Privacy Policy
In short
ONEP runs on your own hardware. ONEP 1.0.0 has no telemetry and does not automatically send data to AITDAAL. The ONEP website uses Cloudflare for website delivery and security. Paddle processes payments when you purchase a license. We process personal data when you contact us, join our mailing list, purchase a license, or voluntarily submit a support report.
Some ONEP features connect to external services when you choose to use them. This policy explains what information is involved and why.
Who is responsible
AITDAAL, the seller identified in the ONEP Terms and Conditions, is responsible for the personal data processing described in this policy.
For privacy questions or requests, contact:
Email: hello@onep.io
What we collect
Contacting us
When you email us, we process your email address and the information you include so that we can respond to your inquiry.
Mailing list
When you join our mailing list through the ONEP website or email us to request inclusion, we process your email address to tell you when ONEP Pro is available and, if you ask, about the Community release.
We do not use your address for unrelated marketing. You can request removal by contacting hello@onep.io.
Website visits
The ONEP website uses Cloudflare to deliver and protect the website. In providing these services, Cloudflare may process technical information such as IP addresses, request details, and security-related data.
The information processed and its retention depend on the services and configuration in use. Cloudflare's own privacy information is available through its official website.
Our website does not use analytics or advertising trackers. Interface preferences, such as your chosen color theme, may be stored locally in your browser. The documentation sidebar may also remember which sections you have opened during your visit.
When checkout is on, the Buy page loads Paddle's checkout script, so opening that page connects to Paddle before any purchase.
Our website infrastructure may also process standard server logs necessary to deliver, maintain, and protect the website.
When you use the join form, your IP address is part of a rate-limit counter that our hosting provider keeps for up to two hours.
Purchasing a license
Paddle acts as our merchant of record and processes payment and billing information for license purchases.
Paddle may collect payment details, billing addresses, and tax information. We receive the information needed to issue and manage your license, which may include your name or company, email address, country, order details, and installation ID.
The checkout process may also transmit the installation ID you provide and a record of your purchase consent, including its version and timestamp.
Paddle handles payment processing, invoices, applicable taxes, and relevant payment-related matters. We do not receive your full payment card number.
Support reports
When you submit a problem report or voluntarily send us a saved support bundle, we process the information you provide. This may include your description of the issue, the page you were using, your name and email address, screenshots, and relevant logs.
Where support bundles contain logs, credential-shaped fields may be removed by the filtering process. This filtering cannot guarantee that every sensitive value will be identified.
Support bundles are encrypted using AES-256-GCM. Access to the encrypted contents is restricted to authorized ONEP support personnel.
ONEP does not automatically send support reports to AITDAAL.
AI topology builder
The AI topology builder sends your description to the AI endpoint you configure.
Depending on your configuration, this may be a model running on your own network or an external AI service. If you use an external provider, that provider may process your input under its own terms and privacy policy.
The AI request is sent to your configured endpoint, not to AITDAAL.
What the appliance sends
ONEP 1.0.0 has no telemetry and does not automatically transmit data to AITDAAL. Its license is validated locally against the signed license file.
ONEP may make outbound connections when you explicitly use features that require them, including:
- Downloading software or images from external sources.
- Building Content Hub environments that fetch materials from their original project sources.
- Pulling container images from registries.
- Sending requests to the AI endpoint you configure.
The underlying operating system may also connect to configured DNS resolvers, time synchronization services, and software update repositories.
These connections are separate from telemetry to AITDAAL. External services may process connection information according to their own practices.
Future license check-in
License check-in is not active in ONEP 1.0.0.
If introduced in a future release, the intended design is to document the feature and its data processing before activation. The proposed information includes the license ID and signature, installation ID, product version and edition, timestamp, and one-way hashes of selected hardware identifiers.
Raw hardware identifiers are not intended to leave the appliance. The final implementation and this policy will be reviewed and updated before the feature is activated.
Why we process personal data
Depending on the circumstances, we process personal data for the following purposes:
- Responding to inquiries and providing support: to respond to requests and resolve reported issues.
- Mailing list notifications: to tell you when ONEP Pro is available and, if you ask, about the Community release.
- License purchases: to fulfill purchases, issue licenses, manage orders, and meet applicable accounting and tax obligations.
- Website operation and security: to deliver the website, prevent abuse, and maintain service security.
- Legal compliance: to meet applicable legal obligations and establish, exercise, or defend legal claims where necessary.
Depending on the purpose, the legal basis may be performance of a contract, steps taken at your request before entering into a contract, compliance with a legal obligation, consent, or our legitimate interests. Where we rely on legitimate interests, those interests must be balanced against your rights and freedoms.
Who receives personal data
We share personal data only where necessary for the purposes described in this policy, to fulfill a transaction, to provide a requested service, or to meet legal obligations.
Relevant service providers include:
- Cloudflare, for website delivery and security.
- Paddle, for license purchases and payment processing.
- AI providers, when you configure and use an external AI endpoint.
- Website infrastructure providers, where they process information required to operate and protect the website.
Service providers may process data on our behalf or independently under their own terms, depending on their role.
Personal data may be processed in countries outside your country of residence. Where applicable, international transfers are subject to the safeguards required by data protection law.
How long we retain personal data
We retain personal data only for as long as necessary for the purpose for which it was collected, including applicable contractual, accounting, tax, and legal requirements.
In general:
- Inquiries and support correspondence are retained for as long as needed to respond, resolve the issue, and maintain necessary records.
- Mailing list addresses are retained until you request removal or the notification purpose ends.
- Purchase and accounting records are retained for the periods required by applicable law.
- Website and security logs are retained according to the relevant service provider's configuration and retention practices.
Retention may vary according to the type of information, legal requirements, and whether information is needed to resolve a dispute or protect the service.
Your rights
Depending on applicable data protection law, you may have the right to request access to, correction of, or deletion of your personal data, restrict or object to certain processing, and request a copy of certain information.
To exercise these rights, email hello@onep.io. We will review your request and respond within the timeframe required by applicable law. We may need to verify your identity before acting on a request.
Some information may need to be retained to meet legal obligations or establish, exercise, or defend legal claims.
You may also lodge a complaint with your local data protection authority.
Security
We take reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, and disclosure.
No method of transmission or storage can be guaranteed to be completely secure.
Children
ONEP is intended for business, educational, and hobby use. We do not knowingly collect children's personal data where consent is required by law.
Changes to this policy
We may update this policy when our product, services, or data processing practices change. The latest version will be published on this page with its revision date.
Contact
For privacy questions, data requests, or other matters relating to this policy, contact:
Email: hello@onep.io
Website: https://onep.io