Skip to content

Data Processing Addendum

Last updated 6 September 2026

This published baseline describes intended processing arrangements. Deployment-specific parties, processing details, retention, subprocessors and transfers need to be completed in the applicable agreement. It is not a certification of GDPR Article 28 compliance.

Roles

For workforce content processed on the customer’s instructions, the intended relationship is customer as controller and Attendify as processor. Attendify’s own account, billing and website administration has a separate role analysis. Confirm the parties and the actual processing in the applicable agreement.

Scope and instructions

We process personal data only to provide the service and on documented instructions from the customer, including as configured through the dashboard. We will tell the customer if, in our opinion, an instruction infringes applicable data protection law.

Categories of data and data subjects

The processing covers:

  • Data subjects: the customer's administrators, site managers and field workers.
  • Data categories: identifiers, contact details, employment identifiers, attendance timestamps, geolocation at the point of check-in and check-out, check-in photographs, verification outcomes, and — where enabled — biometric templates.
  • Special category data: biometric data used for the purpose of uniquely identifying a natural person, where the customer has enabled that feature.

Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • Row-level policies and capabilities on supported authenticated queries; explicit tenant checks in privileged worker and ERP service functions. Current within-company scope limitations are described on the security and permissions pages.
  • Encryption in transit for all connections, and encryption at rest for stored data.
  • Server-side biometric templates are held in a table not directly queryable by authenticated client applications. Personal devices may also keep a secure local reference for pre-checking.
  • Field-worker authentication by opaque per-device tokens stored hashed, with administrator-initiated revocation.
  • PINs stored using a salted one-way hash, never in recoverable form.
  • Private object storage for attendance photographs, not publicly addressable.
  • Least-privilege access controls for our own personnel, granted only where necessary to operate or support the service.

Subprocessors

The deployment agreement needs to identify hosting, database, storage and any optional assistant providers, their processing locations, contractual safeguards and the notice and objection process for changes. Payment activation is on hold. This baseline does not establish an executed subprocessor schedule.

International transfers

The configured Supabase project region is ap-south-1 (Mumbai). Selectable data residency is not an established offer. Document the actual recipients, locations and applicable transfer arrangements in the deployment agreement; this page alone does not establish executed Standard Contractual Clauses.

Assistance to the controller

We will assist the customer, taking into account the nature of processing, in responding to data subject requests, in carrying out data protection impact assessments — which we expect to be necessary before biometric matching is enabled — and in notifying personal data breaches.

Breach notification

We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information reasonably available to us at the time and updates as the picture develops.

Deletion and return

Document the return/export window, deletion process, retained legal records and backup treatment in the deployment agreement. Do not assume that disabling an account immediately erases every copy or that an undefined post-termination export window is available.

Audit

We will make available the information necessary to demonstrate compliance with this addendum and will contribute to audits conducted by the customer or an agreed independent auditor, subject to reasonable notice and confidentiality.