Draft for legal review — not yet the final Ordo privacy notice.
Account identity and contact details, business and branch configuration, staff permissions, product and stock records, sales and payment records, device health, support messages and sanitised diagnostics. Ordo must not store raw online-banking passwords, card security codes or unapproved customer credentials.
To provide point-of-sale and back-office services, synchronise authorised devices, secure accounts, support customers, maintain audit evidence, bill subscriptions and meet legal obligations.
Access is restricted by business, branch and role. Approved infrastructure, email, monitoring and payment providers may process only the information required for their service. Ordo does not sell personal information.
Operational information is retained according to documented business, tax, support and security requirements. Ordo uses access controls, encryption in transit, audit records, backups and incident procedures. Final retention periods and the responsible party/operator wording require South African legal approval.
Subject to applicable law, people may request access, correction, objection, restriction or deletion where Ordo is legally permitted to comply. The final notice must include the approved information-officer contact and Information Regulator complaint route.