Privacy Policy
Effective Date: August 14, 2026 • Daybreak Afrika Technologies
1. Information We Collect
To deliver identity verification and utility vending services, we process the following categories of data:
- Account & Contact Data: Name, corporate email, phone number, organization name, and billing details provided during registration.
- Verification Query Data: National Identity Numbers (NIN), Virtual NINs (vNIN), Tax Identification Numbers (TIN), Corporate CAC RC/BN numbers, International Passport details, Driver's License IDs, and Voter VIN numbers submitted by clients.
- Technical Audit Telemetry: IP address, user-agent details, request timestamps, API endpoint activity logs, and authentication token metadata.
2. How We Use Your Information
Personal data processed on NiNCheck is strictly utilized for legitimate operational and compliance purposes:
- Validating individual and corporate identity records against official statutory databases (NIMC, CAC, FIRS, NIS, INEC, FRSC).
- Fulfilling Central Bank of Nigeria (CBN) and Anti-Money Laundering (AML) Know-Your-Customer (KYC) directives.
- Generating real-time verification status reports and audit logs for client record-keeping.
- Maintaining security, detecting fraudulent account lookups, and mitigating cyber threats.
3. Legal Basis for Data Processing
Under the NDPA 2023, NiNCheck processes personal data based on:
- Consent: Explicit authorization obtained from data subjects prior to initiating identity lookups.
- Contract Performance: Executing enterprise API integration agreements and account management services.
- Statutory & Regulatory Obligations: Compliance with financial sector KYC/AML laws and statutory identity verification frameworks.
4. Data Sharing & Government Identity Interfaces
NiNCheck acts as a data processor connecting client applications to authorized government registries:
- Verification queries are transmitted directly to official regulatory endpoints (NIMC, CAC, FIRS, NIS, INEC, FRSC) over encrypted connections.
- We do not sell, rent, or trade personal verification data or customer lists to third-party advertisers or data brokers.
- Information may be disclosed to law enforcement or regulatory authorities only when required by subpoena, court order, or statutory legislation.
5. Data Security & Technical Safeguards
We enforce strict technical and organizational security controls:
- Encryption Standards: Data in transit is secured with TLS 1.3 encryption. Sensitive database fields are protected with AES-256 encryption at rest.
- Zero-Storage Biometrics Policy: We do not store raw fingerprint, iris, or biometric template data on our servers.
- Access Controls: Multi-factor authentication, IP whitelisting, and strict Role-Based Access Control (RBAC) safeguard administrative backends.
6. Data Retention Policy
Verification query logs and transaction records are retained only for the duration necessary to satisfy statutory compliance, dispute resolution, and audit requirements under Nigerian banking laws. Upon expiration of mandatory retention periods, logs are securely purged or anonymized.
7. Data Subject Rights
Subject to statutory limitations under Nigerian law, data subjects possess the following rights regarding their personal data:
- Right to Access: Request confirmation of personal data processing and copy of records.
- Right to Rectification: Request correction of inaccurate profile information.
- Right to Erasure / Objections: Request deletion of data where processing is no longer required by law.
8. Data Protection Officer (DPO) Contact
For data protection inquiries, privacy complaints, or to exercise your statutory rights under NDPA, please contact our Data Protection Officer:
Data Protection Officer & Privacy Desk
Email: privacy@nincheck.com | dpo@daybreak.ng
Daybreak Afrika Technologies, Lagos, Nigeria