Last Updated: 6 August 2026
1. Acceptance of Terms
These Terms of Service ("Terms") constitute a legally binding agreement between you ("Customer", "you", or "your") and EKAMA ("Provider", "we", "us", or "our"), governing your access to and use of the EKAMA Security Operations Platform ("Platform" or "Service"). By accessing, registering for, or using the Platform in any capacity, you acknowledge that you have read, understood, and agree to be bound by these Terms in their entirety. If you are using the Platform on behalf of an organisation, you represent and warrant that you have the authority to bind that organisation to these Terms.
These Terms apply to all users of the Platform, including but not limited to System Administrators, Security Supervisors, Security Officers, Employees subject to attendance verification, and any authorised personnel granted access by an institution operating on the Platform. Your continued use of the Service following the posting of any amendments to these Terms constitutes your acceptance of such amendments.
2. Definitions
"Platform" means the EKAMA Security Operations Platform, a web-based software application comprising an administrative dashboard, a mobile interface for field personnel, and all associated modules, features, and functionalities as described in the system documentation.
"Institution" means any client site, organisation, or entity registered on the Platform to manage its security operations, including but not limited to healthcare facilities, educational institutions, corporate real estate, industrial sites, hospitality venues, and government facilities.
"Biometric Data" means facial photographs and associated facial geometry templates captured through the Platform's AI-powered face verification module for the purpose of employee identity verification during attendance marking.
"GPS Data" means geolocation coordinates, routes, and location timestamps captured by the Platform through officer mobile devices during patrol operations and attendance marking.
"Incident Data" means all information submitted through the incident reporting module, including but not limited to textual descriptions, photographic evidence, voice recordings, GPS-tagged locations, severity classifications, and investigation status records.
"Confidential Information" means all non-public information disclosed by either party, including but not limited to proprietary software code, system architectures, security configurations, institutional patrol data, employee personal data, and business strategies discussed in connection with the Service.
3. Licence Grant & Permitted Use
Subject to your compliance with all terms and conditions set forth herein and the timely payment of all applicable fees, the Provider grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Platform solely for the purpose of managing your organisation's security patrol operations, workforce attendance, incident reporting, and related activities as authorised under your subscription or licence agreement.
You shall not: (a) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Platform; (b) modify, adapt, or create derivative works based on the Platform; (c) rent, lease, lend, sell, or redistribute the Platform to any third party; (d) circumvent, disable, or interfere with any security features, access controls, or usage monitoring mechanisms of the Platform; (e) use the Platform for any unlawful purpose or in any manner that could damage, disable, overburden, or impair the Provider's servers or infrastructure; (f) introduce any malicious software, viruses, or harmful code into the Platform; or (g) use automated means, including bots, scrapers, or scripts, to access or extract data from the Platform without prior written authorisation.
4. User Accounts & Access Control
Each Institution is allocated administrative accounts with role-based access control (RBAC) permissions. The Institution's designated System Administrator(s) are responsible for creating, managing, and deactivating user accounts for Security Officers, Employees, and other authorised personnel within their organisation. Administrators must ensure that all user credentials are kept confidential and are not shared with unauthorised individuals.
The Platform enforces single-device login enforcement for Security Officer accounts. Each officer account is locked to one registered device at a time. Device switching requires authentication through a Force Login procedure. Administrators retain the ability to remotely terminate any active officer session through the Force Logout feature. All login attempts, device registrations, and session terminations are logged for audit and security purposes.
You are responsible for all activities that occur under your account credentials and must promptly notify the Provider of any unauthorised use, suspected security breach, or loss of credentials. The Provider reserves the right to suspend or terminate accounts that exhibit suspicious activity without prior notice to protect the integrity of the Platform and the data of other Institutions.
5. Service Description & Features
The Platform provides the following core modules and capabilities: (a) Patrol Operations, including QR code checkpoint verification with GPS location capture, intelligent patrol scheduling with configurable time intervals, real-time live monitoring of active patrols with auto-refreshing activity feeds, GPS route tracking and historical route replay, and a visual layout editor for floorplan-based checkpoint management; (b) Compliance and Reporting, including automated patrol classification as On Time, Delayed, or Missed, multi-format report generation in daily, weekly, and monthly intervals, and cron-driven automated email reports delivered via configurable SMTP per institution; (c) Workforce Management, including multi-role user administration, employee registration with institutional assignment, shift definition and roster scheduling with grace period configurations; (d) AI-Powered Attendance, including GPT-4o face verification for employee identity confirmation, GPS-gated attendance marking restricted to within 100 metres of the registered institution, and payroll-ready attendance monitoring with IN/OUT transaction tracking and export capabilities; (e) Incident Management, including field incident reporting with photographic and voice evidence, GPS-tagged incident locations, lifecycle tracking with status workflows, and Google Maps navigation integration; (f) Visitor Management, including self-service QR check-in, automated rescheduling, and satisfaction survey collection; (g) Customer Feedback and Satisfaction Surveys, including questionnaire building, automated survey delivery, and analytics dashboards; and (h) System Security and Control features including notifications, dark/light theme support, and per-institution SMTP configuration.
The Provider reserves the right to modify, enhance, or discontinue any feature or module of the Platform at any time, with or without prior notice, provided that such modifications do not materially impair the core functionality for which the Service was subscribed. Material changes will be communicated through the Platform's notification system or via email to registered administrative contacts.
6. Biometric Data Processing & AI Verification
The Platform's AI-Powered Attendance module utilises facial recognition technology powered by OpenAI's GPT-4o Vision API to verify employee identity during attendance marking. By enrolling an employee in the face verification system, the Institution and the enrolled employee acknowledge and consent to the following: (a) the capture and secure storage of facial reference photographs; (b) the processing of real-time facial images through a third-party AI service (OpenAI GPT-4o Vision API) for identity comparison purposes; (c) the retention of facial data for the duration of the employee's association with the Institution and for a period not exceeding twelve (12) months following termination of employment or de-enrolment, after which all biometric data shall be permanently deleted; and (d) the processing of such data may occur on servers located outside the Institution's jurisdiction.
The Provider implements a minimum confidence threshold of seventy-five percent (75%) for face verification acceptance. Verification attempts falling below this threshold are automatically rejected, and the employee is required to retry or contact their administrator. The Institution is solely responsible for obtaining all necessary employee consents, including explicit written consent for biometric data processing as required by applicable data protection legislation in the Institution's jurisdiction, prior to enrolling any employee in the face verification system.
The Provider shall not use, sell, lease, or share biometric data for any purpose other than the identity verification function described herein. Biometric data is encrypted at rest and in transit using industry-standard encryption protocols. In the event of a data breach affecting biometric data, the Provider shall notify affected Institutions within seventy-two (72) hours in accordance with applicable data breach notification requirements.
7. GPS Data Collection & Geolocation Processing
The Platform continuously collects, stores, and processes GPS data from Security Officer mobile devices during active patrol operations and attendance marking. This includes real-time location coordinates, patrol route paths, checkpoint scan locations, and attendance marking locations. GPS data is used for: (a) verifying that Security Officers physically visit designated checkpoint locations during patrols; (b) enforcing GPS-gated attendance restrictions requiring employees to be within 100 metres of the registered institution; (c) generating GPS route replay and compliance reports; and (d) providing real-time location visibility through the Live Monitor dashboard.
Each Institution must ensure that all Security Officers and Employees are informed of and consent to GPS data collection as a condition of using the Platform. The Institution is responsible for complying with all applicable local laws regarding employee location monitoring, including any requirements for prior disclosure, consent, or authorisation. GPS data is retained for a period of ninety (90) days for active institutions and is purged upon Institution deactivation unless a longer retention period is required by applicable law or agreed upon in writing.
8. Data Protection & Privacy
The Provider is committed to protecting the privacy and security of all data processed through the Platform. Each Institution acts as an independent data controller for the personal data of its personnel processed through the Platform, and the Provider acts as a data processor on behalf of each Institution. The Provider processes personal data solely for the purpose of providing the Service and does not process personal data for its own independent purposes.
The Provider implements appropriate technical and organisational security measures, including but not limited to: (a) encryption of data at rest using AES-256 or equivalent standards; (b) encryption of data in transit using TLS 1.2 or higher; (c) role-based access control with least-privilege principles; (d) regular security audits and vulnerability assessments; (e) secure session management with configurable timeout policies; and (f) secure backup and disaster recovery procedures. Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure, and the Provider does not guarantee absolute security of data.
Each Institution shall: (a) process personal data in accordance with applicable data protection laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 where applicable, the Personal Data Protection Act No. 9 of 2022 (Sri Lanka), and any other relevant jurisdictional requirements; (b) maintain its own privacy notices and obtain necessary consents from data subjects; (c) promptly notify the Provider of any data subject access requests, rectification requests, or erasure requests received directly from data subjects; and (d) ensure that its use of the Platform complies with all applicable employment and surveillance laws.
9. Intellectual Property Rights
All intellectual property rights in the Platform, including but not limited to the software code, database schemas, user interface designs, graphical elements, documentation, trademarks, logos, and trade names (collectively, "IP Rights"), are and shall remain the exclusive property of the Provider or its licensors. Nothing in these Terms shall be construed as transferring, assigning, or licensing any IP Rights to you other than the limited right to use the Platform as expressly granted herein.
You retain all intellectual property rights in your own data, content, and materials uploaded to or processed through the Platform ("Customer Data"). By using the Platform, you grant the Provider a limited, non-exclusive licence to process, store, and transmit Customer Data solely for the purpose of providing the Service. The Provider shall not use Customer Data for any purpose other than delivering the Service, generating aggregate anonymised statistics, or complying with legal obligations.
10. Payment Terms & Subscription
Access to the Platform is provided subject to the payment of applicable subscription fees, licence fees, or acquisition costs as agreed upon between the Customer and the Provider in a separate commercial agreement. All fees are quoted exclusive of applicable taxes, duties, and levies, which shall be borne by the Customer. Payment terms, invoicing schedules, and late payment consequences are governed by the applicable commercial agreement between the parties.
The Provider reserves the right to adjust pricing with thirty (30) days' prior written notice for subscription arrangements. For outright purchase and managed deployment arrangements, pricing is fixed as agreed in the commercial agreement. Failure to pay applicable fees within the agreed timeframe may result in suspension or termination of access to the Platform, subject to the cure periods specified in the applicable commercial agreement.
11. Service Level Commitments
The Provider endeavours to maintain the Platform's availability and performance at a high standard. The Platform is designed to operate on standard web infrastructure (Apache or Nginx with PHP 8.0+, MySQL 5.7+ or MariaDB 10.3+) and does not require proprietary hardware. Scheduled maintenance windows shall be communicated to all registered administrative contacts at least forty-eight (48) hours in advance through the Platform's notification system or via email. The Provider shall use commercially reasonable efforts to minimise unplanned downtime and restore service promptly following any disruption.
The Provider does not guarantee uninterrupted or error-free operation of the Platform. Service availability may be affected by factors beyond the Provider's reasonable control, including but not limited to internet connectivity issues, third-party service outages (including OpenAI API availability for face verification), force majeure events, and acts of government. The specific service level commitments, if any, including uptime percentages, response times, and credit mechanisms, are defined in the applicable commercial agreement and are not governed by these Terms.
12. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE PROVIDER SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO DAMAGES FOR LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF DATA, LOSS OF GOODWILL, BUSINESS INTERRUPTION, OR FAILURE TO REALISE EXPECTED SAVINGS, ARISING OUT OF OR IN CONNECTION WITH THESE TERMS OR THE USE OF OR INABILITY TO USE THE PLATFORM, REGARDLESS OF THE LEGAL THEORY UNDER WHICH SUCH DAMAGES ARE SOUGHT, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, AND EVEN IF THE PROVIDER HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
THE PROVIDER'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THESE TERMS SHALL NOT EXCEED THE TOTAL FEES PAID BY THE CUSTOMER TO THE PROVIDER DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THIS LIMITATION APPLIES REGARDLESS OF THE NUMBER OF CLAIMS OR THE NATURE OF THE CAUSE OF ACTION.
13. Indemnification
You agree to indemnify, defend, and hold harmless the Provider, its officers, directors, employees, agents, licensors, and affiliates from and against any and all claims, demands, losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or in connection with: (a) your use of the Platform in violation of these Terms or any applicable law; (b) your violation of any third-party intellectual property or privacy rights through your use of the Platform; (c) your failure to obtain necessary employee consents for biometric data processing, GPS tracking, or CCTV integration as required by applicable law; (d) any content, data, or materials you upload, transmit, or process through the Platform; (e) your negligence or willful misconduct in connection with the Platform; or (f) any dispute between you and your employees, officers, or third parties relating to the use of the Platform.
14. Confidentiality
Each party agrees to maintain the confidentiality of all Confidential Information received from the other party and to use such information solely for the purposes contemplated by these Terms. Confidential Information shall not be disclosed to any third party without the prior written consent of the disclosing party, except as required by applicable law, regulation, or court order. In the event of a legally compelled disclosure, the receiving party shall provide the disclosing party with prompt written notice so that the disclosing party may seek a protective order or other appropriate remedy.
The obligations of confidentiality shall survive the termination or expiration of these Terms for a period of five (5) years. Notwithstanding the foregoing, Confidential Information that is: (a) publicly available through no fault of the receiving party; (b) rightfully received from a third party without confidentiality obligations; (c) independently developed by the receiving party without reference to the disclosing party's Confidential Information; or (d) required to be disclosed by law, shall not be subject to these confidentiality obligations.
15. Term & Termination
These Terms shall remain in effect for the duration of your access to and use of the Platform, unless terminated earlier in accordance with this Section. Either party may terminate these Terms: (a) immediately upon written notice if the other party materially breaches any provision of these Terms and fails to cure such breach within thirty (30) days of receiving written notice specifying the breach; (b) immediately if the other party becomes insolvent, files for bankruptcy, has a receiver appointed for its assets, or ceases business operations; or (c) by the Customer upon thirty (30) days' prior written notice for convenience, subject to any minimum commitment periods specified in the applicable commercial agreement.
Upon termination or expiration: (a) all licences and access rights granted hereunder shall immediately cease; (b) the Customer shall cease all use of the Platform and return or destroy all Provider materials in its possession; (c) the Provider shall, within thirty (30) days of receiving a written data export request, provide the Customer with a machine-readable export of all Customer Data in a commonly used format; and (d) the Provider shall securely delete all Customer Data, including biometric data, within ninety (90) days following the completion of data export, unless retention is required by applicable law. Provisions which by their nature should survive termination, including but not limited to Sections 8 (Data Protection), 9 (Intellectual Property), 12 (Limitation of Liability), 13 (Indemnification), 14 (Confidentiality), and 17 (General Provisions), shall survive any termination of these Terms.
16. Modifications to Terms
The Provider reserves the right to amend or update these Terms at any time. Material amendments shall be communicated to all registered administrative contacts via email at least fifteen (15) days before the effective date of such amendments. Non-material amendments, including corrections of typographical errors, clarifications, and updates to reflect new Platform features, may be implemented with less notice. Your continued use of the Platform following the effective date of any amendment constitutes your acceptance of the revised Terms. If you do not agree to any amended Terms, you must cease using the Platform and notify the Provider in writing prior to the effective date of the amendment.
17. Dispute Resolution & Governing Law
These Terms shall be governed by and construed in accordance with the laws of the Democratic Socialist Republic of Sri Lanka, without regard to its conflict of law principles. The United Nations Convention on Contracts for the International Sale of Goods (CISG) is expressly excluded from application to these Terms.
Any dispute, claim, or controversy arising out of or relating to these Terms or the breach, termination, enforcement, interpretation, or validity thereof, including the determination of the scope or applicability of this agreement to arbitrate, shall be resolved: (a) first, through good-faith negotiation between the parties, with each party designating a senior representative with authority to settle the dispute; (b) if negotiation fails within thirty (30) days, through mediation administered by a mutually agreed mediator in Colombo, Sri Lanka; and (c) if mediation fails within sixty (60) days, through binding arbitration conducted in accordance with the Arbitration Act No. 11 of 1995 of Sri Lanka, with the arbitral tribunal seated in Colombo, Sri Lanka. The language of arbitration shall be English. The arbitral award shall be final and binding and may be entered in any court of competent jurisdiction.
18. General Provisions
Entire Agreement. These Terms, together with any applicable commercial agreement, privacy policy, and acceptable use policy, constitute the entire agreement between you and the Provider with respect to the subject matter hereof and supersede all prior or contemporaneous negotiations, representations, warranties, understandings, and agreements between the parties, whether written or oral.
Severability. If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court or arbitral tribunal of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall continue in full force and effect.
Waiver. The failure of either party to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. Any waiver of any provision of these Terms shall be effective only if in writing and signed by the waiving party.
Assignment. You may not assign, transfer, or delegate any of your rights or obligations under these Terms without the prior written consent of the Provider. The Provider may assign its rights and obligations under these Terms to any affiliate or in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided that the assignee agrees to be bound by these Terms.
Force Majeure. Neither party shall be liable for any failure or delay in performing its obligations under these Terms if such failure or delay results from circumstances beyond the reasonable control of the affected party, including but not limited to natural disasters, pandemics, war, terrorism, civil unrest, government actions, internet or telecommunications failures, or third-party service provider outages.
Notices. All notices required or permitted under these Terms shall be in writing and shall be deemed delivered: (a) when delivered personally; (b) one (1) business day after deposit with a nationally recognised overnight courier; (c) five (5) business days after mailing by registered or certified mail, return receipt requested; or (d) on the date of transmission if sent by email to the addresses specified in the applicable commercial agreement or to info@ekama.lk for the Provider.
19. Contact Information
For any questions, concerns, or requests relating to these Terms of Service, data protection practices, or the Platform in general, please contact us at: