Legal · Privacy Policy

Privacy Policy

Effective from 8 October 2026, updated 11 October 2026. Onix is operated by sassly.ai.

This policy explains the data that Onix ("we", "the service") processes when you and your team use Onix to serve your customers: connecting channels such as WhatsApp, email, livechat on a website, and API channels, replying to conversations, and managing tickets, contacts, sales leads (pipeline), and a knowledge base. Onix is not affiliated with, endorsed by, or sponsored by WhatsApp, Meta, or Google. WhatsApp is a trademark of WhatsApp LLC (Meta Platforms, Inc.).

Our role

  • For account, workspace, and billing data, Onix is the data controller.
  • For the customer data a workspace manages (conversations, contacts, groups, tickets), the business that owns the workspace is the data controller. Onix processes that data on the business's behalf and according to its instructions, as a data processor.

Data we process

Type of dataContentsSource
User accountGoogle account ID, name, email, profile photo, preferred language, last sign-in timeGoogle, when you sign in
Workspace & teamWorkspace name, members, roles and permissions, channel access, invitations (recipient email), personal preferences such as tour statusThe Owner and members
Connected channelsWhatsApp number, display name, profile photo, about text, WhatsApp business profile if any, and connection status. For email channels: the email address, IMAP/SMTP servers, username, mailbox password or App Password (encrypted), folders read, sender name, signature, and ignore list. For every channel: the icon/logo, business hours, and auto-reply texts; livechat: the widget's look & texts and allowed domains; API channels: the webhook URL, the webhook secret (encrypted), and a fingerprint (hash) of the channel keyWhatsApp, after the number is connected by scanning a QR code; a workspace admin, when connecting or configuring a channel
Livechat visitorsThe name, email, and phone number entered in the widget form, the site page where the chat started, the browser/device type, browser language, when they were last active, and the chat content and attachmentsVisitors to the workspace's website, through the livechat widget
API channelsMessages, attachments, and customer data (the ID in the workspace's system, name, email, phone number) sent by the workspace's system, and the webhook delivery history (event, content, HTTP code, time)The workspace's own system, using the channel key
ConversationsThe content of incoming and outgoing messages with their media (images, video, audio, documents, stickers, locations, contacts), reactions, edited or deleted messages, delivery/read status, and times. For email: subject, sender & recipients (To, Cc, Reply-To), body, quoted text, attachments, the original email, and thread headersWhatsApp, the connected email mailbox, and team members
WhatsApp groupsFor groups the connected number belongs to: the group name, photo, and description, the participant list (number or ID and name), and messages in the groupWhatsApp
WhatsApp Business labelsLabel names and colors and which chats carry them, read one way from the WhatsApp Business appWhatsApp Business
ContactsName, WhatsApp number or ID (including privacy IDs), sender email address, profile photo, about text, business profile, and details your team enters: email, company, job title, address, city, language, custom fields, labels, and notesWhatsApp and team members
Team workTickets and their discussions, internal notes, assignments, statuses, labels, reply templates, notificationsTeam members
Pipeline (leads & clients)Leads: title, related contact & client, prospect & deal value, budget, stage, owner, follow-up, lost reason, custom fields, activities & notes, checklists, events (title, time, location), uploaded files, and expenses with their photo/PDF receipts. Clients: name, industry, phone, email, website, address, city, notes, and custom fields. Excel/CSV import files are stored temporarily for at most 1 hour for processingTeam members, file imports, and the workspace API
Broadcasts & segmentsContact segments (name & filter rules); broadcasts: name, message content & variations, attachment, sender number, schedule & sending settings, and the risk acknowledgement (name & time); recipient lists: name, number, sent/delivered/read/replied status, skip or failure reason, the message actually sent, and the times; contacts' unsubscribe status (time & source)Team members; delivery statuses from WhatsApp; STOP replies from recipients
Knowledge baseArticles and their categories, article text chunks, and the vector embeddings of those chunksTeam members; embeddings computed via Sumopod
AI (Pro)AI-generated conversation summaries and AI usage records (request and token counts)Sumopod, when members use AI features
BillingBilling name, email, mobile number, and address; invoices; payment status, method, and referenceThe Owner and Sassly Pay
Custom plan requestsName, email, company, mobile number, estimated number of channels and agents, and requirementsThe person sending the request
Technical dataIP addresses and records of important activity (audit log), webhook logs, error logs, when an API key was last usedOur servers

Some of the features above (WhatsApp, email, contacts, tickets, knowledge base, AI) are rolling out in stages; this policy applies to their data as soon as each feature is available. We never ask for or store Google account or WhatsApp passwords, and we don't store your payment card or bank account details. The only password stored is an email channel's mailbox password or App Password entered by a workspace admin: it is stored encrypted, never shown again, and used only to connect to that workspace's email server.

What data is used for

  • Running the service: showing conversations, sending the replies and broadcasts your team writes & schedules, and managing tickets, contacts, segments, leads & clients, the knowledge base, reports, and teams.
  • Sign-in, account security, and keeping each workspace's data separate.
  • AI features on the Pro plan, only when a member uses them.
  • Billing: creating invoices, processing payments, and sending reminders.
  • Service emails: invitations, notifications, invoices, and important account notices.
  • Fixing disruptions, preventing abuse, and keeping the service reliable.

Data is not sold, not used for advertising, and not used by us to train AI models.

The WhatsApp connection

  • Onix connects to WhatsApp using WhatsApp's linked devices feature (like WhatsApp Web), not the official WhatsApp Business API. The connector service (GOWA) runs on servers we manage ourselves.
  • WhatsApp messages are end-to-end encrypted between devices. Because Onix is one of your number's linked devices, messages are decrypted on the Onix server so your team can read them, and then stored in the Onix database.
  • Media is downloaded right away and stored privately on our servers; members open it through signed links, never public URLs.
  • Messages are sent and received over the WhatsApp network, so WhatsApp also processes them under its own terms and privacy policy.
  • WhatsApp may restrict or ban numbers that are used for spam or bulk messaging. The sending rate per number is limited. The Broadcast feature (Pro & Custom) sends messages your team writes to the contacts in a chosen segment, gradually and with safeguards (delays, rests, sending hours, daily limits); before sending, each recipient's number is checked on WhatsApp. The risk of the number being banned remains with the number owner.
  • You can disconnect Onix from your phone at any time: WhatsApp → Linked devices → select the Onix device → Log out.

The email connection

  • Onix connects to the workspace's email server (IMAP to read, SMTP to send) with the address and password or App Password entered by an admin. Onix only reads: email in the mailbox is not deleted, moved, or marked as read.
  • Email in the Inbox, folders chosen by the admin, and the Sent folder (when turned on) is copied into Onix with its attachments and original version, including older email for the period chosen when connecting. Automatic replies, bounces, and senders on the ignore list don't become conversations.
  • Replies are sent through the workspace's own email server (from the workspace's address), so its email provider (e.g. Google, Yahoo, Zoho, or a host) also processes them under its own terms and privacy policy.
  • Email HTML is sanitized and shown in an isolated frame without scripts; images from the internet aren't loaded until a member asks, so senders can't track when an email was opened.
  • Onix's access stops when the email channel is deleted in the Channels menu, or when the password/App Password is revoked at the email provider.

Livechat on websites

  • The livechat widget is installed by the workspace on its website and loaded from Onix's servers. Before chatting, visitors enter their name, email, and phone number; the intro and consent texts in the widget are set by the workspace, which is the controller of its visitors' data.
  • The widget sets no cookies. To continue a conversation, Onix's chat page stores a random session token in the visitor's browser storage (localStorage, separate per site); our servers store only a fingerprint (hash) of that token. The token expires after 90 days without activity.
  • Visitors' IP addresses are used to limit abuse (e.g. limits on starting chats) and aren't stored with visitor data.
  • Messages arrive in real time over a WebSocket to the Onix real-time server, using a token valid only for that visitor's own conversation. The team's internal notes are never sent to visitors.
  • If the workspace turns it on, replies a visitor hasn't read after closing the chat are sent to the email they entered.

API channels

  • The workspace's system sends customer messages to Onix with a channel key; team replies are sent to a webhook URL chosen by the workspace, signed with the webhook secret. Webhook receivers are outside Onix and are the workspace's responsibility.
  • Reply attachments are provided through signed links that expire after 7 days. Onix only contacts https URLs at public addresses (webhook URLs and attachment URLs).

The workspace's responsibilities

The business that owns a workspace is responsible for having a lawful basis, such as customer consent or a contractual relationship, to contact its customers on WhatsApp, by email, through livechat, or through API channels and to store their data in Onix, including data of group participants, email recipients (Cc) that comes into the inbox, website visitors using livechat, and data its own systems send through API channels. For broadcasts, the workspace must make sure recipients have agreed to receive the messages and must respect unsubscribe requests (STOP replies are recorded automatically and that contact is skipped by later broadcasts). This includes obligations under applicable law, such as Indonesia's Law Number 27 of 2022 on Personal Data Protection (UU PDP). This policy is not legal advice.

AI features (Pro plan)

When a member clicks Summarize, the relevant conversation content is sent to Sumopod to create a summary. For semantic knowledge base search, article text and search queries are sent to Sumopod to compute their vector embeddings. Only the data needed for that request is sent; passwords, API keys, and other workspace data are never sent, and internal notes are not summarized. Summaries and embeddings are stored in Onix (in your workspace) so they don't have to be created again. Onix doesn't use your data to train AI models. AI currently never sends messages to customers automatically.

Other parties that process data

  • Google for sign-in (name, email, profile photo).
  • Sumopod for AI features and knowledge base embeddings (Pro plan), forwarding requests to the language model providers available on Sumopod, and for delivering service emails over SMTP.
  • Sassly Pay (pay.sassly.ai), with Mayar as its payment provider, for invoice payments by QRIS and other methods.
  • Cloudflare as the network and security layer in front of our servers; it processes IP addresses and request data, and may compute cookie-free visit statistics.
  • The workspace's email provider (e.g. Google, Yahoo, Zoho, or a host) when an email channel is connected: email is read and sent through its servers.
  • The workspace's website & systems: the livechat widget runs on the workspace's own website, and API channels send replies to a server chosen by the workspace.
  • Server providers that host Onix, only to the extent needed to run the service.

The WhatsApp connector, the real-time server, and the Onix database run on servers we manage ourselves. Some of the providers above may process data outside Indonesia. Apart from this, data is only disclosed when required by applicable law.

Cookies & the real-time connection

  • A session cookie keeps you signed in; it ends when you sign out or close your browser.
  • A lang cookie remembers your display language, kept for 1 year.
  • While the app is open, your browser opens a WebSocket connection to the Onix real-time server (Centrifugo, self-hosted) using a short-lived token. This connection only carries notices about changes to your workspace's data; if it drops, the app falls back to periodic checks.
  • The livechat widget on a workspace's website sets no cookies; it uses browser storage on Onix's domain for the visitor's session token (see Livechat on websites).
  • There are no advertising cookies or third-party tracking cookies.

Storage & security

  • All access uses an encrypted connection (HTTPS, and WSS for the real-time connection).
  • Each workspace is separate: members can only open data of the workspaces in which they're an active member, according to the role and channel access they've been given.
  • API keys and API channel keys are stored only as hashes and shown once, when they're created; API channel webhook secrets are stored encrypted.
  • Conversation media, attachments, and original emails are stored privately, never at a public URL.
  • Email channel mailbox passwords are stored encrypted and never sent back to the browser. Email servers Onix may connect to are limited to public addresses with valid TLS certificates.
  • Important activity, such as invitations, role changes, settings, API keys, and billing, is recorded in the workspace audit log.

How long data is kept

  • Conversations and tickets are kept while the workspace is active, until the Owner deletes them or a data deletion request is made.
  • Other workspace data (contacts, leads & clients with their files and expense receipts, the knowledge base with its embeddings, settings, and members) is kept while the workspace is active, until the Owner deletes it or a data deletion request is made.
  • Raw webhook logs and the API channel webhook delivery history are deleted automatically after 30 days.
  • Livechat visitor sessions (the token and the form data in that session) are deleted after 90 days without activity; their conversations and contacts follow the conversation retention rule above.
  • When a WhatsApp number is disconnected, Onix logs out of the linked device and no longer receives messages from that number; its conversation history stays stored for the workspace until it's deleted.
  • When an email channel is deleted, Onix stops reading that mailbox and deletes its password; its conversation history stays stored for the workspace until it's deleted.
  • Invoices, payment records, and audit logs are kept as financial and security records in accordance with legal requirements.

Your rights

Under the UU PDP, you have the right to request access to, correction of, and deletion of your personal data, and to withdraw your consent. How to delete data is explained on the Data Deletion page. If you're a customer of a business that uses Onix, send your request to that business; we help them fulfil it. For other requests, contact us at [email protected].

Minors

This service is intended for businesses and users aged 18 and over, and is not intended for children.

Changes to this policy

If this policy changes, the latest version, together with its effective date, is always available on this page. Important changes are also announced by email to workspace Owners.

Contact

Questions about privacy: [email protected].