J One Technologies
Effective date: 01/03/2015 Last updated: 09/09/2026
1. Introduction
J One Technologies (“J One Technologies”, “we”, “us” or “our”) operates the website at www.jonetechnologies.com (the “Site”) and provides web design, custom software systems, business and school management platforms, search engine optimisation, social media management and paid media services (together, the “Services”).
We are based in South Africa and we serve clients worldwide. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over it.
Because we accept clients from any country, this policy is written to meet the requirements of a range of data protection laws, including the Protection of Personal Information Act, 2013 (POPIA) in South Africa, the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Brazil’s Lei Geral de Proteรงรฃo de Dados (LGPD), Canada’s PIPEDA, and the Australian Privacy Act. Where a law that applies to you gives you stronger rights than this policy describes, that law prevails and we will honour it.
Please read this policy together with our Terms of Service.
2. Who we are and how to contact us
Controller / Responsible Party: J One Technologies, trading as J One Technologies Company registration number: 2013/206681/07 Registered address: 28 Anderson Street, Louis Trichardt, Limpopo, South Africa
Information Officer / Privacy Contact: Percy Mudumela : Director, Email: support@jonetechnologies.com Privacy email: privacy@jonetechnologies.com WhatsApp: +27 65 593 8082 Website: https://www.jonetechnologies.com
If you have questions about this policy, or you want to exercise any of your rights, contact us using the details above.
3. Scope of this policy
This policy applies to:
- Visitors to the Site and anyone who submits an enquiry, quote request or contact form
- Clients and prospective clients who book consultations or appointments with us
- Registered users of our client areas, including My Account, the Support Portal, My Bookings, and Tasks & Projects
- Purchasers of any product or service bought through the Site
- Subscribers to our marketing communications
- Anyone who contacts us by email, telephone, WhatsApp or social media
This policy does not apply to:
- Third-party websites we link to, which have their own privacy policies
- Personal information we process on behalf of a client as their service provider โ see Section 13
- Recruitment applicants, who receive a separate notice at the point of application (delete if not applicable)
4. Our two roles: controller and processor
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
As a controller (or “responsible party” under POPIA) we decide why and how personal information is processed. This covers our own website visitors, enquiries, clients, bookings, billing and marketing. Sections 5 to 12 of this policy describe that processing.
As a processor (or “operator” under POPIA) we process personal information on the documented instructions of a client, in systems we build, host or maintain for them. For example, where we build a school management system, the school is the controller of its learner, parent and staff records, and we act only on that school’s instructions. Section 13 covers this. If your data sits inside a platform we built for another organisation, please direct your privacy requests to that organisation in the first instance. We will support them in responding, and we will refer any request we receive directly to them.
5. Personal information we collect
5.1 Information you give us
Enquiry and quote requests. First name, last name, email address, telephone or WhatsApp number, type of business or industry, and the project details you choose to include in free-text fields.
Consultation and appointment bookings. Your name, contact details, the service you are booking, your selected date, time and time zone, answers to any screening questions, and any notes you add. Where a meeting takes place by video, the meeting platform will process further data under its own policy.
Client account registration. Username, email address, password (stored in hashed form, never in plain text), and the profile details you choose to add.
Support tickets. Your name, contact details, the content of your ticket and any attachments, and the correspondence history on that ticket.
Purchases. Billing name, billing address, email address, telephone number, the items or services ordered, your selected currency, order history, invoices and receipts. We do not receive or store your full card number, CVV or expiry date โ payments are processed directly by our payment providers.
Correspondence. The content of emails, WhatsApp messages, contact form submissions, telephone calls and social media messages you send us, along with our replies.
Marketing preferences. Your consent or opt-out status, and the email address or number you asked us to use.
5.2 Information we collect automatically
When you visit the Site, we and our service providers may automatically collect:
- IP address and approximate location derived from it (city or country level)
- Browser type and version, operating system, device type and screen size
- Referring URL, pages viewed, time spent on pages, links and buttons clicked
- Date and time of your visit, and the currency you selected
- Cookie identifiers and similar technologies โ see Section 7
- Server logs, error logs and security event records
5.3 Information from third parties
We may receive personal information from:
- Payment providers, confirming the status of a transaction
- Social media platforms, where you message us or interact with our pages, subject to your settings on those platforms
- Analytics and advertising platforms, in aggregated or pseudonymised form
- Public sources and business directories, where we research a prospective client organisation
- Your organisation, where a colleague provides your work contact details as a project contact
5.4 Special categories and children’s data
We do not deliberately collect special category data (such as health, biometric, religious or political information) about Site visitors or enquirers, and we ask that you do not include it in free-text fields.
The Site and our commercial Services are directed at businesses and organisations, not at children. We do not knowingly collect personal information directly from children under 18 through the Site. Where a platform we build for a client (such as a school management system) contains records about minors, we process that data solely as a processor on the client’s instructions โ see Section 13.
6. Why we use your information, and our legal basis
Where GDPR, UK GDPR, LGPD or a similar law applies, we rely on the legal bases set out below. Under POPIA the equivalent justifications are consent, contractual necessity, legal obligation, and legitimate interests.
| Purpose | Personal information used | Legal basis |
|---|---|---|
| Responding to enquiries and preparing quotations | Contact details, enquiry content | Steps prior to entering a contract; legitimate interests in responding to prospective clients |
| Scheduling and running consultations | Booking details, contact details | Contract; legitimate interests |
| Delivering our Services and managing projects | Client and project contact details, correspondence | Contract |
| Operating client accounts and the support desk | Account credentials, ticket content | Contract |
| Processing payments, invoicing and accounting | Billing and order details | Contract; legal obligation |
| Providing support, maintenance and security updates | Account, ticket and log data | Contract; legitimate interests |
| Site security, fraud prevention and abuse detection | IP address, logs, device data | Legitimate interests; legal obligation |
| Measuring and improving Site performance | Analytics and usage data | Consent, where required by cookie law; otherwise legitimate interests |
| Sending marketing communications | Contact details, preferences | Consent, or legitimate interests for existing clients regarding similar services |
| Advertising and remarketing | Cookie and device identifiers | Consent |
| Meeting tax, accounting and regulatory duties | Transaction and identity records | Legal obligation |
| Establishing, exercising or defending legal claims | Any relevant records | Legitimate interests; legal claims |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You may object to that processing at any time โ see Section 11.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
7. Cookies and similar technologies
We use cookies and similar technologies on the Site. Broadly, they fall into these categories:
Strictly necessary. Required for the Site to function โ session management, login authentication, shopping basket contents, your selected currency, security and load balancing. These cannot be switched off through our cookie controls.
Functional. Remember your preferences and settings, and support features such as the live chat and WhatsApp contact button.
Analytics and performance. Help us understand how visitors find and use the Site so we can improve it. Google Analytics 4 and Bing Webmaster
Advertising and remarketing. Used to measure campaign performance and show relevant advertising on other platforms. Meta Pixel, and Google Ads
Where required by law, we ask for your consent before setting non-essential cookies, and you can change your choices at any time through our cookie banner or preference centre. You can also block or delete cookies through your browser settings, though parts of the Site may then not work correctly.
We do not currently respond to browser “Do Not Track” signals, as no common industry standard exists. Where required by California law, we treat a Global Privacy Control signal as a valid opt-out of the sale or sharing of personal information.
Full cookie list: https://jonetechnologies.com/cookie-policy/
8. Who we share your information with
We do not sell your personal information. We share it only as described here.
Service providers and sub-processors. We use trusted third parties to run our business, each bound by contract to protect your information and use it only for the purposes we specify. These include:
- Website hosting and infrastructure providers
- Email delivery, SMS and WhatsApp messaging providers
- Payment processors, including Bank Trasnfer, PayPal, and PayFast
- Video conferencing providers, including Zoom, Google Meet and Microsoft Teams
- Calendar providers, where you sync bookings โ Google, Apple, Microsoft or Nextcloud
- Analytics and advertising platforms
- Accounting, invoicing and business administration tools
- Backup, security and monitoring services
Professional advisers. Lawyers, accountants, auditors and insurers, where necessary and under a duty of confidentiality.
Authorities. Regulators, courts, law enforcement or government bodies, where we are legally required to disclose information or must do so to establish or defend legal claims.
Business transfers. If our business is sold, merged or reorganised, personal information may transfer to the acquiring entity, which will remain bound by this policy or give you notice of any change.
With your direction. Anyone else you explicitly ask us to share your information with.
A current list of our sub-processors is available on request from privacy@jonetechnologies.com.
9. International transfers of information
We serve clients globally and we use service providers located in a range of countries, including South Africa, the European Union, the United Kingdom and the United States. This means your personal information may be transferred to, stored in or accessed from a country other than your own, where data protection laws may differ from those in your jurisdiction.
Whenever we transfer personal information across borders, we put appropriate safeguards in place, which may include:
- Transferring to a country recognised as providing an adequate level of protection
- Standard Contractual Clauses approved by the European Commission, or the UK International Data Transfer Agreement or Addendum
- Binding contractual commitments requiring the recipient to uphold protection substantially similar to POPIA, as required by section 72 of POPIA
- Your explicit consent, where no other safeguard is available and the law permits it
You may request a copy of the safeguards we rely on by contacting us at privacy@jonetechnologies.com.
10. How long we keep your information
We keep personal information only for as long as we need it for the purposes set out in this policy, or for as long as the law requires.
| Category | Retention period |
|---|---|
| Unsuccessful enquiries and quote requests | 24 months from last contact |
| Client project records and correspondence | Duration of the engagement plus 5 years] |
| Financial, invoicing and tax records | 5 years, per South African tax law] |
| Client account and support ticket data | Duration of the account plus 12 months |
| Marketing contact details | Until you unsubscribe, plus a suppression record kept indefinitely so we do not re-contact you |
| Website analytics and cookie data | Google analytics and Bing Webmasterโtypically 14 to 26 months |
| Server and security logs | Hostinger: 12 months] |
When a retention period ends, we securely delete or irreversibly anonymise the information. Where deletion is not immediately possible โ for example, in encrypted backups โ we isolate the information and delete it on the next backup cycle.
11. Your rights
Subject to the law that applies to you, you have the following rights.
Access. Ask whether we hold personal information about you and receive a copy of it.
Correction. Ask us to correct information that is inaccurate, misleading or incomplete.
Deletion. Ask us to delete information we no longer have a lawful reason to keep.
Restriction. Ask us to limit how we use your information while a dispute or accuracy question is resolved.
Objection. Object to processing based on legitimate interests, and object to direct marketing at any time. Where you object to direct marketing, we will stop without exception.
Portability. Receive information you gave us in a structured, commonly used, machine-readable format, and ask us to transmit it to another provider where technically feasible.
Withdraw consent. Withdraw any consent you previously gave, without affecting processing already carried out.
Automated decisions. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind. If this changes, we will update this policy and tell you about your right to human review.
Complain. Lodge a complaint with your data protection authority โ see Section 15.
11.1 If you are in California
You additionally have the right to know the categories and specific pieces of personal information collected, the categories of sources, the business purposes for collection, and the categories of third parties to whom it is disclosed; to delete personal information; to correct inaccurate personal information; to opt out of the sale or sharing of personal information; and to limit the use of sensitive personal information.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA (confirm this is accurate once you have finalised your advertising and analytics stack โ if you run Meta Pixel or Google Ads remarketing, this statement will likely need to change and a “Do Not Sell or Share My Personal Information” link will be required).
We will not discriminate against you for exercising any of these rights. You may use an authorised agent to submit a request, provided you give that agent written permission and we can verify it.
11.2 If you are in South Africa
Under POPIA you may object to processing on the grounds set out in section 11(3), request correction or deletion under section 24, and complain to the Information Regulator. You may use the Regulator’s prescribed forms, available from its website.
11.3 How to exercise your rights
Contact us at privacy@jonetechnologies.com or by post at the address in Section 2. To protect your information, we may ask you to verify your identity before we act. We will respond within the period the applicable law requires โ generally 30 days, or one month under GDPR โ and we will tell you if we need more time. Exercising your rights is free, though we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, and we will explain our reasons if we do.
12. How we protect your information
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS across the Site and our client portals
- Hashed password storage and support for strong password requirements
- Role-based access control, so staff access only what their role requires
- Access logging and audit trails within our management systems
- Regular software, plugin and security patching
- Routine encrypted backups, with restoration testing
- Confidentiality obligations in all staff and contractor agreements
- Vendor due diligence before we engage a new sub-processor
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach occurs that poses a risk to your rights, we will notify you and the relevant regulator without undue delay, as the applicable law requires.
13. Personal information we process for our clients
Where we build, host, maintain or support a platform for a client โ including business management solution websites, school management systems, e-commerce stores and CRM or booking systems โ we act as a processor for the personal information inside that platform. The client is the controller and decides why and how that data is used.
In that role we:
- Process personal information only on the client’s documented instructions
- Enter into a written data processing agreement with the client where the law requires one
- Apply appropriate security measures to the data we handle
- Bind our own sub-processors to equivalent obligations
- Assist the client in responding to data subject requests and in meeting their breach notification duties
- Delete or return the data at the end of the engagement, according to the client’s instructions
- Refer any request we receive from an individual to the relevant client
Where our client hands over full ownership of the source code, data and assets at project completion and self-hosts the system, our processing of that data ends at handover, and the client becomes solely responsible for it from that point.
If you are a learner, parent, employee or customer of one of our clients and you want to exercise your rights, please contact that organisation directly.
14. Marketing communications
We send marketing communications only where you have consented, or where you are an existing client and the message concerns services similar to those we have already provided and you have not opted out.
Every marketing email includes an unsubscribe link. You can also opt out at any time by emailing privacy@jonetechnologies.com or replying STOP to a marketing SMS or WhatsApp message. We keep a suppression record of your contact details so that we do not accidentally contact you again.
Opting out of marketing does not stop service messages, such as booking confirmations, invoices, support ticket updates and security notices, which we need to send in order to deliver the Services.
15. Complaints
We would prefer to resolve any concern directly, so please contact us first at privacy@jonetechnologies.com. You also have the right to complain to a supervisory authority:
South Africa โ Information Regulator Email: complaints.IR@justice.gov.za Website: https://inforegulator.org.za
United Kingdom โ Information Commissioner’s Office Website: https://ico.org.uk
European Union โ the supervisory authority in your country of residence, work, or where the issue occurred. A list is published by the European Data Protection Board.
Other jurisdictions โ the data protection or privacy authority with jurisdiction where you live.
16. Third-party links
The Site contains links to third-party websites, platforms and social media pages, including WhatsApp, Facebook, Google Play and the Apple App Store. We are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any site you visit from ours.
17. Changes to this policy
We may update this policy to reflect changes in our practices, technology, legal requirements or business. We will post the updated version on this page and change the “Last updated” date at the top.
If the changes are material โ for example, a new purpose for using your information or a new category of recipient โ we will give you prominent notice, and where the law requires it, we will obtain your consent before the change takes effect.
We recommend reviewing this page periodically.
18. Contact us
J One Technologies 28 Anderson Street, Louis Trichardt, Limpopo, South Africa (confirm) Email: support@jonetechnologies.com Privacy email: privacy@jonetechnologies.com, WhatsApp: +27 65 593 8082 Website: https://www.jonetechnologies.com Contact form: https://jonetechnologies.com/contact/
Office hours: Monday to Friday, 08:00 โ 17:00 (SAST)
This policy was last reviewed on 09/09/2026.