Summary
This Privacy Policy explains how OnboardMe collects, uses, stores and discloses personal information, and what rights and controls you have over that information. We handle personal information as described in this Policy and applicable privacy law. If you do not agree with this Privacy Policy, you should not use our website or Services.
As a professional services platform, we recognise the sensitive nature of the information we process, including Tax and revenue identifiers, bank account details, identity documentation, and confidential business information. Protecting this data is a legal obligation and a core part of our mission.
Your use of the Service is also governed by our Terms of Service. Where we process personal information on behalf of your organisation (for example your clients' information), our Data Processing Agreement applies and forms part of our agreement with that organisation.
General
The operator of the OnboardMe platform is OnboardMe Pty Ltd (Australian company), trading as OnboardMe. OnboardMe provides a cloud platform for professional service firms to support client onboarding, engagements, payments and billing, and identity verification / AML screening (where enabled), among other workflows.
For personal information we collect in our own business capacity (for example account administration for your firm's subscription, our billing of your firm, security, and product improvement), OnboardMe Pty Ltd is generally the organisation responsible for how that information is used.
When your firm uses OnboardMe for its clients, your firm is responsible for that client data as the "controller" or equivalent under local law. We provide the platform only, and act as a "processor" or service provider for that processing, following your firm's instructions and our Data Processing Agreement. This Policy still describes how the platform works and our security practices; your firm's privacy notice may also apply to you.
Definitions
In this Privacy Policy:
- OnboardMe, we, us or our means OnboardMe Pty Ltd (ACN 680 379 640) and, where the context requires, the personnel who operate the Service.
- You means the individual reading this Policy, including a practice user or a client of a practice using the Service.
- Customer means the organisation that subscribes to the Service.
- Applicable privacy law means the Protection of Personal Information Act 4 of 2013 (POPIA).
- Information Regulator means the Information Regulator established under POPIA.
- Website means the OnboardMe websites and applications from which the Services are provided for this deployment, including za.onboardme.app.
- Personal information means information about an identified or reasonably identifiable individual, including "personal data" under UK GDPR and equivalent terms under applicable privacy law.
- Client Data means personal information relating to the Customer's clients that is processed in the Service on the Customer's behalf.
- Services means the OnboardMe platform for this deployment, including related websites, APIs, and the OnboardMe Assist Chrome extension where installed.
- Sensitive information — Special personal information has the meaning in POPIA (including biometric information). Identity documents, tax numbers, and bank details are personal information and may be confidential, but they are not automatically special personal information. Where identity verification involves special personal information, the Customer (as responsible party) is responsible for having a POPIA justification; OnboardMe processes it only as operator to provide the enabled feature.
Data Processing Agreement
When your firm uses OnboardMe for its clients, we act as a processor (or the equivalent under local law) as described above. The written terms for that processing — including what we are instructed to do, subprocessors, international transfers, security measures, breach notification, assistance with individual rights, and deletion at the end of the subscription — are set out in our Data Processing Agreement.
That DPA is incorporated into the Terms of Service for this deployment. It applies automatically to client data your organisation puts into the Service. If your organisation needs a countersigned copy for procurement, contact us using the details at the end of this Policy. A separately signed DPA prevails over the standard DPA to the extent they conflict.
The DPA does not apply to information we handle as an independent organisation (for example your firm's subscription billing and staff login accounts). End clients of your firm are not parties to the DPA; they should contact your firm about their information, and we will assist your firm as described in the DPA.
High-risk and restricted information
In addition to ordinary personal information (such as name, email, and phone), OnboardMe may process information that is legally restricted, commercially confidential, or both:
- Sensitive / special category / special personal information as defined in applicable privacy law — in particular biometric data used for identity verification where that feature is enabled
- Government identifiers: Tax and revenue identifiers
- Bank account and payment details
- Identity verification documents (for example passports and driving licences) and AML / PEP / sanctions screening records
- Confidential business content such as engagement letters, contracts, and professional service records (typically not sensitive / special category / special personal information, but confidential)
Special personal information has the meaning in POPIA (including biometric information). Identity documents, tax numbers, and bank details are personal information and may be confidential, but they are not automatically special personal information. Where identity verification involves special personal information, the Customer (as responsible party) is responsible for having a POPIA justification; OnboardMe processes it only as operator to provide the enabled feature.
These categories are subject to tighter access control and encryption as described in this Policy and our Information security & business continuity policy.
Types of personal information we collect
Depending on how you use the Service, we may process:
- Identity and contact: name, email, phone, postal address, job title, employer, practice or entity identifiers.
- Electronic signatures: signature images, typed or drawn signatures, and related audit metadata when you sign documents in the Service.
- Account and technical: login identifiers, session and device data, IP address, audit logs, integration identifiers (where you connect third-party systems).
- Service content: information you or your organisation enters into forms, proposals, engagements, ethical letters, identity verification and AML screening flows, and related workflows.
- Identity and AML verification: where those features are enabled, identity documents, facial / biometric capture used for matching, verification outcomes, and screening results returned by our verification provider.
- Financial: billing details, subscription records, and transaction-related data processed by our payment partners where you pay us.
- Usage and diagnostics: feature usage, performance metrics, error reports, and aggregated analytics.
How we collect personal information
We collect personal information only if it is reasonably necessary for our functions and activities, including providing the Services. We may collect personal information when:
- you access, use, or otherwise interact with our website or Services;
- a Customer (or a person acting for a Customer) submits Client Data so we can provide the Services at their request;
- you communicate with our staff during support, billing, or onboarding;
- we receive it from a third-party system the Customer has connected (for example a practice management or accounting integration); or
- you otherwise deal with us in the course of our business.
Where we collect Sensitive information, we do so only where it is reasonably necessary for the Services (for example identity verification the Customer has enabled) and where collection is permitted or authorised by law, including with consent where required.
Where a Customer submits Client Data, that Customer is responsible for giving those individuals an appropriate collection notice (and any consent the law requires) before or at the time of collection. This Policy describes how we handle that information as a service provider. We do not independently notify every individual whose details a Customer enters, unless the law requires us to.
Why we collect, hold, use and disclose personal information
We process personal information for lawful purposes connected to the Service, including performance of agreements, compliance with law (including identity verification and AML screening where enabled by the Customer), protection of legitimate interests (such as security and service improvement), and consent where we rely on it.
Third parties requesting the Services
Professional firms use OnboardMe to onboard and engage their own clients. If a Customer (your accountant, lawyer, or other adviser) puts your information into the Service, that Customer decides what to collect and how to use it for their professional work. That Customer is responsible for its own privacy notice and for any consent the law requires. We do not control that Customer's privacy practices. We still take the security steps described in this Policy for information we hold.
Connecting an optional integration (for example Xero, FYI, GreatSoft, or Google Workspace) is the Customer's choice. That does not mean we endorse the third party's privacy practices. You should read the Customer's privacy notice and the third party's terms. Requests about Client Data should usually go to the Customer first; we assist as described in our Data Processing Agreement.
Direct marketing
We send service and transactional messages to practice users as needed to operate the Service. Electronic direct marketing is sent only with consent, except we may market similar products or services to existing customers who have not objected, with an opt-out in each message (POPIA section 69). You can opt out via unsubscribe or by emailing [email protected]. We do not use Client Data for OnboardMe marketing.
How we store and protect personal information
Production data for this deployment is stored in the Rackzar in Cape Town, consistent with South African data protection and sovereignty laws. Backups, recovery objectives, and security controls are described in our Information security & business continuity policy.
We take reasonable steps to:
- take reasonable steps so that personal information we collect is accurate, up-to-date, complete and relevant, having regard to the purpose of collection
- take reasonable steps so that personal information we use or disclose is accurate, up-to-date, complete, relevant and not misleading, having regard to that use or disclosure
- take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure
- destroy or de-identify personal information we no longer need for the purposes for which it was collected, except where we must or may retain it (for example legal, tax, or dispute records, or encrypted backups until they expire)
- Encryption: Stored customer data is encrypted at rest. Data in transit is protected using TLS 1.2+. Further controls are described in our Information security & business continuity policy.
- Access controls: Role-based access control (RBAC) and authentication policies limit OnboardMe staff access. Multi-factor authentication (MFA) is mandatory for OnboardMe staff accounts and privileged production access. Subprocessors are bound by confidentiality and security obligations appropriate to their role.
- Monitoring: Access and security events are logged and monitored. Alerts may be sent to our security team at [email protected].
- Backups: Encrypted backups are maintained within South Africa (Cape Town).
- Retention: We retain personal information only as long as needed for the purposes above, including to perform our contract, meet legal, tax, and regulatory record-keeping duties, resolve disputes, and enforce agreements. Retention periods vary by data type; when no longer required, we delete, de-identify, or anonymise it using secure methods, as applicable.
Transmission of information over the internet is not completely secure. We cannot guarantee the security of information in transit. Once we receive it, we take the steps described in this Policy and our Information security & business continuity policy. Those steps do not reduce our security obligations under applicable privacy law.
This Policy does not cover the privacy practices of third parties (including Customers and optional integrations). We are not responsible for those practices.
Who we disclose personal information to
We do not sell your personal information. We share it only as needed to run the Service, comply with law, or with your direction, including with:
- Infrastructure and security: cloud hosting, backup, logging, and monitoring providers for this deployment (see the Material subprocessors table below; primary hosting is Rackzar in Cape Town).
- Identity verification and AML: when your organisation uses identity verification or anti-money laundering (AML) screening features, we share relevant personal information with ComplyCube, a United Kingdom-based identity and AML verification provider (see their Security & Compliance Center for further detail). This may include identity and contact details, identity documents, live facial images or biometric data used for verification, and AML / PEP / sanctions screening inputs and results. ComplyCube processes and stores that data in the United Kingdom. These features are enabled and directed by your organisation; ComplyCube acts as our subprocessor for that processing.
- Analytics and diagnostics: PostHog, Sentry, and (on AWS deployments) CloudWatch, as described under Using our website and cookies.
- Communications: email and SMS delivery providers (Resend and Mailgun for email, and TallBob for SMS) used to send transactional or service-related messages.
- Payments: Paystack processes payment and billing-related personal information as needed to collect fees for this deployment.
- Optional integrations: practice management, accounting, document, or email systems that you or your organisation choose to connect (for example Xero, FYI, GreatSoft, or Google Workspace). What is shared depends on the integration and your configuration. These are generally engaged at your organisation's direction rather than as OnboardMe's default subprocessors.
- Professional advisers: lawyers, accountants, or insurers where required and subject to confidentiality.
- Authorities: regulators, courts, or law enforcement when we are legally required or permitted to respond.
- Corporate transactions: a prospective or actual purchaser, investor, or successor, on confidential terms, if we negotiate or complete a sale, merger, or restructure of our business.
Subprocessors
The table below lists material third-party subprocessors we use to operate this deployment of the Service. Where a name is linked, it opens that provider's privacy or security policy. Optional integrations you connect yourself are not listed here.
| Subprocessor | Purpose | Location |
|---|---|---|
| Rackzar | Cloud hosting, backups, and related infrastructure | South Africa (Cape Town) |
| ComplyCube | Identity verification and AML / PEP / sanctions screening (where enabled) | United Kingdom |
| Paystack | Payment processing | As operated by Paystack for South Africa payments |
| Resend | Transactional and service email delivery | United States (and other locations as operated by Resend) |
| Mailgun | Transactional and service email delivery | United States and other locations as operated by Mailgun |
| TallBob | SMS messaging | Australia (as operated by TallBob) |
| UptimeRobot | External uptime and availability monitoring | As operated by UptimeRobot |
| PostHog | Product analytics and diagnostics | European Economic Area (PostHog EU Cloud) |
| Sentry | Application error monitoring and diagnostics | European Union (error ingestion in Germany) |
We may update this list from time to time. Material changes are communicated in line with your agreement with us (for example, via product notices or email to organisation administrators), including the subprocessor notice process in our Data Processing Agreement.
Monitoring and logging
We use monitoring and logging for security, compliance, reliability, and product improvement.
- User activity: pages visited, time spent, and feature usage, to improve user experience and product design.
- System logs: session metadata, IP addresses, authentication events, and error logs, to maintain stability and detect threats.
- Performance metrics: API response times, latency, and availability statistics.
- Diagnostic data: collected when errors occur to improve stability.
Infrastructure logs for this deployment are stored in South Africa (Cape Town), subject to the same security standards as other service data. Diagnostic and analytics data sent to Sentry, PostHog, or UptimeRobot is processed in those providers’ locations listed in the subprocessors table. Where practicable, we aggregate or pseudonymise analytics.
Automated decision-making
We do not use solely automated decision-making that produces legal or similarly significant effects concerning you as a decision of OnboardMe. Identity verification and AML screening features may return automated results from our verification provider (ComplyCube); your organisation remains responsible for how those results are used in its compliance decisions.
Data breach response
We follow incident response procedures aligned with POPIA and guidance from the Information Regulator, including assessment and notification where the law requires.
- Incidents are detected, investigated, and contained using our security processes.
- Where mandatory notification applies, we notify the Information Regulator and affected data subjects in line with POPIA and applicable timelines.
- We document breaches and remediation as required.
- We review and test our incident response processes on an ongoing basis.
Compliance with South African law
We are committed to handling personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA), including conditions for lawful processing, information quality, security safeguards, and data subject participation.
We review our data handling practices regularly to reflect changes in law, technology, and industry practice.
How you can access or correct personal information
Under POPIA you may have rights to access, correct, delete, or restrict processing of personal information, to object to processing, to withdraw consent where processing is based on consent, and to complain to the Information Regulator. Some rights may be limited by law or by our obligations to you or your organisation. If your request is about Client Data we process as operator for a Customer, contact that Customer first. We may need the Customer’s authorisation before we can act, unless the law requires us to deal with you directly.
To exercise your rights, email [email protected] with the subject line "Privacy request" and enough detail for us to verify your identity and locate the relevant information. If your organisation subscribes to OnboardMe, we may need to coordinate with your organisation's administrator where data is held on their behalf, as described in our Data Processing Agreement.
We will only release personal information to you where we are satisfied that it relates to you. We may ask you to verify your identity before we do so.
If we refuse a request for access or correction, we will give our reasons in writing where the law requires it (and otherwise where reasonable) and tell you how to complain.
We aim to respond within 30 days, or sooner if required by applicable law. There is no fee for a legitimate request unless the law allows a reasonable charge for manifestly unfounded or excessive requests.
Making a complaint
Complaints about this Privacy Policy or our collection, use or disclosure of personal information should first be directed to us at [email protected]. We will investigate and attempt to resolve your complaint.
You may lodge a complaint with the Information Regulator (South Africa). We encourage you to contact us first so we can try to resolve your concern.
Overseas disclosure
Primary infrastructure and stored customer data for this deployment are located in South Africa (Rackzar, Cape Town). When your organisation enables identity verification or AML screening features, relevant personal information (such as identity documents, live facial or biometric capture used for verification, and screening data) is shared with ComplyCube, a United Kingdom-based identity and AML verification provider, and is processed and stored in the United Kingdom. Payment processing is handled by Paystack. Transactional email and SMS (Resend, Mailgun, TallBob), product analytics (PostHog EU Cloud), and error monitoring (Sentry in the EU) necessarily involve processing outside the primary hosting region. Optional integrations you connect may involve further disclosure at your or your organisation’s direction. Those transfers are made only as needed to perform the Services, with appropriate safeguards and in line with POPIA section 72 where it applies.
Where personal information is transferred outside South Africa in order to provide the Services (including to ComplyCube in the United Kingdom, and to email, analytics, and error-monitoring providers), we do so only as needed to perform the Services, with appropriate safeguards and in line with POPIA section 72 where it applies.
Transfer mechanisms, Customer instructions, and subprocessor locations for processing we do on your organisation's behalf are set out in the Data Processing Agreement.
Visitors in the EEA or United Kingdom
If EU or UK data protection law applies to you while you use this South African deployment, we still handle your information as described in this Policy. You may have additional rights. Contact us to exercise those rights; where the information is Client Data held for a Customer, we will usually coordinate with that Customer.
Children's privacy
The Service is designed for businesses and professionals. We do not knowingly collect personal information from children (under 18). If we learn that we have collected such information, we will take steps to delete it.
OnboardMe Assist Chrome extension
Where you install OnboardMe Assist, the extension may handle session API credentials and client bank / identity verification fields solely to fill empty fields in Xero Practice Manager. Credentials are kept in browser session storage only. A dedicated notice for the Chrome Web Store listing is published on our Chrome extension privacy page. .
Changes to this Privacy Policy
We may update this Policy to reflect legal, regulatory, or operational changes. The updated version will be published on this page with a revised effective date. Where changes are material and we have your contact details, we may also notify you by email or through the App.
Further information
For privacy questions or requests, email [email protected] (our privacy contact). We do not currently appoint a statutory data protection officer under UK GDPR. Security reports may be sent to [email protected].
- Email: [email protected]
- Security: [email protected]
OnboardMe Pty Ltd (ACN 680 379 640). Postal or registered office details can be provided on request to the same email address.
Further information about privacy rights and how to complain to a regulator is available from: