Privacy policy
Last updated 3 August 2026
This policy explains how Ondio (Pty) Ltd collects, uses, stores and shares personal information. We process personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA).
1. Who is responsible
Ondio (Pty) Ltd (registration number 2026/567531/07), a company registered in the Republic of South Africa, is the responsible party for the personal information described in this policy.
For anything in this policy, including requests about your own information, contact us at greeff@ondio.co.za.
Where an accommodation provider uses our software to run their own business, that provider decides what guest information they collect and why. For that information the provider is the responsible party and we act as their operator, processing it on their instructions.
2. What this policy covers
This policy covers the Ondio platform and this website. The platform includes:
- booking websites we host for accommodation providers, each at its own address on
ondio.co.za; - the WhatsApp assistant that answers guest messages for participating properties;
- the admin portal that property owners and their staff use.
3. Information we collect
From guests — when you make an enquiry or a booking: your name, email address, phone number, the dates and details of your stay, any notes or requests you send us, and a record of what was paid. We do not take card details online: payments are arranged directly with the accommodation provider, so no card number ever reaches our systems.
From property owners and staff — the account details needed to sign in, and the content you enter about your property: descriptions, photos, rates, policies and contact details.
From WhatsApp conversations — the content of messages exchanged with a property's WhatsApp number, and the phone number they were sent from.
From this website — nothing. This site has no analytics, no tracking and no cookies. Our hosting provider keeps standard technical logs.
4. WhatsApp messaging
Some properties use a messaging assistant built on the official WhatsApp Business Platform, which is operated by Meta Platforms, Inc. Messages are delivered through Meta's systems and are subject to Meta's own terms and privacy policy in addition to this one.
How a conversation starts. We do not send unsolicited messages. A conversation begins when you message the property's number first, or when you ask the property to contact you there.
Opting out. You can stop at any time by saying so in the chat, or by asking the property directly. You can also ask to speak to a person at any point, and the assistant will hand the conversation over.
Automated replies. Replies may be generated automatically, including by an AI language model. Message content is sent to our AI provider (Anthropic) for that purpose. Replies are not always correct — see our terms of use.
Retention. The assistant keeps a short window of recent conversation so it can follow the thread. Message content is automatically deleted from our database after 90 days by a scheduled job.
5. Why we process personal information
- To perform the booking — taking, confirming and managing a reservation with an accommodation provider, and answering questions about a stay.
- To run and improve the service — operating, securing, supporting and improving the platform. This is our legitimate interest, and the provider's, in running the business.
- With your consent — for messaging you on WhatsApp, and for anything else we ask your permission for.
- To meet legal obligations — including the accounting and tax records a business is required to keep.
6. Where information is stored (cross-border transfers)
Our database and application servers are located in Frankfurt, Germany. Personal information about guests therefore leaves South Africa and is stored in the European Union, which has data-protection laws substantially similar to POPIA. Website content and media are delivered through Cloudflare's global network.
These transfers are made in accordance with section 72 of POPIA: the recipients are bound by agreements and by laws that give effect to principles for lawful processing that are substantially similar to those in POPIA.
7. Who we share information with
We do not sell personal information, and we do not share it for advertising.
We share it with the accommodation provider you are dealing with — they see their own guests' information and nobody else's — and with the service providers (operators) we use to run the platform. Each is bound by a written agreement to process personal information only on our instructions and to keep it secure:
- Cloudflare — website hosting, content delivery, DNS and object storage.
- Hostinger — the servers in Frankfurt on which the platform and its database run.
- Anthropic — AI processing of messages and assistant requests.
- Meta Platforms — delivery of WhatsApp messages.
We may also disclose information where the law requires it, or to establish, exercise or defend a legal claim.
8. How long we keep it
- WhatsApp message content — deleted automatically after 90 days.
- Booking and payment records — kept for as long as the accommodation provider needs them and for the periods South African tax and company law require.
- Account details — kept while the account is active, then removed.
- Backups — encrypted backups are kept on a rolling 30-day cycle, so deleted information persists in backups for up to 30 days before ageing out.
9. Security
In line with section 19 of POPIA we take appropriate technical and organisational measures to protect personal information, including:
- encryption in transit (HTTPS/TLS) for the website, the portal and our interfaces;
- database-level isolation between properties, enforced by row-level security, so one property's data cannot be read through another's account;
- encrypted, access-controlled off-site backups;
- administrative access to servers restricted to a private network with key-based authentication, not open to the public internet;
- accounts created by invitation only, with no public sign-up.
If a security compromise affects your personal information, we will notify you and the Information Regulator as POPIA requires.
10. Government and legal requests
If a government body or law-enforcement agency asks us for user data, we review each request for lawfulness, we push back on or challenge requests that are overbroad or unlawful, and we keep a record of the requests we receive and how we responded. We disclose only what a valid, lawful request actually requires.
11. Your rights
Under POPIA you have the right to ask what personal information we hold about you, to have it corrected or deleted, to object to processing in certain circumstances, and to withdraw consent where processing is based on it. To exercise any of these, email greeff@ondio.co.za. We may need to confirm your identity first.
You also have the right to complain to the Information Regulator:
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
enquiries@inforegulator.org.za · inforegulator.org.za
12. Deleting your data
You can ask us to delete the personal information we hold about you, including your WhatsApp message history. Step-by-step instructions, what gets deleted, what we may have to keep, and how long it takes are on our data deletion page.
13. Cookies
This website sets no cookies and uses no analytics or advertising trackers. The booking websites we host for properties use only what is technically necessary to complete a booking.
14. Changes to this policy
We update this policy when the platform or the law changes. The date at the top always reflects the current version.