How OMM uses your information
This notice explains how Online Media Management (Pty) Ltd handles personal information about you and your business in our accounts-receivable workflow, in line with the South African Protection of Personal Information Act 4 of 2013 (“POPIA”).
Last reviewed: 13 Jun 2026
Who we are
Online Media Management (Pty) Ltd (“OMM”, “we”, “us”) is a South African advertising and social-media agency. We are the Responsible Party for the personal information processed in our invoicing and collections workflow.
Reach us at accounts@ommsocial.co.za.
What data we process
We process the minimum needed to issue, track, and collect on invoices:
- Contact details — your name, the name of the business you represent, email address, phone number, and (where relevant) physical address. These are imported from our accounting system (Xero) where we issued you an invoice.
- Communication content — the body of emails, WhatsApp messages, and SMSes exchanged with our accounts team, so we can keep a complete record of what was discussed.
- Payment history — invoice numbers, amounts, dates issued, dates due, dates paid, and any promises-to-pay or disputes recorded against an invoice.
We do not collect or process special personal information (health, religion, biometrics, etc.) for this workflow.
Lawful basis for processing
We process this information under the following lawful bases set out in section 11 of POPIA:
- Contract performance — s11(1)(a): processing is necessary to invoice you for services we agreed to provide and to collect what is owed.
- Legitimate interest — s11(1)(d): it is our legitimate interest to recover outstanding debts using the lightest-touch escalation that works (friendly reminders before formal demands).
Sub-processors
We use the following third parties to operate this workflow. Each acts as our Operator under a written agreement.
- Google Workspace — email send + receive (mailbox
accounts@ommsocial.co.za). - Anthropic (Claude) — drafts reminder copy and classifies your replies. We do not give Claude access to your Xero account directly; the model receives only the specific invoice and conversation context needed to draft a single message.
- Voyage AI — embeds historical Duncan-approved copy snippets so the model can match our tone of voice.
- Meta (WhatsApp Business) — when WhatsApp is enabled, message delivery via the WhatsApp Cloud API. (Not active until Phase 5.)
- Clickatell — SMS fallback delivery in South Africa. (Not active until Phase 5.)
Where your information lives
The system itself runs on a South African server (domains.co.za VPS, Cape Town), so the operational copy of your data stays in South Africa.
Cross-border note: some sub-processors above are not South African. Google Workspace is multi-region; Anthropic and Voyage AI are based in the United States. POPIA section 72 permits this when the recipient is bound by a comparable law, binding rules, or a contractual agreement. We rely on each vendor's Data Processing Addendum.
How long we keep your information
We follow a tiered retention policy that mirrors our tax and record-keeping obligations:
- Invoice + payment records: 7 years. Required under the South African Revenue Service (SARS) record-keeping rules. After 7 years these are pruned from our working database.
- General communications: 3 years active, then archived. Email and message bodies older than 3 years are replaced with a placeholder so the conversation thread remains traceable but the personal content is removed.
- Audit + access logs: 7 years. Held for the same period as the invoice they relate to.
Your rights
POPIA gives you the right to:
- Ask what personal information we hold about you and obtain a copy of it.
- Ask us to correct any information that is wrong or out-of-date.
- Ask us to delete information that we are no longer required to keep for tax or contractual reasons.
- Object to direct marketing (we do not use this data for direct marketing).
- Withdraw consent where processing depends on it.
- Complain to the Information Regulator if you believe we have mishandled your information: inforegulator.org.za.
Opting out of reminders
Reply STOP to any reminder email or message and we will halt automated reminders to you immediately. Manual account-level communication may still happen where there is an open invoice or contractual matter.
Information Officer
Our Information Officer under POPIA is to be appointed (registration in progress with the Information Regulator).
Contact the Information Officer with any access, correction, or deletion request:
- Email: accounts@ommsocial.co.za
Changes to this notice
We review this notice at least once a year and may update it when we change sub-processors, retention rules, or the way we communicate with you. The “Last reviewed” date at the top of the page reflects the most recent review.