Data Protection

Last updated: [EFFECTIVE DATE]

Your shop's records are the memory of your business. This page explains, in plain terms, how KipBox protects them, who can reach them, and what we do if something goes wrong. It sits alongside our Privacy Policy, which explains what we collect and why.

We handle personal data in line with the Nigeria Data Protection Act 2023 (NDPA), supervised by the Nigeria Data Protection Commission (NDPC).

Who is responsible for what

  • Your business is the data controller for the customer and staff information you enter. You decide what to record and why.
  • KipBox is the data processor for that information. We hold and process it only to run the service for you, and only on your instructions.
  • KipBox is the controller for your own account and billing information — your name, email, phone, business details and subscription record.

Your data is separated from every other business

KipBox serves many businesses from one system, and keeping them apart is the single most important protection we provide.

  • Every record — product, sale, customer, invoice, supplier, expense, report — is tied to one business account.
  • Every request the application makes is automatically scoped to the business of the signed-in user, so a query can only ever return that business's rows.
  • There is no shared view, no cross-business search, and no way for another KipBox subscriber to see, list or export your records.

You control what your own staff can see

Access inside your business is controlled by roles and permissions that you set:

  • Each staff member gets their own login — no shared accounts.
  • Roles decide what a user can view and do. A cashier can ring up sales without seeing your profit margins, your cost prices or your reports.
  • Permissions are granular: viewing, creating, editing and deleting are separate rights, and can be granted separately.
  • Users can be limited to a single store or location.
  • An account can be deactivated immediately when someone leaves.

Every change is recorded

KipBox keeps an activity log of records created, updated and deleted. Each entry records which user made the change, what the record was, what the values were before and after, the IP address it came from and the exact time. If a figure changes and you do not know why, the log will tell you. Staff cannot edit or erase this log.

How we protect your data

  • Encrypted in transit. All traffic between your device and KipBox travels over HTTPS/TLS, so it cannot be read on the network in between.
  • Passwords are never stored. We keep only a one-way cryptographic hash. Nobody at KipBox can read or recover your password — we can only help you reset it.
  • Sensitive platform credentials are encrypted at rest in the database.
  • Payment details never touch our servers. Card and bank information is entered directly on our payment provider's own PCI-DSS compliant page. We receive only a transaction reference and a success or failure result.
  • Email verification is required before a new account is fully usable, which prevents accounts being opened against someone else's address.
  • Restricted production access. Only a small number of authorised personnel can reach the production environment, and only where necessary to operate or fix the service.
  • Regular backups of the production database are taken so your records can be restored after a failure.
  • Ongoing maintenance. We keep the underlying platform and its dependencies patched and up to date.

No system can promise perfect security. Two things you control matter as much as anything we do: use a strong, unique password, and give each staff member only the permissions their job needs.

How long we keep data

  • Business records are kept for as long as your account is open, so your history and reports stay complete.
  • After you close your account, records are kept for a short winding-down period so you can retrieve them, then deleted or anonymised.
  • Billing records are kept as long as tax and accounting law requires.
  • Activity and security logs are kept for a limited period for audit purposes.

Getting your data out, or deleting it

Your records are yours and are not held hostage. You can retrieve your data from KipBox at any time while your account is active. If you want your account and its data deleted, email us and we will confirm the request, carry it out, and confirm again when it is done — except for anything we are legally required to retain.

If something goes wrong

If a personal data breach occurs, we will:

  • Contain and investigate it immediately.
  • Notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the people affected.
  • Tell affected businesses without undue delay, explaining what happened, what data was involved, and what you should do.
  • Fix the underlying cause and record what we changed.

Your rights, and how to use them

Under the NDPA you can ask to access, correct, delete, restrict, object to or port your personal data, and you can withdraw consent where we relied on it. Email hello@kipbox.co and we will respond within 30 days. We may first ask you to confirm who you are.

If your request is about information a shop recorded about you as its customer, contact that shop — they control that record. We will help put you in touch if you cannot reach them.

Complaints

If you are not satisfied with how we have handled your data, tell us first and we will try to put it right. You also have the right to complain to the Nigeria Data Protection Commission.

Contact

Data protection enquiries: hello@kipbox.co
KIPBOX, A Product of Dignity Technology Limited