Managed Cloud Privacy Policy
What personal information we hold about you as a Managed Cloud customer, why we hold it, who else sees it, and what you can ask us to do with it.
Last updated
This policy covers personal information that Stockovaa holds as a controller in connection with the Managed Cloud service: information about you and your colleagues as our customer contacts, and information about visitors to managed.stockovaa.com.
It deliberately does not cover the data inside your own Stockovaa instance. Your customers, your staff records and your suppliers are your responsibility, not ours. For that data you are the controller and we act only on your instructions, which is governed by the Data Processing Agreement.
| Data | Who is the controller | Which document applies |
|---|---|---|
| Your name, work email, phone, billing details, support tickets | Stockovaa | This policy |
| Enquiry form submissions from managed.stockovaa.com | Stockovaa | This policy |
| Your customers, staff, suppliers and transactions inside your instance | You | The Data Processing Agreement |
| Cookies set on managed.stockovaa.com | Stockovaa | The Cookie Policy |
The privacy policy published at stockovaa.com covers our subscription product. This one covers Managed Cloud. If you hold a lifetime licence, this is the document that applies to you.
When you enquire
- Business name, your name, email address and phone number.
- What system you run today and roughly how many locations you operate.
- Anything you choose to write in the message field. Please do not put personal data about third parties in there.
When you become a customer
- Account owner and billing contact details, including names, work email addresses and phone numbers.
- Business address, tax identification and registration details where needed for invoicing.
- Payment records. Card and bank details are handled by our payment providers and are not stored on our systems.
- Contract documents, order forms and correspondence.
While we run your service
- Sign-in records for the Managed Cloud portal: timestamps, IP address, browser and device information.
- Support tickets, emails and call notes, including anything you send us as an attachment.
- Operational telemetry about your instance: uptime checks, error rates, resource usage, backup and restore events, certificate status, version history.
- Audit records of administrative actions taken on your instance, including by our own engineers.
When you visit this site
- Pages viewed, referring page, approximate location derived from IP address, browser and device type.
- Cookie identifiers, as described in the Cookie Policy.
We do not ask for and do not want special category data about you, such as health, biometric or political information. Please do not send it to us in a support ticket.
| Purpose | What we use | Lawful basis |
|---|---|---|
| Responding to your enquiry and preparing a quotation | Enquiry form fields, correspondence | Steps taken at your request before entering a contract |
| Providing and operating the Managed Cloud service | Account, contact and access records, operational telemetry | Performance of our contract with you |
| Invoicing, collecting payment and keeping accounting records | Billing contact, payment records, tax details | Performance of our contract, and legal obligation |
| Support, incident investigation and root cause analysis | Tickets, logs, audit records | Performance of our contract, and our legitimate interest in running a reliable service |
| Securing the platform, detecting abuse and preventing fraud | Sign-in records, IP addresses, audit records | Our legitimate interest in protecting our customers |
| Service notices about maintenance, incidents and renewals | Account owner and billing contact details | Performance of our contract |
| Marketing about Managed Cloud, where you have asked for it | Name and email address | Your consent, withdrawable at any time |
Service notices are not marketing and cannot be unsubscribed from while your service is active. If we are taking your instance offline for maintenance, you need to know, whatever your marketing preference is.
We do not sell personal information. We do not share it with advertisers. We do not use your data, or the data in your instance, to train machine learning models.
- Traffic between your browser and our systems is encrypted in transit using TLS.
- Backups are encrypted at rest and stored separately from the systems they protect.
- Passwords are hashed. We cannot read yours, and we will never ask you for it.
- Access to production systems follows the principle of least privilege and is reviewed periodically.
- Administrative actions are logged, and the log is retained.
- Our staff are bound by confidentiality obligations that continue after they leave.
- Payment details are handled by PCI-compliant providers and are not stored on our servers.
No system is perfectly secure, and anybody who tells you otherwise is selling something. If we become aware of a breach affecting your personal information we will notify you without undue delay, along with what we know and what we are doing about it.
Found a vulnerability? Report it privately to security@stockovaa.com and give us a reasonable chance to fix it before disclosing it publicly. We will not pursue anyone who reports in good faith.
This clause has no equivalent in a self-service product, and it is the one you should read most carefully. Running your instance for you means our engineers hold administrative access to it. That access is the service. It is also a responsibility, so here is exactly how it is governed.
- Access is limited to the engineers who need it to operate, patch, back up, restore or support your instance.
- It is used to run the service and to respond to something you have asked us to look at. It is not used to browse your business data out of curiosity, and doing so is a disciplinary matter.
- Administrative actions on your instance are logged with the actor, the action and the timestamp.
- Where we need to look at a specific record to resolve a support ticket, we will say so in the ticket, so there is a written trail on your side as well as ours.
- Access is revoked when an engineer leaves or changes role.
Under the Data Processing Agreement we act only on your documented instructions in respect of the personal data inside your instance. This clause describes the practical mechanics of that promise.
We share personal information only where it is needed to run the service, and only with parties bound to protect it.
| Category | Why | What they see |
|---|---|---|
| Infrastructure and network providers | Running and protecting your instance | Encrypted data at rest, traffic metadata |
| Email delivery provider | Sending service notices, invoices and support replies | Recipient name, email address, message content |
| Payment providers | Taking payment and issuing receipts | Billing contact, amount, payment method details they collect directly |
| Domain and certificate providers | DNS and TLS for domains you connect | Domain records and technical contact |
| Professional advisers | Accounting, audit and legal advice | Only what the specific matter requires |
We will disclose information where we are legally required to, such as under a valid court order. Where we are permitted to tell you that has happened, we will.
If our business is sold or reorganised, your information may transfer to the acquiring entity, which remains bound by this policy or one no less protective. We will tell you before that happens.
A current list of the sub-processors we use to run your instance is maintained in the Data Processing Agreement.
| What | How long | Why |
|---|---|---|
| Enquiries that do not become customers | 24 months from the last contact | So we know we have already spoken, and do not approach you twice |
| Customer account and contact records | For the life of the service, then 60 days | Running the service, then a window for you to retrieve anything |
| Invoices and accounting records | As required by Nigerian tax and company law | Legal obligation. This period is not ours to shorten |
| Support tickets and correspondence | 36 months from closure | Continuity of support and dispute resolution |
| Sign-in and administrative audit logs | 12 months | Security investigation |
| Backups of your instance | As stated in the Service Level Agreement | Restore capability |
When your Managed Cloud service ends, what happens to the data inside your instance is governed by clause 9 of the Terms of Service, which gives you a free export and a defined window before anything is deleted.
In respect of personal information we hold about you as a controller, you may ask us to do any of the following.
- Confirm what we hold about you, and give you a copy.
- Correct anything that is inaccurate or incomplete.
- Delete information we no longer have a lawful reason to keep. This does not extend to records we are legally required to retain.
- Restrict how we use it while a dispute about its accuracy is resolved.
- Object to processing that rests on our legitimate interest, telling us why.
- Receive it in a portable, machine-readable format.
- Withdraw consent, where consent was the basis. Withdrawing it does not undo what was lawful beforehand.
Write to privacy@stockovaa.com. We will respond within 30 days. If a request is complex we may need longer, and we will tell you why before the 30 days are up. There is no charge unless a request is manifestly excessive or repetitive.
If a request concerns data inside your own instance, we will point you back to your own controls, or act on your written instruction under the Data Processing Agreement. We will not act on a request from your customer or your employee directly, because that data is not ours to hand over.
If you are not satisfied with how we handle a request, you may complain to the Nigeria Data Protection Commission. We would rather you came to us first, and we will take the complaint seriously.
- Customer data is primarily processed and stored on infrastructure located in Nigeria.
- Cross-border transfers happen only where they are necessary, for example for payment processing, email delivery or an international support tool.
- Where a transfer takes place, we rely on an adequacy determination or on contractual safeguards with the recipient.
- Stockovaa is a Nigerian entity and treats the Nigeria Data Protection Regulation as the governing framework. We also align with the principles of the GDPR where they apply.
If your business is subject to a data residency requirement, tell us during onboarding. It is a design decision, and it is far easier to accommodate before your instance is built than afterwards.
- We may update this policy. The date at the top of this page is a real revision date.
- Where a change materially affects how we use your information, we notify the account owner by email at least 30 days before it takes effect.
- Previous versions are available on request.
Questions about your privacy?
Ask a real question and get a real answer. Privacy requests do not go into a queue behind feature work.
- Privacy
- privacy@stockovaa.com
- Customer support
- support@stockovaa.com
- Phone
- +234 707 222 2315
- Response time
- Within one business day
The other documents
- Terms of ServiceThe agreement itself. What your perpetual licence covers, what the service fee buys, and what happens if the service lapses.
- Service Level AgreementUptime, backups, restores, certificates, patching and support response targets, with the credits payable if we miss.
- Refund PolicyWhich payments can be refunded and which cannot, and why a licence fee and a service fee are treated differently.
- Acceptable Use PolicyWhat you may and may not run on your instance, including custom code, outbound email and capacity.
- Data Processing AgreementThe processor terms for the personal data inside your instance, including the access our engineers hold.
- Cookie PolicyWhat this site and the portal store on your device, and why your own instance needs its own notice.

