HomeServicesAPIPricingDocumentationAboutContact
LoginGet Started

Legal

Acceptable use policy

Identity data can be used to protect people or to harm them. This policy draws the line, and it is part of the agreement you accept when you create an account.

Last updated: 19 August 2026

The principle behind every rule here

A National Identification Number or a Bank Verification Number identifies a person for life. It cannot be reissued after misuse the way a password can. Verify only what you have a lawful reason to verify, and only what you have been asked to verify.

1. What this policy covers

This acceptable use policy applies to everyone who uses IDEX — through the website, the customer dashboard or the REST API — and to anyone acting under your account, including your staff, your contractors and any system holding your API key. It forms part of our terms of service; a breach of this policy is a breach of those terms.

It applies in addition to the law, not instead of it. Something permitted here may still be unlawful in your circumstances, and it remains your responsibility to know that.

2. Lawful basis and consent

When you submit somebody's identifier, you decide why that person's data is processed. Under the Nigeria Data Protection Act 2023 that makes you the controller of that decision, and it obliges you to have a lawful basis before the check is run — not afterwards, and not because the check turned out to be justified.

Before every verification you must be able to answer all four of these questions:

  1. What is my lawful basis? Consent, performance of a contract with the data subject, a legal obligation, or another basis recognised by the NDPA.
  2. If it is consent, can I evidence it? Consent must be freely given, specific, informed and unambiguous, and you must be able to show when and how it was given.
  3. Has the data subject been told? They should know that a verification will be carried out, by whom and for what purpose, unless an exemption applies.
  4. Is this check for that purpose? Data collected to onboard a customer may not be reused to satisfy curiosity, to check on a relative, or to build a list.

Consent obtained for one purpose does not cover another. Consent given once does not last forever. Consent given by an employer does not cover checks on an employee's family. Where you cannot answer all four questions, do not submit the verification.

We may ask you to demonstrate your lawful basis for a specific verification or for a pattern of them, and to do so promptly. We may suspend a service, a key or an account while we ask. Our not asking is not our approval.

3. Uses the platform is built for

The following are typical legitimate uses, provided section 2 is satisfied in each case:

  • Onboarding a customer or an account holder as part of a know-your-customer process you are required or permitted to run.
  • Verifying an agent, a merchant, a rider, a driver or a vendor before granting them access to your platform or your funds.
  • Confirming the identity of an applicant during recruitment, where the applicant has been told and has consented.
  • Confirming the details of a person who has asked you for a service, a loan or a payout, in order to complete that request.
  • Preventing or investigating fraud against your own business, on a specific and reasoned suspicion.
  • Meeting a regulatory, licensing or statutory obligation that requires you to verify identity.

In every one of these, the verification concerns a person who has a relationship with you and a reason to expect it. That is the test.

4. Prohibited uses

You must not use IDEX, or any result obtained from it, for any of the following.

4.1 Locating, monitoring or harassing a person

  • Stalking, tracing, surveilling or attempting to locate an individual.
  • Checking on a former partner, a family member, a neighbour or an acquaintance.
  • Harassing, threatening, intimidating or shaming a person, or enabling somebody else to.
  • Publishing, posting or circulating a person's identifier or verification result — to a group chat, a social platform, a forum or anywhere else.
  • Debt collection or recovery activity conducted by tracing an individual rather than through a lawful process.

4.2 Discrimination and exclusion

  • Using a verification, or a result, to discriminate against a person on the basis of ethnicity, state of origin, religion, gender, disability, health status, political opinion or any other characteristic protected by law.
  • Screening people out of a service, a tenancy, employment or an opportunity on a basis the law does not permit.
  • Profiling communities, screening a list of names for a characteristic, or any comparable exercise.

4.3 Unauthorised background checks

  • Running a check on a person who has not been told and has not consented, where consent is the basis you would have to rely on.
  • Vetting an employee, a tenant, a partner or a counterparty without a lawful basis for doing so.
  • Verifying somebody on behalf of a third party who has no lawful basis of their own, including running checks as a favour or for a fee.
  • Continuing to check a person after the relationship that justified it has ended.

4.4 Bulk harvesting and enumeration

  • Submitting identifiers in bulk in order to build, enrich, validate or clean a database.
  • Enumerating identifiers — sequential, random or generated — to discover which ones exist.
  • Speculative or exploratory lookups against people with whom you have no relationship.
  • Testing a stolen or leaked list of identifiers against the platform for any reason.
  • Storing results in a general-purpose repository that can be searched by anyone in your organisation regardless of need.

4.5 Resale and onward supply

  • Reselling, sublicensing, brokering or white-labelling access to the platform without a written reseller or partner agreement with us.
  • Offering a verification service to the public using your account as the back end.
  • Sharing an account or an API key with another business, or letting a third party submit through your credentials.
  • Selling, licensing or trading a verification result, or supplying it to anyone who does not need it for the purpose the data subject was told about.
  • Building a competing verification service, a lookup directory or a search interface over identity data using results obtained here.

4.6 Misrepresentation

  • Presenting IDEX, or a result from it, as an official, governmental or regulatory certification. It is not one.
  • Claiming or implying that you or we are affiliated with, endorsed by or acting for NIMC, NIBSS, the Central Bank of Nigeria or any government body.
  • Impersonating a law enforcement officer, a regulator, a bank or another organisation in order to justify a check.
  • Giving false information when you register, or concealing who is really using the account.
  • Altering or fabricating a result and presenting it as one the platform returned.

4.7 Attacks on the platform and on others

  • Circumventing or attempting to circumvent authentication, authorisation, rate limiting, pricing or an availability control.
  • Creating multiple accounts to evade a limit, a price, a suspension or a block.
  • Probing, scanning or testing the security of the platform without our written permission, other than reporting a vulnerability you encountered in normal use.
  • Accessing, or attempting to access, another customer's account, data, wallet or verification records.
  • Scraping the site, reverse engineering the software, or interfering with its operation.
  • Introducing malware, or using the platform to distribute it.
  • Any activity that places an unreasonable load on the platform or on a provider.

4.8 Unlawful and harmful activity generally

  • Fraud, identity theft, money laundering, terrorist financing or the evasion of sanctions.
  • Opening or operating an account in a false name, or on behalf of an undisclosed person.
  • Anything that breaches the Nigeria Data Protection Act 2023, the Cybercrimes (Prohibition, Prevention etc.) Act, or any other applicable law.

5. Your own obligations to data subjects

Because you are the controller of the checks you instruct, you must also:

  • keep results only as long as your stated purpose requires, and delete them afterwards;
  • restrict access to results inside your organisation to people who need them;
  • keep your own record of the lawful basis for each check, so you can answer a data subject or a regulator;
  • respond to a data subject who asks you why a check was run — we will direct them to you;
  • tell us promptly if you learn that a check was run without a lawful basis, or that results have been exposed; and
  • secure your credentials, so that nobody runs a check in your name that you did not authorise.

6. How we monitor compliance

We look at the shape of platform usage, not at the substance of your results. In practice that means volumes, submission patterns, failure and not-found rates, sudden changes in behaviour, credential sharing signals and abuse reports.

Verification results are encrypted at rest and are not browsed by our staff. Where an investigation genuinely requires access to a specific record, it is authorised, limited to that record, and written to the audit log with the identity of the person who performed it.

Automated controls may throttle or block a request in real time. Those controls are protective and can be reviewed on request.

7. Consequences of a breach

What we do depends on what happened. We would rather correct a misunderstanding than close an account, but we will close an account without hesitation where people are at risk.

SituationWhat we do
A pattern we do not understand We ask you to explain it and to demonstrate your lawful basis.
An isolated or apparently inadvertent breach A written warning, and a requirement to confirm what you have changed.
Excessive volume, enumeration or automated abuse Rate limits reduced, keys scoped down, or the service throttled for your account.
A serious or repeated breach, or a refusal to explain Immediate suspension of the account, the service or the affected API key.
Use that endangers a person, or clear unlawful conduct Immediate termination, retention of the evidence, and a report to the appropriate authority.

Suspension or termination does not refund amounts already spent. Any unused balance is handled under section 8 of the terms of service, and may be held where it is subject to an investigation or a legal hold. Where a breach causes us loss — including a claim by a data subject, a regulator or a provider — the indemnity in the terms of service applies.

We will tell you what we have done and why, unless telling you would be unlawful or would defeat the purpose of the action. You may ask us to review any decision by writing to the contact in section 8.

8. Reporting abuse

If you believe IDEX is being used in breach of this policy — or that your own identifier has been submitted without a lawful basis — tell us. Reports are taken seriously and are investigated.

Use the contact form with Abuse report in the subject line, and include:

  • what you believe is happening, in plain terms;
  • any account name, business name, reference or key identifier you know of;
  • dates, times and anything else that helps us find the activity;
  • how the conduct affected you or somebody else; and
  • how we can reach you if we need more detail.

Do not include a full NIN or BVN in your report. A masked identifier or a verification reference is enough for us to find the record, and sending the full value creates the very exposure you are reporting.

We acknowledge abuse reports within one business day and will tell you the outcome where we can do so without breaching somebody else's privacy. We do not disclose the identity of a reporter to the party reported, and we will not retaliate against a customer who reports in good faith.

For a suspected vulnerability rather than a misuse, use Security report as the subject line instead — see our data protection page. Either report can also be sent directly to support@idex.com.ng.

9. Changes to this policy

We update this policy as the platform changes, as new patterns of misuse appear and as the law develops. The date at the top of this page shows when it was last revised, and we will give notice of a material change before it takes effect. Continuing to use the platform after that date means you accept the revised policy.

Related documents: terms of service, privacy policy, data protection.