Data processing terms
Our Article 28 obligations when we handle your people's data. Last updated 20 August 2026.
Who is who
When your organisation loads the names and badge numbers of your staff into Nilstock, you are the controller and we are your processor. Those people did not sign up to us; they work for you, and you decided to record what they take from the store. We hold their data on your instructions and do nothing else with it.
Separately, for the handful of people who sign in to the back office — including you — we are the controller of their account data, because that is our relationship with them directly. Our privacy policy covers that half.
These terms form part of the terms of service and apply automatically. You do not need to ask us to sign a separate agreement, though we are happy to sign yours if your procurement needs a countersigned document.
What we process, and why
| Subject matter | Providing the Nilstock stock control and equipment custody service. |
|---|---|
| Duration | For as long as your account is open, plus 30 days. |
| Categories of data subject | Your employees, contractors and anyone else you enrol as a store user; and your own staff who hold back-office accounts. |
| Categories of personal data | Name, employee number, badge or card identifier, department, work email address where you supply one, and the record of what each person took, returned or holds. |
| Special category data | None. There is no field for it, and the acceptable use policy asks you not to put it anywhere else. |
| Nature of processing | Storage, retrieval, display, aggregation into reports, and transmission of reminder emails to the people who hold overdue equipment. |
What we undertake
- Only on your instructions. We process your data to run the service and for nothing else. We do not sell it, mine it, or use it to train anything.
- Confidentiality. Anyone with access is bound to keep it confidential. In practice access is limited to the people who operate the platform, and the internal console they use is deliberately built so it cannot read your ledger — it sees counts and billing state, not movements. Every support action taken on your account is written to your audit log with the name of who did it.
- Security. Set out on the security page, including the parts we have not done yet. Passwords and PINs are hashed with Argon2id; session, device and terminal tokens are stored only as hashes; tenant isolation is enforced centrally in the data layer rather than trusted to each query.
- Sub-processors. Three, listed at /legal/sub-processors. We will give notice before adding another, and if you object on reasonable grounds you may leave without penalty for the rest of the term.
- Helping you answer people. If one of your staff asks what you hold about them, everything is exportable to CSV from the account without asking us. If you need something the interface cannot produce, we will help.
- Breach notice. Without undue delay and in any case within 48 hours of becoming aware, with what we know at that point — we will not sit on it while we assemble a complete picture.
- Deletion. On request, or 30 days after your account closes. Backups age out on their own schedule, which is at most 90 days; we will not restore a deleted account from one.
- Audit. We will answer a security questionnaire and provide what we have. We are a small company and do not yet hold SOC 2 or ISO 27001 — saying so plainly is more useful to you than a maybe.
Where the data is
Your account data is held in the EU. Two of our sub-processors — Stripe and Resend — also operate in the United States; transfers to them rely on the UK addendum to the EU standard contractual clauses, and in Stripe’s case additionally on the EU–US Data Privacy Framework. Neither receives stock, ledger or employee records: Stripe sees a billing email address, and Resend sees the recipient and content of the emails we send on your behalf.
Being straight about the gaps
These terms have not yet been reviewed by a solicitor, and we would rather tell you that than let you find out. If your legal team wants changes, send them — for a first customer that is a conversation we want to have, not an obstacle.
Questions to [email protected].