Trust Center

Your data is our responsibility.

16 formal security policies. End-to-end encryption. ISO 27001 alignment. Here is how we protect what belongs to you.

🇳🇬NDPA
🏦CBN
📶NCC
🔐AES-256
🛡️ISO 27001 Aligned
📋SOC 2 (Planned)

Documentation.

Public policies, processing agreements, and internal security documentation.

Public

Privacy Policy

How we collect, use, and protect your personal information.

Public

Terms of Service

The terms governing your use of Zeyntra's platform and services.

Public

Cookie Policy

How we use cookies and similar tracking technologies.

Public

Acceptable Use Policy

What is and isn't permitted on our platform.

NDA Required

Data Processing Agreement

How we process personal information on behalf of our customers.

NDA Required

Security Overview

High-level summary of our security practices and compliance posture.

Restricted

Information Security Policy

Our comprehensive security governance framework aligned to ISO 27001:2022.

Restricted

Identity and Access Management Policy

How we manage authentication, authorization, and access lifecycle.

Restricted

Access Control Policy

Rules governing who can access what, and under which conditions.

Restricted

Incident Response Policy

How we detect, respond to, and recover from security incidents.

Restricted

Business Continuity and DR Plan

How we maintain operations and recover from disruptions.

Restricted

Data Classification and Handling

How we categorize and handle data based on sensitivity.

Restricted

Cryptography Policy

Standards for encryption, key management, and cryptographic controls.

Restricted

Secure Development Policy

How we build and deploy secure software.

Restricted

Third-Party Management Policy

How we assess and manage vendor and partner risk.

Restricted

Risk Management Policy

Our framework for identifying, assessing, and mitigating risk.

Security controls.

The measures we maintain to protect your data.

Encryption at Rest

All stored data encrypted with AES-256.

Encryption in Transit

All data transmitted over TLS 1.3.

Multi-Factor Authentication

MFA enforced for all admin and production access.

Role-Based Access Control

Least-privilege access based on documented business need.

Continuous Monitoring

Automated alerting for suspicious access patterns.

Vulnerability Management

Regular scanning, patching, and penetration testing.

Automated Backups

Encrypted backups with tested recovery procedures.

Employee Security

Background checks, training, and 24-hour departure revocation.

Environment Isolation

Production, staging, and dev fully separated.

Regional Hosting Priority

Infrastructure hosted in-region where available.

Data practices.

What we collect

  • Name, date of birth, government IDs
  • Email, phone, mailing address
  • Financial information (for screening and PAD)
  • Rental history and lease details

How we store it

  • Encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Canadian-hosted infrastructure where available
  • Automated encrypted backups
  • Full environment separation

Who can access it

  • Authorized personnel with RBAC and documented need
  • MFA required for all administrative access
  • Monthly and quarterly access reviews
  • No shared accounts permitted

Your rights

  • Access your personal information
  • Correct inaccurate data
  • Request deletion (subject to legal retention)
  • Withdraw consent at any time

Sub-processors.

Categories of third parties that process data on our behalf. Zeyntra is vendor-agnostic.

Category

Identity Verification

Purpose

NIN and BVN verification

Examples

Smile Identity, Dojah

Data

NIN, BVN, biometric data

Location

Nigeria

Category

Payment Processing

Purpose

Bank transfer and card payments

Examples

Paystack, Flutterwave, OPay

Data

Banking info, transaction data

Location

Nigeria

Category

Cloud Infrastructure

Purpose

Application hosting and data storage

Examples

AWS, Supabase, GCP

Data

Encrypted application data

Location

Nigeria, US

Category

Communication Services

Purpose

Transactional email, SMS, and WhatsApp

Examples

Resend, Twilio

Data

Email, phone number

Location

US

Category

Analytics and Monitoring

Purpose

Product analytics and error tracking

Examples

PostHog, Sentry

Data

Anonymized usage data

Location

US

Get in touch.

We reply to every inquiry within one business day.

Common questions.