Privacy
Last updated 1 September 2026
BeOne is an engineering house based in South Africa. We build systems that our clients operate under their own name. This page covers two separate things: what this website does, and how we handle personal data inside the systems we build.
This website
It sets no cookies. There is no cookie banner because there is nothing to consent to. We store nothing in your browser: no cookies, no local storage, no session storage.
We do count page views, using self-hosted analytics on our own server rather than a third-party platform. It is cookieless and records no personal information, no cross-site identifier and no advertising profile. There is no session replay, no heatmap, no third-party tracker and no ad network anywhere on this site. The only external request the page makes is to our own analytics host.
If you email us, we keep that email so we can reply to it. Nothing else.
Work we do for clients
In almost all client work we are a processor, not the controller. The data belongs to the client, the lawful basis is theirs to establish, and the retention periods, access rights and deletion rules are theirs to set. We build to them rather than around them, under the contract and the data-processing terms that govern the engagement.
That is not a formality. It decides who a data subject goes to, and the answer is the client whose panel, customers or operation it is, not us.
Respondent verification, specifically
Our panel fraud work looks at device and network signals, completion behaviour and patterns that persist across sessions. That is personal-data processing before it is anything else, and it needs a lawful basis and a privacy notice on the client's side before a single signal is collected.
Two constraints we hold to. We produce a probability, not a verdict, and the client sets the threshold, so no respondent is excluded by a decision we made on our own. And we work inside the client's governance, on data they already hold and have told their respondents about, rather than acquiring or enriching from anywhere else.
The law we work under
South African work falls under POPIA. Work involving people in the EU or the UK falls under the GDPR, where our role is set out in the processing terms for that engagement. Where a client operates under the ICC/ESOMAR International Code, we build to their obligations under it.
We do not claim a certification we do not hold. If your procurement needs something specific, an ISO position, a completed security questionnaire, a DPIA input, or our standard processing terms, ask and we will tell you plainly what exists and what does not.
Your rights
- Ask what personal information we hold about you, and get a copy.
- Have it corrected if it is wrong, or deleted where we are not required to keep it.
- Object to how it is used, or withdraw consent where consent was the basis.
- Complain to a regulator: the Information Regulator in South Africa, or your supervisory authority in the EU or UK.
If we hold your data on a client's behalf we will pass your request to that client and tell you who they are, because the decision is theirs to make.
Contact
Data and privacy questions, including anything above: hello@beone.ai