Who we are
ONE VERIFY LTD, trading as One Verify, is a technology company licensed by NIMC to provide identity verification services and provides technological and end-to-end business solutions to corporate and institutional Clients. This Privacy Policy explains how we collect, use, disclose, retain and protect Personal Data.
Scope
This Policy applies to Personal Data processed through:
- the One Verify website;
- Client dashboards;
- APIs;
- identity verification services;
- business verification services;
- customer support channels; and
- other One Verify technology platforms.
Categories of personal data
Depending on the Services used, we may process:
Identity Data
- full name;
- date of birth;
- gender;
- nationality;
- NIN;
- BVN;
- passport information;
- driver's licence information;
- identification-document information;
- photograph;
- biometric information where applicable;
- signature; and
- verification results.
Corporate Data
- company registration details;
- directors;
- shareholders;
- beneficial owners;
- business addresses;
- tax information; and
- related corporate information.
Technical Data
- IP address;
- device information;
- browser information;
- login records;
- API logs;
- access logs;
- timestamps; and
- security information.
Sources of personal data
Personal Data may be obtained from:
- Data Subjects;
- Clients;
- NIMC and authorised NIMC channels;
- government agencies;
- authorised data providers;
- corporate registries;
- verification partners; and
- other lawful sources.
NIMC currently identifies verification and authentication among its identity-management services, and its 2026 statutory framework places emphasis on secure and interoperable identity and data exchange. (NIMC)
Purposes of processing
We process Personal Data for:
- identity verification;
- authentication;
- KYC/KYB;
- fraud prevention;
- identity-risk management;
- regulatory compliance;
- business verification;
- data validation;
- provision of Verification Data;
- customer support;
- account administration;
- security;
- billing;
- audit;
- service improvement; and
- responding to lawful requests.
Lawful basis
Depending on the circumstances, processing may be based on:
- consent;
- contractual necessity;
- legal obligation;
- legitimate interests;
- public interest; or
- another lawful basis recognised under applicable law.
We do not rely on consent where another lawful basis appropriately applies.
Identity data
Identity Data is central to our Services and may include unique identifiers, identification-document information, photographs and biometric information where applicable. We process Identity Data only for lawful and authorised purposes. We do not permit the Platform to be used for indiscriminate or unauthorised identity searches.
Controller and processor roles
One Verify may act as:
Data Controller, where we determine the purposes and means of processing; or
Data Processor, where we process Personal Data on behalf of a Client. The applicable role depends on the particular processing activity.
Client responsibilities
Clients using the Services are responsible for ensuring:
- lawful collection of Personal Data;
- appropriate lawful basis;
- required consent;
- appropriate privacy notices;
- legitimate verification purposes;
- appropriate security controls; and
- compliance with applicable law.
Disclosure
Personal Data may be disclosed to:
- NIMC;
- authorised government authorities;
- authorised data providers;
- Clients;
- technology providers;
- cloud-service providers;
- professional advisers;
- regulators; and
- law enforcement where legally required.
International transfers
Where Personal Data is transferred outside Nigeria, One Verify shall comply with applicable legal requirements and implement appropriate safeguards.
Security
We maintain appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, destruction, alteration or disclosure.
Retention
Personal Data is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, regulatory, contractual, audit and security requirements. Detailed retention periods are contained in the One Verify Data Retention and Disposal Policy.
Data subject rights
Subject to applicable law, Data Subjects may have rights to:
- access;
- correction;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent; and
- other rights recognised under applicable law.
Automated processing
Our technology may use automated processes to compare, validate or authenticate information. Where automated processing produces legally significant or similarly significant effects, appropriate safeguards shall apply in accordance with applicable law.
Data breaches
Where a Personal Data breach occurs, One Verify shall take appropriate steps to investigate, contain and remediate the incident and make notifications where required.
Children
Our Services are primarily designed for corporate and institutional Clients. Where children's Personal Data is processed in connection with a lawful verification activity, appropriate safeguards shall apply.
Contact
Data Protection Officer: [●]
Email: [●]
Address: [●]