This policy explains how DPLIGHT handles data needed to operate its B2B platform.
1. Controller
The DPLIGHT entity for the relevant market manages platform data. DPLIGHT DRC operational address: Kampala, Uganda. The final legal name and privacy contact remain subject to legal confirmation.
2. Data collected
We may process contact and company details, verification and security data, addresses, orders, payment proofs, messages, device information, IP addresses and logs.
3. Purposes
Data is used to manage accounts, orders, payments, delivery and support, prevent fraud, maintain audit records and meet legal obligations.
4. Sharing
Data is shared only as necessary with authorised staff, technical providers, warehouses, logistics providers, banks, advisers, auditors and lawful authorities. It is not sold.
5. International processing
Some providers may process data outside the customer’s country. DPLIGHT will document safeguards required by applicable law.
6. Retention
Data is retained as needed for service, security, accounting, tax, dispute and legal requirements.
7. Security
Controls include access restriction, password hashing, code expiry, audit records and transport encryption.
8. Rights
Subject to applicable law, you may request access, correction, applicable deletion, restriction or objection through the official support channel.
9. Updates
Material updates receive a new version and effective date.
Operational draft subject to local legal review; the detailed retention schedule and privacy contact will be confirmed in a future version.
