Vepiom policies

Privacy policy

We process bank statements for lenders, which means we handle other people's financial lives. This page explains exactly what we take, what we keep, for how long, and what we will never do with it.

Effective 1 August 2026 Version 0.1 Under legal review

01Two different roles, two different policies

Vepiom handles personal data in two distinct capacities, and the rules differ. Read the one that applies to you.

If you areOur roleWhat governs it
A visitor to this website, or someone who emails or calls us Data controllerSections 2 to 6 below
A loan applicant whose bank statement a lender submitted to Vepiom Data processor acting for that lenderSections 7 to 10 below. The lender is the controller and their privacy notice governs your relationship.

Vepiom is operated by [registered entity name and RC number], registered at [registered office address, Lagos, Nigeria]. You can reach us at info@vepiom.com or +234 806 942 4477.

02What we collect from website visitors

We keep this deliberately small.

  • What you send us. If you request an audit or email us, we receive your name, company, work email, role, stated application volume and whatever you write in the message.
  • Technical request data. Our hosting provider logs IP address, user agent, requested page and timestamp, as every web server does. We use this for security and to keep the site working, not to build profiles.
  • Nothing else by default. This site sets no advertising cookies, runs no third-party analytics tags and carries no tracking pixels. If that changes we will say so here before it does, and ask for consent where consent is required.

The one third-party request the page makes is to Google Fonts for two typefaces. We intend to self-host these and remove that request.

03Why we process it, and on what basis

PurposeLawful basis
Replying to your enquiry and running a free audit you asked for Performance of a contract, or steps taken at your request before one
Sending you the audit report and following up about it Legitimate interests, and your request
Keeping the website secure and availableLegitimate interests
Meeting our accounting, tax and regulatory obligationsLegal obligation

We do not sell personal data. We do not share it with advertisers. We do not use it to train machine learning models, and that includes documents submitted for audits or through the API.

04How long we keep enquiry data

  • Enquiries that do not become customers: 24 months, then deleted.
  • Customer records: for the life of the relationship, then as long as our accounting and tax obligations require.
  • Server logs: 90 days.

05Your rights over your own data

Where we are the controller, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interests. You can also ask for it in a portable format. Email info@vepiom.com and we will respond within 30 days.

We will not charge you, and we will not make you explain why. If you are unhappy with how we handle it you can complain to the Nigeria Data Protection Commission, or to your local supervisory authority if you are in the EEA or UK.

Important

If you are a loan applicant and want your bank statement deleted or corrected, we cannot act on that directly. Contact the lender you applied to. They are the controller and they instruct us. We will help them respond, and we will comply with their instruction.

06Cookies

This site sets no cookies at all. There is nothing to consent to and no banner, because there is nothing to hide behind one. If we add a session cookie for a product login later, this section will be updated to describe it before it ships.

07Documents submitted through the service

When a lender sends us a bank statement, that file contains someone's personal and financial data. We treat it as the sensitive material it is.

What we receive

  • The document itself, and any figures inside it: transactions, balances, counterparty names, account numbers, the account holder's name.
  • Metadata the lender chooses to send: the applicant's name and account number for ownership checks, the expected statement period, and their own internal reference.

What we do with it

  • Analyse it for signs of manipulation and produce a risk score with reason codes.
  • Extract the structured figures the lender asked for.
  • Generate anonymous fingerprints — see section 9.

What we never do with it

  • Train models on it, or use it to improve the service for anyone else, except as anonymous fingerprints and aggregate statistics that cannot be linked back to a person.
  • Share it with another customer, or with anyone outside our documented sub-processors.
  • Sell it, rent it, or supply it to a credit bureau or marketing list.
  • Make a decision about anyone with it. We return evidence. The lender decides.

08How long we keep documents

The core commitment

Source documents are deleted within 72 hours of analysis, by default, on an automated timer. Customers may set a shorter window. Backups follow the same clock, so a deleted document does not survive in a backup.

After that point what remains is:

What we keepHow longContains personal data?
Risk score, reason codes, evidence referencesLife of contract, then 12 months Minimal. Page and row references, amounts.
Extracted figures the customer requestedAs the customer instructs Yes. Held on their behalf.
Document and layout fingerprints24 months No. One-way hashes and layout vectors. A document cannot be reconstructed from them and no person can be identified by them.
Audit log of processing and access24 months Document identifiers and our own staff identities.

09The cross-lender fingerprint network

Customers who opt in contribute anonymous fingerprints to a shared pool, and in return can check against it. If the same forged template appears at four different lenders, all four find out.

This is the part of the product most likely to worry you, so here is exactly what it does and does not carry.

Shared across customersNever shared
One-way document hashes. Perceptual layout fingerprints. Counts and time windows, for example "seen 4 times across 3 institutions in 60 days". Names. Account numbers. Transactions. Balances. The document itself. Which institutions were involved. Which applicants were involved. Anything that would let one customer identify another customer's borrower.

A match tells a lender that a document has been seen elsewhere. It never tells them who, or where, or anything about the person. Participation is opt-in and contractual, and a customer can withdraw, after which their contributed fingerprints are removed from the pool.

10Sub-processors and where data goes

We use a small number of infrastructure providers. Current categories:

PurposeProviderRegion
Application hosting and compute[provider][region]
Encrypted object storage, 72-hour lifecycle[provider][region]
Transactional email[provider][region]
Plain-language summary generation[provider] [region]. Receives reason codes and redacted specifics only, never names, account numbers or full transaction narration. Zero-retention endpoint.

Customers get 30 days' notice before we add or change a sub-processor, and may object.

International transfers

Where data leaves Nigeria or the EEA we rely on Standard Contractual Clauses or an equivalent mechanism, and we assess the destination. Enterprise customers can require in-region processing, in which case their data does not leave the region at all.

11Security

Encryption in transit and at rest, tenant isolation, least-privilege access with multi-factor authentication, immutable audit logging, and isolated sandboxed parsing of untrusted files.

The full picture, including what we have not yet built, is on the security page. We would rather you read an honest account than a list of badges.

12Children

The service is sold to businesses and is not directed at children. We do not knowingly process data about anyone under 18 through the website. Where a lender lends to young adults, any personal data in a submitted statement is processed on that lender's instruction and under their lawful basis.

13Changes to this policy

We will post any change here with a new version number and effective date. For material changes affecting customers we give 30 days' notice by email. We will not reduce the protections described here for data already collected without telling you first.

Questions about anything on this page: info@vepiom.com.