1. Introduction
This Privacy Policy explains how RALPHONES PHARMACEUTICAL COMPANY LIMITED collects, uses, stores and protects your personal data when you visit www.ralphonespharma.com, purchase our health supplements, or otherwise interact with us online or offline.
We are committed to protecting your privacy in line with the Nigeria Data Protection Regulation 2019 (NDPR), the Nigeria Data Protection Act 2023 (NDPA), Section 37 of the Constitution of the Federal Republic of Nigeria 1999 (as amended), and other applicable data protection laws in Nigeria.
By using our website or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
2. Who We Are (Data Controller)
For the purpose of Nigerian data protection laws, RALPHONES PHARMACEUTICAL COMPANY LIMITED, a company registered in Nigeria with RC No. RC 1226648 and registered address at 1 Ralphones Lane, Off Ikorodu road, Erunkan, Lagos, Nigeria is the Data Controller of your personal data.
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details in Section 17.
3. Scope of this Policy
This Privacy Policy applies to:
- Visitors to www.ralphonespharma.com;
- Customers who purchase our health supplements, create an account, or communicate with us;
- Persons who subscribe to our newsletters, promotions or other marketing communications.
It does not apply to third-party websites or services that may be linked from our site (see Section 16).
4. The Personal Data We Collect
We may collect and process the following categories of personal data:
4.1 Information You Provide Directly
When you use our website or interact with us, you may provide:
Identity and Contact Details – name, title, date of birth (if needed), phone number, email address, delivery address, billing address.
Account Details – username, password, security questions/answers.
Order & Transaction Details – items ordered, order history, payment reference (we usually receive limited payment information from our payment providers, not your full card details).
Health-Related Information (Optional & Minimal) – information you voluntarily provide about your health or wellness goals (e.g. “I am pregnant”, “I have hypertension”, allergies, dietary restrictions) to help us recommend or avoid certain supplements. We avoid collecting detailed medical records unless strictly necessary and with your explicit consent.
Customer Support Information – records of your communications with us, including email, chat, telephone, or social media messages.
4.2 Information Collected Automatically
When you visit our website, we may automatically collect:
Technical Data – IP address, browser type, device type, operating system, time zone, and approximate location (city-level).
Usage Data – pages visited, products viewed, time and date of visits, clickstream data, and other usage statistics.
Cookie Data – information from cookies and similar technologies (see Section 7).
4.3 Information from Third Parties
We may receive personal data about you from:
Payment service providers (e.g. card processors, payment gateways) – to confirm payments and prevent fraud.
Logistics and delivery partners – to ensure successful delivery of your orders.
Marketing or advertising partners – where permitted by law and applicable privacy terms.
5. Legal Basis for Processing Your Personal Data
Under the NDPR and NDPA, we must have a lawful basis to process your personal data. Depending on our relationship with you and the specific purpose, we may rely on:
1. Contract – to take steps at your request before entering into a contract or to perform our contract with you (e.g. processing your order, delivering products, managing your account).
2. Consent – where you have clearly agreed to the processing (e.g. email marketing, certain cookies, or optional health-related information you choose to provide). You may withdraw consent at any time (see Section 13).
3. Legal Obligation – to comply with obligations under tax, accounting, consumer protection, or regulatory laws.
4. Legitimate Interests – to operate and improve our business, prevent fraud, secure our systems, and understand how our website is used, provided such interests are not overridden by your rights and freedoms.
5. Vital Interests – in rare cases where processing is necessary to protect your life or physical safety or that of another person.
6. How We Use Your Personal Data (Purposes)
We may use your personal data for the following purposes:
- To Provide Our Products and Services
- Process and fulfil your orders;
- Deliver health supplements to your chosen address;
- Manage payments, refunds, and replacements;
- Create and manage your online account.
2. Customer Support
- Respond to your enquiries, complaints, and requests;
- Provide product information and guidance (without replacing professional medical advice).
3. Health-Related Preferences (Optional)
Use limited health or wellness information that you voluntarily provide to help recommend suitable supplements or avoid products that may not be appropriate for you. We treat this information with enhanced confidentiality and only use it for this purpose and related customer support.
4. Marketing and Communications
Send you newsletters, offers, promotions, and product updates if you have opted in or where permitted by law;
Personalise marketing content based on your previous purchases and preferences, where allowed.
5. Website Operation, Analytics and Improvement
- Monitor and analyse website usage and performance;
- Improve our products, services, content and user experience;
- Conduct surveys and obtain feedback.
6. Security and Fraud Prevention
- Protect our website, systems, and users from fraud, abuse, and security risks;
- Detect and prevent suspicious or illegal activities.
7. Legal and Regulatory Compliance
- Keep records required by law;
- * Cooperate with law enforcement, regulators, and courts when required by applicable laws.
7. Cookies and Similar Technologies
- Our website uses cookies and similar technologies to:
- Enable core site functions (e.g. shopping cart, secure login);
- Remember your preferences and settings.
- Analyse website traffic and performance;
- Support marketing and advertising, where applicable.
You can manage or disable cookies through your browser settings. However, if you block certain cookies, some features of the website may not function properly.
Where required by law, we will obtain your consent before using non-essential cookies (e.g. analytics or advertising cookies).
8. Marketing Communications
We may send you marketing communications (such as newsletters, promotions, or information about new products):
When you opt in on our website or during checkout, or
Where we are otherwise permitted by law to do so.
You can opt out at any time by clicking the “unsubscribe” link in our emails.
Opting out of marketing will not affect transactional or service messages (e.g. order confirmations, shipping updates).
9. Sharing Your Personal Data
We do not sell your personal data. We may share your personal data with:
1. Service Providers and Business Partners
- Payment processors;
- Delivery and logistics companies;
- IT, hosting, and cloud service providers;
- Customer support and communication tools;
- Marketing and analytics providers.
These third parties are required to use your personal data only in accordance with our instructions and applicable data protection laws.
2. Professional Advisers
Lawyers, auditors, accountants, and consultants, where necessary for legitimate business purposes and subject to confidentiality obligations.
3. Regulators and Law Enforcement
Where required by law, regulation, court order, or government directive.
4. Business Transfers
In connection with a merger, acquisition, sale of assets, or restructuring, your personal data may be transferred to a new owner, subject to continued protection under applicable laws.
10. International Transfers of Personal Data
We are based in Nigeria, but some of our service providers or partners may be located outside Nigeria. Where this involves the transfer of your personal data to another country, we will ensure that such transfers comply with the NDPA/NDPR, including by using appropriate safeguards such as contractual clauses or ensuring that the recipient is subject to adequate data protection obligations.
11. Data Retention – How Long We Keep Your Data
We will keep your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, including:
- For as long as you maintain an account with us
- For the period needed to complete your transactions and provide support;
- For as long as required by tax, accounting, regulatory, or legal obligations;
- For a limited period to resolve disputes or enforce our agreements.
Where there is no specific legal requirement, we will generally delete or anonymise personal data within a reasonable period after it is no longer needed, in accordance with the storage limitation principles under NDPA/NDPR and relevant guidance from the Nigeria Data Protection Commission.
12. How We Protect Your Personal Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, alteration, or disclosure. These may include:
- Secure servers, firewalls and encryption where appropriate;
- Access controls and role-based access to personal data;
- Staff training on data protection and confidentiality;
- Policies and procedures for handling data incidents.
While we strive to protect your personal data, no system can be completely secure, and we cannot guarantee absolute security.
13. Your Rights as a Data Subject
Under the NDPR and NDPA, you have certain rights in relation to your personal data, which may include:
1. Right to Information and Transparency
To be informed about how we collect, use and share your personal data (as set out in this Policy).
2. Right of Access
To request confirmation that we process your personal data and to obtain a copy of the personal data we hold about you.
3. Right to Rectification
To request correction of inaccurate or incomplete personal data.
4. Right to Erasure (“Right to be Forgotten”)
To request deletion of your personal data in certain circumstances (e.g. where it is no longer needed, where you withdraw consent and there is no other legal basis for processing, or where processing is unlawful).
5. Right to Restrict Processing
To request that we limit the processing of your personal data in certain circumstances.
6. Right to Object
To object to processing based on our legitimate interests, especially for direct marketing purposes.
7. Right to Data Portability
To receive certain personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible and applicable.
8. Right to Withdraw Consent
Where we rely on your consent (for example, for marketing or certain health-related information), you can withdraw that consent at any time. This will not affect the lawfulness of processing prior to withdrawal.
9. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or any other competent authority.
To exercise any of these rights, please contact us using the details in Section 17. We may need to verify your identity before responding to your request.
14. Children’s Privacy
We do not knowingly collect personal data from children without verifiable parental consent.
If you are under 18, please do not use our website or provide any personal data without your parent/guardian’s supervision and consent.
If we become aware that we have collected personal data from a child without appropriate consent, we will take reasonable steps to delete such data.
15. Third-Party Websites and Services
Our website may contain links to third-party websites, plug-ins, or services (for example, payment gateways or social media platforms). We are not responsible for the privacy practices, content or security of those third parties.
We encourage you to read the privacy policies of any third-party site or service you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes, we will:
- Update the “last updated” date below; and
- Where appropriate, notify you by email, website notice, or other reasonable means.
Last updated: 22nd November 2025
