Stodacom Desktop

Trust & Compliance Platform

Privacy Policy Last updated: July 28, 2026 Platform v2.1.1

Protecting Your Privacy

How Stodacom Desktop collects, uses, stores, and protects your information across our research screening, background-check, and workforce-screening services.

No Data Selling
Google API Limited Use
Multi-Tenant Data Isolation
Stodacom Desktop ("we", "our", "us") operates the platform at https://stodacomdesktop.com, offering research and OSINT screening subscriptions, pay-as-you-go background check ordering, and a workforce/HR screening suite for organizations. This Privacy Policy explains how we collect, use, store, share, and protect personal data across all three, including Google user data obtained through OAuth. We encourage you to read this policy in full.

1. Information We Collect

The types of personal information we collect and how.

AGoogle User Data (via OAuth)
Limited Scope Access
When you sign in with Google, we may access only the following:
Your Google account email address
Your full name
Your Google profile image URL
Your Google account unique identifier

We do NOT access Gmail content, Google Drive files, Google Calendar, contacts, or any sensitive Google API data beyond what is listed above.

BAccount, Billing & Organization Data
Basic Information
Your name, email address, and username
Security Information
Password and, if enabled, a 4-digit PIN — stored using cryptographic hashing, never in plaintext
Subscription & Wallet Data
Your plan type, billing period, prepaid wallet balance, and order/transaction history
Organization Data
For workforce/HR accounts: your organization's name, plan, team member roles, and seat usage
CScreening & Case Data

If you order a background check, run a screening search, or use the workforce hiring workflow, we process the data you submit about the subject of that check (such as a candidate's or entity's name and identifying details), the results returned (PEP, sanctions, adverse media, registry, and verification data), and any case notes, compliance-review decisions, or hiring outcomes your organization records.

Candidates invited into an organization's hiring workflow have their data processed on behalf of that organization, which is responsible for obtaining any consent required to screen them.

DUsage Data
IP Address
For security and fraud detection
Device Info
Browser type and operating system
Push Notification Token
If you enable browser or installed-app notifications
Error & Audit Logs
System errors and an audit trail of actions taken on sensitive records
ECookies

We use cookies for essential platform functions only:

Authentication
Secure login sessions
Session Management
Maintain user preferences (e.g. theme, sidebar state)
CSRF Security
Protect against cross-site request forgery

For full details, see our Cookie Policy.

2. How We Use Your Information

The purposes for which we process your personal data.

Account Management
Create and manage your account; authenticate you via password, Google OAuth, or PIN fallback
Screening & Reporting
Run the checks you order and produce risk reports, dashboards, and continuous monitoring alerts
Billing
Process wallet top-ups, subscription payments, and per-check charges
Security & Fraud Prevention
Detect and prevent unauthorized access and security threats
Communication
Send service updates, security alerts, renewal reminders, and required account messages
Legal Compliance
Meet obligations under applicable data protection and financial-record-keeping law
Our Commitment
We NEVER sell your data or use it for advertising. Your data is used solely to provide and improve our services.

3. How We Share Data

We do not sell or rent personal data. Limited sharing only.

Service Providers & Sub-Processors
Only for the specific service purpose, never beyond
Hosting & Storage
Infrastructure, server hosting, and file/document storage
Payment Processing
Stripe processes card payments for subscriptions and wallet top-ups; we do not store your full card number
Email Delivery
Transactional and notification email services
Push Notifications
Browser/app push notification delivery

Sub-processors may only use data as instructed and are bound by contractual data-protection obligations.

Legal Disclosure: We may disclose data only when legally required:

  • To comply with applicable laws or regulations
  • In response to lawful court orders or government requests
  • To prevent fraud, abuse, or threats to user safety

4. Data Storage & Security

How we protect your information.

We store data on secured servers within controlled environments and apply access controls appropriate to a multi-tenant platform, including:

Encryption in Transit
All data transmitted over HTTPS/TLS
Multi-Tenant Isolation
Each organization's and client's data is logically segmented and enforced at the database query layer
Role-Based Access
Access to sensitive records is scoped to a user's role and organization
Audit Logging
An audit trail is kept for actions on wallet transactions, screening decisions, and hiring outcomes

While we employ these safeguards, no digital system is 100% secure. In the event of a data breach affecting your personal data, we will notify affected users in accordance with applicable data protection law.

5. Data Retention

How long we keep your information.

We aim to retain personal data no longer than necessary for the purposes described in this policy, or as required by law. Our retention practice is:

Account Data
Kept for the lifetime of your account, then deleted or anonymized following a deletion request (Section 6)
Billing & Wallet Records
Kept for as long as required for financial record-keeping and tax obligations
Screening & Audit Records
Kept for as long as needed for compliance, dispute-resolution, and audit purposes
Usage & Error Logs
Kept for a limited operational window, then rotated out

You may request earlier deletion of your data at any time — see Section 6 below.

6. Data Deletion Requests

Your right to erasure under GDPR.

You have the right to request deletion of your personal data at any time. To submit a deletion request:

  • Email support@stodacomdesktop.com with the subject "Data Deletion Request"
  • We will process your request within 30 days and confirm completion by email

Some data may be retained beyond your deletion request where required by law (for example, financial records) or for legitimate fraud-prevention purposes. We will inform you of any such exceptions.

7. Google OAuth Compliance

Our commitment to Google's Limited Use requirements.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only request the minimum scopes necessary (email, profile, openid)
  • Google data is used only to authenticate users and populate their profile
  • We do not transfer Google user data to third parties for advertising
  • We do not use Google data to build user profiles beyond the platform
  • Humans do not read your Google data except with your explicit consent or for security purposes

8. Your Rights

Your rights under GDPR and applicable data protection law.

Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data
Right to Restrict
Limit how we process your data in certain circumstances
Right to Portability
Receive your data in a structured, machine-readable format
Right to Object
Object to processing based on legitimate interests

To exercise any of these rights, contact us at support@stodacomdesktop.com. We will respond within 30 days.

9. Changes to This Policy

How we handle updates to this document.

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users via the platform and update the "Last updated" date at the top of this document. We encourage you to review this policy periodically.

Continued use of the platform after changes are published constitutes your acceptance of the updated policy. If you do not agree with the changes, you may request deletion of your account and data.

10. Contact Information

How to reach us with privacy-related questions.

Stodacom Desktop
Kampala, Uganda
General Inquiries
sales@stodacomdesktop.com
Privacy & Data Requests
support@stodacomdesktop.com
Response within 30 days