1. Information We Collect
- ShadowSpark collects the following categories of information to provide and improve our sovereign compliance platform:
- Biometric Data — Facial recognition data collected via rPPG (remote photoplethysmography) for liveness detection and anti-spoofing verification. This data is used exclusively for identity verification and is stored with AES-256 encryption.
- Business Data — Company registration details, director information, beneficial ownership structures, financial records, and compliance documentation required for regulatory reporting to SEC, CBN, and FIRS.
- Usage Data — Platform interaction data, including login timestamps, feature usage patterns, API call logs, and performance metrics. This data helps us optimize the platform and improve user experience.
- Communication Data — Records of communications via WhatsApp, email, and in-platform messaging for compliance auditing and support purposes.
2. How We Use Your Information
- We use the collected information for the following purposes:
- To provide, maintain, and improve the Platform's compliance verification and monitoring services.
- To perform biometric liveness detection and identity verification for secure onboarding and authentication.
- To generate regulatory compliance reports and filings as required by Nigerian financial regulators.
- To communicate with you regarding your account, service updates, security alerts, and support requests.
- To detect, prevent, and address fraud, security incidents, and unauthorized access to the Platform.
- To comply with legal obligations and enforce our Terms of Service.
3. Data Sharing and Disclosure
- ShadowSpark does not sell your personal data. We may share your information only in the following circumstances:
- With regulatory authorities (SEC, CBN, FIRS) as required for compliance reporting and audit purposes.
- With trusted service providers who process data on our behalf under strict data processing agreements (e.g., cloud infrastructure, payment processing).
- When required by law, court order, or legal process, or to protect the rights, property, or safety of ShadowSpark, our users, or others.
- In connection with a merger, acquisition, or sale of assets, with notice to users before any data transfer occurs.
4. Data Security
- We implement enterprise-grade security measures to protect your data:
- Encryption at Rest — All data stored using AES-256 encryption, ensuring your information remains secure even in the event of unauthorized database access.
- Encryption in Transit — All data transmitted between your systems and our Platform is protected using TLS 1.3 protocol, the latest industry standard for secure communications.
- Infrastructure Security — The Platform runs on Google Cloud Run within isolated VPCs, protected by Web Application Firewall (WAF) and intrusion detection systems.
- Access Controls — Strict role-based access control (RBAC) with multi-factor authentication (MFA) and comprehensive audit logging for all data access events.
5. Your Rights
- Under the Nigeria Data Protection Regulation (NDPR) and other applicable privacy laws, you have the following rights:
- Right of Access — You may request a copy of the personal data we hold about you.
- Right to Correction — You may request correction of inaccurate or incomplete personal data.
- Right to Deletion — You may request deletion of your personal data, subject to legal retention requirements.
- Right to Restriction — You may request restriction of processing your personal data under certain circumstances.
- Right to Data Portability — You may request a machine-readable copy of your data for transfer to another service provider.
- Right to Object — You may object to the processing of your personal data for specific purposes.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by applicable law. Biometric data is retained for the duration of your active account and securely deleted within 90 days of account closure, unless retention is required for regulatory compliance or legal proceedings. Business records and compliance documentation are retained in accordance with SEC, CBN, and FIRS record-keeping requirements.
7. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer at privacy@shadowspark.tech or via our WhatsApp Business line. We aim to respond to all privacy inquiries within 5 business days.