Privacy Policy & Data Sovereignty

Regulatory compliance regarding the handling of telemetry and personal data.

Effective Date: June 1, 2026

At EyeTrack, we recognize that the processing of geospatial telemetry, vehicle diagnostics, and personal safety communications carries profound security responsibilities. This policy governs how we collect, process, and secure data across our hardware infrastructure, APIs, and cloud applications.

1. Data Collection & Processing

Depending on the specific hardware deployed and the service tier engaged, our systems may process:

  • Geospatial Data: GNSS/GPS coordinates, Cell-ID locations, speed, and heading.
  • Telematics & ECU Data: Vehicle identification numbers (VIN), fuel consumption, RPM, and diagnostic trouble codes (DTCs).
  • Audio & Emergency Data: Initiated solely during active SOS events via our personal safety wearables, including 2-way VoLTE streams and environmental audio buffers.
  • Account Information: Administrator identities, contact matrices, and billing credentials.

2. Regulatory Compliance (POPIA & GDPR)

As an entity operating with a global footprint and infrastructure hubs in South Africa, EyeTrack strictly complies with the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR).

We process personal and locational data solely for the legitimate business interests of providing asset security, fleet optimization, and human safety. We operate as a Data Operator/Processor on behalf of our enterprise clients (the Responsible Parties/Data Controllers). We do not sell, broker, or monetize raw or aggregated telemetry data to third parties.

3. Cryptography and Data Storage

All communication between tracking terminals and our cloud servers utilizes TLS 1.3 encryption, guarding against Man-In-The-Middle (MITM) packet sniffing. Data at rest is secured utilizing AES-256 block-level encryption within compliant data centers featuring strict physical and logical access controls.

4. Data Retention

Historical tracking data is retained for a standard rolling period of 12 months for active accounts, after which it is programmatically purged or anonymized, unless a custom retention architecture has been legally mandated and procured by the client.

5. Contacting the Compliance Officer

Requests for data auditing, deletion, or compliance inquiries under POPIA or GDPR should be routed directly to our secure compliance portal at legal@eyetrack.co.za.