Privacy Policy
Last updated: 13 August 2026
This Privacy Policy explains how OneAI (“OneAI”, “we”, “our”) collects, uses, discloses, and safeguards information about you when you use our website and our compliance operating system for payments (the “Services”).
We designed our Services for regulated payments businesses. Where our customers act as data controllers, we act as a data processor and process personal data only under a Data Processing Agreement.
1. Information we collect
1.1 Information you provide
- Account and contact information (name, work email, company).
- Content you submit through forms, demos, or support requests.
- Billing information (processed by our payment provider).
1.2 Information collected automatically
- Usage data (pages visited, features used, session timestamps).
- Device and connection metadata (IP address, browser, OS).
- Cookies and similar technologies (see our Cookies policy).
1.3 Customer data processed on behalf of controllers
When our customers use the Services, we process transaction, merchant, and case data on their instructions. We treat that data as customer data and do not use it for our own purposes.
2. How we use information
- To provide, secure, and improve the Services.
- To respond to enquiries and support requests.
- To meet legal, regulatory, and audit obligations.
- To detect and prevent fraud and abuse.
- To communicate service updates and, where permitted, marketing you can opt out of at any time.
3. Legal bases (EEA / UK)
We rely on the following legal bases: performance of a contract, compliance with legal obligations, our legitimate interests, and — where required — your consent.
4. Sharing and disclosure
We share information with:
- Sub-processors that host, secure, and support the Services. See our current list on the Security page.
- Professional advisors (auditors, lawyers, insurers).
- Authorities where legally required or to protect rights, property, or safety.
- Successors in a merger, acquisition, or reorganisation.
We do not sell personal information.
5. International transfers
Where we transfer personal data outside your country, we rely on appropriate safeguards, including Standard Contractual Clauses and supplementary measures.
6. Retention
We retain personal data only as long as necessary for the purposes for which it was collected, and in line with legal, tax, and audit requirements. Customer data is retained per the Data Processing Agreement.
7. Your rights
Depending on your location you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing. To exercise these rights, contact us at sales@oneaialert.com.
8. Security
We implement administrative, technical, and physical safeguards appropriate to the risk. See the Security page for details.
9. Children
The Services are not directed to children under 16, and we do not knowingly collect their personal data.
10. Changes to this policy
We may update this policy from time to time. Material changes will be highlighted on this page and, where required, notified to you.
11. Contact
Privacy enquiries: sales@oneaialert.com.