Privacy Policy
Deis Technologies respects your privacy and is committed to protecting personal data processed through the Omni Link platform in accordance with applicable data protection laws.
1. Legal Framework
This Privacy Policy explains how Deis Technologies (Pty) Ltd ("Deis Technologies", "we", "us", or "our") collects, uses, stores, and protects personal data across the Omni Link platform and all related services. We process personal data in accordance with the Protection of Personal Information Act (POPIA), the General Data Protection Regulation (GDPR) where applicable, and other relevant data protection legislation. This policy applies to all Omni Link services, APIs, and platforms including WhatsApp Business API integrations.
Roles Under This Policy
- Data Controller: The Omni Link customer (your organisation) that determines the purposes and means of processing personal data of your contacts and end users.
- Data Processor: Deis Technologies, acting on your instructions to process personal data via the Omni Link platform.
- Data Subject: Any individual whose personal data is processed, including your customers, contacts, or end users.
2. Meta Platform Terms Compliance
Where Omni Link processes Platform Data as defined by the Meta Platform Terms, such processing is subject to and governed by the Meta Platform Terms and Meta Developer Policies. In the event of any conflict between this Privacy Policy and the Meta Platform Terms regarding Platform Data, the Meta Platform Terms shall prevail. Platform Data is not sold, licensed, or used for purposes prohibited under the Meta Platform Terms, including surveillance, discrimination, or eligibility determinations.
3. Data We Collect
We collect and process different categories of personal data depending on your role as an Omni Link customer or as an end user interacting through our platform.
Account & Registration Data
- Full name and work email address
- Organisation name and registration details
- Phone numbers and contact details
- Role, job title, and team assignment
- Billing address and payment method details (processed by PCI-compliant providers)
- Authentication credentials (hashed; never stored in plaintext)
Messaging & Communications Data
- Message content sent and received via WhatsApp Business API and other channels
- Media attachments (images, documents, audio, video)
- Message delivery status, timestamps, and read receipts
- Template message content and campaign details
- Conversation metadata (thread IDs, channel identifiers)
Contact & End-User Data
- Names and phone numbers of your customers
- Custom contact attributes and tags you define
- Opt-in/opt-out status for messaging channels
- Conversation history tied to a contact record
- Customer lists and segmentation data
Payment & Financial Data
- Pay-by-Link transaction amounts and status
- Scan-to-Pay QR transaction records
- Payer reference data for reconciliation
- Dispute and refund records
- Usage billing records (message volumes, API calls)
Technical & Usage Data
- IP addresses and browser/device identifiers
- API request logs (endpoint, timestamp, response code)
- Session identifiers and authentication tokens
- Feature usage events and click-stream analytics
- Error and crash reports for service improvement
Commerce Data
- Product catalogue entries and inventory information
- Customer orders and purchase history
- Commerce session data tied to WhatsApp conversations
- Fulfilment and delivery status records
4. How We Use Your Data
Operate the Omni Link platform, process messages, manage contacts, handle payments, and provide all contracted features.
Monitor for suspicious access, detect abuse, prevent fraud, and protect the integrity of payment transactions.
Calculate usage-based charges, generate invoices, and maintain financial records as required by law.
Analyse aggregated usage patterns to improve features, performance, and reliability of the Omni Link platform.
Comply with POPIA, GDPR, FICA, financial services regulations, and requirements from Meta, WhatsApp, and payment network operators.
Investigate and resolve support tickets, diagnose technical issues, and respond to security incidents.
Send transactional notifications, service updates, and (where you have opted in) product announcements.
5. Prescribed Purpose & Customer Obligations
The Omni Link messaging and payment services are provided solely for lawful business communication and commerce purposes as determined by the customer. Customers are responsible for ensuring that they have the necessary rights and lawful basis to send messages to and collect data from end users.
When processing personal information through Omni Link, customers must ensure compliance with applicable legislation including:
- The Protection of Personal Information Act (POPIA)
- WhatsApp Business Policy and Meta Platform Terms
- The Financial Intelligence Centre Act (FICA) for payment-related services
- The National Credit Act (NCA) where credit-related information is involved
- Any other applicable data protection or industry-specific regulations
6. Our Privacy Principles
Data Protection
Customer data is protected using industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256).
Purpose Limitation
Personal data is processed only for the specific purposes for which it was collected and as described in this policy.
Access Control
Access to customer data is restricted to authorised systems and personnel only, with full audit logging.
Data Minimisation
We collect and retain only the data necessary to provide our services effectively.
Accuracy
We take reasonable steps to keep personal data accurate and up to date.
Transparency
We are transparent about how we collect, use, and share personal data through this policy and any service-specific notices.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, or as required by applicable financial and regulatory frameworks.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & user data | Duration of subscription + 7 years | POPIA / FICA / contractual |
| Message & conversation data | 24 months from last activity, or as configured by customer | Service delivery / contractual |
| Payment transaction records | 7 years from transaction date | FICA / tax regulations |
| API access logs | 12 months | Security / audit |
| Billing & usage records | 7 years | Tax / financial regulations |
| Contact records | Duration of subscription, or until deletion is requested | Service delivery |
| Security & audit logs | 12 months (aggregates may be retained longer) | Legitimate interest / legal obligation |
Upon account closure, data is scheduled for deletion within 90 days unless longer retention is required by law or is subject to a pending dispute or legal hold. You may request earlier deletion via the Data Deletion page.
8. Cookies & Tracking Technologies
The Omni Link web portal uses cookies and similar technologies to maintain your session, remember preferences, and collect aggregated usage analytics. We do not use third-party advertising cookies.
Strictly Necessary Cookies
Authentication session tokens, CSRF protection, and load-balancer affinity. These cannot be disabled as they are required for the portal to function.
Functional Cookies
User interface preferences (theme, language, table column settings). These improve your experience but are not strictly required.
Analytics Cookies
Aggregated, anonymised usage data to understand how features are used and identify areas for improvement. No individual profiling is performed.
No Advertising Cookies
We do not use advertising networks or cross-site tracking technologies. Your activity on Omni Link is never used to serve targeted advertisements.
9. Third-Party Services & Sub-processors
To deliver the Omni Link platform, we engage trusted third-party sub-processors who may process personal data on our behalf. All sub-processors are contractually bound to process data only on our documented instructions and to maintain appropriate technical and organisational security measures.
Message routing, delivery, and status updates via the WhatsApp Business Platform
User identity, social sign-in (Google), and authentication token management when Firebase auth is enabled
Transaction authorisation, settlement, and fraud detection for Pay-by-Link and Scan-to-Pay services
Servers, databases, object storage, and network infrastructure. Data is hosted in South Africa or the EU depending on your configuration
System notifications, password resets, and billing alerts sent to registered users
We do not sell, rent, or share personal data with third parties for their own marketing purposes. We may disclose data to regulatory authorities, law enforcement, or courts where required by applicable law.
10. International Data Transfers
Omni Link is primarily hosted and operated in South Africa. Where personal data is transferred to countries outside South Africa or the European Economic Area, we ensure that appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to non-adequate countries.
- Binding Corporate Rules or equivalent mechanisms where applicable.
- The Information Regulator's requirements under POPIA for cross-border transfers of personal information.
- Processing via Meta's WhatsApp Business API is subject to Meta's Data Processing Terms and applicable cross-border transfer mechanisms.
You can request information about specific transfer mechanisms used for your data by contacting our privacy team.
11. Product-Specific Privacy Practices
Messaging & Campaigns
- Messages are processed solely for delivery to intended recipients via approved channels.
- Deis Technologies does not sell, share, or use message content for advertising or profiling.
- Campaign analytics are aggregated and do not expose individual recipient data to other tenants.
- Opt-out requests are processed immediately and contacts are not messaged again without fresh consent.
Payments (Pay By Link & Scan to Pay)
- Payment information is processed solely for transaction completion and reconciliation.
- Financial data is retained in accordance with applicable financial regulations (7 years).
- Card numbers, CVVs, and payment credentials are never stored by Deis Technologies; processing is handled by PCI-DSS-compliant payment providers.
- Dispute and refund records are maintained as required by payment network rules.
Commerce
- Product catalogue and order data is processed solely for commerce fulfilment.
- Customer purchase history is accessible only to the tenant account managing the transaction.
- No cross-tenant data sharing or profiling is performed on commerce data.
Contact Management & Imports
- Bulk-imported contacts are stored exclusively within your tenant account and are not accessible to other tenants.
- Customers are solely responsible for ensuring that consent to contact was obtained prior to import.
- Import files are processed and then discarded; original upload files are not retained after processing.
12. Data Breach Notification
In the event of a personal data breach that is likely to result in risk to affected individuals, Deis Technologies will:
- Notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
- Notify the Information Regulator (South Africa) and relevant EU supervisory authorities as required by POPIA and GDPR respectively.
- Provide affected customers with sufficient information to enable them to fulfil their own notification obligations to data subjects.
- Cooperate fully with regulatory investigations and implement remediation measures promptly.
13. Your Rights
Under POPIA and GDPR, you have the following rights regarding your personal data:
Right to Access
You may request a copy of your personal data that we hold.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data, subject to legal retention requirements.
Right to Object
You may object to processing of your personal data in certain circumstances.
Right to Portability
You may request transfer of your personal data in a structured, machine-readable format.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time.
To exercise any of these rights, submit a request to [email protected]. We will respond within 30 days. Some requests may require identity verification.
14. Security Measures
Technical Controls
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Multi-factor authentication (TOTP) support
- Regular penetration testing and security assessments
- Intrusion detection and anomaly monitoring systems
- Network segmentation and least-privilege access
Organisational Controls
- Role-based access controls with full audit trails
- Background checks for staff with access to personal data
- Regular mandatory data protection and security training
- Incident response and disaster recovery procedures
- Data Processing Agreements with all sub-processors
- Regular policy reviews and compliance audits
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify registered users via email or a prominent notice within the Omni Link portal at least 14 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the revised policy.
Contact Us About Privacy
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a data protection concern, please contact our privacy team.
Deis Technologies (Pty) Ltd - Information Officer
24 Sand Olive Close, Sagewood, 1685, South Africa
Email: [email protected]
Phone: +27 78 872 6405
Last updated: June 2026 | Effective: January 2025 | Deis Technologies (Pty) Ltd | Registration No. 2022/595177/07