Biometric Data Policy & Notice
Last updated: July 13, 2026
1. PURPOSE
This Notice explains how Ha-Shem Limited (“Spidify”, “we”) processes biometric data when you complete an identity verification. It supplements our Privacy Policy and is provided in line with the Nigeria Data Protection Act 2023 (NDPA) and the GAID 2025.
2. WHAT BIOMETRIC DATA WE PROCESS
To confirm that you are a real, live person and that you match your identity document, we may process:
- Facial images and short video frames captured during a liveness check;
- Facial feature measurements used to compare your live capture with the photo on your identity document (1:1 face match);
- Liveness signals used to detect presentation attacks (e.g. photos, replays, deepfakes).
3. LAWFUL BASIS & CONSENT
We process biometric data on the basis of your explicit consent, obtained before capture, and to meet the identity-verification and anti-money-laundering obligations of the business you are being onboarded by. You may withdraw consent at any time, though this may prevent completion of your verification.
4. HOW WE USE IT
- To verify liveness and confirm you are physically present;
- To match your face to your identity document;
- To prevent identity fraud and impersonation;
- To produce a verification result and audit record for the requesting business.
We do not sell biometric data or use it for advertising.
5. PROCESSORS
Liveness detection and face comparison are performed using Microsoft Azure Face services as our sub-processor, under contractual data-protection terms. Processing is performed in secured cloud infrastructure.
6. RETENTION & MINIMISATION
We apply data-minimisation and defined retention controls. Biometric captures are retained only as long as necessary to complete verification, satisfy applicable record-keeping obligations, and defend against fraud, after which they are archived, have personal data purged, and are ultimately deleted in accordance with our retention policy and applicable law.
7. SECURITY
Biometric data is encrypted in transit and at rest, access is restricted, and sensitive identifiers are masked in logs and audit records.
8. YOUR RIGHTS
You have the right to access, correct, or request deletion of your biometric data. Submit a request through our data-request page and we will respond within the statutory timeframe.
9. CONTACT
For questions about biometric processing, contact our Data Protection Officer at dpo@ha-shem.com.