SPBS SPBS Certificate Verification Initiative
Login
Login

Legal information

Privacy Policy

Last updated: 29 August 2026

This Privacy Policy explains how the SPBS Certificate Verification Initiative portal (the “Platform”), provided with Risk Control Services as service partner, collects, uses, shares and protects personal data. It applies to visitors, authorised company users, administrators, people whose education records are searched, and members of the public who use a certificate verification link.

1. Who may use the Platform

Portal accounts are created by authorised administrators; there is no public self-registration. Company users must use the Platform only for an authorised and lawful verification purpose. The Platform is intended for adults and authorised business use, and is not directed to children for independent use.

2. Information we collect

Depending on how you use the Platform, we may process:

  • Account and company data: name, work email, phone number, company name/domain, role, account status, login and security information.
  • Search data: student name, institution, course, qualification, session/year, search criteria, result status and limited result identifiers.
  • Certificate data: student name, institution, qualification, course, session, grade where available, verification code, certificate status, expiry and view information.
  • Record-request data: information supplied when asking the support team to investigate a record, administrator notes and resolution status.
  • Payment and wallet data: credit quantity, amount, currency, invoice and payment references, payment status and wallet transactions. Card details are entered with the payment provider and are not intended to be stored by this Platform.
  • Public verification data: viewer email/domain, verification code, access/payment decision, reference, request/payment/view times, IP address and browser user-agent.
  • Technical and audit data: IP address, browser/device information, session data, timestamps, activity descriptions, security events and error logs.
  • Communications: information you include in emails, support requests, forms or other communications with us.

3. How we obtain information

Information may come from you, your employer or company administrator, an education-record source connected to the Platform, payment providers, service providers, or automatically from your browser and use of the Platform.

4. Why we use information

We process information where necessary to:

  • create, secure and administer authorised accounts;
  • perform requested education-record searches and show authorised results;
  • generate, store and verify certificates and Not Found Certificates;
  • process payments, invoices, credits, commissions and remittances;
  • investigate record requests and send status notifications;
  • prevent fraud, misuse, scraping and unauthorised access;
  • maintain audit trails, troubleshoot errors and improve reliability;
  • comply with legal, regulatory, contractual and dispute-resolution obligations; and
  • communicate about the service and respond to enquiries.

Our lawful basis may include performance of a contract, compliance with a legal obligation, legitimate interests in operating and securing a professional verification service, consent where required, and the establishment, exercise or defence of legal claims. The organisation requesting a background check remains responsible for obtaining any consent or other lawful authority required for its search.

5. Company-level sharing

Users associated with the same company email domain may share a company wallet and may see company-scoped searches, payments, invoices, transactions and eligible certificates created by colleagues. Do not use an email domain for a company account unless this organisational sharing is authorised. Personal record-investigation request lists are limited to the submitting user, while authorised administrators may review all requests.

6. When information is shared

We may disclose information only as reasonably required to:

  • the authorised company and its users/administrators;
  • connected education-record providers used to carry out a search;
  • Paystack or another configured payment provider to process and verify a transaction;
  • email, hosting, storage, security, support and other service providers working on our behalf;
  • professional advisers, regulators, courts or law-enforcement bodies where lawfully required; or
  • a successor organisation in a lawful merger, restructuring or transfer, subject to appropriate safeguards.

We do not state that we sell personal data or use the Platform for third-party behavioural advertising.

7. Public certificate verification

A certificate contains a verification code/QR link. A public viewer must provide an email address and may have to pay the displayed fee before seeing the stored result. Eligible administrator emails and registered company domains may be exempt. Access is limited in time and rate-limited. Certificate pages are instructed not to be indexed by search engines, but anyone receiving a verification link may attempt to use it; users must share links responsibly.

8. Storage, retention and deletion

  • Recent activity logs and searches without successful verification are normally cleaned after five days.
  • A Not Found Certificate is linked to its no-result search and may cease to be available when that search is cleaned.
  • Successful verification certificates are normally valid for 365 days from the original search date, unless the configured period is changed. Expired records may remain for audit and authorised download.
  • Public paid/exempt browser access normally lasts seven days, while its audit/payment log may be retained longer.
  • Payments, invoices, wallet transactions, record requests, notifications and public-access logs currently have no automatic age-based deletion in the application and may be retained for operational, accounting, security or legal purposes.
  • Account deletion through Profile Settings is a soft deletion and does not immediately erase every related business, audit or certificate record.

Retention may be extended where necessary for law, accounting, fraud prevention, dispute handling, backups or legal claims. When data is no longer required, it may be deleted, anonymised or securely archived in line with applicable obligations. A user-facing time filter does not itself guarantee that records exist for the full period shown.

9. Cookies and similar technology

The Platform uses essential cookies/session storage for login, security, form protection, two-factor state and time-limited public verification access. Disabling these may prevent important features from working. Payment providers and linked third-party services may apply their own cookies and privacy policies.

10. Security

We use reasonable technical and organisational safeguards, including access controls, private file storage, password hashing, administrator two-factor authentication, signed links, rate limits and activity logging. No online system is completely secure. Users must protect passwords, recovery codes, devices, downloaded PDFs and verification links, and must promptly report suspected unauthorised access.

11. Your data-protection rights

Subject to the Nigeria Data Protection Act 2023 and other applicable law, you may have rights to be informed, request access, correct inaccurate data, request deletion, restrict or object to processing, request portability where applicable, withdraw consent where processing relies on consent, and complain to the Nigeria Data Protection Commission. These rights are not absolute; lawful retention and the rights of others may limit a request.

To make a request, email info@socpbs.com. We may verify your identity and authority before responding. If the data is controlled by your employer, an institution or another organisation, we may direct the request to that organisation.

12. International access and third-party sites

The Platform is operated for use in Nigeria. If information is processed outside Nigeria by a service provider, appropriate measures should be applied as required by law. Links or redirects to payment providers and other third-party sites are governed by those parties' own terms and privacy notices.

13. Changes and contact

We may update this Policy to reflect legal, operational or technical changes. The revised date will be displayed on this page. Questions, complaints and privacy requests should be sent to info@socpbs.com.

SPBS SPBS

Certificate verification Initiative trusted by organizations across Nigeria.

Quick Links

  • Features
  • How to Use
  • FAQs

Legal & Account

  • Privacy Policy
  • Terms of Service
  • Sign In

© 2026 SPBS Certificate Verification Initiative. All rights reserved.

Partner: Risk Control Services

info@socpbs.com