Privacy Policy

Effective from 8 October 2026. Onix is operated by sassly.ai.

This policy explains the data that Onix ("we", "the service") processes when you and your team use Onix to serve your customers: connecting channels such as WhatsApp, replying to conversations, and managing tickets, contacts, and a knowledge base. Onix is not affiliated with, endorsed by, or sponsored by WhatsApp, Meta, or Google. WhatsApp is a trademark of WhatsApp LLC (Meta Platforms, Inc.).

Our role

  • For account, workspace, and billing data, Onix is the data controller.
  • For the customer data a workspace manages (conversations, contacts, groups, tickets), the business that owns the workspace is the data controller. Onix processes that data on the business's behalf and according to its instructions, as a data processor.

Data we process

Type of dataContentsSource
User accountGoogle account ID, name, email, profile photo, preferred language, last sign-in timeGoogle, when you sign in
Workspace & teamWorkspace name, members, roles and permissions, channel access, invitations (recipient email), personal preferences such as tour statusThe Owner and members
Connected channelsWhatsApp number, display name, profile photo, about text, WhatsApp business profile if any, and connection statusWhatsApp, after the number is connected by scanning a QR code
ConversationsThe content of incoming and outgoing messages with their media (images, video, audio, documents, stickers, locations, contacts), reactions, edited or deleted messages, delivery/read status, and timesWhatsApp and team members
WhatsApp groupsFor groups the connected number belongs to: the group name, photo, and description, the participant list (number or ID and name), and messages in the groupWhatsApp
WhatsApp Business labelsLabel names and colors and which chats carry them, read one way from the WhatsApp Business appWhatsApp Business
ContactsName, WhatsApp number or ID (including privacy IDs), profile photo, about text, business profile, and details your team enters: email, company, job title, address, city, language, custom fields, labels, and notesWhatsApp and team members
Team workTickets and their discussions, internal notes, assignments, statuses, labels, reply templates, notificationsTeam members
Knowledge baseArticles and their categories, article text chunks, and the vector embeddings of those chunksTeam members; embeddings computed via Sumopod
AI (Pro)AI-generated conversation summaries and AI usage records (request and token counts)Sumopod, when members use AI features
BillingBilling name, email, mobile number, and address; invoices; payment status, method, and referenceThe Owner and Sassly Pay
Custom plan requestsName, email, company, mobile number, estimated number of WhatsApp numbers and agents, and requirementsThe person sending the request
Technical dataIP addresses and records of important activity (audit log), webhook logs, error logs, when an API key was last usedOur servers

Some of the features above (WhatsApp, contacts, tickets, knowledge base, AI) are rolling out in stages; this policy applies to their data as soon as each feature is available. We never ask for or store Google or WhatsApp passwords, and we don't store your payment card or bank account details.

What data is used for

  • Running the service: showing conversations, sending the replies your team writes, and managing tickets, contacts, the knowledge base, reports, and teams.
  • Sign-in, account security, and keeping each workspace's data separate.
  • AI features on the Pro plan, only when a member uses them.
  • Billing: creating invoices, processing payments, and sending reminders.
  • Service emails: invitations, notifications, invoices, and important account notices.
  • Fixing disruptions, preventing abuse, and keeping the service reliable.

Data is not sold, not used for advertising, and not used by us to train AI models.

The WhatsApp connection

  • Onix connects to WhatsApp using WhatsApp's linked devices feature (like WhatsApp Web), not the official WhatsApp Business API. The connector service (GOWA) runs on servers we manage ourselves.
  • WhatsApp messages are end-to-end encrypted between devices. Because Onix is one of your number's linked devices, messages are decrypted on the Onix server so your team can read them, and then stored in the Onix database.
  • Media is downloaded right away and stored privately on our servers; members open it through signed links, never public URLs.
  • Messages are sent and received over the WhatsApp network, so WhatsApp also processes them under its own terms and privacy policy.
  • WhatsApp may restrict or ban numbers that are used for spam or bulk messaging. Onix is built for replying to customers, offers no bulk-messaging ("blast") feature, and limits the sending rate per number.
  • You can disconnect Onix from your phone at any time: WhatsApp → Linked devices → select the Onix device → Log out.

The workspace's responsibilities

The business that owns a workspace is responsible for having a lawful basis, such as customer consent or a contractual relationship, to contact its customers on WhatsApp and to store their data in Onix, including data of group participants that comes into the inbox. This includes obligations under applicable law, such as Indonesia's Law Number 27 of 2022 on Personal Data Protection (UU PDP). This policy is not legal advice.

AI features (Pro plan)

When a member clicks Summarize, the relevant conversation content is sent to Sumopod to create a summary. For semantic knowledge base search, article text and search queries are sent to Sumopod to compute their vector embeddings. Only the data needed for that request is sent; passwords, API keys, and other workspace data are never sent. AI currently never sends messages to customers automatically.

Other parties that process data

  • Google for sign-in (name, email, profile photo).
  • Sumopod for AI features and knowledge base embeddings (Pro plan), forwarding requests to the language model providers available on Sumopod, and for delivering service emails over SMTP.
  • Sassly Pay (pay.sassly.ai), with Mayar as its payment provider, for invoice payments by QRIS and other methods.
  • Cloudflare as the network and security layer in front of our servers; it processes IP addresses and request data, and may compute cookie-free visit statistics.
  • Server providers that host Onix, only to the extent needed to run the service.

The WhatsApp connector, the real-time server, and the Onix database run on servers we manage ourselves. Some of the providers above may process data outside Indonesia. Apart from this, data is only disclosed when required by applicable law.

Cookies & the real-time connection

  • A session cookie keeps you signed in; it ends when you sign out or close your browser.
  • A lang cookie remembers your display language, kept for 1 year.
  • While the app is open, your browser opens a WebSocket connection to the Onix real-time server (Centrifugo, self-hosted) using a short-lived token. This connection only carries notices about changes to your workspace's data; if it drops, the app falls back to periodic checks.
  • There are no advertising cookies or third-party tracking cookies.

Storage & security

  • All access uses an encrypted connection (HTTPS, and WSS for the real-time connection).
  • Each workspace is separate: members can only open data of the workspaces in which they're an active member, according to the role and channel access they've been given.
  • API keys are stored only as hashes and shown once, when they're created.
  • Conversation media is stored privately, never at a public URL.
  • Important activity, such as invitations, role changes, settings, API keys, and billing, is recorded in the workspace audit log.

How long data is kept

  • Conversations and tickets are kept while the workspace is active, until the Owner deletes them or a data deletion request is made.
  • Other workspace data (contacts, the knowledge base with its embeddings, settings, and members) is kept while the workspace is active, until the Owner deletes it or a data deletion request is made.
  • Raw webhook logs are deleted automatically after 30 days.
  • When a WhatsApp number is disconnected, Onix logs out of the linked device and no longer receives messages from that number; its conversation history stays stored for the workspace until it's deleted.
  • Invoices, payment records, and audit logs are kept as financial and security records in accordance with legal requirements.

Your rights

Under the UU PDP, you have the right to request access to, correction of, and deletion of your personal data, and to withdraw your consent. How to delete data is explained on the Data Deletion page. If you're a customer of a business that uses Onix, send your request to that business; we help them fulfil it. For other requests, contact us at [email protected].

Minors

This service is intended for businesses and users aged 18 and over, and is not intended for children.

Changes to this policy

If this policy changes, the latest version, together with its effective date, is always available on this page. Important changes are also announced by email to workspace Owners.

Contact

Questions about privacy: [email protected].