Last updated: 12 July 2026
This Privacy Policy explains how [Legal Entity Name] ("Veem", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with the Veem identity verification platform and our website (together, the "Service").
We take the protection of personal data seriously — particularly because our Service processes sensitive identity and biometric information. This policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and other applicable laws.
Veem operates identity verification infrastructure used by businesses ("Merchants") to verify their customers and users ("Data Subjects").
This policy applies to personal data we process about (a) representatives and users of Merchant accounts, (b) Data Subjects whose information is submitted for verification, and (c) visitors to our website. Where we act as a processor, the relevant Merchant's own privacy notice governs its collection and use of Data Subject information.
Under the NDPA, we rely on one or more of the following legal bases: performance of a contract; compliance with a legal obligation; your consent (or the consent obtained by the Merchant from the Data Subject); our legitimate interests in operating and securing the Service; and, where applicable, the protection of vital interests or performance of a task in the public interest.
Where processing relies on consent, Merchants are responsible for obtaining valid consent from Data Subjects before submitting their information for verification.
Biometric data (such as facial images used for liveness and face match) and government identifiers are sensitive personal data. We apply heightened protections: they are encrypted, access is strictly limited, and they are used only to perform the verification requested and to secure the Service. We do not sell personal data or use biometric data for advertising.
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, to comply with legal and regulatory obligations (including KYC/AML record-keeping), to resolve disputes, and to enforce our agreements. Retention periods for verification records are set in line with Merchant instructions and applicable law, after which data is deleted or de-identified.
We implement technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, least-privilege and role-based access controls, tenant isolation, logging and monitoring, and audit trails on verifications. No system is completely secure, but we work continuously to protect personal data and to respond promptly to any incident, including notifying affected parties and regulators where required.
Subject to applicable law, Data Subjects have rights over their personal data, including the right to:
Where Veem acts as a processor, we will refer requests to the relevant Merchant (the controller) or assist them in responding. To exercise your rights, contact us or the Merchant that verified you.
We primarily process personal data within Nigeria. Where data is transferred to or accessed from another country (for example, a sub-processor's infrastructure), we ensure an adequate level of protection through appropriate safeguards consistent with the NDPA and NDPR.
The Service is intended for use by businesses and is not directed at children. Where a Merchant's use case involves verifying minors, the Merchant is responsible for obtaining appropriate parental or guardian consent and complying with rules protecting children's data.
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where changes are material, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
For privacy questions or to exercise your rights, contact our Data Protection Officer at privacy@useveem.com or hi@useveem.com. You may also write to us at 1 Odobo Street, Ogba Lagos, Nigeria. You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).