Privacy Policy

How Simba Security Service collects, uses, shares, retains, and protects personal data — across our website and across live security operations.

Controlled document
Document reference
3S-SOMS-LEG-003
Revision
00
Effective date
29 June 2026
Document owner
Privacy Officer / Management Representative — SOMS
Approved by
Chief Executive Officer, Simba Security Service

1. Purpose and Scope

Simba Security Service ("3S", "we", "us", or "our") processes personal data in two distinct contexts, and this policy covers both:

  • Our website and commercial relationships — enquiries, quote requests, membership registrations, and client administration
  • Live security operations — video surveillance, access control, visitor management, patrol records, incident reports, and the vetting and management of our own personnel

The second context is where a security company's privacy obligations are heaviest, and it is addressed in detail below. This policy applies to every site we operate and to all personal data we hold, in any format.

2. Who We Are and How to Reach Us

Simba Security Service is a private security company incorporated in the Federal Democratic Republic of Ethiopia and a subsidiary of East African Holding. We act as data controller for the personal data described in section 5, except where we process data on a client's behalf and under their instructions — in which case the client is the controller and we act as processor under a written agreement.

We have appointed a Privacy Officer responsible for this policy, for handling requests and complaints, and for reporting privacy performance into management review. Contact details are in section 22.

3. Legal and Normative Framework

We process personal data in accordance with:

  • Ethiopia's data protection legislation, including the Personal Data Protection Proclamation, and the Computer Crime Proclamation No. 958/2016
  • Applicable labour, private security licensing, firearms, and criminal procedure law
  • The data protection law of any other jurisdiction in which we operate, and the EU General Data Protection Regulation where it applies to a client engagement
  • ISO 18788:2015, which requires that security operations respect privacy and protect the confidentiality of information gathered during operations
  • The International Code of Conduct for Private Security Service Providers and the UN Guiding Principles on Business and Human Rights, under which privacy is treated as a human right subject to due diligence

4. Principles We Apply

  • Lawfulness and fairness — we process data only where we have a lawful basis, and in ways people would reasonably expect
  • Purpose limitation — data collected for security purposes is not repurposed for unrelated ends, and specifically is not used to monitor lawful trade union activity, lawful protest, or protected personal characteristics
  • Data minimisation — we collect the least data required for the security objective
  • Proportionality — surveillance and monitoring are proportionate to an assessed risk, not deployed by default
  • Accuracy — records, particularly incident and vetting records, are kept accurate and corrected when shown to be wrong
  • Storage limitation — data is deleted at the end of the retention period in section 13
  • Integrity and confidentiality — access is restricted, controlled, and logged
  • Accountability — we document our processing and can demonstrate compliance to an auditor

5. Personal Data We Process

5.1 Website visitors and enquirers

  • Name, email address, telephone number, organisation, and job title
  • Service requirements, site details, and the content of your enquiry or quote request
  • Membership registration details where you register for a membership programme
  • Technical data: IP address, browser type and version, pages visited, time on page, referring URL, and device information

5.2 Clients and client representatives

  • Contact and role details for authorised representatives, site contacts, and emergency contacts
  • Contract, billing, and payment records (card details are handled by third-party payment providers, not stored by us)
  • Site risk assessments and post orders, which may name individuals

5.3 Personnel and job applicants

  • Identity, contact, next-of-kin, and right-to-work documentation
  • Employment history, qualifications, references, and licence details
  • Vetting and background screening results, including criminal record checks where permitted by law
  • Medical fitness and, for armed or high-risk roles, psychological suitability assessments
  • Training, competence, weapons qualification, and disciplinary records
  • Attendance, shift, payroll, and leave records

5.4 Operational security data

  • CCTV and video surveillance footage from client sites and our own premises
  • Body-worn camera footage where deployment is authorised and notified
  • Access control records — card, PIN, or biometric entry and exit events
  • Visitor management records — name, organisation, host, identification presented, vehicle details, and time in and out
  • Vehicle data, including registration numbers recorded at gates or by number-plate recognition where deployed
  • Patrol and guard-tour data, including checkpoint scans and geo-fencing location data for officers on duty
  • Control room logs, alarm activations, and recorded emergency calls where recording is notified

5.5 Incident, investigation and use-of-force records

  • Incident reports naming those involved, witnesses, and reporting officers
  • Witness statements and evidence gathered during investigation
  • Use-of-force, firearm discharge, and apprehension records
  • Injury, accident, and near-miss records

5.6 Grievance and whistleblowing data

Reports submitted through our whistleblowing channel, including the content of the report and, where the reporter chooses to provide them, their contact details. Reports submitted anonymously are recorded without identifying data, and we do not attempt to identify anonymous reporters. Whistleblowing records are held separately with access restricted to those handling the report.

5.7 Special categories of data

Some of the above is sensitive and attracts additional safeguards: biometric data used for access control, health and medical fitness data, and criminal record data from vetting. We process these only where there is a specific lawful basis, only for the stated security or employment purpose, under stricter access controls, and — for biometrics — only where a less intrusive method cannot achieve the security objective and an alternative is offered where practicable.

6. Lawful Bases for Processing

  • Contract — to deliver services you or your organisation have engaged us for, and to administer employment
  • Legal obligation — licensing, labour, tax, health and safety, firearms record-keeping, and mandatory incident reporting
  • Legitimate interests — protecting people and property, preventing and investigating crime, verifying that contracted services were delivered, and defending legal claims. We balance these against the rights of the individuals concerned and record that assessment
  • Vital interests — where processing is necessary to protect someone's life or physical safety, including in an emergency
  • Consent — for marketing communications, and for any processing not covered above. Consent can be withdrawn at any time, and we do not rely on consent where a genuine free choice does not exist, such as for our own personnel

7. Video Surveillance, Body-Worn Cameras and Monitoring

Surveillance is the most intrusive processing we carry out, so it is governed by specific controls:

  • Notice. Areas under CCTV are marked with clear signage identifying the operator and a contact point. Body-worn cameras are visible and their use is announced where practicable.
  • No covert surveillance is conducted except where specifically authorised in law, approved in writing by senior management for a defined and documented purpose, limited in time, and reviewed on completion.
  • Prohibited areas. Cameras are never placed in toilets, changing rooms, prayer rooms, medical rooms, or any location where a person has a reasonable expectation of privacy.
  • Field of view is limited to the area needing protection. Cameras are not directed at neighbouring private property or public space beyond what the security purpose requires.
  • Audio recording is not conducted unless separately justified, notified, and approved.
  • Access to live and recorded footage is limited to authorised personnel, granted on a need-to-know basis, and logged. Every viewing, export, and disclosure is recorded.
  • Not for performance monitoring. Surveillance and patrol location data are used for security and service verification, not for covert monitoring of employees. Officers are informed where their location is tracked on duty and for what purpose.
  • Export and disclosure follow section 10 and section 11. Footage is not shared on social media or used for marketing.

8. Privacy Impact Assessment and Proportionality

Before deploying a new surveillance system, biometric access control, body-worn cameras, location tracking, or any materially new form of monitoring, we carry out a documented privacy impact assessment. It records the security objective, why less intrusive alternatives are insufficient, who is affected, the risks to those individuals, and the controls applied. Assessments are reviewed when the deployment changes, and are available to auditors and to clients for their sites.

9. How We Use Personal Data

  • Delivering, supervising, and verifying the security services contracted
  • Preventing, detecting, and investigating crime, security incidents, and breaches of site rules
  • Responding to emergencies and protecting the safety of people on site
  • Recruiting, vetting, training, licensing, supervising, and paying our personnel
  • Managing incidents, grievances, whistleblowing reports, and disciplinary matters
  • Meeting legal, regulatory, licensing, and reporting obligations
  • Responding to your enquiries and administering client relationships
  • Demonstrating conformity with ISO 18788:2015 to auditors and clients
  • Establishing, exercising, or defending legal claims
  • Improving our services and our website, using aggregated or anonymised data wherever it will serve

We do not sell, rent, or trade personal data, and we do not use operational security data for marketing or profiling.

10. Disclosure and Sharing

We share personal data only where necessary, and only with:

  • The client for whose site the data was collected, in accordance with the service agreement — for example incident reports and access logs for their premises
  • Law enforcement and competent authorities, under section 11
  • Subcontractors and service providers — including IT hosting, payroll, background screening, and occupational health providers — bound by written confidentiality and data protection terms, permitted to process only on our instructions, and subject to our right to audit
  • East African Holding group companies, where necessary for governance, insurance, or shared services, under the same protections
  • Our certification body and auditors. Independent auditors — including Intertek in connection with ISO 18788:2015 certification — sample records that may contain personal data in order to verify conformity. Auditors are bound by professional confidentiality obligations, access records under supervision, and do not retain copies beyond what their accreditation requires. This access is a necessary part of independent oversight and is disclosed here so that it is transparent.
  • Professional advisers, insurers, and courts, where necessary to establish or defend legal claims
  • A successor entity, in the event of a merger, acquisition, or transfer of business, subject to equivalent protection
  • Anyone else with your explicit consent

11. Requests from Law Enforcement and Authorities

Disclosure to police or other authorities is controlled, not routine:

  • Requests must be lawful, and made in writing identifying the requesting officer, the legal authority relied on, and the material sought — except in a genuine emergency involving a risk to life, where an urgent verbal request is actioned and documented immediately afterwards
  • Requests are reviewed by authorised management before release, and we disclose only the material actually within the scope of the request
  • Every request and every disclosure is logged, including what was released, to whom, when, and on what authority
  • We do not grant standing or bulk access to our systems or footage
  • Where we may lawfully do so, we notify affected individuals of a disclosure
  • We refuse or challenge requests that lack legal basis, and we do not disclose data where we have reasonable grounds to believe it would contribute to a human rights violation

12. International Transfers

Personal data is primarily held in Ethiopia. Some service providers, such as cloud hosting and email, may process data outside Ethiopia. Where data is transferred across borders, we ensure an appropriate safeguard is in place — an adequacy determination, contractual data protection clauses, or your explicit consent — and we assess whether the destination offers effective protection in practice. Details of transfers relevant to you are available on request.

13. Retention Schedule

We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Data held for an active incident, investigation, grievance, legal claim, or lawful preservation request is retained until that matter closes, even where the period below has expired. At the end of the retention period data is securely deleted, or irreversibly anonymised where retained for statistical purposes.

Retention periods by record category
Record category Retention period Basis
Website enquiry, quote request and contact form data 24 months from last contact Follow-up, service history, dispute defence
Client contract and engagement records Duration of contract plus 10 years Contractual and statutory limitation periods
CCTV and video surveillance footage 30 days, unless retained for an incident or lawful request Purpose limitation — footage not needed is overwritten
Body-worn camera footage 30 days, unless retained for an incident or lawful request As above
Access control, visitor and gate logs 12 months Investigation of security incidents
Patrol, guard tour and geo-fencing location records 12 months Service verification and incident reconstruction
Incident reports and investigation files 7 years from closure Legal defence, regulatory and audit evidence
Use-of-force and firearm discharge records 10 years from the incident Accountability and human rights due diligence
Grievance and whistleblowing records 7 years from closure Pattern analysis, audit evidence, non-retaliation monitoring
Personnel files and training records Duration of employment plus 7 years Employment law and competence evidence
Vetting and background screening records Duration of employment plus 7 years Demonstrating fitness-to-work at time of assignment
Unsuccessful job applicant data 12 months from decision Recruitment defence; deleted thereafter
Occupational health and injury records As required by applicable labour and health law Statutory obligation
Website server and security logs 12 months Security monitoring and abuse investigation

Where a client's service agreement specifies a different period for data we hold on their behalf, that period applies and is recorded in the agreement.

14. Security of Personal Data

We apply technical and organisational measures proportionate to the sensitivity of the data:

  • Role-based access control, unique user accounts, and least-privilege permissions
  • Encryption of sensitive data in transit, and of stored footage and backups where the system supports it
  • Physical security of control rooms, recording equipment, servers, and paper records
  • Logging of access to surveillance footage and sensitive records, with periodic review of those logs
  • Written confidentiality undertakings for all personnel, surviving the end of engagement
  • Data protection and information security training on induction and refreshed periodically
  • Secure backup, tested restoration, and secure destruction of media at end of life
  • Vulnerability management and patching for systems under our control
  • Periodic internal audit of these controls under the SOMS

No system is perfectly secure, and we do not claim otherwise. Where a control fails, section 15 applies.

15. Personal Data Breach Management

A personal data breach — loss, theft, unauthorised access, unauthorised disclosure, or destruction of personal data — is treated as a reportable incident under our incident management procedure.

  • Personnel must report a suspected breach immediately on discovery; delay in reporting is itself a disciplinary matter
  • We contain the breach, assess the risk to affected individuals, and record the facts, effects, and remedial action
  • Where the breach is likely to result in a risk to individuals' rights, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware
  • Where the risk is high, we notify affected individuals directly and in plain language, describing what happened and what they can do
  • Where the breach concerns data we process for a client, we notify that client without undue delay so they can meet their own obligations
  • Every breach is subject to root cause analysis and corrective action under the SOMS

16. Your Rights and How to Exercise Them

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy
  • Rectify data that is inaccurate or incomplete
  • Erase data where we no longer have a lawful reason to hold it
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Object to processing based on legitimate interests, including direct marketing — an objection to marketing is always honoured
  • Data portability, where processing is based on consent or contract and carried out by automated means
  • Withdraw consent at any time where processing is based on consent
  • Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect

How to make a request: contact us using section 22. We will verify your identity before releasing data — this protects you, and we ask only for what is necessary to be satisfied who you are. We respond within 30 days, and will tell you if a complex request needs longer.

Requests for CCTV footage of yourself are accepted. Please tell us the site, the date, and an approximate time, and provide identification, so we can locate the footage within the retention window — a request made after footage has been overwritten cannot be fulfilled. Where footage shows other people, we redact or obscure them before release, or where redaction is not technically possible we may offer supervised viewing instead.

We do not charge for these requests unless a request is manifestly unfounded or excessive, in which case we will explain the reason before proceeding.

17. Complaints, Grievance and Whistleblowing

If you are unhappy with how we have handled your personal data, contact our Privacy Officer first — most issues are resolved quickly. If you would rather raise it confidentially or anonymously, use our whistleblowing channel, which is open to anyone, free of charge, and protected against retaliation as described in our Terms of Service.

You also have the right to complain to the competent data protection supervisory authority in your jurisdiction at any time, whether or not you have raised the matter with us first. Nothing in this policy restricts that right.

18. Cookies and Website Analytics

Our website uses cookies and similar technologies for essential site function, session management on secure areas, and understanding how the site is used so we can improve it. Non-essential cookies are used only where permitted. You can configure your browser to refuse cookies or to alert you when one is set; if you refuse essential cookies, parts of the site may not work.

Website analytics data is used in aggregate. We do not combine it with operational security data, and we do not use it to identify individual visitors.

19. Third-Party Links

Our website links to third-party sites we do not control and whose privacy practices are their own. We are not responsible for their content or their handling of your data — review their policies before providing information to them.

20. Children's Data

Our website and commercial services are not directed to individuals under 18, and we do not knowingly collect personal data from children through them. If you believe a child has provided us with personal data, contact us and we will delete it.

Separately, our surveillance systems at client sites may incidentally record children present at those sites. Such footage is handled under the same controls as all other footage, with particular care over disclosure, and is not used for any purpose beyond security.

21. Changes and Document Control

This Privacy Policy is a controlled document. Amendments are reviewed and approved before issue, take effect on the effective date shown in the document control panel at the top of this page, and are identified by revision number. Material changes are communicated to clients, and to individuals directly where the change significantly affects how their data is used. Superseded revisions are retained in our document register.

22. Contact Us

To exercise a right, ask a question, or raise a concern about personal data:

  • Privacy Officer, Simba Security Service
  • Email: info@simbasecurityservice.com
  • Phone: 0998666644
  • Address: Torhayloch, Near Awash Winery
  • Confidential or anonymous reporting: Whistleblowing channel
  • Service terms and grievance procedure: Terms of Service

Please mark data protection requests clearly so they reach the Privacy Officer without delay.

By using our website and services, you acknowledge that you have read and understood this Privacy Policy. Where we operate at a site you visit or work at, the operational sections above — particularly sections 7, 11, 13, and 16 — describe the rights you hold in relation to footage and records concerning you.