POPIA Compliance Statement
Rescue One (Pty) Ltd ("Rescue One", "we", "us") operates the ResQ1 and ResQconnect emergency-response and family-safety services. This statement explains how we process personal information in compliance with the Protection of Personal Information Act, No. 4 of 2013 ("POPIA"). Where we process personal information on behalf of an insurer or business partner, we do so as their Operatorunder a written processing agreement; where we determine the purpose and means ourselves, we act as the Responsible Party.
Information Officer
Rescue One has appointed an Information Officer who is responsible for POPIA compliance and is (or is being) registered with the Information Regulator of South Africa. Reach the Information Officer at privacy@resq1.co.za.
What we collect
To deliver the Service we process the minimum information necessary, which may include:
- Identity & contact: name, South African ID or passport number, gender, cellphone number and email address.
- Household & cover: relationships between principal members and dependants, plan type and subscription status.
- Location: device GPS location — shared only when you activate a panic/SOS event, or through an approved household location request that you have consented to.
- Emergency & safety notes: any medical, vehicle, home-security or situational details you choose to provide to assist responders.
- Service & device data: app activation status, incident history and technical logs needed to operate and secure the platform.
Purpose & lawful basis
We process your information to: validate eligibility and manage your subscription; receive and coordinate emergency alerts; dispatch armed-response, medical or other responders to your location; keep your household informed; and meet our legal, regulatory and insurer-partner obligations. Our lawful bases are the performance of your subscription contract, your consent (for location sharing and household features), legal obligation, and our legitimate interest in providing a safe, reliable emergency service.
The eight conditions for lawful processing
Security safeguards
We apply appropriate, reasonable technical and organisational measures, including:
- Encryption of personal information in transit (TLS) and at rest.
- Role-based, least-privilege access with multi-factor authentication for administrative accounts.
- Audit logging, monitoring and regular review of access to sensitive data.
- Vetted staff bound by confidentiality/NDA and POPIA awareness training.
- Due diligence and written operator agreements with all sub-processors and cloud providers.
Cross-border processing
Some of our infrastructure, cloud hosting and sub-processors may store or process personal information in locations outside the Republic of South Africa. Where a cross-border transfer occurs, we ensure it complies with Section 72 of POPIA: the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles of protection substantially similar to POPIA; and/or the transfer is necessary for the performance of our contract with you (or a contract concluded in your interest); and/or you have consented. We remain accountable for personal information processed on our behalf regardless of where the processing takes place.
Sharing your information
We share information only as needed to deliver the Service — for example, with control-room operators, contracted armed-response and medical partners, and emergency services, strictly to action an incident. Where we act as an Operator for an insurer or business partner, we process on their documented instructions. We do notsell or trade your personal information.
Retention
We keep personal information only for as long as necessary to provide the Service and to meet legal, regulatory, audit and legitimate-business requirements. When it is no longer required, we securely delete or de-identify it.
Breach notification
Where a security compromise affecting personal information occurs, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after establishing the extent of the compromise, in line with Section 22 of POPIA.
For insurer & business partners
We enter into written Operator agreements (Sections 20–21) that define instructions, confidentiality, security obligations and breach handling, so that partners hosting customer data with us can demonstrate their own POPIA accountability.
Your rights & complaints
You may request access to, correction or deletion of your personal information, object to processing, or withdraw consent, by emailing privacy@resq1.co.za. You also have the right to lodge a complaint with the Information Regulator:
- Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
- Complaints: POPIAComplaints@inforegulator.org.za
- Enquiries: enquiries@inforegulator.org.za
POPIA queries? Contact privacy@resq1.co.za.