1. Who we are
[LEGAL ENTITY NAME] ("AuthOrigin", "we", "us", "our") operates a product-authentication and anti-counterfeiting platform that lets brands register their products and lets consumers verify a product's authenticity by scanning a QR code or barcode. We are the data controller responsible for the personal data described in this policy.
- Registered company:
[LEGAL ENTITY NAME], RC[RC NUMBER] - Registered address:
[REGISTERED ADDRESS] - Website:
[WEBSITE] - Data protection contact:
[PRIVACY EMAIL]/ Data Protection Officer,[DPO EMAIL]
For some processing we act as a data processor on behalf of our business customers (the brands) — see §7.
2. Scope of this policy
This policy explains how we collect, use, share, store and protect personal data, and the rights you have under the Nigeria Data Protection Act 2023 (NDPA) and the NDPC General Application and Implementation Directive (GAID) 2025. It covers everyone whose data we handle:
- Business users — people who create or use an AuthOrigin account on behalf of a brand, distributor or partner organisation (the "company" and "platform" applications).
- Consumers — people who scan a product to verify it, or who submit a counterfeit report, through our consumer application. No account is required to scan.
- Website and enquiry visitors — people who visit our marketing website or contact us.
This policy does not cover third-party websites or services we link to, which have their own privacy policies.
3. Key definitions
We use terms as defined in the NDPA. In brief: personal data is any information relating to an identifiable individual (a "data subject"); processing is any operation performed on personal data; a data controller decides why and how data is processed; a data processor processes data on a controller's behalf; the NDPC is the Nigeria Data Protection Commission.
4. The personal data we collect
4.1 Business users (company & platform applications)
- Account & identity: full name, work email address, phone number, job title/role, and the organisation you belong to.
- Authentication data: hashed password, multi-factor authentication (MFA) settings and tokens, session and login records (including IP address, device and browser information, timestamps).
- Know-Your-Business (KYB) / onboarding data: business name, company registration (RC) number, business address, regulatory registration numbers (e.g. NAFDAC), and any supporting documents or details you submit to verify your organisation. Where these documents identify individuals (e.g. directors or authorised representatives), that information is personal data.
- Billing data: subscription plan, billing contact, transaction and invoice history. Card/payment credentials are handled by our payment processor — we do not store full card numbers.
- Usage data: API keys (stored securely), API and console activity, feature usage, and support correspondence.
4.2 Consumers (consumer application)
When you scan a product or view a verification result we record a scan event, which may include:
- The product/unit identifiers involved and the verification result.
- Coarse location derived from your IP address — country, region and city only (we do not store precise GPS coordinates for scans).
- A hashed/truncated form of your IP address for fraud-prevention analytics — we do not retain the raw IP address in our analytics stores.
- Device and browser information (user-agent), timestamp, and automated fraud/risk signals (see §13).
If you submit a counterfeit or product report, we also collect the details you provide: the reason, a description, purchase location and date, and any contact details you choose to give us (optional). You do not need an account to scan or report.
4.3 Website & enquiry visitors
- Contact-form details you submit (name, email, message) and coarse location for spam/abuse prevention.
- Cookies and similar technologies — see §6.
We apply data minimisation: we collect only what we need for the purposes below.
5. How and why we use your data, and our lawful basis
Under section 25 of the NDPA we must have a lawful basis for each processing purpose. The table below sets out ours.
| Purpose | Personal data used | Lawful basis (NDPA) |
|---|---|---|
| Create and manage business accounts; authenticate users; secure logins and MFA | Account, identity, authentication data | Performance of a contract with your organisation |
| Verify a business's identity (KYB) and eligibility for regulated features | KYB/onboarding data | Legal obligation and legitimate interests (preventing fraud/counterfeiting) |
| Provide product-verification results to consumers | Scan events, coarse location, device data | Legitimate interests (enabling the service; protecting consumers and brands from counterfeits) |
| Detect and prevent fraud, counterfeiting and grey-market diversion; risk scoring | Scan events, hashed IP, device data | Legitimate interests and, where applicable, legal obligation |
| Handle counterfeit reports and respond to you | Report details, optional contact | Legitimate interests; consent where you volunteer contact details |
| Process billing and subscriptions | Billing data | Performance of a contract |
| Respond to enquiries and provide support | Contact and correspondence data | Consent / legitimate interests |
| Send service and (where you opt in) marketing communications | Contact data | Consent (marketing); legitimate interests (essential service notices) |
| Comply with law, respond to lawful requests, and defend legal claims | As relevant | Legal obligation / establishment of legal claims |
| Maintain, secure and improve the platform (analytics, logging) | Usage and technical data | Legitimate interests |
Where we rely on consent, you may withdraw it at any time (see §11); withdrawal does not affect processing already carried out.
6. Cookies and similar technologies
We use cookies and similar technologies on our website and applications. In line with GAID 2025, we ask for your opt-in consent before setting any non-essential cookies (such as analytics or marketing cookies); strictly necessary cookies that are required to run the service are set without consent. You can manage your preferences through our cookie banner and your browser settings. Full details are in our [Cookie Policy / cookie banner].
7. When we share personal data
We do not sell your personal data. We share it only as follows:
- On behalf of brands (as processor): scan and verification data generated for a brand's products is made available to that brand, which acts as controller of that data for its own purposes.
- Service providers (processors): cloud hosting (Microsoft Azure), email delivery, payment processing, analytics and geolocation providers who process data on our instructions under a written data processing agreement as required by the NDPA.
- Professional advisers and auditors, including our licensed Data Protection Compliance Organisation (DPCO), under confidentiality.
- Authorities and regulators (including the NDPC and NAFDAC) where required by law or to protect rights, safety and property.
- Corporate transactions: to a successor entity in a merger, acquisition or reorganisation, subject to this policy.
8. International (cross-border) transfers
Our platform is hosted on Microsoft Azure in the European Union ([West/North Europe] region). This means personal data collected in Nigeria is transferred to and stored in the EU, and some processors may access it from other countries.
We only transfer personal data outside Nigeria where the NDPA (sections 41–43) and GAID permit it — that is, where the destination provides an adequate level of protection, or where an appropriate safeguard applies (such as contractual clauses / binding data-processing terms), or where a permitted derogation applies (e.g. your consent, or necessity for a contract). The EU is widely recognised as providing a high standard of data protection. You may request details of the safeguards we use by contacting us at [PRIVACY EMAIL].
9. How long we keep your data (retention)
We keep personal data only for as long as necessary for the purposes above, then delete or anonymise it:
- Business account data: for the life of the account and up to
[e.g. 12–24 months]after closure, unless a longer period is required by law. - KYB and billing records: retained for the period required by tax, accounting and anti-fraud law (typically up to
[e.g. 6–7 years]). - Scan events: retained in identifiable/coarse form for
[e.g. 24 months]for fraud analytics, then aggregated/anonymised. - Counterfeit reports: for as long as needed to investigate and for legal-claim purposes.
- Marketing consent records: until you withdraw consent, plus a short proof-of-consent period.
10. How we protect your data
We implement appropriate technical and organisational measures under section 39 of the NDPA, including: encryption of data in transit and of sensitive fields at rest, hashing of passwords and IP addresses, multi-factor authentication, role-based access control and tenant isolation (row-level security), audit logging, and least-privilege access for staff. No system is perfectly secure, but we work continuously to protect your data.
11. Your rights as a data subject
Under the NDPA you have the right to:
- Be informed about how your data is processed (this policy).
- Access your personal data and obtain a copy.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where the law allows.
- Restrict or object to certain processing, including direct marketing.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to request human review (see §13).
- Lodge a complaint with the NDPC (see §17).
12. How to exercise your rights
Email [PRIVACY EMAIL] or write to us at the address in §1. We will verify your identity and respond without undue delay and within the timeframe required by the NDPA/GAID (in principle within one month). Exercising your rights is free unless a request is manifestly unfounded or excessive. If we cannot act on your request, we will explain why and tell you how to complain to the NDPC.
13. Automated processing and fraud scoring
To protect brands and consumers from counterfeiting, we run automated risk scoring on scan events (for example, detecting impossible-travel patterns, unusual scan volumes, or out-of-market activity). This assesses a product unit's authenticity risk rather than profiling you as an individual, and a "suspicious" result does not by itself make any legal decision about you. Where automated processing could significantly affect an individual, you have the right to request human review — contact us at [PRIVACY EMAIL].
14. Children's data
Our services are intended for businesses and adult consumers and are not directed at children under 18. We do not knowingly collect children's personal data. Where the processing of a child's data is required, we will obtain verifiable parental/guardian consent as required by the NDPA. If you believe a child has provided us data, contact us and we will delete it.
15. Data breaches
We maintain a data-breach response plan. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it, and we will notify affected individuals where the breach is likely to result in a high risk, in line with the NDPA and GAID.
16. Data Protection Officer and contact
- General privacy enquiries and rights requests:
[PRIVACY EMAIL] - Data Protection Officer:
[DPO NAME],[DPO EMAIL],[REGISTERED ADDRESS]
17. Complaints and the NDPC
If you have a concern, please contact us first at [PRIVACY EMAIL] and we will try to resolve it. You also have the right to lodge a complaint with the regulator:
Nigeria Data Protection Commission (NDPC)
Website: https://ndpc.gov.ng · Email: info@ndpc.gov.ng
18. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "Last updated" date and, where changes are significant, notify you directly. Please review it periodically.
AuthOrigin