Legal
Privacy policy
Effective date: 19 August 2026 · Last updated: 19 August 2026
This policy explains what personal data Oneop collects, why, who else processes it, and what you can ask us to do with it. It is written to be read, not to be survived.
Oneop does not hold any privacy or security certification. Where this policy describes a practice, it describes a practice — not an attestation by a third party. SeeSecurity for the specific technical controls that exist.
Section 1 — Who we are
ENEXXUS ("Oneop", "we", "us"), a sole proprietorship registered in Pakistan, of D2, Phase 1, Johar Town, Lahore, Pakistan, National Tax Number 3783814-8, operates the Oneop platform at oneop.io andapp.oneop.io. ENEXXUS is a sole proprietorship, which under Pakistani law is not a separate legal person from the individual who owns it. The controller of your personal data is therefore that individual, trading as ENEXXUS at the address above. The proprietor's personal name is not published on this page. If you need the controller identified by name — for a procurement check, a data protection impact assessment, or to serve a formal notice — write to legal@oneop.io or to the postal address above and we will identify them to you in writing.
Contact for any privacy question, request or complaint: privacy@oneop.io.
No representative, and no Data Protection Officer. Oneop has not appointed a representative in the European Union or the United Kingdom under GDPR Art. 27, and has not appointed a Data Protection Officer. Oneop does not carry out large-scale systematic monitoring of data subjects, and does not process special-category data on a large scale — the two conditions in Art. 37(1) that would make a DPO mandatory. That is Oneop's own reading of those thresholds, published so that you can disagree with it rather than discover it later. It is not a determination by a regulator, and Oneop will appoint both if the assessment changes.
Section 2 — The two roles Oneop plays
Is Oneop a controller or a processor?
Both, depending on whose data it is. The distinction decides which rights you exercise and against whom.
Oneop is the controller of data about the people who buy and use Oneop directly — account holders, their team members, people who contact us, and visitors tooneop.io. This policy governs that data.
Oneop is a processor of the data our customers put into the product: their contacts, leads, deal records, chat transcripts, support tickets, invoices and so on. We process that data on the customer's documented instructions, and the customer is its controller. The terms for that processing are in theData Processing Agreement.
If you are the customer of a business that uses Oneop and you want your data corrected or deleted, contact that business. They control it; we cannot act on it without their instruction. If you tell us, we will pass your request to them.
Section 3 — What we collect, and why
What personal data does Oneop hold about me as an account holder?
Only what the product needs to work, plus what the law requires us to keep.
| Category | Specific fields | Why we hold it |
|---|---|---|
| Account identity | Name, email address, username, organisation name, role, language and timezone preference | To create and operate your workspace, and to identify you when you sign in |
| Authentication | A scrypt hash of your password (never the password itself), a 24-hour email-verification token, TOTP secret if two-factor is enabled, and — if you use Google or Microsoft sign-in — that provider's stable subject identifier | To sign you in and to keep other people out |
| Session | A signed session cookie identifier, and the timestamps of session activity | To keep you signed in |
| Billing | Plan, subscription state, seat count, and the customer/subscription identifiers held at our payment processor | To bill you and to apply your plan entitlements |
| Support correspondence | Anything you send us by email or through the product | To answer you |
| AI usage records | Which type of AI action ran, when, for which workspace, and the credits it consumed | To meter your AI usage against your plan and show you your balance |
| Security events | Sign-ins, changes to two-factor settings, data exports and erasure requests | To let you and us see who did what to your account |
We do not collect special-category data (health, biometrics, political opinions, religious beliefs, trade union membership, sexual orientation) about account holders, and the product asks for none of it.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
This website uses Google Analytics 4 (measurement IDG-66QW28D4BL) to count visits and see which pages people read. It is the only third-party script on this site: no advertising tag, no tag manager, no session recorder, and no advertising features, audience sharing or Google Signals are enabled on the property. Google Analytics sets first-party cookies in your browser and receives your IP address, which Google discards after using it to derive an approximate location; it also receives the page you are on, the page that referred you, and coarse device and browser information. It runs on this marketing site only — app.oneop.io, the product itself, carries no analytics script, so nothing you do inside your workspace is measured this way.
It loads on every page as soon as the page does. We are telling you rather than asking you, and you can refuse it: any browser tracking-protection or ad-blocking extension, or Google's ownopt-out add-on, stops it, and nothing on this site depends on it working. Everything else the site loads still comes from oneop.io itself: the content security policy names Google Analytics explicitly and permits no other off-origin script, and the build refuses to publish a page that loads one. See §9.
Section 4 — The lawful bases we rely on
These are the bases Oneop relies on, and Oneop's own analysis of them. They are set out so you can check the reasoning rather than take it on trust — not because a regulator has approved them.
- Performance of a contract (GDPR Art. 6(1)(b)) — creating and running your workspace, authenticating you, billing you, and providing support.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse, metering AI usage, and improving the product. We consider these interests balanced against your rights because the data involved is operational rather than intrusive and is not used to profile you.
- Legal obligation (Art. 6(1)(c)) — keeping financial records for the period tax law requires.
- Consent (Art. 6(1)(a)) — marketing email, which you may withdraw at any time, and any non-essential cookie if one is ever introduced.
Section 5 — Who else processes your data
Does anyone outside Oneop see my data?
Yes, and they are all named. Oneop uses a small set of subprocessors for infrastructure, email, payments and AI. The complete, dated list — what each one does and what data reaches it — is published at /trust/subprocessors.
Two facts worth stating here rather than burying:
AI processing. Google Gemini is the only model provider Oneop uses. When an AI feature runs, the relevant prompt content is sent to Google's Generative Language API. Before it leaves, every prompt passes through a redaction step that strips detected personal identifiers, and an injection-detection step that blocks the call outright on a detected attack pattern. Both run on every call, on every plan, and cannot be turned off.
Integrations you connect yourself. If you connect HubSpot, WooCommerce, WordPress, a mailbox, Apollo.io, a shipping carrier, an e-signature provider or a bank feed, data flows to that provider because you instructed it to. Those are your processors, under your agreement with them, using credentials you supply. Oneop encrypts those credentials with AES-256-GCM before storing them.
We do not otherwise disclose personal data, except where we are legally compelled to, or to a buyer as part of a merger or acquisition — in which case this policy travels with the data.
Section 6 — Where your data is held, and international transfers
Oneop's application and its database are hosted by Hetzner Online GmbH, in Germany. Both run on the same server; there is no separate database provider. Files and attachments you upload are held in Cloudflare R2 object storage, in a bucket created in Cloudflare's European Union jurisdiction. So the data you put into Oneop sits in the EU.
Several subprocessors are nevertheless based in the United States — the payment, transactional email, AI and sign-in providers named on thesubprocessor register. Personal data therefore reaches the United States when one of those services is used, and the register says which data reaches which of them.
Those onward transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), and on the UK International Data Transfer Addendum where the transfer originates in the United Kingdom — in each case as they are incorporated into that provider's own published data processing addendum and accepted as part of Oneop's contract with the provider. They are incorporated by reference, not negotiated bespoke, and Oneop relies on no adequacy decision. Thesubprocessor register names every provider, so you can read the addendum being relied on instead of taking this paragraph's word for it.
Oneop does not offer region selection. Germany and the EU are where the platform runs, not a choice you can make per workspace, and Oneop cannot host your workspace in a different country on request.
Section 7 — How long we keep it
| Data | Retention |
|---|---|
| Workspace content while your account is active | For as long as the account is active |
| Workspace content after you close your account | Deleted or anonymised within 30 days of closure, on request to privacy@oneop.io. This is a manual process today, not an automated job |
| Financial and billing records | 6 years, as required by tax law in Pakistan (Income Tax Ordinance 2001, s.174) |
| In-app notifications | Purged automatically after 90 days |
| Internal operator audit records | Retained for at least one year; the current default retention is approximately seven years, and no record is deleted before an onward audit stream has confirmed receipt |
| Backups | No public commitment. Oneop does not publish a backup frequency, a backup retention window or a recovery time, and does not want you to rely on one. Keep your own copy of anything you cannot afford to lose |
Section 8 — Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict our processing, receive it in a portable format, and withdraw consent you previously gave. You also have the right to complain to a supervisory authority.
How to exercise them. Email privacy@oneop.io. We will respond within 30 days.
What the product can already do. Account owners can export the workspace's contacts, conversations, tickets and deals from within the application, and can request erasure of a person by email address, which anonymises their contact and user records. This tooling does not cover every table in the product — for anything outside those four record types, email us and we will handle it manually.
A note on wording. Oneop ships GDPR data-export and erasure tooling. Oneop does not describe itself as "GDPR compliant", because compliance is a determination made by a regulator about an organisation, not a feature a vendor can sell you.
Where to complain. Oneop is established in Pakistan, which has no data protection supervisory authority — the Personal Data Protection Bill has not been enacted, so there is no Pakistani regulator to receive a complaint. If you are in the EEA or the United Kingdom, GDPR Art. 77 lets you complain to the supervisory authority in the country where you live, where you work, or where you believe the infringement took place — the Information Commissioner's Office, for instance, if you are in the UK. You do not have to come to us first, though we would rather you did.
Section 9 — Cookies and the website
oneop.io is a statically generated site. It sets onecategory of non-essential cookie: the Google Analytics 4 cookies described in §3 (_ga, and a _ga_66QW28D4BL cookie carrying the session state — both names read out of a real browser, not copied from Google's docs). They are first-party, they hold a randomly generated identifier rather than anything you have told us, and Google's default retention applies — two years for_ga. They exist to count visitors and pages, and for nothing else.
These cookies are set when the page loads; this site does not currently ask you first. That is a deliberate choice and we state it plainly rather than implying consent you did not give. If you do not want them, block them — see the opt-out routes in §3 — and the site works exactly as it did before. It sets no advertising cookie, runs no advertising or session-recording script, and no data collected here is used to target advertising at you anywhere.
app.oneop.io — the product — sets one essential cookie: a signed session identifier that keeps you logged in. It is strictly necessary for the service to function and cannot be turned off while you are signed in. The application also stores your theme, language and interface preferences in your browser's local storage; that data never leaves your device.
Section 10 — Security
The technical controls behind this policy are described specifically, control by control, atSecurity — including the controls Oneop does nothave. In summary: passwords are hashed with scrypt; stored third-party credentials are encrypted with AES-256-GCM; the customer app, the internal operator console and the client portal are three separate session principals with three distinct signing secrets; inbound webhooks fail closed on an unverified signature; and internal staff access to a customer account is time-boxed, revocable, logged and blocked from destructive actions.
Oneop holds no SOC 2, ISO 27001, PCI DSS or HIPAA certification, publishes no uptime SLA, and has not commissioned a third-party penetration test.
Section 11 — Children
Oneop is a business product and is not directed at children. We do not knowingly collect personal data from anyone under16 — or the lower age your own country has set under GDPR Art. 8(1), which several EU member states have set at 13. Under the US Children's Online Privacy Protection Act the threshold is 13. If you believe we have, email privacy@oneop.io and we will delete it.
Section 12 — Changes to this policy
We will update this page when our practices change and will revise the "Last updated" date at the top. If a change materially affects how we handle your personal data, we will email account owners before it takes effect.
Section 13 — Contact
Privacy questions, requests and complaints: privacy@oneop.io
Security issues: security@oneop.io — see Security
Everything else: Contact
Links out
Data processing agreementSubprocessorsSecurityTerms of serviceContact
No CTA banner on this page — a legal page ending in a sales banner reads badly and helps nothing.