Legal

Privacy policy

Last updated: 2026-07-18

1. What we collect

We distinguish carefully between two categories of personal data, because our role differs for each.

Tenant users (the businesses that use KarVerifi): name, work email, hashed password, tenant role, dashboard activity, IP address, browser user-agent, and — if MFA is enrolled — a TOTP seed. We collect this directly from you when you sign up and use the dashboard.

End-users (the persons your workflows verify): identity attributes you submit or that end-users enter into a hosted flow — including full name, date of birth, phone, BVN, NIN, bank account details, business registration details, government-issued ID images, and selfies. For this data, you are the data controller and KarVerifi is your data processor. We process it only to deliver the verification you requested.

Operational data: API request logs, webhook delivery logs, audit trails, and error traces — used for security, debugging, and billing reconciliation.

2. Why we collect it

  • Delivering the verification, workflow, wallet, and hosted UI services you subscribe to.
  • Complying with Nigerian KYC, AML, and NDPR obligations that apply to us and to you.
  • Detecting and preventing fraud, abuse, and misuse of the platform.
  • Producing anonymised aggregate analytics that help us improve the product.
  • Communicating important account, security, and product update notices.

4. Data sharing

We share personal data with a small, deliberate set of sub-processors — each of them under an NDPR-compliant data-processing agreement:

  • Identity registries and KYC providers — including NIBSS (BVN, account enquiry), NIMC (NIN), QoreID, and SmileID — to execute the checks you request.
  • Wallet processor — Karrabo Financial Solutions — for wallet top-ups, disbursement, and reconciliation.
  • Email delivery — Microsoft Office 365 — for account, security, and notification emails.
  • Infrastructure — Nigerian-hosted primary cloud provider and CDN for TLS termination and static asset delivery.

We do not sell personal data. We do not share personal data for advertising or profiling by third parties.

5. Retention

Retention windows are configurable per tenant, subject to legal minimums. Defaults:

  • Tenant user accounts: for the life of the account, plus 90 days after deletion for audit and dispute resolution.
  • End-user verification records: 7 years by default (aligned with CBN record-keeping requirements), configurable per tenant compliance policy.
  • Uploaded ID document images and selfies: purged 90 days after verification, or sooner if you configure automatic redaction. See the Security page for our PII-redaction approach.
  • API request logs: 30 days full detail, then hashed for another 60 days for security analytics.

6. International transfers

Personal data is primarily processed on infrastructure located in Nigeria. Where processing must occur outside Nigeria — for example, certain sub-processor services or backup replicas — we ensure the transfer is supported by NDPR-compliant safeguards, including standard contractual clauses and adequate destination jurisdictions per NITDA guidance.

7. Your rights

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion, subject to legal retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — where processing relies on consent.
  • Complaint — lodge a complaint with the Nigeria Data Protection Commission.

To exercise any of these rights, email dsar@karverifi.com. If you are an end-user whose data was submitted by a tenant, please contact that tenant first — they are the data controller. We will respond to verified requests within 30 days.

8. Cookies

We use a small set of strictly functional cookies. We do not use advertising or cross-site tracking cookies.

  • session — short-lived HTTP-only cookie holding the access token for the current dashboard session.
  • refresh — HTTP-only cookie holding the rotating refresh token, scoped to auth routes.
  • csrf — cookie paired with a header token to defeat cross-site request forgery on state-changing requests.
  • signout-reason — one-shot cookie used to display context on the login page after an auto-signout (e.g. session expired).

9. Security

We encrypt data in transit with TLS 1.2 or better, and at rest with AES-256. Passwords are hashed with bcrypt. Access to production is limited by role and audited. For a full description of our security posture, see the Security page.

10. Children

The Services are not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have collected personal data from a child, contact us at dpo@karverifi.com and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email to the account's billing contact and posted in the dashboard at least 30 days before the effective date.

12. Contact

Data Protection Officer: dpo@karverifi.com

Data subject access requests: dsar@karverifi.com

Karrabo Financial Solutions Limited
85–86 Terrace Wing, Tafawa Balewa Square
Lagos Island, Lagos, Nigeria