1. Introduction
Madibana Endpoint is an enterprise mobile device management (MDM) enrolment agent developed by Madibana SA. It is designed exclusively for use by organisations that have deployed the Madibana MDM platform to manage company-owned or work-profile devices. It is not a consumer application and is not available for general download.
This Privacy Policy explains what information Madibana Endpoint collects, why it collects it, how it is used, and who can access it. By completing the enrolment process, the user acknowledges and agrees to the practices described in this policy.
2. Who Controls Your Data
Madibana Endpoint operates as a data processor on behalf of your organisation (the data controller). All device information collected by the app is transmitted to, and governed by, your organisation's IT administration team. Madibana SA does not independently access, use or retain your personal device data beyond what is necessary to operate the enrolment service.
3. What Madibana Endpoint Collects and Transmits
3.1 Bootstrap Enrolment Data
During the one-time device enrolment process, Madibana Endpoint collects and transmits the following information to your organisation's MDM server:
| Data | Purpose |
|---|---|
| Device IMEI | Uniquely identifies the device within your organisation's MDM inventory |
| Manufacturer model name | Records the device make and model for IT asset management |
| Android OS version | Enables compatibility checks and policy targeting |
| Firebase Cloud Messaging (FCM) push token | Enables the MDM server to securely deliver management commands to the device |
| Pairing code | Authenticates the device to the correct organisational account during enrolment |
| Client version | Records the Madibana Endpoint version used for support and audit purposes |
This data is sent over an encrypted HTTPS connection to dashboard.iforensic.co.za using a one-time registration token issued during the pairing flow.
3.2 What Madibana Endpoint Does NOT Collect
Madibana Endpoint, as a bootstrap agent, does not collect or transmit:
- SIM card details or MSISDN (phone number)
- Device serial number
- Installed application inventory
- Device location or GPS coordinates
- Browsing history, call logs, messages or any personal content
- Biometric data, photos or media files
- Credentials or passwords
3.3 Data Collected After Enrolment
Once enrolment is complete, Madibana Endpoint activates your organisation's full MDM management profile and transfers all device management authority to it.
The capabilities of the management profile are governed by your organisation's IT policy and a separate agreement between your organisation and Madibana SA. Depending on your organisation's configuration, the management profile may collect:
- Application inventory — the list of apps on the device, for compliance and app management
- Device location — periodically, if enabled by your organisation's policy
- Device compliance status — screen lock configuration, OS patch level, encryption state
- Network information — Wi-Fi SSID and connectivity state, for policy application
Your organisation's IT administrator is responsible for disclosing the full scope of monitoring under the management profile. Contact your IT department for details.
4. How We Use the Information
Enrolment data collected by Madibana Endpoint is used exclusively for:
- Device registration — linking the device to your organisation's MDM platform
- Authentication — verifying that the device is enrolling into the correct organisational account
- Support and auditing — diagnosing enrolment failures and maintaining enrolment records for your IT Admins
No data collected by Madibana Endpoint is used for advertising, profiling, analytics, or any commercial purpose unrelated to enterprise device management.
5. Legal Basis for Processing
Madibana Endpoint processes device data on the following bases:
- Contractual necessity — Processing is required to deliver the MDM enrolment service that your organisation has contracted with Madibana SA to provide.
- Legitimate interest — Identifying and registering the device is a necessary step in deploying enterprise management.
- Consent — For direct-install (BYOD) flows, explicit in-app consent is obtained from the user before any data is collected or transmitted.
For devices enrolled through zero-touch or QR provisioning, enrolment is authorised by the organisation as the device owner under the Android Enterprise framework.
6. Data Sharing and Third Parties
Madibana SA does not sell, rent or share device data collected by Madibana Endpoint with any third party for commercial purposes.
Data is shared only with:
- Your organisation's IT Admins, via the MDM server at
dashboard.iforensic.co.za, which is operated by or on behalf of your organisation. - Firebase Cloud Messaging (Google LLC), solely for the purpose of delivering push tokens that enable MDM command delivery. FCM token registration is governed by Google's Privacy Policy.
No other third parties receive device data collected through this app.
7. Data Security
All data transmitted by Madibana Endpoint is:
- Encrypted in transit using HTTPS/TLS
- Authenticated using a one-time server-issued registration token
- Accessible only to your organisation's authorised IT Admins on the MDM dashboard
Madibana SA applies industry-standard security controls to the MDM platform infrastructure. In the event of a data breach affecting your organisation's device records, Madibana SA will notify the affected organisation in accordance with applicable data protection regulations.
8. Work Profile Boundary (Personal Devices)
On personal devices enrolled with an Android work profile:
- Madibana Endpoint and the installed MDM app operate exclusively within the work profile.
- Your organisation cannot access, view or manage personal apps, personal messages, photos, browser history, call logs or any content outside the work profile.
- The work profile can be removed at any time by the device user, which will delete all managed work data from the device. Madibana Endpoint will stop operating upon profile removal.
9. Data Retention
- Enrolment data (IMEI, model, OS version, FCM token) is retained on your organisation's MDM server for the duration of the device's enrolment. It is removed when the device is unenrolled or wiped from the MDM console.
- Madibana Endpoint itself does not maintain a persistent local database of user data after the ownership transfer is complete. Any locally cached enrolment data (stored in app SharedPreferences) is cleared upon app removal.
- Retention periods for data held on the MDM server are governed by your organisation's data retention policy.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, restrict or request deletion of personal data held about you. Since Madibana Endpoint operates as a processor on your organisation's behalf:
- Requests relating to device data on the MDM platform should be directed to your organisation's IT department or Data Protection Officer.
- Requests relating to Madibana SA's data processing practices may be directed to Madibana SA using the contact details below.
11. Children
Madibana Endpoint is an enterprise application intended for use on devices issued to employees or authorised staff. It is not directed at, and should not be used by, individuals under the age of 18.
12. Changes to This Policy
Madibana SA may update this Privacy Policy to reflect changes in the app's functionality or applicable law. When a material change is made, the "Last updated" date at the top of this document will be revised. Continued use of the application following an update constitutes acceptance of the revised policy. Your organisation will be notified of material changes through the MDM dashboard or by email to the registered IT Admin contact.
13. Contact
For privacy-related enquiries regarding Madibana Endpoint:
For questions about how your organisation uses device management data, contact your IT department directly.