RESQ1Emergency Protection
← Home
LEGAL · POPIA COMPLIANCE

POPIA Compliance Statement

Protection of Personal Information Act 4 of 2013 · Effective June 2026

Rescue One (Pty) Ltd ("Rescue One", "we", "us") operates the ResQ1 and ResQconnect emergency-response and family-safety services. This statement explains how we process personal information in compliance with the Protection of Personal Information Act, No. 4 of 2013 ("POPIA"). Where we process personal information on behalf of an insurer or business partner, we do so as their Operatorunder a written processing agreement; where we determine the purpose and means ourselves, we act as the Responsible Party.

Information Officer

Rescue One has appointed an Information Officer who is responsible for POPIA compliance and is (or is being) registered with the Information Regulator of South Africa. Reach the Information Officer at privacy@resq1.co.za.

What we collect

To deliver the Service we process the minimum information necessary, which may include:

  • Identity & contact: name, South African ID or passport number, gender, cellphone number and email address.
  • Household & cover: relationships between principal members and dependants, plan type and subscription status.
  • Location: device GPS location — shared only when you activate a panic/SOS event, or through an approved household location request that you have consented to.
  • Emergency & safety notes: any medical, vehicle, home-security or situational details you choose to provide to assist responders.
  • Service & device data: app activation status, incident history and technical logs needed to operate and secure the platform.
We do not store banking details
Rescue One does not collect, process or store any bank account, debit-order or payment-card details. All subscription payments are handled exclusively by accredited third-party payment providers under their own PCI-DSS and POPIA obligations. We never receive, view or retain your card or bank information.

Purpose & lawful basis

We process your information to: validate eligibility and manage your subscription; receive and coordinate emergency alerts; dispatch armed-response, medical or other responders to your location; keep your household informed; and meet our legal, regulatory and insurer-partner obligations. Our lawful bases are the performance of your subscription contract, your consent (for location sharing and household features), legal obligation, and our legitimate interest in providing a safe, reliable emergency service.

The eight conditions for lawful processing

CONDITION 01· Accountability
Rescue One (Pty) Ltd, as Responsible Party, ensures the eight conditions for lawful processing under POPIA are met throughout the information lifecycle.
CONDITION 02· Processing Limitation
We process personal information lawfully, minimally, and only with a valid basis — consent, performance of your subscription contract, a legal obligation, or a legitimate interest such as dispatching emergency response.
CONDITION 03· Purpose Specification
Information is collected for the explicit, defined purpose of providing and coordinating emergency-response and family-safety services, and you are made aware of that purpose.
CONDITION 04· Further Processing Limitation
Any further processing is kept compatible with the original purpose. We do not repurpose your data for unrelated activities.
CONDITION 05· Information Quality
We take reasonable steps to keep the personal information we hold complete, accurate, current and not misleading.
CONDITION 06· Openness
We maintain documented processing activities and make this statement available so data subjects understand what we collect and why.
CONDITION 07· Security Safeguards
We protect the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures (see Security below).
CONDITION 08· Data Subject Participation
You may request confirmation of, access to, and correction or deletion of your personal information, subject to law.

Security safeguards

We apply appropriate, reasonable technical and organisational measures, including:

  • Encryption of personal information in transit (TLS) and at rest.
  • Role-based, least-privilege access with multi-factor authentication for administrative accounts.
  • Audit logging, monitoring and regular review of access to sensitive data.
  • Vetted staff bound by confidentiality/NDA and POPIA awareness training.
  • Due diligence and written operator agreements with all sub-processors and cloud providers.

Cross-border processing

Some of our infrastructure, cloud hosting and sub-processors may store or process personal information in locations outside the Republic of South Africa. Where a cross-border transfer occurs, we ensure it complies with Section 72 of POPIA: the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles of protection substantially similar to POPIA; and/or the transfer is necessary for the performance of our contract with you (or a contract concluded in your interest); and/or you have consented. We remain accountable for personal information processed on our behalf regardless of where the processing takes place.

Sharing your information

We share information only as needed to deliver the Service — for example, with control-room operators, contracted armed-response and medical partners, and emergency services, strictly to action an incident. Where we act as an Operator for an insurer or business partner, we process on their documented instructions. We do notsell or trade your personal information.

Retention

We keep personal information only for as long as necessary to provide the Service and to meet legal, regulatory, audit and legitimate-business requirements. When it is no longer required, we securely delete or de-identify it.

Breach notification

Where a security compromise affecting personal information occurs, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after establishing the extent of the compromise, in line with Section 22 of POPIA.

For insurer & business partners

We enter into written Operator agreements (Sections 20–21) that define instructions, confidentiality, security obligations and breach handling, so that partners hosting customer data with us can demonstrate their own POPIA accountability.

Your rights & complaints

You may request access to, correction or deletion of your personal information, object to processing, or withdraw consent, by emailing privacy@resq1.co.za. You also have the right to lodge a complaint with the Information Regulator:

POPIA queries? Contact privacy@resq1.co.za.

Also available
Privacy Policy
Read Privacy →