Do not miss our big August Offer - August Offer

Give us your feedback about the new look - info@dimarkltd.co.uk

Free deliveries above £450 - See Our Shipping Policy

DIMARK PORTAL PRIVACY POLICY

# Dimark Portal Privacy Notice

**Last updated: 19 August 2026**

## 1. Who we are

Dimark Limited (“Dimark”, “we”, “us” or “our”) is the controller of the personal information described in this Privacy Notice.

**Dimark Limited**
Company number: 04996865
Registered office: Unit 4 & 5 Advent Business Park, 14 Advent Way, Edmonton, London N18 3AL
Email: [info@dimarkltd.co.uk](mailto:info@dimarkltd.co.uk)

This Privacy Notice applies to the **Dimark Portal** iPhone and iPad application and the customer registration process carried out through the application.

Dimark Portal is a business application used by authorised Dimark sales representatives, managers and office staff. Customers do not create or operate Dimark Portal accounts themselves. During an in-person business account application, an authorised Dimark representative may use the application to collect information from a customer, sole trader, director, guarantor or other person connected with the business.

This notice supplements any other privacy information provided by Dimark in connection with our websites, trading accounts or other services.

## 2. Whose information we process

Dimark Portal may process information relating to:

* authorised Dimark employees, sales representatives, managers and contractors using the application;
* prospective business customers;
* sole traders;
* company directors and officers;
* guarantors;
* site managers, employees and business contacts;
* witnesses to agreements or guarantees; and
* existing Dimark customers and their authorised contacts.

## 3. Information we collect

### Business and account information

We may collect business and trading names, legal structure, business activity, business start date, company registration number, VAT information, Self Assessment UTR where relevant, purchasing method, business addresses, billing and delivery addresses, business telephone numbers and email addresses, store type, trading locations and other information required to assess, establish or maintain a Dimark trade account.

For existing customers, Dimark Portal may also display information already held by Dimark, including customer account details, contact details, addresses, account status, account balance, notes and customer-specific pricing information.

### Personal information relating to directors, sole traders and other individuals

Where required for a business account application, we may collect:

* full name;
* position or relationship to the business;
* residential address;
* telephone and mobile numbers;
* email address;
* date of birth where required;
* business and trading contact details;
* information relating to a personal guarantee;
* information necessary for credit assessment, identity verification or fraud prevention; and
* other information supplied as part of the application.

### Identification and supporting documents

Where necessary for business onboarding, identity verification, credit assessment or due diligence, we may collect photographs or copies of documents including:

* passports;
* driving licences;
* identity or biometric residence cards;
* proof of residential address;
* utility bills or bank statements used as evidence of address;
* proof of business address;
* rates, lease or electricity documents;
* shop or premises photographs; and
* other supporting documentation provided for the application.

The application may use on-device technology to check whether a photographed document is sufficiently readable. Recognised document text used for this readability check is not retained by that function.

### Signatures and agreements

Dimark Portal may capture handwritten signatures and associated information where a customer, guarantor or witness signs a business agreement or personal guarantee.

We may also record which version of an agreement was accepted, when it was accepted, confirmations that information supplied is correct and other information necessary to evidence the application and agreement.

### Location information

During a customer registration visit, Dimark Portal may collect the location of the device being used by the sales representative.

Location may be recorded at specific points such as the start of the registration, acceptance of terms or signature of the application.

This information is used to provide an audit record of where and when the business application was completed, support fraud prevention and help maintain the integrity of the registration process.

Dimark Portal does **not** continuously track the location of customers or sales representatives and does not use background location tracking.

If location permission is not provided or a location cannot be obtained, the registration process may record the relevant time without a GPS location.

Location may also be used when selecting or confirming business, shop or delivery locations.

### Communication and marketing preferences

We may record whether a customer wishes to receive communications such as:

* agreement documents;
* online-account invitations;
* marketing emails;
* marketing SMS messages; and
* marketing messages through supported messaging services.

Optional marketing choices are kept separate from acceptance of the business agreement. Marketing options are not selected automatically.

Where we rely on consent for marketing, consent can be withdrawn at any time.

### Information relating to credit assessment

Where a credit account is requested, we may collect information required to assess the application and may carry out credit-reference, identity-verification and fraud-prevention checks.

The application records the relevant acknowledgement or authorisation during the registration process. Credit-reference checks are carried out through Dimark's business processes and are not performed directly by the iPhone or iPad itself.

Information may be shared with credit-reference, fraud-prevention or identity-verification organisations where necessary for this purpose.

### Information about Dimark Portal users

For authorised staff using the application, we may process:

* username and authentication information;
* name;
* work email address;
* telephone and mobile numbers;
* user or sales-representative code;
* role and access permissions;
* profile and witness information;
* working hours;
* device session information; and
* customer/account information needed for the employee's work.

Authentication information and session credentials are stored using security features provided by iOS.

## 4. How we obtain information

We obtain personal information in several ways.

Most customer-registration information is provided directly during an in-person registration carried out by a Dimark representative.

Some company information may be obtained from publicly available official sources such as Companies House to assist with company verification. Information obtained from these sources may be presented during the application so that it can be reviewed and confirmed.

Address and location information may be assisted by mapping or address-search services.

Information about existing Dimark customers may be supplied from Dimark's existing business and account systems through the Dimark backend.

## 5. Why we use personal information

We use personal information where necessary to:

* take steps requested by a customer before entering into a business relationship;
* assess and process applications for Dimark trade accounts;
* verify the identity of applicants, directors, sole traders and guarantors;
* verify businesses and trading locations;
* assess creditworthiness and credit risk;
* prevent and detect fraud or misuse;
* establish and administer customer accounts;
* administer personal guarantees and business agreements;
* provide appropriate customer-specific pricing and account information to authorised sales representatives;
* arrange deliveries and maintain accurate trading-location information;
* maintain evidence and audit records of applications;
* comply with legal, regulatory, tax, accounting and record-keeping obligations;
* protect Dimark, its customers and its systems;
* manage authorised employee access to Dimark Portal; and
* provide marketing communications where permitted and where any required consent has been obtained.

Depending on the particular purpose, our lawful basis may include taking steps before or performing a contract, complying with a legal obligation, pursuing Dimark's legitimate interests in operating and protecting its business, assessing commercial and credit risk and preventing fraud, or consent where consent is appropriate, including certain marketing communications.

Where we rely on legitimate interests, we consider whether the use of the information is necessary and whether those interests are overridden by the rights and interests of the individual.

## 6. Customer privacy information during registration

Before personal and business information is collected during a new Dimark Portal registration, the application presents a privacy notice explaining how the information will be used and provides access to this full Privacy Notice.

The privacy notice may be stored on the device so that it remains available when the sales representative is working offline.

Dimark may maintain version information so that we can identify which version of the privacy information was presented during a particular registration.

Providing privacy information is separate from accepting Dimark's trading terms, signing a personal guarantee, confirming that information supplied is correct, authorising applicable credit checks or selecting marketing preferences.

## 7. How information is stored on the iPhone or iPad

Dimark Portal is designed to work offline.

This means some information may be temporarily stored on the authorised sales representative's device while the representative is working without an internet connection.

Registration drafts, supporting documents and signatures may therefore remain securely within the application's private storage until they can be submitted to Dimark.

Following successful submission, the registration becomes restricted from normal access by the sales representative.

If Dimark's office identifies a correction that is required, authorised office staff may return the registration to the assigned representative. The registration may then be downloaded or reopened on the device so that the required correction can be made.

After the corrected registration is submitted, access is restricted again.

Submitted registration information stored locally on the device is automatically removed after a limited retention period configured by Dimark. The current standard local retention period is **30 days following successful submission**, although information may be removed earlier where appropriate.

Removal from the iPhone or iPad does not necessarily delete records retained by Dimark's central business systems where those records remain necessary for account administration, due diligence, legal compliance, fraud prevention, credit assessment or other legitimate record-keeping purposes.

## 8. How long we keep information

We do not keep personal information for longer than necessary for the purposes for which it is used.

Different categories of information may therefore have different retention periods.

Registration drafts remain on the authorised device while the registration is being prepared, subject to local cleanup processes.

Submitted registrations and attachments held on the device are retained only temporarily and are normally removed automatically after the local retention period described above.

Information held by Dimark's central systems may be retained for longer where necessary for the operation of a customer's account, the establishment or defence of legal claims, accounting or tax obligations, customer due diligence, credit or fraud-prevention requirements, or another legal or regulatory requirement.

When information is no longer required, it will be deleted, anonymised or otherwise securely disposed of in accordance with Dimark's retention procedures.

## 9. Who we share information with

Personal information may be made available only where necessary to authorised Dimark employees and personnel whose responsibilities require access to it.

We may also use service providers and external organisations for purposes including:

* hosting Dimark's backend systems and databases;
* secure document and file storage;
* company verification through Companies House;
* address and location lookup services;
* mapping and delivery-location services;
* credit-reference and fraud-prevention services;
* professional legal, accounting, insurance or compliance services; and
* other technical providers required to operate and secure Dimark Portal.

The current technical infrastructure includes cloud hosting and storage services used by Dimark, including Railway and Cloudflare services.

Some address and mapping functionality may use Google, Apple MapKit and what3words services. Companies House information may be used to assist with UK company verification.

Where an external provider processes personal information on our behalf, we require appropriate protection of that information in accordance with applicable data-protection requirements.

We do **not** sell personal information.

Dimark Portal does not contain third-party advertising and does not use personal information to track people across apps or websites owned by other companies for advertising purposes.

## 10. International processing

Some technology and cloud-service providers used by Dimark may process or store information outside the United Kingdom.

Where UK data-protection law treats this as a restricted international transfer, Dimark will use an applicable legal transfer mechanism, such as relevant adequacy regulations or appropriate contractual safeguards.

**[Before publication: Dimark should confirm the production Railway and Cloudflare storage regions and the transfer safeguards applying to each service.]**

## 11. Security

Dimark uses technical and organisational measures intended to protect information against unauthorised access, alteration, disclosure or loss.

These measures include encrypted network communications, authenticated access to Dimark systems, role-based permissions, iOS secure credential storage, restricted storage for registration documents and controls that restrict access to submitted registrations.

Sensitive registration information is not intended to remain permanently accessible to the sales representative. Submitted registrations are normally locked, and they can only be made available again where authorised office staff return the registration for correction.

No method of electronic storage or transmission can be guaranteed to be completely secure, but we review our measures according to the nature and sensitivity of the information being processed.

## 12. Camera and photo access

Dimark Portal may use the device camera to photograph identification documents, proof-of-address documents, proof-of-business documents and business premises required for customer registration.

Where the representative selects an existing photograph, the application only uses the photograph specifically selected for the registration.

Dimark Portal does not upload the contents of the device's photo library generally.

## 13. Marketing

Marketing preferences are separate from the business-account application and trading agreement.

Where consent is required and you have agreed to receive marketing, you may withdraw that consent at any time by contacting Dimark or using any unsubscribe method provided in the relevant communication.

Withdrawing marketing consent does not affect the operation of an existing trading account or the lawfulness of processing carried out before consent was withdrawn.

## 14. Your data-protection rights

Depending on the circumstances and the lawful basis on which we use your information, you may have rights to:

* request access to personal information we hold about you;
* ask us to correct inaccurate or incomplete information;
* request deletion of information in certain circumstances;
* request restriction of processing;
* object to certain uses of your information, including direct marketing;
* request portability of certain information; and
* withdraw consent where our processing is based on consent.

These rights are not absolute. For example, Dimark may need to retain certain information where it has a legal obligation to do so or where the information is required for the establishment, exercise or defence of legal claims.

To exercise your rights, contact Dimark using the details below.

## 15. Complaints

If you have concerns about how we use your personal information, please contact us first so that we can investigate.

You also have the right to complain to the **Information Commissioner's Office (ICO)**, the UK's data-protection regulator.

## 16. Children

Dimark Portal is a business application used for trade-account management and business customer registration.

It is not intended for use by children and Dimark does not knowingly use the application to establish trading accounts for children.

## 17. Changes to this Privacy Notice

We may update this Privacy Notice when our services, legal requirements or data-processing activities change.

The latest version will be made available through Dimark's website and Dimark Portal.

The application may also store the current published privacy notice locally so that it remains available during offline customer registrations.

## 18. Contact us

For questions about this Privacy Notice, how Dimark uses personal information or to exercise a data-protection right, contact:

**Dimark Limited**
Unit 4 & 5 Advent Business Park
14 Advent Way
Edmonton
London N18 3AL

Email: **[info@dimarkltd.co.uk](mailto:info@dimarkltd.co.uk)**