AuthOrigin
Legal

Privacy Policy

How AuthOrigin collects, uses, and protects personal information across our website and product-authentication platform.

Last updated: [DATE]

We publish two editions of this policy. Choose the one that applies to you — the Nigeria / Africa edition follows the Nigeria Data Protection Act 2023 and NDPC GAID 2025, and the EU / EEA / UK edition follows the GDPR and UK GDPR.

1. Who we are

[LEGAL ENTITY NAME] ("AuthOrigin", "we", "us", "our") operates a product-authentication and anti-counterfeiting platform that lets brands register their products and lets consumers verify a product's authenticity by scanning a QR code or barcode. We are the data controller responsible for the personal data described in this policy.

  • Registered company: [LEGAL ENTITY NAME], RC [RC NUMBER]
  • Registered address: [REGISTERED ADDRESS]
  • Website: [WEBSITE]
  • Data protection contact: [PRIVACY EMAIL] / Data Protection Officer, [DPO EMAIL]

For some processing we act as a data processor on behalf of our business customers (the brands) — see §7.

2. Scope of this policy

This policy explains how we collect, use, share, store and protect personal data, and the rights you have under the Nigeria Data Protection Act 2023 (NDPA) and the NDPC General Application and Implementation Directive (GAID) 2025. It covers everyone whose data we handle:

  • Business users — people who create or use an AuthOrigin account on behalf of a brand, distributor or partner organisation (the "company" and "platform" applications).
  • Consumers — people who scan a product to verify it, or who submit a counterfeit report, through our consumer application. No account is required to scan.
  • Website and enquiry visitors — people who visit our marketing website or contact us.

This policy does not cover third-party websites or services we link to, which have their own privacy policies.

3. Key definitions

We use terms as defined in the NDPA. In brief: personal data is any information relating to an identifiable individual (a "data subject"); processing is any operation performed on personal data; a data controller decides why and how data is processed; a data processor processes data on a controller's behalf; the NDPC is the Nigeria Data Protection Commission.

4. The personal data we collect

4.1 Business users (company & platform applications)

  • Account & identity: full name, work email address, phone number, job title/role, and the organisation you belong to.
  • Authentication data: hashed password, multi-factor authentication (MFA) settings and tokens, session and login records (including IP address, device and browser information, timestamps).
  • Know-Your-Business (KYB) / onboarding data: business name, company registration (RC) number, business address, regulatory registration numbers (e.g. NAFDAC), and any supporting documents or details you submit to verify your organisation. Where these documents identify individuals (e.g. directors or authorised representatives), that information is personal data.
  • Billing data: subscription plan, billing contact, transaction and invoice history. Card/payment credentials are handled by our payment processor — we do not store full card numbers.
  • Usage data: API keys (stored securely), API and console activity, feature usage, and support correspondence.

4.2 Consumers (consumer application)

When you scan a product or view a verification result we record a scan event, which may include:

  • The product/unit identifiers involved and the verification result.
  • Coarse location derived from your IP address — country, region and city only (we do not store precise GPS coordinates for scans).
  • A hashed/truncated form of your IP address for fraud-prevention analytics — we do not retain the raw IP address in our analytics stores.
  • Device and browser information (user-agent), timestamp, and automated fraud/risk signals (see §13).

If you submit a counterfeit or product report, we also collect the details you provide: the reason, a description, purchase location and date, and any contact details you choose to give us (optional). You do not need an account to scan or report.

4.3 Website & enquiry visitors

  • Contact-form details you submit (name, email, message) and coarse location for spam/abuse prevention.
  • Cookies and similar technologies — see §6.

We apply data minimisation: we collect only what we need for the purposes below.

5. How and why we use your data, and our lawful basis

Under section 25 of the NDPA we must have a lawful basis for each processing purpose. The table below sets out ours.

PurposePersonal data usedLawful basis (NDPA)
Create and manage business accounts; authenticate users; secure logins and MFAAccount, identity, authentication dataPerformance of a contract with your organisation
Verify a business's identity (KYB) and eligibility for regulated featuresKYB/onboarding dataLegal obligation and legitimate interests (preventing fraud/counterfeiting)
Provide product-verification results to consumersScan events, coarse location, device dataLegitimate interests (enabling the service; protecting consumers and brands from counterfeits)
Detect and prevent fraud, counterfeiting and grey-market diversion; risk scoringScan events, hashed IP, device dataLegitimate interests and, where applicable, legal obligation
Handle counterfeit reports and respond to youReport details, optional contactLegitimate interests; consent where you volunteer contact details
Process billing and subscriptionsBilling dataPerformance of a contract
Respond to enquiries and provide supportContact and correspondence dataConsent / legitimate interests
Send service and (where you opt in) marketing communicationsContact dataConsent (marketing); legitimate interests (essential service notices)
Comply with law, respond to lawful requests, and defend legal claimsAs relevantLegal obligation / establishment of legal claims
Maintain, secure and improve the platform (analytics, logging)Usage and technical dataLegitimate interests

Where we rely on consent, you may withdraw it at any time (see §11); withdrawal does not affect processing already carried out.

6. Cookies and similar technologies

We use cookies and similar technologies on our website and applications. In line with GAID 2025, we ask for your opt-in consent before setting any non-essential cookies (such as analytics or marketing cookies); strictly necessary cookies that are required to run the service are set without consent. You can manage your preferences through our cookie banner and your browser settings. Full details are in our [Cookie Policy / cookie banner].

7. When we share personal data

We do not sell your personal data. We share it only as follows:

  • On behalf of brands (as processor): scan and verification data generated for a brand's products is made available to that brand, which acts as controller of that data for its own purposes.
  • Service providers (processors): cloud hosting (Microsoft Azure), email delivery, payment processing, analytics and geolocation providers who process data on our instructions under a written data processing agreement as required by the NDPA.
  • Professional advisers and auditors, including our licensed Data Protection Compliance Organisation (DPCO), under confidentiality.
  • Authorities and regulators (including the NDPC and NAFDAC) where required by law or to protect rights, safety and property.
  • Corporate transactions: to a successor entity in a merger, acquisition or reorganisation, subject to this policy.

8. International (cross-border) transfers

Our platform is hosted on Microsoft Azure in the European Union ([West/North Europe] region). This means personal data collected in Nigeria is transferred to and stored in the EU, and some processors may access it from other countries.

We only transfer personal data outside Nigeria where the NDPA (sections 41–43) and GAID permit it — that is, where the destination provides an adequate level of protection, or where an appropriate safeguard applies (such as contractual clauses / binding data-processing terms), or where a permitted derogation applies (e.g. your consent, or necessity for a contract). The EU is widely recognised as providing a high standard of data protection. You may request details of the safeguards we use by contacting us at [PRIVACY EMAIL].

9. How long we keep your data (retention)

We keep personal data only for as long as necessary for the purposes above, then delete or anonymise it:

  • Business account data: for the life of the account and up to [e.g. 12–24 months] after closure, unless a longer period is required by law.
  • KYB and billing records: retained for the period required by tax, accounting and anti-fraud law (typically up to [e.g. 6–7 years]).
  • Scan events: retained in identifiable/coarse form for [e.g. 24 months] for fraud analytics, then aggregated/anonymised.
  • Counterfeit reports: for as long as needed to investigate and for legal-claim purposes.
  • Marketing consent records: until you withdraw consent, plus a short proof-of-consent period.

10. How we protect your data

We implement appropriate technical and organisational measures under section 39 of the NDPA, including: encryption of data in transit and of sensitive fields at rest, hashing of passwords and IP addresses, multi-factor authentication, role-based access control and tenant isolation (row-level security), audit logging, and least-privilege access for staff. No system is perfectly secure, but we work continuously to protect your data.

11. Your rights as a data subject

Under the NDPA you have the right to:

  • Be informed about how your data is processed (this policy).
  • Access your personal data and obtain a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") where the law allows.
  • Restrict or object to certain processing, including direct marketing.
  • Data portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to request human review (see §13).
  • Lodge a complaint with the NDPC (see §17).

12. How to exercise your rights

Email [PRIVACY EMAIL] or write to us at the address in §1. We will verify your identity and respond without undue delay and within the timeframe required by the NDPA/GAID (in principle within one month). Exercising your rights is free unless a request is manifestly unfounded or excessive. If we cannot act on your request, we will explain why and tell you how to complain to the NDPC.

13. Automated processing and fraud scoring

To protect brands and consumers from counterfeiting, we run automated risk scoring on scan events (for example, detecting impossible-travel patterns, unusual scan volumes, or out-of-market activity). This assesses a product unit's authenticity risk rather than profiling you as an individual, and a "suspicious" result does not by itself make any legal decision about you. Where automated processing could significantly affect an individual, you have the right to request human review — contact us at [PRIVACY EMAIL].

14. Children's data

Our services are intended for businesses and adult consumers and are not directed at children under 18. We do not knowingly collect children's personal data. Where the processing of a child's data is required, we will obtain verifiable parental/guardian consent as required by the NDPA. If you believe a child has provided us data, contact us and we will delete it.

15. Data breaches

We maintain a data-breach response plan. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it, and we will notify affected individuals where the breach is likely to result in a high risk, in line with the NDPA and GAID.

16. Data Protection Officer and contact

  • General privacy enquiries and rights requests: [PRIVACY EMAIL]
  • Data Protection Officer: [DPO NAME], [DPO EMAIL], [REGISTERED ADDRESS]

17. Complaints and the NDPC

If you have a concern, please contact us first at [PRIVACY EMAIL] and we will try to resolve it. You also have the right to lodge a complaint with the regulator:

Nigeria Data Protection Commission (NDPC)

Website: https://ndpc.gov.ng · Email: info@ndpc.gov.ng

18. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new "Last updated" date and, where changes are significant, notify you directly. Please review it periodically.