Legal

Privacy Policy

Last updated: 12 July 2026

This policy explains what personal data Veem processes, why, and the rights you have. It reflects our commitment to handling identity and biometric data responsibly and in line with the Nigeria Data Protection Act.

01Introduction

This Privacy Policy explains how [Legal Entity Name] ("Veem", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with the Veem identity verification platform and our website (together, the "Service").

We take the protection of personal data seriously — particularly because our Service processes sensitive identity and biometric information. This policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and other applicable laws.

02Who we are & our role

Veem operates identity verification infrastructure used by businesses ("Merchants") to verify their customers and users ("Data Subjects").

  • As a processor:when a Merchant submits a Data Subject's information for verification, the Merchant is the data controller and Veem processes that data on the Merchant's documented instructions.
  • As a controller: for our own purposes — such as operating and securing the Service, preventing fraud, managing Merchant accounts, and meeting legal obligations — Veem acts as a data controller.

03Scope of this policy

This policy applies to personal data we process about (a) representatives and users of Merchant accounts, (b) Data Subjects whose information is submitted for verification, and (c) visitors to our website. Where we act as a processor, the relevant Merchant's own privacy notice governs its collection and use of Data Subject information.

04Information we collect

Merchant & account information

  • Business details submitted during onboarding (name, registration/RC number, TIN, licences, addresses).
  • Details of authorised signatories and account users (name, job title, work email, phone, and identity details where required).
  • Billing and Wallet transaction information.

Verification data (Data Subjects)

  • Government identifiers submitted for a check, such as NIN and BVN.
  • Identity attributes returned or reconciled during verification (name, date of birth, phone number, address, photo).
  • Biometric data, including facial images and liveness data used for face match and liveness detection.
  • Screening data, such as matches against PEP, sanctions, and adverse-media sources.
  • Business lookup data, such as CAC registration details and directors.

Technical & usage information

  • API request metadata, logs, timestamps, and verification outcomes.
  • Device, browser, and IP information when you use our website or dashboard.
  • Cookies and similar technologies (see the Cookies section).

05How we use information

  • To provide verification results to Merchants and operate the Service.
  • To create and manage Merchant accounts and process Wallet payments.
  • To secure the Service, detect and prevent fraud and abuse, and maintain audit trails.
  • To provide support and communicate with you about the Service.
  • To improve and develop the Service, using aggregated or de-identified data where possible.
  • To comply with legal, regulatory, and contractual obligations.

07Biometric & sensitive data

Biometric data (such as facial images used for liveness and face match) and government identifiers are sensitive personal data. We apply heightened protections: they are encrypted, access is strictly limited, and they are used only to perform the verification requested and to secure the Service. We do not sell personal data or use biometric data for advertising.

08How we share information

We share personal data only as necessary to provide the Service and as described below:

  • With the Merchant who initiated a verification (as their processor).
  • With authoritative and third-party data sources accessed through licensed channels (for example NIMC, NIBSS, CAC, and screening providers) to perform checks.
  • With sub-processors and service providers (such as hosting, communications, and payment providers) under appropriate contractual and confidentiality safeguards.
  • With regulators, law enforcement, or other authorities where required by law or to protect rights, safety, and the integrity of the Service.
  • In connection with a merger, acquisition, or reorganisation, subject to this policy.

09Data retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, to comply with legal and regulatory obligations (including KYC/AML record-keeping), to resolve disputes, and to enforce our agreements. Retention periods for verification records are set in line with Merchant instructions and applicable law, after which data is deleted or de-identified.

10Data security

We implement technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, least-privilege and role-based access controls, tenant isolation, logging and monitoring, and audit trails on verifications. No system is completely secure, but we work continuously to protect personal data and to respond promptly to any incident, including notifying affected parties and regulators where required.

11Your rights

Subject to applicable law, Data Subjects have rights over their personal data, including the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data in certain circumstances;
  • Object to or request restriction of certain processing;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC).

Where Veem acts as a processor, we will refer requests to the relevant Merchant (the controller) or assist them in responding. To exercise your rights, contact us or the Merchant that verified you.

12International transfers

We primarily process personal data within Nigeria. Where data is transferred to or accessed from another country (for example, a sub-processor's infrastructure), we ensure an adequate level of protection through appropriate safeguards consistent with the NDPA and NDPR.

13Cookies & tracking

Our website and dashboard use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.

14Children's data

The Service is intended for use by businesses and is not directed at children. Where a Merchant's use case involves verifying minors, the Merchant is responsible for obtaining appropriate parental or guardian consent and complying with rules protecting children's data.

15Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where changes are material, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16Contact us & Data Protection Officer

For privacy questions or to exercise your rights, contact our Data Protection Officer at privacy@useveem.com or hi@useveem.com. You may also write to us at 1 Odobo Street, Ogba Lagos, Nigeria. You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).