Security & Compliance

Compliance Policy

The regulatory regimes we align with and how we operationalise them.

Effective date: 29 July 2026 · Applies to Deepacal, deepacal.com and all Deepacal applications.

1. Regulatory scope

  • Data protection — Nigeria Data Protection Act, EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and comparable US state laws.
  • Biometric privacy — BIPA-style statutes and Article 9 GDPR explicit-consent requirements.
  • AI regulation — EU AI Act transparency obligations for synthetic media and prohibited-practice restrictions on biometric categorisation and manipulative uses.
  • Consumer protection — distance-selling and digital-content rules, transparent pricing and fair-terms requirements.
  • Intellectual property — DMCA and EU copyright directives.
  • Financial crime — anti-money-laundering, counter-terrorist-financing and sanctions screening performed by us and by our payment providers.
  • Telecommunications — provider terms and national rules governing virtual numbers and SMS verification.
  • Online safety — child protection, non-consensual intimate imagery and illegal content removal obligations.

2. Operational measures

  • Documented policies published in the Legal Center and incorporated into the Terms.
  • Consent capture for biometric processing and marketing, with withdrawal paths.
  • Retention schedules enforced by automated purge jobs.
  • Verification controls for privileged actions and for high-risk accounts.
  • Audit logging, incident response and breach notification procedures.
  • Provider due diligence, contractual data-protection terms and transfer safeguards.
  • Complaint and appeal channels with human review.

3. Sanctions and export controls

Deepacal does not knowingly provide services to persons or entities subject to applicable sanctions, or to users located in comprehensively sanctioned territories. You warrant that you are not such a person and will not export or re-export access to the Services in breach of export-control law.

4. Anti-money-laundering and KYC

Credits cannot be cashed out, transferred or redeemed, which materially limits laundering risk. We nonetheless monitor for structuring, unusual purchase patterns and third-party funding, may require identity and source-of-funds verification, and may refuse, reverse or freeze transactions and report suspicious activity to competent authorities.

6. Complaints

Compliance complaints may be sent to legal@deepacal.com. You may also complain to your national data protection or consumer authority.

Related legal documents

See all 31 documents in the Deepacal Legal Center.