Legal
Privacy Policy
Effective date: 1 July 2026
1. Data we collect
When you use the Veriadd API we process the following data: **Identity fields** (BVN, NIN, phone number) — transmitted to our identity provider to fulfil your request, then hashed with SHA-256 before storage. Raw values are never persisted. **Postcode and address fragments** — stored alongside the verification decision for audit purposes. **API request metadata** — endpoint, timestamp, HTTP status, billed amount, confidence score, and reasons. This constitutes the audit trail. **Console account data** — organisation name, email address and API key (stored as a one-way hash, never in plain text).
2. How we use your data
We use collected data to: deliver the verification service; maintain the wallet and billing ledger; generate the auditable decision record required by CBN KYC guidelines; detect and prevent abuse of the API.
3. Data retention
Verification audit records are retained per our retention schedule to meet audit and legal obligations. Console account data is retained until you request deletion. Contact us for the current retention periods.
4. Third-party processors
We share minimal data with: **NIPOST** (postcode registry lookups — no identity data transmitted); **Dojah** (BVN/NIN/phone lookups — transmitted over TLS solely to fulfil your verification request, never persisted by us); **Paystack** (wallet top-ups — email and amount only).
5. Your rights (NDPR)
Under the Nigeria Data Protection Regulation you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure subject to legal retention obligations; lodge a complaint with NITDA.
6. Security
Traffic is encrypted in transit (TLS). Secrets live in environment configuration, never in code. Production data access follows least-privilege practices.
7. Contact
Privacy enquiries: privacy@veriadd.tech. Data Protection Officer: dpo@veriadd.tech.