Before publishing this page: this document is a thorough starting draft, not certified legal advice. Pakistan does not yet have an enacted, comprehensive data-protection law (PECA 2016, as amended 2025, addresses electronic-crime misuse of data; the Personal Data Protection Bill remains in draft). This policy is written to align with that draft Bill's principles and with international best practice (GDPR-style) as a responsible baseline. Because this product handles biometric data and can handle location data โ both high-sensitivity categories โ please have a Pakistani lawyer review and adapt this before it governs a real client's employees or customers.
1. Who We Are
This Privacy Policy is issued by ZeeTech AI Security ("we", "us", "our"), the developer and operator of the following products, referred to together as the "Services":
- Zee AI Vision โ AI-based camera object/person detection, zones, line-counting, and alerting.
- Wahand โ face-recognition attendance for employees, students, or other enrolled individuals.
- Geofence Employee Location โ location-based verification of an employee's presence within a defined work area during work hours.
This policy applies to the business or organization that licenses our Services ("Client", "you") and, where relevant, to the individuals whose data the Services process on the Client's behalf โ employees, students, customers, or visitors ("Data Subjects"). Where our Services process personal data belonging to a Client's employees or customers, the Client is the data controller and we act as a data processor on the Client's instructions, unless stated otherwise.
2. Data We Collect, By Product
2.1 Zee AI Vision โ Object & Video Detection
- Live video frames from the connected webcam, IP camera, or screen-share source, processed in real time to detect objects, people, and events.
- Detection metadata โ object type, confidence score, timestamp, and zone/line the event occurred in.
- Snapshot images attached to email/WhatsApp alerts and saved scan history, when this feature is enabled.
- Camera configuration โ zone shapes, counting lines, and the objects a user has chosen to watch for.
Where this processing happens matters, and it is under the Client's control:
- When a local AI engine is selected (TensorFlow.js, YOLOX, YOLO11n, or MediaPipe), video frames are analyzed entirely within the user's own browser. No video or image data is transmitted to us or to any third party for detection itself.
- When the Roboflow cloud engine is selected instead, individual video frames are sent to Roboflow Inc.'s inference servers to obtain detection results. See Section 6 (Third Parties) below.
2.2 Wahand โ Face Recognition Attendance
- Facial biometric data. During enrollment, the system captures roughly 20 image samples of an individual's face across a few natural head angles and computes a mathematical face descriptor (a numeric representation of facial geometry) from them. This descriptor โ not necessarily a viewable photograph โ is what gets stored and used for later recognition.
- An enrollment photo may optionally be stored alongside the descriptor for the Client's own record-keeping/verification purposes.
- Attendance records โ the enrolled individual's name, and the date/time their face was matched by the system.
Facial biometric data is treated by this policy as sensitive personal data requiring a higher standard of care. See Section 4 (Consent) below โ enrollment must never happen without the individual's clear, informed, opt-in agreement.
2.3 Geofence Employee Location
- Device location data (GPS coordinates or network-based location) from an employee's phone or device, checked against a defined geographic boundary ("geofence") set by the Client.
- Entry/exit timestamps โ when the employee's device entered or left the defined work area.
- Location is intended to be checked only during the employee's configured work hours, for the specific purpose of attendance/presence verification โ not for continuous, off-hours, or personal-life tracking. A Client's specific configuration should always be checked against this intent before deployment.
3. How We Use the Data
Data collected through the Services is used only for the purposes the Client configures the system for, principally:
- Detecting and alerting on security-relevant events (Zee AI Vision).
- Verifying identity for attendance or access purposes (Wahand).
- Confirming an employee's physical presence at a worksite during work hours (Geofence).
- Generating the Client's own reports, logs, and alert history within their account.
- Maintaining, securing, and improving the Services themselves.
We do not sell personal data. We do not use facial biometric data or employee location data for advertising, profiling, or any purpose beyond what the Client has configured the Services to do.
4. Consent โ Especially For Biometric & Location Data
Because facial biometric data and precise location data are sensitive, the Client (as data controller) is responsible for obtaining clear, informed, opt-in consent before enrolling any individual in Wahand or enabling Geofence tracking for them. At minimum, that means:
- Telling the individual, before enrollment, exactly what is being collected (their face data, or their location during work hours) and why.
- Obtaining their explicit agreement โ a signed form, a digital opt-in, or an equivalent clear record โ not just an implied "they showed up to work so they agreed."
- Allowing the individual to ask questions and, where feasible, offering a non-biometric alternative (e.g. a manual sign-in) for anyone who does not wish to enroll their face.
- Letting the individual withdraw consent later โ see Section 8 (Your Rights).
Children & educational institutions: if Wahand is deployed in a school, madrassah, or any setting involving individuals under 18, parental or guardian consent is required in addition to โ not instead of โ the student's own assent where age-appropriate. Schools should not enroll a student's face without a parent/guardian being clearly informed and given the opportunity to decline. This is a stricter standard than for adult employees, and it should be treated as non-negotiable, not a formality.
5. Data Storage & Security
- Data is stored within the Client's own WordPress database, on hosting the Client controls or has chosen.
- Face descriptors, enrollment photos, attendance logs, and location logs are scoped to each user's own account โ one Client's data is not visible to another.
- Data in transit to third-party services (see Section 6) is sent over encrypted HTTPS connections.
- Access to enrolled biometric data and location logs should be restricted, on the Client's side, to personnel who genuinely need it (e.g. HR/security administrators) โ not exposed broadly within the organization.
- No system is 100% immune to breach. In the event of a data breach affecting biometric or location data, affected individuals and, where applicable, the relevant authority should be notified without undue delay.
6. Third Parties We May Share Data With
Depending on which features a Client enables, data may be sent to:
- Roboflow Inc. โ only if the Client selects the Roboflow cloud detection engine (not the local/on-device engines). Individual video frames are sent to Roboflow's servers to return detection results. Roboflow's own privacy policy governs their handling of this data; the Client should review it directly before enabling this engine, particularly for sensitive locations.
- WhatsApp / Meta Platforms, Inc. โ if WhatsApp alerts are enabled, alert messages and any attached snapshot images are transmitted through WhatsApp's Business API/Twilio infrastructure to reach the configured recipient numbers.
- Email delivery infrastructure โ alert emails are sent via the Client's configured WordPress mail delivery (which may be the hosting provider's own mail service or a third-party SMTP provider the Client has configured).
- We do not otherwise sell, rent, or share personal data collected through the Services with advertisers or data brokers.
7. Data Retention
- Live video frames processed for detection are not retained after processing, except where a snapshot is explicitly saved to scan history or attached to an alert.
- Facial biometric descriptors and enrollment photos are retained for as long as the individual remains enrolled (e.g. remains an employee or student), and should be deleted promptly once that relationship ends โ see Section 8.
- Attendance and location logs should be retained only as long as reasonably needed for the Client's payroll, compliance, or record-keeping purposes, then deleted or anonymized.
- Clients are responsible for setting retention periods appropriate to their own legal/regulatory obligations and for actually enforcing deletion once those periods pass.
8. Your Rights
Any individual whose data is processed by the Services โ an employee, student, or enrolled user โ may ask the Client (as data controller) to:
- Access a copy of the personal data held about them.
- Correct inaccurate data (e.g. a misspelled name on an attendance record).
- Delete their enrolled face data and be removed from facial recognition entirely โ enrolled faces can be deleted from the system's Face Recognition management screen at any time.
- Withdraw consent for location tracking or face enrollment going forward, subject to any separate, legitimate employment/attendance-policy requirements the Client may have.
Requests should be directed to the Client organization first, since they control the data as data controller. Where ZeeTech AI Security operates a system directly, requests can be sent to the contact details in Section 11.
9. International Data Transfers
Where the Roboflow cloud engine is used, video frames may be processed on servers located outside Pakistan. Clients operating in or processing data of individuals in jurisdictions with cross-border transfer restrictions should confirm this is acceptable for their use case, or use a local/on-device detection engine instead, which keeps all video processing on the local device.
10. Changes to This Policy
We may update this policy as the Services change or as Pakistani data protection law develops (including if the Personal Data Protection Bill is enacted). Material changes will be reflected by updating the "Last updated" date at the top of this page.
11. Contact Us
For privacy questions, data access/deletion requests, or to report a concern: