1. Who we are and the scope of this policy
Oasentra is a business software platform operated by DAILY ICT SOLUTIONS, with its registered address at Ikota GRA, Lekki, Lagos (“we,” “us,” or “our”). Its available capabilities include customer relationship management, communications, workflow automation, human-reviewed AI assistance, developer integrations, and operational analytics. This policy applies to information processed through the Oasentra website, workspace, APIs, webhooks, and support communications.
Businesses using our workspace remain responsible for having a lawful basis and appropriate permission to contact their recipients. Third-party messaging services also process information under their own terms and privacy policies.
2. Information we collect
Account and contact information
We may collect a user's name, business email address, authentication details, business name, and information provided in support requests.
Connection and messaging information
To provide the workspace, we may process business account identifiers, phone number identifiers, recipient telephone numbers, message or template content, template language and category, external message identifiers, delivery status, error details, and relevant timestamps.
Customer relationship and consent information
Business users may store customer profiles, company and role information, relationships, internal activity history, communication preferences, consent decisions, evidence notes, lifecycle stages, and external references. The business that supplies this information is responsible for its accuracy and lawful use.
Oasentra newsletter information
When someone subscribes to Oasentra communications, we may process their email address, name, company, country, selected topics, confirmation state, consent source, consent-policy version and timestamps. We also keep unsubscribe, suppression, bounce and complaint evidence, plus limited campaign and link-interaction records where available, so that we can honour communication choices and measure useful outcomes.
Automation, developer, analytics, and AI information
We process workflow definitions and run history, approval decisions, API-key metadata, webhook endpoint and delivery records, and aggregated usage measurements. When Oasentra AI is enabled and an authorised user requests a briefing, we may send a minimised selection of recent customer activity and messages to our AI service provider to generate a recommendation or draft for human review. We do not send Oasentra, Meta, API, or webhook credentials in that context, and the AI cannot send a message or update a customer record by itself.
Technical and usage information
Our systems may record IP address, browser and device information, sign-in events, diagnostic logs, request timestamps, and pages or features used. We use this information for security, troubleshooting, and service operation.
Information we do not request through the interface
Users should not enter payment-card details, government identity numbers, medical records, passwords, access tokens, or other highly sensitive information into message bodies, templates, or support requests.
3. How we use information
We use information to:
- create and secure user accounts;
- connect authorised business messaging resources;
- send user-directed messages and submit or synchronise message templates;
- maintain customer profiles, consent evidence, relationships, and activity history;
- run configured workflows with delays and human approval controls;
- provide scoped APIs, signed webhooks, and integration diagnostics;
- generate requested, human-reviewed AI briefings and drafts when the feature is enabled;
- display activity, delivery state, operational metrics, and errors;
- provide support, investigate incidents, and prevent misuse;
- send confirmed Oasentra newsletters and product communications according to subscriber preferences, and honour unsubscribe or suppression decisions;
- maintain, analyse, and improve service reliability; and
- meet applicable legal, regulatory, and contractual obligations.
4. Legal bases
Depending on the context and applicable law, we process information to perform a contract, pursue legitimate interests such as securing and operating our services, comply with legal obligations, or act on consent. A business using our tools must separately determine and document the proper basis for its customer communications.
5. Sharing and service providers
We may share limited information with infrastructure, hosting, security, email, support, messaging-platform, and AI inference providers when necessary to deliver an enabled service. Oasentra currently uses Hetzner for infrastructure, Cloudflare for DNS and edge security, Meta for WhatsApp business messaging, Spacemail for service email, and OpenAI for requested AI inference. These providers receive only the information needed for their functions and process it under their applicable agreements and safeguards.
Spacemail is also used to transmit confirmed Oasentra newsletters. Each marketing message is addressed individually and includes preference and unsubscribe controls. SMTP acceptance means only that Spacemail accepted the message for onward delivery; we do not present it as proof that a recipient received or opened the message.
We may also disclose information when required by law, to protect people or our systems, to investigate abuse, or as part of a legitimate business reorganisation. We do not sell personal information or share it for unrelated third-party advertising.
6. International processing
Our messaging platform and any hosting or support providers may process information in countries different from the user's location. We will identify the providers used by the deployed service and apply transfer safeguards where required by applicable law before onboarding external business customers.
7. Retention and deletion
We retain information only for as long as it is reasonably needed to operate the service, keep appropriate business and security records, resolve disputes, and meet legal obligations. Signed inbound webhook-event summaries expire after 30 days, failed queue records are pruned after seven days, developer idempotency records normally expire after 24 hours, and terminal outbound webhook delivery records are pruned after 90 days. AI briefing results are encrypted and normally purged after 30 days while minimised usage totals may be retained for operational reporting. Customer profiles, append-only consent history, relationship history, account, connection, message, template, audit, support, and deletion-request records are reviewed as part of a verified deletion request or account closure.
Newsletter consent, preference and unsubscribe evidence is retained while a subscription is active and for a proportionate period afterwards. A minimal suppression record may be retained after an unsubscribe, hard bounce or complaint so that we do not accidentally contact the address again.
Deletion requests are recorded for identity and authority checks, manual processing, and completion tracking. If the deployed service uses backups, deleted data may remain until the documented backup rotation expires. Instructions for requesting deletion are available on our data deletion page.
8. Security
We use administrative, technical, and organisational safeguards proportionate to the nature of the information we process. These include access controls, credential-management practices, request validation, logging controls, and secure transport where supported. No online service is completely risk-free, so users must also protect their credentials and report suspected unauthorised access promptly.
9. Your choices and rights
Subject to applicable law, individuals may ask to access, correct, delete, restrict, or receive a copy of their personal information, or object to certain processing. They may also withdraw consent where processing relies on consent.
We may need to verify identity and authority before acting on a request. If information was provided to us by one of our business customers, we may refer the request to that business as the responsible controller.
Newsletter subscribers can change individual topic preferences or globally unsubscribe through the signed links included in optional communications. Essential account, billing and security notices are not marketing and may still be sent where required to operate an account.
10. Children
Our services are intended for authorised business users and are not directed to children. We do not knowingly collect personal information directly from children through this workspace.
11. Policy changes
We may update this policy as our services or legal obligations change. We will post the revised version and its effective date. Material changes may also be communicated through the service or by email.
12. Contact us
For privacy questions or rights requests, email [email protected]. Please do not include passwords, access tokens, or unnecessary sensitive information.