Privacy Policy

Effective Date: 10 September 2026

Last updated: 10 September 2026

Jurisdiction: Kenya

Compliance: Data Protection Act, 2019 & Regulations, 2021

This Privacy Policy explains how Qazeeni("Qazeeni", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use our websites, APIs, and mobile applications (together, the "Services"). Qazeeni is a workforce attendance and time-management platform used by organisations (employers) and their authorised users (admins, agents/site managers, and employees). If you are an employee, Qazeeni typically processes your data on behalf of your employer — your employer is the data controller and Qazeeni is the data processor.

1. Who This Policy Covers

This policy applies to:

  • Organisation administrators and other authorised staff
  • Agents / site managers who record attendance (including by NFC)
  • Employees who check in and out, view attendance, and (where enabled) use automatic check-in/out
  • Website visitors and people who contact us

The Services are intended for workplace use by adults. We do not knowingly collect personal data from children.

2. Personal Data We Process

We process only what is needed to provide the Services. Categories include:

Identity & Employment

  • Full Name
  • Email
  • Phone Number
  • Employee ID
  • Role
  • Branch / Site Details
  • Profile Photo

Attendance & Work Records

  • Check-in / Check-out Timestamps
  • Attendance Method (manual, NFC, automatic)
  • Hours, Leave & Time-off
  • Workplace / Geofence Details
  • Audit Trails

Device, App & Technical

  • Device Type & OS
  • IP Address
  • Push Notification Token
  • Approved-Device Identifier
  • Crash / Diagnostic Data
  • Offline Sync Queues

Communications & Support

  • In-app & Push Notifications
  • Support Messages & Feedback
  • Bug Reports & Attachments

Authentication

  • Hashed Account Credentials
  • Google / Apple Sign-In Identity
  • On-device Biometric Unlock (templates never leave your device)

NFC & Maps

  • Workplace Card UID (NFC)
  • Map & Places Queries (Google Maps/Places)

Location Data

We use location only for attendance and related workplace features — not for advertising, marketing, or selling location data.

  • Foreground location: when you check in or out, or when an admin/agent sets a workplace on a map, we may collect precise location to confirm you are at an approved workplace and to configure geofences.
  • Background location (Active Monitoring): if your organisation enables automatic check-in and check-out, we collect location during your scheduled work hours — even when the app is closed — to detect arrival/departure at your workplace geofence and record attendance if you forget to tap. Collection is limited to power windows set by your employer, not around the clock, and a visible notification may appear on Android while it is running. We request your consent in-app before requesting the system permission; refusing means automatic check-in/out may not work, but manual check-in/out remains available.
  • On-device last-known location: if the app returns to the foreground after being closed, we may use a single last-known location point to fill a gap in attendance samples. We never receive your device's full location history from Google or Apple.
  • Who sees location: location samples and derived attendance events are sent to Qazeeni's servers and made available to your employer for attendance, payroll support, and workplace compliance. They are not sold and are not used to build advertising profiles.

3. Background Running & Notifications

To deliver attendance reliably, the mobile app may — with your permission and where your employer has enabled the relevant feature:

  • Run in the background or as an Android foreground service during work hours
  • Show a persistent notification while work-hour location is active
  • Wake periodically to sync queued check-ins or location samples
  • Ask Android users to allow notifications and, for Active Monitoring, to ignore battery optimisation so the system does not pause the app mid-shift

These capabilities exist to support automatic check-in/out and offline sync only. You can disable notifications, background location, or battery exceptions in system Settings, though doing so may reduce the accuracy of automatic attendance.

4. How We Use Personal Data

  • Provide workforce attendance, time, leave, and related workplace tools
  • Verify check-in/out against a workplace geofence where required
  • Perform automatic check-in/out during scheduled work hours where Active Monitoring is enabled
  • Authenticate users, protect accounts, and prevent fraud or abuse
  • Send operational notifications (shift reminders, approvals, sync status)
  • Support, secure, and improve the Services, including diagnostics
  • Comply with law and respond to lawful requests
  • Process payments or subscriptions with the organisation, billed to the employer

We do not use location or attendance data for third-party advertising. The Android advertising ID is not used.

5. Lawful Basis for Processing

  • Contract : Providing the Services your organisation has signed up for.
  • Legitimate Interests : Security, fraud prevention, service reliability, and product improvement.
  • Consent : Optional permissions such as background location, camera/photos, contacts, notifications, and biometrics.
  • Legal Obligation : Tax, employment-record, or regulatory requirements.
  • Employer's Lawful Basis : Your employer may rely on contract, legitimate interests, or legal duty; Qazeeni processes on their instructions.

You may withdraw consent for optional permissions in the app or device Settings. Withdrawal does not affect processing already completed, or processing your employer still requires under another lawful basis.

6. Data Sharing & Processors

We do not sell personal data. We share data only as needed with:

  • Your organisation — admins and authorised agents who see attendance, location-derived events, and profile data for their organisation
  • Cloud hosting and API infrastructure (api.qazeeni.com and related services)
  • Firebase Cloud Messaging for push notifications
  • Google Maps / Places for maps and address search
  • Google or Apple, if you choose their sign-in
  • Professional advisers and authorities where required by law
  • A successor entity if we merge, restructure, or transfer the business, under equivalent protections

Cross-border transfers outside Kenya are carried out in line with Section 48 of the Data Protection Act, 2019, including safeguards such as Standard Contractual Clauses (SCCs) or equivalent ODPC-recognised mechanisms.

7. Retention

We keep personal data only as long as needed for the purposes above, including:

  • Account & organisation data — for the life of the contract, then a limited backup/legal retention period
  • Attendance & location samples — per your employer's attendance, payroll, and compliance instructions
  • Device queues — until successfully uploaded, or discarded as stale
  • Support tickets & logs — for a reasonable period to resolve issues and maintain security
  • Legal holds — longer where we must keep data for claims, audits, or law

Ask your employer how long they instruct us to keep your attendance records.

8. Security Measures

We use a defence-in-depth approach appropriate to workforce data:

  • Encryption in transit (TLS)
  • Encryption at rest
  • Token-based session authentication
  • Role-Based Access Control (RBAC)
  • Least-privilege production access and monitoring

No method of transmission or storage is 100% secure. You are responsible for keeping your device and credentials safe and for using official app stores.

9. Your Rights (Kenya)

Subject to the Data Protection Act, 2019, you may request to:

  • Access personal data we hold
  • Correct inaccurate or incomplete data
  • Erase data where the law allows
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Data portability, where applicable
  • Complain to the Office of the Data Protection Commissioner (ODPC)

Notice to Employees

Qazeeni processes your data on behalf of your employer. Send access, correction, or deletion requests to your company's HR or IT administrator first; we will support your organisation in responding. Organisation admins and direct customers should contact us directly using the details below. We may need to verify your identity and may refuse or limit a request where the Act allows.

Data Breach Protocol

If we become aware of a personal data breach, we will notify affected client organisations without undue delay and within 72 hours where required, and support ODPC reporting and mitigation in accordance with Kenyan law. Your employer may also have duties to notify affected employees.

10. International Users

The Services are operated with Kenya as the primary jurisdiction. If you access them from another country, your data may be processed in Kenya and in other locations where our processors operate, with the safeguards described in Section 6.

11. Website, Cookies & Third-Party Links

Our marketing or product website may use strictly necessary cookies or similar technologies to run the site and remember basic preferences. If we use optional analytics cookies, we will provide a choice where required. Website forms collect only what you submit, such as name, email, and message. The Services may link to Google Play, the App Store, maps, or other third-party sites whose privacy practices are their own; app store reviews and payments are handled by Apple or Google under their policies.

12. Changes to This Policy

We may update this policy to reflect product, legal, or operational changes. The "Last updated" date will change. Material changes will be posted on this page and, where appropriate, notified in the app or by email to organisation contacts. Continued use after an update means you acknowledge the revised policy.

Contact Our Office

For inquiries regarding this policy or our data practices:

privacy@qazeeni.com

Office of the Data Protection Commissioner (Kenya): www.odpc.go.ke