1. Who we are
Potrasy (“Potrasy”, “we”, “us”) provides security guard management software to security companies. This policy applies to our website at potrasy.app, our web and desktop applications and the Potrasy mobile apps (together, the “Service”).
We process personal information in line with the Protection of Personal Information Act, 4 of 2013 (“POPIA”). See our POPIA page for our Information Officer’s details.
2. Our role: responsible party and operator
On our website and for our own customers’ accounts, Potrasy is the responsible party: we decide why and how that information is processed.
Inside the Service, the security company that uses Potrasy (our “Customer”) is the responsible party for the information it captures about its guards, clients and sites. Potrasy acts as an operator and processes that information only on the Customer’s instructions and under our agreement with them. If you are a guard or a client of one of our Customers, please contact that company first about your information.
3. Information we collect
Information you give us
- Demo, contact and trial forms: name, company, work email, phone or WhatsApp number, number of guards and sites, and your message.
- Account information: name, email address, company details, password (stored securely hashed) and two-factor sign-in settings.
- Billing information: billing contact and invoice details. Card payments are handled by our payment provider; we do not store full card numbers.
- Communications: messages you send us through email, chat, WhatsApp or social media.
Information captured when the Service is used
Customers and their users may capture the following through the Service:
- Guard and staff records: names, contact details, roles, skills, licences, schedules, pay rates and payroll information.
- Location data: GPS location at clock-in and clock-out, and during a shift for live tracking, patrols, geofencing and panic alerts. Location is collected only while the guard is on duty and signed in.
- Camera and photos: photos attached to incident reports and site tours, when the user chooses to take or upload them.
- NFC and QR scans: checkpoint scans during patrols and site tours.
- Operational records: attendance, patrols, incidents, dispatch activity, visitor and vehicle logs, invoices and reports.
- Messages: conversations from connected channels (WhatsApp, Messenger, Instagram, Gmail and Outlook) that a Customer chooses to connect.
Mobile device permissions (location, camera, notifications) can be managed in your device settings. Turning a permission off may stop related features from working.
Information collected automatically
- Usage and device data: IP address, browser and device type, pages visited, referring pages and the date and time of your visit.
- Cookies and similar technologies: see our Cookie Policy. Non-essential cookies are used only with your consent.
4. How we use information
- To provide, maintain and secure the Service.
- To respond to demo requests, enquiries and support tickets.
- To manage accounts, billing and subscriptions.
- To detect and prevent fraud, misuse and security incidents.
- To improve the website and the Service, using aggregated or de-identified data where possible.
- To send service notices and, where you have agreed or where the law allows, product updates. You can unsubscribe at any time.
- To meet legal, tax and regulatory obligations.
We process personal information on the grounds POPIA allows, including performing a contract, our legitimate interests, compliance with the law and, where required, your consent.
5. Sharing information
We do not sell personal information. We share it only:
- With service providers who help us run the Service, such as hosting, email delivery, payment processing and analytics, under written agreements that require them to protect it.
- With integrations a Customer chooses to connect, such as QuickBooks or messaging channels.
- When required by law, court order or a lawful request from a public authority.
- As part of a merger, acquisition or sale of assets, with the information remaining protected under this policy.
6. Cross-border transfers
Some of our service providers may store or process information outside South Africa. Where this happens, we make sure the transfer complies with section 72 of POPIA, for example by using providers bound by agreements that offer adequate protection.
7. How we protect information
We use reasonable technical and organisational measures to protect personal information, including encryption in transit (HTTPS), hashed passwords, two-factor sign-in, role-based access controls and access limited to staff who need it. No system is completely secure; if a security compromise affects your personal information, we will notify the Information Regulator and affected parties as POPIA requires.
8. How long we keep information
We keep personal information only as long as needed for the purposes above, or as required by law. Customer data is kept for the duration of the subscription and deleted or returned after the account ends, in line with our agreement with the Customer.
9. Your rights
Under POPIA you may:
- Ask whether we hold personal information about you and request access to it.
- Ask us to correct, update or delete it.
- Object to processing, including for direct marketing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
To exercise these rights, contact us. If your information was captured by a Potrasy Customer, we will refer your request to them.
10. Children
The Service is intended for businesses and is not directed at children under 18. We do not knowingly collect children’s personal information.
11. Changes to this policy
We may update this policy from time to time. We will post the new version on this page with a new “Last updated” date and, for significant changes, notify account holders by email or in the app.
12. Contact us
Questions about this policy? Contact us or see our POPIA page. Please also read our Terms of Service and Cookie Policy.