This policy explains how Wolfpak handles personal information. It applies to the Wolfpak control room (the website), the Wolfpak mobile application, and the radio trackers that report positions into the service.
It is written for two audiences: the organisation that uses Wolfpak — a farm watch, a community policing forum, a security company — and the individual members whose position the service reports.
This matters because it decides who you ask about what, and the answer is not the same for everything.
If you are a member of a group and you want to know why you are being tracked, or you want your data corrected or removed, ask your group first. They decide. We will help them act on it, and we will not override them.
This is the most significant thing the service does with personal information, so it is set out on its own.
Positions are also recorded against events in the incident log — for example, where you were when you acknowledged a tasking or reported arriving. See section 10.
Your name, email address, callsign if you have one, your password (stored only as a one-way hash, which means we cannot read it), the groups and roles you hold, and when you were last active.
Latitude and longitude, the accuracy your device reported, and the time of the fix. From a radio tracker we also receive speed, heading and battery level, and a record of how the position was authenticated. A history of these positions is kept — see section 9.
Incidents your group opens, including the type, description and location; taskings, including the destination, the label and any note to the units; each responder's acknowledgement, en route and arrival; and notes your operators or responders type.
A push notification token so we can alert your device, the platform (iOS or Android), and an identifier we generate for the app installation so that reinstalling retires the old registration. We do not collect your advertising identifier, your contacts, your photos, your microphone or your call history.
Ordinary server logs, which include IP addresses, timestamps and which requests were made. We use them to run and secure the service.
We do not use advertising or analytics trackers. We do not build a profile of you. We do not collect payment card details — during a pilot there is nothing to pay.
Under POPIA we need a lawful basis for each purpose. Ours are:
We do not use your information for automated decision-making. Every operational decision in Wolfpak is made by a person in your control room.
An incident record often contains information about somebody who is not a member of your group — a caller, a complainant, a neighbour, a person somebody has described. Your operators type this in.
That information is your group's responsibility. You must have a lawful basis for recording it, you must not record more than you need, and you should assume that what is typed into an incident note will still be there afterwards. Please tell your operators this: it is not a place for opinions about people, and identifying details should only be recorded where there is a reason to.
Some of the providers above operate outside South Africa, including in the United States and the European Union. That means some personal information is processed outside the country.
We rely on section 72 of POPIA: these providers are bound by contractual terms requiring a level of protection substantially similar to POPIA's principles, and the transfer is necessary to perform our agreement with your group.
If your group asks us to delete its data, we will — all of it, or a specified part such as position history older than a given date. Ask at support@wolfpak.co.za. We may keep what we are legally required to keep, and we may keep aggregated information that no longer identifies anybody.
To decide before this is relied on: a fixed retention period for position history — 90 days is a reasonable default — and an automatic job that enforces it. Today deletion happens when a group asks for it, which is honest but means this section promises no automatic expiry. Once the job exists, state the period here.
The incident log is deliberately append-only. Entries are added and never altered or removed, because a record that somebody can quietly revise afterwards is worth very little — and these records exist for exactly the situations where that matters.
This has a consequence worth stating plainly. If information in a log entry is wrong, the correction is a new entry saying so; the original stays. If somebody exercises a right that would require an entry to be changed or erased, we cannot edit the line — what we can do is delete the incident, or the group's records, in full. We will work with your group to find the right answer in the circumstances.
Under POPIA you may:
Where to ask. If you are a member of a group, start with your group — they are the responsible party for operational information and they decide. For account information, or if your group does not respond, write to us at support@wolfpak.co.za. We will respond within 30 days and may need to verify who you are first.
Exercising a right costs nothing and will not affect your standing in your group as far as we are concerned.
We take reasonable technical and organisational measures to protect personal information: traffic is encrypted in transit, passwords are stored only as one-way hashes, tracker credentials are stored hashed and shown once, sessions can be revoked, and one group's data is separated from another's throughout the service.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that creates a real risk to anybody, we will notify the affected groups and the Information Regulator as POPIA requires.
A phone is part of this too. A responder's device holds incident details on its lock screen. Use a device passcode.
Wolfpak is not intended for people under 18 and we do not knowingly collect their information. A group must not invite a person under 18 as a member. If you believe we hold a child's information, tell us and we will delete it.
We will update this policy when the service changes. Where a change materially affects how we handle personal information we will tell your group's administrators by email and give reasonable notice before it takes effect.
The version and effective date at the top tell you which policy applies.
Privacy questions and requests:
support@wolfpak.co.za
Anything else: hello@wolfpak.co.za
To be completed: the name and contact details of your registered Information Officer, and Wolfpak's registration number and physical address. POPIA requires an Information Officer to be registered with the Information Regulator, and a privacy policy that does not name one is incomplete.
You may also complain to the Information Regulator of South Africa: inforegulator.org.za, POPIAComplaints@inforegulator.org.za.