Dimark Portal Privacy Notice
Last updated: 6 October 2026
1. Who we are
Dimark Limited (“Dimark”, “we”, “us” or “our”) is the controller of the personal information described in this Privacy Notice.
Dimark Limited
Company number: 04996865
Unit 4 & 5 Advent Business Park
14 Advent Way
Edmonton
London N18 3AL
United Kingdom
Email: info@dimarkltd.co.uk
This Privacy Notice applies to Dimark Portal, our iPhone and iPad application used by authorised Dimark employees and sales representatives for business-customer registration, account management and related business activities.
Customers do not create or operate Dimark Portal user accounts themselves.
During a business-account registration, an authorised Dimark representative may use the app to collect information from or about a business applicant, sole trader, director, partner, guarantor, site manager, employee, witness or another person connected with the business.
This Privacy Notice supplements any other privacy information provided by Dimark in connection with our websites, customer accounts, online services and other business activities.
---
2. Who this Privacy Notice covers
The app may process information relating to:
* authorised Dimark employees and sales representatives using the app;
* prospective business customers;
* existing business customers;
* sole traders;
* company directors and officers;
* partners;
* guarantors;
* site managers and employees;
* business contacts;
* witnesses to agreements or guarantees; and
* other individuals whose information is provided in connection with a business-account application or customer relationship.
The person operating the app will normally be an authorised Dimark employee or sales representative.
The customer, applicant, sole trader, director, partner, guarantor or other person whose information is collected through the app is not normally a user of the app.
---
3. Business and account information we collect
We may collect business and account information including:
* business or trading name;
* legal company name;
* legal structure;
* nature of the business;
* business start date;
* company registration number;
* VAT number and VAT status;
* Self Assessment Unique Taxpayer Reference where relevant;
* purchasing or trading method;
* registered office address;
* billing address;
* trading addresses;
* delivery addresses;
* business telephone numbers;
* business email addresses;
* business contacts;
* number and location of trading sites;
* store or business type;
* information relevant to account administration;
* account notes; and
* other information required to establish, manage or update a Dimark business account.
For existing customers, the app may also display information already held by Dimark, including:
* customer account number;
* trading and company name;
* business and contact addresses;
* contact names;
* telephone and mobile numbers;
* email addresses;
* VAT and company-registration details;
* customer account status;
* customer account balance;
* account notes;
* assigned sales representative; and
* customer-specific pricing information.
---
4. Personal information relating to individuals connected with a business
Where necessary for a business-account application or an existing customer relationship, we may collect personal information relating to individuals connected with the business.
This may include:
* full name;
* position or relationship to the business;
* residential address;
* telephone number;
* mobile number;
* email address;
* date of birth where required;
* business contact information;
* information relating to a personal guarantee;
* information required for identity or business verification;
* information relevant to fraud prevention;
* information relevant to assessing commercial or credit risk; and
* other information provided during the application or customer relationship.
Information concerning an identifiable sole trader, director, partner, guarantor, employee or other individual is personal information even where it is provided in connection with a business.
---
5. Identification and supporting documents
Where necessary for business onboarding, verification, due diligence, fraud prevention or account administration, we may collect photographs or copies of supporting documents.
These may include:
* passport;
* driving licence;
* identity card;
* biometric residence card;
* proof of residential address;
* utility bill;
* bank statement used as evidence of address;
* proof of business address;
* business rates documentation;
* lease documentation;
* electricity or other utility documentation;
* business premises photographs;
* shop exterior photographs;
* signage photographs; and
* other evidence provided in support of an application.
The app may use on-device technology to check whether a photographed document is sufficiently readable.
Where this functionality is used, text recognised solely for the purpose of checking document readability remains on the device and is not sent to an external service or retained by that function.
Dimark does not use identity photographs for facial recognition or biometric identification.
---
6. Personal guarantees
Every business-account application includes a personal guarantee.
The guarantor will normally be a director or sole trader connected with the business application.
For a guarantor, Dimark may collect:
* full name;
* home address;
* signature;
* photographic identification; and
* proof of residential address.
Date of birth is also required where the applicant is a sole trader.
The personal guarantee forms part of the business-account application.
The guarantor is not credit-checked as a private individual.
Where credit is offered, the credit assessment relates to the business.
Information concerning the guarantor may be processed for the purposes of establishing, administering and, where necessary, enforcing the personal guarantee.
---
7. Signatures and agreements
The app may capture handwritten signatures where an applicant, guarantor or witness signs a business agreement, guarantee or related declaration.
We may also record information including:
* who signed;
* the date and time of signing;
* the version of the relevant agreement or guarantee;
* confirmation that information supplied is correct;
* acceptance of applicable business terms;
* witness information;
* declarations relating to business verification or creditworthiness; and
* other information required to evidence the application, agreement or guarantee.
---
8. Location information
During an in-person business registration, the app may collect the location of the device being used by the authorised Dimark representative.
Location may be recorded at particular stages of the registration process.
Location information may include:
* latitude;
* longitude;
* location accuracy; and
* date and time.
We may use this information to:
* maintain an audit record showing where and when an application was completed;
* confirm that a registration was carried out at or near the customer’s business location;
* support process integrity;
* assist with fraud prevention;
* help verify business and trading locations; and
* assist with delivery-location information.
Location access is optional.
If location access is refused, unavailable or cannot be obtained, the registration can still continue.
In those circumstances, the app may record the relevant date and time without recording GPS coordinates.
A business or delivery location may also be selected manually or pinned using an address.
The app does not continuously track customers or Dimark employees.
The app does not use background location tracking.
---
9. Business verification and Companies House
Where appropriate, Dimark may verify information about a UK company using Companies House.
A company name or company number may be sent to Companies House as part of a search.
Information returned may include:
* company name;
* company number;
* registered office address;
* company status; and
* names of company officers.
This information may be displayed to the authorised Dimark representative so that it can be reviewed and confirmed as part of the business-account application.
---
10. Business credit assessment
Business information collected through the app may later be reviewed by authorised Dimark office or credit-control staff as part of the customer-account approval process.
The app itself does not carry out credit-reference searches, retrieve credit scores or make credit decisions.
Where a customer requests credit terms, authorised Dimark staff may separately use business-information services such as Creditsafe.
This may include reviewing information concerning:
* the business;
* financial standing;
* business credit score;
* recommended credit limit;
* payment history;
* insolvency information;
* County Court Judgments;
* outstanding debts; and
* other information relevant to assessing commercial credit risk.
These checks relate to prospective or existing business customers, including:
* limited companies;
* partnerships; and
* sole traders.
They are not consumer lending checks on the Dimark employee using the app.
They are also not private-individual credit checks on a guarantor.
For a sole trader, business information may necessarily relate to the individual because the individual operates the business in their own capacity.
Credit decisions are made by authorised Dimark office or credit-control personnel.
The final decision on whether to open an account, supply goods on credit and determine an appropriate credit limit is made by Dimark staff.
The app does not make decisions based solely on automated processing.
---
11. Communication and marketing preferences
During registration, Dimark may record communication preferences.
These may include whether a customer wishes to receive:
* agreement documents by email;
* an invitation to access an online customer account;
* marketing emails;
* marketing SMS messages; and
* marketing communications through WhatsApp.
Each marketing preference is recorded separately.
Marketing options are not selected automatically.
Operational communications necessary to establish, administer or service a business account are separate from optional marketing communications.
Where we rely on consent for marketing, the individual may withdraw that consent at any time.
Withdrawing marketing consent will not affect the operation of an existing Dimark business account or the lawfulness of processing carried out before consent was withdrawn.
The app records these preferences but does not itself send marketing emails, SMS messages or WhatsApp messages.
---
12. Optional online shop account
Customers may choose to request access to Dimark’s online business shop.
Where requested, Dimark may create a separate customer account on its Shopify-based online shop so that the customer can view prices, stock availability and place orders without a sales visit.
The app records whether the customer has requested an invitation.
The app does not itself create or send the online-shop account email.
Where an online-shop account is created, relevant customer details are provided to Shopify so that the account can be created and operated.
Use of the online shop is optional and is separate from use of the app by Dimark employees.
---
13. Information relating to authorised app users
The app is used by authorised Dimark employees and sales representatives.
For authorised users, we may process information including:
* name;
* username or sales-representative code;
* authentication information;
* work email address;
* telephone or mobile number;
* home address where required for witness details;
* role;
* system permissions;
* customer assignments; and
* application activity required to perform the user’s authorised role.
Working-hours information may also be stored locally on the device where used.
Location may be recorded during a customer registration where the authorised user has allowed location access.
The app does not continuously monitor the user’s location.
A local device identifier may be stored on the iPhone or iPad so that the device can recognise itself.
This local device identifier is not sent to the Dimark server.
---
14. Technical and security logs
Dimark’s server may keep ordinary technical and security logs.
These may include:
* IP address;
* date and time; and
* whether a login attempt succeeded or failed.
Dimark does not record the user’s device model, iOS version or app version as part of these logs.
These logs may be used for:
* system administration;
* security monitoring;
* troubleshooting;
* investigating unauthorised access; and
* protecting Dimark’s systems.
---
15. How we collect information
Information may be obtained:
* directly from an applicant during an in-person registration;
* from a director, sole trader, partner, guarantor or other person connected with an application;
* from an authorised Dimark representative entering information into the app;
* from documents photographed or selected for a registration;
* from Companies House;
* from address, mapping or location services;
* from business-information services used separately by authorised Dimark staff;
* from Dimark’s existing customer and business systems; and
* through the operation of the app and Dimark’s internal systems.
---
16. Why we use personal information
Depending on the circumstances, we may use personal information to:
* take steps requested before entering into a business relationship;
* assess and process a business-account application;
* establish and maintain a business trading relationship;
* verify applicants and businesses;
* carry out appropriate due diligence;
* prevent and detect fraud;
* assess commercial and credit risk;
* determine whether goods may be supplied on credit;
* determine an appropriate credit limit;
* administer personal guarantees;
* maintain records of applications and agreements;
* establish, administer and service customer accounts;
* process customer orders;
* supply goods;
* issue invoices, statements and other account documentation;
* collect and reconcile payments;
* maintain accounting and tax records;
* provide authorised sales representatives with information necessary to manage assigned customers;
* provide customer-specific pricing;
* arrange and administer deliveries;
* verify business and delivery locations;
* maintain appropriate audit records;
* comply with legal, tax, accounting and record-keeping obligations;
* protect Dimark, its customers, staff and systems;
* administer authorised employee access;
* respond to queries or complaints; and
* provide marketing communications where permitted.
---
17. Our lawful bases for processing
The lawful basis we rely on depends on the information concerned and the purpose for which it is used.
Contract and steps before entering into a contract
We may process information where necessary to consider a business-account application, enter into an agreement, supply goods or administer an existing business relationship.
Legal obligation
We may process or retain information where necessary to meet legal, tax, accounting, regulatory or record-keeping obligations.
Legitimate interests
We may process information where necessary for legitimate business purposes, including:
* verifying businesses and applicants;
* preventing fraud;
* assessing commercial and credit risk;
* maintaining accurate customer records;
* managing customer relationships;
* protecting Dimark’s systems and business;
* administering and collecting customer accounts;
* maintaining audit records; and
* managing business operations.
Where we rely on legitimate interests, we consider whether the processing is necessary and whether those interests are overridden by the rights and interests of the individual.
Consent
We may rely on consent where appropriate, particularly for certain optional marketing communications.
Where processing is based on consent, consent may be withdrawn at any time.
Withdrawal of consent does not affect processing lawfully carried out before consent was withdrawn.
---
18. Information required to open an account
Certain information is required so that Dimark can properly verify the applicant and decide whether a trade account can be opened.
This may include required business information, photographic identification and proof of address.
If the customer does not provide information that Dimark reasonably requires for these checks, Dimark may be unable to open the trade account.
Optional information and optional marketing choices are kept separate from information required to process the account application.
---
19. Privacy information shown during customer registration
Before personal and business information is collected during a new customer registration, the app presents privacy information explaining how information will be used.
The initial screen may provide a concise summary together with access to this full Privacy Notice.
The Privacy Notice may be downloaded and stored securely within the app so that it remains available when a sales representative is working offline.
Dimark may record:
* the privacy-notice version number;
* the effective date; and
* the date and time the notice was presented.
This allows Dimark to identify which version of the privacy information was provided during a particular registration.
The Privacy Notice is separate from:
* Dimark’s business terms;
* confirmation that supplied information is accurate;
* personal guarantees;
* business-verification or creditworthiness declarations; and
* optional marketing preferences.
---
20. Offline operation and information stored on the iPhone or iPad
The app is designed to operate in locations where a reliable internet connection may not be available.
As a result, some information may be temporarily stored within the app’s private storage on an authorised iPhone or iPad.
This may include:
* registration drafts;
* personal and business information entered during registration;
* supporting documents;
* identification photographs;
* business photographs;
* signatures; and
* information required to complete and submit a registration.
Draft registrations may remain locally on the authorised device until they are submitted or deleted in accordance with Dimark’s procedures.
Once a registration has been successfully submitted, normal access to that registration is restricted for the sales representative.
---
21. Corrections to submitted registrations
Submitted registrations are normally locked from further editing by the sales representative.
If authorised Dimark office staff identify an error, missing information or another issue requiring correction, the registration may be returned to the assigned sales representative.
Where necessary, the relevant registration and supporting information may be securely made available on the authorised device again so that the requested correction can be completed.
The sales representative can then amend the relevant information and resubmit the registration.
After resubmission, normal access is restricted again.
Sales representatives cannot independently reopen submitted registrations without the appropriate office-controlled correction process.
---
22. Local device retention
Submitted registration information stored locally on an authorised iPhone or iPad is retained only temporarily.
Dimark currently operates a standard local retention period of approximately **30 days following successful submission**, subject to system configuration and operational requirements.
Local information may be removed earlier where appropriate.
This local deletion may remove:
* registration information;
* identity-document copies;
* supporting documents;
* signatures;
* local photographs; and
* other registration attachments.
Removing information from the iPhone or iPad removes only that device’s local copy.
It does not by itself delete information held within Dimark’s central systems.
---
23. Online registration files
Registration files uploaded through the app may include:
* identification photographs;
* proof-of-address documents;
* shop or business photographs;
* signatures; and
* other registration attachments.
Online copies of these registration files are stored temporarily using Cloudflare R2.
Dimark intends to remove these online file copies after approximately **45 days**.
This deletion relates to the online copies stored through Cloudflare.
Dimark may retain other records, including paper copies and customer-account records, for longer where required for the ongoing customer relationship, legal obligations or legitimate business purposes.
Deletion of online copies is currently administered by authorised Dimark office staff.
---
24. Rejected applications
Where an application is rejected and no customer account is opened, Dimark normally keeps the application for approximately one month.
This allows time for the applicant to provide missing or corrected information where appropriate.
After that period, the rejected application is normally deleted in full.
This includes, where applicable:
* application details;
* identification documents;
* proof-of-address documents;
* photographs;
* signatures;
* supporting documents; and
* server copies.
Deletion is carried out by authorised Dimark office staff.
Information may be retained for longer only where Dimark has a specific legal or legitimate reason to do so.
---
25. Retention for accepted customers
Where a business becomes a Dimark customer, customer and account records are normally retained for as long as the account remains open.
After the account closes, relevant records are normally retained for **six years**.
This may include:
* customer account information;
* customer and trading addresses;
* business contact information;
* orders;
* invoices;
* credit notes;
* payment and account records;
* delivery information;
* transaction history;
* agreements;
* personal guarantees;
* supporting records; and
* information necessary to understand or evidence transactions.
Paper copies of relevant registration documents may also be retained as part of the customer record.
Some information may need to be retained for longer where this is required or justified, for example where:
* money remains outstanding;
* a contractual obligation remains in force;
* a personal guarantee remains relevant;
* a dispute or legal claim exists or may reasonably arise;
* a legal or regulatory requirement applies; or
* information is required for the establishment, exercise or defence of legal claims.
Where Dimark is permitted to delete information earlier following a valid request, it may do so.
When personal information is no longer required for a lawful purpose, it will be deleted, anonymised or securely disposed of in accordance with Dimark’s procedures.
---
26. Services used by the app
The app does **not** include third-party advertising, analytics or crash-reporting kits.
The following external services may be used where necessary for the operation of the app.
Apple
The app runs on Apple iPhone and iPad devices.
Apple mapping services may be used for address searching and map functionality.
Device location may also be used where the authorised Dimark representative allows location access during a registration.
Google Places
If Apple Maps does not return a suitable address, a typed address search may be sent to Google Places through Dimark’s server.
Only the search information necessary to perform the address lookup is used for this purpose.
Dimark does not intentionally send customer names, telephone numbers, email addresses, identity documents, account balances or other customer-account information to Google for address searching.
The app may also make a connectivity check involving Google.
This connectivity check does not send customer information.
what3words
Where this functionality is used, the latitude and longitude of a selected map location may be sent to what3words so that the location can be converted into a three-word address.
Companies House
A company name or company number may be sent to Companies House for a company search.
Companies House may return information including:
* company name;
* company number;
* registered office address;
* company status; and
* names of company officers.
Cloudflare R2
Registration files may be stored temporarily using Cloudflare R2 after they are uploaded through Dimark’s systems.
These files may include:
* identity photographs;
* proof-of-address documents;
* shop photographs;
* signatures; and
* other registration attachments.
Catalogue photographs may also be stored using Cloudflare R2.
Dimark does not currently restrict Cloudflare R2 storage to a UK-only or EU-only location.
Hetzner
Dimark uses dedicated server infrastructure supplied by Hetzner.
The server used by Dimark is located in **Finland**.
The app connects to this infrastructure for functions including:
* authentication;
* synchronisation;
* registration processing;
* customer information;
* catalogue information; and
* related backend operations.
Customer, registration and catalogue information may pass through or be stored on this infrastructure as part of the normal operation of the app.
---
27. Other organisations we may share information with
Access within Dimark is restricted to authorised personnel who require the information for their role.
Depending on the circumstances, personal or business information may also be shared with organisations including:
* accountants;
* insurers;
* delivery or courier companies;
* solicitors;
* debt-collection agencies;
* payment providers;
* email, SMS or WhatsApp service providers;
* Shopify, where an optional online-shop account is created;
* Creditsafe, where authorised office staff carry out a business credit assessment; and
* other professional or technical service providers where necessary.
Delivery companies normally receive only the information required to perform the delivery, such as the business name and delivery address.
Solicitors, debt collectors, payment providers and communications providers are used only where relevant to the particular customer account or business process.
Where Dimark uses a service provider to process personal information on its behalf, we require the provider to process the information only for authorised purposes, protect it appropriately and comply with applicable data-protection requirements.
Dimark does **not** sell personal information.
---
28. International processing and transfers
Some service providers used by Dimark may process or store information outside the United Kingdom.
For example:
* Dimark’s Hetzner server is located in Finland;
* Cloudflare may process or store information through infrastructure in multiple countries; and
* other international technology providers may process information outside the United Kingdom.
Where applicable UK data-protection law treats this as a restricted international transfer, Dimark will use an appropriate legal transfer mechanism or safeguard.
This may include:
* UK adequacy regulations;
* recognised contractual safeguards; or
* another mechanism permitted by applicable data-protection law.
---
29. Camera and photographs
The app may use the device camera to photograph information required for a registration, including:
* identification documents;
* proof-of-address documents;
* proof-of-business documents;
* shop exterior;
* signage; and
* business premises.
Where an existing image is selected from the device, the app uses only the image specifically selected for the relevant registration.
The app does not upload the contents of the device’s photo library generally.
The app does not continuously record video or audio.
---
30. Payments and financial details
The app does not collect or display:
* payment-card numbers;
* bank-account details; or
* direct-debit details.
Payment-related information may be handled separately by Dimark or relevant payment providers where necessary for the customer relationship.
---
31. Sensitive information
Dimark does not intentionally collect through the app information about an individual’s:
* health or disability;
* race or ethnicity;
* religion or philosophical beliefs;
* political opinions;
* trade-union membership;
* sexual orientation; or
* criminal convictions.
A passport, driving licence or other identity photograph may be collected as identification evidence.
Dimark does not use these photographs for facial recognition or biometric identification.
Business classifications or preferences describing the type of goods a shop sells, such as Halal, South Asian or East Asian product ranges, relate to the business and its product requirements.
They are not intended to record the race, ethnicity or religion of the customer or any individual.
---
32. Tracking and advertising
The app does not:
* display third-party advertising;
* contain advertising SDKs;
* contain third-party analytics SDKs;
* contain third-party crash-reporting SDKs;
* use advertising identifiers for targeted advertising;
* track individuals across apps or websites owned by other companies for advertising purposes; or
* sell customer or staff information for advertising purposes.
---
33. Push notifications
The app does not use Apple Push Notification Service and does not send push notifications.
---
34. Children
The app is an internal business application used by authorised Dimark personnel for business-customer registration and account management.
It is not directed at children and is not intended to be used to establish business trading accounts for children.
---
35. How we protect information
Dimark uses technical and organisational measures designed to protect personal information against unauthorised access, disclosure, loss, misuse or alteration.
Measures may include:
* encrypted HTTPS communications;
* authenticated access to Dimark systems;
* access permissions based on authorised user roles;
* secure iOS credential storage;
* private application storage;
* dedicated server infrastructure;
* restricted access to registration documents;
* controls preventing sales representatives from normally accessing submitted registrations;
* office-controlled correction access;
* separation of sensitive registration documentation from ordinary catalogue information;
* local-device deletion procedures;
* online-file deletion procedures; and
* restrictions on access to company systems and records.
No method of electronic storage or communication can be guaranteed to be completely secure, but Dimark uses safeguards appropriate to the nature of the information.
---
36. Your data-protection rights
Depending on the circumstances and the legal basis for processing, individuals may have rights including the right to:
* request access to personal information we hold about them;
* request correction of inaccurate information;
* request completion of incomplete information;
* request deletion of personal information in certain circumstances;
* request restriction of processing in certain circumstances;
* object to certain processing;
* object to direct marketing;
* request portability of certain information; and
* withdraw consent where processing is based on consent.
These rights are not absolute.
For example, Dimark may need to retain information where:
* the law requires us to do so;
* records are required for accounting or tax purposes;
* an existing contract or guarantee requires the information;
* money remains outstanding;
* information is required for fraud prevention; or
* information is necessary for the establishment, exercise or defence of legal claims.
---
37. Requests to delete personal information
Requests to delete personal information are handled by Dimark’s office.
There is no in-app “delete my data” function for customers because customers are not users of the app.
Removing a registration from an iPhone or iPad removes only the local copy held on that device.
It does not by itself delete information held in Dimark’s central systems.
A customer or other individual may contact Dimark to request deletion of personal information where they have a right to do so.
Where Dimark is required or permitted to continue retaining information, a deletion request may not result in immediate deletion of every record.
Where there is no continuing lawful reason to retain the information, Dimark will delete or anonymise it in accordance with its procedures.
---
38. Complaints
If you are concerned about how Dimark collects, uses, stores or otherwise handles your personal information, please contact us so that we can investigate your concern.
Privacy and data-protection requests can be made using the contact details in section 40.
You also have the right to raise a concern or make a complaint to the **Information Commissioner’s Office (ICO)**, the UK’s independent regulator for data protection and information rights.
Further information is available at:
ico.org.uk
Contacting Dimark first does not affect your right to complain to the ICO.
---
39. Changes to this Privacy Notice
We may update this Privacy Notice where:
* our services change;
* the app’s functionality changes;
* our service providers change;
* our data-processing activities change; or
* legal or regulatory requirements change.
The latest version will be made available through Dimark’s public website and through the app.
The app may also securely store the current published version locally so that it remains available during offline customer registrations.
Previous versions may be retained where necessary to demonstrate which privacy information was provided in connection with a particular registration.
---
40. Contact us
For questions about this Privacy Notice, how Dimark uses personal information, to exercise a data-protection right or to make a data-protection complaint, contact:
Dimark Limited
Company number: 04996865
Unit 4 & 5 Advent Business Park
14 Advent Way
Edmonton
London N18 3AL
United Kingdom
Email: info@dimarkltd.co.uk