Privacy Policy — OmniPremise
Effective date: 8 September 2026 · JBNC Solutions, South Africa
This policy explains how JBNC Solutions ("JBNC", "we", "us") handles personal information in OmniPremise, our property and estate management application for Android and the web, together with its resident portal — "the Services". We are committed to compliance with South Africa's Protection of Personal Information Act, 2013 (POPIA).
This policy covers OmniPremise specifically. Other JBNC software is covered by our general privacy policy.
Who is responsible for your information
OmniPremise is business software used by managing agents, estate managers, bodies corporate and facilities teams ("Clients"). In almost every case the Client who manages your building is the responsible party for your personal information, and JBNC processes it on their behalf as an operator/processor under POPIA. Each Client's data is stored in its own isolated environment and is not visible to any other Client. For our own website visitors and business contacts, JBNC is the responsible party.
What we collect
If you are a resident — an owner or a tenant
- Identity and contact details — your name, cell number and, where you provide one, an email address. Your cell number is normally also how you sign in. Accounts are created by your managing agent; there is no public self-registration.
- Your property — the unit, section or address you are linked to, and whether you are recorded as an owner or a tenant.
- Faults you report — the description, category and location of the fault, any photographs you attach, and the progress of the work until it is signed off.
- Messages — messages you exchange with your managing agent's team through the app or over WhatsApp, which are kept on the building's record so any authorised staff member can follow the conversation.
- Utility and billing records — meter readings taken for your unit, the consumption calculated from them, and the invoices issued to you. The app records invoices and their status; it does not process payments and never handles card or banking details.
If you are a Client's staff member
- Account details — your name, your email address or cell number, and the role and permissions your administrator assigns you.
- Work records — faults and tasks assigned to you, inspections and forms you submit including any photographs, and cleaning work you confirm.
- Duty and timesheet records — when you clock on and off duty, and the timesheets calculated from that.
- Activity records — the system attributes changes to the account that made them. This protects residents and staff alike and is visible to your administrators.
Technical data
- Crash and diagnostic data — Firebase Crashlytics collects crash reports and basic device information (model, operating system version) so that we can fix faults.
- Notification tokens — a device identifier issued by Google so that push notifications can reach your device. It is used for that and nothing else, and is removed when you sign out.
The app requests no device permissions other than notifications. It does not ask for your location, your contacts, your calendar, your microphone, or access to your photo library. Choosing a photograph uses the Android system photo picker, which hands the app only the image you select.
What we do not collect
OmniPremise contains no advertising and no analytics or tracking software. We do not build advertising profiles, we do not sell personal information, and we do not share it with anyone other than the service providers listed below and the Client whose building you live in or work for.
How we use information
- Operating the Services: logging and resolving faults, assigning work, running inspections, recording duty hours, calculating utility consumption and issuing invoices on the Client's behalf.
- Sending notifications and messages about work that concerns you — a fault update, a task assignment, an invoice — by push notification, email or WhatsApp.
- Maintaining security, preventing misuse and investigating faults, through activity records and crash reporting.
- Providing support to Clients.
Who else processes your information
- Google Firebase (Google Cloud Platform) hosts the Services and provides authentication, storage, notifications and crash reporting.
- WhatsApp (Meta Platforms) — where your Client uses WhatsApp messaging, the messages you exchange travel over WhatsApp's own infrastructure and are subject to WhatsApp's terms and privacy policy in addition to this one.
- Your Client's own email provider — email from OmniPremise is sent through each Client's own mail server, from their own address, using credentials they configure. JBNC does not operate a mail service on their behalf.
Where information is stored
The Services run on Google Firebase. Database records and application services are hosted in Google's europe-west1 region (Belgium). Where personal information is transferred across borders it is protected by Google Cloud's contractual and security commitments, in line with section 72 of POPIA.
Photographs and uploaded files are stored in Google's africa-south1 region (Johannesburg) and do not leave South Africa. Fault photographs, inspection images and documents are the most sensitive material the Services hold, and they are deliberately kept in-country.
Information is encrypted in transit at all times.
How long we keep it
- Fault, task, inspection and message records are retained for as long as the Client requires them for the management of the building.
- Utility and invoicing records are financial records, and South African tax law requires them to be retained for five years.
- Duty and timesheet records are employment records and are retained by the Client for the period required by South African labour legislation.
- When a Client leaves the platform, its environment — including resident records — is removed on conclusion of the engagement.
Your rights
Under POPIA you may request access to, correction of, or deletion of your personal information. Residents should direct requests to their managing agent, who is the responsible party and can action them in the system; you may also contact us directly and we will assist or forward your request. Staff accounts and their records can be corrected or deactivated by your administrator, or by us on request.
If you believe your information has been handled unlawfully, you have the right to lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za.
Requesting deletion of your data
To ask us to delete your personal information, email info@jbncsolutions.co.za with the subject line “OmniPremise data deletion request” and include:
- your full name;
- the building, estate or managing agent you are a resident of, or work for;
- the cell number or email address on your account; and
- whether you want everything deleted, or only specific information.
We acknowledge requests within 5 working days and complete them within 30 days. Where the request concerns a resident record, the managing agent is the responsible party and we act on their instruction — we will tell you if they need to authorise it first.
What is deleted: your account and sign-in credential, your contact details, your link to a unit or property, the faults you reported and their photographs, your messages, and any inspection or form submissions attributed to you.
What we must keep: where a record must be retained by law — utility invoices and other financial records for five years under South African tax law, and employment records including duty and timesheet history for the period required by labour legislation — we remove or de-identify the personal details attached to it wherever possible and keep only what the law requires.
Your managing agent can deactivate an account at any time from inside the application, without contacting us.
Security
Access to the Services requires authentication, and every request from the app is additionally verified as coming from a genuine, unmodified installation. Within a Client's environment, access is role-based: what a caretaker, a maintenance manager and a director can each see is decided by permissions their administrator sets. Each Client's data is isolated from every other Client's by rules enforced on the server, not in the app. We maintain activity records of changes, and the database is protected by point-in-time recovery backups.
Children
The Services are business and residential management tools and are not directed at children. We do not knowingly collect personal information directly from children.
Changes to this policy
We may update this policy from time to time. The current version will always be available at this address, with its effective date shown above.
Contact
JBNC Solutions
Email: info@jbncsolutions.co.za
Website: www.jbncsolutions.co.za