Privacy
Privacy Policy
How OneWISP collects, uses, stores and protects personal information across the marketing site, the OneWISP Platform, and the OneWISP-Field mobile app - written plainly, and aligned to South Africa's POPIA.
Last updated 16 June 2026
01Who we are and what this covers
OneWISP is operated by OneCarrier (Pty) Ltd, a company registered in the Republic of South Africa ("we", "us", "our", or "OneWISP").
This Privacy Policy applies to all of the following, collectively the "OneWISP Services":
- Site - the marketing website at one-wisp.co.za and the Apply / Contact forms hosted on it.
- OneWISP Platform - the web-based ISP management system (customer, billing, RADIUS, network, helpdesk and related modules) provided to ISPs under a counter-signed SLMaS Agreement.
- OneWISP-Field - the field-technician mobile companion app (Android), including its offline-first local storage and background sync.
We process personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA").
Two roles, depending on the service. For visitors to the Site, applicants, and direct contacts, OneCarrier (Pty) Ltd is the responsible party. For data that an ISP loads into the Platform or that its technicians capture through the Field app about that ISP's own subscribers and staff, the ISP is the responsible party and OneWISP acts as the operator. The split is set out in detail in the SLMaS Agreement and Annexure C (Data Processing Agreement).
For any privacy queries, write to admin@one-wisp.co.za.
02What personal information we collect
We collect different categories depending on which part of the OneWISP Services you interact with.
From applicants on the Site
- Company details: registered name, registration number, VAT number, physical and legal addresses, business phone.
- Contact persons: full name, job title, email and phone of every contact listed against the application.
- Service selection: chosen pricing plan, subscriber tier, optional add-ons, subscription term, customisation requirements.
- Signature: an image of your hand-drawn signature captured on the application page, embedded into the signed agreement PDF.
- A complete copy of the signed Software Licence, Maintenance and Support Agreement (SLMaS) generated from your inputs.
From visitors using the contact form
- Name and (optional) company.
- Email address and (optional) phone number.
- The contents of the message you send us.
From ISPs and Platform users
- User account information for staff who log into the Platform: name, email, role/permissions, login timestamps, IP address of the session.
- Audit-trail entries that record administrative actions in the Platform.
- Customer Data the ISP loads into the Platform - including their own subscribers' names, contact details, service addresses, network identifiers, billing records, support tickets and RADIUS sessions. For this data the ISP is the responsible party; we are the operator.
- Licence-validation pings transmitted by on-premise installations: licence key, application URL, provisioned subscriber count, software version (described in Part D of the SLMaS Agreement).
From field technicians using OneWISP-Field
The Field app is designed for ISP field staff. When a technician signs in and works a shift, the app captures the following on the device and syncs it to the ISP's tenant on the Platform:
- Technician account & device: staff name, email, role, the device's operating-system version, the app version, and a device identifier used to bind the licence.
- Location data: GPS coordinates attached to each speed test, photo, job-card timestamp, vehicle inspection and tower-finder reading. The app does not stream continuous location to OneWISP - location is captured at the moment of each event.
- Photos and attachments: labelled site photos, vehicle inspection photos, fuel-receipt photos, and any other media the technician chooses to attach to a job.
- Job and job-card data: assigned jobs, status changes, on-hold reasons, timer durations, customer signature image, OTP verification record, and any free-text notes the technician enters.
- Network capture: speed test results (download, upload, latency) and any device readings the technician records on-site.
- Vehicle & fleet records: claimed vehicle, odometer at shift start/end, fuel litres, cost, fuel station, receipt photo, multi-point vehicle inspections.
- Safety records: hazard and incident reports filed by the technician.
- Stock usage: materials drawn against a job.
- Push-notification tokens: a device token used to deliver job assignment notifications. We do not use push notifications for marketing.
The end customers visited by the technician (the ISP's subscribers) may have their signature, address and contact details recorded against the job card. For that data the ISP is the responsible party and OneWISP acts as operator.
Information we collect automatically across the Services
- IP address, browser/app type and version, operating system and device class, used to render the Service and detect abuse.
- Approximate country derived from your IP address (Site only), used to display pricing in your local currency.
- Diagnostic events, crash reports and error logs from the Platform and the Field app, used to keep the Services reliable.
We do not knowingly collect personal information from children under 18. We do not collect special personal information (such as race, religion, health information or biometric data) through the Site, the Platform or the Field app.
03Device permissions used by the Field app
OneWISP-Field is installed on the technician's mobile device. The first time it needs one of the following capabilities, the operating system will prompt the technician to grant permission. The technician can revoke any permission later through their device settings, with the consequence that the related feature will stop working.
- Location ("while in use"). Required to geo-tag speed tests, photos, job-card events, vehicle inspections, and to power the Tower Finder. We do not request "background location" tracking.
- Camera. Required to capture site photos, vehicle inspection photos, fuel-receipt photos, and signatures.
- Photo library / storage. Required to attach existing photos to a job and to cache pending uploads while offline.
- Notifications. Required to deliver job-assignment and status notifications to the technician.
- Network state. Used by the offline-first sync engine to decide whether to upload now or queue for later.
We do not request access to contacts, calendar, microphone, SMS messages, or call logs. We do not enable background location tracking, and we do not run continuous-tracking telematics.
04Offline-first storage and sync
OneWISP-Field is built to keep working when the technician drives out of signal. When there is no connectivity:
- Photos, notes, signatures, vehicle and stock records are stored encrypted on the device.
- Nothing leaves the device until connectivity is restored.
- Once connectivity returns, the app uploads the queued items in order to the ISP's tenant on the Platform.
A technician who loses, breaks, sells or returns the device should sign out of the Field app first. If they cannot, the ISP administrator can revoke the device session from the Platform, which renders any data still on the device unusable for further sync.
05Why we collect it, and our legal basis
POPIA requires every act of processing to have a lawful basis. We rely on the following bases set out in section 11 of POPIA:
- Consent. Submitting an apply or contact form, or signing into the Platform / Field app for the first time, counts as consent for the processing described in this Policy.
- Contract performance. Evaluating an application and onboarding an ISP are pre-contractual steps; running the Platform and the Field app for paying ISPs is contract performance under the SLMaS Agreement.
- Legal obligation. We retain certain records for tax, accounting, and audit purposes as required by South African law.
- Legitimate interest. Limited technical information (IPs, diagnostic events) is processed to keep the Services secure, prevent abuse, and improve reliability.
- Operator instructions. For Customer Data inside the Platform and Field app, we process only on the documented instructions of the responsible-party ISP, as set out in Annexure C of the SLMaS Agreement.
The specific purposes for which we use information are:
- To evaluate, action and respond to applications.
- To generate, store and counter-sign SLMaS Agreements.
- To provide, support and improve the OneWISP Platform and the OneWISP-Field app.
- To deliver job assignments, sync field captures, and produce reports for the responsible-party ISP.
- To reply to enquiries.
- To meet our legal, accounting, audit and tax obligations.
- To detect, investigate and prevent fraud, abuse, and unauthorised access.
We will not use your information for any other purpose without first obtaining your consent (or the responsible-party ISP's consent, where applicable).
07How long we keep it
We keep personal information only for as long as we need it.
- Active application: while we are evaluating it, plus 90 days after a decision is made.
- Rejected or withdrawn applications: retained for 12 months in case you re-apply, then securely deleted.
- Accepted applications and signed agreements: for the duration of our contractual relationship with you, plus the periods required by South African tax, accounting and prescription laws (typically 5 to 7 years after the end of the contract).
- Platform Customer Data: for the duration of the SLMaS Agreement, plus the 90-day Transition Period defined in that Agreement. We also retain backups in line with our published retention schedule.
- Field-app captures (photos, job cards, vehicle records, signatures): retained inside the responsible-party ISP's Platform tenant for as long as the ISP requires, subject to the same Platform retention rules. The local device cache is automatically pruned once items have synced.
- Contact form messages: retained for up to 24 months after the last correspondence on that thread, unless we need to keep them longer to defend a legal claim.
- Technical logs (IP, user agent, diagnostics): retained for up to 12 months for security and abuse prevention, then deleted or anonymised.
Once these periods expire, we securely delete the information or anonymise it so it can no longer be linked back to an individual.
08How we protect it
We take appropriate technical and organisational measures, as contemplated by POPIA section 19, to protect personal information across the Services. These measures include:
- Encryption in transit (HTTPS / TLS) for the Site, the Platform and every Field-app API call.
- Encryption at rest for signed documents, database storage, and the Field app's on-device cache.
- Strict access controls: only authorised staff who need information for their role can access it.
- Tenant isolation: each ISP's Platform data is logically separated from every other ISP's data.
- Audit logging of administrative actions on Customer Data.
- Periodic review of security measures, dependencies, and patch levels.
- Operator agreements with every third-party processor obliging them to the same standard.
In the unlikely event of a security compromise affecting personal information, we will notify the affected parties and the Information Regulator without unreasonable delay, as required by POPIA section 22. Where we are the operator, we will notify the responsible-party ISP within the time limits stipulated in Annexure C of the SLMaS Agreement.
09Where your information is stored
Personal information is primarily stored on servers located in the Republic of South Africa.
If we ever need to transfer information to a country outside South Africa (for example, to use a cloud provider with infrastructure abroad), we will only do so where:
- You (or the responsible-party ISP, where we are the operator) have consented to the transfer; or
- The recipient is subject to a law, binding corporate rules or contractual obligation that provides an adequate level of protection equivalent to POPIA; or
- The transfer is necessary to perform a contract between you and us.
10Your rights under POPIA
You have the following rights in respect of your personal information:
- Right of access. Ask us to confirm what information we hold about you and to provide a copy.
- Right to correction. Ask us to correct information that is inaccurate, misleading, outdated, or incomplete.
- Right to deletion. Ask us to delete information we no longer have a lawful basis to keep.
- Right to object. Object, on reasonable grounds, to processing based on legitimate interest.
- Right to withdraw consent. Where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint. Complain to the Information Regulator if you believe we have not complied with POPIA. Contact details for the Regulator are at inforegulator.org.za.
To exercise any of these rights for information we hold as responsible party, email admin@one-wisp.co.za. If you are an end-subscriber of an ISP, contact the ISP directly - they are the responsible party for your data and we will support them in responding to you.
We may need to verify your identity before responding, and we will respond within the period required by POPIA (currently 30 days).
12Changes to this policy
We may update this Privacy Policy from time to time. The "last updated" date at the top of the policy will tell you when. Material changes will be drawn to your attention through the Site, the Platform, in-app notification in the Field app, or by email to active applicants, customers and the technicians of customer ISPs.
Continuing to use any of the OneWISP Services after a change indicates your acceptance of the updated policy.
Questions about this document? Email admin@one-wisp.co.za or use the contact form.
