OpenTRD Privacy Statement

Last Updated: August 31, 2026

About Daedalis and the OpenTRD Platform

OpenTRD (opentrd.com) is an enterprise artificial intelligence and operational data infrastructure platform developed and operated by Daedalis ("Daedalis," "Company," "we," "us," or "our").

Daedalis designs, builds, and deploys high-assurance AI agents, data unification layers, and supply chain verification systems for corporate enterprises, government bodies, and commercial networks across South Africa and international markets. Our mission is to transform fragmented operational silos into structured, self-learning, and audit-ready data environments.

In providing these services, Daedalis acts both as a data controller (or "Responsible Party" under the Protection of Personal Information Act, POPIA) and a data processor (or "Operator" under POPIA / "Data Processor" under the General Data Protection Regulation, GDPR), depending on the context of the data engagement.

What is the scope and purpose of this Privacy Statement?

This Privacy Statement explains how Daedalis collects, processes, stores, protects, and discloses personal information and operational data when you interact with the OpenTRD platform, visit opentrd.com, register for an account, or utilise our AI-driven supply chain and compliance infrastructure.

It is critical to distinguish the two operational modes governed by this Privacy Statement:

  • When opentrd acts as a responsible party / data controller: We dictate the purpose and means of processing personal data regarding our direct website visitors, prospective customers, account administrators, billing contacts, and platform usage telemetry.
  • When opentrd acts as an operator / data processor: When enterprise clients ingest their supplier, vendor, employee, or operational logistics data into OpenTRD to run AI agents, verification workflows, or compliance audits (e.g., B-BBEE, POPIA, ESG, or Scope 3 emission tracking), the enterprise client acts as the Responsible Party/Data Controller. OpenTRD processes such Customer Data strictly on behalf of and according to the legal instructions of that enterprise client.

This Statement applies to all global users, administrators, and visitors of OpenTRD. By accessing the platform, you acknowledge the data handling practices described herein.

What categories of personal and operational data do we collect?

We collect personal data directly from you, automatically through your interaction with our infrastructure, and indirectly from enterprise organisations operating on OpenTRD. We organise collected data into four distinct categories:

1. Identity, account and contact data

  • Registration and account information: Full name, corporate email address, business telephone number, job title, organisational affiliation, department, and country of operation.
  • Authentication credentials: Encrypted passwords, single sign-on (SSO) identifiers, multi-factor authentication (MFA) tokens, and account permission roles.
  • Communication records: Inquiries submitted through our forms, support ticket correspondence, feedback, and customer success interactions.

2. Operational, supplier and customer business data (processor context)

  • Supply chain records: Vendor contact details, verification documents, supplier business registration details, compliance certificates (e.g., B-BBEE affidavits, tax clearance certificates, ESG disclosure metrics), and operational audit documentation uploaded by enterprise account holders.
  • Entity identifiers: Personal details embedded within trade invoices, purchase orders, shipping manifests, and regulatory filings ingested into the OpenTRD data fusion engine.

3. Technical telemetry and AI model interaction data

  • System identifiers: IP addresses, device identifiers, browser type, operating system version, time zone settings, and language preferences.
  • Usage telemetry: API call logs, interface navigation paths, feature utilisation rates, session duration, clickstream data, error reports, and system latency metrics.
  • AI agent execution logs: Inputs, prompts, parameter configurations, and automated output logs generated during user interactions with OpenTRD AI workflow agents.

4. Billing, financial and payment metadata

  • Payment processing data: Subscription plan history, transaction IDs, invoice records, tax registration numbers (e.g., VAT numbers), and billing addresses.
  • Paystack integration: All direct payment card details (credit/debit card numbers, CVVs, expiration dates) are processed directly by our PCI-DSS compliant payment gateway partner, Paystack. OpenTRD does not receive, process, or store raw payment card credentials on our servers; we retain only anonymised payment tokens, card type, last four digits, and transaction execution statuses provided by Paystack.

How and on what legal grounds do we process your data?

We process personal data strictly in accordance with applicable legal bases established under POPIA, GDPR, and international data protection standards.

Legal grounds for processing

  • Performance of a contract: Processing required to provision, maintain, and support the OpenTRD platform pursuant to our Terms of Service or an Enterprise Master Services Agreement (MSA).
  • Legitimate interests: Processing required to secure our infrastructure, prevent fraud, optimise AI performance, and deliver enterprise-grade software capabilities.
  • Compliance with legal obligations: Processing required to fulfil statutory tax, trade compliance, anti-money laundering (AML), and regulatory disclosure mandates.
  • Consent: Where you have explicitly authorised us to process your data for specific auxiliary purposes (e.g., opt-in marketing communications).

Detailed processing purposes and AI model guarantees

Processing purpose Category of data involved Legal basis
Platform Provisioning and Management Identity, Account and Contact Data Contract Performance
Data Fusion and AI Agent Execution Operational, Supplier and Customer Data Contract Performance / Legitimate Interests
Payment Settlement and Invoicing Billing and Financial Metadata via Paystack Contract Performance / Legal Obligation
System Security, Audit and Fraud Prevention Technical Telemetry and System Identifiers Legitimate Interests / Legal Obligation
Infrastructure Optimisation and Research Anonymised and Aggregated Telemetry Legitimate Interests

Strict AI training safeguard

Daedalis maintains a strict separation between customer operational environments and foundation model training pipelines:

Zero customer data model training policy: Daedalis does not use proprietary Customer Data, confidential supplier records, or enterprise operational documents ingested into OpenTRD to train, fine-tune, or refine public, foundation, or multi-tenant AI models without the express, written consent of the enterprise client. Customer data pipelines are logically isolated within enterprise tenant boundaries.

Under what circumstances do we share or disclose your data?

Daedalis enforces a strict data minimisation and lifecycle management framework. We retain personal and operational data only for as long as necessary to fulfil the purposes outlined in this Statement, satisfy contractual obligations, enforce our agreements, or comply with statutory retention mandates.

1. [ Active Account / Subscription ]: Data processed continuously for Service Delivery

2. [ Account Cancellation / Termination ]: 30-Day Export and Grace Window

3. [ Post-Grace Period ]: Permanent Purge / Anonymisation

4. [ Statutory / Tax Audit Records ]: Retained 5-7 Years (Secure Archive)

Specific retention schedules

  • Account and identity data: Retained for the duration of your active subscription. Upon account termination, primary account details are held in a soft-deletion state for thirty (30) days to allow customer data export, after which they are permanently purged or irrevocably anonymised.
  • Customer supply chain and operational data (processor context): Deleted or returned to the enterprise account holder in accordance with the specific terms of the customer's Enterprise Agreement or Master Services Agreement (MSA), subject to a standard 30-day post-termination purge window.
  • Financial and transaction metadata: Retained for seven (7) years following payment execution to satisfy statutory accounting, corporate tax, statutory auditing, and anti-money laundering obligations under South African law (such as SARS requirements) and international financial regulations.
  • Technical telemetry and security logs: Raw infrastructure access logs and system interaction records are retained for twelve (12) months for audit, security forensics, and threat analysis before being aggregated or purged.

How do we use cookies and platform tracking technologies?

OpenTRD utilises cookies, local web storage, session tokens, and automated telemetry tracking tools to maintain platform security, preserve user configuration settings, measure system latency, and optimise user experience across opentrd.com.

Categories of tracking technologies we use

  • Strictly necessary cookies and tokens: Essential for basic platform operations, security authentication, multi-factor verification, tenant session persistence, and API gateway routing. Disabling these breaks platform functionality.
  • Performance and analytics technologies: Used to gather aggregated, non-identifying telemetry regarding API response times, feature usage density, workflow error rates, and system load. This helps Daedalis engineers detect bottlenecks and maintain platform stability.
  • Functional cookies: Remember client environment preferences (such as dashboard layout settings, language configurations, and persistent UI filters) across user sessions.

Third-party tracking and advertising stance

OpenTRD is an enterprise operational workspace. We do not deploy third-party advertising trackers, cross-site retargeting cookies, or data-broker web beacons within our core software application.

Managing cookie preferences

You can control cookie settings through your browser interface or OS security controls. Note that blocking essential authentication cookies will prevent access to paid OpenTRD workspaces and features.

How do we govern cross-border and international data transfers?

Daedalis is headquartered in South Africa, and OpenTRD primary infrastructure is hosted in enterprise-grade, geographically resilient data centers located within South African border jurisdictions and selected global cloud nodes (such as AWS and Microsoft Azure regional zones). Because enterprise supply chains operate across international boundaries, your personal or operational data may be transferred, stored, or processed outside of your home jurisdiction.

Safeguards for cross-border transfers

When we transfer personal data across international borders, Daedalis ensures compliance with applicable legal frameworks:

  • POPIA compliance (Section 72): Transfers outside South Africa occur only to countries offering an adequate level of data protection, or under binding contracts (such as Data Processing Agreements) incorporating strict Operator obligations that enforce data protection standards equivalent to POPIA.
  • GDPR compliance (Chapter V): Transfers of European Economic Area (EEA) data to third countries rely on European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs) executed between Daedalis, its sub-processors, and enterprise clients.
  • Vendor due diligence: All third-party hosting partners and sub-processors operating cross-border infrastructure undergo technical security reviews to ensure zero-trust architecture, physical site security, and strong encryption standards.

What technical and organisational security measures do we enforce?

Daedalis treats security as a core architectural imperative. OpenTRD employs defence-in-depth security mechanisms designed to protect data against unauthorised access, loss, alteration, or disclosure.

OpenTRD security layer

1. [ Data in Transit ]: TLS 1.3 Transport Layer Encryption

2. [ Data at Rest ]: AES-256 Storage Encryption and KMS Control

3. [ Access Control ]: Role-Based Access (RBAC) and Enforced Multi-Factor

4. [ Isolation ]: Strict Multi-Tenant Logical Data Segregation

  • Encryption architecture: All data transmitted between user clients and OpenTRD servers is encrypted using TLS 1.3 protocols. All sensitive Customer Data databases, and authentication stores are encrypted at rest using industry-standard AES-256 cryptographic algorithms.
  • Logical tenant isolation: Operational datasets ingested by enterprise customers are segregated within multi-tenant systems using strict logical access control boundaries. One enterprise customer cannot query, access, or view another tenant's data or AI execution contexts.
  • Access controls and authentication: Access to administrative and production infrastructure is restricted according to the Principle of Least Privilege (PoLP) and requires multi-factor authentication (MFA) alongside continuous access logging.
  • Security breach notification protocol: In the event of a confirmed security compromise or data breach affecting personal information under our control, Daedalis will notify affected account holders and relevant supervisory authorities (such as the South African Information Regulator) without unreasonable delay, in full compliance with Section 22 of POPIA and applicable international breach notification mandates.

What are your statutory rights under POPIA and global privacy laws?

Depending on your geographic location and the regulatory framework governing your engagement (such as POPIA in South Africa or GDPR in the EU), you possess specific legal rights regarding your personal information.

Summary of Data Subject Rights

  • Right to be informed: You have the right to receive clear, transparent, and easily understandable information about how we process your personal data.
  • Right of access (PAIA / POPIA / GDPR): You have the right to request confirmation of whether we hold personal information about you, along with a copy of the specific records (subject to statutory access request procedures under PAIA).
  • Right to rectification: You have the right to request the immediate correction, update, or completion of inaccurate, misleading, or outdated personal information.
  • Right to erasure ("right to be forgotten"): You may request that we delete or remove your personal data where there is no compelling legal or statutory reason for us to continue processing it.
  • Right to object / restrict processing: You have the right to object to processing based on legitimate interests, direct marketing, or automated processing, or to request that processing be temporarily restricted under specific dispute circumstances.
  • Right to data portability: Where technically feasible, you may request a copy of your personal data provided to us in a structured, commonly used, and machine-readable format for transfer to another service provider.
  • Right to withdraw consent: Where processing relies on your consent, you may withdraw your consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.

Exercising your rights

To exercise any of these rights, submit a written request to our Information Officer (morningstar@opentrd.com). To prevent unauthorised data exposure, we will require reasonable identity verification prior to fulfilling any data subject request.

How will we notify you of changes to this Statement?

Daedalis reserves the right to update or modify this Privacy Statement at any time to reflect software enhancements, emerging AI governance standards, changes in our sub-processor network, or updates to global data protection laws.

When material changes are made:

  • We will update the "Last Updated" date at the top of this Statement.
  • We will provide notice via a prominent platform banner on opentrd.com or send a direct email notification to registered account administrators prior to the changes taking effect.

We encourage users to periodically review this Statement to stay informed about how we protect corporate and personal data.