Last updated 24 August 2026.
Attesta provides identity, credit and fraud verification services to businesses ("customers"). This policy explains what personal data we process, why, and the rights of the people that data is about ("data subjects"). It is written to align with Ghana's Data Protection Act, 2012 (Act 843), Ghana's Credit Reporting Act, 2007 (Act 726) and Nigeria's Data Protection Act, 2023 and NDPR.
Attesta operates globally. For the data our customers submit through the API and dashboard, Attesta acts as a data processor on the customer's instructions. For dashboard account data (your name, email, organisation), Attesta is the data controller.
To perform the checks our customers request, to route each check to the appropriate licensed data partner, to bill per check, to keep an audit trail regulators may ask for, and to keep the platform secure.
Verification requests are sent to our licensed identity-verification and credit-bureau partners as instructed by the customer's routing policy. Each response records which source answered. We do not sell personal data and do not share it with anyone else except as required by law.
Data is encrypted in transit (TLS) and sensitive identifiers are encrypted at rest and masked in logs. Access is role-based and every access is logged. Dashboard accounts can enable two-factor authentication.
Verification records are retained for the period set by the customer's retention policy or as required by applicable law, then deleted. Account data is retained while the account is active.
Data subjects may request access to, correction of, or deletion of their personal data, and may object to processing, subject to legal retention duties. Requests about a specific check should go to the business that ran it; we will assist them. You can also write to privacy@attesta.africa.
We will post updates to this policy here and note the date above.