Privacy Policy
Last updated: 21 August 2026
1. Introduction
At Fobisoft Solutions Ltd (“Fobisoft”, “we”, “us”), we are committed to protecting your privacy and the personal data entrusted to us. This Privacy Policy explains how we collect, use, store, share and protect personal information when you interact with our website, request a demo, contact us or use our software products and services, including Hospitum, FobiPOS and related platforms.
This notice operates together with our formal governance documents, in particular:
- FB-DPP-002 – Data Protection & Privacy Policy
- FB-ISP-001 – Information Security Policy
- FB-ACP-003 – Access Control Policy
2. Data We Collect
Via our website
- Mobile Phone Number: Collected when you request a demo or require urgent user support.
- Email Addresses: Collected when you contact us through the website’s Contact page or send us an email.
Via our mobile application (DauLabs)
- Google Account information: Collected when you sign in using the Google Account on your device for authentication.
- Mobile Phone Number: Collected when you are prompted to enter it after signing in. This number is used to send notifications and process rewards payouts, including M-Pesa.
In the course of providing our software products and services
We process personal data that our customers, as the data
controllers, enter into our systems. This may include identity,
contact, technical, usage and support information necessary to
deliver the contracted service. Customer data remains the property
of the customer at all times.
3. How We Use Your Data & Legal Bases
We process personal data only for legitimate, specified purposes:
| Purpose | Legal basis |
|---|---|
| Responding to demo requests or support | Consent or performance of a contract |
| Responding to website enquiries | Consent or legitimate interests |
| Authenticating users in the DauLabs mobile application through a Google Account | Performance of a contract or consent |
| Sending notifications and processing rewards payouts, including M-Pesa, in DauLabs | Performance of a contract or consent |
| Delivering, maintaining and supporting our software products | Performance of a contract |
| Security monitoring, fraud prevention and service improvement | Legitimate interests |
| Compliance with legal obligations | Legal obligation |
In line with FB-ISP-001, customer information is never used for marketing, Artificial Intelligence model training, product demonstrations, research or unrelated testing unless we have explicit customer authorisation or another lawful basis under applicable data-protection law.
4. Sharing of Data
- We do not sell, rent or share phone numbers or email addresses collected through the website with third parties for marketing.
- We only share personal data with authorised personnel, approved processors operating under strict contracts, or when required by law or regulators.
- Access is granted strictly according to the principle of least privilege under FB-ACP-003.
5. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. These measures include, but are not limited to, the controls described in:
- FB-ISP-001 Information Security Policy, including encryption in transit and at rest, secure software development lifecycle, encrypted backups and endpoint protection.
- FB-ACP-003 Access Control Policy, including least privilege, identity and access management and periodic access reviews.
6. Retention
We retain personal data only for as long as necessary to fulfil the purposes above, meet legal, regulatory or contractual requirements, or until you request deletion, whichever is earlier. Customer data is securely returned or disposed of at the end of a contractual relationship in accordance with FB-ISP-001 and our Data Retention & Disposal Policy.
In our mobile applications, including DauLabs, users can manage their accounts as follows:
- Temporarily disable: Turn offline visibility off so the account is no longer visible or active online.
- Permanently delete: Request complete deletion of the user account and all related personal data.
Once a permanent deletion request is processed, the account and associated data are permanently removed from our systems, subject only to any limited retention required by law.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your personal data
- Restrict or object to processing
- Withdraw consent at any time
- Lodge a complaint with the Office of the Data Protection Commissioner in Kenya
To exercise any of these rights, email us at security@fobisoft.com .
8. Cookies & Tracking
Our website may use essential cookies necessary for its operation. We do not use non-essential tracking or advertising cookies without your consent. You can control cookies through your browser settings.
9. International Transfers
Where personal data is transferred outside Kenya, we ensure appropriate contractual, technical and organisational safeguards are in place.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page with the updated date. We encourage you to review this policy periodically.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
- Email: security@fobisoft.com
- Phone: +254 727 282 656 or +254 715 576 928