Privacy Notice
Effective 1 July 2026. This notice explains what personal data Keepable collects when you use a recipient mailbox, how we use it, who we share it with, and the rights you have under the Nigeria Data Protection Act 2023 (NDPA). It applies to the recipient app at app.keepable.co and to the marketing site at keepable.co. Senders and their corporate users are covered by a separate sender agreement and our Data Processing Addendum.
Ciphersec Limited, a company incorporated in the Federal Republic of Nigeria, is the data controller responsible for your information.
What we collect
We collect only what we need to run a verified digital mailbox.
Identity data. To open your mailbox, we check your Nigerian National Identification Number (NIN) with an accredited identity-verification provider, and a liveness check confirms you are physically present. The raw NIN is used only for that verification and is not retained after it completes. We retain only a keyed one-way hash (HMAC), so we can recognise the same person on a return visit but cannot reverse it to the number.
Account and contact data. Your email address, optional phone number, display name, passkey credentials (public-key material; we never see your private keys or biometrics), and any preferences you set in the app.
Mailbox contents. The documents senders deliver to you, the metadata that lets us route and display them (sender, document type, delivery time), and anything you upload yourself.
Operational data. Sign-in events (device, approximate location derived from IP, time), audit-log entries for actions taken in your mailbox, and the event chain that backs the document seal described in our Security page.
Telemetry. Basic, aggregate product analytics used to detect outages and improve the experience. We do not sell this data and we do not place advertising cookies on the recipient app.
Why we use it
| Purpose | NDPA lawful basis |
|---|---|
| Deliver documents to the right person and let you read, sign, and download them | Performance of a contract with you |
| Verify your identity when you open a mailbox | Performance of a contract; legal obligation where applicable |
| Detect fraud, abuse, and unauthorised access; send security alerts (new-device sign-in, suspicious activity) | Legitimate interest; legal obligation |
| Maintain audit trails and seal evidence | Legal obligation; legitimate interest |
| Respond to your support requests | Performance of a contract |
| Send transactional notifications (a sender delivered a document, a sealed download is ready) | Performance of a contract |
| Send product news, if you opt in | Consent (you can withdraw at any time) |
Who we share it with
We share personal data only with:
- The sender that delivered a specific document to you. Senders see the read and signing events for documents they delivered, so they can confirm that a statement was opened or an agreement signed.
- Our sub-processors, listed below, which help us run the service.
- Law enforcement or regulators, where we are legally compelled to disclose specific information. We will tell you when we are permitted to do so.
- A successor, in connection with a merger, acquisition, or restructuring. The same protections in this notice will continue to apply.
We do not sell your personal data. We do not share it for advertising.
Sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Compute, storage, key management, database, and identity liveness | af-south-1 (Cape Town) |
| Cloudflare, Inc. | CDN, DNS, edge workers | Global edge; data terminates at af-south-1 |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States |
| Prembly | NIN identity verification for recipient onboarding | Nigeria |
Staff sign-in uses a managed identity provider; that is an internal control and does not process your data.
Where your data lives
Our primary processing region is AWS af-south-1 in Cape Town, South Africa. Identity verification stays in Nigeria and liveness runs inside our own AWS region. Where a sub-processor does process data in another jurisdiction (notably Resend for transactional email), we rely on a transfer mechanism permitted under section 41 of the NDPA, including NDPC adequacy decisions where they exist and contractual safeguards with each sub-processor. Write to dpo@keepable.co if you want a summary of these arrangements.
How we secure it
Encryption in transit (TLS 1.2 or higher) and at rest (AWS KMS-managed keys); passkey-only sign-in (no SMS one-time passwords); document seal anchored to a tamper-evident audit log; segregation of the recipient, sender, and staff planes; least-privilege staff access with full audit logging. The Security page goes into more detail.
How long we keep it
We keep your data for as long as your mailbox is open and you are actively using the service. When you close your mailbox we remove your identifying data from active systems within 30 days, except where the law requires us to keep some of it longer (signed and sealed documents, audit-log entries that establish the integrity chain, statutory records). Backups roll off on a 7-day cycle.
Your rights
Under the NDPA you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct data that is wrong or incomplete;
- delete data that we no longer need or that you withdraw consent for;
- give you a portable copy of data you provided to us;
- restrict or object to specific processing;
- withdraw a consent you previously gave (for example, marketing email).
To exercise any of these rights, write to dpo@keepable.co. We respond within 30 days. There is no charge for a first reasonable request.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng. We would prefer the chance to address it first.
Children
Keepable is not directed at children under 18. We do not knowingly create mailboxes for under-18s. If you believe a mailbox belongs to a child, tell us at dpo@keepable.co and we will investigate.
Changes
We will update this notice when our practices or the law change. The “effective” date at the top reflects the current version. For material changes we will tell you in the app or by email before the change takes effect.
Contact
Ciphersec Limited, Lagos, Nigeria. Data protection officer: dpo@keepable.co.
Effective date: 1 July 2026.