1. Regulatory Framework & Roles Under POPIA
This Privacy Policy outlines how ProSecure OS processes personal information in compliance with the Protection of Personal Information Act No. 4 of 2013 ("POPIA"):
- Subscriber as Responsible Party: The security firm or agency subscribing to ProSecure OS is the "Responsible Party" who determines the purpose and means of collecting guard identity documents, biometric facial data, and client site records.
- ProSecure Platform Provider as Operator: The Platform Provider acts solely as an "Operator" processing data on the lawful instructions and automated operational triggers configured by the Subscriber.
2. Categories of Information Processed
To enable security operations management, shift verification, and BCEA payroll calculations, ProSecure processes:
- Officer & Personnel Records: Full legal names, South African national ID numbers, PSIRA registration certificate numbers, expiration dates, grade classifications (A through E), and mobile phone contact numbers;
- Biometric Facial Telemetry: High-dimensional facial match descriptor vectors and verification confidence scores, captured strictly during shift clock-in and clock-out to eliminate fraudulent attendance and "buddy clocking";
- Geolocation & Checkpoint Telemetry: Device GPS coordinates (latitude, longitude) captured strictly during active shift clock-in/out events and QR/RFID checkpoint patrol scans to confirm guard presence within verified facility geofences;
- Employment & Remuneration Telemetry: Hourly wage rates, clocked shift hours, statutory night shift allowances, attendance records, and itemized disciplinary penalty deductions.
3. Purpose of Processing
All personal and biometric data is processed strictly for legitimate operational purposes:
- Authenticating guard physical presence on post and verifying shift clocking integrity;
- Tracking compliance with the Private Security Industry Regulation Act (PSiRA) and Sectoral Determination 6;
- Verifying guard deployment within designated client site perimeter geofences using Haversine distance calculations;
- Calculating accurate BCEA-compliant payroll remuneration and auditing disciplinary penalties.
4. Subscriber Warranties & Guard Consent Obligations
The Subscriber warrants and covenants that:
- It has informed all registered security officers and obtained their explicit, written consent to capture and process their biometric facial data and mobile GPS coordinates during active shifts;
- It maintains lawful authority to store and manage client facility addresses and contact details on the platform;
- It will immediately notify the Platform Provider in the event of any security officer revocation of consent or data subject access request.
5. Local South African Data Sovereignty
All database records, biometric mathematical descriptors, shift clock logs, and patrol telemetry are hosted and stored exclusively within enterprise ISO-27001 certified data centers located in Johannesburg and Cape Town, South Africa. Zero guard personal information is transferred or exported outside South African territorial borders.
6. POPIA Rights: Pre-Deletion Data Portability & Right to Erasure
In full compliance with Sections 14 and 24 of POPIA, ProSecure OS provides automated data governance tools directly in the system settings:
- Right to Data Portability (POPIA Section 14): Subscribers may at any time download a comprehensive operational archive containing all 18 sharded database tables in standardized JSON/CSV formats before account closure.
- Right to Erasure / Cascading Shard Deletion (POPIA Section 24): When an account owner executes permanent account deletion, the system automatically drops and purges all 18 sharded operational data tables prefixed with
biz_{clientId}across the database architecture.
7. Enterprise Security Safeguards
We maintain strict administrative, technical, and physical safeguards to protect personal information:
- Data Encryption: AES-256 encryption at rest for all operational shards and TLS 1.3 encryption in transit for all web and mobile API requests;
- Multi-Tenant Functional Sharding: Each subscriber operates on dynamically provisioned isolated operational tables (
biz_{clientId}), preventing cross-agency data leakage; - Role-Based Access Control (RBAC): Granular permissions restricting officer access according to administrative roles (Super Admin, Operations Manager, Shift Supervisor, Control Officer).
8. Information Officer Contact & Regulatory Inquiries
For questions regarding this policy or to exercise POPIA statutory rights, contact the ProSecure Information Officer at privacy@prosecure.co.za. If you are dissatisfied with our response, you retain the right to lodge a complaint with the Information Regulator of South Africa (complaints.IR@justice.gov.za).