Legal

Privacy Policy — Dandori

This policy explains how JBNC Solutions ("JBNC", "we", "us") handles personal information in Dandori, our field service management and security operations application for Android and the web, together with its customer portal, live job tracker and guest links — "the Services". We are committed to compliance with South Africa's Protection of Personal Information Act, 2013 (POPIA), and to the equivalent rights of people in other countries where the Services are used.

This policy covers Dandori specifically. Other JBNC software is covered by its own policy, for example our OmniPremise privacy policy and our general privacy policy.

Who is responsible for your information

Dandori is business software used by service companies — electricians, plumbers, fabricators, HVAC and other trades — and by security companies ("Clients"). In almost every case the Client you work for, or who does work for you, is the responsible party for your personal information, and JBNC processes it on their behalf as an operator/processor. Each Client's data is stored in its own isolated environment and is not visible to any other Client. For our own website visitors and business contacts, JBNC is the responsible party.

What we collect

If you are a Client's staff member — office staff, technicians, guards and supervisors

If you are a customer of a Client

If you visit a site guarded by a Client

Where a security company uses Dandori at a gate, your visit may be recorded, including your name, the vehicle registration, and details read from your driver's licence or vehicle licence disc by scanning it on the guard's device. Your full identity number is kept separately, visible only to managers, and is shown masked everywhere else. Visit records are anonymised automatically after a retention period (90 days by default), when the identity number, any document photograph and your name are removed.

If you are a guest — for example a subcontractor with a link

A Client may send you a link to view drawings and details for a job without creating an account. We record your name as the Client entered it, the phone number the link was sent to, when you open the link, which drawings you acknowledge, photographs you send, and visits you mark as started or finished.

Technical data

What we do not collect

The Dandori app contains no advertising and no analytics or tracking software. We do not build advertising profiles, we do not sell personal information, and we do not share it with anyone other than the service providers listed below and the Client you work for or deal with.

How we use information

Who else processes your information

Dropbox and Google Drive

A Client's owner may connect the company's Dropbox or Google Drive so that office staff can attach drawings from it to jobs. Connecting is optional and can be undone at any time from Administration → Integrations.

Where information is stored

The Services run on Google Firebase. Database records, uploaded files and application services are hosted in Google's europe-west1 region (Belgium). Where personal information is transferred across borders it is protected by Google Cloud's contractual and security commitments, in line with section 72 of POPIA. Service providers listed above may process information in other countries under their own safeguards.

Information is encrypted in transit at all times, and the most sensitive items — email and payment credentials, banking details and drive connection credentials — are additionally encrypted before they are stored.

How long we keep it

Your rights

You may request access to, correction of, or deletion of your personal information. Dandori lets signed-in users download a copy of their own data from their profile. Customers and staff may also direct requests to the Client they deal with or work for, who is the responsible party and can action them in the system; you may also contact us directly and we will assist or forward your request.

If you believe your information has been handled unlawfully, you have the right to lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za — or with the data protection authority in your own country.

Requesting deletion of your data

From inside the app

If you have a Dandori account, open your profile and choose "Delete my account". Your account is scheduled for deletion after a 7-day cooling-off period, during which you can cancel. An account owner's request is first confirmed by JBNC, so that a business is never locked out of its own records by mistake. When the period ends, your account is disabled and signed out on every device, and your name, email address and phone number are removed from your profile and, for customers, from the customer record linked to you.

By email

If you cannot use the app — for example you are a customer, a guest, a site visitor or a former employee — email info@jbncsolutions.co.za with the subject line “Dandori data deletion request” and include:

We acknowledge requests within 5 working days and complete them within 30 days. Where the request concerns information a Client holds about you, the Client is the responsible party and we act on their instruction — we will tell you if they need to authorise it first.

What is deleted: your account and sign-in, your contact details, your notification tokens, your messages, photographs and voice notes, location recorded for you, and records attributed only to you that no law requires us to keep. Where a record must remain for the business (for example a job card someone else signed off), your personal details on it are removed or de-identified.

What we must keep: where a record must be retained by law — invoices and other financial records for five years under South African tax law, and employment, payroll and disciplinary records for the period required by labour legislation — we remove or de-identify the personal details attached to it wherever possible and keep only what the law requires.

Security

Access to the Services requires authentication, and every request from the app is additionally verified as coming from a genuine, unmodified installation. Within a Client's environment, access is role-based: what a technician, a guard, a dispatcher and an owner can each see is decided by permissions their administrator sets. Each Client's data is isolated from every other Client's by rules enforced on the server, not in the app. Sensitive credentials and banking details are encrypted before storage, and we keep activity records of changes.

Children

The Services are business tools and are not directed at children. We do not knowingly collect personal information directly from children.

Changes to this policy

We may update this policy from time to time. The current version will always be available at this address, with its effective date shown above.

Contact

JBNC Solutions
Email: info@jbncsolutions.co.za
Website: www.jbncsolutions.co.za