Privacy Policy for Zentry Authenticator

Effective Date: July 1, 2026

Zentry Authenticator is a mobile multi-factor authentication application developed by Domiveon Limited (“Domiveon,” “we,” “us,” or “our”). This Privacy Policy explains how Zentry Authenticator collects, uses, stores, and protects information when you use the app.

Domiveon Limited is located at Plot 7 Lourdel Road, Kampala, Uganda. You may contact us at zentry@domiveon.com.

1. Information We Collect

Zentry Authenticator is designed to minimise the collection of personal data. The app primarily stores
authentication credentials and security information locally on your device.

Depending on how your organisation configures Zentry, the app may process:

  • Account or identity labels, such as issuer name, account name, username, or email address shown inside the app.
  • Authentication token metadata, such as token identifier, issuer, algorithm, digit count, and validity period.
  • Encrypted token secrets are used to generate one-time passcodes.
  • Device identifiers or trusted-device binding identifiers are used to register the device with a Zentry server.
  • Push notification tokens, including Firebase Cloud Messaging tokens and platform notification tokens.
  • Security state information, such as biometric unlock status, failed unlock attempts, and token lock status.
  • Basic technical information, such as app version, device model, operating system version, and platform type.

The app may request access to:

  • Camera: to scan activation QR codes.
  • Biometric authentication: to unlock protected authentication tokens.
  • Push notifications: to receive MFA approval requests.

We do not use the camera, biometrics, or notifications for advertising or tracking.

2. Information Stored Locally on Your Device

Zentry Authenticator stores authentication tokens and secrets on your device using platform security features such as Android Encrypted Storage, Android Keystore, iOS Keychain, and biometric protection, where available.

Your one-time password secrets are intended to remain protected on your device. Domiveon does not use Zentry Authenticator to collect your device biometrics. Biometric authentication is handled by your device’s operating system.

3. Information Sent to Zentry Servers

When you activate a token, register a trusted device, or respond to a push MFA request, the app may communicate with a Zentry server operated by Domiveon or by your organisation.

This communication may include:

  • Device binding identifier.
  • Public key or device registration information.
  • Push notification token.
  • Token or approval identifiers.
  • Approval or denial decisions for MFA requests.
  • App and device security metadata are needed to protect authentication flows.

4. Firebase Cloud Messaging

Zentry Authenticator uses Firebase Cloud Messaging to deliver push notification requests on Android and may use Firebase services for push notification support on iOS.

Firebase may process technical identifiers such as push tokens and device/app instance information to deliver notifications. Firebase is provided by Google. Google’s privacy practices are described at https://policies.google.com/privacy. Zentry Authenticator does not use Firebase for advertising in the app.

5. How We Use Information

We use information processed by Zentry Authenticator to:

  • Activate and manage authentication tokens.
  • Generate one-time passcodes.
  • Deliver push-based MFA approval requests.
  • Register and validate trusted devices.
  • Protect token access with PINs and biometrics.
  • Detect and prevent unauthorised access or misuse.
  • Maintain, debug, and improve the service’s reliability and security.
  • Comply with legal, security, and operational obligations.

6. Sharing of Information

We do not sell personal information.

We may share or process information only in limited circumstances:

  • With your organisation or administrator, where Zentry is used as part of an enterprise authentication system.
  • With service providers necessary to operate the app, such as Firebase Cloud Messaging.
  • When required by law, regulation, legal process, or governmental request.
  • To protect the rights, safety, and security of users, customers, or the public.

7. Data Retention

Data stored locally in the app remains on your device until you delete tokens, reset the app, uninstall the app, or your organisation revokes access.

Data sent to a Zentry server is retained according to Domiveon’s or your organisation’s security, audit,
and operational retention policies. MFA events may be retained for security auditing and fraud prevention.

8. Security

We use technical and organisational safeguards designed to protect authentication data. These may include encryption, secure device storage, trusted-device binding, signed approval flows, transport security, and access controls.

No system can be guaranteed to be completely secure. You should protect your device with a strong passcode and keep your operating system updated.

9. Your Choices and Controls

You may:

  • Disable push notifications through your device settings.
  • Disable biometric unlock in the app or device settings where supported.
  • Delete tokens from the app.
  • Reset the app to remove locally stored app data.
  • Contact your organisation’s administrator to revoke a device or token.
  • Contact Domiveon using the email below for privacy questions.

10. Children’s Privacy

Zentry Authenticator is intended for enterprise and organisational authentication use. It is not directed to children and is not intended for use by children under the age required by applicable law.

11. International Data Processing

Domiveon Limited is based in Uganda. Depending on your organisation’s deployment and service providers, information may be processed in Uganda or other countries. We take reasonable steps to protect information in accordance with this Privacy Policy and applicable law.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and make the revised policy available at the hosted web URL.

13. Contact Us

Domiveon Limited
Plot 7 Lourdel Road
Kampala, Uganda
Email: zentry@domiveon.com