iFleet Africa

Privacy policy

Last updated 6 October 2026. Covers the iFleet web portal (portal.ifleet.africa and your organisation's own address) and the iFleet, iCon and iTask mobile apps.

This policy explains what personal data the iFleet platform handles, why, who receives it, where it is kept, for how long, and your rights. It is written for the people who use the platform in Mauritius and Zambia, and for the people whose details are recorded in it, under the Data Protection Act 2017 of Mauritius and the Data Protection Act 2021 of Zambia.

1. Who we are

The platform is run by Island Communications Ltd, a company registered in Mauritius under business registration number C09018515, with its registered office at 13C, Volcy de la Faye St, Beau Bassin, Mauritius ("we", "us").

We are registered with the Data Protection Office in Mauritius as a controller and a processor. Organisations in Zambia contract with our subsidiary, ICL Zambia Ltd.

For anything about personal data, write to [email protected].

2. Your organisation's role and ours

Most people use the platform through an organisation: their employer, or a company they work for. That organisation is our customer.

  • For what the platform records about vehicles, cameras, buildings, field work and the people your organisation deals with, your organisation decides what is collected, who sees it and how long it is kept. It is the controller. It must use the platform lawfully: telling its staff about tracking and cameras, telling other people whose details it records, and getting consent where the law requires it. We act only on its instructions, under the data-processing terms in our agreement with it.
  • For your account and sign-in details, security records and our customers' business contacts, we decide, so we are the controller.

If you have a question about how your organisation uses tracking or cameras at work, ask it first. We will help it answer you.

3. What we collect

Your account

Your name, work email address, phone number if one is given, job role, and the workspaces you can enter. Your password and the sign-in codes we email you are stored only as one-way hashes that cannot be turned back into the original. If you choose to remember a device, we keep a token for it. If your organisation signs in with Microsoft, we keep the identifier Microsoft gives us; your Microsoft password never reaches us.

Vehicles and driving (iFleet)

Tracking devices in your organisation's vehicles send position, speed, direction, ignition and odometer readings; fuel and engine readings; trips, stops and alerts, such as speeding or entering a place; the driver identified for a trip, for example by an ID tag or card; and panic-button presses. Remote engine-immobiliser commands are recorded with the name of the person who sent them. The platform also calculates driver scores (section 5). When one person usually drives a vehicle, this information shows where that person was and how they drove.

Vehicle cameras

Where your organisation has fitted cameras, we receive the video clips and pictures it asks for, and the live picture while someone watches it. We do not use video to recognise faces.

Vehicle accidents

After an accident, the driver or the office can record a statement of facts. For each vehicle involved, it holds the registration, the insurer, policy and policy holder, and the driver's name, sex, age, address, phone number and driving licence. It also holds where and how the accident happened, with a sketch and photos, witnesses' names and contact details, whether anyone was hurt, and the drivers' signatures. A photo of a paper statement can be kept instead.

Buildings and equipment (iCon)

Sensor readings such as temperature, humidity and energy use; equipment status and alarms; floor plans; and alarm acknowledgements, notes and commands, with the name of the person who made them.

Field work (iTask)

  • Jobs, forms, checklists, notes, signatures, and the photos, short videos and documents you add. A video, up to 30 seconds, is recorded by your phone's own camera app, with sound.
  • Clock-in and clock-out times.
  • Your location when you start a job step, arrive and complete it, and during your working hours and while a job is in progress, at intervals your organisation sets, so your team can see your trip. iTask collects your location only while the app is open, never when it is closed or in the background.

People who do not use the platform

Your organisation can also record details of people who do not use the platform, such as its own customers, the occupants of its buildings, and the other driver and witnesses of an accident. This can include names, contact details, addresses, signatures, photos and answers to its forms and workflows. Your organisation is the controller for these records and must tell these people how it uses their details. They can use their rights with it, or with us (section 10).

Signatures are kept as pictures, with the signer's name and the time. They are not used to check anyone's identity.

Notifications

Your phone's push-notification address, and the emails, text messages and push notifications we send for your organisation (alerts, reminders, sign-in codes and password resets), with whether they were delivered.

Your phone and browser

The apps use the camera only to scan codes and to take the photos and videos you choose to add. Fingerprint and face unlock are handled by your phone, and we never receive that data. iFleet and iCon do not collect your phone's location: the dot showing your own position on the map stays on your phone. The apps and the portal contain no advertising or analytics trackers.

Technical and security records

IP address, browser or app version, the time and nature of actions taken in the platform (an audit trail), and error logs.

AI features

AI Insights is off unless your organisation turns it on. When it is on, your questions and the data needed to answer them are sent to an AI provider. Some features use AI to read documents and photos you upload, such as supplier invoices and equipment labels; they run only when your organisation uses them.

Do you have to give us this information?

Your account details are needed to give you access. Most other data comes from devices and settings your organisation controls. In iTask, location is needed for the job and attendance features your organisation uses; if you turn it off, those features stop working.

4. Why we use it

  • To provide the platform your organisation signed up for: positions and readings, alerts, jobs and reports. Our basis is our contract with your organisation and its legitimate interest in running its operations.
  • To sign you in and keep accounts secure. Our basis is our legitimate interest in a secure service, and our legal obligations.
  • To send notifications your organisation sets up, and service messages such as password resets.
  • To support you and your organisation when something goes wrong.
  • To measure use for billing, such as the number of tracked vehicles, sensors or users.
  • To meet legal obligations, and to establish or defend legal claims.

Where we or your organisation rely on your consent, you can withdraw it at any time; this does not affect what was done before. We do not sell personal data, use it for advertising, or use it to train AI models.

5. Driver scores, alerts and AI

The Driver Scorecard rates driving over a period from events such as speeding, harsh braking and acceleration, night driving and long driving without a break. Your organisation sets how much each one counts, and events are compared with the distance or time driven, so short trips are not scored. Camera alarms can also give a safety score. Alerts flag events as they happen, and AI Insights answers questions from your organisation's data.

These give information to people at your organisation. They do not make decisions about you on their own: a person should review them before acting. You can ask your organisation to have a person look again at any score or event, or dispute an event, and a disputed event that is upheld is removed from your score.

6. Who receives it

Your organisation, and the people it gives access to, see the data in its workspace. We use the providers below to run the platform; each handles only what its job needs, under contract with us.

ProviderWhat it doesWhere
DigitalOceanHosts our servers, databases and stored filesSingapore
BackblazeKeeps an offsite copy of our backupsEuropean Union
CloudflareDomain names, and protection of traffic to the platformWorldwide network
flespi (Gurtam)Receives data from some tracking devices and vehicle cameras and passes it to usEuropean Union (Netherlands)
TwilioSends text messagesUnited States
Amazon Web ServicesSends emailsSingapore
Expo, Google Firebase and AppleDeliver push notifications to phonesUnited States
Google MapsShows maps in the mobile apps, and in the web portal when your organisation chooses Google mapsUnited States
OpenStreetMap and EsriProvide the map pictures in the web portalUnited Kingdom, United States
Anthropic, or an AI provider your organisation choosesAI features, when your organisation uses themUnited States
MicrosoftSingle sign-on, when your organisation uses itWorldwide

We disclose personal data to the police or other authorities only when the law requires it. Where we can, we refer the request to your organisation and tell it first. We may also share it with professional advisers who are bound to confidentiality, and with a buyer of our business, who must keep to this policy.

7. Where it is kept

We store the platform's data in Singapore, with an offsite backup copy in the European Union. Some of the providers above handle data in the United States, the United Kingdom and the European Union.

  • From Mauritius: we transfer personal data abroad only with the safeguards section 36 of the Data Protection Act 2017 requires, such as contract terms that protect it to the same standard.
  • From Zambia: data from organisations in Zambia is also stored in Singapore, under the same contract terms with our providers.

8. How long we keep it

  • Raw messages from tracking devices: 7 days, for troubleshooting.
  • Positions, trips, readings, camera clips, jobs and other records: for the period in your organisation's agreement with us, unless your organisation sets a shorter one.
  • Backups are overwritten on a regular cycle.
  • When an organisation leaves, it can export its data, and we then delete it, unless the law requires us to keep something longer.

9. How we protect it

  • Every connection to the platform is encrypted.
  • Each customer organisation's data is kept in its own database.
  • Passwords and sign-in codes are stored only as one-way hashes, and keys for outside services are encrypted.
  • Access follows the roles and permissions your organisation sets, and actions are recorded.
  • Two-step sign-in with an emailed code is available, and organisations can require it.
  • Uploaded files are checked for malware, and backups are copied to a separate location every night.

If a breach puts personal data at risk, we tell the organisation concerned without delay, and we tell the Data Protection Office in Mauritius, the Data Protection Commissioner in Zambia, and you, as the law requires.

10. Your rights

You have the right to:

  • see the personal data held about you, free of charge;
  • have it corrected;
  • have it deleted, or its use restricted;
  • object to its use. You can object at any time to processing based on legitimate interests, and to direct marketing; we then stop unless the law allows us to continue;
  • receive a copy in a portable format;
  • withdraw consent you have given;
  • ask for a person to review a decision made about you by automated means.

To use these rights, write to [email protected]. If the data is in your organisation's workspace, we pass your request to your organisation and help it answer. We reply within one month, and may first ask you to confirm who you are.

If you are not satisfied, you can complain to the Data Protection Office in Mauritius (dataprotection.govmu.org), or to the Office of the Data Protection Commissioner in Zambia (dataprotection.gov.zm).

11. Cookies and browser storage

The portal keeps your sign-in session and your display choices, such as list layouts and report settings, in your browser. If you ask it to remember your device at the sign-in code step, it sets one cookie for that, for 30 days. There are no advertising or analytics cookies.

12. Children

The platform is for work and is not meant for anyone under 18.

13. Changes to this policy

We post changes on this page and update the date at the top. If a change is significant, we also tell customer organisations, or tell you in the platform or by email.

14. Contact us

Email: [email protected]
Island Communications Ltd, 13C, Volcy de la Faye St, Beau Bassin, Mauritius
In Zambia: our subsidiary, ICL Zambia Ltd

See also our terms of use.