Dimark Portal & Customer Registration Privacy Notice
Last updated: 20 August 2026
1. Who we are
Dimark Limited (“Dimark”, “we”, “us” or “our”) is the controller of the personal information described in this Privacy Notice.
Dimark Limited
Company number: 04996865
Unit 4 & 5 Advent Business Park
14 Advent Way
Edmonton
London N18 3AL
United Kingdom
Email: info@dimarkltd.co.uk
This Privacy Notice applies to the Dimark Portal iPhone and iPad application and to customer and business-account registration carried out through the application.
Dimark Portal is a business application used by authorised Dimark sales representatives, managers and office staff.
Customers do not create or operate Dimark Portal user accounts themselves. During a business-account registration, an authorised Dimark representative may use the application to collect information from a business applicant, sole trader, director, guarantor, site manager or other person connected with the business.
This notice supplements any other privacy information provided by Dimark in connection with our websites, customer accounts and other services.
2. Who this Privacy Notice covers
Dimark Portal may process information relating to:
-
authorised Dimark employees, sales representatives, managers and contractors using the application;
-
prospective business customers;
-
existing Dimark customers;
-
sole traders;
-
company directors and officers;
-
guarantors;
-
site managers and employees;
-
business contacts;
-
witnesses to agreements or guarantees; and
-
other individuals whose information is provided as part of a business-account application.
3. Information we collect
3.1 Business and account information
We may collect information including:
-
business or trading name;
-
legal company name;
-
legal structure;
-
nature of the business;
-
business start date;
-
company registration number;
-
VAT number and VAT status;
-
Self Assessment UTR where relevant;
-
purchasing or trading method;
-
registered office address;
-
billing address;
-
trading addresses;
-
delivery addresses;
-
business telephone numbers;
-
business email addresses;
-
business contacts;
-
number and location of trading sites;
-
store or business type;
-
business notes and information relevant to account administration; and
-
information required to establish, manage or update a Dimark business account.
For existing customers, Dimark Portal may also display information already held by Dimark, including:
-
customer account number;
-
trading and company name;
-
business and contact addresses;
-
contact names;
-
telephone numbers;
-
mobile numbers;
-
email addresses;
-
VAT and company-registration details;
-
customer account status;
-
customer account balance;
-
account notes;
-
assigned sales representative; and
-
customer-specific pricing information.
4. Personal information relating to directors, sole traders and other individuals
Where necessary for a business-account application or existing business relationship, we may collect personal information including:
-
full name;
-
position or relationship to the business;
-
residential address;
-
telephone number;
-
mobile number;
-
email address;
-
date of birth where required;
-
business contact information;
-
information relating to a personal guarantee;
-
information required for identity and business verification;
-
information used for due-diligence and fraud-prevention purposes;
-
information relevant to assessing commercial or credit risk; and
-
other information provided during the application.
Information concerning an identifiable director, sole trader, guarantor, employee or other individual is personal information even where it is provided in connection with a business.
5. Identification and supporting documents
Where necessary for business onboarding, verification, due diligence or fraud prevention, we may collect photographs or copies of supporting documents.
These may include:
-
passport;
-
driving licence;
-
identity card;
-
biometric residence card;
-
proof of residential address;
-
utility bill;
-
bank statement used as evidence of address;
-
proof of business address;
-
business rates documentation;
-
lease documentation;
-
electricity or utility documentation;
-
business premises photographs;
-
shop exterior or signage photographs;
-
other evidence provided in support of an application.
Dimark Portal may use on-device technology to check whether a photographed document is sufficiently readable.
Where this functionality is used, recognised text used solely for the readability check is not retained by that function.
6. Signatures, agreements and guarantees
Dimark Portal may capture handwritten signatures where an applicant, guarantor or witness signs a business agreement, guarantee or related declaration.
We may also record information such as:
-
who signed;
-
the date and time of signing;
-
the agreement or guarantee version;
-
confirmation that the information supplied is correct;
-
acceptance of applicable business terms;
-
witness information;
-
confirmation relating to business verification or creditworthiness checks; and
-
other information required to evidence the application or agreement.
Where a personal guarantee is provided, information concerning the guarantor may be processed for the purposes of establishing, administering and enforcing that guarantee.
7. Location information
During an in-person business registration, Dimark Portal may collect the location of the device being used by the authorised Dimark representative.
Location may be recorded at specific stages including:
-
the start of a registration;
-
confirmation of terms or declarations;
-
signing of an application or guarantee; and
-
selection or confirmation of a business or delivery location.
Location information may include:
-
latitude;
-
longitude;
-
location accuracy;
-
date and time.
We use this information to:
-
maintain an audit record showing where and when an application was completed;
-
support process integrity;
-
assist with fraud prevention;
-
help verify business and trading locations; and
-
assist with delivery-location information.
Dimark Portal does not continuously track customers or sales representatives.
Dimark Portal does not use background location tracking.
If location access is declined or a location cannot be obtained, the application may record the relevant date and time without a GPS location.
8. Business verification, due diligence and creditworthiness checks
As part of a business account application, Dimark may carry out checks to verify the applicant and business, assess commercial risk and determine whether trading or credit terms can be offered.
These checks may apply to companies and sole traders and may involve information obtained from credit-reference, business-information, identity-verification or fraud-prevention providers.
Depending on the type of applicant and account requested, we may use information provided during the application together with information obtained from relevant external sources to:
-
verify the identity of the applicant and individuals connected with the business;
-
confirm that the business exists;
-
verify company and business information;
-
carry out appropriate customer due-diligence checks;
-
carry out fraud-prevention checks;
-
assess the financial standing or creditworthiness of the applicant;
-
assess commercial risk;
-
determine whether a business account can be opened; and
-
determine whether trading or credit terms can be offered and, where applicable, what those terms should be.
For limited companies, checks may relate to the company and may also involve information concerning directors, guarantors or other individuals connected with the application where necessary.
For sole traders, checks may involve information relating directly to the individual because the individual operates the business in their own capacity.
Where a personal guarantee is provided, information concerning the guarantor may also be processed where necessary to assess and administer the guarantee.
Dimark will use information obtained through these checks for appropriate business-account administration, verification, due-diligence, fraud-prevention, commercial-risk and creditworthiness purposes.
Credit-reference and related checks are carried out through Dimark's business processes and relevant service providers.
The Dimark Portal iPhone and iPad application does not itself provide consumer lending services or automatically make lending decisions.
9. Information obtained from Companies House and other sources
Where appropriate, Dimark may use information from official or publicly available business sources, including Companies House, to assist with verification of a UK company.
This may include:
-
company name;
-
company number;
-
registered office address;
-
company status; and
-
names of company officers.
Information obtained from these sources may be displayed during the application so that it can be reviewed and confirmed as relevant to the business-account application.
We may also obtain information from:
-
business-information providers;
-
credit-reference providers;
-
identity-verification providers;
-
fraud-prevention providers;
-
mapping and address-search services; and
-
Dimark's existing customer and business systems.
10. Communication and marketing preferences
During registration, Dimark may record communication preferences.
These may include whether a customer wishes to receive:
-
agreement documents by email;
-
an invitation to access an online customer account;
-
marketing emails;
-
marketing SMS messages;
-
WhatsApp or other supported marketing communications.
Operational communications necessary to administer a business account are separate from optional marketing communications.
Optional marketing choices are kept separate from acceptance of the business agreement.
Marketing options are not selected automatically.
Where we rely on consent for marketing, the individual may withdraw that consent at any time.
Withdrawing marketing consent will not affect the operation of an existing Dimark business account or the lawfulness of processing carried out before consent was withdrawn.
11. Information relating to Dimark Portal users
Dimark Portal itself is used by authorised Dimark personnel.
For these users, we may process information including:
-
username;
-
authentication information;
-
user or sales-representative code;
-
name;
-
work email address;
-
telephone number;
-
mobile number;
-
address information where used for witness details;
-
role;
-
system permissions;
-
session information;
-
working hours;
-
profile information;
-
customer assignments; and
-
activity necessary to perform the user's authorised role.
User accounts are created and managed by Dimark.
Customers do not create Dimark Portal user accounts.
Authentication and session information may be stored securely on the authorised iPhone or iPad to support both online and permitted offline operation.
12. How we collect information
Information may be obtained:
-
directly from the applicant during an in-person registration;
-
from a director, sole trader, guarantor or other individual connected with the application;
-
from an authorised Dimark representative entering information into Dimark Portal;
-
from documents photographed or selected for the registration;
-
from Companies House;
-
from business-information and verification providers;
-
from credit-reference or fraud-prevention providers;
-
from address, mapping or location services;
-
from Dimark's existing customer systems; and
-
through the operation of Dimark Portal itself.
13. Why we use personal information
Depending on the circumstances, we may use personal information to:
-
take steps requested before entering into a business relationship;
-
assess and process a business-account application;
-
establish and maintain a business trading relationship;
-
verify applicants and businesses;
-
carry out due diligence;
-
prevent and detect fraud;
-
assess commercial risk;
-
assess whether trading or credit terms can be offered;
-
administer personal guarantees;
-
maintain appropriate records of applications and agreements;
-
establish, administer and service customer accounts;
-
provide authorised sales representatives with information necessary to manage assigned customers;
-
provide customer-specific catalogue pricing;
-
arrange and administer deliveries;
-
verify business and delivery locations;
-
maintain appropriate audit records;
-
comply with applicable legal, regulatory, accounting, tax and record-keeping obligations;
-
protect Dimark, its customers, staff and systems;
-
administer authorised employee access to Dimark Portal;
-
respond to queries or complaints; and
-
provide marketing communications where permitted.
14. Our lawful bases for processing
The lawful basis we rely on depends on the particular information and purpose.
These may include:
Contract and steps before entering into a contract
We may process information where necessary to consider a business-account application, enter into an agreement or administer an existing business relationship.
Legal obligation
We may process or retain information where necessary to meet legal, tax, accounting, regulatory, due-diligence or record-keeping obligations.
Legitimate interests
We may process information where necessary for legitimate business purposes, including:
-
verifying businesses and applicants;
-
preventing fraud;
-
assessing commercial risk;
-
maintaining accurate customer records;
-
managing customer relationships;
-
protecting Dimark's systems and business;
-
maintaining audit records; and
-
administering business operations.
Where we rely on legitimate interests, we consider whether the processing is necessary and whether those interests are overridden by the rights and interests of the individual.
Consent
We may rely on consent where appropriate, particularly for certain optional marketing communications.
Where processing is based on consent, consent may be withdrawn at any time.
Withdrawal of consent does not affect processing lawfully carried out before withdrawal.
15. Privacy information shown during customer registration
Before personal and business information is collected during a new customer registration, Dimark Portal presents privacy information explaining how information will be used.
The initial screen may provide a concise summary together with access to this full Privacy Notice.
The Privacy Notice may be downloaded and stored securely within Dimark Portal so that it remains available when a sales representative is working offline.
Dimark may maintain:
-
privacy-notice version number;
-
effective date;
-
date and time the notice was presented.
This helps us identify which version of the privacy information was provided during a particular registration.
The Privacy Notice is separate from:
-
Dimark's business terms;
-
confirmation that supplied information is accurate;
-
a personal guarantee;
-
business-verification or creditworthiness declarations; and
-
optional marketing preferences.
16. Offline operation and information stored on the iPhone or iPad
Dimark Portal is designed to operate in locations where a reliable internet connection may not be available.
As a result, some information may be temporarily stored within the application's private storage on an authorised iPhone or iPad.
This may include:
-
registration drafts;
-
personal and business information entered into the registration;
-
supporting documents;
-
identification photographs;
-
business photographs;
-
signatures; and
-
information required to complete and submit the registration.
Draft registrations may remain locally on the authorised device until they are submitted or deleted in accordance with Dimark's procedures.
Once a registration has been successfully submitted, normal access to that registration is restricted for the sales representative.
17. Corrections to submitted registrations
Submitted registrations are normally locked from further editing by the sales representative.
If Dimark's office identifies an error, missing information or another issue requiring correction, authorised office staff may return the application to the assigned sales representative.
Where necessary, the application and relevant supporting information may be downloaded securely to the authorised device again so that the requested correction can be completed.
The sales representative can then amend the relevant registration and submit it again.
After resubmission, access is restricted again.
Sales representatives cannot independently reopen submitted registrations without the appropriate office-controlled correction process.
18. Local device retention and deletion
Submitted registration information stored locally on the authorised iPhone or iPad is retained only temporarily.
Dimark currently operates a standard local retention period of 30 days following successful submission, subject to system configuration and operational requirements.
Local information may be removed earlier where appropriate.
This local retention process may remove:
-
registration information;
-
identity-document copies;
-
supporting documents;
-
signatures;
-
local photographs; and
-
other registration attachments.
If a correction is subsequently required after information has been removed locally, authorised office staff may return the registration so that the necessary information can be securely downloaded again for correction.
Removal from the iPhone or iPad does not necessarily delete information from Dimark's central systems.
19. Retention in Dimark's central systems
Information held in Dimark's central systems may need to be retained for longer than information stored on the sales representative's device.
Different categories of information may have different retention periods.
We may retain information where necessary for:
-
maintaining a customer account;
-
business administration;
-
customer due diligence;
-
identity or business verification;
-
creditworthiness or commercial-risk records;
-
fraud prevention;
-
contracts and personal guarantees;
-
accounting and taxation;
-
legal or regulatory obligations;
-
establishment, exercise or defence of legal claims; and
-
appropriate business record keeping.
Where Dimark is legally required to retain information, a request for deletion may not require us to delete that information immediately.
When information is no longer necessary and no applicable legal or legitimate reason requires its retention, it will be deleted, anonymised or securely disposed of in accordance with Dimark's retention procedures.
20. Who we share information with
Access within Dimark is restricted to authorised personnel who require the information for their role.
We may also use external organisations and service providers where necessary to operate our business and Dimark Portal.
These may include providers involved in:
-
application and backend hosting;
-
database services;
-
secure document and file storage;
-
company verification;
-
address and location lookup;
-
mapping services;
-
delivery-location services;
-
credit-reference information;
-
business-information services;
-
identity verification;
-
fraud prevention;
-
legal, accounting and compliance services;
-
IT and security services.
Our technical infrastructure may include services provided by organisations including:
-
Railway;
-
Cloudflare;
-
Companies House;
-
Google;
-
Apple; and
-
what3words.
The precise service involved depends on the functionality being used.
Dimark does not sell personal information.
Dimark Portal does not contain third-party advertising.
Dimark Portal does not use personal information to track individuals across applications or websites owned by other organisations for advertising purposes.
21. Mapping and location services
Dimark Portal may use mapping, geocoding or address-search services to assist with:
-
locating a business;
-
confirming a trading address;
-
selecting a delivery location;
-
recording map coordinates; and
-
improving accuracy of address information.
Depending on the functionality being used, these services may involve Apple MapKit, Google address or mapping services or what3words.
Where an external provider is used, the minimum information reasonably necessary to provide the relevant functionality is sent to that provider.
22. Camera and photographs
Dimark Portal may use the device camera to photograph information required for a registration, including:
-
identification documents;
-
proof-of-address documents;
-
proof-of-business documents;
-
shop exterior;
-
signage;
-
business premises.
Where an existing image is selected from the device, Dimark Portal uses only the image specifically selected for the relevant registration.
The application does not upload the contents of the user's photo library generally.
Dimark Portal does not continuously record video or audio.
23. Tracking and advertising
Dimark Portal does not:
-
display third-party advertising;
-
use an advertising identifier for targeted advertising;
-
track individuals across apps or websites owned by other companies for advertising purposes;
-
contain third-party behavioural advertising functionality; or
-
sell customer or staff information for advertising purposes.
24. Children
Dimark Portal is an internal business application used for business-account management and trade-customer registration.
It is not directed at children and is not intended to be used to establish business trading accounts for children.
25. International processing and transfers
Some cloud, technology or service providers used by Dimark may process or store information outside the United Kingdom.
Where applicable data-protection law treats this as a restricted international transfer, Dimark will use an appropriate legal mechanism or safeguard for the transfer.
This may include an applicable adequacy decision or recognised contractual safeguards.
Dimark reviews the locations and arrangements used by relevant service providers as part of its data-protection responsibilities.
26. How we protect information
Dimark uses technical and organisational measures designed to protect personal information against unauthorised access, disclosure, loss, misuse or alteration.
Measures used by Dimark Portal and related systems include, where appropriate:
-
encrypted HTTPS communications;
-
authenticated access to Dimark's systems;
-
access permissions based on authorised user roles;
-
secure iOS credential storage;
-
private application storage;
-
restricted access to registration documents;
-
controls preventing sales representatives from normally accessing submitted registrations;
-
office-controlled correction access;
-
separation of sensitive customer documentation from ordinary catalogue imagery;
-
automatic removal of locally stored submitted registrations after the applicable local-retention period; and
-
restrictions on access to company systems and records.
The application also performs document-readability checks on the device without retaining the text recognised solely for that purpose.
No method of electronic storage or communication can be guaranteed to be completely secure, but we use safeguards appropriate to the nature of the information and review those measures where appropriate.
27. Your data-protection rights
Depending on the circumstances and the legal basis for processing, individuals may have rights including the right to:
-
request access to personal information we hold about them;
-
request correction of inaccurate information;
-
request completion of incomplete information;
-
request deletion of personal information in certain circumstances;
-
request restriction of processing in certain circumstances;
-
object to certain processing;
-
object to direct marketing;
-
request portability of certain information; and
-
withdraw consent where our processing is based on consent.
These rights are not absolute.
For example, we may need to retain information where:
-
the law requires us to do so;
-
information is required for regulatory or due-diligence purposes;
-
an existing contract or guarantee requires the information;
-
records are required for accounting or tax purposes; or
-
information is necessary for the establishment, exercise or defence of legal claims.
28. Requests to delete personal information
You may contact Dimark to request deletion of personal information where you have a right to do so.
A request to delete personal information does not automatically require Dimark to delete every record relating to a business or individual.
We may retain information where continued retention is necessary or required for purposes including:
-
legal obligations;
-
due diligence;
-
fraud prevention;
-
taxation or accounting;
-
contractual records;
-
personal guarantees;
-
regulatory obligations; or
-
legal claims.
Where there is no requirement or legitimate reason to continue retaining information, it will be deleted or anonymised in accordance with our retention procedures.
Dimark Portal user accounts for authorised staff are created and administered by Dimark rather than created by users through the application.
29. Complaints
If you have concerns about how Dimark uses your personal information, please contact us so that we can investigate.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator.
30. Changes to this Privacy Notice
We may update this Privacy Notice where:
-
our services change;
-
Dimark Portal functionality changes;
-
our service providers change;
-
our data-processing activities change; or
-
legal or regulatory requirements change.
The latest version will be made available through Dimark's public website and through Dimark Portal.
Dimark Portal may also securely store the current published version locally so that it remains available during offline customer registrations.
Previous versions may be retained by Dimark where necessary to demonstrate which privacy information was provided in connection with a particular registration.
31. Contact us
For questions about this Privacy Notice, how Dimark uses personal information or to exercise a data-protection right, contact:
Dimark Limited
Unit 4 & 5 Advent Business Park
14 Advent Way
Edmonton
London N18 3AL
United Kingdom
Email: info@dimarkltd.co.uk