How OneDash complies with the Protection of Personal Information Act (POPIA).
Last updated: 16 July 2026
OneDash is fully POPIA compliant: it processes customer data lawfully, secures information with technical and organisational controls, and supports data subject rights across its messaging, CRM, invoicing, and AI services.
Fadaeco (Pty) Ltd, trading as OneDash ("OneDash", "we", "us", or "our"), is fully committed to complying with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA") of the Republic of South Africa. As both a responsible party and an operator (processor) of personal information, we have implemented comprehensive measures to ensure the lawful, fair, and transparent processing of personal information.
POPIA is South Africa's primary data protection legislation, aligned with international standards including the EU General Data Protection Regulation (GDPR). It establishes conditions for the lawful processing of personal information and grants data subjects specific rights regarding their personal data.
When we collect personal information directly from users (account registration, support interactions, website visits), OneDash acts as the responsible party under POPIA. We determine the purpose and means of processing this data.
When our customers use the OneDash platform to process their own customers' personal information (e.g., CRM contacts, chat messages, invoicing records), OneDash acts as an operator (data processor). Our customers remain the responsible party for that data, and we process it solely on their instructions and in accordance with our Data Processing Agreement.
We adhere to all eight conditions for lawful processing as defined in POPIA:
We have appointed an Information Officer responsible for ensuring POPIA compliance, handling data subject requests, and liaising with the Information Regulator. All staff receive POPIA awareness training.
We only collect personal information that is adequate, relevant, and not excessive for the purpose for which it is processed. We obtain consent where required and provide alternative legal bases (contractual necessity, legitimate interest, legal obligation) where applicable.
Personal information is collected for specific, explicitly defined, and lawful purposes. We do not process personal information for secondary purposes incompatible with the original purpose without additional consent.
Any further processing of personal information is compatible with the original purpose of collection. We assess compatibility based on the nature of the information, potential consequences, and the relationship between ourselves and the data subject.
We take reasonable steps to ensure personal information is complete, accurate, not misleading, and updated where necessary. Users can update their information through their account settings or by contacting us.
We maintain transparency about our processing activities through this POPIA policy, our Privacy Policy, and our registration with the Information Regulator. Data subjects are notified at the time of collection about how their data will be used.
We implement appropriate technical and organisational measures to protect personal information, detailed in Section 5 below.
We respect and facilitate data subject rights, detailed in Section 6 below.
We process personal information under the following lawful grounds:
In accordance with Section 19 of POPIA, we maintain the following security safeguards:
Under POPIA, you have the following rights regarding your personal information:
Request confirmation of whether we hold your personal information and access a copy.
Request correction or deletion of inaccurate, irrelevant, or outdated information.
Request destruction or deletion of personal information no longer needed.
Object to the processing of your personal information for direct marketing.
Lodge a complaint with the Information Regulator if you believe your rights have been infringed.
Request your information in a structured, machine-readable format.
To exercise any of these rights, submit a request to our Information Officer at [email protected]. We will respond within 30 days as required by POPIA Section 18.
Your data is primarily stored and processed in South Africa. Where personal information is transferred to another country (e.g., for AI processing services), we ensure:
In the event of a security breach that compromises personal information, we will:
We do not retain personal information longer than necessary for the purposes for which it was collected, unless:
When personal information is no longer needed, it is destroyed, deleted, or de-identified in a manner that prevents reconstruction.
If you use OneDash to process your customers' personal information, you are the responsible party under POPIA. You must:
OneDash has a Data Processing Agreement available upon request to formalise the operator relationship.
Our appointed Information Officer can be contacted at:
You also have the right to lodge a complaint with the Information Regulator: