1. Introduction
OneDash collects only the personal information needed to deliver its AI communication, CRM, billing, and support services, and protects that data with industry-standard security, POPIA compliance, and transparent sharing terms.
Fadaeco (Pty) Ltd, trading as OneDash ("OneDash", "we", "us", or "our"), is committed to protecting the privacy and personal information of our users, customers, and website visitors. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, mobile application, and related services (collectively, the "Services").
By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, company name, job title, and password when you register for an account.
- Billing Information: Payment method details, billing address, and transaction history processed through our payment partners.
- Communication Data: Messages, chat transcripts, call logs, and other content exchanged through our multi-channel platform (WhatsApp, SMS, web chat, VoIP).
- CRM & Business Data: Contact records, deal information, invoices, quotations, purchase orders, inventory data, and other business information you enter into the platform.
- Support Requests: Information provided when you contact our support team or submit feedback.
2.2 Information Collected Automatically
- Device & Browser Data: IP address, browser type, operating system, device identifiers, and screen resolution.
- Usage Data: Pages visited, features used, click patterns, session duration, and interaction timestamps.
- Cookies & Tracking: We use cookies and similar technologies to maintain sessions, remember preferences, and analyse usage patterns.
- Log Data: Server logs that record requests, errors, and system performance metrics.
2.3 Information From Third Parties
- Channel Providers: Data received through WhatsApp Business API, SMS gateways, and VoIP providers when customers message your business.
- Payment Processors: Transaction confirmations and payment status from processors such as PayFast, Ozow, Yoco, and Paystack.
- Imported Data: Contacts, leads, and business data you import from CSV files or external systems.
3. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: To operate, maintain, and improve the OneDash platform and its modules (messaging, CRM, invoicing, inventory, lead management, analytics, and customer portal).
- AI Training: To power AI agents using your knowledge base documents and conversation data, strictly within your account's scope.
- Communication: To send transactional emails, service notifications, security alerts, and product updates.
- Billing: To process payments, generate invoices, and manage subscriptions.
- Analytics: To provide you with dashboards, reports, and insights about your business performance.
- Security: To detect, prevent, and respond to fraud, abuse, and security incidents.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share data in the following circumstances:
- Service Providers: Trusted third parties who assist with hosting, payment processing, analytics, and customer support, bound by confidentiality agreements.
- Channel Partners: WhatsApp (Meta), SMS providers, and VoIP carriers as required to deliver messages on your behalf.
- Legal Requirements: When required by law, court order, or regulatory authority.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
- With Your Consent: In any other circumstances where you have given explicit consent.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control (RBAC) with granular module-level permissions.
- Complete audit trails for all data access and modifications.
- Regular security assessments and vulnerability testing.
- Redundant infrastructure with automatic failover and disaster recovery.
- Secure cloud storage with Cloudflare R2 for document and media files.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Services. Specific retention periods:
- Account Data: Retained while your account is active and for 90 days after deletion request.
- Communication Data: Retained according to your account settings and applicable regulations.
- Billing Records: Retained for 7 years as required by South African tax law.
- Audit Logs: Retained for 2 years for security and compliance purposes.
- AI Training Data: Deleted when you remove documents from your knowledge base or close your account.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal information, subject to legal retention obligations.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing of your data for specific purposes.
- Restriction: Request restriction of processing in certain circumstances.
- Withdraw Consent: Withdraw consent for processing where consent was the legal basis.
To exercise any of these rights, contact us at [email protected].
8. International Transfers
Your data is primarily stored in data centres located in South Africa (Johannesburg). Where data is transferred internationally (e.g., to AI processing services), we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements.
9. Children's Privacy
The Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Continued use of the Services after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: