Trust

Your documents. Protected.

XOYA processes passport scans, bank statements, and personal documents. We take that seriously. Here is exactly how we handle your data.

Compliance posture

Where we stand.

✓ CompliantGDPR — General Data Protection Regulation
✓ CompliantNDPR — Nigeria Data Protection Regulation
⏳ Q4 2026SOC 2 Type II — in progress
📋 2027 RoadmapISO 27001
✓ AvailableLocal data residency for African deployments
✓ IncludedAudit-grade event logs on all enterprise plans
Security architecture

How we protect your data.

🔐

Encryption in transit and at rest

All documents are transmitted over TLS 1.3 and stored with AES-256 encryption at rest. No exceptions.

🗄️

Data residency

African applicant data is stored on servers within Africa. Enterprise and government partners can specify data residency requirements.

Retention limits

Documents are retained only for the duration of the application process plus a statutory compliance window. Applicants can request deletion at any time.

🚫

No third-party data sales

XOYA does not sell, share, or monetize applicant document data. Documents are not used to train third-party models without explicit consent.

🔍

Audit-grade logs

Every action on every document is logged with timestamp, actor, and action. Logs are immutable and available to enterprise partners.

🛡️

Role-based access controls

Applicant documents are accessible only to the applicant, their designated XOYA case manager, and authorized organizational admins.

Your rights under GDPR & NDPR

You own your data.

Right to access

Request a copy of all personal data XOYA holds about you at any time.

Right to erasure

Request deletion of your personal data. XOYA will comply within 30 days, subject to legal retention obligations.

Right to portability

Request your data in a structured, machine-readable format.

Right to object

Object to processing of your personal data at any time.

Right to rectification

Request correction of inaccurate personal data.

To exercise any of these rights, contact: hello@xoyavisa.io
Legal documents
Privacy Policy
How XOYA collects, processes, and stores personal data.
Last updated May 2026
Terms of Service
The terms governing use of the XOYA platform and services.
Last updated May 2026
Cookie Policy
How XOYA uses cookies and tracking technologies.
Last updated May 2026
Acceptable Use Policy
Permitted and prohibited uses of the XOYA platform.
Last updated May 2026
Security

Responsible disclosure.

If you discover a security vulnerability in XOYA infrastructure, we ask you to disclose it responsibly. We commit to acknowledging valid reports within 48 hours and resolving critical issues within 30 days.

Report to: security@xoyavisa.io

Questions about how we handle your data?

Contact us