Comiine is operated by Millyjoy & Co (Proprietary) Limited, a company registered in the Republic of Botswana under registration number BW00009256082, of Plot 7414, Mogoditshane, Botswana, trading as Comiine. In this policy, "Comiine", "we", "us" and "our" mean that company.
This policy explains what personal information Comiine handles, why, and what you can do about it. It is written to the Botswana Data Protection Act, 2024 (Act No. 18 of 2024) ("the Act"), which has been in force since 14 January 2025. Botswana's regulator is the Information and Data Protection Commission (IDPC). We also design to the EU General Data Protection Regulation (GDPR) as a stricter benchmark, and we will apply South Africa's Protection of Personal Information Act, 2013 (POPIA) when we operate there.
This policy was prepared in-house. It has not yet been reviewed by a legal practitioner admitted in Botswana. We say that plainly rather than imply an approval we do not have.
An English language version is published here. A Setswana translation will follow.
1. Two roles, and which one applies to you
Comiine handles personal information in two different roles. Which one applies decides who is responsible.
We are the controller for your account and identity information, for device and technical information about your use of the app, for optional crash reports, for product usage events we use to measure and improve Comiine, and for messages you send us. This policy covers that information.
We are the processor for the operational and workforce records that a customer organisation keeps in Comiine. That includes work orders, asset records, meter readings, downtime, inventory, purchasing, safety inspections, photographs and digital signatures, together with the personal information of that organisation's own employees and contractors. For those records, the customer organisation is the controller. It decides why and how they are processed. We process them only on that organisation's documented instructions, under our Data Processing Agreement.
If you are an employee or contractor and your details are in Comiine because your employer uses it, your employer is the controller of your work records. Ask your employer first about access, correction or deletion of those records. If you send the request to us, we will pass it to your employer without undue delay and tell you that we have done so.
2. What we collect
| What | Examples | Where it comes from |
|---|---|---|
| Account and identity | Name, work email, organisation, job role or trade, in-app preferences, and authentication credentials stored in hashed form | You, or your organisation's administrator |
| Device and technical | Device model, operating system version, app version, sync status. Connection details such as IP address and timestamps appear in our hosting providers' service logs | Automatically, when you use Comiine |
| Photographs and signatures | Photos you attach to a record, and signatures you draw when you sign off work | You, when you choose to add them |
| Crash and error diagnostics | Error reports, session health signals and sampled performance data, with personal information removed before sending | Only if you switch crash reporting on. It is off by default and you can switch it off again at any time |
| Product usage events | The name of a core action you take, for example a work order created or completed, downtime recorded, a meter reading taken, an inspection completed, with a timestamp, your organisation, a pseudonymous user identifier, the platform and the app version, plus non-identifying typed details only (numbers, yes or no flags, and fixed category labels) | Automatically, when you take the action. First-party and cookieless |
| Support and correspondence | Messages, feedback and enquiries you send us | You |
Free text is structurally excluded from usage events. Titles, notes, comments, names and photographs are never sent as event properties.
We do not collect your location. Comiine does not collect location in the foreground or the background, and the Android app blocks the fine, coarse and background location permissions outright. The app requests only camera and vibration permissions on Android. It does not request microphone access.
We do not sell personal information, and we do not use it for advertising. Usage measurement is first-party and cookieless. There are no third-party trackers in the app or on our website, no advertising identifier is collected, and no advertising or analytics company receives anything about you.
3. Why we process it, and our lawful basis
Section 26 of the Act sets out the lawful bases for processing personal information. Ours are:
| What we do | Our lawful basis |
|---|---|
| Create and administer your account; deliver, sync and support Comiine | Performance of our contract with you, or with your organisation |
| Keep the service secure, prevent abuse, maintain audit and integrity records, and improve the product | Our legitimate interests, balanced against your rights |
| Meet duties Botswana law places on us, such as tax, company records, and lawful requests | Compliance with a legal obligation |
| Optional features you switch on, being photo storage and crash reporting, and any marketing messages | Your consent, freely given and withdrawable at any time |
We do not treat your consent as the basis for account, security or core service processing. Consent is reserved for things that are genuinely optional. Switching an optional item off never affects core functionality.
Product usage events: two purposes, two controllers
The same events serve two purposes and the responsibility differs.
Your organisation's adoption and data quality view. Your employer sees which work is completed on which platform and how recently each person has recorded work. Your employer is the controller for that purpose and we process on its instructions. Direct questions about it to your employer.
Comiine's own measurement. We measure activation and product usage so we can improve Comiine. We are the controller for that purpose and we rely on our legitimate interests. Our balance rests on this: identifiers are pseudonymous, properties are typed with no free text, collection is first-party and cookieless, no third party receives the data, it is never used for advertising or to profile an individual for our purposes, and it is deleted after 24 months.
You may object to our legitimate interests processing at any time by emailing privacy@comiine.com. For your employer's purpose, contact your employer.
There is deliberately no consent toggle for usage events. In an employment relationship consent is generally not freely given, so consent would not be a sound basis, and a toggle in our app could not stop your employer's own processing. Presenting one would misdescribe the position. The only consent-based diagnostics we collect are crash reports, which stay off unless you switch them on.
4. Who we share it with
We use a small number of service providers to run Comiine. They host our database and files, monitor errors, host our websites, and build and deliver the mobile app. Each processes personal information only on our instructions, under a written contract.
The current list, with each provider's role, the data it handles and where it processes it, is published in our Sub-processor List. We will update that list before we add or replace a provider.
We may also disclose personal information where the law requires it, or to establish or defend legal claims, in each case to the minimum extent necessary.
5. Sending your data outside Botswana
Comiine is operated from Botswana, but the servers that hold your data are not in Botswana. We are direct with you about what that means.
Where your data sits. Our database, authentication and file storage run on Supabase, on Amazon Web Services infrastructure in the United States (region us-east-1). Our crash reporting provider, our web hosting provider and our mobile build and update service also process limited data outside Botswana.
What the law says. The Act governs when personal information may be transferred outside Botswana. One route is a transfer to a country that has been designated as offering adequate protection. Botswana made that designation in the Data Protection (Transfer of Personal Data) Order, 2022, issued on 29 July 2022, which lists roughly forty five countries. It covers the countries subject to the EU GDPR and a number of others, and in Africa it lists South Africa and Kenya.
The honest position. The United States is not on that list. We therefore do not claim that our United States hosting is covered by an adequacy designation, because it is not. What we do rely on is the data protection terms and contractual safeguards we hold with each provider, the fact that we tell every customer organisation exactly where its data is held, and the security measures in section 6 below.
What we are doing about it. We are seeking confirmation from a legal practitioner admitted in Botswana on the correct transfer basis for our position, and on whether the Act requires us to keep a copy of personal data inside Botswana. We do not currently keep a copy inside Botswana, and we will not claim that we do. Moving our hosting to a region inside Africa is on our roadmap. When the position changes we will update this policy, say what changed, and tell customers.
If you want to object to a transfer, or you want to know exactly which provider holds which part of your data, email privacy@comiine.com.
6. How we protect your data
We maintain security measures appropriate to the risk. Described truthfully, they are:
- Encrypted in transit. Connections between the app and our servers use TLS.
- Organisation-scoped access control. Row-level security on the server database means each organisation can reach only its own data. Service credentials are least-privilege and secrets are held in environment stores, never in our code.
- Credentials on your device are held in the operating system's secure key store, not in ordinary app storage.
- Audit integrity. Sign-off and audit records are written to an append-only, hash-chained log, designed so that undetected alteration is evident.
- Storage encryption is provided by our hosting provider at the storage layer on its infrastructure.
An honest limitation about your device. Comiine is offline-first, so a working copy of your data is kept in a local database on your phone or tablet. That local database is not separately encrypted by the Comiine app. It is protected by the operating system's app sandbox and by your device lock. Please set a screen lock, and use your organisation's device management controls where they are available. We do not claim application-level encryption of data at rest on the device.
We describe only measures we have. We will not describe Comiine as certified, audited or accredited unless and until it is.
7. How long we keep it
We keep personal information only as long as we need it. The full schedule is in our Data Retention and Deletion Policy. In short: account information is kept while your account is open and for a short period after it closes; product usage events are deleted after 24 months; crash diagnostics are kept only as long as we need to fix the problem; and operational and workforce records, where your employer is the controller, are kept as your employer instructs and are returned or deleted when the customer relationship ends.
8. Your rights
Under the Act you have the right to:
- be informed about how your personal information is used, which is what this policy is for;
- access the personal information we hold about you;
- have it corrected if it is wrong or incomplete;
- have it erased in the circumstances the Act allows;
- restrict or object to certain processing, including processing based on our legitimate interests and any direct marketing;
- portability, meaning you can receive certain information in a structured, machine-readable form; and
- not be subject to a decision made solely by automated means that has legal or similarly significant effects for you.
Comiine does not make decisions about you by automated means alone. Our scheduling and reporting features produce suggestions and figures for people to act on. No feature decides anything about an individual without a person involved.
To exercise a right, email privacy@comiine.com. We may need to verify your identity first. We respond as quickly as we can, within the time the Act allows, and we aim to reply within 30 days of verifying who you are. If we need longer, we will tell you and explain why. There is no charge, unless a request is clearly unfounded or excessive.
If your request is about work records your employer controls, we will forward it to your employer and tell you.
To delete your account, see our Data Retention and Deletion Policy, which explains how to do it and what happens to records your employer controls. You do not need to be logged in to make that request.
9. Children
Comiine is a workplace tool. Accounts are created by an employer for its workers, and Comiine is not directed to children. We do not knowingly collect personal information from anyone under 18. If a customer organisation's workforce includes anyone under 18, that organisation is the controller of their records and is responsible for the additional conditions that apply to children's data.
10. Complaints
Please contact us first at privacy@comiine.com so we can try to put things right.
You also have the right to complain to the Information and Data Protection Commission (IDPC), Botswana's data protection regulator. The IDPC publishes its channels at www.idpc.org.bw. It has not yet published a permanent public postal address. We will update this section when it does, and if you ask us we will help you route a complaint.
11. Changes to this policy
We may update this policy. When we do, we publish a new version number and date. Where a change is material we take reasonable steps to tell you, and where a change affects the optional items you consented to, the app asks for your consent again.
12. Contact
Data protection contact: privacy@comiine.com General enquiries: game@comiine.com Millyjoy & Co (Proprietary) Limited trading as Comiine, Plot 7414, Mogoditshane, Botswana. Company registration BW00009256082.