Important notice
This policy is written for practical transparency and should be reviewed by legal counsel before production publication.
1. Purpose and POPIA context
AdvisorOne is committed to processing personal information lawfully, transparently, and securely. This policy is designed to align conceptually with South African data- protection principles, including POPIA.
2. Information we collect
AdvisorOne may process:
- adviser account details such as name, email, phone, and login identifiers,
- practice and compliance profile information entered by advisers,
- client information captured by advisers, including financial-planning inputs,
- technical and authentication information such as log events and session metadata.
3. Adviser account and practice information
We process adviser and practice information to create and maintain user accounts, deliver platform features, provide support, process billing operations, and maintain service integrity.
4. Client information entered by advisers
Advisers may capture client information required for planning workflows, document generation, and review history. Advisers are responsible for ensuring they have a lawful basis to collect and upload client information.
AdvisorOne provides tooling and storage services and does not become the independent financial-advice decision-maker.
5. Legal and operational reasons for processing
We process information to:
- perform contracted platform services,
- provide user authentication and account security,
- generate calculations, reports, and compliance workflow outputs,
- support billing, support tickets, and service operations,
- meet legal, regulatory, audit, and risk-management obligations.
Under POPIA-aligned principles, processing may rely on contractual necessity, compliance with legal obligations, legitimate interests, or consent where required for the specific processing activity.
6. Adviser role and AdvisorOne role
In most advisory contexts, the adviser and relevant FSP remain responsible for determining purpose and lawful basis for client-data capture and use. AdvisorOne acts as the software platform and operator for processing activities required to deliver the service.
[PLACEHOLDER - CONFIRM LEGAL POSITIONING: Controller/operator descriptions for each jurisdiction and contract model used in production.]
7. Data storage and hosting
Data is stored using managed cloud infrastructure and service providers selected for availability and security capabilities.
[PLACEHOLDER - CONFIRM ARCHITECTURE: Production hosting regions, storage services, and data residency posture.]
8. Data retention and deletion
Information is retained only as long as required for platform operation, legal obligations, dispute handling, and legitimate business records. Retention periods may vary by data category and contractual context.
[PLACEHOLDER - CONFIRM RETENTION SCHEDULE: Specific durations by category and secure deletion workflow.]
9. Sharing with service providers
AdvisorOne uses vetted service providers for core operations, which may include:
- authentication providers,
- payment-processing providers,
- email and communications providers,
- cloud hosting and infrastructure providers.
Service providers are expected to process information only for authorised platform purposes and under appropriate contractual controls.
10. Cross-border processing
Depending on provider architecture, processing may occur in jurisdictions outside South Africa. Where cross-border processing occurs, AdvisorOne will apply appropriate contractual and operational safeguards.
11. Cookies and analytics
AdvisorOne may use essential cookies and limited analytics or telemetry mechanisms to maintain sessions, improve reliability, and understand product performance.
12. Data-subject rights and requests
Subject to applicable law, users may request access, correction, deletion, or objection to certain processing activities. Requests are assessed in line with legal obligations and legitimate limitations.
Advisers requesting action on client records should ensure request authority and applicable legal basis are documented.
Where users believe a privacy concern was not adequately resolved, they may escalate to the relevant South African regulator.
[PLACEHOLDER - CONFIRM REGULATORY DETAILS: Information Regulator complaint channels and any mandatory escalation wording.]
13. Security safeguards and compromises
AdvisorOne applies technical and organisational safeguards intended to reduce the risk of unauthorised access, loss, alteration, or disclosure. No digital service can guarantee absolute security.
If a security compromise affecting personal information is confirmed, AdvisorOne will follow applicable legal notification requirements and incident-response procedures.
14. Special personal information and children
Advisers should avoid capturing unnecessary sensitive categories of personal information. Where special personal information is processed, the adviser remains responsible for lawful basis and sector-specific compliance.
AdvisorOne is not intended for direct use by children. Do not upload children's information unless required for a lawful advisory purpose and handled in line with applicable legal safeguards.
15. Changes to this privacy policy
This policy may be updated to reflect legal, operational, or platform changes. Updated versions become effective when published.
16. Privacy contact details
For privacy-related requests, use the Contact page and select Privacy request.
[PLACEHOLDER - CONFIRM CONTACT DETAILS: privacy@advisorone.co.za and designated information officer details, including registration where required.]
[PLACEHOLDER - CONFIRM PAIA: Link to the current PAIA manual and access-to-records workflow where applicable.]