services
  • Maintaining continuity of care where applicable
  • Complying with legal, regulatory, audit, and recordkeeping obligations
  • Resolving disputes
  • Preventing fraud and misuse
  • Maintaining security
  • Supporting legitimate operational and public health functions

Retention periods may vary depending on the type of data, the deployment context, and applicable law.

13. Account Deletion

Users may request and initiate deletion of their Impilo account directly within Impilo vNext, through any other available in-app account settings, through the deletion request mechanism made available on www.impilo.io, or by contacting support@impilo.io.

Upon receipt and verification of a valid deletion request, Impilo Technologies Private Limited will take reasonable steps to delete or de-identify personal data associated with the account that it controls, within a reasonable period and subject to applicable law, regulatory obligations, technical constraints, and legitimate operational requirements.

Deletion of an account does not necessarily result in the immediate deletion of all related information. Certain data may be retained where necessary or permitted for lawful reasons, including security, fraud prevention, dispute resolution, audit requirements, compliance with legal or regulatory obligations, enforcement of contractual rights, public health obligations, continuity-of-care requirements, or recordkeeping obligations imposed on authorized healthcare providers, healthcare organizations, employers, payers, or other institutions using the Platform.

Where health, clinical, or service records are held by authorized providers, healthcare organizations, or other legally responsible entities, those records may continue to be retained and governed by those entities in accordance with their own legal, clinical, professional, and public health obligations. In such cases, Impilo Technologies Private Limited is not responsible for deleting records that are not under its direct control.

Where immediate deletion is not technically possible, relevant data may first be restricted from active use and thereafter securely deleted, anonymized, or de-identified in accordance with applicable retention schedules, system constraints, and backup-cycle requirements.

Users who are unable to access the in-app deletion function in Impilo vNext or other available account settings may submit an account deletion request through www.impilo.io or by emailing support@impilo.io. Impilo Technologies Private Limited may request reasonable information necessary to verify identity and prevent unauthorized deletion requests.

14. Security

We use reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, authentication, encryption in transit and at rest where appropriate, audit logging, secure hosting, segmentation, and incident response procedures.

No method of transmission or storage is completely secure, and we do not guarantee absolute security.

15. International Transfers

Where information is transferred across borders, we will take steps appropriate to the applicable legal and regulatory framework, which may include contractual safeguards, access controls, jurisdiction-specific hosting choices, and other appropriate measures.

16. Your Rights

Subject to applicable law, you may have rights to:

  • Access personal data
  • Request correction of inaccurate data
  • Request deletion of certain data
  • Restrict or object to certain processing
  • Withdraw consent where consent applies
  • Receive information about processing
  • Request portability where applicable
  • Lodge a complaint with a regulator or supervisory authority

These rights may be limited where data must be retained or processed for care delivery, legal obligations, patient safety, security, public interest, or public health purposes.

17. Children and Age-Appropriate Use

Where the Platform is intended for or used by minors, additional safeguards may apply. Where required by law, consent or authorization from a parent, guardian, institution, or other lawful authority may be required.

We do not knowingly permit unlawful collection or misuse of children’s data.

18. Third-Party Services

The Platform may link to or integrate with third-party systems, applications, devices, or services. We are not responsible for the privacy practices of third parties except to the extent required by law or contract in relation to our own role.

19. Changes to This Policy

We may update this Privacy Policy from time to time. Where required, we will provide notice through the Platform, by email, by publication on our website, or by other appropriate means.

20. Contact Us

For privacy questions, requests, complaints, or account deletion requests, contact:

Impilo Technologies Private Limited
Suite 45, 18th Floor, Kaguvi Building
Cnr Central Avenue and 4th Street
Harare, Zimbabwe

Email: support@impilo.io
Phone: +263 242 798537-70 / +263 4 290 1210
Website: www.impilo.io
Emergency Help