Privacy & Data Policy
Comprehensive details on how Smart Duuka handles, protects, and utilizes your enterprise data across our retail, manufacturing, and HR ecosystems.
Last Updated: April 27, 2026
1. Scope & Introduction
This Privacy Policy applies to the Smart Duuka operating system, SmartServe POS, our mobile applications, and associated services provided by Digi-volve Technologies Limited. It governs how we collect, process, and safeguard the data of our tenants (businesses) and their end-users (employees and customers).
By utilizing our suite of tools, you consent to the data practices described in this comprehensive policy.
2. Information We Collect
To provide a robust multi-tenant environment, we collect several categories of data:
- Registration & Account Data: Company name, tax identification numbers, physical addresses, and primary administrator contact details (email, phone).
- Authentication Data: Encrypted passwords, active session tokens, and 2-Factor Authentication (2FA) verification logs.
- Operational Data: Real-time inventory levels, supply chain records, human resource files (including employee payroll data), and systemic cash flow movements.
- Customer Data (Processed on your behalf): Names, contact details, and purchase histories of your clients entered into the CRM and receipting modules.
- Device & Diagnostic Data: IP addresses, browser types, and crash reports to help us maintain system stability.
3. How We Use Your Data
We do not sell your data. We utilize the information collected strictly for the following purposes:
- To provide, maintain, and improve the Smart Duuka and SmartServe POS infrastructure.
- To process transactions and generate accurate financial and operational reports.
- To authenticate users and prevent fraudulent activity.
- To send critical system alerts, maintenance updates, and administrative communications.
- To comply with legal obligations and regulatory requirements.
4. Third-Party Integrations & Data Sharing
Smart Duuka securely shares necessary data payloads with verified third-party partners strictly to fulfill operational features requested by your business.
EFRIS (URA)
For tax compliance and automated e-invoicing, necessary transaction and fiscal data are securely transmitted to the Uganda Revenue Authority's Electronic Fiscal Receipting and Invoicing Solution API.
WhatsApp Business API
Utilized for real-time alerts, digital customer receipts, and operational notifications. Only specific messaging payloads (phone numbers and message templates) are shared with Meta's infrastructure.
Cloud Infrastructure (Backblaze & VPS Providers)
Your data is stored on our secure VPS infrastructure and backed up to Backblaze B2. These providers process data entirely encrypted and have no direct access to the plaintext contents of your databases.
5. Data Retention & Financial Immutability
We retain your account and operational data for as long as your tenant account is active.
Principle of Immutability
A core principle of our architecture is the absolute integrity of financial records. Once a transaction, cash flow movement, or invoice is completed, it is immutable. Users cannot hard-delete or silently modify historical financial data. Adjustments require logged reversing entries.
Upon account termination, operational data can be exported. We will securely purge non-financial data within 90 days of termination, though certain fiscal records may be retained longer to comply with local tax laws.
6. Security Measures
We implement enterprise-grade security to protect your multi-tenant environment:
- Infrastructure: Hosted on secure Virtual Private Servers (VPS) with stringent Nginx firewall rules and restricted port access.
- Encryption: All data in transit is encrypted using modern TLS protocols. Passwords and sensitive tokens are heavily hashed.
- Automated Backups: To guarantee data survival, Smart Duuka employs high-frequency cron-based rotations. Databases are securely offloaded to cloud storage every two hours.
7. Your Data Rights
Depending on your jurisdiction, you retain the following rights concerning your data:
- The Right to Access: Request a full export of your tenant data.
- The Right to Rectification: Correct inaccurate operational or profile data (excluding immutable financial logs).
- The Right to Restrict Processing: Request a temporary pause on specific data processing activities.
To exercise these rights, the primary tenant administrator must contact our support team.
9. Contact Us
If you have questions regarding this Privacy Policy, your data rights, or wish to report a security concern, please contact our administrative team: