Legal document

One Verify Limited

Terms of Service

Effective date1 September 2026
Last updatedSeptember 2026

These Terms of Service are a business-to-business agreement. They should be read together with the applicable Service Level Agreements (SLA), pricing schedule, Data Processing Agreement (DPA), Privacy Statement and any product-specific terms. In the event of conflict, the SLA prevails on commercial terms and the DPA prevails on Personal Data processing matters, unless expressly stated otherwise.

1

Acceptance of terms and effective date

1.1These Terms of Service (Terms) govern the access to and use of the One Verify platform, website, application programming interfaces ("APIs"), dashboards, software, identity verification services, data verification services and other technology-enabled solutions provided by ONE VERIFY LTD, a company incorporated under the laws of the Federal Republic of Nigeria and licensed by the National Identity Management Commission (NIMC) to provide identity-verification services (One Verify, Company, we, us or our).

1.2These Terms form a legally binding agreement between One Verify and the corporate, institutional, governmental or other business entity identified in the applicable SLA or otherwise approved by One Verify (Client, you or your).

1.3These Terms take effect on the earliest of: (a) the date the Client signs an SLA or other commercial agreement incorporating these Terms; (b) the date the Client accepts these Terms electronically; (c) the date One Verify issues Account or API credentials to the Client; or (d) the date the Client first accesses or uses the Platform or Services (Effective Date).

1.4The individual accepting these Terms represents and warrants that they are duly authorised to bind the Client.

1.5By registering for, accessing or using the Platform or Services, the Client confirms that it has read, understood and agreed to these Terms and that the person accepting these Terms is duly authorised to bind the Client.

2

Definitions

"Account" means an account established for the Client to access the Platform.

"API" means the application programming interfaces made available by One Verify for integration with the Client’s systems.

"Authorised User" means an employee, contractor or representative of the Client whom the Client has authorised to access the Services on its behalf.

"Client Data" means information, Personal Data or other data submitted, uploaded, transmitted or otherwise provided by or on behalf of the Client through the Services.

"Data Subject" means an identified or identifiable natural person whose Personal Data is processed through the Services.

"Identity Data" means information relating to an identified or identifiable individual used for identity verification or authentication, including identification numbers, names, dates of birth, photographs, biometric information, identification-document information and related information.

"Personal Data" means has the meaning given under applicable data protection law.

"Platform" means One Verify’s websites, dashboards, APIs, applications, software, systems and technological infrastructure.

"Services" means the identity verification, authentication, data verification, business verification and other technology-enabled services provided by One Verify.

"SLA" means the Service Level Agreement, a commercial agreement detailing the pricing schedule, identifying the Services, fees, API-call allocation, subscription period or other applicable commercial terms agreed by the parties.

"Verification Data" means verification results, responses, information and other data generated or returned through the Services.

3

Purpose and overview of services

3.1One Verify provides technology-enabled identity verification, authentication, data verification and end-to-end business solutions to corporate and institutional Clients.

3.2Subject to applicable law, regulatory requirements, data-source availability, Client eligibility and the applicable commercial arrangement, the Services may include:

  • NIN verification
  • BVN verification
  • identification-document, driver’s licence and passport verification
  • business, CAC, TIN and address verification
  • biometric or facial verification, where available and lawfully provided
  • identity authentication, data matching and validation
  • fraud and identity-risk checks
  • other verification and technology-enabled services made available by One Verify

3.3One Verify may update, improve, expand, restrict or discontinue a Service where reasonably necessary for security, operational, legal, regulatory or commercial reasons. One Verify will use reasonable efforts to give advance notice of material changes where practicable, but may act without prior notice where required to protect the Platform, comply with law or respond to a security or regulatory risk.

4

Client eligibility, onboarding and due diligence

4.1The Services are intended for corporate and institutional Clients. One Verify may conduct know-your-business, compliance, risk, sanctions, fraud and other due-diligence checks before or after granting access.

4.2The Client shall provide accurate, complete and current information and documents reasonably requested by One Verify, including information on ownership and beneficial ownership, directors, business activities, regulatory licences, intended use, expected verification volumes and jurisdictions of operation.

4.3One Verify may refuse, delay, restrict or terminate onboarding or access where the Client does not satisfy applicable legal, regulatory, compliance or risk requirements.

4.4The Client shall promptly update One Verify if any information provided during onboarding changes materially.

5

Accounts, authorised users and API access

5.1One Verify grants the Client a limited, non-exclusive, non-transferable and revocable right, during the applicable subscription period, to access and use the Platform and Services solely for the Client’s internal, lawful business purposes and in accordance with these Terms and the applicable SLA.

5.2The Client shall ensure that only Authorised Users access its Account or use its API credentials. The Client is responsible for all activity conducted through its Account or credentials, except to the extent caused by One Verify’s negligence or wilful misconduct.

5.3The Client shall keep credentials confidential, maintain appropriate access controls, promptly revoke access for departing personnel, and notify One Verify without undue delay of suspected unauthorised access, credential compromise or misuse.

5.4The Client shall not share credentials with unauthorised persons, resell or sublicense API access, reverse engineer the Platform or API, circumvent technical restrictions, interfere with Platform security or exceed agreed usage limits.

5.5One Verify may apply rate limits, usage limits, authentication requirements and other reasonable technical controls to protect security and availability.

6

Verification requests and client responsibilities

6.1The Client shall submit Identity Data only where it has a specific, legitimate and lawful purpose for the verification request.

6.2The Client shall ensure it has a valid lawful basis for collecting and submitting Personal Data through the Services and, where consent is required, has obtained valid consent in accordance with applicable law.

6.3The Client shall provide Data Subjects with all privacy information required by applicable law and shall retain evidence of its lawful basis, notices and consents where applicable.

6.4The Client shall submit only data reasonably necessary for the verification purpose, take reasonable steps to ensure its accuracy and completeness, and maintain records sufficient to support each verification request.

6.5The Client shall not conduct indiscriminate, speculative or unauthorised searches of individuals or businesses.

6.6The Client shall not use Identity Data, Verification Data, the Platform or Services to commit or facilitate fraud, identity theft, unlawful discrimination, harassment, unauthorised surveillance, money laundering, terrorism financing, unlawful data acquisition, or any other unlawful activity.

6.7The Client shall implement appropriate technical and organisational measures to protect Identity Data and Verification Data in its possession or control and shall not retain, sell, publish, disclose, transfer or otherwise make Verification Data available to unauthorised third parties.

7

Verification results and client decisions

7.1One Verify will use reasonable efforts to provide Verification Data based on information available through authorised data sources.

7.2A verification result may be successful, failed, inconclusive, unavailable, delayed or affected by incomplete, inaccurate, outdated, restricted or unavailable information from a data source.

7.3A failed, inconclusive or unavailable result does not establish that an individual has committed fraud or that information supplied by that individual is false.

7.4Verification Data is provided to assist the Client’s own business, compliance and risk decisions. The Client remains solely responsible for determining what action it takes based on a result and shall not treat a result as an absolute guarantee of identity, character, financial position, creditworthiness, integrity or suitability.

7.5The Client shall have appropriate human review, escalation and correction procedures for material decisions made using Verification Data where required by applicable law or appropriate to the Client’s use case.

8

NIMC, third-party data sources and service providers

8.1One Verify shall provide identity verification and authentication through NIMC, government authorities, registries, authorised data providers, cloud and infrastructure providers and other third-party service providers or data sources.

8.2Access to identity information may be subject to legal restrictions, permissions, authorisations, consent requirements, service rules and technical controls. The Client shall comply with all requirements applicable to its use of the Services, including relevant NIMC requirements.

8.3Nothing in these Terms grants the Client any ownership of, or right in, NIMC databases, government databases, third-party data sources or their underlying records.

8.4One Verify does not control third-party systems or data sources and is not responsible for their availability, accuracy, integrity, changes, outages, delays or restrictions to the extent outside One Verify’s reasonable control.

8.5One Verify may change, add, replace, restrict or discontinue a third-party provider or data source where reasonably necessary. Continued use of the Services remains subject to any applicable third-party restrictions communicated to the Client.

9

Fees, prepayment and API calls

9.1The Client shall pay all subscription, setup, API, verification and other fees specified in the applicable SLA, pricing schedule or invoice. Fees are exclusive of applicable taxes unless expressly stated otherwise.

9.2The Client shall prepay the applicable fees for the API calls allocated for each Month or Quarter on or before the first day of that Month or Quarter, in accordance with the payment terms stated in the relevant invoice.

9.3Unless the applicable SLA expressly states otherwise, unused API calls roll over to a subsequent Month or Quarter. Consumed API calls are non-refundable. API calls are consumed when a request is submitted to the applicable service, whether or not a successful match or result is returned, except where the failure is demonstrably caused solely by One Verify’s internal systems.

9.4Additional usage, overages or services outside the allocated API calls will be charged at the applicable agreed rate. One Verify may require advance payment before enabling additional usage.

9.5One Verify may suspend or restrict the Services if fees remain unpaid after the applicable due date, without prejudice to its other rights and remedies.

10

Data protection

10.1Each party shall comply with applicable data protection laws, including the Nigeria Data Protection Act 2023 and applicable regulations, guidance and regulatory requirements.

10.2Depending on the nature of the processing, One Verify may act as a Data Controller, Data Processor or both. Where One Verify processes Personal Data on behalf of the Client, the parties shall comply with the applicable DPA.

10.3The Client remains responsible for ensuring that Personal Data submitted to One Verify has been collected and processed lawfully. The Client shall reasonably cooperate with One Verify in relation to data-subject requests, regulatory inquiries, security incidents and data-protection complaints relevant to the Services.

10.4To the extent of a conflict concerning Personal Data processing, the DPA prevails over these Terms.

11

Security, service availability and incidents

11.1One Verify will maintain appropriate technical and organisational measures designed to protect information processed through the Platform. The Client shall maintain appropriate security controls over its systems, devices, networks, credentials and personnel.

11.2The Services may be temporarily unavailable because of planned maintenance, emergency maintenance, third-party outages, data-source downtime, internet or telecommunications failures, regulatory restrictions or circumstances outside One Verify’s reasonable control. One Verify will use reasonable efforts to provide notice of planned material maintenance where practicable.

11.3Each party shall notify the other without undue delay of a confirmed Personal Data breach or material security incident affecting Personal Data processed under the Services where notification is required by applicable law or the DPA. The parties shall reasonably cooperate in investigation, containment, remediation and any required notification.

12

Prohibited activities

12.1The Client shall not use the Services in a manner that violates applicable law; infringes another person’s rights; compromises Platform security; transmits malicious software; circumvents usage restrictions; enables unauthorised identity searches; resells the Services without One Verify’s written authorisation; or exposes One Verify to material legal, regulatory, security or reputational risk.

13

Confidentiality and intellectual property

13.1Each party shall keep the other party’s non-public business, technical, commercial, security and other confidential information confidential and use it only to exercise its rights or perform its obligations under these Terms.

13.2Confidentiality obligations do not apply to information that the receiving party can demonstrate is publicly available without breach, lawfully received from a third party without a confidentiality obligation, or independently developed without use of the disclosing party’s confidential information.

13.3A party may disclose confidential information where required by law, regulation, court order or competent authority, or where reasonably necessary to provide the Services, provided that it gives notice where legally permitted and practicable.

13.4All rights in the Platform, software, APIs, documentation, interfaces, trademarks, technology and related intellectual property belong to One Verify or its licensors. The Client receives only the limited rights expressly granted under these Terms.

14

Suspension and termination

14.1One Verify may immediately suspend, restrict or disable access to all or part of the Services where reasonably necessary because of suspected fraud, money laundering, terrorism financing, prohibited activity, non-payment, misuse of Identity Data or Verification Data, a material breach, unauthorised access, a security risk, a regulatory requirement or directive, or circumstances exposing One Verify to material legal, regulatory or reputational risk.

14.2Where legally permitted and reasonably practicable, One Verify will notify the Client of a suspension and the steps, if any, required to restore access. One Verify is not required to disclose information where doing so would be unlawful, compromise an investigation or create a security risk.

14.3Either party may terminate in accordance with the applicable SLA. One Verify may terminate immediately where the Client commits a material breach, continued provision would violate law, a competent authority requires termination, or the Client presents an unacceptable legal, regulatory or security risk.

14.4On termination, the Client shall cease use of the Platform and Services, pay all amounts due and return or securely delete One Verify’s confidential information as requested, subject to applicable legal retention requirements. Accrued rights and provisions intended to survive termination, including payment, confidentiality, data protection, intellectual property, indemnity, liability and governing-law provisions, survive termination.

15

Indemnity, disclaimers and limitation of liability

15.1The Client shall indemnify and hold harmless One Verify and its affiliates, officers, employees and service providers against claims, losses, liabilities, penalties, costs and expenses arising from the Client’s unlawful use of the Services; breach of these Terms; unlawful collection or submission of Identity Data; failure to obtain a required lawful basis or consent; misuse or unauthorised disclosure of Verification Data; or violation of applicable law or regulatory requirements.

15.2Except as expressly stated in these Terms, the Platform, Services and Verification Data are provided on an “as is” and “as available” basis. One Verify does not warrant that the Services will be uninterrupted, error-free, available at all times or suitable for a particular purpose, or that third-party data will be complete, accurate or current.

15.3To the maximum extent permitted by applicable law, One Verify shall not be liable for indirect, incidental, special, punitive or consequential loss, or for loss of profit, revenue, business, goodwill, opportunity, anticipated savings or data, arising out of or in connection with the Services.

15.4To the maximum extent permitted by applicable law, One Verify’s aggregate liability arising out of or in connection with these Terms shall not exceed the fees actually paid by the Client to One Verify for the affected Services in the twelve (12) months preceding the event giving rise to the claim.

15.5Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited.

16

Notices, complaints and changes

16.1One Verify may give notices electronically through the Platform, dashboard, the Client’s registered email address, or any other contact details supplied by the Client. The Client shall keep its contact details current.

16.2Clients may submit complaints relating to the Services to: Email: info@oneverify.ng. One Verify will acknowledge a complaint within a reasonable period and investigate and respond having regard to its nature and complexity. The Client shall submit sufficient information and cooperate reasonably with the investigation.

16.3One Verify may amend these Terms where reasonably necessary to reflect changes in the Services, technology, law, regulation, security requirements or its business. One Verify will make the current version available to Clients and will provide reasonable notice of material changes where practicable. Continued use after the effective date of an amendment constitutes acceptance, except where the applicable SLA or law requires a different process.

17

Governing law and general

17.1These Terms and any non-contractual obligations arising out of or in connection with them are governed by the laws of the Federal Republic of Nigeria.

17.2The parties shall first attempt in good faith to resolve any dispute through authorised representatives. If unresolved, either party may pursue remedies before the courts of competent jurisdiction in Nigeria, unless the applicable SLA provides otherwise.

17.3The Client may not assign, transfer or sublicense its rights or obligations under these Terms without One Verify’s prior written consent. One Verify may assign or transfer these Terms to an affiliate or successor in connection with a restructuring, merger, acquisition or transfer of substantially all relevant assets, on notice to the Client where practicable.

17.4If any provision is held invalid or unenforceable, it shall be modified to the minimum extent necessary and the remaining provisions shall continue in full force. A failure to enforce a provision is not a waiver. These Terms, the applicable SLA, DPA and Privacy Statement constitute the entire agreement relating to the Services and replace prior discussions or understandings on that subject.

Contact details

Name: ONE VERIFY LTD

Address: 9 Onitsha Crescent, Off Gimbiya Street Garki, Area 11, Abuja, FCT

Telephone: +234816918684

Email: info@oneverify.ng