Privacy Policy
What we collect, the two very different roles we play, and the things we have committed never to do with your data.
LAST UPDATED · 21 SEPTEMBER 2026
01Who we are
Blepo is a product of Blepo, a company registered in Nigeria (RC [REGISTRATION NUMBER]), with its registered office at Lagos, Nigeria.
In this policy, “we”, “us” and “Blepo” mean Blepo. “You” means whoever is reading a visitor to this website, a person whose organisation uses Blepo, or a person who happens to be on a site where Blepo is installed.
This policy is written to the Nigeria Data Protection Act 2023 (NDPA). Where a customer operates in a jurisdiction with additional requirements, those are dealt with in the agreement we sign with that customer rather than here.
02The two roles and why the difference matters to you
Blepo handles personal data in two entirely separate capacities, and your rights differ depending on which one applies. This is the most important section on this page.
AS A CONTROLLER
Our own website and accounts
When you browse this site, request a demo, email us or hold a Blepo login, we decide why and how that data is used. We are the data controller and this policy governs it directly.
AS A PROCESSOR
Everything the platform observes at a site
Camera health readings, device observations, alerts and any footage involved belong to the organisation that owns the site. They are the controller. We act only on their documented instructions, under a Data Processing Agreement.
The practical consequence: if you are a member of staff, a visitor or a contractor at a site monitored by Blepo and you want to exercise a right over what was observed, your request goes to the organisation that controls that site, not to us. We will help them answer it. If you approach us directly we will tell you who the controller is, so long as doing so does not itself breach their rights.
03What we collect
As controller our website and your account
- Enquiry details — name, work email, phone number, company and whatever you put in the message field when you contact us or book a demo.
- Account details — name, work email, hashed password, role and the organisation you belong to.
- Billing details — company name, billing contact, invoice history. Card details are handled by our payment provider and never reach our servers.
- Technical data — IP address, browser and device type, pages viewed and approximate location derived from IP.
As processor — data from a monitored site
- Device and site records — what equipment exists, where it is, how it is reached. Mostly not personal data, but it describes premises.
- Observations and attestations — the signed record of whether each device was working, and when. These are readings about equipment, not about people.
- Detection events — where the detection layer is enabled: that a person or vehicle was present in a defined zone at a time, with appearance attributes such as clothing colour. Appearance, never identity.
- Short event clips — seconds long, attached to an alert, with a hard expiry. Blepo never holds continuous video.
- Facial verification data — only where a customer has separately licensed that module. See section 06.
04What we will never do
These are limits on the business, not preferences we can quietly revise. They are written here because a commitment you cannot check is not a commitment.
We do not sell raw footage. Not to insurers, not to advertisers, not to anyone.
We do not sell identity data. No face templates, no name lists, no person-level records leave Blepo as a product.
We do not run one-to-many face search. There is no query in our system capable of matching a face against every enrolled person. The database is built so that it cannot be done, not merely so that it is not offered.
We do not grant bulk access to state actors absent lawful process. A valid court order or statutory demand is answered; an informal request is not.
We do not use customer site data to train models for other customers without a specific, separately signed agreement with the controller.
Where we build a product from aggregate data for example an attestation report for an insurer it is built from attestations and derived metadata, under an agreement with the specific customer whose sites are involved, and never across customers who have not agreed.
05Lawful basis
Under section 25 of the NDPA, we rely on the following:
| Purpose | Basis |
|---|---|
| Responding to an enquiry or demo request | Steps at your request prior to a contract |
| Providing the platform to a customer | Performance of a contract |
| Billing, tax and statutory records | Legal obligation |
| Keeping the service secure and diagnosing faults | Legitimate interest |
| Marketing email to a business contact | Consent, withdrawable at any time |
| Facial verification | Explicit consent of the enrolled person |
Where we act as processor, the lawful basis for monitoring a site is established by the site’s controller, per site, not once by us on their behalf. Our agreement requires them to have it, to display the notices their jurisdiction requires, and to tell us if it changes.
06Facial verification the gated module
Facial verification is off by default, licensed separately, and structurally separable from the rest of Blepo. A deployment that has not licensed it carries none of its data.
- One-to-one only. A comparison is always against one named enrolment that the customer has already identified. It answers “is this the person you said it would be?” and cannot answer “who is this?”
- Consent is evidenced, not assumed. Every enrolment carries a recorded consent event with evidence attached. Where consent cannot be evidenced, enrolment does not proceed.
- Templates, not photographs. We store an encrypted mathematical template. Source images are not retained after enrolment.
- Withdrawal deletes within 72 hours. The deletion is recorded so that it can be proven. The audit trail of past verification attempts survives the template, as required for accountability, but it can no longer be used to recognise anyone.
- No name is stored by us. An enrolment is keyed to the customer’s own staff or contractor reference.
07How long we keep it
| Data | Retention |
|---|---|
| Website enquiry that does not become a customer | 24 months |
| Account data | Life of the account, then 90 days |
| Invoices and tax records | 6 years statutory |
| Device observations | Set by the customer, 90 days by default |
| Short event clips | Hard expiry, 30 days by default |
| Face templates | Until consent is withdrawn or the enrolment expires |
| Attestation records | Retained see the note below |
One exception, stated plainly. The attestation log is an append-only chain in which each entry commits to the one before it. When observations are deleted under a retention policy, the attestation entries that covered them remain, because removing a link would destroy the integrity of every record after it. What remains is a cryptographic digest and a timestamp not the underlying readings, and not anything that identifies a person. We would rather disclose this than have you discover it.
08Where it is stored, and transfers out of Nigeria
Continuous video never leaves the customer’s premises. Blepo reads recorders and devices in place and transmits only status readings, structured events and short clips. This is an architectural constraint, not a setting.
Cloud infrastructure is hosted in [HOSTING REGION] with [CLOUD PROVIDER]. Where that is outside Nigeria, the transfer is made on the basis of [TRANSFER MECHANISM — adequacy decision, standard contractual clauses, or the customer’s explicit instruction], as required by sections 41 to 43 of the NDPA.
A customer requiring in-country residency should raise it before contracting. We will tell you honestly whether we can meet it.
09Who else touches the data
We use a small number of sub-processors. Each is bound by contract to terms no weaker than these.
| Provider | Purpose | Location |
|---|---|---|
| [CLOUD PROVIDER] | Hosting and storage | [REGION] |
| [MESSAGING PROVIDER] | WhatsApp and email alert delivery | [REGION] |
| [PAYMENT PROVIDER] | Card processing and invoicing | [REGION] |
| [EMAIL PROVIDER] | Transactional and account email | [REGION] |
We notify customers before adding a sub-processor that handles their site data. We do not share personal data with anyone else except where the law requires it, and we will tell the affected customer unless we are legally barred from doing so.
10Security
- Encryption in transit — TLS on every connection, with certificate validation.
- Credentials at rest — recorder and device credentials are encrypted with per-site keys. They are never written to logs and never appear in support tooling.
- Signing keys stay on site — the private key an agent uses to sign its readings never leaves the customer’s premises. A breach of our cloud would let an attacker read or delete, but not forge a past attestation.
- Read-only at the edge — the agent can read a recorder but cannot write to one or change its configuration.
- Append-only audit — every credential access and configuration change is recorded and cannot be edited.
- Least privilege — role-based access scoped to the site level, reviewed [REVIEW CADENCE].
No system is perfectly secure and we will not claim otherwise. If you believe you have found a vulnerability, email info@blepo.io with the detail and we will acknowledge within two working days.
If a breach occurs that is likely to result in a risk to people’s rights, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware, and the affected controllers without undue delay.
11Your rights
Under the NDPA you may ask us to:
- tell you what personal data we hold about you, and give you a copy
- correct it where it is wrong
- delete it, where we have no overriding obligation to keep it
- restrict or object to how we use it
- port it to another provider, where it is technically feasible
- withdraw consent at any time, where consent is the basis we relied on
Email info@blepo.io. We respond within 30 days and will not charge you unless a request is manifestly excessive, in which case we will tell you the cost before doing the work.
Where we hold the data as a processor for a customer, we will forward your request to that controller and support them in answering it.
If you are unhappy with our response you may complain to the Nigeria Data Protection Commission at ndpc.gov.ng. We would rather you came to us first, but you do not have to.
12Cookies
This site uses only what it needs to work: a cookie remembering your light or dark theme preference, and session cookies where you are signed in. [IF AND WHEN ANALYTICS ARE ADDED, NAME THE PROVIDER HERE AND ADD A CONSENT BANNER do not add analytics without updating this section.]
You can block cookies in your browser. The theme toggle will stop remembering your choice; nothing else breaks.
13Children
Blepo is sold to organisations and is not directed at children. Where a customer operates Blepo at a school or any site where children are present, that customer is the controller and is responsible for the lawful basis, the notices and any consent required. We will not knowingly enrol a child in the facial verification module.
14Changes to this policy
We will update the date at the top when this changes. Where a change materially affects how we handle personal data, we will email account holders at least 30 days before it takes effect, rather than relying on you to notice.
15Contact
Blepo
Lagos, Lagos, Nigeria
info@blepo.io
Data protection contact: [DPO OR RESPONSIBLE PERSON NAME AND EMAIL]