Attendify – Privacy Policy

Last updated: August 25, 2025
B2B HR/Attendance Service No ads, no data selling Encryption in transit & at rest

Quick summary

Not legal advice. This template is provided for general information. You should review it with counsel and adapt it to your actual practices, locations, and contracts.

1) Scope & Roles

This Privacy Policy describes how Attendify (the “Service”) handles personal data of users who access our mobile apps, web dashboards, and APIs.

Roles: For enterprise deployments, your organization (the “Customer”) is typically the data controller for employee data, and Attendify acts as a data processor under a services agreement. For direct or self‑serve accounts, Attendify may act as the data controller for your account data.

2) Data We Collect

A. Data you and your employer provide

B. Data collected automatically

C. Biometric data (optional)

Some Customers enable biometric verification (e.g., face or fingerprint). Attendify uses biometric templates derived from your image/scan for matching. Templates are stored encrypted and cannot be used to reconstruct the original image. Customers can configure whether templates are kept on‑device only or synchronized to their secure tenant storage. Raw images/scans used to create templates are not stored for matching.

Tenant configuration: If your employer disables biometrics, the app won’t collect biometric data.

D. Sources

We receive data from: (i) you, (ii) your employer, (iii) devices running the app, and (iv) third‑party providers (e.g., authentication, cloud hosting, push notifications).

3) How We Use Data

Legal bases (EEA/UK): contract performance, legitimate interests (security, improvement), consent (where required, e.g., optional biometrics), and legal obligations.

4) How We Share Data

We do not sell personal information or use it for targeted advertising.

5) Security

We apply industry‑standard safeguards, including transport layer encryption (TLS), encryption at rest, role‑based access controls, logging, and regular backups. No method is 100% secure, and we encourage Customers to enforce strong authentication and device security policies.

6) Retention

We retain personal data for as long as needed to provide the Service to the Customer and to meet legal, accounting, or reporting requirements. Customers can configure retention periods for attendance records. When an account is closed or data is no longer required, we delete or de‑identify it within a reasonable time unless we must keep it by law.

7) Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to portability.

You may withdraw consent where processing relies on consent (e.g., optional biometrics). This won’t affect prior processing.

8) Cookies & SDKs

The mobile apps may use device identifiers and SDKs for functionality (e.g., push notifications, crash analytics). The web dashboard uses necessary cookies for login and session management. We do not use third‑party advertising cookies.

9) International Transfers

We may process and store data in data centers located outside your country. Where required, we use appropriate safeguards such as Standard Contractual Clauses. Customers can request information about data residency options.

10) Children’s Privacy

The Service is intended for workplace use and is not directed to children under 16. We do not knowingly collect personal data from children.

11) Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via the Service or by email to administrators. The “Last updated” date at the top reflects the current version.

12) Contact Us

Company: [Your Legal Entity Name]
Address: [Street, City, Country]
Email: privacy@attendify.me (replace with your address)
DPO/Privacy Contact: [Name or team]

Appendix – GDPR & CCPA Notices

EEA/UK (GDPR)

California (CCPA/CPRA)

We collect the following categories for business purposes: identifiers; employment‑related information; internet/network activity; geolocation (if enabled); inferences for security/anti‑fraud; and biometric information (if enabled by your employer). We do not sell or share personal information as defined by the CCPA/CPRA. You may exercise your rights via the contact methods above or through your employer.