TACTICAL COMMAND/PRIVACY

PRIVACY POLICY

Last Updated: May 2026 ยท POPIA Compliant

1. Introduction

Smart Guard ("we", "us", "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA") of the Republic of South Africa. This policy explains what personal information we collect, why we collect it, how it is stored, and your rights as a data subject.

2. Information We Collect

Smart Guard collects information necessary to provide security management services:

  • Identification information (full name, ID number, PSIRA number, contact details)
  • Employment information (employer, site assignment, shift schedule, banking details for payroll)
  • Biometric data (facial recognition data for attendance verification)
  • Location data (GPS coordinates during active shifts for patrol verification and safety)
  • Photographs (clock-in/out photos, incident evidence, checkpoint verification)
  • Voice recordings (panic button audio, dictated incident reports)
  • Device information (device ID, app version, IP address)
  • Activity logs (incident reports, observation book entries, patrol records, communications)

Some of the above qualifies as special personal information under POPIA Section 26 (biometric data) and requires your explicit consent before processing.

3. Lawful Basis for Processing

We process your personal information on one or more of the following lawful bases:

  • Consent: for biometric data, location tracking, and photographs (captured at first sign-in and revocable at any time)
  • Employment contract: for processing required to fulfil your employment as a security officer
  • Legal obligation: for records required by PSIRA, SARS, BCEA, and labour law
  • Legitimate interest: for security operations, safety alerts, and fraud prevention

4. How We Use Your Information

  • Verify guard attendance and patrol completion
  • Enable real-time location tracking during shifts for officer safety and dispatch
  • Facilitate communication between guards, supervisors, and control room
  • Generate operational reports for security companies and their clients
  • Process payroll, statutory deductions (PAYE, UIF, SDL), and EFT payments
  • Respond to panic alerts and dispatch emergency response
  • Maintain audit trails for compliance and incident investigation

5. Third-Party Operators

We use the following operators (third-party service providers) to process personal information on our behalf, under written agreements that comply with POPIA Section 21:

  • Supabase Inc. โ€” database hosting and authentication (servers located in the European Union)
  • Vercel Inc. โ€” web application hosting
  • Expo Inc. โ€” push notification delivery for the mobile app
  • Twilio Inc. โ€” SMS and WhatsApp notifications (where used)
  • Google LLC โ€” AI services (Gemini) for report enhancement and OCR
  • OpenAI and/or Anthropic โ€” AI text enhancement (where enabled)

6. Cross-Border Data Transfer

Personal information is stored on servers operated by Supabase Inc. in the European Union (Stockholm, Sweden). The EU has been recognised as having data protection laws (GDPR) substantially similar to POPIA. By using Smart Guard, you consent to the transfer of your personal information outside of the Republic of South Africa for the purposes set out in this policy, as permitted by POPIA Section 72.

7. Data Retention

We retain your information for the following periods, after which records are automatically deleted or anonymised:

  • Real-time location data: 48 hours
  • Patrol records, observation book entries: 3 years
  • Attendance & shift records: 5 years (BCEA requirement)
  • Payroll & financial records: 5 years (SARS requirement)
  • Incident reports & panic alerts: 5 years
  • Security event logs: 2 years
  • Notification & error logs: 90 days
  • Biometric reference data: deleted within 30 days of termination of employment, unless required for an ongoing investigation

8. Data Security

We implement technical and organisational safeguards including encryption in transit (TLS) and at rest, row-level security on all database records, account lockout after repeated failed login attempts, audit logging of sensitive operations, restricted CORS, signed webhooks, and bcrypt password hashing. Despite these measures, no system is completely secure. In the event of a data breach involving your information, we will notify you and the Information Regulator as soon as reasonably possible, as required by POPIA Section 22.

9. Your Rights as a Data Subject

Under POPIA you have the right to:

  • Be notified that your personal information is being collected
  • Request access to the personal information we hold about you
  • Request correction or deletion of inaccurate or outdated information
  • Object to the processing of your personal information
  • Withdraw consent previously given (for biometric data, location tracking, etc.)
  • Lodge a complaint with the Information Regulator of South Africa

To exercise these rights, contact our Information Officer (details below). We will respond within 30 days. There is no charge for reasonable requests.

10. Information Officer

Our designated Information Officer (registered with the Information Regulator of South Africa) is:

Name: [TO BE COMPLETED]
Email: privacy@smartguarddesk.com
Phone: [TO BE COMPLETED]

11. Information Regulator

If you believe your rights have been infringed, you may contact the Information Regulator:

Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za
Website: inforegulator.org.za

12. Changes to This Policy

We may update this policy from time to time. Material changes will be notified to you via the app or by email. Continued use of Smart Guard after such changes constitutes acceptance of the updated policy.