Privacy Policy
How RAKSHA Ireland collects, uses, and protects your personal and safety data. Looking for our Terms of Use?
1. Introduction
RAKSHA Ireland operates a community-powered personal safety network. This Privacy Policy explains what personal data we collect, why we collect it, the lawful bases we rely on, how long we keep it, who it is shared with, and the rights you have under the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts.
Because RAKSHA is an identity-verified safety network, anonymous participation is not possible. This policy covers our mobile application and website. Our separate Terms of Use govern account eligibility, conduct and the limits of the service.
2. Who We Are (Data Controller)
The data controller responsible for your personal data is the entity operating RAKSHA Ireland. We are finalising our company registration and will publish the following details in full before public launch:
- Legal entity name: [to be confirmed before launch]
- Registered / business address: Dublin, Ireland [full address to be confirmed]
- Company registration number: [to be confirmed, where applicable]
- Privacy contact: support@rakshaireland.com
- Data protection contact / safeguarding lead: support@rakshaireland.com
If we appoint a Data Protection Officer, their contact details will be published here.
3. Information We Collect
To provide a reliable safety network, we collect:
- Personal identity information: Your full legal name, phone number, email address, and profile photo.
- Government-issued ID: A photograph of a passport, driving licence, or national identity card, used by our verification team to confirm your identity.
- Location data: When you trigger an SOS, your device captures a one-time GPS location and attaches it to that alert so nearby members can find you. RAKSHA does not continuously track your location and does not share your location at any other time — there is no live or background location tracking.
- Device identifiers: Basic device details (such as model and operating system) used to maintain a single active session per account.
- Push notification token: A device token used to deliver emergency SOS notifications.
- Alert and history data: Details of SOS alerts you send or respond to, including timestamps, the GPS location at the time of the alert, and resolution status.
- Support correspondence: Messages you send us and our replies.
4. How We Use Your Data & Lawful Bases
We only process personal data where we have a lawful basis to do so under Article 6 (and, for identity documents and location, the additional conditions for special-category or sensitive processing where applicable). The bases below are indicative and are being confirmed as part of our data-protection assessment before launch:
| Purpose | Lawful basis |
|---|---|
| Creating and maintaining your account | Performance of a contract |
| Identity verification (photo ID) | Legitimate interests / contract (subject to confirmed assessment) |
| Capturing your location when you trigger an SOS | Contract, and/or vital interests and/or consent depending on the circumstances |
| Fraud, abuse and misuse prevention | Legitimate interests |
| Legal disclosures to authorities | Legal obligation |
| Optional marketing or updates | Consent |
Where we rely on consent, it is optional, specific and can be withdrawn at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, we have balanced those interests against your rights and can provide details on request.
5. How the SOS Broadcast Works
So you understand exactly what is shared when you raise an alert:
- Who receives it: Verified, active members of the RAKSHA network who are nearby.
- What they see: Your name, phone number and the GPS location captured at the time of the alert.
- How long it stays visible: Up to 60 minutes from the time it is sent.
- Who keeps a record: After the alert closes, only you (the sender) and the first member who accepted it retain the alert in their history. Other members no longer have access.
- What we cannot control: As with any information shown on another person's screen, we cannot technically prevent a recipient from taking a screenshot or noting details. Misuse of alert information is prohibited under our Terms of Use and may result in a ban and referral to the Gardaí.
When you accept an alert to help someone, your name and profile photo are shared with them so they know who is responding.
6. Data Storage and Security
We use established cloud service providers to host and process personal data. Information about the principal providers we use, their purposes and relevant processing locations is set out in the “Service Providers & International Transfers” section below.
We apply technical and organisational safeguards appropriate to the nature and risk of the information we process. These include encryption of data in transit, access controls, authentication safeguards, and restrictions that limit access to personal data to authorised personnel with a legitimate operational need.
Government-issued identity documents are accessible only to authorised personnel responsible for identity verification. They are retained for a limited period and then securely deleted, unless longer retention is required by law, for the establishment or defence of legal claims, or for the investigation of suspected fraud or serious misuse. See the retention schedule below.
No electronic system can be guaranteed to be completely secure. We review our safeguards from time to time and will respond to any personal-data breach in accordance with applicable data-protection law.
7. How Long We Keep Your Data (Retention)
We keep personal data only for as long as necessary for the purposes described above. Our retention periods are being finalised as part of our pre-launch assessment; the schedule below shows our intended approach:
| Data | Intended retention |
|---|---|
| Rejected identity documents | Deleted shortly after the decision [period to be confirmed] |
| Approved identity documents | Deleted within a defined period after verification [to be confirmed]; a limited verification result and date may be kept |
| Profile information | For the life of your account |
| SOS event locations & incident history | Retained with the sender and accepting responder [period to be confirmed] |
| Responder acceptance records | [period to be confirmed] |
| Device identifiers & push tokens | While the device is linked to your account |
| Support correspondence | [period to be confirmed] |
| Security & diagnostic logs | Short, defined period [to be confirmed] |
| Deleted accounts | Removed or anonymised within a defined period, subject to legal-hold exceptions |
8. Service Providers & International Transfers
We do not sell, rent or trade your personal data. We share it only with the processors below, who act on our instructions, and with authorities where legally required.
| Provider | Purpose | Processing location |
|---|---|---|
| AWS | Application infrastructure | EEA |
| Supabase | Database, authentication and file storage | EEA |
| Firebase (Google) | Push notifications | To be confirmed |
| Resend | Transactional emails | To be confirmed |
We are verifying the actual processing and remote-access locations for each provider. Where any personal data is transferred to, accessed from, or supported outside the European Economic Area (EEA), we will rely on an appropriate transfer mechanism — such as an adequacy decision or Standard Contractual Clauses — and will describe the countries involved and how you can obtain information about the safeguards in place.
We may also disclose personal data where required by Irish law or to assist the Gardaí (police) in investigating a serious incident.
9. Your Rights
Under the GDPR you have the right to:
- Be informed about how your data is used (this policy).
- Access a copy of the personal data we hold about you.
- Rectify inaccurate data — you can update your name, phone number and profile photo in the app.
- Erase your data (“right to be forgotten”), subject to legal exceptions.
- Restrict processing in certain circumstances.
- Data portability — receive certain data in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing is based on consent (for example, optional updates or communications).
- Complain to the Irish Data Protection Commission (DPC) at dataprotection.ie.
To exercise any right, contact us at support@rakshaireland.com. We may ask you to verify your identity before responding, and we will reply within the timeframe required by law (normally within one month). Some rights may be limited where necessary — for example, to protect another person involved in an incident, or to comply with a legal obligation.
10. Data Protection Impact Assessment
Because RAKSHA involves precise location data, government identity documents, emergency incidents and disclosure to nearby community members, we are completing a formal Data Protection Impact Assessment (DPIA) before public launch, and will mitigate identified risks before enabling high-risk processing.
11. Changes & Contact
We may update this policy from time to time. Material changes will be notified in the app or on this page. For any question or data-rights request, contact us at:
Email: support@rakshaireland.com
RAKSHA Ireland, Dublin, Ireland