Data Processing Agreement
The terms under which FaceTrust AI processes personal and biometric data on behalf of an institution we onboard.
Effective date: September 4, 2026
1. Roles
For data an institution submits about its own customers or staff (registry numbers, verification requests), the institution is the data controller and FaceTrust AI is the data processor. For data FaceTrust AI collects directly to operate the Services (system logs, our own staff accounts), FaceTrust AI is the controller. This document governs the processor relationship.
2. Scope and instructions
FaceTrust AI processes personal and biometric data solely to provide identity verification and 1:N identification as configured by the institution, and otherwise only on the institution's documented instructions, unless required to do otherwise by law — in which case we'll inform the institution first, where legally permitted.
3. Confidentiality
Access to an institution's data is scoped to that institution — Institution Console access, branch data, and staff records for one institution are never visible to another. Our own staff access is layered (password, one-time codes, face check, and for the most sensitive actions, hardware keys plus a second approver) and logged.
4. Sub-processors
FaceTrust AI uses infrastructure and cloud-hosting sub-processors to run the Services, and the national identity registries (NIMC/NIBSS or their authorized aggregators) to validate NIN/BVN records. We remain responsible for any sub-processor's compliance with the same data-protection commitments made here, and will notify institutions of any material change of sub-processor.
5. Security measures
Photo release is gated behind a successful live-face proof; liveness is checked before any comparison; each person's face is stored as a single canonical embedding rather than a photo library, with prior embeddings archived rather than exposed; and every comparison is logged for audit. Full detail is in our Security page.
6. Data subject requests
Where FaceTrust AI receives a request directly from a data subject concerning data we process on an institution's behalf, we will notify the institution and support it in responding, without responding on the institution's behalf unless instructed to.
7. Deletion and return of data
On termination of an institution's use of the Services, and consistent with our Data Retention Policy, biometric records are deleted first; verification and audit logs are retained for the period required for legal, regulatory, or dispute-resolution purposes even after other data is removed.
8. International transfers
Where personal data is processed or stored outside Nigeria — which happens because FaceTrust AI runs on AWS infrastructure, some of it outside Nigeria — the transfer relies on an NDPC adequacy decision for the receiving country, Standard Contractual Clauses approved or recognised by the NDPC, or another safeguard permitted under Part VIII of the NDPA and the GAID, consistent with our Privacy Policy. We'll document the specific mechanism used on request.
9. Precedence
Where an institution has a separately signed agreement or order form with FaceTrust AI that conflicts with this document, the signed agreement controls.
Questions about this document? Contact info@facetrustai.com. See also our Privacy Policy, Data Retention Policy, and Data Subject Request form.
Bring FaceTrust AI to your business
Talk to us about a pilot, or dig into the API reference to see exactly how it fits your stack.