AdvisorOne policy

AdvisorOne Privacy Policy

This policy explains how AdvisorOne handles personal information for adviser users and client records captured in the platform.

Last updated: 05 August 2026

Important notice

This policy is written for practical transparency and should be reviewed by legal counsel before production publication.

1. Purpose and POPIA context

AdvisorOne is committed to processing personal information lawfully, transparently, and securely. This policy is designed to align conceptually with South African data- protection principles, including POPIA.

2. Information we collect

AdvisorOne may process:

  • adviser account details such as name, email, phone, and login identifiers,
  • practice and compliance profile information entered by advisers,
  • client information captured by advisers, including financial-planning inputs,
  • technical and authentication information such as log events and session metadata.

3. Adviser account and practice information

We process adviser and practice information to create and maintain user accounts, deliver platform features, provide support, process billing operations, and maintain service integrity.

4. Client information entered by advisers

Advisers may capture client information required for planning workflows, document generation, and review history. Advisers are responsible for ensuring they have a lawful basis to collect and upload client information.

AdvisorOne provides tooling and storage services and does not become the independent financial-advice decision-maker.

We process information to:

  • perform contracted platform services,
  • provide user authentication and account security,
  • generate calculations, reports, and compliance workflow outputs,
  • support billing, support tickets, and service operations,
  • meet legal, regulatory, audit, and risk-management obligations.

Under POPIA-aligned principles, processing may rely on contractual necessity, compliance with legal obligations, legitimate interests, or consent where required for the specific processing activity.

6. Adviser role and AdvisorOne role

In most advisory contexts, the adviser and relevant FSP remain responsible for determining purpose and lawful basis for client-data capture and use. AdvisorOne acts as the software platform and operator for processing activities required to deliver the service.

[PLACEHOLDER - CONFIRM LEGAL POSITIONING: Controller/operator descriptions for each jurisdiction and contract model used in production.]

7. Data storage and hosting

Data is stored using managed cloud infrastructure and service providers selected for availability and security capabilities.

[PLACEHOLDER - CONFIRM ARCHITECTURE: Production hosting regions, storage services, and data residency posture.]

8. Data retention and deletion

Information is retained only as long as required for platform operation, legal obligations, dispute handling, and legitimate business records. Retention periods may vary by data category and contractual context.

[PLACEHOLDER - CONFIRM RETENTION SCHEDULE: Specific durations by category and secure deletion workflow.]

9. Sharing with service providers

AdvisorOne uses vetted service providers for core operations, which may include:

  • authentication providers,
  • payment-processing providers,
  • email and communications providers,
  • cloud hosting and infrastructure providers.

Service providers are expected to process information only for authorised platform purposes and under appropriate contractual controls.

10. Cross-border processing

Depending on provider architecture, processing may occur in jurisdictions outside South Africa. Where cross-border processing occurs, AdvisorOne will apply appropriate contractual and operational safeguards.

11. Cookies and analytics

AdvisorOne may use essential cookies and limited analytics or telemetry mechanisms to maintain sessions, improve reliability, and understand product performance.

12. Data-subject rights and requests

Subject to applicable law, users may request access, correction, deletion, or objection to certain processing activities. Requests are assessed in line with legal obligations and legitimate limitations.

Advisers requesting action on client records should ensure request authority and applicable legal basis are documented.

Where users believe a privacy concern was not adequately resolved, they may escalate to the relevant South African regulator.

[PLACEHOLDER - CONFIRM REGULATORY DETAILS: Information Regulator complaint channels and any mandatory escalation wording.]

13. Security safeguards and compromises

AdvisorOne applies technical and organisational safeguards intended to reduce the risk of unauthorised access, loss, alteration, or disclosure. No digital service can guarantee absolute security.

If a security compromise affecting personal information is confirmed, AdvisorOne will follow applicable legal notification requirements and incident-response procedures.

14. Special personal information and children

Advisers should avoid capturing unnecessary sensitive categories of personal information. Where special personal information is processed, the adviser remains responsible for lawful basis and sector-specific compliance.

AdvisorOne is not intended for direct use by children. Do not upload children's information unless required for a lawful advisory purpose and handled in line with applicable legal safeguards.

15. Changes to this privacy policy

This policy may be updated to reflect legal, operational, or platform changes. Updated versions become effective when published.

16. Privacy contact details

For privacy-related requests, use the Contact page and select Privacy request.

[PLACEHOLDER - CONFIRM CONTACT DETAILS: privacy@advisorone.co.za and designated information officer details, including registration where required.]

[PLACEHOLDER - CONFIRM PAIA: Link to the current PAIA manual and access-to-records workflow where applicable.]