PRIVACY POLICY

ALL IN ONE EMERGENCY SERVICES (PTY) LTD

e-Panic Application, Website, and MyAllIn1 Emergency Wallet

Last updated: 02/09/2026 Version [01/2026]

PRIVATE AND CONFIDENTIAL

1. INTRODUCTION AND SCOPE

1.1 This Privacy Policy explains how All In One Emergency (Pty) Ltd, registration number [CIPC registration number], of 2010/022369/07, 147 Gateway St, Klipriviersoog, Soweto, Gauteng, South Africa (“All-In-1 Emergency”, “the Company”, “we”, “us”, “our”), collects, uses, discloses, retains, and protects personal information collected through the e-Panic mobile application, the e-Panic website, our 24-hour call centre and control room, and the MyAllIn1 Emergency Wallet (collectively, the “Platform”).

1.2 This Policy is issued in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”), and, where applicable to payment and identity verification data, the Financial Intelligence Centre Act 38 of 2001 (“FICA”).

1.3 This Policy applies to all natural and juristic persons who download, register on, or otherwise use the Platform (“User”, “you”, “your”, or, in POPIA terminology, “data subject”).

1.4 This Policy should be read together with our Terms and Conditions, available at [link], which govern your use of the Platform generally.

1.5 By downloading the e-Panic application, creating an account, or otherwise submitting personal information to us, you acknowledge that you have read and understood this Policy. Where POPIA requires your consent for a particular form of processing, that consent is obtained separately and specifically, as described in clause 5.

2. INTERPRETATION AND DEFINITIONS

2.1 In this Policy, the following terms bear the meanings assigned to them under POPIA, unless the context indicates otherwise:

2.1.1 “personal information” means information relating to an identifiable, living natural person, and, where applicable, an identifiable, existing juristic person, including but not limited to name, contact details, identity number, location information, and financial information;

2.1.2 “special personal information” means personal information concerning a data subject’s health, as more fully addressed in clause 6;

2.1.3 “processing” means any operation performed on personal information, including collection, storage, use, dissemination, or destruction;

2.1.4 “responsible party” means All-In-1 Emergency, as the entity that determines the purpose and means of processing personal information collected through the Platform;

2.1.5 “operator” means a third party that processes personal information on behalf of, and under the instruction of, the Company, including PayGate (Pty) Ltd and vetted Service Providers, as described in clause 8;

2.1.6 “Information Regulator” means the Information Regulator established under section 39 of POPIA;

2.1.7 “Information Officer” means the person appointed by the Company to ensure compliance with POPIA, as identified in clause 13.

2.2 Capitalised terms not defined in this Policy bear the meaning given to them in the Company’s Terms and Conditions.

3. THE INFORMATION WE COLLECT

3.1 We collect personal information necessary to operate the Platform, dispatch emergency and roadside assistance, process payments, and comply with our legal obligations. This includes:

3.1.1 Identity and contact information — full name, identity number or passport number (where required for verification), mobile number, email address, and physical or billing address;

3.1.2 Location information — real-time and historic GPS location data transmitted from your device when you submit a service request through the Platform, which is necessary to dispatch the nearest available Service Provider to your location;

3.1.3 Vehicle and property information — where relevant to roadside assistance services, vehicle registration, make, model, and related details;

3.1.4 Payment and Wallet information — Wallet balance, transaction history, and Subscription status. Card numbers, expiry dates, and CVV codes are entered directly into PayGate’s secure payment interface and are not collected, transmitted, or stored by the Company, as more fully described in clause 8.2;

3.1.5 Communications data — recordings and transcripts of calls to our 24-hour call centre and control room, made for dispatch accuracy, quality assurance, and dispute resolution purposes, and correspondence via email, in-app messaging, or other support channels;

3.1.6 Device and technical information — device type, operating system, unique device identifiers, IP address, and application usage data, collected automatically through the app and website;

3.1.7 Service history — records of past service requests, Service Provider dispatches, and outcomes.

3.2 Where a User submits personal information concerning another person (for example, requesting assistance on behalf of a family member or passenger), the User warrants that they have the necessary authority or consent to disclose that person’s personal information to us for the purpose of the request.

4. HOW WE COLLECT INFORMATION

4.1 We collect personal information:

4.1.1 directly from you, when you register for the Platform, submit a service request, contact our call centre, or complete a Subscription sign-up;

4.1.2 automatically, through your use of the application and website, including location data (subject to device-level permissions you control), device identifiers, and usage analytics;

4.1.3 from PayGate, limited to confirmation of successful or failed transactions and Wallet balance updates, and not extending to full card data; and

4.1.4 from Service Providers, limited to information reasonably necessary to confirm and record service delivery.

4.2 Where location data collection requires device-level permission under your mobile operating system, you may withdraw that permission at any time through your device settings; however, doing so may materially limit or prevent our ability to dispatch emergency assistance to you.

5. LAWFUL BASIS AND PURPOSE OF PROCESSING

5.1 In accordance with section 11 of POPIA, we process personal information only where at least one of the following lawful grounds applies:

5.1.1 Consent — where you have given specific, informed consent, for example to receive marketing communications;

5.1.2 Necessity for performance of a contract — where processing is necessary to provide the Services you have requested, administer your Subscription, or manage your Wallet;

5.1.3 Compliance with a legal obligation — including record-keeping obligations under FICA and disclosure obligations to regulatory or law enforcement authorities where lawfully required;

5.1.4 Protection of a legitimate interest — including the legitimate interest of the data subject or a third party, in particular the protection of life, health, or safety in an emergency; and

5.1.5 Legitimate interests of the Company — including fraud prevention, service quality monitoring, and the improvement of dispatch accuracy, provided such interests do not override your rights as a data subject.

5.2 We process personal information for the following purposes:

5.2.1 to register and administer your Platform account and Wallet;

5.2.2 to receive, process, and dispatch service requests to the nearest appropriate Service Provider;

5.2.3 to process Subscription and Cash Basis payments via PayGate;

5.2.4 to verify identity where required under FICA or for fraud prevention;

5.2.5 to communicate with you regarding your account, service requests, billing, and Platform updates;

5.2.6 to record and review call centre communications for quality assurance and dispute resolution;

5.2.7 to comply with applicable legal, regulatory, or law enforcement requirements; and

5.2.8 with your consent, to send you promotional or marketing communications, from which you may opt out at any time.

6. LOCATION DATA AND SPECIAL PERSONAL INFORMATION IN AN EMERGENCY CONTEXT

6.1 Location data is central to the Platform’s function as an emergency and roadside dispatch service. By submitting a service request, you consent to your real-time location being shared with the Company’s control room and the dispatched Service Provider for the sole purpose of responding to that request. Location data is retained for the period set out in clause 10 for dispute resolution, safety auditing, and regulatory purposes.

6.2 In the course of an emergency call or dispatch, you, or a person calling on your behalf, may disclose special personal information concerning health (for example, the nature of a medical emergency) for the sole purpose of enabling an appropriate emergency response. In accordance with section 27 of POPIA, such information is processed only:

6.2.1 with your consent, express or implied by the circumstances of the emergency call; or

6.2.2 where processing is necessary to protect your vital interests, or those of another individual, and you are physically or legally incapable of giving consent; or

6.2.3 where processing is necessary for the establishment, exercise, or defence of a right or obligation in law.

6.3 Health-related information disclosed in the course of an emergency dispatch is shared only with the Service Provider actually dispatched to respond, and, where applicable, onward emergency or medical services, and is not used for any secondary purpose, including marketing.

7. DIRECT MARKETING

7.1 Where you have consented, we may send you direct marketing communications regarding Platform updates, Subscription offers, or promotions, by email, SMS, or push notification, in accordance with section 69 of POPIA and section 45 of ECTA.

7.2 You may withdraw consent to direct marketing at any time by using the opt-out mechanism provided in the relevant communication, through your in-app account settings, or by contacting us using the details in clause 14. Withdrawal of marketing consent does not affect our ability to send you operational communications necessary for the provision of the Services.

8. SHARING OF PERSONAL INFORMATION

8.1 We do not sell personal information to third parties. We disclose personal information only as reasonably necessary for the purposes set out in clause 5, to the following categories of recipient:

8.2 PayGate (Pty) Ltd, our appointed, PCI-DSS compliant payment gateway, which processes Subscription and Wallet payment transactions as an operator acting on our instruction. PayGate receives payment card data directly from you and does not share full card data with the Company.

8.3 Service Providers, the independent, vetted third parties dispatched to respond to your service request, who receive the minimum personal information (typically name, contact number, and location) reasonably necessary to locate and assist you.

8.4 Regulators and law enforcement, where disclosure is required by law, including in response to a lawful request from the South African Police Service, the Information Regulator, the South African Reserve Bank, or a court of competent jurisdiction.

8.5 Professional advisors and service providers, including IT hosting, customer support, and analytics providers who process personal information on our behalf as operators, under written agreements that require them to apply security safeguards consistent with POPIA.

8.6 A successor in title, in the event of a merger, acquisition, or sale of all or substantially all of the Company’s business, subject to that successor being bound by terms materially consistent with this Policy.

8.7 All operators processing personal information on our behalf are contractually bound to process such information only in accordance with our instructions, to maintain confidentiality, and to implement appropriate security safeguards, in accordance with section 21 of POPIA.

9. CROSS-BORDER TRANSFER OF PERSONAL INFORMATION

9.1 Personal information is, as a general rule, stored and processed within the Republic of South Africa. Where any personal information is transferred to, or processed in, a jurisdiction outside South Africa (including where a service provider’s servers are located abroad), such transfer shall occur only in accordance with section 72 of POPIA — that is, where the recipient jurisdiction is subject to a law, binding corporate rules, or a binding agreement affording adequate protection substantially similar to POPIA, or where you have consented to the transfer, or where the transfer is necessary for the performance of a contract with you.

9.2 [If any specific sub-processor stores or processes data outside South Africa — e.g. cloud hosting — name the provider, the country, and the safeguard relied upon here.]

10. RETENTION OF PERSONAL INFORMATION

10.1 In accordance with section 14 of POPIA, we retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law, whichever is longer.

10.2 As a general guide:

10.2.1 account and Subscription information is retained for the duration of your active use of the Platform, and for [X years] thereafter for record-keeping and dispute-resolution purposes;

10.2.2 transaction and payment records are retained for a minimum of five years, in accordance with FICA record-keeping requirements;

10.2.3 call centre recordings and location data associated with a specific service dispatch are retained for [X months/years] for quality assurance, safety auditing, and dispute-resolution purposes; and

10.2.4 information may be retained for a longer period where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.

10.3 On expiry of the applicable retention period, personal information is deleted, destroyed, or de-identified in a manner that prevents its reconstruction in an intelligible form, in accordance with section 14 of POPIA.

11. SECURITY SAFEGUARDS

11.1 In accordance with section 19 of POPIA, we implement appropriate, reasonable technical and organisational measures to protect personal information against loss, unauthorised access, interference, modification, destruction, or disclosure, including:

11.1.1 encryption of payment data in transit, processed exclusively through PayGate’s PCI-DSS compliant environment;

11.1.2 access controls limiting internal access to personal information to employees and contractors who require it to perform their functions;

11.1.3 secure storage of call centre recordings and location data; and

11.1.4 regular review of our security measures in light of prevailing industry standards.

11.2 No system of transmission or storage can be guaranteed to be 100% (one hundred percent) secure. Should a security compromise occur that has compromised, or is reasonably believed to have compromised, your personal information, we will notify the Information Regulator and affected data subjects in accordance with section 22 of POPIA, as soon as reasonably possible after becoming aware of the compromise.

12. YOUR RIGHTS AS A DATA SUBJECT

12.1 Subject to the limitations set out in POPIA, and in particular section 23 to section 25, you have the right to:

12.1.1 be notified that personal information about you is being collected, and for what purpose;

12.1.2 establish whether we hold personal information about you, and to request access to that information;

12.1.3 request the correction, updating, or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained;

12.1.4 object, on reasonable grounds, to the processing of your personal information, including for direct marketing purposes;

12.1.5 withdraw any consent on which processing is based, without affecting the lawfulness of processing carried out prior to withdrawal;

12.1.6 submit a complaint to the Information Regulator regarding an alleged interference with the protection of your personal information; and

12.1.7 institute civil proceedings for damages in respect of an alleged breach of POPIA.

12.2 To exercise any of these rights, contact our Information Officer using the details in clause 13. We will respond to a request within the timeframes prescribed by POPIA, and may require proof of identity before giving effect to a request, to protect against unauthorised access to your personal information.

12.3 Where we are unable to give effect to a request — for example, where retention is required by FICA — we will explain the basis for that limitation to you.

13. INFORMATION OFFICER

13.1 In accordance with section 55 of POPIA, the Company has appointed the following Information Officer, registered with the Information Regulator:

Information Officer: [name]

Email: Happy Chauke

Telephone: 0860 255 461

Address: 147 Gateway St, Klipriviersoog, Soweto, 1811

13.2 Should you be dissatisfied with our response to a request or complaint, you may lodge a complaint with the Information Regulator:

The Information Regulator (South Africa)

Email: complaints.IR@justice.gov.za

Website: www.justice.gov.za/inforeg

 

14. CONTACT US

14.1 For any query regarding this Policy or the processing of your personal information, contact:

All In One Emergency (Pty) Ltd

Email: info@allin1emergency.co.za

24-Hour Call Centre: 0860 255 461

Registered Address: 147 Gateway St, Klipriviersoog, Soweto, 1811

 

15. COOKIES AND WEBSITE TRACKING

15.1 The e-Panic website uses cookies and similar tracking technologies to enable core website functionality, remember your preferences, and, where you consent, to analyse website usage. Full details are available in our [Cookie Policy / Notice, link].

15.2 You may manage or disable cookies through your browser settings; however, doing so may affect the functionality of the website.

16. CHILDREN’S INFORMATION

16.1 The Platform is not intended for use by children under the age of 18, save where a parent or legal guardian has registered on a child’s behalf or consented to their use of the Platform, in accordance with section 34 read with section 35 of POPIA governing the processing of children’s personal information.

16.2 Where we become aware that personal information has been collected from a child without the requisite parental or guardian consent, we will take reasonable steps to delete that information, save where retention is otherwise required by law (for example, records of an emergency dispatch already carried out).

17. CHANGES TO THIS POLICY

17.1 We may amend this Policy from time to time to reflect changes in our data practices, the Services offered, or applicable law. Material changes will be communicated to registered Users via the Platform or by email, and the “Last updated” date will be revised accordingly.

17.2 Continued use of the Platform following notification of a material change constitutes your acknowledgement of the amended Policy, save where POPIA requires that fresh consent be obtained, in which case we will seek that consent separately.