dmistocks
About Contact Terms of Use Privacy Policy
Contents
  1. About this policy
  2. Who is responsible for your data
  3. Business data: our role and yours
  4. Information we collect
  5. How we use it and our lawful bases
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Cookies and similar technologies
  12. The Dara assistant and automated processing
  13. Children
  14. Data breaches
  15. If you are outside Nigeria
  16. Changes to this policy
  17. Contact and complaints

Privacy Policy

Effective 17 September 2026 · Version 2026-09-17

The short version.

• We collect what we need to run your account and keep it secure, and a business's own records belong to that business.

• We don't sell personal data, and we don't use it for advertising.

• Service providers such as hosting, email, payments and AI process some data for us under contract. Some of them are outside Nigeria, with safeguards in place.

• You can access, correct, export or delete your data, object to processing, and complain to the Nigeria Data Protection Commission.

1. About this policy

This policy explains how dmistocks (the "Service") handles personal data: information that identifies, or could identify, a living person. It applies to people who visit our website, create or use an account, are invited to join a business, or contact us. It is written to meet the Nigeria Data Protection Act 2023 ("NDPA") and the General Application and Implementation Directive issued by the Nigeria Data Protection Commission ("NDPC"), and it explains the rights people in other countries have under their own laws (section 15).

Please read it together with our Terms of Use.

2. Who is responsible for your data

The data controller for account, billing, website and support information is DMIDEVELOPERS LTD (RC 8916456), a company registered in Nigeria, of Abuja, Nigeria ("we", "us"), which operates this service under the name Dmistocks. For anything about your personal data, email [email protected]. For anything else, write to [email protected] or call +234 902 253 4410.

3. Business data: our role and yours

Businesses use the Service to keep records that include personal data, such as their customers' names and phone numbers, supplier contacts, and staff details. For that information:

  • the business is the data controller. It decides what to collect and why, and it is responsible for having a lawful basis and giving notice to the people concerned; and
  • we are the data processor. We process that data only to provide the Service on the business's instructions, keep it confidential and secure, and help the business meet its obligations.

If you are a customer, supplier or employee of a business that uses dmistocks and want to exercise your rights over data that business holds about you, please contact the business directly. If you contact us, we will pass your request on to that business and help it respond.

4. Information we collect

4.1 Information you give us

  • Account details: name, email address, phone number (optional) and password (stored only as a one-way hash), or your Google or Microsoft sign-in identity if you use one.
  • Business details: business name, legal name, registration number, address, contact details, logo, country, currency, timezone and tax settings.
  • Staff and roles: names, email addresses, roles, branch assignments, and, if the business uses the staff features, positions, departments and employment details.
  • Business records (Customer Data): products, prices, stock, sales, receipts, invoices, purchases, payments, expenses, accounting entries, and details of the business's customers and suppliers, such as names, phone numbers, email addresses, addresses and balances.
  • Billing: plan, invoices, payment references and status. Card payments are handled by our payment provider, and we never receive or store full card numbers.
  • Communications: messages you send to support, questions you ask the Dara assistant, and feedback.

4.2 Information collected automatically

  • Security and sign-in records: date and time of sign-in attempts (successful or not), the email address entered, IP address and browser/device description, and whether two-factor authentication was used.
  • Sessions and devices: active sessions and API tokens, so you can see and sign out other devices.
  • Audit trail: who created, changed or deleted records in a business, and when. This protects businesses against fraud and error.
  • Technical logs: request identifiers, errors and performance information, used to keep the Service working and secure.

4.3 Information from others

  • Sign-in providers (Google, Microsoft): your name, email address, whether the provider has verified that address, and an account identifier. We do not receive your password for those services.
  • Connected services a business chooses to link, such as Paystack, Flutterwave, Shopify, WooCommerce or its own online store: order, payment and product details, which can include the names and contact details of that business's customers.
  • A business that invites you: your email address and the role you are offered.

We do not knowingly collect sensitive personal data (such as health, religious or biometric data) for our own purposes. Please do not enter it into the Service unless your business has a lawful reason and appropriate safeguards.

5. How we use it and our lawful bases

Under the NDPA we must have a lawful basis for each use of personal data. We rely on the following:

What we doLawful basis
Create and run your account, provide the Service's features, process your business's records on its instructionsPerformance of a contract with you or your business
Bill subscriptions, confirm payments, send invoices and service noticesPerformance of a contract; legal obligation (tax and accounting records)
Keep the Service secure: sign-in protection, two-factor authentication, detecting suspicious sign-ins, rate limiting, audit trails, fraud preventionLegitimate interests in protecting our users and the Service; legal obligation to implement appropriate security
Provide support, including read-only support sessions you are notified ofPerformance of a contract; legitimate interests
Contact account holders about their account by email, phone or WhatsApp, including checking in when an account has not been used for a while, or a trial or subscription has endedLegitimate interests in supporting our customers; you can ask us to stop at any time
Answer questions through the Dara assistantPerformance of a contract (a feature you choose to use)
Improve the Service using aggregated, de-identified usage statisticsLegitimate interests
Product news and offers by email (optional)Consent, which you can withdraw at any time
Respond to lawful requests from courts, regulators and law enforcement; keep records the law requiresLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights, and you can object (section 10). We do not use personal data for advertising, sell it, or use a business's customer lists to contact those customers ourselves.

6. Who we share it with

We share personal data only as described here. Our service providers ("sub-processors") act on our instructions under written contracts that require confidentiality and security.

RecipientPurposeLocation
Hosting and database providerRuns the application and stores its data, including uploaded imagesContabo GmbH, Germany
Backup storage providerEncrypted off-site backups for disaster recoveryBunny.net (BunnyWay d.o.o.), European Union
Email delivery providerSending sign-in, invitation, billing, notification and document emailsBrevo (Sendinblue SAS), France
PaystackProcessing subscription paymentsNigeria
OpenAIGenerating Dara assistant answers, only when a user asks Dara a questionUnited States
Google, MicrosoftSign-in, only if you choose to sign in with themUnited States / global
Meta Platforms (WhatsApp Business API)Sending and receiving WhatsApp messages where a business has chosen to reach its customers that way, and where you message us on WhatsAppUnited States / global
Google FontsDelivering the typeface used by our pages; your browser's IP address is visible to Google when fonts loadUnited States / global

We also share data:

  • within a business: staff see the records their role permits, and Owners can see staff activity in the audit trail;
  • with services a business connects (such as its own payment gateway or online store), at that business's instruction;
  • with our authorised staff, whose access is role-limited, audited, and, for a business's own screens, only through a notified, read-only, time-limited support session;
  • with professional advisers (lawyers, auditors, accountants) under confidentiality;
  • where the law requires, or to respond to a valid court order or lawful request by a government authority, or to protect the rights, safety or property of our users, the public or us; and
  • in a business transfer, such as a merger or acquisition, where the recipient must honour this policy. We will tell you before that happens.

WhatsApp and the Meta platform

We use the WhatsApp Business API, provided by Meta Platforms, to exchange messages with customers — to answer a support question, or where a business has chosen to send its own customers a receipt or a payment reminder on WhatsApp. When a message goes either way, the phone number and the content of that message pass through Meta's systems, and Meta processes them under its own terms as well as ours. Messages are encrypted in transit.

You never have to use WhatsApp to use dmistocks. Email and the screens inside the Service reach us just as well, and a business that would rather not message its own customers that way simply does not turn it on.

7. International transfers

Some providers listed above process data outside Nigeria. Where personal data is transferred out of Nigeria, we do so only as the NDPA and the NDPC's rules allow. That means the recipient's country is recognised as providing adequate protection, or we rely on appropriate safeguards such as contractual clauses that protect the data to NDPA standards, or another lawful ground such as the transfer being necessary to perform our contract with you. You can ask us for more information about the safeguards for a particular transfer.

8. How long we keep it

We keep personal data only as long as we need it for the purposes above, or as the law requires.

DataHow long
Account and business recordsWhile the subscription is active, then 90 days after it ends or the account is closed (to allow reactivation or export), then deleted or anonymised
Accounting, invoice and tax-related recordsAs long as the law requires. Nigerian tax and company law commonly require financial records to be kept for at least six years. Records a business deletes early remain its own responsibility.
Our own billing records (subscriptions, invoices, payments)At least six years, to meet tax and accounting obligations
Deleted items in a business's trashUntil restored or purged by the business, or the account is deleted
Read notifications90 days
Outbound webhook delivery logs60 days
Sign-in attempts12 months, then deleted automatically
Signed-in sessions and device listRemoved after the session has expired
Audit trails and operator action logsFor the life of the business account, and afterwards as long as needed for legal claims
BackupsRemoved on a rolling schedule. Data deleted from the Service disappears from backups as they expire.
Support conversations and Dara questionsFor the life of the account, unless you ask us to delete them sooner

9. How we protect it

We use technical and organisational measures appropriate to the risk, including:

  • encryption in transit (HTTPS), and encryption at rest for sensitive fields such as two-factor secrets and integration credentials;
  • passwords stored only as strong one-way hashes, two-factor authentication for users and mandatory two-factor authentication for our operators, sign-in rate limiting, and alerts for suspicious sign-ins;
  • strict separation between businesses' data, role-based access within each business, and role-limited, audited access for our own staff;
  • security headers, protection against common web attacks, and checks on outbound connections;
  • regular encrypted backups with tested restores, and monitoring of the Service's health; and
  • confidentiality obligations for staff and contractors, and security review of our code.

No system is completely secure. You help keep your account safe by using a strong, unique password, turning on two-factor authentication, and removing staff access that is no longer needed.

10. Your rights

Under the NDPA you have the right to:

  • be informed about how your data is used (this policy);
  • access the personal data we hold about you and get a copy;
  • rectification: have inaccurate or incomplete data corrected. Much of it you can change yourself in your profile;
  • erasure: have your data deleted where there is no longer a lawful reason to keep it;
  • restriction: ask us to limit processing while a concern is looked into;
  • data portability: receive your data in a structured, commonly used, machine-readable format, or have it sent to another provider where technically feasible;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • withdraw consent where we rely on it, without affecting processing already done; and
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (see section 12).

To exercise a right, email [email protected] from the address on your account, or contact us as in section 17. We may need to verify your identity. We respond without undue delay, and in any case within the time the law allows, normally within one month. This is free unless a request is clearly unfounded or excessive. If we cannot fully meet a request, for example because the law requires us to keep certain records, we will explain why.

If your data is held by a business that uses dmistocks, see section 3.

11. Cookies and similar technologies

We use only the cookies and browser storage needed to run the Service securely. We do not use advertising or cross-site tracking cookies.

NamePurposeDuration
Session cookies (for example dmistocks-session)Keep you signed in and protect formsUntil you sign out or the session expires
XSRF-TOKENProtects against cross-site request forgerySession
remember_*Keeps you signed in on a device if you choose "remember me"Until you sign out or it is revoked
ivm_support_sessionUsed only by our staff's browsers during a support sessionUp to the length of the session
Browser local storage (for example the theme preference)Remembers interface choices such as light or dark modeUntil you clear it

These are strictly necessary, so they do not need consent. You can block or delete cookies in your browser, but the Service will not work without the session cookies.

12. The Dara assistant and automated processing

  • When you ask Dara a question, your question and the business records needed to answer it (limited to what your role can already see) are sent to OpenAI to generate an answer. OpenAI processes this as our service provider and, under its API terms, does not use it to train its models. You don't have to use Dara.
  • Dara's answers support your own decisions. We do not make decisions about you with legal or similarly significant effects based solely on automated processing. Automated security measures, such as locking sign-in after repeated failed attempts, protect accounts and can always be reviewed by contacting us.

13. Children

The Service is for businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children for our own purposes. If you believe a child has given us personal data, contact us and we will delete it. Businesses that record data about minors (for example a young customer) are responsible for the NDPA's additional safeguards.

14. Data breaches

If a personal data breach is likely to result in a risk to people's rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it, as the NDPA requires. Where the risk is high, we will also inform the affected people directly, telling them what happened and what they can do. Where we act as a processor for a business, we will notify that business without undue delay so it can meet its own obligations.

15. If you are outside Nigeria

The Service is operated from Nigeria and designed primarily for Nigerian businesses, but people and businesses elsewhere use it too. Where the law of your country applies, you have the rights it gives you. Those rights are in addition to this policy, and nothing here reduces them. In particular:

  • European Union, EEA and United Kingdom (GDPR / UK GDPR): you have the rights described in section 10, and the right to complain to your local supervisory authority, such as the Information Commissioner's Office in the UK. Our lawful bases are as set out in section 5. Transfers use recognised safeguards such as standard contractual clauses.
  • Ghana (Data Protection Act, 2012 (Act 843)): you may complain to the Data Protection Commission of Ghana.
  • Kenya (Data Protection Act, 2019): you may complain to the Office of the Data Protection Commissioner.
  • South Africa (Protection of Personal Information Act, 2013): you may complain to the Information Regulator.
  • Businesses outside Nigeria remain responsible for their own obligations as controllers of their customers' and staff's data under local law.

16. Changes to this policy

We will update this policy when our practices or the law change. For a material change, we will tell account Owners by email or in the Service at least 14 days before it takes effect, unless it is needed sooner for legal or security reasons. The version and effective date at the top show which version applies.

17. Contact and complaints

DMIDEVELOPERS LTD
Abuja, Nigeria
Email: [email protected]

If you are not satisfied with our response, you have the right to complain to the Nigeria Data Protection Commission (ndpc.gov.ng), or to the data protection authority in your country (section 15).

dmistocks

Inventory, point of sale and double-entry accounting for Nigerian retail and distribution businesses.

Product
  • Features
  • Pricing
  • FAQ
Get started
  • Create your account
  • Sign in
Company
  • About
  • Contact
  • Terms of Service
  • Privacy Policy

DMIDEVELOPERS LTD RC 8916456

Abuja
Nigeria
  • +234 902 253 4410
  • [email protected]
© 2026 DMIDEVELOPERS LTD. All rights reserved. Dmistocks is a product of DMIDEVELOPERS LTD. RC 8916456. Made for the counter, the store room and the books.
dmistocks