Who we are
The SecurIT SOS application is published by MY KEEPER, a French simplified joint-stock company (SAS) registered with the Grasse Trade and Companies Register under number 821 064 474, whose registered office is at Les Espaces de Sophia, 80 route des Lucioles, Bâtiment O, 06560 Valbonne – Sophia Antipolis, France.
SecurIT SOS is a lone worker protection (PTI) and alert management application. It is installed on the user’s smartphone: the alert is triggered from the phone. It allows an alert to be raised and automatic alerts to be configured. The application can be downloaded freely from app stores. Using the alert features then requires access to be activated by the organisation that has subscribed to the service: the triggering of an alert, its routing and the emergency contacts who receive it are configured by that organisation according to the way it organises work. This activation is necessary for the alert service to operate.
Controller and My Keeper’s role
The application is deployed by your employer or your organisation, which determines the purposes and means of the processing: it acts as data controller. My Keeper acts as processor, on behalf of and according to the instructions of that organisation, in accordance with Article 28 GDPR. Technical and diagnostic data strictly necessary to keep the application in working order are, for their part, processed by My Keeper as controller. The business contact details required to activate your access are determined and provided by your organisation in its capacity as controller; it is for that organisation to inform you accordingly, in accordance with Articles 13 and 14 GDPR. My Keeper processes those details solely on its instructions and for the performance of the contract. My Keeper does not obtain any personal data from third parties for its own purposes, does not build any file for commercial or advertising purposes, and does not collect any information about you outside the application and its use.
For any question concerning your data in the context of your professional activity, please contact your employer in the first instance. You may also contact My Keeper (see section 9).
Data we process, purposes and retention periods
The table below sets out, for each category of data, the purpose pursued, the legal basis and the retention period.
| Category of data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Approximate and precise location, including in the background — transmitted when an alert is triggered; the last known position is stored locally on the device between two readings | To locate the person in an alert situation so that emergency services can intervene; the background permission makes it possible to obtain the position even when the application is not in the foreground | Legitimate interest and the employer’s safety obligation | The alert’s location point is retained for the term of the contract, then deleted (section 6). Outside an alert, no position is transmitted to our servers; only the last known position is stored locally on the device, between two readings. The application does not collect your journeys. Your position is not transmitted to any of our technical diagnostic providers |
| Alert data: date, time, alert type / scenario, technical identifier of the installation that triggered the alert, nature of the alert. The data transmitted by the application when an alert is triggered are the telephone number, the location, the time and the reason for the alert, identical on the SMS channel and on the HTTP channel | To handle the alert and keep a record of it; traceability and proper operation of the system | Legitimate interest and the employer’s safety obligation | Term of the contract; at the end of the contract, the alert history is anonymised (section 6) |
| Audio of the telephone call established following an alert: incoming call answered automatically, calls placed successively to the designated contacts, or connection to a remote assistance centre | To enable the alerted parties to assess the situation and provide assistance. Depending on the configuration, following an alert the incoming call is answered automatically, or a call is placed to the designated contacts in turn, or to a remote assistance centre. The call is opened without any action on your part, and your phone’s microphone is active for its whole duration | Legitimate interest and the employer’s safety obligation | The application makes no recording of the call: it is established in real time by your device’s telephone function and is not stored on any of our servers. No audio recording is transmitted to our technical providers |
| Identification data: email address, surname, first name, job title, telephone number (user and alert or technical contacts). Only the email address is entered in the application. Surname, first name and job title are entered by your organisation in its supervision interface: they are not collected by the application | Account creation and management, identification of the person during an alert, information of the designated contacts and emergency services | Performance of the contract between the employer and My Keeper; the employer’s safety obligation | Term of the contract, then deletion at the end of the period set out in section 6 |
| Telephone number and user account — in the context of access activated by your organisation and of fleet deployments (“HTTP” alerts) | Authentication, linking the device to the deploying organisation and routing alerts to their recipients | Performance of the contract; the employer’s safety obligation | Term of the contract, then deletion at the end of the period set out in section 6 |
| Identifier of the Keeper alert button paired with the application, where applicable: the name given to the device and its technical identifier | To pair the alert button with the application so that an alert can be triggered from that button, and to display its connection status and battery level | Legitimate interest in the proper operation of the alert system | Stored on your phone until the button is disconnected or your access is deleted |
| Technical identifiers: a device identifier which persists after the application is uninstalled and is only reset by a factory reset of the device; installation identifiers specific to each technical tool, renewed on reinstallation. Technical characteristics of the device. These identifiers do not allow you to be named and are not advertising identifiers | Operation of the service; linking a technical log or a crash report to an installation, without identifying the person | Legitimate interest in the proper operation and security of the application | For as long as strictly necessary for the operation of the service. Installation identifiers are retained until you request deletion, then erased within a maximum of 180 days |
| Crash and freeze reports: crash or freeze trace, execution threads, extracts of the application code around the error, timestamp and session duration; model, manufacturer, operating system version, memory, storage, battery and device state; application version | To ensure the stability and security of the application, and to detect and correct faults. Since a crash results in a loss of protection, correcting these faults is a matter of the safety of the system | Consent (Article 6(1)(a) GDPR), obtained in the application in accordance with Article 82 of French Act no. 78-17 | 90 days, then erasure |
| Technical operating log: a timestamped event for each alert and pre-alert and its origin, each activation or deactivation of the detection features, each change to the alert settings and its value, each permission check and its result, the automatic answering of a call, the starting and stopping of the detection services, the state of the location service; make, model, operating system version, language, available memory and storage, and an indication of whether the device is rooted | Reliability of detection: to reconstruct the sequence of a missed or spurious alert on a given device. Without this log, an alert that fails to trigger can neither be explained after the event nor corrected | Legitimate interest in the proper operation and security of the alert system, and the employer’s safety obligation | 12 months, then deletion. These data are hosted in the European Union |
| Application usage data: first opening, start and duration of sessions, screens viewed (technical name), updates and uninstallation, country inferred by Google from your IP address; versions installed | To monitor the installed base and the use of versions, in order to organise updates and support | Consent (Article 6(1)(a) GDPR), obtained in the application in accordance with Article 82 of French Act no. 78-17 | 14 months, then deletion. Anonymous aggregated reports are not affected |
We do not collect health data, payment data, or any data that is not necessary for the alert service. We do not sell your data and do not use it for any advertising purpose. We do not collect an advertising identifier. Our technical diagnostic tools receive neither your position, nor your identity, nor any audio recording, nor any screenshot.
Permissions requested by the application
The application requests the following permissions on your phone. You may refuse them, or withdraw them at any time in your device settings; the corresponding alert features can then no longer be provided.
- Nearby devices (Bluetooth): only if you pair a Keeper alert button with the application. This permission makes it possible to detect the button, connect to it and display its status. If you do not use a Keeper button, you may refuse it with no effect on the other features;
- Location, including when the application is not open: necessary in order to transmit your position to the alerted parties when an alert is triggered. An information screen is displayed in the application before any permission request. Outside an alert, no position is transmitted to our servers; only the last known position is stored on your phone, between two readings, so that it can be transmitted immediately if you trigger an alert. The application does not collect your journeys;
- Sending SMS and making calls: to transmit the alert to the contacts designated by your organisation, a message is sent and a call is placed to those contacts;
- Microphone and call management: following an alert, the telephone call is opened automatically: the incoming call is answered without any action on your part, or a call is placed to the designated contacts or to a remote assistance centre. Your phone’s microphone is then active, so that the alerted parties can assess the situation and provide assistance. The application makes no recording. Automatic answering applies for a configurable period after the alert; it covers incoming calls received during that period, and you may stop it at any time from the notification displayed by the application;
- Notifications: to display alerts and service messages on your phone. These notifications are produced by the application on the device: no server sends them.
Legal basis for the processing
Depending on the data concerned, the processing is based on one of the following grounds, as determined by the organisation acting as controller:
- performance of the contract between My Keeper and your organisation and the safety mission arising from it;
- the legitimate interest of your organisation and of My Keeper in ensuring the safety of individuals and the proper operation of the alert system;
- where applicable, the employer’s legal obligation regarding the protection of lone workers.
Data security
My Keeper implements appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, loss or alteration: hosting of alert data and of the technical operating log within the European Union, encryption of communications, access control and logging. Our processors are subject to equivalent contractual obligations.
Retention and deletion of data
Real-time geolocation (outside an alert) is not retained: it is processed in real time and is not recorded on our servers. Only the last known position is stored on your phone, between two readings, so that it can be transmitted immediately in the event of an alert.
Identification data, alert data, the location of an alert and the associated history are retained for the term of the contract concluded between your organisation and My Keeper.
At the end of the contract, your organisation has 30 days in which to give its instructions. Failing instructions within that period:
- account data (identification of the organisation, of the sites and of the users, and contact lists) are deleted;
- the alert history is anonymised, the location data being deleted, so that the data retained can no longer identify an individual.
Technical data are retained for the periods set out in section 3: 12 months for the technical log, 90 days for crash reports and 14 months for usage data. They are then deleted, or retained in an aggregated form that can no longer identify you. Installation identifiers are erased within a maximum of 180 days from your deletion request. These data are transmitted only after you have agreed, that agreement being obtained when the application is first launched; this choice can be changed at any time in the settings.
You may request the deletion of your data at any time (see sections 7 and 9). Deleting your access to the application erases the data and settings stored on your phone. Alert data, which are attached to the contract concluded between your organisation and My Keeper, follow the periods set out above.
Your rights and how to exercise them
In accordance with the GDPR, you have the rights of access, rectification, erasure, objection, restriction and portability, as well as the right not to be subject to a decision based solely on automated processing.
As the application is deployed by your organisation (the controller), you should exercise these rights with that organisation in the first instance; My Keeper assists it in handling your requests. You may also address your request directly to My Keeper, by email to the Data Protection Officer or to support (see section 9). We respond within the periods laid down by the GDPR.
Your access to SecurIT SOS is activated and administered by your organisation, which determines its scope. You nevertheless have several ways of acting directly: logging out of the application, which preserves your settings; deleting your access from within the application, which erases the data and settings stored on your phone; and requesting the deletion of data concerning you, from within the application or from the dedicated page indicated in section 9, including after uninstallation. We handle your request together with your organisation, as controller. Deleting your access does not delete the alert history retained on behalf of your organisation, whose retention period is set out in section 6.
How to send us a request
Write to dpo@mykeeper.fr stating the subject of your request — access, rectification, erasure, objection, restriction, portability, or withdrawal of the agreement you have given for technical data — and indicating the email address or telephone number associated with your access, so that we can identify your installation. We acknowledge receipt of your request and respond within one month, in accordance with Article 12 GDPR. Where the request concerns data processed on behalf of your organisation, we forward it to that organisation, assist it in handling the request, and inform you accordingly. You may also address your request directly to your organisation.
Recipients, processors and transfers outside the European Union
When an alert is triggered, the information needed to handle it is transmitted: to the contacts designated by your organisation or, depending on the configuration of the application, to a pre-configured emergency number, by message, by call and, depending on the configuration, by email; to your organisation’s supervision interface; and, where the subscribed configuration so provides, to a partner remote assistance centre acting on behalf of your organisation. Where the telephone call is opened automatically, the person or the centre receiving the call hears the sound environment you are in.
Your data are processed by My Keeper (servers located in the European Union, AWS hosting – EU region). Depending on the configuration of the system, they may be processed by the following technical providers, acting as sub-processors:
- Partner remote assistance centre, where the subscribed configuration so provides (handling and response to alerts);
- Mobile operator (routing of messages and calls);
- Google Firebase (notifications and diagnostics) and Sentry (error reporting): these services may involve a transfer of data to the United States, subject to the appropriate safeguards provided for in Chapter V GDPR (standard contractual clauses or certification under the Data Privacy Framework). The details are as follows. The technical operating log is hosted by Google in the European Union. The crash reporting and usage measurement services, by contrast, are operated by Google on a worldwide basis: processing may take place in any of its data centres, including outside the European Union. Incident reports sent to Sentry are processed in the United States; Sentry receives neither your IP address, nor your identity, nor the application usage log. None of these providers receives an advertising identifier.
The list of processors may change; any substantial modification is brought to your attention in accordance with section 10.
Contact
- Data Protection Officerdpo@mykeeper.fr
- Supportsupport@mykeeper.fr — +33 4 83 43 20 32
- Postal addressMy Keeper – Les Espaces de Sophia, 80 route des Lucioles, Bâtiment O, 06560 Valbonne – Sophia Antipolis, France.
Request for deletion of data or exercise of your rights: dpo@mykeeper.fr.
You also have the right to lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), www.cnil.fr.
Changes
We may amend this policy. Any substantial modification is brought to your attention and published on this page, with an update to the date shown at the top of this document.
Language
The French version of this policy is the reference version. This English translation is published for information purposes; in the event of any discrepancy, the French version prevails.