Trust

Skin data, handled with care.

Oyster reads faces for a living, so privacy is not a policy page for us, it is the product. Here is how we hold your customers' data.

POPIA & NDPR aligned

Built to the data protection standards of the markets we serve, including South Africa and Nigeria, with GDPR informed defaults.

Encrypted in transit and at rest

Our DPA specifies AES-256 encryption for stored data and TLS 1.2+ for data in transit, with role-based access controls and multi-factor authentication.

Data residency

Regional deployment, including af-south-1 in Cape Town, so partner data can stay in region where that is required.

Privacy by design

Our DPA distinguishes temporary scan inputs, client-controlled personal data and anonymized analytics. Selfie images are deleted after analysis; the shorter retention periods are not extended by the 90-day termination deadline.

Doing due diligence?

We will walk your security and legal teams through data handling, residency, and our subprocessors.