Privacy Policy
How LumiID collects, uses, and protects identity data across our verification and fraud-intelligence platform.
Last Updated
September 17, 2026
PRIVACY POLICY
At LumiID Limited ("LumiID", "we", or "us"), we prioritize our relationship with our customers/clients ("you" or "your"). It is important to us that we are transparent about the way we handle your personal information. Accordingly, our privacy policy ("Privacy Policy") describes how we collect, use and safeguard the information you provide to us and your rights with respect to that information when using our Services as defined below.
For the purpose of this Privacy Policy, "Site" refers to LumiID's website which can be accessed at https://lumiid.com. "Service(s)" includes but is not limited to LumiID's verification and compliance services, and the IdentifyPass, IdentityRadar and IdentifyForm products accessed via the Site, our software and APIs, and our platform and services.
We recommend that you read our Privacy Policy carefully to understand our views and practices regarding your personal data and information, its collection and usage. By clicking the "Accept" icon or any other icon that indicates agreement with this Privacy Policy, accessing our Sites, creating an account with us, becoming integrated on our platform, and accessing our Services, you agree and consent to our terms and conditions, and to the collection, use, storage and sharing of your information as described in this Policy.
Modification
As our business evolves and we improve on our Services, we may modify this Privacy Policy to conform with regulatory requirements. Any modification will be notified by changing the date at the top of this Privacy Policy. We make any such changes to our Privacy Policy, we may notify you by email (sent to the email address specified in your account), by means of a notice on our Services prior to the change becoming effective, or as otherwise required by law. In any event, by continuing to use our Services or maintaining your account with us after the posting of any changes, you confirm your continuing acceptance of this Privacy Policy together with such changes. We encourage you to periodically review LumiID's Privacy Policy for the latest information on our privacy practices and to keep track of our latest updates. Queries, comments and requests regarding this Privacy Policy are welcomed and should be addressed to legal@lumiid.com
1. Our Commitment to Data Protection
We process all personal data lawfully, fairly, and transparently, and only for the purpose for which it was collected. Where LumiID processes Data Subject information supplied by a business customer for verification purposes, LumiID acts as a data processor on that customer's behalf; the business customer remains the data controller and is responsible for obtaining valid consent from its own end users.
2. Legal Basis for Processing Personal Data
Consent
When you or a business acting on your behalf explicitly agree to our data processing.
Contractual Necessity
To fulfill our obligations in providing verification and fraud-intelligence services.
Legal Obligation
When required by law, a regulator, or a governmental authority.
Legitimate Interest
To improve services, detect and prevent fraud, and secure the platform.
3. Information We Collect
A. Submitted Information
Information we may collect and process from you include those you provide to us when: filling in forms on our Site(s); corresponding with us; registering to use our Services; subscribing to any of our Services; when you become integrated with our security and compliance functionalities; and reporting a problem with our Site, products, our Services, or any of our platforms.
This information may include your name, address, email address and phone number, age, gender, marital status, username, password and other registration information where applicable. By the use of any of the LumiID Services, you consent to the collection, use and storage of your information in the manner provided herein.
B. Automatically Collected Information
Information we may collect from you automatically are information including but not limited to your; technical information, including the type of software you use for integration with the Site (for example, your device's IMEI or serial number), information (software development kit [SDK]) you use, privacy status of your APIs (whether publicly shared or private), or your device's location and time zone setting (Device Information); and details of your use of and visits to any of the Sites and/or platforms.
C. Business Information
This includes but is not limited to the following: the full name of your business with registration details, incorporation documents, country of operations, details of directors and address information of the business, information required to be provided to us by filling in the forms on the Site or any other information which you submit to us via the website or email.
To maintain and improve the quality of our Service to you, we track information provided to us by your browser when you view or use the Service, such as the type of browser or device you are using, the website which you are connected to the Service, the time and date of access, and other information that does not personally identify you. We track this information using cookies, or small text files which include an anonymous unique identifier. Other information and data about you which we may collect, use, and process include the following:
- Records of correspondence received via the Site, email and telephone.
- Your responses to surveys or research that we carry out from time to time.
- Details of transactions or API calls made to us via the Site, platforms, telephone or other means, including details of payment methods used.
4. Purpose of Data Processing
- Identity verification and validation
- Account creation and management
- Wallet transactions and payment processing
- Compliance with KYC/AML regulations
- Fraud detection, scoring, and prevention
- Continuous monitoring of previously verified identities
- Customer support improvement
- Legal and regulatory reporting obligations
6. Data Retention
- Personal data is retained only as long as necessary to fulfill the purpose for which it was collected, or the specific period stated in a customer's Data Processing Agreement.
- Verification records and transaction logs may be retained for longer periods where required for KYC/AML recordkeeping or other legal obligations.
- After the applicable retention period, data is securely deleted or anonymized.
7. Data Subject Rights
Subject to applicable law and any exemptions, you may exercise the following rights over your personal data:
If your information was submitted through a LumiID business customer, please contact that business first — as data controller, they are best placed to action your request. You can also reach our DPO directly: privacy@lumiid.com
9. Security & International Transfers
We use secure transmission protocols including TLS encryption, multi-factor authentication, and continuous vulnerability monitoring to protect personal data. Where personal data is transferred outside Nigeria — for example, to a cloud infrastructure provider — such transfers are governed by contractual safeguards designed to meet NDPA/NDPR adequacy requirements.
TLS
Encrypted in Transit
2FA
MFA Access
Monitoring
Continuous Audits
Minimization
Purpose Only
10. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and affected individuals or business customers without undue delay, in line with our obligations under the NDPA/NDPR.
11. Children's Privacy
Our services are not designed for individuals under 18 years of age. We do not knowingly collect data from minors. If a child's information is inadvertently collected, we will promptly delete it upon becoming aware.
12. Updates to This Policy
We may update this Privacy Policy periodically to reflect legal, technical, or business changes. We will notify you of material updates through email or a prominent notice on the platform before they take effect.
13. Contact Information
Division Address
Data Protection Officer (DPO)
OmniNile Systems Limited (LumiID Division)
Gboko, Benue State, Nigeria
Digital Reach
📧 privacy@lumiid.com
🌍 https://lumiid.com
NDPA / NDPR Principles Observed