Privacy Policy

Deis Technologies respects your privacy and is committed to protecting personal data processed through the Omni Link platform in accordance with applicable data protection laws.

Effective Date: January 2025Last Updated: June 2026

1. Legal Framework

This Privacy Policy explains how Deis Technologies (Pty) Ltd ("Deis Technologies", "we", "us", or "our") collects, uses, stores, and protects personal data across the Omni Link platform and all related services. We process personal data in accordance with the Protection of Personal Information Act (POPIA), the General Data Protection Regulation (GDPR) where applicable, and other relevant data protection legislation. This policy applies to all Omni Link services, APIs, and platforms including WhatsApp Business API integrations.

Roles Under This Policy

  • Data Controller: The Omni Link customer (your organisation) that determines the purposes and means of processing personal data of your contacts and end users.
  • Data Processor: Deis Technologies, acting on your instructions to process personal data via the Omni Link platform.
  • Data Subject: Any individual whose personal data is processed, including your customers, contacts, or end users.

2. Meta Platform Terms Compliance

Where Omni Link processes Platform Data as defined by the Meta Platform Terms, such processing is subject to and governed by the Meta Platform Terms and Meta Developer Policies. In the event of any conflict between this Privacy Policy and the Meta Platform Terms regarding Platform Data, the Meta Platform Terms shall prevail. Platform Data is not sold, licensed, or used for purposes prohibited under the Meta Platform Terms, including surveillance, discrimination, or eligibility determinations.

3. Data We Collect

We collect and process different categories of personal data depending on your role as an Omni Link customer or as an end user interacting through our platform.

Account & Registration Data

  • Full name and work email address
  • Organisation name and registration details
  • Phone numbers and contact details
  • Role, job title, and team assignment
  • Billing address and payment method details (processed by PCI-compliant providers)
  • Authentication credentials (hashed; never stored in plaintext)

Messaging & Communications Data

  • Message content sent and received via WhatsApp Business API and other channels
  • Media attachments (images, documents, audio, video)
  • Message delivery status, timestamps, and read receipts
  • Template message content and campaign details
  • Conversation metadata (thread IDs, channel identifiers)

Contact & End-User Data

  • Names and phone numbers of your customers
  • Custom contact attributes and tags you define
  • Opt-in/opt-out status for messaging channels
  • Conversation history tied to a contact record
  • Customer lists and segmentation data

Payment & Financial Data

  • Pay-by-Link transaction amounts and status
  • Scan-to-Pay QR transaction records
  • Payer reference data for reconciliation
  • Dispute and refund records
  • Usage billing records (message volumes, API calls)

Technical & Usage Data

  • IP addresses and browser/device identifiers
  • API request logs (endpoint, timestamp, response code)
  • Session identifiers and authentication tokens
  • Feature usage events and click-stream analytics
  • Error and crash reports for service improvement

Commerce Data

  • Product catalogue entries and inventory information
  • Customer orders and purchase history
  • Commerce session data tied to WhatsApp conversations
  • Fulfilment and delivery status records

4. How We Use Your Data

Service Delivery
Contract

Operate the Omni Link platform, process messages, manage contacts, handle payments, and provide all contracted features.

Security & Fraud Prevention
Legitimate Interest

Monitor for suspicious access, detect abuse, prevent fraud, and protect the integrity of payment transactions.

Billing & Usage Tracking
Contract

Calculate usage-based charges, generate invoices, and maintain financial records as required by law.

Service Improvement
Legitimate Interest

Analyse aggregated usage patterns to improve features, performance, and reliability of the Omni Link platform.

Legal & Regulatory Compliance
Legal Obligation

Comply with POPIA, GDPR, FICA, financial services regulations, and requirements from Meta, WhatsApp, and payment network operators.

Support & Incident Response
Contract / Legitimate Interest

Investigate and resolve support tickets, diagnose technical issues, and respond to security incidents.

Communications
Legitimate Interest / Consent

Send transactional notifications, service updates, and (where you have opted in) product announcements.

5. Prescribed Purpose & Customer Obligations

The Omni Link messaging and payment services are provided solely for lawful business communication and commerce purposes as determined by the customer. Customers are responsible for ensuring that they have the necessary rights and lawful basis to send messages to and collect data from end users.

When processing personal information through Omni Link, customers must ensure compliance with applicable legislation including:

  • The Protection of Personal Information Act (POPIA)
  • WhatsApp Business Policy and Meta Platform Terms
  • The Financial Intelligence Centre Act (FICA) for payment-related services
  • The National Credit Act (NCA) where credit-related information is involved
  • Any other applicable data protection or industry-specific regulations

6. Our Privacy Principles

Data Protection

Customer data is protected using industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256).

Purpose Limitation

Personal data is processed only for the specific purposes for which it was collected and as described in this policy.

Access Control

Access to customer data is restricted to authorised systems and personnel only, with full audit logging.

Data Minimisation

We collect and retain only the data necessary to provide our services effectively.

Accuracy

We take reasonable steps to keep personal data accurate and up to date.

Transparency

We are transparent about how we collect, use, and share personal data through this policy and any service-specific notices.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, or as required by applicable financial and regulatory frameworks.

Data CategoryRetention PeriodBasis
Account & user dataDuration of subscription + 7 yearsPOPIA / FICA / contractual
Message & conversation data24 months from last activity, or as configured by customerService delivery / contractual
Payment transaction records7 years from transaction dateFICA / tax regulations
API access logs12 monthsSecurity / audit
Billing & usage records7 yearsTax / financial regulations
Contact recordsDuration of subscription, or until deletion is requestedService delivery
Security & audit logs12 months (aggregates may be retained longer)Legitimate interest / legal obligation

Upon account closure, data is scheduled for deletion within 90 days unless longer retention is required by law or is subject to a pending dispute or legal hold. You may request earlier deletion via the Data Deletion page.

8. Cookies & Tracking Technologies

The Omni Link web portal uses cookies and similar technologies to maintain your session, remember preferences, and collect aggregated usage analytics. We do not use third-party advertising cookies.

Strictly Necessary Cookies

Authentication session tokens, CSRF protection, and load-balancer affinity. These cannot be disabled as they are required for the portal to function.

Functional Cookies

User interface preferences (theme, language, table column settings). These improve your experience but are not strictly required.

Analytics Cookies

Aggregated, anonymised usage data to understand how features are used and identify areas for improvement. No individual profiling is performed.

No Advertising Cookies

We do not use advertising networks or cross-site tracking technologies. Your activity on Omni Link is never used to serve targeted advertisements.

9. Third-Party Services & Sub-processors

To deliver the Omni Link platform, we engage trusted third-party sub-processors who may process personal data on our behalf. All sub-processors are contractually bound to process data only on our documented instructions and to maintain appropriate technical and organisational security measures.

Meta / WhatsApp Business API
Messaging channel operator

Message routing, delivery, and status updates via the WhatsApp Business Platform

Firebase (Google LLC)
Authentication provider (optional)

User identity, social sign-in (Google), and authentication token management when Firebase auth is enabled

Payment Network Operators
Payment processing

Transaction authorisation, settlement, and fraud detection for Pay-by-Link and Scan-to-Pay services

Cloud Infrastructure Provider
Hosting & storage

Servers, databases, object storage, and network infrastructure. Data is hosted in South Africa or the EU depending on your configuration

Email Delivery Service
Transactional notifications

System notifications, password resets, and billing alerts sent to registered users

We do not sell, rent, or share personal data with third parties for their own marketing purposes. We may disclose data to regulatory authorities, law enforcement, or courts where required by applicable law.

10. International Data Transfers

Omni Link is primarily hosted and operated in South Africa. Where personal data is transferred to countries outside South Africa or the European Economic Area, we ensure that appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to non-adequate countries.
  • Binding Corporate Rules or equivalent mechanisms where applicable.
  • The Information Regulator's requirements under POPIA for cross-border transfers of personal information.
  • Processing via Meta's WhatsApp Business API is subject to Meta's Data Processing Terms and applicable cross-border transfer mechanisms.

You can request information about specific transfer mechanisms used for your data by contacting our privacy team.

11. Product-Specific Privacy Practices

Messaging & Campaigns

  • Messages are processed solely for delivery to intended recipients via approved channels.
  • Deis Technologies does not sell, share, or use message content for advertising or profiling.
  • Campaign analytics are aggregated and do not expose individual recipient data to other tenants.
  • Opt-out requests are processed immediately and contacts are not messaged again without fresh consent.

Payments (Pay By Link & Scan to Pay)

  • Payment information is processed solely for transaction completion and reconciliation.
  • Financial data is retained in accordance with applicable financial regulations (7 years).
  • Card numbers, CVVs, and payment credentials are never stored by Deis Technologies; processing is handled by PCI-DSS-compliant payment providers.
  • Dispute and refund records are maintained as required by payment network rules.

Commerce

  • Product catalogue and order data is processed solely for commerce fulfilment.
  • Customer purchase history is accessible only to the tenant account managing the transaction.
  • No cross-tenant data sharing or profiling is performed on commerce data.

Contact Management & Imports

  • Bulk-imported contacts are stored exclusively within your tenant account and are not accessible to other tenants.
  • Customers are solely responsible for ensuring that consent to contact was obtained prior to import.
  • Import files are processed and then discarded; original upload files are not retained after processing.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in risk to affected individuals, Deis Technologies will:

  • Notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
  • Notify the Information Regulator (South Africa) and relevant EU supervisory authorities as required by POPIA and GDPR respectively.
  • Provide affected customers with sufficient information to enable them to fulfil their own notification obligations to data subjects.
  • Cooperate fully with regulatory investigations and implement remediation measures promptly.

13. Your Rights

Under POPIA and GDPR, you have the following rights regarding your personal data:

Right to Access

You may request a copy of your personal data that we hold.

Right to Rectification

You may request correction of inaccurate or incomplete personal data.

Right to Erasure

You may request deletion of your personal data, subject to legal retention requirements.

Right to Object

You may object to processing of your personal data in certain circumstances.

Right to Portability

You may request transfer of your personal data in a structured, machine-readable format.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time.

To exercise any of these rights, submit a request to [email protected]. We will respond within 30 days. Some requests may require identity verification.

14. Security Measures

Technical Controls

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Multi-factor authentication (TOTP) support
  • Regular penetration testing and security assessments
  • Intrusion detection and anomaly monitoring systems
  • Network segmentation and least-privilege access

Organisational Controls

  • Role-based access controls with full audit trails
  • Background checks for staff with access to personal data
  • Regular mandatory data protection and security training
  • Incident response and disaster recovery procedures
  • Data Processing Agreements with all sub-processors
  • Regular policy reviews and compliance audits

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify registered users via email or a prominent notice within the Omni Link portal at least 14 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the revised policy.

Contact Us About Privacy

If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a data protection concern, please contact our privacy team.

Deis Technologies (Pty) Ltd - Information Officer

24 Sand Olive Close, Sagewood, 1685, South Africa

Email: [email protected]

Phone: +27 78 872 6405

Last updated: June 2026 | Effective: January 2025 | Deis Technologies (Pty) Ltd | Registration No. 2022/595177/07