Data Retention Policy
How long we keep different kinds of data, and the exact order things are removed when an account is deleted.
Effective date: September 14, 2026
1. Principle
We keep data only as long as it serves the purpose it was collected for — running a verification, supporting a dispute, or meeting a legal or regulatory obligation under the Nigeria Data Protection Act 2023 — and no longer. When a retention period expires, we securely erase the data or anonymise it so you can no longer be identified from it. Where data is subject to a legal hold, litigation, or regulatory investigation, we may extend retention for the duration of those proceedings.
2. Biometric facial images
Photographs and video frames captured during verification, including liveness-detection frames, are retained for a maximum of 90 days from the date of capture. After that period they're securely deleted, unless retention is required for an ongoing fraud investigation or legal proceeding.
3. Biometric vector embeddings
Only one canonical 512-dimensional ArcFace embedding is kept per enrolled person at any time. It's retained for the duration of your active account or verification relationship, plus 12 months following account closure or your last verification event, whichever is later. When a new enrollment replaces it, the prior embedding is moved to an internal audit table rather than kept as an active, searchable record. On account deletion, the active canonical embedding is removed first — before the rest of the profile is soft-deleted — as a hard precondition, not a background cleanup job that might lag behind.
4. Identity data and NINs
Registry numbers (NIN/BVN) are stored as a lookup hash plus an application-layer-encrypted value used only for masked display. Identity data and NINs are retained for 7 years from the date of collection to comply with KYC/AML record-keeping requirements under Nigerian financial regulation.
5. Contact data
Name, phone, email, and preferences are retained for the duration of our contractual or service relationship with you, plus 24 months thereafter. On account deletion, this data is soft-deleted (marked inactive, excluded from normal product use) rather than purged immediately, to preserve referential integrity with historical verification logs.
6. Device and technical data
IP address, browser and device information, and session data are retained for 12 months from the date of collection.
7. Transaction, usage, and audit data
Verification request identifiers, match and fraud risk scores, and general usage records are retained for 7 years to satisfy regulatory audit requirements. Audit and system logs are retained for 36 months from the date of creation. These logs are kept beyond account deletion to support disputes, fraud investigation, and regulatory audit — a deliberate exception to immediate deletion, since a log's value is largely in outlasting the account it describes.
8. Deletion ordering, summarized
- Canonical face embedding is removed.
- The user profile is soft-deleted (excluded from active use, contact data no longer used).
- Verification, search, and audit logs are retained under the windows in Sections 4 and 7, referencing the now-deleted account by ID only.
9. Institution-level data
Branch, staff, and billing records for an institution are retained for the duration of the institution's relationship with FaceTrust AI, plus a reasonable period after termination for billing reconciliation and dispute resolution, consistent with our Data Processing Agreement.
Questions about this document? Contact info@facetrustai.com. See also our Privacy Policy, Data Retention Policy, and Data Subject Request form.
Bring FaceTrust AI to your business
Talk to us about a pilot, or dig into the API reference to see exactly how it fits your stack.