Privacy Policy
Last updated: 21 August 2026
1. Introduction
At Fobisoft Solutions Ltd (“Fobisoft”, “we”, “us”), we are committed to protecting your privacy and the personal data entrusted to us. This Privacy Policy explains how we collect, use, store, share and protect personal information when you interact with our website, request a demo, contact us, or use our software products and services (including Hospitum, FobiPoS and related platforms).
This notice operates together with our formal governance documents, in particular:
- FB-DPP-002 – Data Protection & Privacy Policy
- FB-ISP-001 – Information Security Policy
- FB-ACP-003 – Access Control Policy
2. Data We Collect
Via our website
- Mobile Phone Number: Collected when you request a demo or require urgent user support.
- Email Addresses: Collected when you contact us via our website’s Contact page or send us an email.
Via our mobile application (DauLabs)
- Google Account information: Collected when you sign in using the Google Account on your device for authentication.
- Mobile Phone Number: Collected when you are prompted to enter it after signing in. This number is used to send notifications and to process rewards payouts (including M-Pesa).
In the course of providing our software products and services
We process personal data that our customers (the data controllers) enter into our systems. This may include
identity, contact, technical, usage and support information necessary to deliver the contracted service.
Customer data remains the property of the customer at all times.
3. How We Use Your Data & Legal Bases
We process personal data only for legitimate, specified purposes:
| Purpose | Legal basis |
|---|---|
| Responding to demo requests or support | Consent or performance of a contract |
| Responding to website enquiries | Consent or legitimate interests |
| Authenticating users in the DauLabs mobile app via Google Account | Performance of a contract / Consent |
| Sending notifications and processing rewards payouts (including M-Pesa) in DauLabs | Performance of a contract / Consent |
| Delivering, maintaining and supporting our software products | Performance of a contract |
| Security monitoring, fraud prevention and service improvement | Legitimate interests |
| Compliance with legal obligations | Legal obligation |
In line with FB-ISP-001, customer information is never used for marketing, Artificial Intelligence model training, product demonstrations, research or unrelated testing unless we have explicit customer authorisation or another lawful basis under applicable data-protection law.
4. Sharing of Data
- We do not sell, rent or share phone numbers or email addresses collected via the website with third parties for marketing.
- We only share personal data with authorised personnel, approved processors (under strict contracts), or when required by law or regulators.
- Access is granted strictly on the principle of least privilege (FB-ACP-003).
5. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. These measures include (but are not limited to) the controls described in:
- FB-ISP-001 Information Security Policy (encryption in transit and at rest, secure software development lifecycle, encrypted backups, endpoint protection, etc.)
- FB-ACP-003 Access Control Policy (least privilege, identity & access management, periodic access reviews)
6. Retention
We retain personal data only for as long as necessary to fulfil the purposes above, to meet legal, regulatory or contractual requirements, or until you request deletion (whichever is earlier). Customer data is securely returned or disposed of at the end of a contractual relationship in accordance with FB-ISP-001 and our Data Retention & Disposal Policy.
In our mobile applications (including DauLabs), users can manage their accounts as follows:
- Temporarily disable: Turn offline visibility off so the account is no longer visible or active online.
- Permanently delete: Request complete deletion of the user account and all related personal data.
Once a permanent deletion request is processed, the account and associated data are permanently removed from our systems (subject only to any limited retention required by law).
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your personal data
- Restrict or object to processing
- Withdraw consent at any time
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya
To exercise any of these rights, please email us at security@fobisoft.com.
8. Cookies & Tracking
Our website may use essential cookies necessary for its operation. We do not use non-essential tracking or advertising cookies without your consent. You can control cookies through your browser settings.
9. International Transfers
Where personal data is transferred outside Kenya, we ensure appropriate safeguards (contractual, technical and organisational) are in place.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page with the updated date. We encourage you to review this policy periodically.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Email: security@fobisoft.com
- Phone: +254 727 282656 or +254 715 576 928