Last updated
27/09/2026
Empire OS (Pty) Ltd (“Empire OS”, “we”, “us”) builds and runs client acquisition systems for businesses. This policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have. It covers goempireos.com, our onboarding site at onboarding.goempireos.com, and the services we provide to our clients.
1. Who we are
Empire OS (Pty) Ltd is a private company registered in South Africa with registration number 2025/974952/07. We are the responsible party for the personal information in this policy, except where section 7 explains that we act on behalf of a client.
Registered office: 180 Katherine St, Barlow Park, Sandton, Gauteng, 2148, South Africa
Information Officer: Caskey Ndaba
Email: caskey@goempireos.com
Phone: +27 64 948 8603
2. Information we collect
When you visit our websites. The pages you view, how you arrived, your device and browser type, and your approximate location. We collect this through Framer analytics, Google Analytics and the Meta Pixel, as described in section 8.
When you contact us or book a call. Your name, email address, phone number, business name and anything else you choose to tell us. Our forms and booking calendars run on GoHighLevel.
When you become a client. Your billing details (payments are processed by Whop, and we never see or store your full card number), the information you give us in our onboarding form, such as business details, team members, brand assets, advertising budget and goals, and our messages, emails and recorded calls with you.
When you connect your Meta ad account. The data described in section 5.
3. How we use it
To reply to you, book and hold calls, and send you information you asked for
To deliver our services, including building your systems, running and optimising your advertising, and reporting on results
To bill you and keep financial records
To improve our websites and measure the performance of our own advertising
To meet our legal obligations
We do not sell personal information, and we do not use it for purposes that are incompatible with the reason we collected it.
4. Who we share it with
We share personal information only with service providers that process it on our behalf and on our instructions, and only as far as they need it:
Hosting, databases and automation: Vercel, Supabase and Hostinger, which hosts our own servers
CRM, forms and booking calendars: GoHighLevel
Payments: Whop
Email, documents and file storage: Google Workspace
Team communication and project management: Slack and ClickUp
Call recording and notes: Fathom
AI processing: Anthropic and OpenAI, under business terms that do not allow them to use our data to train their models
Advertising and analytics: Meta and Google
We may also disclose information where the law requires it or to protect our legal rights. If Empire OS is sold or merged, personal information may pass to the new owner, who must keep protecting it as this policy describes.
5. Data we receive from Meta
Clients can connect their Meta ad account to Empire OS through Facebook Login for Business. You choose which business assets to share inside Meta’s own screens. With your permission we receive:
The IDs and names of the ad accounts and Facebook Pages you share with us
An access token that lets our system work with those assets
Advertising performance data for those accounts, such as spend, impressions, clicks, leads and cost per result
We use this data only to create, manage and optimise your campaigns and to report results to you. We do not sell it, use it to build advertising profiles, use it for any other client, or share it with anyone other than the service providers in section 4 that help us deliver your service. Access tokens are kept on our servers in a restricted database. They are never sent to your browser, written to logs or placed in web addresses. When our engagement ends, we stop using your Meta access and delete the stored token.
Removing access and deleting your data. You can remove Empire OS’s access at any time in your Meta Business Settings under Integrations, or in your Facebook settings under Business Integrations. To ask us to delete the data we hold from Meta, email caskey@goempireos.com with the subject “Delete my data” and the name of your business or ad account. We will delete the stored access token and the Meta data we hold within 30 days and confirm by email. Figures already included in reports we have sent you may remain in those reports as part of your client records.
6. How long we keep it
Enquiry and booking details: for as long as we are in conversation with you, and deleted sooner if you ask
Client records: for the length of our engagement, and afterwards for as long as South African tax and company law requires us to keep financial records
Meta access tokens: until you disconnect, ask us to delete them, or our engagement ends
Website analytics: according to the retention settings of the analytics providers
7. When we act for our clients
When we run advertising, forms, calls and follow-up for a client, the personal information of that client’s customers and leads belongs to the client. The client is the responsible party and we act as its operator, processing that information only on its instructions. If you are one of our clients’ leads and want to see or delete your information, please contact the business you dealt with. We will help them respond.
8. Cookies and tracking
Our websites use cookies and similar technologies from Framer, Google Analytics and the Meta Pixel to measure visits and the performance of our advertising. You can block or delete cookies in your browser settings, opt out of Google Analytics with Google’s opt-out browser add-on, and control how Meta uses this information in your Facebook ad preferences.
9. Security
We use access controls, encrypted connections and providers that encrypt stored data, and only people who need information to do their work can access it. No system is perfectly secure. If a security compromise affects your personal information, we will notify you and the Information Regulator as the law requires.
10. Transfers outside South Africa
Several of our service providers store data outside South Africa, mainly in the United States and the European Union. We use providers that are bound by data protection laws or agreements that give protection substantially similar to the Protection of Personal Information Act.
11. Your rights
You can ask us to:
Confirm whether we hold personal information about you and give you a copy
Correct or delete it
Stop using it for direct marketing
Stop other processing, where you have reasonable grounds to object