Office of the Chief Legal Officer
legal@posi.health
Platform Legal Terms
Privacy Policy
Version 1.0. Effective 11 August 2026. Olamiposi, Inc., a Delaware corporation doing business as POSI.
1. Introduction
Olamiposi, Inc. ("we", "us", or "our") operates a Platform that facilitates healthcare service coordination and payment processing between Funders, Patients, and Providers. This Privacy Policy explains how we collect, use, and protect Personal Data in connection with our Platform.
If you do not agree to this Privacy Policy, you may not use our Platform.
Definitions
- "Funder" means any individual or entity that funds, pays for, or otherwise covers the cost of healthcare services provided to a Patient through the POSI Platform.
- "Health Information" means information relating to a Patient's medical condition, diagnosis, treatment, procedures, treatment history, medical reports, treatment estimates, and other health information reasonably necessary for the Services.
- "Patient" means the individual receiving healthcare services.
- "Personal Data" means any information relating to an identified or identifiable individual, including information that can be used, directly or indirectly, to identify an individual, such as a name, identification information, contact details, financial information, health or medical information, or other information associated with that individual.
- "Platform" means the POSI website, application, software, systems, and related digital services operated or made available by Olamiposi, Inc. for the coordination of healthcare services, funding, payment facilitation, communication, and related services.
- "Provider" means the licensed healthcare professional or institution delivering the services.
2. Information We Collect
We may collect the following types of information:
From Funders
- Name, email, and contact details
- Payment and transaction information
- Identification information
From Patients
- Name, contact details
- Identification information
- Health Information relating to the treatment being funded
From Providers
- Business and licensing information
- Contact details
- Banking and payment details
Evidence of care
Because payment is released only after care has been evidenced, the Platform collects and stores documents and images submitted as proof that treatment took place. Depending on the episode, these may include photographs taken at the point of care, itemised clinical invoices and receipts, signed clinical summaries, discharge documentation, prescription and laboratory slips, appointment confirmations, and written attestations from the Provider and the Patient.
These documents are more detailed than general contact information and may reveal a Patient's diagnosis, treatment, and medical history. Patients should understand what they are submitting before they submit it.
3. How We Use Information
We use Personal Data to facilitate healthcare service coordination between Patients and Providers; process and manage payments through third-party providers; conduct compliance checks (including fraud prevention, AML/KYC, and sanctions screening); manage disputes, chargebacks, and payment verification; comply with legal and regulatory obligations; and operate and improve the Platform.
4. Legal Bases for Processing
We process Personal Data only where we have a lawful basis to do so under applicable data protection laws. Depending on the circumstances, our legal bases may include:
- Consent, including where required for the processing of health or other sensitive Personal Data;
- Performance of a contract, including providing services requested through the Platform;
- Compliance with legal and regulatory obligations, including applicable healthcare, financial, fraud prevention, and compliance requirements;
- Protection of vital interests, where permitted by applicable law, including circumstances involving urgent or emergency healthcare situations; and
- Legitimate interests, where permitted by applicable law and where such interests are not overridden by the rights and interests of the individual.
Where we rely on consent, individuals may withdraw consent at any time, subject to any legal or contractual limitations and the need to retain information where required by law or necessary for the establishment, exercise, or defence of legal claims.
5. Sharing of Information
We only share Personal Data where necessary, and never sell it.
| Recipient | Why information may be shared |
|---|---|
| Healthcare Providers | To coordinate and provide requested treatment |
| Funders | To evaluate and fund approved treatment, and to review the evidence of care against which payment is released |
| Payment providers | To process and settle authorised payments |
| Compliance providers | Identity verification, fraud prevention and sanctions screening |
| Banks and financial institutions | Payment settlement and verification |
| Regulators and authorities | Where legally required |
| Technology and cloud providers | Hosting, security and operation of the Platform |
What the Funder can see
A Funder who is funding a Patient's care can view the evidence of care submitted for that episode. This includes the documents and images described in Section 2, which may reveal the Patient's diagnosis, the treatment received, and other Health Information. We state this plainly because it is the disclosure Patients are least likely to expect: the person paying for treatment can see the clinical evidence that the treatment took place.
Access is limited to the specific care episode being funded. A Funder cannot see evidence relating to care they are not funding, and no other Platform user can see it at all.
Service providers we use
We share Personal Data with the following categories of provider, including: payment processors (Stripe, Inc. and Wise Payments Limited); banking partners, including settlement account providers (JPMorgan Chase Bank, N.A.); cloud infrastructure and database providers who host the Platform and store Platform records (Supabase, Inc. and Vercel, Inc.); compliance, verification, and fraud prevention service providers; Providers, for treatment coordination; and regulators or authorities where required by law.
6. Cross-Border Data Transfers
Due to the nature of our Platform, Personal Data may be transferred between jurisdictions, including the United States and Nigeria. Where Personal Data is transferred across borders, we will implement appropriate safeguards and comply with applicable requirements governing international transfers of Personal Data.
7. Data Security
We implement reasonable technical and organisational safeguards to protect Personal Data against unauthorised access, loss, misuse, or disclosure. Users are responsible for ensuring that any information they provide is accurate and that they have the right to share such information.
7.1 Data Processors and Service Providers
We may engage third-party service providers to process Personal Data on our behalf, including cloud hosting, authentication, payment processing, identity verification, fraud prevention, analytics, communications, and other technology services. We require such providers to implement appropriate safeguards and to process Personal Data only for authorised purposes.
7.2 Security Incidents
If we become aware of a security incident involving Personal Data, we will take reasonable steps to investigate, contain, mitigate, and remediate the incident and will provide notifications to affected individuals, Providers, Funders, regulators, or other parties where required by applicable law.
8. Fraud Prevention and Platform Integrity
We may process Personal Data to verify the identity and authority of users, authenticate accounts, verify healthcare providers and funders, detect and prevent fraud, financial crime, misuse, impersonation, and other unlawful activity, conduct compliance and sanctions screening, protect the security and integrity of the Platform, and investigate suspected violations of our Terms or applicable law.
9. Data Retention
We retain Personal Data only as long as necessary to provide services; comply with legal and regulatory obligations; resolve disputes; and prevent fraud. Retention periods may vary depending on the nature of the information, the purpose for which it was collected, applicable legal and regulatory requirements, contractual obligations, dispute resolution needs, fraud prevention requirements, and legitimate business needs.
10. Your Rights
Depending on applicable law, individuals may have rights to access or correct their Personal Data; request deletion of data (subject to legal obligations); and object to or restrict certain processing.
Requests can be made by contacting us at legal@posi.health.
11. Cookies
We may use cookies, session technologies, logs, and similar technologies to maintain security, authenticate users, remember preferences, understand Platform usage, and improve our Services. Where required by law, we will obtain appropriate consent before using non-essential cookies or similar technologies.
12. Role of POSI
POSI is not a healthcare provider and does not determine or control clinical treatment. Providers remain responsible for clinical care and for maintaining official medical records in accordance with applicable law and professional obligations.
Depending on the specific processing activity and relationship between the parties, POSI and a Provider may act as independent data controllers or in another legally applicable capacity. The parties may enter into a separate Data Processing and Data Sharing Agreement where required.
13. Updates to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on the Platform with a revised effective date. Where a change materially affects how we handle Personal Data, we will ask you to review and accept the updated policy.
14. Contact
For questions regarding this Privacy Policy, please contact legal@posi.health. Olamiposi, Inc., a Delaware corporation doing business as POSI.