About this document
This Policy explains Identro’s role as controller or processor, the Personal Data handled through our services, the lawful purposes for processing and the rights available to individuals.
1. Who we are and our data-protection roles
Identro is a digital trust, identity, business verification, AML, fraud, decision-support, wallet, digital-services, API and agent-services platform. The legal operator is Syrol Technologies Limited of Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria.
For Account, staff, merchant onboarding, billing, security, fraud prevention, legal compliance, audit, service integrity and dispute records, Identro generally acts as a Data Controller. When a Business Customer submits an individual’s data for a requested verification or workflow, the Business Customer generally acts as Controller and Identro acts as Processor for that submitted data.
Identro may act as an independent Controller for limited processing connected to the same request where necessary to protect the Platform, prevent fraud and abuse, maintain billing and audit records, comply with law, manage provider disputes or establish and defend legal claims. The applicable Data Processing Addendum governs Processor activities.
2. Who this Policy applies to
- Website visitors and prospective customers.
- Merchants, Integration Partners, Service Partners, agents, staff and authorised users.
- Individuals whose identity, business, address, biometric or financial identifiers are submitted for verification.
- End users of merchant-provided digital or wallet-enabled services.
- Directors, beneficial owners, representatives, vendors, applicants and support contacts.
3. Personal Data we collect
- Account and profile data: name, email, phone, credentials, role, security settings and status.
- Business and KYB data: company details, CAC and TIN information, licences, directors, beneficial owners, contact persons, addresses, bank and settlement details.
- Verification data: BVN, NIN, driver’s licence, voter-card data, address, facial image, liveness capture, consent reference, request metadata and verification result.
- AML, fraud and decision-support data: sanctions or watchlist indicators, risk signals, fraud markers, credit or eligibility inputs and outcome metadata.
- Wallet, payment and transaction data: balances, funding records, debits, reversals, commissions, settlement, provider references, receipts and reconciliation entries.
- Digital-service data: telephone, meter, smart-card, examination or beneficiary details required to fulfil a selected service.
- Technical and security data: IP address, device and browser data, API usage, allowlist configuration, webhooks, logs, session data and security events.
- Support, sales, complaint and communication records.
4. Sources of Personal Data
We receive Personal Data directly from individuals and organisations, from authorised merchants and agents, and from providers used to deliver a requested Service. These may include identity and business registries, financial institutions, payment processors, credit or risk partners, government agencies, telecommunications providers and fraud-prevention services.
Business Customers are responsible for ensuring that data submitted to Identro was collected lawfully and that required notices and consents were provided.
5. Purposes and lawful bases
We process Personal Data only where a lawful basis applies under the Nigeria Data Protection Act 2023 and other applicable law.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create and administer Accounts and merchant relationships | Account, business and contact data | Contract; legitimate interests |
| Provide verification, liveness, fraud, AML and decision-support Services | Identity, biometric, business and request data | Customer instructions; consent where required; contract; legal obligation |
| Process wallets, payments, commissions and settlements | Financial, transaction and provider data | Contract; legal obligation; legitimate interests |
| Secure the Platform and prevent abuse | Technical, security, identity and risk data | Legitimate interests; legal obligation |
| Support, complaints, audits and legal claims | Communications, account and transaction evidence | Contract; legal obligation; legitimate interests |
| Improve reliability using aggregated or de-identified data | Usage and performance data | Legitimate interests |
6. Consent and responsibility of Business Customers
Where consent is required for biometric, identity or other sensitive processing, the Business Customer must obtain and retain valid, specific and informed consent before submission. Identro may request evidence and may reject or suspend a request where a lawful basis is not reasonably demonstrated.
Consent may be withdrawn, but withdrawal does not affect prior lawful processing and may not require deletion of records that must be retained for legal, fraud, billing, security or dispute purposes.
7. Sensitive Personal Data and biometrics
BVN, NIN, facial images, biometric templates, liveness data and certain identity or financial identifiers receive enhanced protection. We apply access restrictions, encryption, masking or pseudonymisation where appropriate, monitoring and controlled retention.
Biometric data is used only for authorised verification, authentication, fraud prevention and security purposes. Identifiable verification images, biometric templates and API-submitted customer data are not used to train general-purpose AI models unless a separate lawful basis, appropriate notice and any required explicit consent are in place.
8. Automated processing, AI and decision-support
Identro may use automated systems, artificial intelligence and machine learning to perform and improve face matching, liveness detection, identity verification, fraud prevention, AML screening, risk assessment, credit or loan decision-support and Platform security.
Unless Identro is expressly contracted and legally authorised to make the final decision, the relevant merchant, lender or organisation remains responsible for final onboarding, credit, employment, compliance or transaction decisions. Where applicable law gives an individual rights concerning a solely automated significant decision, the individual may request human intervention, express a view and contest the decision through the relevant organisation or Identro.
9. Children and vulnerable persons
Identro Accounts are generally intended for adults and authorised organisations. A minor may nevertheless be the subject of a lawful merchant request or the beneficiary of a digital service. The submitting customer must verify age where appropriate, obtain parent or guardian consent where required, collect only necessary information and apply heightened safeguards. Identro may refuse processing where these requirements are not demonstrated.
10. API and SDK processing
Business Customers may submit Personal Data through APIs and SDKs for a specified request. Identro processes such data to deliver the requested Service and does not use identifiable submitted data for unrelated marketing or general product training. Customers must secure credentials, minimise payloads, provide end-user notices and comply with the Data Processing Addendum.
12. Sub-processors
Where Identro acts as Processor, it may engage vetted sub-processors under written obligations concerning confidentiality, security, lawful processing, breach assistance, deletion and data-subject rights. Enterprise customers may request the current sub-processor list. Material changes will be notified as required by the applicable agreement.
13. International transfers
Personal Data may be stored in or accessed from another country only where a transfer mechanism recognised by applicable law is in place. Depending on the circumstances, safeguards may include an adequacy determination, approved contractual clauses, binding corporate rules, a documented necessity ground or specific informed consent where legally appropriate. We assess transfer risk and apply contractual, technical and organisational controls.
14. Retention
We retain Personal Data only for the period necessary for the relevant purpose, legal obligations, fraud prevention, billing, security and dispute management. Retention may be extended where a legal hold, complaint, investigation or proceeding applies.
| Record category | Standard retention approach |
|---|---|
| Account and merchant records | Up to 7 years after closure or the end of the relationship. |
| Raw face or liveness captures | The shortest operational period reasonably required, normally not more than 90 days unless the service, dispute or law requires longer. |
| Biometric templates | Only while necessary for the contracted verification or authentication purpose, then securely deleted or irreversibly de-identified. |
| Verification results, consent references and request metadata | Up to 12 months, or longer where reasonably required for audit, billing, fraud investigation or dispute evidence. |
| Wallet, payment, settlement and accounting records | Up to 7 years or any longer period required by law. |
| Technical and security logs | Normally 12 months; longer for active security investigations or legal requirements. |
| Support and complaint records | Normally 3 years after final interaction or resolution. |
Deletion is applied across active systems and provider workflows where technically and contractually possible. Backup copies are isolated from normal use and expire through controlled backup-rotation schedules.
15. Data-subject rights
- Access and information about processing.
- Correction of inaccurate or incomplete data.
- Deletion where no lawful reason for retention remains.
- Restriction or objection where available.
- Data portability where legally and technically applicable.
- Withdrawal of consent.
- Human review of qualifying automated decisions.
- Complaint to the Nigeria Data Protection Commission or another competent authority.
Requests may be sent to info@identro.ng with “Attention: Data Protection Officer”. We may verify identity and, where Identro acts only as Processor, refer or coordinate the request with the relevant Business Customer. We aim to respond without undue delay and within the period required by law.
16. Security and breach response
We use risk-appropriate safeguards including encryption in transit, encryption at rest where appropriate, role-based access, least privilege, credential controls, IP restrictions, logging, monitoring, secure development, vulnerability management, backups, incident response and vendor due diligence.
Where Identro acts as Processor, it will notify the relevant Controller without undue delay after becoming aware of a Personal Data Breach. Where Identro acts as Controller, it will notify the NDPC within 72 hours where the breach is likely to result in a risk to individuals, and notify affected individuals without undue delay where the breach is likely to result in high risk, subject to applicable law.
18. Marketing
Marketing communications are sent only on a lawful basis and include a free opt-out. Transactional, security, service and legal notices are not marketing and may continue where necessary for the Account or Services.
19. DPIAs and privacy governance
Identro conducts Data Protection Impact Assessments for high-risk processing, including large-scale identity verification, biometrics, liveness, fraud scoring, loan decision-support and material new technologies. We maintain processing records, vendor reviews, retention controls, training and compliance assessments appropriate to our operations.
20. Changes and contact
Material changes to this Policy will be communicated through the Platform, email or another reasonable channel. The effective date above identifies the current version.
Privacy and rights requests: info@identro.ng (Attention: Data Protection Officer). Security incidents: security@identro.ng. General support: support@identro.ng or info@identro.ng. Postal address: Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria. Complaints may also be made directly to the Nigeria Data Protection Commission through its official channels.
Questions, complaints or rights requests
Contact Identro at support@identro.ng. Security incidents should be sent to security@identro.ng. Identro, Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria.