Biometric Data Policy & Notice

Last updated: July 13, 2026

1. PURPOSE

This Notice explains how Ha-Shem Limited (“Spidify”, “we”) processes biometric data when you complete an identity verification. It supplements our Privacy Policy and is provided in line with the Nigeria Data Protection Act 2023 (NDPA) and the GAID 2025.

2. WHAT BIOMETRIC DATA WE PROCESS

To confirm that you are a real, live person and that you match your identity document, we may process:

  • Facial images and short video frames captured during a liveness check;
  • Facial feature measurements used to compare your live capture with the photo on your identity document (1:1 face match);
  • Liveness signals used to detect presentation attacks (e.g. photos, replays, deepfakes).

3. LAWFUL BASIS & CONSENT

We process biometric data on the basis of your explicit consent, obtained before capture, and to meet the identity-verification and anti-money-laundering obligations of the business you are being onboarded by. You may withdraw consent at any time, though this may prevent completion of your verification.

4. HOW WE USE IT

  • To verify liveness and confirm you are physically present;
  • To match your face to your identity document;
  • To prevent identity fraud and impersonation;
  • To produce a verification result and audit record for the requesting business.

We do not sell biometric data or use it for advertising.

5. PROCESSORS

Liveness detection and face comparison are performed using Microsoft Azure Face services as our sub-processor, under contractual data-protection terms. Processing is performed in secured cloud infrastructure.

6. RETENTION & MINIMISATION

We apply data-minimisation and defined retention controls. Biometric captures are retained only as long as necessary to complete verification, satisfy applicable record-keeping obligations, and defend against fraud, after which they are archived, have personal data purged, and are ultimately deleted in accordance with our retention policy and applicable law.

7. SECURITY

Biometric data is encrypted in transit and at rest, access is restricted, and sensitive identifiers are masked in logs and audit records.

8. YOUR RIGHTS

You have the right to access, correct, or request deletion of your biometric data. Submit a request through our data-request page and we will respond within the statutory timeframe.

9. CONTACT

For questions about biometric processing, contact our Data Protection Officer at dpo@ha-shem.com.