Privacy policy
1. Who we are and our role
PatrolBot is a service of MJ Tech Solutions, South Africa ("we", "us").
- For guards, supervisors and other staff of a security company or site owner using PatrolBot, that company (your employer or the company you contract to) is the responsible party under the Protection of Personal Information Act, 2013 (POPIA). It decides why and how your information is used. We are its operator (POPIA section 21): we process the information only on its instructions, under a written agreement, and keep it secure.
- For visitors to this website and people who ask us for a demo, we are the responsible party.
2. What we collect
| About | Information |
|---|---|
| Guards | Name, WhatsApp number, optional staff and PSIRA numbers; sites you work at; shift start and end times; checkpoint check-ins (time, checkpoint and, when asked, your location at that moment or a photo); breaks and handovers; incident reports with photos; SOS alerts with your location; replies to "are you OK?" checks; your PIN in scrambled (hashed) form if you use a shared phone. |
| Supervisors, managers, control room, response teams | Name, WhatsApp number, optional email, role, the sites you cover, alerts sent to you and how you responded. |
| Everyone using PatrolBot | Your privacy decision (accepted, declined or withdrawn, and when); security records such as login attempts and blocked phones. |
| Demo requests | Name, company, email, optional phone number, number of sites and your message. |
| Website visitors | Nothing beyond standard server logs (IP address, time, page) kept briefly for security. No advertising or tracking cookies. |
What we do not do: we do not track your location continuously or in the background, read your other WhatsApp chats, or access your phone's contacts, files or gallery. A photo is only received when you send or take it for PatrolBot.
3. Why we use it (and the lawful basis)
- Running patrols and proving them to the security company and its clients: performing the employment or service contract, and the company's legitimate interest in security services that can be checked (POPIA section 11(1)(b) and (f)).
- Your safety: SOS alerts and "are you OK?" checks protect your life and health (section 11(1)(d)). This is why SOS works even before you accept the notice.
- Alerts and reports to supervisors, managers, control rooms, response teams and the company's clients.
- Detecting false or careless patrols through checks on timing, location and patterns. These checks flag patrols for a person to review; PatrolBot does not discipline anyone automatically.
- Security of the service: preventing misuse, blocking lost or stolen phones, keeping an audit trail.
- Responding to demo requests, with your consent (section 11(1)(a)).
We also ask everyone to read this notice and agree before using PatrolBot, and record that decision. You can withdraw at any time by sending WITHDRAW to PatrolBot; your supervisor is told so they can arrange another way of working.
4. Who sees it
- The security company that uses PatrolBot, and the people it chooses (supervisors see their own sites; managers see the company).
- The company's clients receive patrol reports for their own sites.
- Response teams receive SOS alerts with the site address and location.
- Our service providers, only as needed to run PatrolBot: Meta (WhatsApp Business Platform) to deliver messages, and our cloud hosting provider (Cloudflare) to run the service and store data. They are bound to protect it.
- Authorities, only when the law requires it.
We never sell personal information and never use it for advertising.
5. Where it is stored
PatrolBot runs on secure cloud servers that may be outside South Africa. We only use providers in countries or under agreements that give protection substantially similar to POPIA (section 72).
6. How long we keep it
- Patrol records, check-ins and alerts: about 12 months.
- Incident reports: 24 months.
- Longer only when needed for an open investigation, insurance claim or legal case, or when the law requires it.
- Privacy decisions and security records: as long as needed to show compliance.
- Demo requests: up to 24 months, unless you ask us to delete them sooner.
After that, information is deleted or anonymised. When a security company stops using PatrolBot, its data is returned or deleted as agreed with it.
7. How we protect it
- Encryption in transit; access only through personal, revocable tokens; each company sees only its own data.
- PINs stored only as salted hashes; one-time links for logins and evidence; limits on repeated attempts.
- Signed checkpoint tags; forwarded messages and map-picked locations rejected.
- An audit trail of changes, and the ability to block a lost or stolen phone immediately.
If there is a security compromise affecting your information, the responsible party and the Information Regulator are told as POPIA section 22 requires, and you are told when required.
8. Your rights
You may ask to see the information held about you, ask for it to be corrected or deleted, object to its use, or withdraw your agreement. Guards and staff should first contact their employer (the responsible party); we help them respond. You may also contact us directly and we will pass on the request.
You can complain to the Information Regulator: inforegulator.org.za, [email protected].
9. Contact
Information Officer, MJ Tech Solutions: [email protected]
10. Changes
When we change this policy in a way that matters, we update the version above and PatrolBot asks everyone to read and agree to the new notice.