INPROFIC, an ITERATID LTD product, recognises that privacy matters to the businesses that use our platform, their staff, customers, delivery participants, website visitors and other people whose information may be processed through our services. This Privacy Policy explains the information we handle, why we handle it, how it may be shared, and the choices available to you.
Who we are
INPROFIC is a business operations platform that connects inventory, procurement, production, sales, point-of-sale, commerce, payments, finance, delivery, reporting, notifications and related workflows. Depending on the context, ITERATID LTD may act as a data controller for platform account, billing, security and service-administration information, and as a data processor or service provider when a business uses INPROFIC to process information about its own staff, customers, suppliers or operations.
Scope
This policy applies to the INPROFIC marketing website, hosted application, Business Workspaces, hosted storefronts, checkout and order-tracking pages, delivery experiences, installed web application features, platform communications and headless API services. A business using INPROFIC may have its own privacy obligations and policy for information it controls. Third-party websites, payment providers, delivery providers and other services linked to or integrated with INPROFIC may also apply their own privacy terms.
Information we collect
Information you provide
- Account and workspace information, such as name, username, business name, email address, phone number, role and service type.
- Business operational information entered into the platform, including products, inventory, recipes or formulas, procurement, production, sales, expenses, finance, customer orders, delivery records, reports and audit information.
- Commerce and customer information needed to place, fulfil and support orders, such as customer name, contact details, delivery address, order contents, fulfilment choices and delivery instructions.
- Payment-related information, such as transaction references, payment status, account-selection details and transfer proof uploaded for verification. Where a third-party payment provider handles payment credentials, those credentials are handled under that provider's systems and terms rather than being stored by INPROFIC unless expressly stated.
- Delivery information, including assignment and route details, estimated arrival times, delivery status, customer-rider messages and delivery reports created while a delivery is active.
- Files you choose to upload, such as storefront branding, payment evidence, business backup files or other documents used by an enabled feature.
- Information you send when contacting support or otherwise communicating with us.
Information collected automatically
- Basic device and request information such as IP address, browser or device type, operating environment, request timestamps and security-related request metadata.
- Session and authentication information needed to keep signed-in users connected to the correct workspace and to protect requests against misuse.
- First-party product analytics and operational events used to understand registrations, logins, subscription milestones and feature usage. INPROFIC is designed not to capture passwords, payment secrets or arbitrary form contents in product-analytics events.
- Web-push subscription information when a user expressly enables device notifications.
How we use information
We use information as reasonably necessary to:
- Create and administer accounts, workspaces, subscriptions, roles and access controls;
- Provide inventory, procurement, production, sales, commerce, finance, delivery, reporting, API and related platform functions;
- Process and reconcile orders and payment states, including staff verification where a payment method requires it;
- Coordinate delivery assignments, route-aware estimates, live status updates and delivery communications;
- Send transactional, security, operational and service notifications;
- Provide customer support, diagnose faults, maintain service reliability and improve performance;
- Protect the Platform, Businesses and Users against fraud, abuse, unauthorised access and other security threats;
- Measure first-party product usage and improve INPROFIC's services; and
- Comply with applicable legal obligations and enforce our agreements.
Legal bases for processing
Where the Nigeria Data Protection Act 2023 or another law requiring a legal basis applies, processing may rely on consent, performance of a contract or steps requested before a contract, compliance with a legal obligation, protection of vital interests, public-interest grounds where applicable, or legitimate interests that do not override the rights and interests of the data subject. The applicable basis depends on the specific processing activity. A Business remains responsible for identifying an appropriate basis where it controls the information it places in INPROFIC.
Cookies and browser storage
INPROFIC uses a limited set of first-party cookies and browser-storage features that support core product functions. These may include:
- Session cookies used to keep authenticated users signed in, maintain secure customer/order continuity and remember the active business workspace.
- CSRF security cookies used to protect browser requests and form submissions against cross-site request forgery.
- Local or session storage used for functional preferences such as storefront baskets, interface state, onboarding state, notification-tray preferences and temporary checkout or tracking continuity.
These technologies are used for security and functionality rather than third-party behavioural advertising. INPROFIC does not load advertising or cross-site tracking cookies by default. If non-essential analytics or advertising technologies are introduced later, they should be subject to any consent or preference controls required by applicable law before they are activated.
You can clear or block cookies and browser storage using your browser controls, but disabling essential storage may prevent sign-in, checkout, saved basket, security or other core features from working correctly.
How information is shared
We may share or make information available only where reasonably necessary for the service, including with:
- Authorised users of the relevant business workspace according to configured roles and permissions;
- Payment providers selected by the business or customer for payment processing and confirmation;
- Delivery providers, in-house riders and authorised dispatch users for delivery fulfilment;
- Hosting, storage, email, web-push and other infrastructure providers that help operate INPROFIC;
- Professional advisers, regulators, courts or public authorities where disclosure is required or permitted by law; and
- A successor or relevant party in connection with a lawful business restructuring, financing, acquisition or transfer, subject to appropriate protections.
We do not sell personal information for monetary consideration.
Headless API and external websites
Businesses may use the INPROFIC headless API to present catalogue, checkout, receipt, order and other commerce functions inside their own websites or applications. The operator of that external website remains responsible for its own privacy notice, cookies and customer-facing collection practices. Information sent to INPROFIC through the API is handled under this policy and the applicable service relationship.
Data retention
We retain information for as long as reasonably necessary to provide the service, maintain operational and accounting records, meet contractual or legal requirements, resolve disputes, protect security and enforce agreements. Retention periods can differ by record type and Business configuration. Where a workspace or record is deleted, some information may remain for a limited period in backups, security records or records that must be retained by law before being deleted or anonymised in the ordinary course.
Data security
INPROFIC uses administrative and technical safeguards appropriate to the service, including role-based access controls, Business scoping, secure transport in production, CSRF protections, controlled secrets, audit-oriented records and other measures intended to protect confidentiality, integrity and availability. No internet transmission or storage system can be guaranteed to be completely secure.
Your privacy rights
Depending on applicable law and our role in relation to the information, you may have rights to request access to personal data, correction of inaccurate data, deletion or erasure in applicable circumstances, restriction or objection to certain processing, withdrawal of consent where consent is the basis, data portability where applicable, and information about the processing of your data. You may also have the right to lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.
If your information is controlled by a business using INPROFIC, we may direct your request to that business or assist it in responding, as appropriate.
International data transfers
INPROFIC may use infrastructure or service providers that process information in countries other than the country where it was originally collected. Where applicable law requires safeguards for an international transfer, the relevant controller will take reasonable steps to use an appropriate transfer mechanism or other lawful safeguard.
Children's privacy
INPROFIC is a business operations service and is not intended for children to create platform accounts on their own. Businesses using the platform should not submit children's personal information unless it is lawful, necessary for the relevant service and handled with any consent or safeguards required by applicable law.
Third-party services and links
INPROFIC may connect to third-party payment, delivery, communications or other services, or link to external websites. Those third parties control their own services and privacy practices. We encourage users and businesses to review the terms and privacy information of third parties they choose to use.
Marketing choices
Where we send optional promotional communications, recipients may opt out using the unsubscribe method provided in the communication or by contacting us. Opting out of marketing does not prevent necessary service, security, billing or transactional messages.
Changes to this policy
We may update this Privacy Policy when INPROFIC's services, legal requirements or data practices change. The public page will show the effective or updated date of the current policy. Where a change is material and additional notice is appropriate or legally required, we may provide notice through the platform or another suitable channel.
Contact us
Questions, privacy requests or concerns about this policy may be sent through the INPROFIC support contact shown on this page. Where a request relates to data controlled by an INPROFIC business customer, please identify the relevant business so the request can be routed appropriately.
Privacy contact
For privacy questions or requests, email support@inprofic.com.ng.
INPROFIC is an ITERATID LTD product.