innkorp

Privacy Notice

Last updated 9 July 2026 · Version 2026-07-09

1. Who we are

innkorp is a KYC facilitation and vault service for African SMEs. We help businesses obtain and prepare missing KYC documents, store those documents in a vault that the SME owns and controls, and, only with the SME's explicit consent, share that data with the banks, fintechs and platforms the SME chooses to work with.

This notice is issued under the Nigeria Data Protection Act, 2023 (NDPA) and the NDPC's General Application and Implementation Directive (GAID), 2025. For your vault, innkorp is the data controller of your account and audit records, and your custodian and processor for the documents you store: we act on your instructions. innkorp does not verify your documents against any government or third-party system. That remains the responsibility of the institution you share with.

2. The data we process

Depending on how you use innKorp, we may process:

  • Business details: business name(s), type, category, RC number, TIN, addresses, contact email and phone.
  • Proprietor / director / shareholder details: name, date of birth, BVN, contact details, residential address, ownership percentage, and politically-exposed-person status where applicable.
  • Documents: e.g. CAC certificate, status report, MEMART, TIN certificate, utility bill, board resolution, IDs and other KYC documents you or our partners upload.
  • Account & audit data: one-time passcodes, consent records, and a log of who accessed what and when.

We do not collect your financial account balances, transactions, or savings data.

3. Lawful basis (NDPA s.25)

Our primary lawful basis is your explicit consent, given when you authenticate and approve an action inside the innkorp widget or portal. Consent is specific, informed, unambiguous and logged, and you may withdraw it at any time (see Your rights below). We also rely on performance of a contract for operating your account, and legal obligation where record-keeping is required by law. Documents you store may include identity information; we apply heightened safeguards to all vault contents regardless of sensitivity classification.

4. Automated processing (OCR)

When a document is uploaded we extract its text to verify that it matches the registered business and to read key fields (e.g. RC number, dates). This processing runs on our own infrastructure: your documents are not sent to external OCR services. Verification is assistive, not solely automated: a flagged document is reviewed by a person, and no decision producing legal effects is made by automation alone.

5. How your data is shared

Your data is only shared in two situations, and always with your explicit consent:

  • Facilitation (referral by a fintech). If a fintech refers you while your business is being registered, you may consent to that fintech sharing a minimal, purpose-limited set of data with innKorp so we can facilitate your registration and prepare your documents. That set is limited to:
    • Proposed business name(s)
    • Business type & category
    • Business email & phone
    • Business address
    • Proprietor name & date of birth
    • Proprietor phone, email & address
    • Proprietor BVN (for CAC registration)
    This data is used only for that purpose.
  • Distribution (you share your vault). When you choose to share your vault with a fintech, you select exactly which documents are shared and grant a time-limited access token. The fintech receives only the documents you approved, via short-lived signed links (1 hour).

We never sell your data, and we never share it without a consent record tied to the specific purpose.

6. How we protect your data

  • Documents are stored privately and served only via short-lived signed links, never public URLs.
  • Access tokens are scoped, signed, and expire within 24 hours.
  • Every vault access, consent grant and revocation is logged, and consent receipts can be produced as evidence.
  • Data is segregated so that only you and parties you consent to can access your vault.
  • Administrative access is role-based and protected with two-factor authentication.
  • Data is encrypted in transit (TLS) and at rest by our hosting providers.

7. Where your data is stored and sub-processors

Your data is hosted with vetted infrastructure providers acting as our sub-processors under data-processing terms:

  • Supabase: database and encrypted document storage;
  • Vercel: application hosting;
  • Meta (WhatsApp Business): delivery of one-time passcodes to your phone;
  • Our email delivery provider: transactional emails and passcodes.

Where hosting involves transfer outside Nigeria, we rely on the safeguards permitted under Part VIII of the NDPA, including contractual protections with each provider. A current sub-processor list is available from our DPO on request.

8. Data retention

Your documents remain in your vault for as long as you keep your account, so you can reuse them across institutions without re-entry. You can delete any document, revoke any partner's access, or ask us to erase your vault at any time. Consent and audit records are retained for up to six years after account closure to meet legal and evidential obligations, then deleted.

9. Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high, in line with the NDPA and GAID.

10. Your rights under the NDPA

Under Part VI of the NDPA you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data (you can edit your profile directly);
  • Erase your data (delete documents or your vault);
  • Restrict or object to processing;
  • Withdraw consent and revoke any partner's access, as easily as consent was given;
  • Port your data to another service in a machine-readable format;
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC).

You can exercise most of these directly in your innkorp vault, or by contacting us below. We respond to rights requests within 30 days.

11. Contact

For privacy questions or to exercise your rights, contact our Data Protection Officer at privacy@innkorp.com. If you are not satisfied with our response, you may complain to the NDPC at ndpc.gov.ng.

This notice describes innKorp's data practices. It is provided for transparency and does not constitute legal advice.