Privacy Policy — Dandori
Effective date: 15 September 2026 · JBNC Solutions, South Africa
This policy explains how JBNC Solutions ("JBNC", "we", "us") handles personal information in Dandori, our field service management and security operations application for Android and the web, together with its customer portal, live job tracker and guest links — "the Services". We are committed to compliance with South Africa's Protection of Personal Information Act, 2013 (POPIA), and to the equivalent rights of people in other countries where the Services are used.
This policy covers Dandori specifically. Other JBNC software is covered by its own policy, for example our OmniPremise privacy policy and our general privacy policy.
Who is responsible for your information
Dandori is business software used by service companies — electricians, plumbers, fabricators, HVAC and other trades — and by security companies ("Clients"). In almost every case the Client you work for, or who does work for you, is the responsible party for your personal information, and JBNC processes it on their behalf as an operator/processor. Each Client's data is stored in its own isolated environment and is not visible to any other Client. For our own website visitors and business contacts, JBNC is the responsible party.
What we collect
If you are a Client's staff member — office staff, technicians, guards and supervisors
- Account details — your name, email address and/or cell number, and the role and permissions your administrator assigns you. Accounts are created by invitation from your employer; there is no public self-registration.
- Work records — appointments, job cards (including photographs and the customer's signature), expenses and hours you record, tasks, drawings you acknowledge, inspections, forms, incidents and patrol records you submit.
- Location while on shift — when you start a shift, the app records your location so your team can dispatch the nearest person, show arrival times and keep you safe. Location is collected only while a shift is active, including in the background, and a persistent notification is shown the whole time; it stops when you end the shift. Location is also used, in the foreground, for in-app navigation, patrol checkpoints, geofenced sites, and panic/SOS and welfare check-ins.
- Messages — text messages, photographs and voice notes you send to your team through the app.
- Security-industry records (security companies only) — rosters and attendance, and compliance documents such as registration grade and number, firearm competency, training, and medical fitness certificates.
- Employment records (where your employer uses Dandori's workforce features) — identity or passport number, date of birth, home address, next of kin, tax and UIF reference numbers, leave, disciplinary records, wage rates and payroll exports. Banking details are encrypted and only the last four digits of an account number are ever shown. These are sensitive records; access is restricted to the roles your employer authorises.
- Activity records — the system attributes changes to the account that made them. This protects customers and staff alike and is visible to your administrators.
If you are a customer of a Client
- Contact and site details — your name, phone number, email address, and the addresses of the sites where work is done, with a map location.
- Work done for you — appointments, job cards and photographs, your signature when you sign off work, quotes and invoices.
- Payments — if the Client offers online payment, you pay through the Client's own Stripe account. Dandori records whether an invoice has been paid; it never sees or stores your card details.
- Live job tracker — if a Client sends you a tracking link, it shows the business name, the technician's first name, their location on the way to you and the expected arrival time. The link stops working shortly after the appointment.
If you visit a site guarded by a Client
Where a security company uses Dandori at a gate, your visit may be recorded, including your name, the vehicle registration, and details read from your driver's licence or vehicle licence disc by scanning it on the guard's device. Your full identity number is kept separately, visible only to managers, and is shown masked everywhere else. Visit records are anonymised automatically after a retention period (90 days by default), when the identity number, any document photograph and your name are removed.
If you are a guest — for example a subcontractor with a link
A Client may send you a link to view drawings and details for a job without creating an account. We record your name as the Client entered it, the phone number the link was sent to, when you open the link, which drawings you acknowledge, photographs you send, and visits you mark as started or finished.
Technical data
- Crash and diagnostic data — Firebase Crashlytics collects crash reports and basic device information (model, operating system version) so that we can fix faults.
- Notification tokens — a device identifier issued by Google so that push notifications can reach your device. It is used for that and nothing else.
- App integrity checks — every request from the app is checked as coming from a genuine, unmodified installation.
Device permissions. The Android app asks for: location (including background location, used only while you are on shift, with a visible notification), camera (photographs, and scanning licences and discs at a gate), microphone (recording a voice note, only while you are recording), photos (attaching an image you choose) and notifications. Scanning licences and reading text from them happens on the device.
What we do not collect
The Dandori app contains no advertising and no analytics or tracking software. We do not build advertising profiles, we do not sell personal information, and we do not share it with anyone other than the service providers listed below and the Client you work for or deal with.
How we use information
- Operating the Services: scheduling and dispatching work, recording job cards and signatures, invoicing, tracking arrival times, managing drawings and materials, rostering and paying staff, running patrols and control rooms, and recording site access — all on the Client's behalf.
- Keeping people safe: panic/SOS alerts, welfare check-ins and the location of staff on shift.
- Sending notifications and messages about work that concerns you — an appointment, an arrival time, an invoice, an invitation — by push notification, SMS, WhatsApp or email.
- Maintaining security, preventing misuse and investigating faults, through activity records and crash reporting.
- Providing support to Clients.
Who else processes your information
- Google Firebase (Google Cloud Platform) hosts the Services and provides authentication, database, file storage, notifications, app integrity checks and crash reporting.
- Mapbox provides maps, address search, directions and travel times. Addresses and locations are sent to Mapbox to answer those requests. Where Mapbox is unavailable, map images come from OpenStreetMap.
- Twilio sends SMS messages, such as invitation codes and job links, to the phone number concerned.
- WhatsApp (Meta Platforms) — where a Client links its own WhatsApp number, messages to you are sent over WhatsApp through a gateway operated by JBNC, and are subject to WhatsApp's terms and privacy policy in addition to this one.
- The Client's own email provider — email from Dandori is sent through each Client's own mail server, using credentials they configure and that we store encrypted.
- Stripe processes subscription payments from Clients to JBNC and, where a Client enables it, invoice payments from customers to that Client's own Stripe account.
- Dropbox and Google Drive — only where a Client chooses to connect them. See the next section.
Dropbox and Google Drive
A Client's owner may connect the company's Dropbox or Google Drive so that office staff can attach drawings from it to jobs. Connecting is optional and can be undone at any time from Administration → Integrations.
- Access requested. Dropbox: permission to read the account's basic details and to read files and their details. Google: your Google account's email address (to show which account is connected) and the per-file Google Drive permission (
drive.file), which gives Dandori access only to the files a user picks with Google's own file picker — not to the rest of the Drive. - What Dandori does with it. When a user picks a file, Dandori makes a copy of it as a drawing on the job, and remembers which file it came from so it can tell the Client when that file changes. Dandori periodically checks the picked files' details (name, version and checksum) for that purpose. Dandori does not create, change or delete anything in a connected Dropbox or Google Drive.
- What is stored. An encrypted access credential for the connection (never shown to any user), the connected account's email or name, and, for each attached file, its identifier, name, version and checksum, and the copy made. Copies are kept with the job's other drawings.
- Browser access. To open Google's file picker, a short-lived access key for the connected Google account (valid for up to an hour) is sent to the browser of the office staff member using it. Office staff can only use this feature if their role allows it.
- Disconnecting. Disconnecting removes the stored credential and asks Dropbox or Google to revoke Dandori's access. Drawings already attached remain as copies on the jobs. You can also remove Dandori's access directly from your Dropbox or Google account settings.
- Sharing. Information obtained from Dropbox or Google is used only to provide the attach-and-update feature to the Client that connected the account. It is not sold, not used for advertising, not used to train AI models, and not shared with anyone except as needed to run the feature, to comply with the law, or with the Client's permission.
Dandori's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where information is stored
The Services run on Google Firebase. Database records, uploaded files and application services are hosted in Google's europe-west1 region (Belgium). Where personal information is transferred across borders it is protected by Google Cloud's contractual and security commitments, in line with section 72 of POPIA. Service providers listed above may process information in other countries under their own safeguards.
Information is encrypted in transit at all times, and the most sensitive items — email and payment credentials, banking details and drive connection credentials — are additionally encrypted before they are stored.
How long we keep it
- Job, appointment, drawing and customer records are retained for as long as the Client requires them to run their business.
- In-app messages, including photographs and voice notes, are deleted automatically after 180 days unless the Client sets a different period.
- Site-access visit records are anonymised automatically after 90 days unless the Client sets a different period.
- Activity records are deleted automatically after 90 days unless the Client sets a different period.
- Location recorded while on shift is kept as part of the Client's operational records while their account is active.
- Invoices and other financial records are retained for five years as required by South African tax law, and employment, payroll and disciplinary records for the period required by labour legislation.
- When a Client leaves the platform, its environment is removed on conclusion of the engagement, subject to the legal retention periods above.
Your rights
You may request access to, correction of, or deletion of your personal information. Dandori lets signed-in users download a copy of their own data from their profile. Customers and staff may also direct requests to the Client they deal with or work for, who is the responsible party and can action them in the system; you may also contact us directly and we will assist or forward your request.
If you believe your information has been handled unlawfully, you have the right to lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za — or with the data protection authority in your own country.
Requesting deletion of your data
From inside the app
If you have a Dandori account, open your profile and choose "Delete my account". Your account is scheduled for deletion after a 7-day cooling-off period, during which you can cancel. An account owner's request is first confirmed by JBNC, so that a business is never locked out of its own records by mistake. When the period ends, your account is disabled and signed out on every device, and your name, email address and phone number are removed from your profile and, for customers, from the customer record linked to you.
By email
If you cannot use the app — for example you are a customer, a guest, a site visitor or a former employee — email info@jbncsolutions.co.za with the subject line “Dandori data deletion request” and include:
- your full name;
- the company that uses Dandori that you work for, deal with, or visited;
- the cell number or email address on your account or that the company holds for you; and
- whether you want everything deleted, or only specific information.
We acknowledge requests within 5 working days and complete them within 30 days. Where the request concerns information a Client holds about you, the Client is the responsible party and we act on their instruction — we will tell you if they need to authorise it first.
What is deleted: your account and sign-in, your contact details, your notification tokens, your messages, photographs and voice notes, location recorded for you, and records attributed only to you that no law requires us to keep. Where a record must remain for the business (for example a job card someone else signed off), your personal details on it are removed or de-identified.
What we must keep: where a record must be retained by law — invoices and other financial records for five years under South African tax law, and employment, payroll and disciplinary records for the period required by labour legislation — we remove or de-identify the personal details attached to it wherever possible and keep only what the law requires.
A Client's administrator can deactivate a staff account at any time from inside the application, without contacting us.
Security
Access to the Services requires authentication, and every request from the app is additionally verified as coming from a genuine, unmodified installation. Within a Client's environment, access is role-based: what a technician, a guard, a dispatcher and an owner can each see is decided by permissions their administrator sets. Each Client's data is isolated from every other Client's by rules enforced on the server, not in the app. Sensitive credentials and banking details are encrypted before storage, and we keep activity records of changes.
Children
The Services are business tools and are not directed at children. We do not knowingly collect personal information directly from children.
Changes to this policy
We may update this policy from time to time. The current version will always be available at this address, with its effective date shown above.
Contact
JBNC Solutions
Email: info@jbncsolutions.co.za
Website: www.jbncsolutions.co.za