Skip to content

Privacy Policy

Last updated: 11 September 2026

This policy explains how Kodeywebs Digital Studio Ltd handles personal information in connection with OsemFlow.

We are registered in Nigeria, at Zone 7 no 224b, Motorcycle spare parts Nnewi, Anambra State, Nigeria. For anything in this policy, contact info@osemflow.com.

1. Two kinds of personal information

This distinction matters throughout, so it is worth stating first.

Information about you, our customer. Your name, email address, phone number and business details, along with records of how you use the service.

Information you enter about your own customers. When you create a customer record you may enter a name, contact name, phone number, email address and physical address belonging to someone else.

For the first kind we decide how the information is used. For the second, you decide and we process it on your behalf, under these terms and your instructions. You are responsible for having a lawful basis to enter those details, and for whatever you tell your own customers about how you handle their information.

2. What we collect

From you

  • Account details: name, email address, phone number, business name, and the currency label and settings you choose
  • Staff accounts you create, with the names, roles and email addresses you assign
  • Records of sign-in activity, including times, session records and failed attempts
  • Subscription and billing records, including plan, billing period and payment status
  • Support correspondence you send us
  • Technical information from your use of the service, including error reports

We do not receive or store card numbers. Payment details are handled by the payment processor.

From your use of the marketing website

We use Umami, a privacy-focused analytics tool that we host ourselves, to count page visits and see which pages people find. It does not set cookies, does not track you across other websites, and does not build a profile of you. It records page addresses, referring sites, and general information such as country, browser and device type. It does not collect anything that identifies you individually.

Because it sets no cookies, this website does not display a cookie consent banner. It does not need one.

Information you enter about others

Customer and vendor records you create, containing whatever contact details you choose to enter.

3. Why we use it

  • To provide the service and keep your account working
  • To authenticate you and keep accounts secure
  • To take subscription payments and manage plans
  • To send service messages: alerts about low stock, overdue invoices, expiring products, plan limits and payment problems. On Pro and Enterprise plans some of these also go by email
  • To respond when you contact support
  • To detect and prevent misuse, fraud and security incidents
  • To find and fix faults
  • To meet legal and regulatory obligations

We do not sell personal information. We do not share it with advertisers. We do not use it to train machine learning systems.

4. Our legal basis

Where data protection law requires a basis for processing, we rely on:

  • Performance of a contract, for everything necessary to provide the service you signed up for
  • Legitimate interests, for security, fraud prevention, fault diagnosis and understanding how the site is used, balanced against your interests
  • Legal obligation, where retention or disclosure is required by law
  • Consent, where we ask for it, which you may withdraw

5. Who we share it with

We use a small number of service providers, each with access limited to what their function requires.

Provider Purpose What they receive
Paystack Subscription payments Billing contact details and payment information
Flutterwave Backup payment processing The same, where used
SendGrid Sending email Recipient address and message content
Sentry Error reporting Technical error details, with customer data scrubbed
Backblaze B2 Encrypted backup storage Encrypted backup files only, unreadable without keys held separately

We may also disclose information where the law requires it, to enforce our terms, or to protect the rights and safety of users. If the business is sold or reorganised, information may transfer as part of it, and this policy will continue to apply until you are told otherwise.

Our platform administrators can see account-level information such as your subscription status and usage totals. They cannot open your business records, and they cannot sign in as you.

6. Where it is held

Data is held on servers we operate, and in encrypted backup storage. Some providers listed above may process information outside your country. Where that happens we take steps to ensure protection appropriate to the information involved.

7. How long we keep it

  • Business records you enter are kept for as long as your account is open
  • Activity history showing who changed what is kept for 30 days on Free and Starter, 90 days on Pro, and 180 days on Enterprise, then deleted automatically
  • Sign-in and security records are kept for 90 days on every plan
  • Billing records are kept as long as tax and accounting law requires
  • Support correspondence is kept while needed to handle the matter and for a reasonable period after

When an account is closed, its data is deleted from the live system immediately. Encrypted backup copies remain until they expire under normal backup rotation, after which they are gone.

8. Security

Traffic between your browser and the service is encrypted. Passwords are stored using a one-way hash and are never readable by us or recoverable.

One active session is allowed per person, so signing in somewhere new ends the previous session. Sessions end automatically after 30 minutes without activity. Repeated failed sign-in attempts trigger a lockout.

Each business's data is isolated from every other business on the platform. This is the single control we treat as most important, because customer records hold personal information belonging to people who are not our users.

Backups are encrypted before being written or transferred, using keys stored separately from the backups. Someone obtaining the backup storage alone would obtain nothing readable.

Error reports sent to Sentry have customer data removed before transmission.

No system is perfectly secure. If a breach affects your information and the law requires us to tell you, we will.

9. Your rights

Depending on where you are, you may have the right to:

  • ask what personal information we hold about you
  • have inaccurate information corrected
  • ask for information to be deleted
  • object to or ask us to restrict certain processing
  • receive information in a portable format
  • withdraw consent where processing relies on it
  • complain to your data protection authority

Write to info@osemflow.com to exercise any of these. We will respond within the period the applicable law sets.

If your request concerns information held in another business's OsemFlow account, we will direct you to that business, since they control that data and we process it for them.

Some information you can act on directly. Account and staff details are editable in the application, and reports export to CSV and PDF at any time.

10. Children

The service is for businesses and is not directed at children. We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.

11. Changes

We may update this policy. The date at the top shows when it last changed. Material changes will be notified through the service or by email.

12. Contact

Kodeywebs Digital Studio Ltd
Zone 7 no 224b, Motorcycle spare parts Nnewi, Anambra State, Nigeria