1. Who we are
We are Duress Pty Ltd (ABN 11 613 710 026), an Australian company with registered office at 420 St Kilda Road, Melbourne VIC 3004. In this document "we", "us" and "our" mean Duress Pty Ltd. "The app" means Duress EVAC on iOS or Android and the closely related web pages it uses, including the confirm-safe link in messages we send you.
Under Australian law we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you live in the European Union or the United Kingdom, we treat the equivalents of those rules as also applying to how we handle your information.
2. What this policy covers
This policy covers personal information we collect about you as an individual when you use the app. Where you use the app on behalf of an organisation — a school, an employer, a venue operator — that organisation has its own responsibilities for the information it holds about you, and its own privacy notice. This policy does not replace that notice.
Some of what the app does involves organisations giving us your contact details so they can reach you in an emergency. Section 4 explains how that works and what happens with your details in that case.
3. What personal information we collect
We collect only what we need to do the four things the app is for: letting you receive alerts from places you follow, letting you ask for help nearby, letting you help someone nearby, and running missing-person alerts inside opted-in venues.
When you sign up and use the app, we collect your email address or phone number so that we can confirm it is you when you sign in from a new device, and so that we can reach you by email or text where you have chosen those channels. We collect the push notification token your phone gives us, so that we can send you push notifications. We collect a display name if you provide one.
When you follow a place, we record that you follow it. That record tells us which alerts to send you, and it tells the place that you are following it — but never anything else about you beyond that a person who confirmed a contact address is now following.
When you sign in at a site as a visitor or a contractor, we record your name, the address you gave, and the departure time you stated, so that the site knows to count you in a drill or an emergency. Where a site uses presence-based counts, this is what makes those counts honest. If you opt in to sharing your position for the length of that visit — which is off by default — we hold that position for the visit and erase it when the visit ends. If you decline, you still receive every alert and still count in the safety numbers, and the site's emergency control team still has enough to look after you.
When you carry something an emergency control team should know about — a reliever, an autoinjector — you may record that carriage on your presence record. This is visible only to the site's emergency control team and only during an active event. It never appears in a signed compliance report, and it is purged when your visit ends.
When you confirm you are safe in response to an alert, we record your answer and the time. You may optionally attach where you are; you may confirm safe without attaching anything.
When you help someone nearby, we hold your position for as long as you are en route to the person who asked. When the ask ends, resolved or cancelled or timed out, your position is erased from the record and the map, and cannot be written back to it afterwards. See §6 of the Terms.
When you raise a nearby-help ask, we hold what you typed (your description, any note), your position for as long as the ask is open, and the responses we receive. When the ask ends, position is erased. We do not retain a history of where you were when you asked.
When you attach a reference photograph to a missing-person alert, and only where you have consented on the screen for the photograph to seed an avatar, that one photograph is sent to an image-generation service to produce the illustration that responders will see. It is not a face-recognition input and it is not retained by us beyond the generation. Three separate consent axes govern the real photograph (whether responders see it, whether security and police may hold it, whether we may keep it for later model improvement), and consent to any one does not imply consent to another.
When we deliver messages, we record delivery attempts and outcomes — attempted, accepted by the carrier, delivered to the device, confirmed by you — so that we can tell honestly whether an alert reached you. The Terms explain why these are kept as four separate numbers rather than one.
4. What we do not collect
We do not collect a location trail of you. We do not build, buy, or infer a history of where you have been. The narrow exceptions to storing any position at all are listed in §3 and each is opt-in, time-bounded, and erased on completion.
We do not read your address book. The app does not ask for your phone contacts and does not upload them. If you have granted contacts access to another app, that access does not reach us.
We do not run face recognition. We do not extract or store face embeddings. We do not re-identify you across camera frames or across devices.
We do not transmit the content of camera frames from the missing-person crowd scan or from any incident-streaming preview. Those features run on your device. The one narrow exception is the reference photograph you deliberately attach to a missing-person alert, as described in §3.
5. Where the information comes from
Most of what we hold, we collected from you directly, when you signed up, when you set a preference, when you responded to an alert, when you typed a description into an ask.
Some information reaches us through an organisation. The most common case is the emergency-contact bulk invite, described in §10 of the Terms: a school or an employer that already holds your details as an emergency contact may ask us to deliver an invitation from them, in their name, offering you the app as a channel for the alerts you nominated yourself to be contacted about. The invitation carries a one-tap decline. If you decline, or if you do not answer, your details are deleted from the invitation pipeline after 30 days. If you accept, the invitation becomes a follow relationship with the place, and from that point on we hold your details on the same basis as any other user.
We do not obtain your details from data brokers, marketing lists, or public scraping.
6. Why we collect it — the purposes
We collect and use your personal information only for these purposes: to operate the app (sign-in, follow-list, presence, alerting, confirm-safe, sweep and accountability, nearby help); to deliver messages (push notifications, emails, text messages, in-app notifications about the places you follow); to let organisations do the safety job the law asks of them (sharing your confirm-safe response with the place you followed, so its emergency control team knows you are accounted for); to keep the service safe (logging, abuse detection, fraud prevention, spam control, protecting other users); and to meet legal obligations (tax and record-keeping requirements, responding to lawful requests from law enforcement or regulators).
We do not use your personal information for advertising, for building profiles about you, or for anything not on this list.
7. Who we share it with
We do not sell your personal information. We do not share it for advertising or marketing. This is a rule, not a preference.
We share personal information with the organisation you have chosen to follow only to the extent that organisation needs to run its drills, incidents and reports. That typically means: that you follow the place, whether you confirmed safe, and (where you have signed in as a visitor) that you are on site. An organisation never receives your address book, your other follows, your position history, or anything about you from outside its own site.
We use a small number of sub-processors to help us deliver the service. Our servers, databases and file storage sit inside Amazon Web Services in Australia (Sydney and Melbourne regions); AWS is a data processor and does not use your information for its own purposes. Push notifications reach your device through Apple Push Notification service (iPhones and iPads) and Google's Firebase Cloud Messaging (Android phones and tablets) — we hold a device token and those services deliver the message to your specific device. Transactional emails are sent through a cloud email service inside the same Australian region. Text messages are sent through a telecommunications provider under an Australian sender-identifier registration. And where you have consented on the screen for a reference photograph to seed a generated illustration, that photograph is sent to an image-generation service; nothing else goes to that service.
Where a sub-processor is outside Australia, we bind it by contract to handle your personal information consistently with this policy and with Australian law. We may share personal information with law enforcement, a regulator, or a court where we are required by law to do so and the request is valid. Where we can lawfully tell you, we will.
We share information we have about you with other Duress corporate affiliates in order to operate and improve products and services and to offer other Duress affiliated services to you. The protections of this policy apply to the information we share in these circumstances.
We may share or transfer information we collect under this policy in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. Where a transaction like that takes place, we will notify you by email or a prominent notice in the app.
8. Where the information is stored
Personal information you give us is stored inside Australia on AWS infrastructure in the Sydney and Melbourne regions. A copy of a small number of long-lived items — for example, the cryptographic key we use to sign compliance reports — is replicated across those two regions so that a regional outage cannot break verification of a report you already hold. Personal information is not routinely copied outside Australia.
Some of the sub-processors listed in §7 process data outside Australia as an inherent property of what they do (for example, push-notification services are global). Where that is the case, we bind those sub-processors by contract to the equivalent of Australian privacy protections.
9. How we protect the information
The technical measures we use include encryption in transit and at rest for personal information; strict database-level access control that isolates one organisation's information from another (row-level security enforced by the database, not just by application code); no long-lived administrative credentials — human access is time-boxed and requires a stated reason recorded in the audit trail; multi-factor authentication for every administrative sign-in; and an append-only audit trail of sensitive actions.
The organisational measures we use include role separation between engineers who can read logs and metrics and the very small number of people who can, temporarily and under audit, reach personal information; a documented incident-response plan; and regular reviews of our own configuration and dependencies.
No system is perfectly secure. If a breach occurs and we believe there is a real risk of serious harm to you, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
10. How long we keep the information
We keep personal information only for as long as we need it, and no longer. The specific periods depend on the category.
Sign-in identifiers (email, phone) are kept while your account is active and deleted (or redacted, per §12) when you close it. Follow relationships are kept while you follow the place and deleted when you unfollow it. Push tokens are kept while your device is registered and are retired the moment we learn the token is no longer valid — for example, if you uninstall the app. Presence records for a visit expire at the departure time you stated, or when you sign out, or when your phone crosses the site's geofence — whichever comes first. Position data during a nearby-help ask is erased when the ask ends. Missing-person reference photographs are deleted after avatar generation unless you have consented to us keeping them for later model improvement.
Signed compliance reports are retained for seven years by default for organisations on paid plans and for thirty days for organisations on the free plan. A compliance report contains a record of who was alerted and who responded, and the retention period reflects the record-keeping obligations that emergency-management law places on organisations.
Suppression records — that you declined an invitation, or opted out of text messages from a place — are retained indefinitely as the lawful exception to deletion. A "do not contact" record has to outlive the reason it was created; otherwise, a fresh upload could re-invite somebody who has already said no.
11. Your rights
You have rights over the personal information we hold about you. You can exercise them from inside the app, or by writing to us at the address in §16.
You can see what we hold about you (Australian Privacy Principle 12). Where practical, the account portal in the app shows you your sign-in identifiers, your follows, your visits, your responses, and the settings you have chosen. Where a request for access needs manual work, we will respond within 30 days.
You can correct information that is wrong (APP 13). Most fields you can edit yourself in the app. Where you cannot, write to us.
You can withdraw consent for any opt-in feature — being asked to help nearby, missing-person alerts, sharing your visit location — at any time, without giving a reason. Withdrawing consent is honoured immediately and does not affect anything you consented to before you withdrew.
You can pause a place so you receive no alerts or drill notices from it, without unfollowing it. A pause never suppresses a genuine live emergency, because pausing at 3pm and being on fire at 4pm cannot mean silence.
You can stop text messages or emails from any specific place using the stop link in the message or your account settings.
You can close your account. When you close your account we delete your personal information, except that information forming part of a signed compliance report is redacted rather than physically deleted. §12 explains the difference.
You can ask for your basic account information in a portable format (data portability). On request we will provide an electronic file of your basic account information — the identifiers, follows and settings we hold — in a format you can move elsewhere.
If you are protected by the European Union General Data Protection Regulation (GDPR) or the United Kingdom's equivalent, you have specific rights: to withdraw consent where you previously gave it, to object to our processing of your personal information, and to ask us to delete or restrict how we use it. Deletion and restriction are subject to some exceptions (see §12 on signed compliance reports) and may affect what parts of the app you can use afterwards.
Do Not Track (DNT). Because there is not yet a common understanding of how to interpret the browser DNT signal, our web pages do not currently respond to it. You can use the account settings in the app and the other tools described in this section to control what we hold and what we send you.
You can complain. §16 sets out how.
12. Deletion and redaction
When you close your account, we delete the personal information that is not part of a signed compliance report — your sign-in identifiers, your device tokens, your follows, your account settings.
Information that is part of a signed compliance report we redact rather than delete. A compliance report is a legal record of who was alerted and who responded during a real emergency or a drill, and the record is signed so that a regulator can verify it years later. Deleting a person from a signed report would change the report and break the signature — which, aside from being unlawful, would defeat the reason the record exists. Redaction replaces your identifying details in the record with a tombstone entry, so that the count remains intact and your identity does not.
Redaction is immediate on close. It cannot be undone.
13. Direct marketing
We do not send marketing messages. We do not use your personal information to profile you for advertising and we do not share it with anyone else for advertising. The only messages we send are the ones the app exists to send — alerts, drill notices, all-clears, confirm-safe requests, transactional replies to something you did in the app — and each channel is opt-in and each message carries a way to stop.
14. Cookies and analytics
The Duress EVAC website and any web pages the app uses (for example, the confirm-safe link) use only the minimum cookies necessary for the page to function. We do not run third-party advertising trackers on these pages. We use privacy-preserving product analytics only where we can do so without collecting personal information beyond what is described in this policy.
15. Children
The app is not directed at individuals under 16. We do not knowingly collect personal information from a child under 16. A parent or guardian may use the app on behalf of a child, and a school may nominate a parent as an emergency contact for a student — those cases are how children are covered by the safety net, and no child's personal information is collected for its own sake. If you become aware that a child has provided us with personal information, please contact our Privacy Officer at the address in §16 and we will take steps to delete it.
16. Complaints and how to reach us
Your information is controlled by Duress Pty Ltd. If you have a concern about how we have handled your personal information, or a question about anything in this policy, please direct it to our Privacy Officer, who we have appointed to be responsible for facilitating such inquiries.
Privacy Officer
Duress Pty Ltd
420 St Kilda Road
Melbourne VIC 3004, Australia
support@duress.com
We will acknowledge a complaint within five business days and give a substantive response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Where you live in the European Union or the United Kingdom, you can also complain to your national data protection authority.
17. Changes to this policy
We may update this policy. Where a change materially affects you — a new use of your data, a new sub-processor category, a shorter or longer retention period — we will notify you in-app and by email if we hold an email for you, at least 14 days before it takes effect. The current version and effective date are shown at the top of this document.
We keep a record of previous versions and will provide any past version on request.
18. Related documents
The Terms and Conditions describe what the app does and how you may use it, and use the same defined words this policy uses. A separate Organisation terms agreement governs any organisation that operates a site or venue on the platform; those terms do not change what this policy says about you as an individual.