Wise Hustlers — Digital Product & App Development Studio Logo
Get Consultation
🇳🇬 Data Protection & Trust Centre · Nigeria

Your Data is Protected

This page sets out how our intelligent monitoring system handles personal and biometric data in Nigeria: what is processed, where it lives, who can see it, how long it survives, and which parts of that are enforced by the architecture rather than by a promise.

It also states plainly which certifications we hold and which we do not. That second part is unusual on a vendor page, and it is deliberate.

See our certification statusPrivate sector offer →

Our rule on compliance badges

We display a certification, registration or approval badge only where the certificate has actually been issued and is in force. Everything else on this page is labelled with what it really is — a contractual commitment, a configurable option, something under review, or simply targeted and not yet true.

This costs us something on a first read, because a page of green ticks is more persuasive at a glance. It is worth it, because a buyer who discovers during due diligence that a badge was aspirational stops believing everything else on the page — and in this market that discovery usually happens in front of a board.

Certificate heldIssued, in force, and viewable on this site.
Contractual commitmentWritten into the service agreement — not a third-party certificate.
Configurable optionAvailable in the deployment; enabled or disabled per your architecture.
Under reviewFormal process started; outcome not yet issued.
TargetedOn the roadmap. Not yet obtained. Do not rely on it today.
Subject to approvalDepends on a third-party approval we do not yet hold.
Certification & capability status

Every claim, with its real status attached

Read the right-hand column before the left. Two of these rows are certificates we hold and can show you. Two are things we do not have and are not pretending to have.

ISO/IEC 27001:2022 — organisational ISMS

Wise Hustlers Technologies Private Limited is certified for its information security management system, covering information security management for web, mobile and custom software development, AI solutions, cloud services and IT consulting. Certified by QRO Certification LLP, certificate registry ID 3050260810139IS, in force from 10 August 2026 to 9 August 2029. This certifies how we run our organisation — it is not a certification of any camera or hardware product, and we do not present it as one.

View the certificate →
Certificate held

ISO 9001:2015 — quality management system

Certified quality management system covering the design, development, deployment and maintenance of our software solutions. Certificate registry ID 3050260810138Q, in force from 10 August 2026 to 9 August 2029. Again an organisational certificate, not a product approval.

View the certificate →
Certificate held

Product-level security certification for the monitoring hardware

No product-specific security certification is claimed for the camera or edge device. If you require one for a tender, tell us which scheme and we will tell you honestly whether we can meet it and by when.

Targeted

NDPC registration for your deployment

Two registrations are in play and they are separate. Yours: an organisation processing the personal data of more than 200 data subjects in six months, or operating in a listed sector such as education, health or hospitality, registers as a data controller of major importance. Ours: a vendor commercially processing sensitive personal data at that scale is registrable in its own right, and we do not pretend your filing covers us. We prepare the technical and architectural material your filing needs and support you through it — but we have not registered, been approved by, or been endorsed by the Nigeria Data Protection Commission on your behalf, and we will not imply we have.

Subject to approval

ISO/IEC 27701 — privacy information management

An extension to ISO 27001 covering privacy information management specifically. On our roadmap. Not held today, and nothing on this site should be read as claiming it.

Targeted

Analysis performed on the camera, not in the cloud

Detection and analysis run on the device. In the default configuration the frame is discarded from memory once the event is produced and no image is transmitted off the camera.

Contractual commitment

Encryption in transit and at rest

Links between camera, site gateway and management plane are encrypted, and stored events and any retained footage are encrypted on disk. The specific cipher suites for your deployment are stated in the technical documentation issued with your quotation.

Contractual commitment

Nigeria-hosted or fully on-premises deployment

The same system runs on your own premises, in a Nigeria-hosted tenancy, or in a cloud region you name. The choice is yours and it is written into the service agreement rather than defaulted by us.

Configurable option

No cross-border transfer of recorded material by default

In an on-premises or Nigeria-hosted deployment, recorded material does not leave Nigeria. Where a client chooses a foreign cloud region, the resulting transfer is documented and governed contractually rather than happening silently.

Configurable option

Configurable retention with automatic deletion

Retention is set per camera and enforced by a scheduled deletion job. Nothing survives past its schedule because someone forgot to clear it.

Contractual commitment

Comprehensive audit trail

Every view, search and export writes an append-only audit entry naming the user, the time and the stated reason. The audit log is access-controlled separately from the footage itself.

Contractual commitment

Role-based access and named administrator accounts

Access is granted by role and scoped per site and per camera. Individually named logins; shared accounts are not supported by design, because a shared account destroys the value of the audit trail.

Contractual commitment

Your data is never sold or shared for our own purposes

We process client monitoring data solely to deliver the service, on the client's documented instructions. We do not sell it, do not share it with third parties for their purposes, and do not use it to train models for other clients. This is a contractual undertaking in the service agreement, not just a statement on a web page.

Contractual commitment
Security architecture

Three trust boundaries, and what crosses each one

The question a regulator asks is not which brand of camera you bought. It is: what happens on the device, what stays on the site, and what leaves it. This is that answer, drawn.

System architecture across three trust boundariesAnalysis runs on the camera at the edge. Recorded video and biometric templates stay inside the site boundary. Only the streams a client explicitly enables cross into the management plane, and the management plane can itself be hosted on the client premises, in Nigeria, or in the cloud.ZONE 1 — CAMERA EDGEPhysically on the deviceCamera + edge processorCaptures frames. Runs detection andanalysis on-device, in memory.No frame is written to disk here.On-device inferenceProduces an event: what happened,when, on which camera — plus anumeric template where matching is on.Discarded at the edgeThe raw frame is dropped from memoryonce the event is produced, unlessrecording is explicitly enabled forthat camera by your administrator.ZONE 2 — YOUR SITEYour premises, your networkSite gateway / recorderReceives events. Holds recorded videoand templates if you enable them.Encrypted at rest on local storage.Local watchlist matchingWhere enabled, matching happensagainst a list you control, heldon site — not in a shared database.Retention engineApplies your retention schedule anddeletes on expiry automatically.Deletion is a scheduled job, not amanual clean-up someone remembers.ZONE 3 — MANAGEMENT PLANEYou choose where this runsAdministration consoleUsers, roles, camera configuration,retention policy, watchlist admin.Every session individually named.Audit logWho viewed or exported what, when,and the reason given. Append-onlyand separately access-controlled.Hosting is your decision● On your premises● Nigeria-hosted tenancy● Cloud region of your choosingWritten into the contract, not defaulted.Events +templatesEncryptedin transitMetadataonlyEncryptedin transitPolicy + configpushed downVideo leaves the site only if you switch it on.In the default configuration, recorded footage stays inside Zone 2. Streaming it to Zone 3 is an explicitper-camera choice made by your administrator, and it is recorded in the audit log when it changes.
Reference architecture. The exact component layout for your site is produced during the survey and issued to you as part of the deployment pack.
Biometric data flow

What happens to a single frame, from capture to deletion

The most common question we are asked in Nigeria is whether facial images are stored. Rather than answer it in a sentence, here is the whole lifecycle — including the stage where the image ceases to exist.

Lifecycle of a frame, from capture to automatic deletionFive stages. A frame is captured into camera memory, analysed on the device, and then discarded — no image is transmitted. What is stored is an event record and, only where matching is enabled, a numeric template. A retention clock deletes the record automatically. Every read of a stored record writes an audit entry.LIFECYCLE OF A SINGLE FRAME01CaptureWHAT EXISTSA single video frame,held in the camera'sworking memory.WHERE IT LIVESCamera RAM.Not written to any disk.IDENTIFIES A PERSON?Yes — it is an image ofa person02On-device analysisWHAT EXISTSA detection result, and— only where matching isenabled — a numerictemplate derived from it.WHERE IT LIVESCamera RAM.Never transmitted as animage.IDENTIFIES A PERSON?Template only, and onlyagainst your own list03Frame discardedWHAT EXISTSNothing of the originalimage remains, unlessrecording is switched onfor that camera.WHERE IT LIVESOverwritten in cameramemory.IDENTIFIES A PERSON?No04Event storedWHAT EXISTSCamera ID, timestamp,event type, and thetemplate reference wherematching is in use.WHERE IT LIVESSite storage, encryptedat rest — or the hostyou selected.IDENTIFIES A PERSON?Only by resolving itagainst your watchlist05Automatic deletionWHAT EXISTSNothing.The retention clock hasexpired and the recordis gone.WHERE IT LIVESDeleted. A deletion entryremains in the audit log.IDENTIFIES A PERSON?NoACROSS EVERY STAGE WHERE A RECORD EXISTSEach viewing, search and export writes an audit entry naming the user, the time and the stated reason.The audit log is append-only and is access-controlled separately from the footage itself.THE SHORT ANSWERIn the default configuration no facial image is transmitted off the camera and none is retained.Where a client switches recording on, the footage is held under that client’s own retention schedule and deleted on expiry.
The configuration applied to your deployment is recorded in your Data Protection Impact Assessment, which is issued to you before go-live rather than described only on a web page.

Data minimisation, applied concretely

Minimisation is usually written as a principle and then ignored at configuration time. We apply it as a default: if a purpose can be met by counting people, we configure counting and leave identity matching switched off entirely.

Traffic analytics, footfall measurement and queue monitoring almost never need to know who anyone is. We will say so during scoping even when the larger configuration would be the larger sale.

How a biometric template differs from a photograph

Where identity matching is enabled, what is retained is a numeric template derived from the image, not the image. A template is generated for the purpose of comparison against a list you control and is held on your site.

We will not tell you a template is “anonymous”, because it is not: it exists precisely to identify someone, and it should be treated as sensitive personal data with everything that implies. Vendors who describe templates as anonymous are describing a legal position that does not hold.

Regulatory framework

The rules this deployment has to answer to

Nigerian clients are governed by Nigerian data protection law; clients with European operations or European counterparties are also answerable to the GDPR. The points below are the ones that actually change how a monitoring system should be configured — and each quotes the primary text and links to it, rather than asking you to take our summary on trust.

Two of them are worth reading before you talk to any vendor, including us: the distinction between ordinary CCTV and face matching, and the fact that no certificate anyone holds is a compliance defence.

Which rules actually apply, as of today

Nigeria

The governing statute is the Nigeria Data Protection Act 2023, assented to on 12 June 2023. The instrument that governs day-to-day compliance, though, is the NDPC's General Application and Implementation Directive (GAID) 2025, issued on 20 March 2025 — 52 articles and 10 schedules of operational detail that the Act itself does not contain.

One point of confusion worth clearing up: the Act did not repeal the older NDPR 2019. The NDPR was displaced on 20 March 2025, when GAID Article 3(3) directed that the Commission would cease to apply it. If a vendor is still citing the NDPR at you as the current framework, their compliance material is out of date.

Source: NDPC, GAID 2025, Articles 3(2) and 3(3)

Nigerian law names facial images as biometric data, explicitly

Nigeria

There is no ambiguity to exploit here. Section 65 of the Act defines sensitive personal data to include “genetic and biometric data, for the purpose of uniquely identifying a natural person”, and separately defines biometric data as data from specific technical processing that allows unique identification, “including without limitation by physical measurements, facial images, blood typing, fingerprinting, retinal scanning, voice recognition and deoxyribonucleic acid (DNA) analysis”.

This was a real change. The predecessor NDPR 2019 did not list biometric data as sensitive at all. Any compliance position built on the older regulation understates what a face-matching deployment now requires.

Source: NDPA 2023, section 65

The regulator directs consent for sensitive personal data

Nigeria

GAID Article 18(1) states that “consent is required … (b) For the processing of sensitive personal data”. Article 17(5) then adds that reliance on any lawful basis other than consent, where unsupported, “shall be strictly scrutinised during NDP Act compliance audits and in any proceeding where the conduct of a data controller or processor is called into question”.

We are deliberately precise about this. Section 30(1) of the Act does list nine alternative grounds for processing sensitive data, and where the Act and the directive conflict the Act prevails. So it would be wrong to tell you consent is the only lawful route. What is accurate — and what you should plan around — is that the regulator directs consent, and anything else will be examined hard in an audit.

Notably, the European position converges on the same answer: the EDPB concludes that private-sector video surveillance with biometric recognition will in most cases require explicit consent. A deployment built on genuine consent plus a filed impact assessment is defensible under both regimes at once.

Source: NDPC, GAID 2025, Articles 18(1)(b) and 17(5)

For public-facing cameras a DPIA is mandatory, not advisable

Nigeria

GAID Article 28(3) makes a Data Protection Impact Assessment mandatory, and filable with the Commission, for a list of processing types that a monitoring deployment hits repeatedly: systematic monitoring; processing involving sensitive data; “deployment of surveillance cameras in places that may be accessed by members of the public”; educational services involving pupil records; and hospitality services.

Two operational consequences most vendors do not mention. Article 28(4) requires the assessment to be vetted by a certified DPO accredited by the Commission — our draft is an input to that, not a substitute for it. And Article 28(6) provides that failing to carry one out may result in a restriction on the platforms through which you contact data subjects at all.

Source: NDPC, GAID 2025, Article 28(3)–(6)

You may have to register — and so may we, separately

Nigeria

The Commission registers “data controllers and data processors of major importance”. Under its registration guidance, an organisation is designated as of major importance if it processes the personal data of more than 200 data subjects in six months, or operates in a listed sector — which includes education, health, hospitality, financial services and public service.

The part vendors tend to leave out is that the obligation reaches us too. The same guidance designates processors who commercially process sensitive personal data for more than 200 data subjects. A biometrics vendor meets that. Our registration does not discharge yours and yours does not discharge ours — and you are entitled to ask us for evidence of ours before you sign. The GAID tells you to.

Source: NDPC Guidance Notice on registration of DCPMIs (GAID Schedule 7)

Churches: exempt from registration, not from the Act

Nigeria

The registration guidance exempts faith-based organisations, community-based associations, foreign missions, judicial bodies and multigovernmental organisations from the requirement to register with the Commission.

That exemption is narrow and it is easy to over-read. It removes a filing obligation. It removes nothing else: lawful basis, consent, security measures, breach notification, impact assessments and data subject rights all continue to apply in full to a church running cameras. Schools and hotels get no exemption at all — both are named sectors.

We spell this out because a vendor implying that a church sits outside Nigerian data protection law would be doing that buyer real harm.

Source: NDPC Guidance Notice on registration, exemptions from registration

There is no general legal requirement to host in Nigeria

Nigeria

We offer Nigeria-hosted and on-premises deployment, and many clients should take it. But we will not sell it to you on a false premise. Neither the NDPA 2023 nor the GAID 2025 contains a data-localisation requirement. Part VIII of the Act regulates the conditions under which data may be transferred, not where it must be stored.

NITDA's National Cloud Policy 2025 is mandatory for federal public institutions and federally-owned companies, and reaches a private company only where its data is designated as being of strategic national interest. The CBN's payments localisation rule binds licensed payment ecosystem participants. Neither reaches a church, a school or a hotel.

So the honest case for in-country hosting is sovereignty, latency, and a contractual assurance you can show your board — not a legal obligation. If a competitor tells you Nigerian law requires it, that is a sales tactic, and you can check it against the sources on this page.

Source: NITDA National Cloud Policy 2025, scope and data classification

72 hours to the Commission, immediately to the people affected

Nigeria

Section 40(2) requires a controller to notify the Commission within 72 hours of becoming aware of a breach likely to result in a risk to people's rights and freedoms. Section 40(3) requires that where the risk is high, the controller communicates it to the affected individuals immediately, in plain and clear language, with advice on mitigation.

A processor's duty under section 40(1) is different and worth stating precisely: it is to notify the controller on becoming aware. The 72-hour clock is the controller's, which is why our contact points and escalation path are agreed in the service agreement before go-live. Section 40(8) also requires both parties to keep a record of every breach and its remedial action.

Source: NDPA 2023, section 40

What getting this wrong actually costs

Nigeria

For a controller or processor of major importance, the maximum penalty is the greater of ₦10,000,000 or 2% of annual gross revenue in the preceding financial year. For everyone else it is the greater of ₦2,000,000 or 2% of that revenue. Note the structure: the naira figures are floors, not caps, because the provision reads “the greater of”.

There is also criminal exposure, though not where people usually assume. Section 49 attaches it to failing to comply with a compliance order made by the Commission — up to one year's imprisonment, a fine, or both — rather than to the underlying breach. Section 53 makes principal officers personally culpable unless they can show diligence, and makes organisations vicariously liable for their staff and agents.

For completeness: the Commission's published enforcement posture describes itself as restorative rather than punitive, and it can order remedial fees in lieu of strict penalties.

Source: NDPA 2023, sections 48, 49 and 53

A six-month backstop on keeping anything

Nigeria

GAID Article 49(3) provides that where no timebound obligation applies, storage lapses not later than six calendar months after the original purpose has been accomplished — subject to retention needed for legal claims or due diligence.

Our default retention schedule of 30 days for event records and footage sits well inside that. We mention the backstop because it is the ceiling a regulator will measure your configuration against if you ask us to extend a period, and because “we keep it indefinitely in case we need it” is not a position that survives contact with it.

Source: NDPC, GAID 2025, Article 49(3)

The obligations Nigerian law puts on us, as the software vendor

Nigeria

GAID Article 31 imposes duties directly on whoever deploys data-processing software: carry out an impact assessment before deployment; build to privacy by design and by default; provide a privacy policy inside the software; and provide a pre-installation privacy statement naming the data types, the lawful purpose, and the specific technical measures — the article says encryption should be specifically indicated.

Article 34 then prescribes the twenty terms a Data Processing Agreement must contain, including the location of processing, the technical and organisational measures, the impact assessment outcome, evidence of our registration with the Commission, indemnity and insurance.

We list these because they are the concrete, checkable things a buyer should be asking any vendor for. They are a better test of whether a supplier has done the work than any certificate, including ours.

Source: NDPC, GAID 2025, Articles 31 and 34

Ordinary CCTV is not biometric data. Face matching is.

GDPR · EDPB

This distinction matters under both regimes, and it is routinely got wrong in both directions. Footage of a person is not automatically special-category biometric data. It becomes biometric data once it is put through a specific technical process intended to identify someone uniquely — the same qualifier the Nigerian definition uses.

The European Data Protection Board puts it plainly: video footage of an individual “cannot however in itself be considered as biometric data under Article 9, if it has not been specifically technically processed in order to contribute to the identification of an individual”. GDPR Recital 51 says the same of photographs.

Practically, the decision to switch face matching on is the decision to move your deployment into the heightened-obligation category. It is a configuration choice with a legal consequence, which is why we treat it as a scoping decision rather than a default.

Source: EDPB Guidelines 3/2019 on video devices, paras 74–76

With face matching on, you need two legal grounds, not one

GDPR · EDPB

A common and expensive mistake is to identify a single lawful basis and stop. Where a video system processes special categories of data, the controller must identify both an exception under Article 9 and, separately, a legal basis under Article 6. The two are cumulative.

We raise this at scoping because the answer sometimes is that no workable pair exists for the purpose being described — and the right response then is to configure the system without identity matching, not to proceed and hope.

Source: EDPB Guidelines 3/2019 on video devices, para 68

For a private facility, that usually means explicit consent

GDPR · EDPB

The EDPB addresses this exact scenario — a private organisation running biometric recognition on its own premises for its own purposes — and concludes that it “will, in most cases, require explicit consent from all data subjects (Article 9(2)(a)), however another suitable exception in Article 9 could also be applicable”. It names security explicitly as one of the private purposes this covers.

The word doing the work is “all”. The EDPB's own worked examples require the deployment to be designed so that people who have not consented are not captured at all — a physically separated lane or gate, not merely a promise to delete. That is a design requirement, and it is why the enrolment question belongs in the site survey rather than in the terms and conditions.

Source: EDPB Guidelines 3/2019 on video devices, paras 77–80

Walking past a camera does not make someone's data public

GDPR · EDPB

Some vendors reach for the argument that a person in a public or semi-public space has made their data “manifestly public” and so no further basis is needed. The EDPB closes that route explicitly: “The mere fact of entering into the range of the camera does not imply that the data subject intends to make public special categories of data relating to him or her.”

If you are shown a compliance argument built on this, it does not hold.

Source: EDPB Guidelines 3/2019 on video devices, para 70

You are expected to have considered a less intrusive option first

GDPR · EDPB

The EDPB states that facial recognition entails heightened risks and that controllers “should first of all assess the impact on fundamental rights and freedoms and consider less intrusive means”.

This is the obligation behind a habit we apply as standard: where a purpose can be met by anonymous counting, we configure counting and leave identity matching off. Being able to show that you considered and chose the lesser option is part of what makes the deployment defensible — and it is a record you can only create before installation, not after.

Source: EDPB Guidelines 3/2019 on video devices, para 73

No certificate — ours or anyone's — is a compliance defence

GDPR

Article 42(4) of the GDPR is unusually direct: a certification “does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities”.

We hold ISO certificates and we are glad to show them. They are evidence that we run our organisation to an audited standard. They are not a shield, they do not transfer your accountability to us, and any vendor implying otherwise is selling you a false sense of security.

Source: GDPR, Article 42(4) (Regulation (EU) 2016/679)

Why an ISO 27001 certificate structurally cannot certify a camera

ISO

This is not a matter of interpretation, it is a matter of which accreditation scheme issued the certificate. Management-system certification — which is what ISO/IEC 27001 is — is governed by ISO/IEC 17021-1:2015, “Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements”, together with ISO/IEC 27006-1:2024 for information security specifically.

Product certification is a different accreditation scope entirely, governed by ISO/IEC 17065. A body accredited to certify a management system is not thereby accredited to certify a product, and a certificate issued under the one scheme says nothing about the other.

So when we say our ISO/IEC 27001:2022 certificate covers our organisation and not the monitoring hardware, that is not modesty. It is the only thing the certificate is capable of meaning. ISO itself issues no certificates at all — accredited certification bodies do, which is why we name ours and give you the registry ID.

If you are a public authority, two common routes are closed to you

GDPR

Where the GDPR applies, a public authority acting in the performance of its tasks cannot rely on legitimate interests: Article 6(1) provides that point (f) “shall not apply to processing carried out by public authorities in the performance of their tasks”.

Article 49(3) closes a second route, disapplying the consent, contract and third-party-contract transfer derogations for “activities carried out by public authorities in the exercise of their public powers”. In practice that pushes a public-sector transfer onto Article 46 safeguards — standard contractual clauses under Article 46(2)(c) or (d), or binding corporate rules.

We flag this because a ministry, agency or state government evaluating this technology will be given advice built for private buyers unless someone points out the difference.

Source: GDPR, Articles 6(1) and 49(3) (Regulation (EU) 2016/679)

Controller & processor responsibilities

Which obligations are yours, and which are ours

This is the distinction that decides who is accountable when something goes wrong, and it is the one most vendor pages leave vague. In a typical deployment your organisation is the controller and we are the processor. Below is what that actually means in practice, obligation by obligation.

ObligationYou, as data controllerUs, as data processor
Deciding why the system existsYours entirely. You decide the purpose, what the cameras point at, and which features are switched on. We advise, and we will tell you when a purpose does not need identity matching — but the decision is yours.We act only on your documented instructions. We do not repurpose your data or enable a feature you have not asked for.
Establishing a lawful basisYours. You must be able to state the basis on which you process, and a separate one for any biometric processing. The NDPC's directive expects that to be consent where sensitive personal data is involved.We provide the technical facts you need to assess it — what is processed, how, and what the alternatives are.
Notifying people who are monitoredYours. Your privacy notice and your entrance signage, issued in your name.We supply the notice and signage template pack drafted for your configuration, in every package.
Data Protection Impact AssessmentYours to adopt and own, because it is your processing being assessed. For cameras in places the public can reach, Nigerian law makes it mandatory rather than advisable, and it is filed with the Commission.We prepare it for your deployment scope and issue it before go-live. It must then be vetted by a DPO accredited by the Commission — we will tell you that rather than let you assume our draft is the finished article.
Registration with the NDPCYours, where you meet the threshold — broadly, processing the personal data of more than 200 data subjects in six months, or operating in a listed sector such as education, health or hospitality.Ours, separately and in our own right. A vendor commercially processing sensitive personal data for more than 200 data subjects is itself registrable. Neither registration discharges the other, and we will show you ours.
Responding to a data subject requestYours. The request comes to you, and you decide whether it must be honoured.We execute what you instruct — retrieval, redaction of third parties, or erasure — and confirm in writing what was done.
Setting the retention periodYours, per camera, and recorded in the service agreement.We enforce it technically through a scheduled deletion job, and audit-log every change to it.
Securing the dataYours for your own premises, your staff and your account discipline — including not sharing logins.Ours for the system: encryption in transit and at rest, role-based access, named accounts, and the audit trail.
Breach notificationYours to make to the Commission within 72 hours where the breach is likely to risk people's rights, and immediately to the affected individuals where the risk is high.Ours to notify you as soon as we become aware, with what you need to assess it. Contact points and timescales are agreed in the service agreement before go-live, not improvised during an incident.
Choosing where the data is hostedYours. On your premises, in Nigeria, or in a named cloud region.We implement your choice and write it into the contract, rather than defaulting it at installation.
Deletion at the end of the engagementYours to instruct, and to verify the export before anything is destroyed.We export in the agreed format, delete, and issue you a written deletion confirmation.

Why we will not say we are “NDPC certified”

Because there is no such thing to be, in the sense a vendor badge would imply. What exists is registration, and it cuts both ways: you register as a controller if you meet the threshold, and we are registrable as a processor in our own right. Neither filing discharges the other. We prepare the technical and architectural material your filing needs and we support you through it — but a vendor claiming to have discharged your regulatory obligations for you is describing something that did not happen.

What we give you for your own compliance file

  • A Data Protection Impact Assessment for your deployment scope
  • The data-flow record showing exactly what is processed and where it goes
  • The system architecture pack, for your own regulator filings
  • Your retention schedule as configured, per camera
  • The privacy notice and entrance signage pack for your site
  • A written description of the technical and organisational security measures in place
Technical & organisational controls

The controls that hold this together

Encryption in transit

Every link between camera, site gateway and management plane is encrypted. Nothing about this deployment sends monitoring data across a network in the clear.

Encryption at rest

Stored events and any retained footage are encrypted on disk. In an on-premises deployment your organisation holds the keys, which means we cannot read your footage even if we wanted to.

Role-based access control

Access is granted by role and scoped per site and per camera. A guard at one branch does not get a window into another branch because the permission model was built as one flat list.

Named administrator accounts

Individual logins with multi-factor authentication available. Shared accounts are not supported by design — a shared login destroys the audit trail's value entirely.

Append-only audit trail

Every view, search and export records the user, the time and the reason given. The log is access-controlled separately from the footage, so someone who can watch cannot quietly edit the record of having watched.

Automatic retention enforcement

A scheduled job deletes expired records. Retention is set per camera, changes are audit-logged, and nothing survives its schedule through inattention.

Specific cipher suites, protocol versions and supported authentication factors are stated in the technical documentation issued with your quotation. We have deliberately not published a set of figures here that might not match the configuration you are actually sold — see the technical datasheet for what is confirmed today and what is still open.

Hosting, localisation & cross-border transfer

You decide where your data lives — and it goes in the contract

Three options, one decision, made by you at scoping rather than defaulted by us at installation.

On your premises

Processing and storage run entirely on hardware inside your facility. No recorded material leaves the building. Your team holds the encryption keys and the administrator root accounts.

TYPICALLY CHOSEN BY

Hospitals, no-egress policies, and any buyer who needs the answer to be physical rather than contractual.

Nigeria-hosted tenancy

Data resides in a hosting facility located in Nigeria. You get central administration across sites without recorded material crossing a border.

TYPICALLY CHOSEN BY

Multi-site operators who want in-country residency without running their own infrastructure.

Cloud region of your choosing

Hosted in a named region agreed with you. Any resulting cross-border transfer is documented and governed contractually rather than discovered later.

TYPICALLY CHOSEN BY

International groups already operating to a global hosting standard.

Retention & deletion

Data that deletes itself, on a clock you set

Retention is configured per camera and enforced by a scheduled job. The default is 30 days for event records and for recorded video where a client has enabled it; templates are deleted when the individual is removed from your list; audit entries outlive the data they describe.

Read the full retention & deletion policy →
Frequently asked questions

The questions Nigerian buyers actually ask first

Where is my data stored?

For Nigerian clients the solution can be configured for secure in-country hosting or for on-premises deployment on your own hardware, subject to the agreed system architecture and your requirements.

Whichever you choose is recorded in the service agreement rather than left as a vendor default, so the answer to this question is a contractual fact you can show someone, not an assurance you have to take on trust.

Is my biometric data transferred or sold to third parties?

No. The system is designed to prevent unauthorised sharing or sale of personal data, and we undertake contractually not to sell client data, not to share it with third parties for their own purposes, and not to use it to train models for other clients.

Any processing or transfer that does occur is subject to the applicable contractual, privacy and regulatory requirements, and is documented in your deployment's data-flow record.

Can the system be deployed in churches, schools, hotels, hospitals and other private facilities?

Yes, and these are the settings the early-adopter programme is aimed at. Deployment is subject to the applicable privacy, consent, notification, security and sector-specific requirements for that setting.

One point specific to churches, because it is easy to get wrong in both directions: the NDPC exempts faith-based organisations from the requirement to register as a controller of major importance. That exemption is from registration only. Lawful basis, consent, security, breach notification, impact assessments and data subject rights all still apply in full. Schools and hotels get no exemption at all — education and hospitality are both listed sectors.

Appropriate privacy notices and consent mechanisms must be provided where required — which is why a privacy notice and entrance signage pack is included in every package rather than sold as an extra. Some settings carry heightened obligations: schools involve children, hospitals involve health context, and workplaces engage employment law as well as data protection.

Can customers keep their data within Nigeria?

Yes. A Nigeria-hosted or fully on-premises deployment option can be offered, subject to the agreed technical configuration.

In the on-premises configuration your organisation holds the encryption keys and the administrator root accounts, and recorded material does not leave your building.

Are raw facial images stored?

In the default configuration, no. Analysis runs on the camera; the frame is released from memory once the event has been produced, and no image is transmitted off the device.

Some settings legitimately require continuous recording, and a client administrator can enable it per camera. Where that happens the footage is held under your own retention schedule, encrypted at rest, access-logged, and deleted automatically on expiry. Which configuration applies to your deployment is stated in your Data Protection Impact Assessment, issued before go-live.

Who is the data controller — you or us?

In a typical deployment your organisation is the data controller and we are the data processor. You decide why the cameras exist, what they are pointed at and how long material is kept; we operate the system on your documented instructions.

That distinction matters practically: registration and notification duties, and responses to data subject requests, sit with you as controller. We provide the technical material and the support to discharge them, but we cannot and do not discharge them on your behalf.

What happens if there is a data breach?

As processor, our obligation is to notify you as controller without undue delay once we become aware, with the information you need to assess it — what happened, which data categories and roughly how many individuals are affected, and what we are doing about it.

The notification to the regulator and, where required, to affected individuals is the controller's to make. The breach-notification procedure, including contact points and timescales, is agreed in writing in the service agreement before go-live rather than improvised during an incident.

Can we get our data out if we leave?

Yes. Export formats and the deletion procedure at termination are agreed at the start of the engagement and written into the contract, not negotiated at the point you want to leave.

At termination we export in the agreed format, you verify the export is complete and readable, and only then is the data deleted — with a written deletion confirmation issued to you.

Do we have to register with the NDPC, and do you?

Probably both, and separately. Under the Commission's registration guidance an organisation is a controller of major importance if it processes the personal data of more than 200 data subjects in six months, or operates in a listed sector — education, health, hospitality, financial services and public service are all listed. Registration tiers carry different fees and different annual return obligations.

The part vendors tend to leave out is that the same guidance reaches processors: a supplier commercially processing sensitive personal data at that scale is registrable in its own right. Our registration does not discharge yours and yours does not discharge ours. You are entitled to ask us for evidence of ours before signing, and the NDPC's directive on data processing agreements tells buyers to do exactly that.

Do we need a Data Protection Impact Assessment, or is that optional?

For cameras in a place members of the public can reach, it is mandatory rather than advisable. The NDPC's directive lists systematic monitoring, processing involving sensitive personal data, public-facing surveillance cameras, educational services involving pupil records, and hospitality services among the processing types that require one. Most deployments in this programme hit at least two.

Two consequences worth knowing. The assessment has to be vetted by a DPO accredited by the Commission — the version we prepare for your deployment is an input to that, not a substitute for it, and we will say so rather than let you assume otherwise. And failing to carry one out can result in a restriction on the platforms through which you contact people at all.

Do you hold a government approval or licence for this?

No, and we will not imply otherwise. Public-sector engagements remain subject to the relevant government reviews and approvals, which have not concluded.

This private-sector programme does not depend on those approvals. If a specific approval becomes relevant to your deployment we will tell you its actual status rather than describing an application as an authorisation.

Still have a question this page did not answer?

Ask it. If the honest answer is “we do not have that yet”, that is the answer you will get — which is more useful to you than a confident one that falls apart during due diligence.

Request a demonstrationSend an enquiry