Skip to content
Karmat Engineering Limited

Data sovereignty

Privacy policy

This policy explains what Karmat Engineering Limited collects, why we collect it, how long we keep it, and what you can require us to do with it. It covers our website, our web applications, and the APIs we publish.

Effective 27 August 2026

GDPR and NDPR aligned

01

Scope of this policy

This policy applies to karmat-hq.com, to the applications we operate at diagnostics.karmat-hq.com and attender.karmat-hq.com, and to the APIs served from api-diagnostics.karmat-hq.com and api-seerahai.karmat-hq.com. Where you use one of our APIs inside your own product, you are the controller of your users' data and we act as your processor; your own privacy notice governs your relationship with them. It does not cover third-party sites we link to.

02

Who is responsible

Karmat Engineering Limited, of Akure, Ondo State, Nigeria, is the data controller for information collected through our own website and applications. Written questions and requests should go to [email protected], which reaches the people who can actually action them rather than a ticket queue.

03

Information we collect

We collect three categories. Information you give us: your name, email address and organisation when you request API access, join a waiting list, or contact us. Information created by using the service: API request metadata such as timestamps, endpoint, response status, token or request counts, and the key fingerprint that made the call. Technical information: IP address, browser and device type, and pages visited. We do not buy personal data from brokers, and we do not build advertising profiles.

04

Prompts, images and other content

Content you send to an API — a clinical feature set, an uploaded fundus image, a question put to Seerah AI — is processed to produce your response and is not used to train our models without a separate written agreement. Uploaded files are stored only where you have explicitly used the upload endpoints, and remain retrievable and deletable by you. Request and response bodies are not retained in our logs by default; we log metadata and outcomes, not payloads.

05

Biometric data

Attender processes facial images to verify attendance. Facial templates are mathematical representations, not stored photographs, and are encrypted at rest and bound to the organisation that enrolled them. They are never shared between organisations, never used for any purpose other than the attendance check they were collected for, and never used to train a general-purpose model. Biometric processing requires explicit, informed consent from each individual, and any organisation deploying Attender must offer a non-biometric alternative to anyone who declines.

06

Health and clinical data

Optical Diagnostics processes clinical features and ocular imagery. This is health data and is treated as a special category throughout: encrypted in transit and at rest, access-controlled to the consuming organisation, and never combined across customers. Model output is clinical decision support and is not a diagnosis. Where you deploy it in a care setting, you remain the controller of your patients' records and are responsible for the lawful basis on which you process them.

07

How we use information

To provide and operate the services you asked for; to authenticate requests and enforce rate limits; to detect abuse, fraud and security incidents; to produce aggregate, non-identifying statistics on service performance; to bill correctly; and to reply when you contact us. We do not sell personal data, and we do not use it to make automated decisions producing legal effects about you.

09

Sharing and processors

We do not sell, rent or trade personal data. We share it only with infrastructure providers who host and deliver the services on our behalf, each bound by a data processing agreement and permitted to act only on our instructions; with professional advisers under duty of confidence; where required by law or valid legal process; and with a successor entity in the event of a merger or acquisition, on notice to you. We publish the current list of sub-processors on request.

10

How long we keep information

Access requests and account records are kept for the life of the relationship and for six years afterwards, to meet contractual and tax obligations. API request metadata is retained for twelve months. Security logs are retained for twelve months. Uploaded objects persist until you delete them, or until the retention period you have configured expires. Biometric templates are deleted when enrolment is withdrawn or the organisation's account closes, whichever comes first. Anything that no longer has a purpose is deleted or irreversibly anonymised.

11

Security

Transport is TLS 1.2 or higher. Data at rest is encrypted with AES-256. API keys are stored only as peppered hashes and cannot be recovered — which is why an issued key is displayed exactly once. Access to production systems is limited to named engineers, requires multi-factor authentication, and is logged. We run dependency scanning and review changes before release. No system is perfectly secure, and we do not claim otherwise; where a breach is likely to result in a risk to your rights, we will notify the relevant authority within 72 hours and tell affected users without undue delay.

12

Your rights

You may request access to the personal data we hold about you; correction of anything inaccurate; deletion where we have no overriding basis to keep it; restriction or objection to processing; a portable copy in a machine-readable format; and withdrawal of consent where consent is the basis. Write to [email protected]. We will respond within 30 days, and we will not charge you for a reasonable request. If you are dissatisfied you may complain to your supervisory authority, or in Nigeria to the Nigeria Data Protection Commission.

13

International transfers

Our infrastructure may process data outside your country of residence. Where personal data leaves Nigeria or the European Economic Area, we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses with the receiving processor. Customers with a hard residency requirement should raise it before integration — it is a constraint we can usually design around, but only in advance.

14

Cookies and local storage

This website uses local storage to remember your theme preference. It is stored in your browser, never transmitted to us, and can be cleared at any time through your browser settings. We do not use advertising cookies, third-party trackers or cross-site analytics on this site.

15

Children

Our services are not directed at children under 18 and we do not knowingly collect their personal data through this website. Where an organisation deploys Attender in a school, that organisation is the controller and is responsible for obtaining consent from a parent or guardian in line with local law. If you believe we hold a child's data without a proper basis, tell us and we will delete it.

16

Changes to this policy

We may update this policy as the services change or the law does. The effective date at the top always reflects the current version. Where a change materially affects your rights, we will give notice by email to account holders before it takes effect, rather than relying on you to notice a silent edit.

17

Contact and complaints

Questions, requests and complaints go to [email protected], or by post to Karmat Engineering Limited, Akure, Ondo State, Nigeria. We would rather resolve a concern directly, but you are entitled to go to a supervisory authority at any point and do not need to come to us first.