Privacy Policy
Last updated: September 2026
1. About This Policy
This Privacy Policy explains how EMCorp Group Pty Ltd (ABN 21 106 612 800) ("EMCorp", "we", "us", "our") collects, uses, discloses, and protects personal information through the EMAction emergency management platform ("Platform"), the EMAction mobile application ("App"), and the emaction.io website. We are committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Information We Collect
We collect the following types of personal information in the course of providing the Platform:
- Account information: name, email address, mobile phone number, role, and building/site assignment
- Emergency check-in data: check-in status, timestamps, GPS location (when voluntarily shared), and warden notes
- Lone worker session data: visit destination and address, scheduled and actual visit times, expected duration, session status, safety notes, GPS location during a monitored session (when voluntarily shared), and any hazard reports submitted during a visit
- PEEP (Personal Emergency Evacuation Plan) data: mobility classifications, sensory/cognitive classifications, medical/equipment dependencies, and evacuation priority levels
- Communications: SMS messages, in-app chat messages, and email correspondence sent through the Platform during incidents and lone worker sessions
- Media: photos and videos uploaded during incidents and lone worker sessions
- Contact form submissions: name, email, phone, company, and any additional information provided via the demo request form on emaction.io
- Technical data: browser type, device information, and IP address collected automatically when you access the Platform
3. How We Use Your Information
We use personal information to:
- Operate the EMAction Platform and provide emergency evacuation management services to your organisation
- Monitor lone worker sessions, raise overdue and duress alerts, and escalate alerts to your organisation's nominated monitoring contacts
- Send SMS notifications and alerts during emergency incidents
- Display your location on the incident map or lone worker monitor when you have voluntarily enabled GPS sharing
- Generate incident reports, audit trails, and compliance documentation
- Provide AI-assisted situational analysis during incidents (see AI Processing below)
- Respond to demo requests and enquiries
- Improve the Platform's functionality and reliability
4. GPS Location Data
GPS location sharing is entirely voluntary and is used in two contexts:
- Incident check-ins: when you check in during an incident, you may be prompted to share your device location. If you grant permission, your location is updated periodically and displayed on the incident map to assist wardens and incident controllers.
- Lone worker sessions: when you start a monitored lone worker session, you may be prompted to share your device location for the duration of the session. If you grant permission, your location is visible to your organisation's monitoring staff so they can respond if you raise an alert or become overdue. Location tracking stops when the session ends.
You can revoke location access at any time by disabling location permissions in your device or browser settings. GPS data is stored as part of the relevant incident or lone worker session record and its associated reports.
5. Mobile Application
The EMAction App provides the same Platform functionality on Android and iOS devices. The App requests the following device permissions, each only when the corresponding feature is used, and each of which you may decline or later revoke in your device settings:
- Location — for incident check-in maps and lone worker session monitoring, as described above
- Camera and microphone — for capturing photos and videos of incidents and site hazards
- Photos and files — for uploading existing media to an incident or lone worker session
The App does not collect any information beyond what the Platform collects, and does not include third-party advertising or analytics software.
6. AI Processing
EMAction uses Anthropic's AI services to provide situational awareness analysis, warden message interpretation, notification drafting, incident summary generation, and automatic tagging of uploaded incident photos (for example, identifying smoke or a blocked exit). Data sent to the AI service includes incident timeline entries, check-in statistics, warden messages, and uploaded media. Photo analysis is instructed not to identify or describe specific individuals. This data is processed under Anthropic's commercial terms, is not used to train AI models, and may be retained by Anthropic only for a limited period for abuse-monitoring purposes.
7. Disclosure of Information
We may share personal information with:
- Your organisation: EMAction is deployed on behalf of building owners, facility managers, and employers. Your organisation's administrators have access to incident data, check-in records, lone worker session records, and audit logs
- Service providers: Twilio (SMS delivery), Anthropic (AI processing), and Aussie Web & IT Solutions (hosting) for the purpose of operating the Platform
- Optional integrations enabled by your organisation: where your organisation connects EMAction to its own systems — such as Salesforce (visit scheduling) or RLDatix RiskMan (incident and hazard compliance records) — relevant data is exchanged with those systems under your organisation's own agreements with those providers
- Emergency services: if required by law or in a genuine emergency where there is a serious threat to life or safety
- Regulatory authorities: where required under WHS legislation or other applicable laws
We do not sell personal information to third parties.
8. Data Security
We implement appropriate technical and organisational measures to protect personal information, including encrypted data transmission (HTTPS/SSL), two-factor authentication for warden and admin accounts, role-based access controls, and tamper-resistant audit logging. However, no method of electronic transmission or storage is 100% secure.
9. Data Retention
Incident data, check-in records, and lone worker session records are retained for the period required by your organisation's compliance obligations and applicable WHS legislation. Account information is retained for the duration of your organisation's subscription. Contact form submissions are retained for a reasonable period to respond to your enquiry.
10. Your Rights
Under the Australian Privacy Principles, you have the right to access the personal information we hold about you and request correction of any inaccurate information. You may also request deletion of your account and associated personal information. Because EMAction accounts are administered by your organisation, requests should be made to your organisation's EMAction administrator in the first instance, or to us directly using the details below; we will action deletion requests subject to your organisation's legal record-keeping obligations.
11. Contact Us
If you have questions about this Privacy Policy or wish to make a privacy complaint, please contact:
EMCorp Group Pty Ltd
PO Box 748, Bondi Junction, NSW Australia 1355
Email: info@emcorp-group.com
Phone: 1300 855 812