Privacy Policy
What personal and biometric data FaceTrust AI processes, why, how long we keep it, and the rights you have over it under the Nigeria Data Protection Act.
Effective date: September 14, 2026
1. Who we are
FaceTrust AI ("FaceTrust," "we," "us," or "our") is a company incorporated under the laws of the Federal Republic of Nigeria. Our registered office address is NO 11, Alatare Comp, Omoda/Adangba Street, Ilorin, Ilorin, Kwara State, Nigeria. This policy is governed by the Nigeria Data Protection Act 2023 ("NDPA") and the General Application and Implementation Directive 2025 ("GAID") issued by the Nigeria Data Protection Commission ("NDPC").
We've appointed a Data Protection Officer ("DPO") under Section 31 of the NDPA, who oversees our compliance and is your main point of contact for anything to do with your data — including requests to the NDPC. Reach the DPO at Admin@facetrustai.com.
Where we process personal data on behalf of an institution we onboard, that institution is typically the data controller and FaceTrust AI is the processor, under a separate Data Processing Agreement.
2. Who this applies to
This policy covers individuals whose identity is verified through FaceTrust AI — consumers who link a NIN or BVN and enroll a face, responsible officers and staff of institutions we onboard, and operators at merchant desks. It also covers visitors to facetrustai.com.
3. What we collect
Identity data. Your full legal name, date of birth, gender, nationality, and photograph, and, where applicable, your NIN or BVN as issued by the relevant national registry, which we use for identity verification and KYC/AML compliance. When you link a NIN or BVN, we validate it against the relevant registry and store a masked, encrypted record of it — never the full plaintext number displayed back to staff.
Biometric data. A live face capture, including frames used for liveness detection, is used at the moment of verification to confirm you match the registry photo. These facial images are sensitive personal data under the NDPA. From that capture we derive a single canonical 512-dimensional ArcFace face embedding — a numeric representation of your face, not a photo — which is what's stored and reused for future identification. We do not keep a rolling album of past photos; a new enrollment replaces the canonical embedding, and the prior one is archived to an internal audit table rather than kept as an active record.
Contact data. Telephone number, email address, and postal address, where you've provided them to us or your institution has provided them as part of a verification request.
Device and technical data. When you interact with our platform, we automatically collect your IP address, browser type and version, operating system, device identifiers, screen resolution, session timestamps, and referring URLs.
Transaction and usage data. Every comparison — matched, not matched, or too close to call — is logged with its verification request identifier, confidence score, fraud risk score, timestamp, and which merchant desk or channel it came from. This is what makes disputes and audits possible.
4. Why we process it, and our legal basis
Under Section 25 of the NDPA, we need a lawful basis for each processing activity. We don't use your data for advertising, and we don't sell it.
Biometric identity verification. To confirm your identity by capturing your facial image, generating a face embedding, and matching it against reference embeddings — on the basis of your explicit consent, obtained before capture. You may withdraw that consent at any time (see Your rights below); withdrawal doesn't affect the lawfulness of processing carried out before you withdrew.
Fraud detection and prevention. To generate fraud risk scores, detect duplicate or spoofed identities, and run velocity checks across the embedding space — on the basis of our legitimate interest in protecting the integrity of our platform and our clients' customers, which we've assessed as not overridden by your rights and freedoms given the safeguards we apply.
Service delivery. To provide the verification services you or your institution requested and manage your account — on the basis of performance of a contract, or steps taken at your request before entering one.
KYC/AML compliance. To satisfy know-your-customer and anti-money-laundering obligations under Nigerian financial regulation — on the basis of compliance with a legal obligation.
System security and audit logging. To monitor system performance, detect and respond to security incidents, and maintain audit trails — on the basis of our legitimate interest in the security and reliability of our systems and in meeting our accountability obligations.
Service communications. To send you operational communications such as verification confirmations, security alerts, and policy updates — on the basis of contract performance and legitimate interest.
5. How we protect it
The registry photo behind a NIN or BVN is never released to a client before your own live face proof succeeds — validating an identity and fetching its photo are two separate, gated steps. Liveness is checked before any face comparison runs, so a printed photo or screen replay is rejected before it reaches the matching engine. Staff access is layered — password, one-time codes, and for the most sensitive actions, hardware security keys plus a second person's approval. Biometric embeddings and facial images are encrypted in transit using TLS 1.2 or higher and at rest using AES-256, with keys under our sole control through AWS Key Management Service. Full detail is in our Security page.
6. Who we share it with
We do not sell your personal data. We never have, and we don't intend to. We share it only where necessary, with:
Enterprise clients. The institution you enrolled through receives verification results (match or no-match) and risk scores, scoped to that institution only. We do not share raw biometric images or embeddings with clients unless you've explicitly authorized it.
Cloud infrastructure providers. We use Amazon Web Services (AWS) for hosting, processing, and disaster recovery, under a written data processing agreement — our primary database is AWS RDS PostgreSQL with the pgvector extension for storing and querying biometric embeddings. AWS Key Management Service manages encryption keys and does not have access to the plaintext data those keys protect.
Regulators and law enforcement. Where required by law, a court order, or a binding request from the NDPC or another competent authority.
Professional advisors. Auditors, legal advisors, and insurers, to the extent necessary for their professional functions and subject to confidentiality obligations.
All third-party recipients are contractually required to apply appropriate safeguards and process data only on our documented instructions.
7. Cross-border transfers
Because we use AWS infrastructure, some of which sits outside Nigeria, your data may be processed in other countries. Any such transfer is governed by Part VIII of the NDPA and Article 45 and Schedule 5 of the GAID. Depending on the destination, we rely on an NDPC adequacy decision for that country, Standard Contractual Clauses approved or recognised by the NDPC, or — for intra-group transfers should FaceTrust AI expand into a group structure — Binding Corporate Rules. Before relying on Standard Contractual Clauses we run a transfer impact assessment and add supplementary measures (such as additional encryption) where needed. In limited cases we may instead rely on your explicit consent, or on a derogation permitted under the NDPA and GAID (for example, where the transfer is necessary to perform our contract with you). We review our cross-border arrangements at least annually.
8. How long we keep it
Full detail, including the exact ordering used when you delete your account, is in our Data Retention Policy. In short: biometric facial images are kept for a maximum of 90 days from capture; your canonical face embedding is removed first and immediately on account deletion; identity data and NINs are retained for 7 years to meet KYC/AML record-keeping obligations; and verification and audit logs are retained beyond account deletion to support disputes, fraud investigation, and regulatory audit.
9. Your rights
Subject to conditions under the NDPA, you have the right to confirm whether we're processing your data and get a copy of it; correct or complete inaccurate data; request deletion (which we may decline where retention is required by law, such as KYC/AML record-keeping); restrict processing in certain circumstances; receive your data in a portable, machine-readable format; object to processing based on our legitimate interest; and withdraw consent at any time for processing that relies on it, without affecting the lawfulness of processing carried out before you withdrew.
You can exercise these through our Data Subject Request form, or directly from your account settings where the underlying action (export, delete) is available in-product. We'll respond within 30 days of a verified request, or sooner where the NDPA or GAID requires it. If you believe we haven't handled your data properly, you have the right to lodge a complaint with the NDPC — we'd appreciate the chance to address it directly first, but that right is yours to exercise at any time.
10. Cookies
We use cookies and similar tracking technologies on our websites and web applications in accordance with Article 19 of the GAID. Full detail on what we use and how to manage it is in our Cookie Policy.
11. Children
FaceTrust AI is not directed at children under eighteen and is not knowingly used to enroll anyone below that age. If we discover we've inadvertently collected a child's data without appropriate parental or guardian consent, we'll delete it promptly and in its entirety. Parents or guardians with concerns can contact our DPO immediately at Admin@facetrustai.com.
12. Changes to this policy
We'll update the effective date above when this policy changes. Where a change is material, we'll notify you by email, an in-platform notification, or a prominent website notice at least 30 days before it takes effect, and seek fresh consent where the change affects processing based on consent. Continued use of our services after that notice constitutes acceptance, unless you object within the notice period.
Questions about this document? Contact info@facetrustai.com. See also our Privacy Policy, Data Retention Policy, and Data Subject Request form.
Bring FaceTrust AI to your business
Talk to us about a pilot, or dig into the API reference to see exactly how it fits your stack.