Privacy Policy — S-Protokol
Last updated: 2026-06-01 Operator:
Fabricus (s-protokol.rs, contact:
njegos.ignjic@fabricus.tech)
S-Protokol (“the Service”) is a B2B SaaS platform for building
management companies. This policy explains what data we collect, why,
and what you can do about it.
1. Data we collect
1.1 Account data
- Email, full name, role (worker / building manager / company owner /
platform admin), phone (optional), date of birth (workers only),
national ID number (Serbian JMBG, workers only — required for tax
reporting by employer companies)
- Provided by you or by your employer when your account is
created
1.2 Work-order data
- Work order titles, descriptions, statuses, assigned worker,
building, photos attached by the executing worker
- Created by managers and updated by workers as part of their job
1.3 Presence data
- Bluetooth Low Energy (BLE) beacon detections: which beacon
(identifying a specific building) your device detected, and at what
time
- Used to track on-site presence at managed buildings during
shifts
- Collected only while the worker app is installed and the worker is
logged in
- Not collected for managers (manager app does not scan BLE)
1.4 Push notification tokens
- A device-specific token issued by Apple (APNs) or Google (FCM) when
you install the app
- Used to deliver work-order assignments and status updates
- Refreshed whenever your device contacts our servers
1.5 Location
- We do not collect GPS coordinates
- BLE proximity inside managed buildings is the only location-adjacent
data point
2. How we use data
- Operate the Service: deliver work orders, track presence, generate
reports for employer companies
- Authentication and authorization
- Push notifications for new assignments and status changes
- Internal diagnostics (server logs retained 30 days)
3. Sharing
- We do not sell personal data
- Data is shared with your employer company (the entity that created
your account); they see your profile, your work orders, and your
presence records
- We use sub-processors: Hetzner (EU hosting), Firebase Cloud
Messaging (push delivery), Let’s Encrypt (TLS)
4. Retention
- Account data: retained while the account is active; deleted within
30 days of account deletion request
- Work orders + presence: retained 3 years (legal requirement for
employer companies in Serbia and the region)
- Push tokens: deleted when invalidated by the OS or after 90 days of
inactivity
5. Your rights
Under GDPR (and equivalent laws), you can: - Request a copy of your
data - Request correction or deletion - Withdraw consent for processing
(note: this may end your ability to use the Service) - File a complaint
with your local data protection authority
Contact: njegos.ignjic@fabricus.tech
6. Security
- TLS for all transport
- Passwords hashed with bcrypt
- Database access restricted to the application server
- Push tokens stored as opaque strings; not usable without our private
FCM credentials
7. Children
The Service is not directed at children under 16 and we do not
knowingly collect their data.
8. Changes
We may update this policy. The “Last updated” date at the top changes
whenever we do. Material changes are announced via the app.