1. Introduction
Offload ("we," "our," or "us") provides a specialized business-to-business (B2B) sales order automation and workflow processing platform. The platform integrates with wholesale communication channels (such as WhatsApp Business API and Email accounts), parses unstructured messages, audits them against core enterprise resource planning (ERP) databases, and generates draft transactions.
We are committed to protecting the proprietary, operational, and personal information of our business clients ("Customers") and their respective end-customers ("End-Users"). This Privacy Policy details our practices concerning the collection, usage, processing, storage, sharing, and protection of information that is processed through our web portal, client APIs, and chat pipelines (collectively, the "Services").
By accessing or using the Services, you acknowledge that you have read, understood, and agreed to be bound by the terms of this Privacy Policy. If you do not agree with the terms outlined herein, you must immediately discontinue your use of the Services.
2. Information We Collect
As a dedicated B2B software provider, the scope of information processed by Offload is strictly limited to transaction histories, business contacts, and operational metrics. We collect the following categories of information:
A. Business Account Information
To establish, configure, and maintain your account, we collect corporate contact metadata. This includes your registered company name, corporate billing address, contact person name, professional email address, office telephone numbers, bank account and billing details, and active tax identifiers.
B. Customer Communication Streams
When you connect your WhatsApp Business API endpoint or enterprise email server to the Services, we ingest data transmitted during customer interactions, which may include raw text messages, voice notes, email bodies, sender/recipient telephone numbers and email addresses, timestamps, and files or attachments (such as PDF purchase orders, Excel spreadsheets, images of paper receipts, and quotations).
C. Operational Data
To enable automatic SKU resolution and price audits, our Services query and process product catalogs, unit-of-measure (UOM) configurations, customer-specific contract price sheets, multi-warehouse stock levels, and historical order profiles uploaded by your company.
D. Technical and Telemetry Data
We automatically collect telemetry logs from your team's use of the portal, including IP addresses, browser types, device information, operating system configurations, login timestamps, API access tokens, audit trails of who reviewed and approved specific drafts, and clickstream interactions.
3. How We Use Your Information
We use the collected information solely to deliver, secure, maintain, and optimize our B2B workflow automation services. We do not sell this data.
- Automated Workflow Processing: Analyzing messages to match unstructured requests against your ERP databases, compiling order drafts.
- ERP System Ingestion & Delivery Management: Staging sales orders in your systems and verifying stock levels and client shipping details.
- Performance Tuning & System Integrity: Detecting and preventing fraudulent activities, unauthorized API calls, and service abuse.
- Customer Support: Resolving integration errors, pipeline disruptions, and user questions.
- Legal Compliance: Complying with regulatory obligations, record-keeping demands, and corporate audit trails.
4. Artificial Intelligence Processing
Our Services utilize advanced Natural Language Processing (NLP) and Artificial Intelligence (AI) models to analyze the unstructured communications you receive.
Scope of AI Activities: The AI models read text and document attachments to extract structured transactional details (such as identifying that "5 units of item X" translates to warehouse SKU "X-005" with a specific Unit of Measure), verify prices against contract terms, draft appropriate replies, and identify missing order details (such as missing delivery addresses).
No Automated Final Decisions: The AI is designed to act strictly as an operational co-pilot. All AI-generated outputs, including draft sales orders, pricing matches, and email drafts, must be reviewed and approved by an authorized member of your staff before they are committed to your ERP or transmitted to End-Users. Users retain sole operational responsibility and judgment.
5. AI Service Providers
We utilize enterprise-grade commercial developer APIs (such as the OpenAI API and Google Cloud Vertex AI / Gemini API) to perform specific AI parsing operations.
API Safety & Foundation Models: Under the terms of our agreements with these AI providers, customer communications and uploaded business documents processed via these developer APIs are not used to train the providers' public or foundation models.
Operational Retention: Our AI API providers may store data in encrypted form for a limited time (typically up to 30 days) for the sole purpose of monitoring for abuse, troubleshooting API reliability, billing verification, and complying with legal requirements, after which it is deleted.
7. Data Security
We implement robust, enterprise-grade safety protocols to safeguard your data:
- Encryption: All data in transit is encrypted using Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocols. Data stored on our servers is protected using industry-standard AES encryption at rest.
- Access Control: We enforce strict role-based access control (RBAC) and multi-factor authentication (MFA) on all internal portals. Only authorized employees with a business need-to-know have access to database tables.
- Audit Logs & Monitoring: Continuous infrastructure monitoring, security scans, audit logging of portal activities, and regular database backups are maintained.
While we employ industry-leading safeguards, no transmission method over the Internet or digital storage structure is 100% secure, and we cannot guarantee absolute protection.
8. Data Retention
We retain your business data and communication logs only as long as necessary to fulfill the operational requirements of your active subscription.
If you terminate your account, we will delete or anonymize your customer communications and ERP-audit logs within 90 days, except where retention is required to comply with local financial audit, tax record-keeping, or legal dispute compliance.
10. Your Rights & Jurisdictional Compliance
We respect the legal rights of our Customers and their End-Users regarding their data:
- Access and Portability: You may request a structured export of the business details we hold on your account.
- Correction and Deletion: You can correct out-of-date company records or request that we delete specific contact entries, subject to business record requirements.
Global Compliance Framework: We are committed to complying with applicable data protection laws in all jurisdictions where our B2B customers are located and where we operate. This includes complying with Singapore’s Personal Data Protection Act (PDPA), the Australian Privacy Act, and other regional privacy frameworks, adapting our practices to match the statutory requirements of your region.
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect shifts in AI API terms, regulatory standards, or new feature additions. The revised policy will be posted on this page, and the "Effective Date" at the top will be updated accordingly. We encourage you to review this policy regularly.
12. Contact Information
For questions, complaints, or inquiries, please contact:
Company: Terrabyte Systems Pte. Ltd.
Attention: Data Protection Officer
Email: privacy@offload.com.sg
Website: https://offload.com.sg