Legal

Privacy Policy

How RAKSHA Ireland collects, uses, and protects your personal and safety data. Looking for our Terms of Use?

Last updated: July 13, 2026

1. Introduction

RAKSHA Ireland operates a community-powered personal safety network. This Privacy Policy explains what personal data we collect, why we collect it, the lawful bases we rely on, how long we keep it, who it is shared with, and the rights you have under the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts.

Because RAKSHA is an identity-verified safety network, anonymous participation is not possible. This policy covers our mobile application and website. Our separate Terms of Use govern account eligibility, conduct and the limits of the service.

2. Who We Are (Data Controller)

The data controller responsible for your personal data is the entity operating RAKSHA Ireland. We are finalising our company registration and will publish the following details in full before public launch:

  • Legal entity name: [to be confirmed before launch]
  • Registered / business address: Dublin, Ireland [full address to be confirmed]
  • Company registration number: [to be confirmed, where applicable]
  • Privacy contact: support@rakshaireland.com
  • Data protection contact / safeguarding lead: support@rakshaireland.com

If we appoint a Data Protection Officer, their contact details will be published here.

3. Information We Collect

To provide a reliable safety network, we collect:

  • Personal identity information: Your full legal name, phone number, email address, and profile photo.
  • Government-issued ID: A photograph of a passport, driving licence, or national identity card, used by our verification team to confirm your identity.
  • Location data: When you trigger an SOS, your device captures a one-time GPS location and attaches it to that alert so nearby members can find you. RAKSHA does not continuously track your location and does not share your location at any other time — there is no live or background location tracking.
  • Device identifiers: Basic device details (such as model and operating system) used to maintain a single active session per account.
  • Push notification token: A device token used to deliver emergency SOS notifications.
  • Alert and history data: Details of SOS alerts you send or respond to, including timestamps, the GPS location at the time of the alert, and resolution status.
  • Support correspondence: Messages you send us and our replies.

4. How We Use Your Data & Lawful Bases

We only process personal data where we have a lawful basis to do so under Article 6 (and, for identity documents and location, the additional conditions for special-category or sensitive processing where applicable). The bases below are indicative and are being confirmed as part of our data-protection assessment before launch:

PurposeLawful basis
Creating and maintaining your accountPerformance of a contract
Identity verification (photo ID)Legitimate interests / contract (subject to confirmed assessment)
Capturing your location when you trigger an SOSContract, and/or vital interests and/or consent depending on the circumstances
Fraud, abuse and misuse preventionLegitimate interests
Legal disclosures to authoritiesLegal obligation
Optional marketing or updatesConsent

Where we rely on consent, it is optional, specific and can be withdrawn at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, we have balanced those interests against your rights and can provide details on request.

5. How the SOS Broadcast Works

So you understand exactly what is shared when you raise an alert:

  • Who receives it: Verified, active members of the RAKSHA network who are nearby.
  • What they see: Your name, phone number and the GPS location captured at the time of the alert.
  • How long it stays visible: Up to 60 minutes from the time it is sent.
  • Who keeps a record: After the alert closes, only you (the sender) and the first member who accepted it retain the alert in their history. Other members no longer have access.
  • What we cannot control: As with any information shown on another person's screen, we cannot technically prevent a recipient from taking a screenshot or noting details. Misuse of alert information is prohibited under our Terms of Use and may result in a ban and referral to the Gardaí.

When you accept an alert to help someone, your name and profile photo are shared with them so they know who is responding.

6. Data Storage and Security

We use established cloud service providers to host and process personal data. Information about the principal providers we use, their purposes and relevant processing locations is set out in the “Service Providers & International Transfers” section below.

We apply technical and organisational safeguards appropriate to the nature and risk of the information we process. These include encryption of data in transit, access controls, authentication safeguards, and restrictions that limit access to personal data to authorised personnel with a legitimate operational need.

Government-issued identity documents are accessible only to authorised personnel responsible for identity verification. They are retained for a limited period and then securely deleted, unless longer retention is required by law, for the establishment or defence of legal claims, or for the investigation of suspected fraud or serious misuse. See the retention schedule below.

No electronic system can be guaranteed to be completely secure. We review our safeguards from time to time and will respond to any personal-data breach in accordance with applicable data-protection law.

7. How Long We Keep Your Data (Retention)

We keep personal data only for as long as necessary for the purposes described above. Our retention periods are being finalised as part of our pre-launch assessment; the schedule below shows our intended approach:

DataIntended retention
Rejected identity documentsDeleted shortly after the decision [period to be confirmed]
Approved identity documentsDeleted within a defined period after verification [to be confirmed]; a limited verification result and date may be kept
Profile informationFor the life of your account
SOS event locations & incident historyRetained with the sender and accepting responder [period to be confirmed]
Responder acceptance records[period to be confirmed]
Device identifiers & push tokensWhile the device is linked to your account
Support correspondence[period to be confirmed]
Security & diagnostic logsShort, defined period [to be confirmed]
Deleted accountsRemoved or anonymised within a defined period, subject to legal-hold exceptions

8. Service Providers & International Transfers

We do not sell, rent or trade your personal data. We share it only with the processors below, who act on our instructions, and with authorities where legally required.

ProviderPurposeProcessing location
AWSApplication infrastructureEEA
SupabaseDatabase, authentication and file storageEEA
Firebase (Google)Push notificationsTo be confirmed
ResendTransactional emailsTo be confirmed

We are verifying the actual processing and remote-access locations for each provider. Where any personal data is transferred to, accessed from, or supported outside the European Economic Area (EEA), we will rely on an appropriate transfer mechanism — such as an adequacy decision or Standard Contractual Clauses — and will describe the countries involved and how you can obtain information about the safeguards in place.

We may also disclose personal data where required by Irish law or to assist the Gardaí (police) in investigating a serious incident.

9. Your Rights

Under the GDPR you have the right to:

  • Be informed about how your data is used (this policy).
  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate data — you can update your name, phone number and profile photo in the app.
  • Erase your data (“right to be forgotten”), subject to legal exceptions.
  • Restrict processing in certain circumstances.
  • Data portability — receive certain data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent (for example, optional updates or communications).
  • Complain to the Irish Data Protection Commission (DPC) at dataprotection.ie.

To exercise any right, contact us at support@rakshaireland.com. We may ask you to verify your identity before responding, and we will reply within the timeframe required by law (normally within one month). Some rights may be limited where necessary — for example, to protect another person involved in an incident, or to comply with a legal obligation.

10. Data Protection Impact Assessment

Because RAKSHA involves precise location data, government identity documents, emergency incidents and disclosure to nearby community members, we are completing a formal Data Protection Impact Assessment (DPIA) before public launch, and will mitigate identified risks before enabling high-risk processing.

11. Changes & Contact

We may update this policy from time to time. Material changes will be notified in the app or on this page. For any question or data-rights request, contact us at:

Email: support@rakshaireland.com
RAKSHA Ireland, Dublin, Ireland