NDPR Compliant

Privacy Policy

How Vine e-ID collects, uses, stores, and protects your personal data.

Last updated: 18 June 2026 · Effective date: 18 June 2026

1. Introduction

Vine e-ID ("Vine", "we", "us", or "our") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our mobile application, website, APIs, and related services (collectively, the "Services").

We operate in accordance with the Nigeria Data Protection Regulation (NDPR) 2019, the Nigeria Data Protection Act 2023, and applicable international data protection frameworks including the EU General Data Protection Regulation (GDPR) where relevant to cross-border processing.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of our Services.

2. Data We Collect

We collect only the data necessary to provide secure digital identity services. The categories of personal data we may process include:

Identity Information

  • National Identity Number (NIN)
  • Bank Verification Number (BVN)
  • Government-issued ID details
  • Biometric data (fingerprint, facial recognition templates)

Account & Usage Data

  • Name, email address, and phone number
  • Device identifiers and IP address
  • App usage logs and verification history
  • Authentication and session metadata

Third-Party Verification Data

  • NIMC verification responses
  • Financial institution KYC results
  • Partner organisation verification requests
  • Credential issuance and revocation records

We do not collect more data than is necessary for the purpose for which it is processed. Sensitive personal data, including biometric information, receives enhanced protection and is processed only with your explicit consent or as required by law.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Creating, verifying, and managing your Vine e-ID digital identity
  • Performing identity verification against NIMC, BVN, and other authorised databases
  • Authenticating you when you access our Services or third-party integrations
  • Issuing, managing, and revoking verifiable digital credentials
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with legal and regulatory obligations under Nigerian law
  • Improving our Services through anonymised analytics and product development
  • Communicating with you about your account, updates, and support requests

We apply data minimisation and purpose limitation principles — your data is used only for the specific purposes described above and not for unrelated processing without your consent.

5. Data Sharing & Disclosure

We do not sell your personal data. We may share your information only in the following circumstances:

  • Identity verification partners: NIMC, financial institutions, and authorised verification providers necessary to validate your identity.
  • Service providers: Trusted processors who assist with hosting, analytics, customer support, and security — bound by data processing agreements.
  • Business integrations: Third-party services you explicitly authorise to receive your credentials via selective disclosure.
  • Legal requirements: When required by court order, regulatory authority, or applicable law.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate safeguards for your data.

All third-party processors are required to implement appropriate technical and organisational measures and process data only on our documented instructions.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements.

  • Active account data: retained for the duration of your account plus 7 years for regulatory compliance
  • Verification logs: retained for 5 years in accordance with CBN and NITDA guidance
  • Biometric templates: deleted upon account closure unless retention is legally required
  • Marketing preferences: retained until you withdraw consent

When data is no longer needed, we securely delete or anonymise it in accordance with our data retention and destruction policies.

7. Your Rights

As a data subject under the NDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your data where legally permitted.

Right to Restrict Processing

Limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is consent-based.

Right to Lodge a Complaint

File a complaint with NITDA or another supervisory authority.

To exercise any of these rights, contact our Data Protection Officer at privacy@vine-eid.ng. We will respond within 30 days as required by the NDPR.

8. Cookies & Tracking Technologies

Our website and application use cookies and similar technologies to provide essential functionality, remember your preferences, and analyse usage patterns.

  • Essential cookies: Required for authentication, security, and core site functionality. These cannot be disabled.
  • Analytics cookies: Help us understand how visitors interact with our Services. You may opt out via your browser settings or our cookie preferences.
  • Preference cookies: Remember your theme, language, and display settings.

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our Services.

9. International Data Transfers

Vine e-ID is incorporated in Nigeria and primarily processes data within Nigeria. Where we transfer personal data outside Nigeria — for example, to cloud infrastructure providers or international partners — we ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by NITDA or the European Commission
  • Adequacy decisions where the recipient country provides equivalent protection
  • Binding corporate rules for intra-group transfers
  • Your explicit consent where required

10. Children's Privacy

Our Services are not directed at children under the age of 18. We do not knowingly collect personal data from minors without verifiable parental or guardian consent. If you believe we have inadvertently collected data from a minor, please contact us at privacy@vine-eid.ng and we will take steps to delete such information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email or in-app notification.

The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of our Services after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Vine e-ID Limited

Lagos, Nigeria

Data Protection Officer: dpo@vine-eid.ng

Questions about your privacy?

Our Data Protection team is available to help with access requests, data deletion, and any privacy-related concerns.