Find out what information the platform handles, why it is needed, who may receive it and how to ask about your rights.
1. Who this policy covers
This policy describes personal information handled through UniqueEye Connect by Unique Optical Services, Ghana. It covers visitors, patients, family representatives, customers and staff. Health information and information about children require particular care.
This notice should be read with any information given when you book care, submit a form or use a specific service. The organisation responsible for your care may also provide information about its clinical recordkeeping.
2. Information the platform handles
- Account and identity information: names, email addresses, phone numbers, profile details, sign-in and verification records, and staff role assignments.
- Care information: patient and family profiles, symptoms and intake answers, appointment details, consultation notes, prescriptions, attachments and clinical documents.
- Shopping information: cart and order details, chosen frames and lenses, prescription information supplied for an order, delivery addresses, purchase history and digital-book access records.
- Payment information: transaction references, amounts, payment status, provider responses and refund records. Payment credentials entered in the provider’s checkout are handled by that provider; do not send card details or mobile-money PINs in Messages.
- Communications: messages, attachments, support requests, notification records and optional communication preferences.
- Technical and security information: IP addresses, browser or device details, session activity, access logs, security events and audit records. Browser storage may also remember a preference such as data-saver mode.
3. Where information comes from
Information comes from you, an authorised person acting for you, staff involved in your care or support, and the records generated when you use the service. Payment providers return transaction results. Technical information is generated by requests to the platform and its service providers.
Some fields are required to identify the correct patient, arrange care, secure an account, take payment or deliver an order. Without them, the relevant service may not be available. Optional fields and preferences can be left unset where the interface allows.
4. Why information is used
Information is used to operate accounts, authenticate users, manage family access, schedule and provide care, maintain clinical records, fulfil orders, provide downloads, reconcile payments, issue refunds and respond to questions.
It is also used to send service updates, prevent fraud or misuse, investigate errors, maintain audit trails and understand service activity. Optional outreach is managed separately from essential booking, payment and security communications.
The appropriate justification depends on the activity: delivering a requested service, meeting a legal or professional obligation, protecting a person, a legitimate operational purpose where permitted, or consent where required. Health information is handled subject to the additional rules that apply to it. Acceptance of general terms is not a blanket consent to every use of health data.
5. Access and service providers
Platform access is controlled by account type, staff roles and permissions. Authorised care staff, support staff, finance staff and administrators have different responsibilities. Family access depends on the authorised relationship and applicable account controls.
Providers may receive information needed to perform their part of the service: Paystack for payments; Daily for video consultations; hosting and file-storage providers, including Amazon S3 where configured; email and SMS delivery providers; and delivery partners for fulfilment. The exact services involved depend on the feature you use and the live deployment.
Relevant information may also be disclosed where required by law, to address a valid legal request, or to protect rights and safety where legally permitted. A third-party website or payment service may publish its own privacy notice; review it when leaving this platform.
6. Video consultations and device access
A video appointment uses a video-service provider to connect participants and process the audio, video and connection information needed for the call. Your browser asks for camera and microphone permissions. You can manage these permissions in your browser, although denying them may prevent a video consultation.
The current integration disables its recording interface and automatic cloud recording. This is separate from the clinical notes a clinician creates during care. Any future recording feature would require clear information and any necessary consent before use. Choose a private location and avoid sharing room or appointment-access links.
8. Messages and your choices
Service messages can include verification codes, security alerts, booking updates, receipts and care-related communications. Optional outreach preferences, where available, let you choose communication categories and withdraw your permission for future optional messages.
Review the communication preferences in your account’s Messages area or contact the team. Changing an outreach preference does not erase clinical or transaction records and does not necessarily stop essential service notices.
9. Retention and account closure
Different records serve different purposes. Clinical information, payments, orders, security logs and support conversations may need to be retained for different periods to provide care, meet legal or professional obligations, resolve disputes and protect the service.
An account-closure or deletion request does not automatically require all records to be erased. Ask the team which records can be removed, corrected or restricted and which must be retained. Backup copies may remain until their normal replacement cycle; they are not a substitute for an active account.
Contact us for the retention period applicable to a particular record and the reason it is kept. The appropriate period depends on the record category and the obligations that apply to it.
10. Security and international processing
The platform includes account authentication, role-based access controls, audit records and protected access to private files. Use a strong password, enable two-factor authentication where available and keep recovery codes private. No online service can guarantee that every security incident will be prevented.
Cloud, payment, video and communications providers may process information outside Ghana. The countries and safeguards depend on the provider and the live service configuration. Contact the team for information about the providers handling your data and the arrangements relevant to your service.
11. Your privacy rights and requests
Ghana’s Data Protection Act, 2012 (Act 843) provides rights concerning personal data. Depending on the circumstances, you can request access, correction and the deletion or blocking of information that should not be retained, object to certain processing, and stop processing for direct marketing. Where processing depends on consent, you can ask to withdraw it for the future.
Contact Unique Optical Services with a clear description of your request and enough information to identify the relevant account or record. The team may need to verify your identity and your authority to act for someone else. Do not send unnecessary identity documents or sensitive details before being told what is needed.
Requests are subject to applicable legal conditions, including obligations to retain some records and protect another person’s information. If a request cannot be fulfilled in full, ask for the reason. You may also raise a concern with Ghana’s Data Protection Commission.
12. Children and family profiles
A parent, guardian or other authorised representative may provide information for a dependent through family-profile workflows. Only provide information you are authorised to share, and keep each person’s care information in the correct profile.
Tell the team if a relationship, guardianship or account-access arrangement changes. A request involving a child’s information may require additional verification and consideration of the child’s interests and applicable law.
13. Contact and policy updates
For a privacy question or rights request, contact Unique Optical Services. Patients can start through Messages in their account and ask for the person responsible for data protection. If you cannot sign in, use the clinic contact details supplied with your booking, receipt or clinic correspondence.
This policy will be updated when relevant practices change. The revision date identifies the version you are reading. Material changes should be explained through an appropriate notice, with further consent obtained where required.