Privacy Policy
Last updated 6 September 2026
This policy explains what personal data Attendify Vision processes, why, and what rights individuals have. It covers both our customers (the companies who subscribe) and the workers whose attendance is recorded through the service.
Who is responsible for your data
When a company uses Attendify Vision to record its workforce's attendance, that company is the data controller. It decides which workers are enrolled, which sites are monitored, and whether optional features such as face matching are switched on.
Attendify Vision acts as a data processor for that content: we process it on the customer's instructions and do not use it for our own purposes. For our own account, billing and website data we act as a controller.
What we collect
The categories of data we hold depend on the role of the person involved.
- Company administrators: name, work email address, authentication credentials, and the company details entered at signup.
- Field workers: name, system worker code, customer employee ID, payroll ID and other entered employment/contact/organization details, site assignment, hashed PIN and hashed device-token records.
- Attendance records: timestamp of capture and of receipt, GPS coordinates and reported accuracy, the assigned site, a check-in photograph, the liveness result, and whether the record was synced from an offline queue.
- Optional biometric templates: where a company has enabled face matching, a numeric face descriptor generated on the worker's device. Enrolment photographs are deleted on the device and are never uploaded.
- Billing: self-service payment activation is on hold. The application stores subscription status and may store a processor reference; no live card-payment service is promised here.
- Operational data: server logs, supported audit events, operation previews/outcomes, staged import data and, where the optional assistant is enabled, submitted assistant requests and proposals.
Why we process it
Attendance, location and verification data are processed to deliver the service the customer has subscribed to: recording attendance evidence associated with a worker and site, calculating configured hours, and supporting human review and payroll handoff. A capture is not proof of continuous presence or a legal/payroll determination.
Location is captured at the moment of check-in and check-out only. Attendify Vision does not track a worker's movements between those events, and there is no continuous location logging in the product.
Biometric data
Face matching is disabled by default and is enabled only for companies that have specifically requested it. Where it is in use, the worker is shown a notice and must give affirmative consent before any template is created. We record which version of that notice they accepted and when.
The enrollment reference is a mathematical descriptor; accepted attendance selfies are stored separately. The reference is held in a table that authenticated client applications cannot query, scoped to the customer's tenant. A company administrator can see whether a worker is enrolled but cannot retrieve the template itself.
An administrator can erase a worker's biometric profile at any time. Doing so deletes the stored template, revokes the consent record, and requires fresh consent and re-enrolment before that worker can be matched again.
Kiosk identification, where a shared device recognises a worker from their face without them first claiming an identity, is a separate processing purpose with its own controls and is gated independently.
Retention
Confirm retention arrangements for attendance records, accepted selfies, templates, logs and backups before deployment. A universal customer-configurable retention schedule is not currently promised. An active biometric profile can be reset to remove its template; rejected matching attempts store outcome metadata rather than the rejected selfie on the server. Device-side rejected captures can be removed during terminal synchronization failure.
Sharing
We do not sell personal data. We share it only with infrastructure providers necessary to run the service — hosting, database, object storage and payment processing — each under contract and processing only on our instructions.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or port your personal data, and to object to processing. Where consent is the applicable basis for processing, withdrawal rights must be addressed. The appropriate grounds and conditions depend on the actual deployment and jurisdiction.
Workers should direct requests to their employer as the controller in the first instance. Where we receive a request directly, we will pass it to the relevant customer and support them in responding.
Contact
Questions about this policy or a company’s use of the service can be sent to mudasar@collectflows.com. Confirm the contracting legal entity and address during procurement; a product name alone does not identify the legal counterparty.
Other policies: Terms of Service, Data Processing Addendum.