Privacy Policy

Last updated: July 13, 2026

INTRODUCTION

At Ha-Shem Limited, we believe strongly in fundamental privacy rights as embedded in Section 37 of the 1999 Constitution (as amended) (the Constitution). That is why we treat any data that relates to an identified or identifiable individual, or that is linked or linkable to them by us, as “personal data.” This means that data that directly identifies you — such as your name — is personal data, and data that does not directly identify you but can reasonably be used to identify you — such as your device’s serial number — is also personal data.

This Privacy Policy covers how Ha-Shem Limited or its affiliates (collectively, “Ha-Shem”) handles personal data, whether you interact with us on our websites, through our Spidify identity verification platform, or in person (including by phone or when visiting our office at 9 Ibikunle Street, Off University Road, Herbert Macaulay Way, Yaba, Lagos). This Privacy Policy is in accordance with the Nigerian Data Protection Act 2023 (NDPA), regulations, guidelines and directives made pursuant to the NDPA (“Applicable Laws”) and is binding on all data subjects whose Personal Data we process.

You accept this Privacy Policy and hereby give Ha-Shem Limited consent to collect, store, process, and use your Personal Data to the extent permitted under Applicable Laws by clicking the “Accept” button or completing a verification. You have the right to withdraw your consent at any time, provided that we do not have another lawful basis to keep processing your Personal Data.

We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy, and we may provide additional notice (such as by adding a statement to our homepages or by sending you an email notification). We encourage you to review the Privacy Policy whenever you interact with us.

1. LAWFUL BASIS FOR PROCESSING YOUR INFORMATION

All Personal Data that we collect and process is justified by at least one of the following lawful bases:

  • You have given consent to the processing;
  • Processing is necessary for the performance of a contract to which you are a party or to take steps to enter into a contract;
  • Processing is necessary for compliance with legal and regulatory obligations to which we are subject (including KYC/AML obligations);
  • Processing is necessary to protect your vital interests or those of another natural person;
  • Processing is necessary for the performance of a task carried out in the public interest;
  • Processing is necessary for the purposes of our legitimate interests or those of a third party, provided that your rights and freedoms do not override such interests.

2. TYPES OF PERSONAL DATA WE PROCESS

We may collect and process the following information about you:

  • Information you provide to us, for example when you fill out a contact or web form, book a demo, or register to receive updates.
  • Personal Data you provide while signing up for a service.
  • Technical data, such as information about the browser or device you use, how you use this site, the pages you visit, and traffic and location data.
  • Information you provide when you contact our customer support, whether by phone, email, or chat.
  • Identity & Verification Data (Spidify): identity documents you submit (such as NIN, BVN records, International Passport, Driver’s Licence, and utility bills) and the structured data extracted from them (name, date of birth, identity numbers, and address); facial images, liveness data and short video frames captured during a liveness check; and verification results including face-match scores, liveness outcomes, and AML/PEP/sanctions screening results.

Our processing of biometric data is described in more detail in our Biometric Data Policy & Notice.

3. USE OF YOUR PERSONAL DATA

We may use your Personal Data as follows:

  • Provide, maintain, and improve our services.
  • Verify your identity, confirm liveness, match your face to your identity document, and prevent fraud and impersonation.
  • Extract and validate information from your identity and address documents.
  • Screen against AML/PEP/sanctions and watchlists as required by law.
  • Produce a verification result and audit record for the business that requested your verification.
  • Send you technical notices, security alerts, support, and administrative messages.
  • Respond to your comments, questions, and requests, and provide customer service.
  • Monitor and analyse trends, usage, and activities in connection with our services.
  • Comply with legal and regulatory obligations and carry out any other purpose for which the Personal Data was collected.

Identity verification processing (Spidify): documents are processed using Microsoft Azure Document Intelligence; liveness and face comparison are performed using Microsoft Azure Face; BVN and NIN checks are performed through licensed identity data partners; AML/PEP/sanctions screening is performed through screening partners. Results are returned to the business that initiated your verification. High-risk screening matches are held for human review and are never automatically approved.

4. DISCLOSURE OF YOUR PERSONAL DATA

Ha-Shem Limited will disclose your Personal Data to third parties in the following circumstances:

  • In response to a request for Personal Data, if we are required by, or believe disclosure is in accordance with, any Applicable Law.
  • With relevant regulatory authorities, law enforcement officials, a court order, and investigators, in line with our legal obligations.
  • With the requesting business: the organisation that initiated your verification (the data controller) receives your verification results, extracted document data, and match/liveness scores in order to make its onboarding decision.
  • With verification data-source and processing partners: licensed identity, AML/screening, and business-registry providers, and cloud providers (Microsoft Azure), strictly to perform the requested checks under contractual data-protection terms. These providers do not use your data to train their models.
  • In connection with any merger, sale of Ha-Shem assets, financing, or acquisition, based on your existing contract with us or your consent.
  • With your consent or at your direction.

5. STORAGE AND TRANSFER OF YOUR PERSONAL DATA

We process Personal Data in both digital and physical formats. Physical records are secured, while digital data is stored on cloud platforms with data centres that may be located outside Nigeria. Documents and captured images are stored in Azure Blob Storage with encryption at rest, structured data is kept in Azure Database for PostgreSQL with SSL-enforced connections, and all API communication uses HTTPS/TLS encryption in transit. Sensitive identifiers such as NIN and BVN are masked in logs and audit records.

By accessing or using our Services or otherwise providing information to us, you consent to the processing and transfer of your information within Nigeria and to other countries where we or our service providers operate. Where data is transferred outside Nigeria, we ensure the recipient country has data protection laws that are adequate and comparable to those in Nigeria.

Where your data is transferred to other countries, there may be an increased risk to your personal information, particularly where such jurisdiction is not subject to the same level of protection as Nigeria. These risks may include:

  • Increased exposure to unauthorized access or misuse due to weaker enforcement mechanisms.
  • Lack of enforceable data subject rights, such as access, rectification, or deletion of personal data.
  • Limited recourse for data breaches, meaning individuals may find it difficult to seek legal remedies.
  • Potential government surveillance without adequate safeguards or oversight.
  • Inadequate technical and organizational measures by recipients to secure data.

We take reasonable steps to mitigate these risks, including using contractual safeguards (such as Standard Contractual Clauses), security measures, and ensuring that third parties processing data on our behalf adhere to high data protection standards.

6. SECURITY

Ha-Shem Limited takes reasonable measures to help protect all Personal Data about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. We implement policies designed to protect the confidentiality and security of your Personal Data, including firewalls, limited access to specified authorized individuals, encryption, and continuous capacity building for relevant personnel.

We implement appropriate technical and organizational measures required by Applicable Laws to protect Personal Data. These include data encryption in transit and at rest, role-based access control, multi-factor authentication, regular security testing, audit logging, masking of sensitive identifiers, employee training on data protection, and clearly defined data retention policies. Learn more on our Security & Trust page.

7. PERSONAL DATA RETENTION PERIOD

We retain Personal Data for no longer than necessary to use it, in accordance with our Retention Policy. Because identity verification is subject to anti-money-laundering record-keeping obligations, verification records and source documents may be retained for the period required by CBN and FATF-aligned regulations (typically at least five years after the end of the business relationship), after which they are archived, have personal data purged, and are ultimately deleted. Biometric captures are minimised and retained only as long as necessary. Audit logs are retained for security and compliance purposes. Where your Personal Data is no longer required, or you request deletion and we have no other lawful basis to retain it, we will securely dispose of it, subject to applicable law.

8. YOUR RIGHTS AS A DATA SUBJECT

At any point while we hold or are processing your Personal Data, you, the data subject, have the following rights, including the right to:

  • Withdraw your consent at any time to our processing of your data.
  • Request access to a copy of the information we hold about you in a commonly structured format.
  • Lodge a complaint with the Nigeria Data Protection Commission if you believe your rights have been violated (https://ndpc.gov.ng/).
  • Correct data that we hold about you that is inaccurate or incomplete.
  • Request that the data we hold about you be erased from our records.
  • Restrict our processing activities on your data.
  • Request that the data we hold about you be transferred to another organisation.
  • Object to certain types of processing, such as direct marketing.
  • Object to automated processing, including profiling.

You can exercise these rights at any time through our data-request page.

9. BREACH / PRIVACY VIOLATION

In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, Ha-Shem Limited shall, within 72 (Seventy-Two) hours of knowing about such breach, report the details of the breach to the Commission. Where we ascertain that such breach is detrimental to your rights and freedoms in relation to your Personal Data, we will, as soon as reasonably practicable, take steps to inform you of the breach incident, the risk to your rights and freedoms, and any course of action to remedy the breach.

10. CHANGES TO THIS POLICY

If we make changes to our Privacy Policy, we will post these changes here so that you are always aware of what information we collect, how we use it, and under what circumstances we disclose it. If at any point we decide to use your information in a manner different from that stated at the time it was collected, we will notify you by email.

11. ENFORCEMENT OF POLICY

If for some reason you believe Ha-Shem Limited has not adhered to these principles, please notify us by email at privacy@ha-shem.com, and we will do our best to determine and correct the problem promptly. Please ensure the words “Privacy Policy” are in the subject line.

12. FILING A COMPLAINT

In the event you are dissatisfied with how we process your data, we advise that you submit your complaint through our Data Protection Officer (DPO), whose details are provided below:

Name: Data Protection Officer (DPO)

Email: dpo@ha-shem.com

Phone: +234 9087393110

Address: 9 Ibikunle Street, Off University Road, Herbert Macaulay Way, Yaba, Lagos.

If you have reasons to believe that your Personal Data has not been handled correctly, or you are unhappy with our response to any requests you have made regarding the use of your Personal Data, you have the right to complain to the Commission.

Nigeria Data Protection Commission

Tel: +234 (0) 916 061 5551

Email: info@ndpc.gov.ng

Website: https://ndpc.gov.ng/

Where you remain dissatisfied, you reserve the right to explore other appropriate legal remedies as guaranteed under Nigerian law.

13. QUESTIONS OR CONCERNS

If you have any questions or concerns about this Privacy Policy or would like to contact us for any reason, you can contact us at dpo@ha-shem.com.