Last updated: 26 August 2026
1. Introduction
This Privacy Policy explains how Nuvett ("the platform", "we", "us", "our") collects, uses, and protects personal information when you use our AI-assisted hiring and candidate-assessment platform. It is written to meet the requirements of the Nigeria Data Protection Act 2023 (NDPA) and its General Application and Implementation Directive (GAID), and it describes what the platform actually does.
2. Who Is Responsible for Your Data
For most processing on this platform, Nuvett is the data controller — we determine the purposes and means of the processing. This applies to identity verification, liveness checks, the selfie-to-ID face match, the cross-tenant biometric registry, duplicate detection and duplicate-registration blocking, remote proctoring, and assessment and interview scoring. Nuvett alone sets the purposes, methods, thresholds, and retention for these activities; employers cannot see or configure them.
Nuvett acts as a data processor only for role and vacancy data that employers supply and that we process on the employer's behalf.
3. Information We Collect
Depending on how you use the platform, we collect:
- Account information — name, email, phone number, date of birth, gender, the country and city you provide in your profile, and login credentials for candidates, employers, and administrators.
- Account sign-in records — the date, time, and the country from which each sign-in to your account occurs, kept for security and account administration. The country is derived from your network location at the time of sign-in — separate from the country you enter in your profile — and this record does not include your IP address or the device you used. For employer accounts, these sign-in times and countries are visible to the company's account owner and administrators, so a company can see when — and from which country — members of its own team have signed in.
- Profile and application information — education, work experience, skills, salary expectations, and other details candidates provide.
- Your CV (if you upload one) — you can add a CV to your profile. We store it in private storage and share it with the employers you apply to, so a person there can read it as part of your application. When an employer views your application, we also run an automated text check that compares your CV against details you gave us in that application — for example a certification or tool you confirmed — and shows the employer where your CV does not mention something you stated, as a prompt to ask you about it, never as a judgement and never affecting any score or automated decision. This check reads your CV's text only at that moment and keeps nothing from it: we do not extract, store, or retain any text from your CV. You can replace or remove your CV at any time, and account erasure deletes it immediately.
- Assessment data — responses to assessments (cognitive, knowledge, work-style, case study, interview, and situational-judgment), scores, and AI-generated summaries.
- Interview and presentation recordings — the AI interview and the case-study presentation are recorded (video and audio). The recording uploads from your browser directly to our private storage; our voice-integrity service (hosted on Fly.io, in France) then extracts a compressed audio-only copy of it for transcription and runs voice-activity and speaker-count checks for assessment integrity; the audio copy is sent to OpenAI for transcription and deleted immediately afterwards; the text transcript is scored by Anthropic; and the employer for the role you applied to can view the stored video through the platform.
- Room scan recording — where the room scan is enabled, you record a short video (about 25 seconds, no audio) of your testing space with your phone's camera immediately before an assessment begins, from the position you will sit the test in. You perform this recording yourself and can see exactly what it captures while you record it. It uploads from your phone directly to our private storage; no automated analysis of any kind is run on it — it is never judged, scored, or scanned by software. The employer for the role you applied to can view it through the platform as a record of the testing environment at the start of the session. It documents the space at that moment only; it does not monitor the space during the assessment. Performing the scan is optional: you can decline, or continue if your device cannot record, and the assessment proceeds either way — the employer simply sees that the scan was not performed or was unavailable.
- Identity verification data — your verification selfie, a liveness check, images of your government ID document (front and back), your government ID number (which you type in — we never extract it from the document image), and the result of the face match between your selfie and the photograph on your ID.
- Facial templates (biometric data) — a numeric template computed from your verification selfie, used for identity checks and — only with your separate consent — for duplicate detection (see Section 6).
- Date of birth — collected at registration and, with your registry consent, also used together with your facial template for duplicate detection.
- Proctoring and integrity events — during proctored assessments, discrete integrity events (see Section 7).
- Usage data — the pages you use and actions you take on the platform, used to operate and secure the service. Your IP address is processed transiently for rate limiting and abuse prevention and is not retained; we do not store the IP address or the device you used to sign in. At sign-in, an approximate country may be derived from that transient network location and kept as part of your sign-in record (see above) — we retain only the country, never the IP address, and not the region or city.
4. Identity Verification — the Two Stages
Identity verification on Nuvett happens at up to two distinct stages. They work differently, and it matters which one applies to you.
Stage 1 — Registration (in-house; no third party). When you register as a candidate you capture a selfie, complete a liveness check, capture your government ID document, and the platform compares your selfie to the photograph on the ID. This runs entirely on Nuvett's own infrastructure, and the facial analysis is performed in your own browser on your device. No third-party identity provider is involved, and your document is not checked against government records at this stage. What this stage establishes is that the person present at registration matches the document they presented — nothing more.
Stage 2 — Hire-stage verification (Smile Identity). When an employer invites you on a role that requires identity verification, you are asked to complete an additional check through Smile Identity, a specialist identity-verification provider that validates your government ID against government records. This is the authoritative identity check and the only step at which your identity is checked against government records.
Smile Identity can validate the government IDs of the countries it operates in; our integration currently offers Nigerian and Kenyan government IDs. If your government ID is not among those supported, you will not be able to complete this check and no verification badge is issued — the employer then decides how to proceed. (Separately, the Stage 1 selfie-to-ID comparison described above is performed in-house on every candidate regardless of country, and involves no third party.)
For candidates who complete Smile Identity verification:
- What Smile Identity receives: a live selfie (SmartSelfie), your government ID details, and identity attributes needed to run the check.
- What it does: validates your document and identity against government records and returns a signed result.
- Where it processes: on Smile Identity's own infrastructure; its processing locations are described in Smile Identity's privacy notice. Transfers outside Nigeria are made on your consent (see Section 9).
- When it happens: only when an employer invites you on a role that requires identity verification. The check is employer-funded — the employer pays for it, never you. You initiate it yourself, and you may decline — if you decline, no data is sent to Smile Identity; your profile simply shows no verification badge, and the employer decides how to proceed with your application.
- What comes back and what we keep: the signed verification result produces a verification badge on your profile. Nuvett also retains the selfie captured by Smile Identity and compares it, on our own infrastructure, against your registration selfie as an anti-impersonation check. This means we hold a second biometric image of you from this stage. A mismatch on that comparison is a review signal for Nuvett administrators only — it never automatically rejects you.
5. Automated Processing, AI, and Your Right to Human Review
We use AI to help score assessment responses, transcribe and score recorded interviews and presentations, and organize and summarize information for employers. AI outputs are inputs to a human decision — a person at the employer makes every hiring decision. You are told before an AI interview begins that AI is used.
You have the right to human review of any automated score. To invoke it, email dpo@getnuvett.com with your account email and the role concerned, or raise it with the employer. A person will review the scored material and respond.
6. The Biometric Duplicate-Detection Registry
To keep hiring fair and prevent duplicate or fraudulent accounts, Nuvett operates a duplicate-detection registry. It works only with your separate, explicit consent, requested before any capture:
- With your consent, a numeric facial template computed from your verification selfie is stored in a secure identity registry.
- The registry runs a one-to-many (1:N) similarity search across all candidate accounts on the platform — across every employer — to detect the same face registering more than once.
- Registry entries are kept for a fixed retention period — currently 179 days — and are then deleted automatically. Deleting your account also removes your registry entry, and you can request deletion at any time.
- Registry results are visible to Nuvett administrators only. Employers never see the registry.
- A facial match on its own never automatically rejects or blocks anyone — it only flags the account for Nuvett's review.
- Duplicate registrations are blocked on three definitive signals: the same email address, the same government ID number, or the same face combined with the same date of birth as an existing account. If you believe a block is wrong, contact support@getnuvett.com.
- If you decline registry consent, no facial template is stored and identity verification is paused until you consent — your choice is recorded and you can change it at any time.
7. Proctoring: What Actually Happens
Where an employer enables proctoring, the platform monitors the assessment session as follows: it periodically compares the face on camera against your stored reference image (to confirm the verified candidate is still the person present), and periodically runs object detection on the camera frame (to detect, for example, a phone or an additional person). All of this analysis happens on your own device, in your browser. No continuous video of a proctored test session is transmitted or stored during the assessment. What is recorded from the monitoring is the set of discrete integrity events (for example, "second person detected at minute 12"), the numeric results of the periodic face comparisons, and, where automated detection flagged specific moments, a short written summary of those moments. That summary is produced by reviewing only the flagged frames; the flagged frames themselves are reviewed and then discarded, never stored. The numeric results of the face comparisons are distance values only, never an image or a face template. They are retained for a limited period — currently 179 days — to calibrate the accuracy of the checks, they are visible only to Nuvett and never to employers, and they are deleted with your account. Three recordings are the exceptions, and each is stored: the AI interview and the business-case presentation, which are recorded as part of the assessment itself, and the pre-assessment room scan, a short video of your testing space that you record yourself before the session starts (all described in Section 3). The room scan is a record of the space at the start of the sitting; it does not monitor the space during the assessment, and nothing about it is judged automatically.
For the recorded interview, the recording's audio is additionally analysed on our voice-integrity service (see Section 3): voice-activity detection checks for speech outside your answer windows (a background voice), and speaker-count analysis checks whether more than one distinct voice answered. These produce integrity events only, never an enrolled voiceprint, and nothing is persisted from that analysis beyond the events themselves.
Proctoring outputs, including the audio-integrity events, are advisory context for the employer's review. They do not contribute to your assessment score and are not used to automatically reject candidates.
8. Lawful Bases for Processing
Under the NDPA, we process personal data on the following bases:
- Consent — for all biometric and other sensitive personal data (your selfie, liveness data, facial templates, ID document images, registry enrolment, and — for candidates in supported African countries — hire-stage verification through Smile Identity), for the AI interview, and for transfers of personal data to jurisdictions without an NDPC adequacy decision.
- Contract — to create and operate your account, deliver assessments, and provide the platform services you and employers sign up for.
- Legitimate interests — fraud prevention and platform integrity: duplicate detection, impersonation prevention, proctoring integrity events, and security logging.
- Legal obligation — where we must retain or disclose information to comply with applicable law or a competent regulator.
9. How We Share Information
We share personal information only as needed to operate the platform:
- With employers — your profile, assessment results, recordings for roles you applied to, and verification status are shared with the employer whose role you applied to. Employers never see the biometric registry, your facial templates, or your ID number.
- With service providers (sub-processors) — named providers who help us operate the platform, listed publicly on our Trust & Compliance page, including Smile Identity (hire-stage identity verification for candidates in supported African countries), Fly.io (the voice-integrity service that processes interview and presentation recordings), cloud hosting, AI transcription and scoring, email, and payments — each under data-protection terms. Where a provider processes data outside Nigeria in a jurisdiction without an adequacy decision, we rely on your consent and appropriate safeguards.
- For legal reasons — where required by law, regulation, or valid legal process.
We do not sell personal information.
10. Data Retention
Retention differs by data type:
- Biometric registry templates — a fixed period — currently 179 days — from enrolment, then deleted automatically. This period runs regardless of any hiring outcome.
- Verification selfies and ID document images (from registration, and the retained hire-stage Smile Identity selfie) — kept for the same period as the biometric identity check that produced them — currently 179 days — then deleted automatically; account erasure removes them immediately at any time. We do not keep the face image longer than the identity data derived from it.
- Interview and presentation recordings and transcripts — kept while your account exists so employers can review them; deleted when your account is erased. The compressed audio-only copy created for transcription is transient: it is deleted immediately after transcription completes, and account erasure also sweeps any copy left behind by an interrupted run.
- Room scan recordings — deliberately kept for less time than any other recording, because this is video of your home or private space. The video is deleted automatically after a fixed period — currently 15 days — or when the application it belongs to reaches a final outcome (hired or not selected), whichever comes first — and account erasure removes it immediately at any time. After deletion, the employer's report shows only that a scan was recorded on a given date and has since been deleted.
- Profile, application, and assessment data — kept while your account exists; deleted or anonymised on erasure.
- Proctoring and integrity data — the integrity events, the numeric face-comparison results (distance values only, never an image or a face template), and any flagged-moment summaries are kept for a limited period — currently 179 days — and are deleted when your account is erased. The flagged frames themselves are never stored (see Section 7).
- Account sign-in records — the sign-in log (which member, their company, the sign-in country, and the time) is kept for 12 months, then automatically deleted. This is the security and account-administration record described in Section 3.
- After account erasure — a minimal, redacted deletion record is retained to honour the erasure and to enforce any account ban; your email is released for future registration unless banned.
- Legal holds — where law requires longer retention, we keep only what the law requires, for as long as it requires.
You can delete your account (and trigger erasure of the above) from your candidate dashboard at any time.
11. Security
We protect personal data with technical and organizational measures including encryption in transit and at rest, role-based access control, private storage buckets with short-lived signed access, and audit logging. No method of transmission or storage is completely secure, but we work to safeguard your data and to limit access to it.
12. Your Rights
Under the NDPA you have the right to access your personal data, correct it, delete it, restrict or object to processing, data portability, and to withdraw consent at any time (withdrawal does not affect processing already carried out). To exercise any of these rights, contact dpo@getnuvett.com.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) — see ndpc.gov.ng for how to complain. We would appreciate the chance to address your concern first, but you may go to the NDPC directly at any time.
13. Cookies
We use strictly necessary cookies and browser storage to sign you in, keep your session secure, and remember your in-progress work. These are essential to the service. We do not use advertising or cross-site tracking cookies. Where we introduce any non-essential cookies, the cookie banner lets you accept or reject them — rejecting never affects your ability to use the platform.
14. International Transfers
Nuvett operates across multiple countries and some of our sub-processors process data outside Nigeria. Where personal data of individuals in Nigeria is transferred to a jurisdiction without an NDPC adequacy decision, the transfer is made on your consent and under contractual safeguards with the receiving provider, consistent with the NDPA.
15. Children
The platform is for people of legal working age. Registration requires a date of birth and is restricted to people aged 21 to 76 — we do not knowingly collect personal information from children, and the age restriction is enforced at registration.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or by other appropriate means. Continued use after changes take effect constitutes acceptance of the revised policy.
17. Contact Us
Data Protection Officer: dpo@getnuvett.com
General enquiries: info@getnuvett.com
Regulator: you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at any time.