Back to overview

Privacy Policy

Zabbu Companion Privacy Policy

This Privacy Policy explains how Zabbu Companion, also known as the Zabbu Employee App, collects, uses, stores, and shares information when employees and authorised workplace staff use the mobile application for attendance, workplace presence, visitor management, bookings, notifications, emergency workflows, and related office operations.

Last updated: May 29, 2026
For Android and iOS users of the Zabbu Companion employee app

Overview

Zabbu Companion is a workplace operations mobile application used by employees and authorised staff at organisations that have deployed Zabbu products. The app supports employee attendance, automatic attendance based on workplace geofences, visitor notifications and approvals, visitor pre-registration, meeting space bookings, delivery records, emergency and evacuation workflows, NFC visitor card registration, and related office operations.

In most deployments, Serve Digital provides the app on behalf of an employer, workplace operator, property manager, tenant, or other deploying organisation. That organisation may also act as a data controller for certain personal data processed through the app.

This policy applies to the Google Play app with package name co.zabbu.employee and to corresponding iOS builds where made available.

Who This Policy Applies To

  • Employees and staff who use the app for attendance, visitor, booking, notification, and workplace operations workflows
  • Hosts who receive visitor notifications, approve or decline visitor requests, pre-register visitors, or review visit history
  • Administrators or authorised staff who configure, manage, or support the app on behalf of a deploying organisation
  • Organisations that deploy Zabbu products for their sites, branches, tenants, or workplaces

Information We Collect

1. Account and profile information

  • Full name
  • Work email address or login identifier
  • Phone number, department, role, employee ID, permissions, and workplace assignment
  • Tenant, site, branch, and geofence assignment
  • Profile photo or profile image, if the user chooses to upload one from the device

2. Attendance and workplace presence information

  • Attendance check-in and check-out records
  • Attendance timestamps, work mode, status, and related attendance history
  • Workplace geofence status, including whether the device is inside or outside an assigned workplace geofence
  • Automatic attendance actions created when the app detects arrival at or departure from an assigned workplace
  • Offline attendance events queued on the device for later sync when network connectivity returns

3. Location information

  • Precise location while the app is open or being used for attendance, dashboard map, geofence, or workplace presence features
  • Background location, where supported and enabled, when automatic attendance or emergency-evacuation safety features are turned on and the user grants all-the-time/background location permission (on Android today, and on iOS where these features are enabled)
  • Latitude and longitude sent to Zabbu backend services for manual check-in, manual check-out, automatic attendance, geofence verification, and attendance status checks
  • Assigned workplace latitude, longitude, and geofence radius stored locally on the device to evaluate workplace presence

Background location allows the app to automatically check a user in when they arrive at their assigned workplace and check them out when they leave, even when the app is closed, and to confirm that a user has reached the assigned muster point during an emergency evacuation. On Android this uses a periodic background task and foreground geofence monitoring; on iOS, where these features are enabled, it uses the operating system's geofence region monitoring. In all cases this happens only after the user accepts the in-app disclosure and grants the required operating system permission.

Location data is used only for attendance automation, manual attendance actions, workplace presence verification, dashboard location display, and related safety workflows. It is not used for advertising, sold to third parties, or used for cross-app tracking.

If background location is not enabled, automatic check-in and check-out may not work and users may need to use manual attendance controls.

4. Visitor, NFC card, booking, and workplace operations information

  • Names, contact details, company, and visit purpose of visitors the user is associated with as a host
  • Visitor approval and decline actions taken in the app
  • Pre-registration details entered by the user for expected visitors
  • Visit timestamps and status records
  • NFC visitor card identifiers submitted when an authorised user scans and registers a visitor card
  • Meeting space or room booking details
  • Delivery workflow records submitted through the app
  • Emergency, evacuation, lockdown, and safety workflow records submitted through the app

5. Push notification data

  • Device push notification token used to deliver visitor arrivals, office alerts, emergency alerts, and operational notifications via Firebase Cloud Messaging
  • Notification delivery acknowledgement records
  • Notification metadata such as related record type, related record ID, read state, and message status

6. Device, app, diagnostic, and analytics information

  • Device model, operating system version, and app version
  • Unique device identifier used for session and notification management
  • Crash reports, error logs, stack traces, and diagnostic context used to troubleshoot the app
  • Firebase and Sentry diagnostic or performance data where enabled to maintain reliability and improve app performance

Photo Library, NFC, and Other Device Access

The app may allow a user to choose a profile image from the device photo library or media picker. Selected images may be uploaded to the Zabbu backend as part of the user's profile update.

On supported Android devices, the app may use NFC to scan visitor cards. The app reads the NFC card identifier and sends it to the Zabbu backend only after the user starts a scan and a card is detected.

The reviewed Android app does not request camera permission for QR or camera scanning workflows.

Location Information

Zabbu Companion collects and transmits device location when location-based safety, attendance, geofence, or workplace presence features are used. This can include precise latitude and longitude while the app is open and, where supported and enabled, background location when automatic attendance or emergency-evacuation features are turned on and the user grants background location permission.

Location is collected to determine whether a user is at their assigned workplace, support manual attendance check-in and check-out, support automatic check-in and check-out, confirm that a user has reached the assigned muster point during an emergency evacuation, display the user's current location in the dashboard map, and support workplace safety workflows. Assigned workplace and muster-point coordinates and geofence radius are based on the user's account and site configuration.

The app does not use location for advertising, does not sell location data, and does not use location for cross-app tracking.

How We Use Information

  • Authenticate users and maintain secure sessions
  • Display employee profile, workplace assignment, department, role, permissions, and site information
  • Record manual attendance check-in and check-out
  • Support automatic attendance check-in and check-out using workplace geofences
  • Verify workplace presence for attendance and safety workflows
  • Deliver real-time visitor arrival notifications to the relevant host
  • Enable hosts to approve or decline visitor requests
  • Support pre-registration of expected visitors
  • Display visit history relevant to the user's site or role
  • Support meeting space bookings, delivery workflows, NFC visitor card registration, and emergency or evacuation workflows
  • Send push notifications for visitor events, office alerts, emergency alerts, and operational updates
  • Store limited information locally to support session continuity, offline attendance sync, cached app state, and reliable notification handling
  • Diagnose crashes, fix bugs, and maintain app security and performance
  • Comply with legal obligations and enforce applicable terms and policies

When Location Is Collected

The app requests location permissions incrementally through the operating system. Users can decline location permission or later disable it in device settings, but some attendance automation features may be unavailable or require manual action.

  • When a user performs manual attendance check-in or check-out
  • When the dashboard checks whether the device is inside or outside the assigned workplace geofence
  • When the app displays the user's current location on the in-app dashboard map
  • When foreground geofence monitoring is active after location permission has been granted
  • During an emergency evacuation, to confirm that the user has reached the assigned muster point
  • In the background, where supported and enabled, when automatic attendance or an emergency evacuation is active, after the user has accepted the in-app background location disclosure and granted background/all-the-time location permission (on Android today, and on iOS where these features are enabled)
  • When queued attendance or geofence events are synced after an offline period

Sharing of Information

We do not sell personal information. Information may be shared with:

  • The employing or deploying organisation, who may access employee attendance records, workplace presence records, visitor records, booking records, safety workflow records, and host activity through Zabbu administration tools
  • Infrastructure and service providers, including cloud hosting, Firebase Cloud Messaging, Firebase Crashlytics, Firebase services, and Sentry, who process data on our behalf
  • Legal or regulatory authorities when required by law, court order, or valid legal process
  • A successor entity in the event of a merger, acquisition, or asset transfer, subject to appropriate protections

Third-Party Services

Firebase Cloud Messaging (Google): Used to deliver push notifications to the device. Firebase may process device identifiers and notification tokens. Refer to Google's Privacy Policy for details.

Firebase Crashlytics and related Firebase services (Google): Used for crash reporting, app reliability, and diagnostic information where enabled.

Sentry: Used for error reporting, performance diagnostics, and operational monitoring where enabled.

OpenStreetMap tile services: Used to display map tiles for the in-app location map. Map tile requests may expose standard network request information such as IP address to the map tile service.

Backend API (Serve Digital): Attendance, location, visitor, approval, host, booking, notification, NFC card, delivery, profile, and safety workflow data is transmitted to and stored on Zabbu's backend infrastructure operated by Serve Digital.

Local Storage on the Device

The app stores limited information locally to support sign-in, session continuity, cached app state, notification handling, attendance status display, geofence checks, and offline attendance sync. This can include authentication tokens, profile display information, permissions, site and geofence coordinates, cached attendance/profile data, pending attendance events, push notification tokens, and background location disclosure status.

Some credentials may be stored in secure device storage when a user chooses a remember-me option.

Data Retention

We retain personal information for as long as necessary to provide the app and related workplace services, maintain attendance, visitor, booking, notification, safety, and operational records for the deploying organisation, troubleshoot issues, protect the service, and comply with legal, contractual, employment, tax, and regulatory obligations.

Retention periods may vary depending on the type of information, the deploying organisation's policies, applicable service agreements, and applicable law. When an account is closed or an organisation ends its Zabbu subscription, personal data is handled in accordance with the applicable service agreement and legal requirements.

Security

We apply reasonable technical and organisational security measures, including authenticated API sessions, encrypted data transmission (HTTPS/TLS), role-based access controls, secure device storage for selected credentials, and controlled access to backend systems. No method of transmission or storage is completely secure.

Your Rights

Under the Uganda Data Protection and Privacy Act 2019 and, where applicable, other data protection laws, you have the right to:

  • Request access to personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of personal information, subject to lawful retention obligations
  • Object to or request restriction of certain processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Personal Data Protection Office of Uganda or another competent authority

To exercise your rights, contact your workplace administrator for employer-controlled records, or contact Serve Digital directly using the details below.

Children's Privacy

Zabbu Companion is a business workplace application. It is not directed at children and is not intended for use by individuals under 18.

International Data Transfers

Personal information may be stored or processed in data centres outside Uganda, depending on Serve Digital's hosting and infrastructure providers. Where required, Serve Digital implements appropriate safeguards for cross-border transfers in accordance with applicable law.

Changes to This Policy

We may update this Privacy Policy from time to time. The most current version is available at the URL provided in the Google Play and Apple App Store listings for Zabbu Companion. We encourage you to review it periodically.

Contact

For privacy questions, data requests, or to exercise your rights, contact Serve Digital:

Serve Digital — 4th Floor Acacia Place, Kampala, Uganda. A company of Gold Leaf Holdings (GLH).