Your Data is Protected
This page sets out how our intelligent monitoring system handles personal and biometric data in Nigeria: what is processed, where it lives, who can see it, how long it survives, and which parts of that are enforced by the architecture rather than by a promise.
It also states plainly which certifications we hold and which we do not. That second part is unusual on a vendor page, and it is deliberate.
Our rule on compliance badges
We display a certification, registration or approval badge only where the certificate has actually been issued and is in force. Everything else on this page is labelled with what it really is — a contractual commitment, a configurable option, something under review, or simply targeted and not yet true.
This costs us something on a first read, because a page of green ticks is more persuasive at a glance. It is worth it, because a buyer who discovers during due diligence that a badge was aspirational stops believing everything else on the page — and in this market that discovery usually happens in front of a board.
Every claim, with its real status attached
Read the right-hand column before the left. Two of these rows are certificates we hold and can show you. Two are things we do not have and are not pretending to have.
ISO/IEC 27001:2022 — organisational ISMS
Wise Hustlers Technologies Private Limited is certified for its information security management system, covering information security management for web, mobile and custom software development, AI solutions, cloud services and IT consulting. Certified by QRO Certification LLP, certificate registry ID 3050260810139IS, in force from 10 August 2026 to 9 August 2029. This certifies how we run our organisation — it is not a certification of any camera or hardware product, and we do not present it as one.
View the certificate →ISO 9001:2015 — quality management system
Certified quality management system covering the design, development, deployment and maintenance of our software solutions. Certificate registry ID 3050260810138Q, in force from 10 August 2026 to 9 August 2029. Again an organisational certificate, not a product approval.
View the certificate →Product-level security certification for the monitoring hardware
No product-specific security certification is claimed for the camera or edge device. If you require one for a tender, tell us which scheme and we will tell you honestly whether we can meet it and by when.
NDPC registration for your deployment
Two registrations are in play and they are separate. Yours: an organisation processing the personal data of more than 200 data subjects in six months, or operating in a listed sector such as education, health or hospitality, registers as a data controller of major importance. Ours: a vendor commercially processing sensitive personal data at that scale is registrable in its own right, and we do not pretend your filing covers us. We prepare the technical and architectural material your filing needs and support you through it — but we have not registered, been approved by, or been endorsed by the Nigeria Data Protection Commission on your behalf, and we will not imply we have.
ISO/IEC 27701 — privacy information management
An extension to ISO 27001 covering privacy information management specifically. On our roadmap. Not held today, and nothing on this site should be read as claiming it.
Analysis performed on the camera, not in the cloud
Detection and analysis run on the device. In the default configuration the frame is discarded from memory once the event is produced and no image is transmitted off the camera.
Encryption in transit and at rest
Links between camera, site gateway and management plane are encrypted, and stored events and any retained footage are encrypted on disk. The specific cipher suites for your deployment are stated in the technical documentation issued with your quotation.
Nigeria-hosted or fully on-premises deployment
The same system runs on your own premises, in a Nigeria-hosted tenancy, or in a cloud region you name. The choice is yours and it is written into the service agreement rather than defaulted by us.
No cross-border transfer of recorded material by default
In an on-premises or Nigeria-hosted deployment, recorded material does not leave Nigeria. Where a client chooses a foreign cloud region, the resulting transfer is documented and governed contractually rather than happening silently.
Configurable retention with automatic deletion
Retention is set per camera and enforced by a scheduled deletion job. Nothing survives past its schedule because someone forgot to clear it.
Comprehensive audit trail
Every view, search and export writes an append-only audit entry naming the user, the time and the stated reason. The audit log is access-controlled separately from the footage itself.
Role-based access and named administrator accounts
Access is granted by role and scoped per site and per camera. Individually named logins; shared accounts are not supported by design, because a shared account destroys the value of the audit trail.
Your data is never sold or shared for our own purposes
We process client monitoring data solely to deliver the service, on the client's documented instructions. We do not sell it, do not share it with third parties for their purposes, and do not use it to train models for other clients. This is a contractual undertaking in the service agreement, not just a statement on a web page.
Three trust boundaries, and what crosses each one
The question a regulator asks is not which brand of camera you bought. It is: what happens on the device, what stays on the site, and what leaves it. This is that answer, drawn.
What happens to a single frame, from capture to deletion
The most common question we are asked in Nigeria is whether facial images are stored. Rather than answer it in a sentence, here is the whole lifecycle — including the stage where the image ceases to exist.
Data minimisation, applied concretely
Minimisation is usually written as a principle and then ignored at configuration time. We apply it as a default: if a purpose can be met by counting people, we configure counting and leave identity matching switched off entirely.
Traffic analytics, footfall measurement and queue monitoring almost never need to know who anyone is. We will say so during scoping even when the larger configuration would be the larger sale.
How a biometric template differs from a photograph
Where identity matching is enabled, what is retained is a numeric template derived from the image, not the image. A template is generated for the purpose of comparison against a list you control and is held on your site.
We will not tell you a template is “anonymous”, because it is not: it exists precisely to identify someone, and it should be treated as sensitive personal data with everything that implies. Vendors who describe templates as anonymous are describing a legal position that does not hold.
The rules this deployment has to answer to
Nigerian clients are governed by Nigerian data protection law; clients with European operations or European counterparties are also answerable to the GDPR. The points below are the ones that actually change how a monitoring system should be configured — and each quotes the primary text and links to it, rather than asking you to take our summary on trust.
Two of them are worth reading before you talk to any vendor, including us: the distinction between ordinary CCTV and face matching, and the fact that no certificate anyone holds is a compliance defence.
Which rules actually apply, as of today
NigeriaThe governing statute is the Nigeria Data Protection Act 2023, assented to on 12 June 2023. The instrument that governs day-to-day compliance, though, is the NDPC's General Application and Implementation Directive (GAID) 2025, issued on 20 March 2025 — 52 articles and 10 schedules of operational detail that the Act itself does not contain.
One point of confusion worth clearing up: the Act did not repeal the older NDPR 2019. The NDPR was displaced on 20 March 2025, when GAID Article 3(3) directed that the Commission would cease to apply it. If a vendor is still citing the NDPR at you as the current framework, their compliance material is out of date.
Nigerian law names facial images as biometric data, explicitly
NigeriaThere is no ambiguity to exploit here. Section 65 of the Act defines sensitive personal data to include “genetic and biometric data, for the purpose of uniquely identifying a natural person”, and separately defines biometric data as data from specific technical processing that allows unique identification, “including without limitation by physical measurements, facial images, blood typing, fingerprinting, retinal scanning, voice recognition and deoxyribonucleic acid (DNA) analysis”.
This was a real change. The predecessor NDPR 2019 did not list biometric data as sensitive at all. Any compliance position built on the older regulation understates what a face-matching deployment now requires.
Source: NDPA 2023, section 65
The regulator directs consent for sensitive personal data
NigeriaGAID Article 18(1) states that “consent is required … (b) For the processing of sensitive personal data”. Article 17(5) then adds that reliance on any lawful basis other than consent, where unsupported, “shall be strictly scrutinised during NDP Act compliance audits and in any proceeding where the conduct of a data controller or processor is called into question”.
We are deliberately precise about this. Section 30(1) of the Act does list nine alternative grounds for processing sensitive data, and where the Act and the directive conflict the Act prevails. So it would be wrong to tell you consent is the only lawful route. What is accurate — and what you should plan around — is that the regulator directs consent, and anything else will be examined hard in an audit.
Notably, the European position converges on the same answer: the EDPB concludes that private-sector video surveillance with biometric recognition will in most cases require explicit consent. A deployment built on genuine consent plus a filed impact assessment is defensible under both regimes at once.
For public-facing cameras a DPIA is mandatory, not advisable
NigeriaGAID Article 28(3) makes a Data Protection Impact Assessment mandatory, and filable with the Commission, for a list of processing types that a monitoring deployment hits repeatedly: systematic monitoring; processing involving sensitive data; “deployment of surveillance cameras in places that may be accessed by members of the public”; educational services involving pupil records; and hospitality services.
Two operational consequences most vendors do not mention. Article 28(4) requires the assessment to be vetted by a certified DPO accredited by the Commission — our draft is an input to that, not a substitute for it. And Article 28(6) provides that failing to carry one out may result in a restriction on the platforms through which you contact data subjects at all.
You may have to register — and so may we, separately
NigeriaThe Commission registers “data controllers and data processors of major importance”. Under its registration guidance, an organisation is designated as of major importance if it processes the personal data of more than 200 data subjects in six months, or operates in a listed sector — which includes education, health, hospitality, financial services and public service.
The part vendors tend to leave out is that the obligation reaches us too. The same guidance designates processors who commercially process sensitive personal data for more than 200 data subjects. A biometrics vendor meets that. Our registration does not discharge yours and yours does not discharge ours — and you are entitled to ask us for evidence of ours before you sign. The GAID tells you to.
Source: NDPC Guidance Notice on registration of DCPMIs (GAID Schedule 7)
Churches: exempt from registration, not from the Act
NigeriaThe registration guidance exempts faith-based organisations, community-based associations, foreign missions, judicial bodies and multigovernmental organisations from the requirement to register with the Commission.
That exemption is narrow and it is easy to over-read. It removes a filing obligation. It removes nothing else: lawful basis, consent, security measures, breach notification, impact assessments and data subject rights all continue to apply in full to a church running cameras. Schools and hotels get no exemption at all — both are named sectors.
We spell this out because a vendor implying that a church sits outside Nigerian data protection law would be doing that buyer real harm.
Source: NDPC Guidance Notice on registration, exemptions from registration
There is no general legal requirement to host in Nigeria
NigeriaWe offer Nigeria-hosted and on-premises deployment, and many clients should take it. But we will not sell it to you on a false premise. Neither the NDPA 2023 nor the GAID 2025 contains a data-localisation requirement. Part VIII of the Act regulates the conditions under which data may be transferred, not where it must be stored.
NITDA's National Cloud Policy 2025 is mandatory for federal public institutions and federally-owned companies, and reaches a private company only where its data is designated as being of strategic national interest. The CBN's payments localisation rule binds licensed payment ecosystem participants. Neither reaches a church, a school or a hotel.
So the honest case for in-country hosting is sovereignty, latency, and a contractual assurance you can show your board — not a legal obligation. If a competitor tells you Nigerian law requires it, that is a sales tactic, and you can check it against the sources on this page.
Source: NITDA National Cloud Policy 2025, scope and data classification
72 hours to the Commission, immediately to the people affected
NigeriaSection 40(2) requires a controller to notify the Commission within 72 hours of becoming aware of a breach likely to result in a risk to people's rights and freedoms. Section 40(3) requires that where the risk is high, the controller communicates it to the affected individuals immediately, in plain and clear language, with advice on mitigation.
A processor's duty under section 40(1) is different and worth stating precisely: it is to notify the controller on becoming aware. The 72-hour clock is the controller's, which is why our contact points and escalation path are agreed in the service agreement before go-live. Section 40(8) also requires both parties to keep a record of every breach and its remedial action.
Source: NDPA 2023, section 40
What getting this wrong actually costs
NigeriaFor a controller or processor of major importance, the maximum penalty is the greater of ₦10,000,000 or 2% of annual gross revenue in the preceding financial year. For everyone else it is the greater of ₦2,000,000 or 2% of that revenue. Note the structure: the naira figures are floors, not caps, because the provision reads “the greater of”.
There is also criminal exposure, though not where people usually assume. Section 49 attaches it to failing to comply with a compliance order made by the Commission — up to one year's imprisonment, a fine, or both — rather than to the underlying breach. Section 53 makes principal officers personally culpable unless they can show diligence, and makes organisations vicariously liable for their staff and agents.
For completeness: the Commission's published enforcement posture describes itself as restorative rather than punitive, and it can order remedial fees in lieu of strict penalties.
A six-month backstop on keeping anything
NigeriaGAID Article 49(3) provides that where no timebound obligation applies, storage lapses not later than six calendar months after the original purpose has been accomplished — subject to retention needed for legal claims or due diligence.
Our default retention schedule of 30 days for event records and footage sits well inside that. We mention the backstop because it is the ceiling a regulator will measure your configuration against if you ask us to extend a period, and because “we keep it indefinitely in case we need it” is not a position that survives contact with it.
Source: NDPC, GAID 2025, Article 49(3)
The obligations Nigerian law puts on us, as the software vendor
NigeriaGAID Article 31 imposes duties directly on whoever deploys data-processing software: carry out an impact assessment before deployment; build to privacy by design and by default; provide a privacy policy inside the software; and provide a pre-installation privacy statement naming the data types, the lawful purpose, and the specific technical measures — the article says encryption should be specifically indicated.
Article 34 then prescribes the twenty terms a Data Processing Agreement must contain, including the location of processing, the technical and organisational measures, the impact assessment outcome, evidence of our registration with the Commission, indemnity and insurance.
We list these because they are the concrete, checkable things a buyer should be asking any vendor for. They are a better test of whether a supplier has done the work than any certificate, including ours.
Ordinary CCTV is not biometric data. Face matching is.
GDPR · EDPBThis distinction matters under both regimes, and it is routinely got wrong in both directions. Footage of a person is not automatically special-category biometric data. It becomes biometric data once it is put through a specific technical process intended to identify someone uniquely — the same qualifier the Nigerian definition uses.
The European Data Protection Board puts it plainly: video footage of an individual “cannot however in itself be considered as biometric data under Article 9, if it has not been specifically technically processed in order to contribute to the identification of an individual”. GDPR Recital 51 says the same of photographs.
Practically, the decision to switch face matching on is the decision to move your deployment into the heightened-obligation category. It is a configuration choice with a legal consequence, which is why we treat it as a scoping decision rather than a default.
Source: EDPB Guidelines 3/2019 on video devices, paras 74–76
With face matching on, you need two legal grounds, not one
GDPR · EDPBA common and expensive mistake is to identify a single lawful basis and stop. Where a video system processes special categories of data, the controller must identify both an exception under Article 9 and, separately, a legal basis under Article 6. The two are cumulative.
We raise this at scoping because the answer sometimes is that no workable pair exists for the purpose being described — and the right response then is to configure the system without identity matching, not to proceed and hope.
For a private facility, that usually means explicit consent
GDPR · EDPBThe EDPB addresses this exact scenario — a private organisation running biometric recognition on its own premises for its own purposes — and concludes that it “will, in most cases, require explicit consent from all data subjects (Article 9(2)(a)), however another suitable exception in Article 9 could also be applicable”. It names security explicitly as one of the private purposes this covers.
The word doing the work is “all”. The EDPB's own worked examples require the deployment to be designed so that people who have not consented are not captured at all — a physically separated lane or gate, not merely a promise to delete. That is a design requirement, and it is why the enrolment question belongs in the site survey rather than in the terms and conditions.
Source: EDPB Guidelines 3/2019 on video devices, paras 77–80
Walking past a camera does not make someone's data public
GDPR · EDPBSome vendors reach for the argument that a person in a public or semi-public space has made their data “manifestly public” and so no further basis is needed. The EDPB closes that route explicitly: “The mere fact of entering into the range of the camera does not imply that the data subject intends to make public special categories of data relating to him or her.”
If you are shown a compliance argument built on this, it does not hold.
You are expected to have considered a less intrusive option first
GDPR · EDPBThe EDPB states that facial recognition entails heightened risks and that controllers “should first of all assess the impact on fundamental rights and freedoms and consider less intrusive means”.
This is the obligation behind a habit we apply as standard: where a purpose can be met by anonymous counting, we configure counting and leave identity matching off. Being able to show that you considered and chose the lesser option is part of what makes the deployment defensible — and it is a record you can only create before installation, not after.
No certificate — ours or anyone's — is a compliance defence
GDPRArticle 42(4) of the GDPR is unusually direct: a certification “does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities”.
We hold ISO certificates and we are glad to show them. They are evidence that we run our organisation to an audited standard. They are not a shield, they do not transfer your accountability to us, and any vendor implying otherwise is selling you a false sense of security.
Why an ISO 27001 certificate structurally cannot certify a camera
ISOThis is not a matter of interpretation, it is a matter of which accreditation scheme issued the certificate. Management-system certification — which is what ISO/IEC 27001 is — is governed by ISO/IEC 17021-1:2015, “Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements”, together with ISO/IEC 27006-1:2024 for information security specifically.
Product certification is a different accreditation scope entirely, governed by ISO/IEC 17065. A body accredited to certify a management system is not thereby accredited to certify a product, and a certificate issued under the one scheme says nothing about the other.
So when we say our ISO/IEC 27001:2022 certificate covers our organisation and not the monitoring hardware, that is not modesty. It is the only thing the certificate is capable of meaning. ISO itself issues no certificates at all — accredited certification bodies do, which is why we name ours and give you the registry ID.
If you are a public authority, two common routes are closed to you
GDPRWhere the GDPR applies, a public authority acting in the performance of its tasks cannot rely on legitimate interests: Article 6(1) provides that point (f) “shall not apply to processing carried out by public authorities in the performance of their tasks”.
Article 49(3) closes a second route, disapplying the consent, contract and third-party-contract transfer derogations for “activities carried out by public authorities in the exercise of their public powers”. In practice that pushes a public-sector transfer onto Article 46 safeguards — standard contractual clauses under Article 46(2)(c) or (d), or binding corporate rules.
We flag this because a ministry, agency or state government evaluating this technology will be given advice built for private buyers unless someone points out the difference.
Source: GDPR, Articles 6(1) and 49(3) (Regulation (EU) 2016/679)
Which obligations are yours, and which are ours
This is the distinction that decides who is accountable when something goes wrong, and it is the one most vendor pages leave vague. In a typical deployment your organisation is the controller and we are the processor. Below is what that actually means in practice, obligation by obligation.
Why we will not say we are “NDPC certified”
Because there is no such thing to be, in the sense a vendor badge would imply. What exists is registration, and it cuts both ways: you register as a controller if you meet the threshold, and we are registrable as a processor in our own right. Neither filing discharges the other. We prepare the technical and architectural material your filing needs and we support you through it — but a vendor claiming to have discharged your regulatory obligations for you is describing something that did not happen.
What we give you for your own compliance file
- A Data Protection Impact Assessment for your deployment scope
- The data-flow record showing exactly what is processed and where it goes
- The system architecture pack, for your own regulator filings
- Your retention schedule as configured, per camera
- The privacy notice and entrance signage pack for your site
- A written description of the technical and organisational security measures in place
The controls that hold this together
Encryption in transit
Every link between camera, site gateway and management plane is encrypted. Nothing about this deployment sends monitoring data across a network in the clear.
Encryption at rest
Stored events and any retained footage are encrypted on disk. In an on-premises deployment your organisation holds the keys, which means we cannot read your footage even if we wanted to.
Role-based access control
Access is granted by role and scoped per site and per camera. A guard at one branch does not get a window into another branch because the permission model was built as one flat list.
Named administrator accounts
Individual logins with multi-factor authentication available. Shared accounts are not supported by design — a shared login destroys the audit trail's value entirely.
Append-only audit trail
Every view, search and export records the user, the time and the reason given. The log is access-controlled separately from the footage, so someone who can watch cannot quietly edit the record of having watched.
Automatic retention enforcement
A scheduled job deletes expired records. Retention is set per camera, changes are audit-logged, and nothing survives its schedule through inattention.
Specific cipher suites, protocol versions and supported authentication factors are stated in the technical documentation issued with your quotation. We have deliberately not published a set of figures here that might not match the configuration you are actually sold — see the technical datasheet for what is confirmed today and what is still open.
You decide where your data lives — and it goes in the contract
Three options, one decision, made by you at scoping rather than defaulted by us at installation.
On your premises
Processing and storage run entirely on hardware inside your facility. No recorded material leaves the building. Your team holds the encryption keys and the administrator root accounts.
Hospitals, no-egress policies, and any buyer who needs the answer to be physical rather than contractual.
Nigeria-hosted tenancy
Data resides in a hosting facility located in Nigeria. You get central administration across sites without recorded material crossing a border.
Multi-site operators who want in-country residency without running their own infrastructure.
Cloud region of your choosing
Hosted in a named region agreed with you. Any resulting cross-border transfer is documented and governed contractually rather than discovered later.
International groups already operating to a global hosting standard.
Data that deletes itself, on a clock you set
Retention is configured per camera and enforced by a scheduled job. The default is 30 days for event records and for recorded video where a client has enabled it; templates are deleted when the individual is removed from your list; audit entries outlive the data they describe.
The questions Nigerian buyers actually ask first
Where is my data stored?
For Nigerian clients the solution can be configured for secure in-country hosting or for on-premises deployment on your own hardware, subject to the agreed system architecture and your requirements.
Whichever you choose is recorded in the service agreement rather than left as a vendor default, so the answer to this question is a contractual fact you can show someone, not an assurance you have to take on trust.
Is my biometric data transferred or sold to third parties?
No. The system is designed to prevent unauthorised sharing or sale of personal data, and we undertake contractually not to sell client data, not to share it with third parties for their own purposes, and not to use it to train models for other clients.
Any processing or transfer that does occur is subject to the applicable contractual, privacy and regulatory requirements, and is documented in your deployment's data-flow record.
Can the system be deployed in churches, schools, hotels, hospitals and other private facilities?
Yes, and these are the settings the early-adopter programme is aimed at. Deployment is subject to the applicable privacy, consent, notification, security and sector-specific requirements for that setting.
One point specific to churches, because it is easy to get wrong in both directions: the NDPC exempts faith-based organisations from the requirement to register as a controller of major importance. That exemption is from registration only. Lawful basis, consent, security, breach notification, impact assessments and data subject rights all still apply in full. Schools and hotels get no exemption at all — education and hospitality are both listed sectors.
Appropriate privacy notices and consent mechanisms must be provided where required — which is why a privacy notice and entrance signage pack is included in every package rather than sold as an extra. Some settings carry heightened obligations: schools involve children, hospitals involve health context, and workplaces engage employment law as well as data protection.
Can customers keep their data within Nigeria?
Yes. A Nigeria-hosted or fully on-premises deployment option can be offered, subject to the agreed technical configuration.
In the on-premises configuration your organisation holds the encryption keys and the administrator root accounts, and recorded material does not leave your building.
Are raw facial images stored?
In the default configuration, no. Analysis runs on the camera; the frame is released from memory once the event has been produced, and no image is transmitted off the device.
Some settings legitimately require continuous recording, and a client administrator can enable it per camera. Where that happens the footage is held under your own retention schedule, encrypted at rest, access-logged, and deleted automatically on expiry. Which configuration applies to your deployment is stated in your Data Protection Impact Assessment, issued before go-live.
Who is the data controller — you or us?
In a typical deployment your organisation is the data controller and we are the data processor. You decide why the cameras exist, what they are pointed at and how long material is kept; we operate the system on your documented instructions.
That distinction matters practically: registration and notification duties, and responses to data subject requests, sit with you as controller. We provide the technical material and the support to discharge them, but we cannot and do not discharge them on your behalf.
What happens if there is a data breach?
As processor, our obligation is to notify you as controller without undue delay once we become aware, with the information you need to assess it — what happened, which data categories and roughly how many individuals are affected, and what we are doing about it.
The notification to the regulator and, where required, to affected individuals is the controller's to make. The breach-notification procedure, including contact points and timescales, is agreed in writing in the service agreement before go-live rather than improvised during an incident.
Can we get our data out if we leave?
Yes. Export formats and the deletion procedure at termination are agreed at the start of the engagement and written into the contract, not negotiated at the point you want to leave.
At termination we export in the agreed format, you verify the export is complete and readable, and only then is the data deleted — with a written deletion confirmation issued to you.
Do we have to register with the NDPC, and do you?
Probably both, and separately. Under the Commission's registration guidance an organisation is a controller of major importance if it processes the personal data of more than 200 data subjects in six months, or operates in a listed sector — education, health, hospitality, financial services and public service are all listed. Registration tiers carry different fees and different annual return obligations.
The part vendors tend to leave out is that the same guidance reaches processors: a supplier commercially processing sensitive personal data at that scale is registrable in its own right. Our registration does not discharge yours and yours does not discharge ours. You are entitled to ask us for evidence of ours before signing, and the NDPC's directive on data processing agreements tells buyers to do exactly that.
Do we need a Data Protection Impact Assessment, or is that optional?
For cameras in a place members of the public can reach, it is mandatory rather than advisable. The NDPC's directive lists systematic monitoring, processing involving sensitive personal data, public-facing surveillance cameras, educational services involving pupil records, and hospitality services among the processing types that require one. Most deployments in this programme hit at least two.
Two consequences worth knowing. The assessment has to be vetted by a DPO accredited by the Commission — the version we prepare for your deployment is an input to that, not a substitute for it, and we will say so rather than let you assume otherwise. And failing to carry one out can result in a restriction on the platforms through which you contact people at all.
Do you hold a government approval or licence for this?
No, and we will not imply otherwise. Public-sector engagements remain subject to the relevant government reviews and approvals, which have not concluded.
This private-sector programme does not depend on those approvals. If a specific approval becomes relevant to your deployment we will tell you its actual status rather than describing an application as an authorisation.
Still have a question this page did not answer?
Ask it. If the honest answer is “we do not have that yet”, that is the answer you will get — which is more useful to you than a confident one that falls apart during due diligence.