Privacy Policy
Your privacy.
Last updated: July 29, 2026
This policy describes what OPA actually collects and how it is actually used, based on the platform as built today. It is a draft prepared for legal review and has not yet been finalized by a qualified attorney. Do not treat this page as a completed legal instrument until that review is complete.
Who we are
OPA Technologies Limited (“OPA,” “we,” “us”) operates the OPA emergency coordination platform. This policy applies to the OPA mobile application, the OPA website, and related services.
Information we collect
Account information
When you create an account, we collect your email address, phone number, first and last name, and a securely hashed version of your password. We never store your password in readable form.
Emergency contact information
If you add emergency contacts, we collect their name, relationship to you, phone number, and, if provided, email address. You are responsible for having the appropriate permission to share a contact's information with us.
Incident and location information
When you activate an emergency, we collect your GPS location (latitude, longitude, and accuracy), the type of trigger used, and, where available, a resolved street address. This data is tied to the specific incident you activated, not collected continuously in the background.
Evidence
OPA's platform supports attaching evidence files to an incident. Where evidence is uploaded, it is hashed with SHA-256 at the point of upload and stored in encrypted Azure Blob Storage. Downloads use short-lived, signed links rather than permanent public URLs.
Hospital and facility staff information
If you are a hospital staff user, your account is associated with a specific facility, and your access to incident data is limited to incidents routed to that facility.
What we do not currently collect
OPA does not currently collect medical information such as blood type, allergies, or known conditions, and the mobile application does not currently capture audio, video, or photo evidence automatically. If these capabilities are added in the future, this policy will be updated before they are enabled.
How we use your information
- To create and secure your account.
- To notify your emergency contacts and, where applicable, hospital staff when you activate an emergency.
- To build the Survival Timeline, a tamper-evident, hash-chained record of what happened during an incident.
- To route incidents to the appropriate facility, where facility routing applies.
- To respond to support requests you send us.
Third-party service providers
We use the following providers to operate OPA. Each receives only the information necessary to perform its function.
- Africa's Talking — SMS and voice call delivery.
- Resend— email delivery.
- Meta (WhatsApp Business Platform) — WhatsApp message delivery, where enabled.
- Microsoft Azure— database hosting and evidence file storage.
Data security
- Passwords are hashed and never stored in readable form.
- Authentication uses short-lived access tokens with a separate refresh mechanism.
- Access to incident data is verified against your current role and facility assignment on every request, not cached.
- Evidence files are integrity-verified with SHA-256 hashing and stored in encrypted cloud storage.
- Every incident produces a hash-chained timeline designed to make unauthorized modification detectable.
Data retention
We are finalizing a formal data retention schedule. Until it is published here, incident, evidence, and account data is retained as needed to operate the service and is not automatically deleted on a fixed timeline. If you would like your data deleted sooner, contact us at privacy@opasafety.com and we will process the request manually.
Your rights
Depending on where you are located, you may have rights to access, correct, or request deletion of your personal data. OPA is built for Nigeria first and intends to align with the Nigeria Data Protection Act. We do not yet offer a self-service tool for these requests; in the meantime, email privacy@opasafety.com and we will respond directly.
Children's privacy
OPA is not directed at children and is not intended for account creation by anyone under the age of 18. A minor may be listed as an emergency contact by an adult user.
Changes to this policy
We may update this policy as the platform develops. Material changes will be reflected on this page with an updated date at the top.
Contact us
Questions about this policy or your data can be sent to privacy@opasafety.com.