Privacy Policy
Guardcell Remote Access ("the App") is an operator-facing application used by authorised personnel of security companies to issue and dispatch access codes to Guardcell handheld remotes and access-control hardware. This Privacy Policy explains what personal information the App collects, how and why it is processed, and how it is protected, and it is written to meet the disclosure obligations of South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA"), as well as the equivalent requirements of other jurisdictions in which the App may be used. The App is provided for use by staff of organisations that have been enrolled as Guardcell tenants. It is not intended for use by the general public.
For the purposes of POPIA, Guardcell CC is the Responsible Party for personal information processed through the App. Where your employer (a Guardcell tenant) determines how its own operators, customers, and access data are used within the App, your employer may itself act as a responsible party (or joint responsible party) for that organisational data, with Guardcell acting as an operator on its behalf in terms of section 20 of POPIA.
1. Information We Collect
| Category | What is collected | Why |
|---|---|---|
| Account & enrolment data | Tenant ID, enrolment token, device ID, service token, company/customer name, encrypted company-token envelope | To authenticate the device against your organisation's Guardcell/Guardova backend and associate activity with the correct company |
| Access & audit log data | Access codes entered or dispatched, area codes, expiry/attempt settings, timestamps, customer number, and the operator action taken (code sent, remote configured, supervisor toggled, etc.) | To operate the core access-dispatch feature and to maintain a compliance/audit trail for your organisation |
| Location data (optional) | Device GPS location at the moment an access code is sent, but only if a supervisor has enabled the "Location on Access" setting for the device | To record where an access event occurred, for your organisation's audit purposes. Not collected unless this setting is explicitly turned on |
| Camera | Used momentarily to scan a QR code during device enrolment. No photo or video is stored or transmitted; only the decoded enrolment data is | To enrol the device against your Guardcell tenant |
| NFC data | Identifiers and configuration data exchanged with nearby Guardcell remotes/receivers over NFC | To write access codes and configuration to Guardcell hardware |
| Device information | Device model, OS version, boot count/uptime (used to detect device reboots for security purposes), app version | Diagnostics, compatibility, tamper/anomaly detection, and troubleshooting |
| Push notification token | Firebase Cloud Messaging (FCM) registration token | To deliver server-dispatched access codes and alerts to the device |
The App does not collect an advertising identifier (such as the Google Advertising ID), does not use analytics or ad-tracking SDKs, does not request Bluetooth access, and does not serve advertising. The App also does not use third-party sign-in (e.g. Google Sign-In). Operators are identified solely through their organisation's Guardcell tenant enrolment.
2. Why We Collect It: Voluntary vs Mandatory
In line with section 18 of POPIA, the table below sets out whether providing each category of information is required to use the App, and the consequence of not providing it.
| Category | Mandatory / Voluntary | Consequence if not provided |
|---|---|---|
| Account & enrolment data | Mandatory | The device cannot be enrolled against your organisation's tenant and the App cannot be used to dispatch access codes |
| Access & audit log data | Mandatory (generated by using the App) | The App's core function (writing and auditing access codes) cannot operate without it |
| Location data | Voluntary (controlled by a supervisor-level setting) | None. Access dispatch works identically whether or not this is enabled; only the location record on that access event is omitted |
| Camera (QR scan) | Mandatory only at enrolment | The device can be enrolled by manual entry instead; camera access is not required for day-to-day use |
| Push notification token | Voluntary (declined via the Android notification permission prompt) | The device will not receive push-dispatched codes or alerts, but can still be used for manual dispatch |
3. Our Legal Basis for Processing (POPIA Condition 2: Processing Limitation)
We process personal information under the App only where at least one of the following applies, consistent with section 11 of POPIA:
- Processing is necessary to carry out actions for the conclusion or performance of a contract between you (or your employer) and Guardcell, i.e. to provide the App as a Guardcell tenant service.
- Processing is necessary to pursue Guardcell's or your employer's legitimate interests, such as maintaining a security audit trail, detecting device tampering, and keeping access-control hardware in a known-good state.
- You (or your employer, on your behalf) have consented to processing, for example by enabling the optional "Location on Access" setting.
- Processing is necessary to comply with an obligation imposed by law on Guardcell or your employer, including record-keeping obligations that may apply to the security industry.
4. How We Use Information
- To operate the core function of the App: issuing, encrypting, and dispatching access codes to Guardcell hardware.
- To maintain an audit log of device activity for your organisation, uploaded to the Guardova backend on each check-in.
- To deliver push-based access codes and notifications.
- To diagnose crashes and technical issues (using de-obfuscated, internal crash symbolication, see Section 5).
- To support device enrolment and re-enrolment against your organisation's tenant.
- To detect anomalies such as unexpected device reboots, for security purposes.
We do not use collected data for advertising or behavioural profiling, and we do not sell personal information to third parties.
5. Data Storage & Security (POPIA Condition 7: Security Safeguards)
- Access codes and related metadata are encrypted (AES-256-GCM / AES-ECB depending on the transport) before being written to hardware or transmitted.
- Credentials such as the supervisor password, enrolment tokens, and tenant keys are stored on-device using encrypted secure storage, not plain preferences.
- Network communication with the Guardova backend occurs over HTTPS.
- The local audit log is stored in an on-device SQLite database and is uploaded to the backend on the next check-in; it is not accessible to other apps.
- Exported audit logs (CSV/Excel) are written to the App's private, app-scoped storage area rather than shared device storage, and are not readable by other apps.
- Release builds of the App are obfuscated to reduce the risk of reverse engineering.
- If we become aware of a security compromise that has affected, or may reasonably affect, your personal information, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA.
6. Cross-Border Transfers of Information (POPIA Section 72)
Some of our infrastructure providers, principally Google/Firebase, used for push notifications (Firebase Cloud Messaging) and app bootstrap (Firebase Core), operate data centres outside South Africa, which means personal information processed through the App (such as the FCM registration token) may be transferred to and processed in other countries. We only use providers who are themselves subject to data protection terms that impose conditions for the processing of personal information that are substantially similar to POPIA's conditions, as required by section 72 of POPIA. Google's standard data processing terms are one example. We do not otherwise transfer personal information outside South Africa.
7. Data Sharing
Information collected by the App is shared only with:
- Your own organisation's Guardcell/Guardova backend infrastructure (the system your administrator manages).
- Google/Firebase, as our infrastructure provider for push notifications and app bootstrap, under Google's own data processing terms (see Section 6).
We do not sell your data, and we do not share it with third parties for their own marketing purposes.
8. Data Retention (POPIA Condition 4: Further Processing & Retention Limitation)
Access and audit log data is retained on your organisation's backend in line with your organisation's own retention practices and any applicable legal record-keeping requirements. On-device data (local logs, credentials) is retained until the operator/administrator clears it, re-enrols the device, or uninstalls the App. In line with section 14 of POPIA, we do not retain personal information for longer than is necessary to achieve the purpose for which it was collected, unless a longer period is required or permitted by law. Crash-symbolication debug symbols are retained internally by Guardcell to interpret crash reports and are not personal data themselves.
9. Your Rights as a Data Subject
Under POPIA (and, where applicable, other data protection law), you have the right to:
- be notified that your personal information is being collected, and why;
- establish whether we hold personal information about you, and request access to it (POPIA section 23);
- request that we correct, destroy, or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained (POPIA section 24);
- object, on reasonable grounds, to the processing of your personal information (POPIA section 11(3)(a));
- withdraw any consent you previously gave, such as for location-on-access, at any time;
- lodge a complaint with South Africa's Information Regulator (see Section 12 below) if you believe your rights under POPIA have been infringed.
Because the App is deployed and administered by your employer/organisation as a Guardcell tenant, requests relating to organisational data (audit logs, enrolment records) should generally be directed to your organisation's administrator in the first instance, who may need to be involved in actioning the request. You may also contact us directly using the details in Section 13.
10. Children's Privacy
The App is a professional tool for authorised security-industry operators and is not directed at, or intended for use by, children. We do not knowingly collect personal information from children.
11. Third-Party Services
The App relies on the following third-party services, each governed by its own privacy terms:
- Google Firebase Core (app initialisation)
- Google Firebase Cloud Messaging (push notification delivery)
- Google Play services (used indirectly by the Android platform)
The App does not integrate Google Sign-In, Firebase Authentication, Cloud Firestore, Firebase Analytics, or Bluetooth-based services. These were removed and are no longer part of the App.
12. Complaints: Information Officer & the Information Regulator
Guardcell's designated Information Officer, as required by POPIA, can be contacted using the details in Section 13 to raise any concern about how your personal information is processed. If you are not satisfied with our response, or wish to raise a complaint directly, you may contact South Africa's Information Regulator:
The Information Regulator (South Africa)
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Tel: +27 10 023 5200
Address: 27 Stiemens Street, Braamfontein, Johannesburg, South Africa
Web: inforegulator.org.za
13. Contact Us
Guardcell CC
Email: support@guardcell.co.za
Address: 48 Rockdale Avenue, Westville, Durban, 3630
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the App, our processing activities, or applicable law. Material changes will be reflected by updating the effective date above.