Legal

Privacy Policy

Effective date: 1 July 2026

1. Data we collect

When you use the Veriadd API we process the following data: **Identity fields** (BVN, NIN, phone number) — transmitted to our identity provider to fulfil your request, then hashed with SHA-256 before storage. Raw values are never persisted. **Postcode and address fragments** — stored alongside the verification decision for audit purposes. **API request metadata** — endpoint, timestamp, HTTP status, billed amount, confidence score, and reasons. This constitutes the audit trail. **Console account data** — organisation name, email address and API key (stored as a one-way hash, never in plain text).

2. How we use your data

We use collected data to: deliver the verification service; maintain the wallet and billing ledger; generate the auditable decision record required by CBN KYC guidelines; detect and prevent abuse of the API.

3. Data retention

Verification audit records are retained per our retention schedule to meet audit and legal obligations. Console account data is retained until you request deletion. Contact us for the current retention periods.

4. Third-party processors

We share minimal data with: **NIPOST** (postcode registry lookups — no identity data transmitted); **Dojah** (BVN/NIN/phone lookups — transmitted over TLS solely to fulfil your verification request, never persisted by us); **Paystack** (wallet top-ups — email and amount only).

5. Your rights (NDPR)

Under the Nigeria Data Protection Regulation you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure subject to legal retention obligations; lodge a complaint with NITDA.

6. Security

Traffic is encrypted in transit (TLS). Secrets live in environment configuration, never in code. Production data access follows least-privilege practices.

7. Contact

Privacy enquiries: privacy@veriadd.tech. Data Protection Officer: dpo@veriadd.tech.