1. Regulatory scope
- Data protection — Nigeria Data Protection Act, EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and comparable US state laws.
- Biometric privacy — BIPA-style statutes and Article 9 GDPR explicit-consent requirements.
- AI regulation — EU AI Act transparency obligations for synthetic media and prohibited-practice restrictions on biometric categorisation and manipulative uses.
- Consumer protection — distance-selling and digital-content rules, transparent pricing and fair-terms requirements.
- Intellectual property — DMCA and EU copyright directives.
- Financial crime — anti-money-laundering, counter-terrorist-financing and sanctions screening performed by us and by our payment providers.
- Telecommunications — provider terms and national rules governing virtual numbers and SMS verification.
- Online safety — child protection, non-consensual intimate imagery and illegal content removal obligations.
2. Operational measures
- Documented policies published in the Legal Center and incorporated into the Terms.
- Consent capture for biometric processing and marketing, with withdrawal paths.
- Retention schedules enforced by automated purge jobs.
- Verification controls for privileged actions and for high-risk accounts.
- Audit logging, incident response and breach notification procedures.
- Provider due diligence, contractual data-protection terms and transfer safeguards.
- Complaint and appeal channels with human review.
3. Sanctions and export controls
Deepacal does not knowingly provide services to persons or entities subject to applicable sanctions, or to users located in comprehensively sanctioned territories. You warrant that you are not such a person and will not export or re-export access to the Services in breach of export-control law.
4. Anti-money-laundering and KYC
Credits cannot be cashed out, transferred or redeemed, which materially limits laundering risk. We nonetheless monitor for structuring, unusual purchase patterns and third-party funding, may require identity and source-of-funds verification, and may refuse, reverse or freeze transactions and report suspicious activity to competent authorities.
5. Law enforcement and legal requests
We respond to valid legal process from competent authorities. Requests should be sent to legal@deepacal.com on official letterhead, specifying the legal basis, the data sought and the account identifiers. We require valid process for content data, narrow requests to what is proportionate, and notify affected users unless legally prohibited or where notice would create risk of harm.
6. Complaints
Compliance complaints may be sent to legal@deepacal.com. You may also complain to your national data protection or consumer authority.