Managed Cloud Data Processing Agreement
How we process personal data on your behalf inside your instance, what we are allowed to do with it, and what we are not.
Last updated
When you use Stockovaa to manage your customers, staff, suppliers and transactions, you decide what is collected and why. You are the data controller. We hold and process that data so we can run the service for you, which makes us the data processor.
Personal data about you and your colleagues as our customer contacts is a different matter. For that we are the controller, and the Privacy Policy governs it.
| Data | You are | We are |
|---|---|---|
| Your customers, staff, suppliers, transactions | Controller | Processor |
| Documents and files you upload into the instance | Controller | Processor |
| Your account owner and billing contact details | Data subject or their employer | Controller |
| Support tickets you raise with us | Controller of anything you put in them | Controller of the ticket record itself |
This agreement forms part of the Managed Cloud Terms of Service and applies for as long as we process personal data on your behalf.
| Item | Detail |
|---|---|
| Subject matter | Operation, maintenance, backup and support of the Stockovaa instance we run for you. |
| Duration | For the term of your Managed Cloud service, plus the deletion window in clause 10. |
| Nature and purpose | Hosting, storage, backup, restore, patching, monitoring, support and incident investigation. |
| Categories of personal data | Names, contact details, addresses, order and transaction records, staff and payroll records you enter, supplier contacts, and usage and audit data generated by the system. |
| Categories of data subject | Your customers, your staff, your suppliers, and anyone else whose details you enter. |
| Special category data | Not expected. If your use of the system will involve health, biometric or similar data, tell us before onboarding so it can be assessed. |
The scope above describes the default. If your instance is configured to do something outside it, that configuration is your documented instruction and this table should be updated to match.
- We process personal data only on your documented instructions. Your instructions are this agreement, the Terms of Service, your order form, the configuration of your instance, and anything you ask us to do in writing through a support ticket.
- We will tell you if, in our opinion, an instruction you have given us breaches applicable data protection law. We may decline to act on it until it is resolved.
- We will not process your data for our own purposes, will not sell it, and will not use it to train machine learning models.
- Where the law requires us to process data beyond your instructions, we will tell you before doing so unless the law forbids us from telling you.
- Everyone we allow to touch your data is bound by a confidentiality obligation that survives the end of their engagement with us.
Statistics about platform performance may be compiled in aggregate, provided the result cannot identify you, your business, your staff or your customers. That is described in clause 10 of the Terms of Service.
We maintain technical and organisational measures appropriate to the risk. In practice that means the following.
- Per-customer data isolation. Your business has its own database rather than a shared table with a customer column.
- Encryption in transit using TLS, and encryption at rest for backups.
- Access control on the principle of least privilege, with periodic review.
- Logging of administrative actions on your instance, retained and reviewable by us.
- Automated backups to the schedule in the Service Level Agreement, stored separately from the instance they protect.
- Patching to the timescales in the Service Level Agreement.
- Availability monitoring with alerting to an on-call engineer.
- Staff confidentiality obligations and access revocation on departure or role change.
- Restore testing at least quarterly, so the backups are known to work rather than assumed to.
We may change these measures as technology moves, provided we do not materially reduce the level of protection.
This clause exists because we are honest about the trade you have made. You are paying us to run your system, which means our engineers can reach the data inside it. A processor agreement that glossed over that would be worthless.
- Privileged access is granted only to engineers who need it to operate, patch, back up, restore or support your instance.
- It is used to deliver the service and to act on your instructions. It is not used to browse your business data, and doing so is a disciplinary matter.
- Administrative actions are logged with actor, action and timestamp.
- Where resolving a ticket requires us to look at a specific record, we say so in the ticket, so you have a written trail as well as us.
- Access is revoked when an engineer leaves or changes role.
- Our staff never require your password and will never ask for it.
If your sector requires named-individual access control or approval before any support access, raise it during onboarding. It is a configuration decision, and it is far easier to build in than to retrofit.
We use third parties to help deliver the service. Each is bound by data protection obligations no less protective than this agreement, and we remain responsible to you for what they do.
| Category | Purpose | Data reached |
|---|---|---|
| Infrastructure provider | Running and storing your instance | All instance data, encrypted at rest |
| Network and security provider | TLS termination, DNS, protection against attack | Traffic metadata and request content in transit |
| Backup storage provider | Off-instance retention of encrypted backups | Encrypted backups only |
| Email delivery provider | Sending receipts, invoices and notifications from your instance | Recipient name, address and message content |
| Payment providers | Processing payments taken through your instance | Payment data they collect directly |
- A current named list of sub-processors, with their locations, is available on request from the Managed Cloud team.
- We will give you at least 30 days notice before adding or replacing a sub-processor that handles personal data.
- You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may end the managed service and the pro-rata refund in the Refund Policy applies.
- Requests from your customers, staff or suppliers are yours to answer. You are the controller and you hold the relationship.
- Most requests can be answered using the tools in the product: search, export, edit and delete.
- Where the product cannot do what a request needs, we will help you within a reasonable time, taking into account the nature of the processing and the information available to us.
- If a data subject contacts us directly about data inside your instance, we will not act on it. We will tell them to contact you, and tell you it happened.
We will also assist you, so far as reasonably possible, with data protection impact assessments and with prior consultation with a supervisory authority, where either relates to the processing we carry out for you.
- If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay, and in any event within 48 hours of becoming aware.
- The notice will describe what we know: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and what we are doing about it.
- Where we do not have all of that at first, we will send what we have and follow up rather than wait until the picture is complete.
- We will help you meet your own notification obligations to a regulator or to affected individuals.
- We will not notify a regulator or a data subject on your behalf unless you ask us to in writing, because that notification is the controller's to make.
Tell us fast if you spot something too. A breach reported by a customer at 09:00 is a much smaller problem than the same breach found by us at 17:00.
- We will make available the information reasonably needed to demonstrate compliance with this agreement.
- You may request a written summary of our security measures, our sub-processor list, and our most recent restore test result, once in any 12-month period, at no charge.
- An on-site or third-party audit may be carried out where a regulator requires it, or after a personal data breach affecting your data. It must be agreed in advance, be conducted during business hours, not disrupt other customers, and be subject to confidentiality.
- Additional audits beyond the above are chargeable at our then-current professional rates.
- We will not give an auditor access to another customer's data, and we will redact anything that would expose it.
When the managed service ends, you get your data back and then we delete it. The timetable is the one in clause 9 of the Terms of Service, and it is repeated here because a processor agreement that does not state it is incomplete.
| Stage | What happens to the data |
|---|---|
| Service ends | Data is retained in full. Nothing is deleted at this point. |
| Export window | You may request a complete export in a documented, machine-readable format, at no charge. |
| Decommission | The instance and its backups are securely deleted, except where retention is required by law. |
| After decommission | Confirmation of deletion is provided in writing on request. |
Backups roll off on their own retention cycle rather than being individually purged. Where a copy persists in a backup after deletion of the live data, it stays encrypted, is not restored, and is destroyed at the end of that cycle.
Ask for the export before the service ends, not after. It is the same export either way, and doing it while the system is live means you can check it against something.
- Your instance data is primarily processed and stored on infrastructure located in Nigeria.
- A transfer outside Nigeria happens only where it is necessary to deliver the service, for example email delivery or payment processing.
- Where a transfer takes place we rely on an adequacy determination or on contractual safeguards with the recipient.
- If your business is subject to a data residency requirement, raise it during onboarding. It is a design decision.
This clause must be read with clause 9 of the Privacy Policy, which describes the same arrangements for the data we control.
- Liability under this agreement is subject to the limits in clause 11 of the Terms of Service.
- Where this agreement conflicts with the Terms of Service on a data protection matter, this agreement takes precedence for that matter.
- This agreement is governed by the laws of the Federal Republic of Nigeria, and the forum clause in the Terms of Service applies.
- A countersigned copy of this agreement is available on request. Write to legal@stockovaa.com with the signatory's name and role.
If your own counsel needs changes to this document, send them. We would rather negotiate a schedule than have you sign something you are uncomfortable with.
Data protection questions
These go to a person, not a form. If your counsel wants to talk to ours, say so and we will arrange it.
- Privacy
- privacy@stockovaa.com
- Legal
- legal@stockovaa.com
- Managed Cloud team
- managed@stockovaa.com
- Phone
- +234 707 222 2315
The other documents
- Terms of ServiceThe agreement itself. What your perpetual licence covers, what the service fee buys, and what happens if the service lapses.
- Service Level AgreementUptime, backups, restores, certificates, patching and support response targets, with the credits payable if we miss.
- Refund PolicyWhich payments can be refunded and which cannot, and why a licence fee and a service fee are treated differently.
- Acceptable Use PolicyWhat you may and may not run on your instance, including custom code, outbound email and capacity.
- Privacy PolicyWhat we hold about you as our customer, why, who else sees it, and how long we keep it.
- Cookie PolicyWhat this site and the portal store on your device, and why your own instance needs its own notice.

