Skip to content

Managed Cloud Privacy Policy

What personal information we hold about you as a Managed Cloud customer, why we hold it, who else sees it, and what you can ask us to do with it.

Last updated

This policy covers personal information that Stockovaa holds as a controller in connection with the Managed Cloud service: information about you and your colleagues as our customer contacts, and information about visitors to managed.stockovaa.com.

It deliberately does not cover the data inside your own Stockovaa instance. Your customers, your staff records and your suppliers are your responsibility, not ours. For that data you are the controller and we act only on your instructions, which is governed by the Data Processing Agreement.

DataWho is the controllerWhich document applies
Your name, work email, phone, billing details, support ticketsStockovaaThis policy
Enquiry form submissions from managed.stockovaa.comStockovaaThis policy
Your customers, staff, suppliers and transactions inside your instanceYouThe Data Processing Agreement
Cookies set on managed.stockovaa.comStockovaaThe Cookie Policy

The privacy policy published at stockovaa.com covers our subscription product. This one covers Managed Cloud. If you hold a lifetime licence, this is the document that applies to you.

When you enquire

  • Business name, your name, email address and phone number.
  • What system you run today and roughly how many locations you operate.
  • Anything you choose to write in the message field. Please do not put personal data about third parties in there.

When you become a customer

  • Account owner and billing contact details, including names, work email addresses and phone numbers.
  • Business address, tax identification and registration details where needed for invoicing.
  • Payment records. Card and bank details are handled by our payment providers and are not stored on our systems.
  • Contract documents, order forms and correspondence.

While we run your service

  • Sign-in records for the Managed Cloud portal: timestamps, IP address, browser and device information.
  • Support tickets, emails and call notes, including anything you send us as an attachment.
  • Operational telemetry about your instance: uptime checks, error rates, resource usage, backup and restore events, certificate status, version history.
  • Audit records of administrative actions taken on your instance, including by our own engineers.

When you visit this site

  • Pages viewed, referring page, approximate location derived from IP address, browser and device type.
  • Cookie identifiers, as described in the Cookie Policy.

We do not ask for and do not want special category data about you, such as health, biometric or political information. Please do not send it to us in a support ticket.

PurposeWhat we useLawful basis
Responding to your enquiry and preparing a quotationEnquiry form fields, correspondenceSteps taken at your request before entering a contract
Providing and operating the Managed Cloud serviceAccount, contact and access records, operational telemetryPerformance of our contract with you
Invoicing, collecting payment and keeping accounting recordsBilling contact, payment records, tax detailsPerformance of our contract, and legal obligation
Support, incident investigation and root cause analysisTickets, logs, audit recordsPerformance of our contract, and our legitimate interest in running a reliable service
Securing the platform, detecting abuse and preventing fraudSign-in records, IP addresses, audit recordsOur legitimate interest in protecting our customers
Service notices about maintenance, incidents and renewalsAccount owner and billing contact detailsPerformance of our contract
Marketing about Managed Cloud, where you have asked for itName and email addressYour consent, withdrawable at any time

Service notices are not marketing and cannot be unsubscribed from while your service is active. If we are taking your instance offline for maintenance, you need to know, whatever your marketing preference is.

We do not sell personal information. We do not share it with advertisers. We do not use your data, or the data in your instance, to train machine learning models.

  • Traffic between your browser and our systems is encrypted in transit using TLS.
  • Backups are encrypted at rest and stored separately from the systems they protect.
  • Passwords are hashed. We cannot read yours, and we will never ask you for it.
  • Access to production systems follows the principle of least privilege and is reviewed periodically.
  • Administrative actions are logged, and the log is retained.
  • Our staff are bound by confidentiality obligations that continue after they leave.
  • Payment details are handled by PCI-compliant providers and are not stored on our servers.

No system is perfectly secure, and anybody who tells you otherwise is selling something. If we become aware of a breach affecting your personal information we will notify you without undue delay, along with what we know and what we are doing about it.

Found a vulnerability? Report it privately to security@stockovaa.com and give us a reasonable chance to fix it before disclosing it publicly. We will not pursue anyone who reports in good faith.

This clause has no equivalent in a self-service product, and it is the one you should read most carefully. Running your instance for you means our engineers hold administrative access to it. That access is the service. It is also a responsibility, so here is exactly how it is governed.

  • Access is limited to the engineers who need it to operate, patch, back up, restore or support your instance.
  • It is used to run the service and to respond to something you have asked us to look at. It is not used to browse your business data out of curiosity, and doing so is a disciplinary matter.
  • Administrative actions on your instance are logged with the actor, the action and the timestamp.
  • Where we need to look at a specific record to resolve a support ticket, we will say so in the ticket, so there is a written trail on your side as well as ours.
  • Access is revoked when an engineer leaves or changes role.

Under the Data Processing Agreement we act only on your documented instructions in respect of the personal data inside your instance. This clause describes the practical mechanics of that promise.

We share personal information only where it is needed to run the service, and only with parties bound to protect it.

CategoryWhyWhat they see
Infrastructure and network providersRunning and protecting your instanceEncrypted data at rest, traffic metadata
Email delivery providerSending service notices, invoices and support repliesRecipient name, email address, message content
Payment providersTaking payment and issuing receiptsBilling contact, amount, payment method details they collect directly
Domain and certificate providersDNS and TLS for domains you connectDomain records and technical contact
Professional advisersAccounting, audit and legal adviceOnly what the specific matter requires

We will disclose information where we are legally required to, such as under a valid court order. Where we are permitted to tell you that has happened, we will.

If our business is sold or reorganised, your information may transfer to the acquiring entity, which remains bound by this policy or one no less protective. We will tell you before that happens.

A current list of the sub-processors we use to run your instance is maintained in the Data Processing Agreement.

WhatHow longWhy
Enquiries that do not become customers24 months from the last contactSo we know we have already spoken, and do not approach you twice
Customer account and contact recordsFor the life of the service, then 60 daysRunning the service, then a window for you to retrieve anything
Invoices and accounting recordsAs required by Nigerian tax and company lawLegal obligation. This period is not ours to shorten
Support tickets and correspondence36 months from closureContinuity of support and dispute resolution
Sign-in and administrative audit logs12 monthsSecurity investigation
Backups of your instanceAs stated in the Service Level AgreementRestore capability

When your Managed Cloud service ends, what happens to the data inside your instance is governed by clause 9 of the Terms of Service, which gives you a free export and a defined window before anything is deleted.

In respect of personal information we hold about you as a controller, you may ask us to do any of the following.

  • Confirm what we hold about you, and give you a copy.
  • Correct anything that is inaccurate or incomplete.
  • Delete information we no longer have a lawful reason to keep. This does not extend to records we are legally required to retain.
  • Restrict how we use it while a dispute about its accuracy is resolved.
  • Object to processing that rests on our legitimate interest, telling us why.
  • Receive it in a portable, machine-readable format.
  • Withdraw consent, where consent was the basis. Withdrawing it does not undo what was lawful beforehand.

Write to privacy@stockovaa.com. We will respond within 30 days. If a request is complex we may need longer, and we will tell you why before the 30 days are up. There is no charge unless a request is manifestly excessive or repetitive.

If a request concerns data inside your own instance, we will point you back to your own controls, or act on your written instruction under the Data Processing Agreement. We will not act on a request from your customer or your employee directly, because that data is not ours to hand over.

If you are not satisfied with how we handle a request, you may complain to the Nigeria Data Protection Commission. We would rather you came to us first, and we will take the complaint seriously.

  • Customer data is primarily processed and stored on infrastructure located in Nigeria.
  • Cross-border transfers happen only where they are necessary, for example for payment processing, email delivery or an international support tool.
  • Where a transfer takes place, we rely on an adequacy determination or on contractual safeguards with the recipient.
  • Stockovaa is a Nigerian entity and treats the Nigeria Data Protection Regulation as the governing framework. We also align with the principles of the GDPR where they apply.

If your business is subject to a data residency requirement, tell us during onboarding. It is a design decision, and it is far easier to accommodate before your instance is built than afterwards.

  • We may update this policy. The date at the top of this page is a real revision date.
  • Where a change materially affects how we use your information, we notify the account owner by email at least 30 days before it takes effect.
  • Previous versions are available on request.

Ask a real question and get a real answer. Privacy requests do not go into a queue behind feature work.

Customer support
support@stockovaa.com
Response time
Within one business day