Last updated: 18 September 2026
This notice explains what the FaceINOUT attendance app collects from employees of [Your Company Name], why it is collected, how it is protected, and what rights you have over it. It covers the Android app and the server it communicates with.
[Your Company Name] is the data fiduciary for this system. Contact: [privacy@yourcompany.com], [Your registered office address].
| Data | Why | When |
|---|---|---|
| Face template (a numeric vector, not an image) |
To verify that the person marking attendance is you | Once, at enrolment; replaced if you re-enrol |
| Employment details name, employee code, mobile, email, department, designation |
To identify your account and produce attendance records | Entered by HR when your account is created |
| Attendance records check-in/out times, working hours, status |
Payroll, leave and statutory record-keeping | Each time you mark attendance |
| Location latitude and longitude |
To record where attendance was marked, where your employer requires it | Only at the moment you mark attendance. You are not tracked at any other time. |
| Device details model, Android version, app version, a device identifier and a device security key |
To bind your account to your own phone and block attendance from an unauthorised device | At sign-in and device registration |
| Verification records match score, liveness result, time, IP address |
Security audit trail and accuracy monitoring | Every verification attempt, successful or not |
| Occasional face image a small cropped image of your face |
Spot-checking that the system is working correctly and has not been tampered with | On a small, randomly selected percentage of check-ins |
When you enrol, the app looks at your face through the camera and converts it into a list of numbers — a face template. This happens entirely on your phone. The camera images used to produce it are discarded immediately and are never uploaded.
A template is a one-way numeric summary. It cannot be reversed into a recognisable image of you. It is, however, still biometric data about you, so it is treated as sensitive throughout.
Because you sign in first, the system only ever asks "is this the same person as employee X?" It does not search a database of faces, and it cannot identify you from a photograph taken elsewhere.
You will be asked to perform a random action such as blinking or turning your head. This is to stop someone marking your attendance using a photograph or a video of you. The app also analyses the camera frames for signs of a screen or printed photo. These checks happen on your phone; only the result is sent to the server.
| Who | What they can see |
|---|---|
| You | Your profile, your attendance, your enrolment status, your registered devices |
| HR and authorised administrators | Your employment details, attendance records, enrolment status, device list, and verification outcomes — never your face template itself, and audit face images only where spot-checking is required |
| System administrators | Technical access to the server for maintenance, under the same audit logging |
| Third parties | Nothing. Your data is not shared, sold or transferred, except where your employer is legally required to disclose it |
| Data | Retention |
|---|---|
| Face template | Until you leave employment, ask for it to be deleted, or re-enrol (which replaces it). Deleted within 30 days of leaving. |
| Attendance records | As required by employment and statutory record-keeping obligations. |
| Verification score logs | 12 months |
| Audit face images | 90 days, then deleted automatically |
| Session tokens | Expire automatically; removed within 7 days |
| Administrative audit logs | Retained for the life of the system, as a security record |
| Permission | Why | Optional? |
|---|---|---|
| Camera | To capture your face for enrolment and verification | No — the app cannot work without it |
| Location | To record where attendance was marked | Yes, unless your employer has made it mandatory. Asked for only when you mark attendance. |
| Internet | To communicate with your employer's server | No |
| Notifications | Reminders and sync results | Yes |
Face recognition is not perfect. It can occasionally fail to recognise you in poor lighting or after a significant change in appearance — when that happens you can retry or contact HR, and no attendance is recorded from a failed attempt. The liveness checks defeat printed photos and simple video replays, but no software-only system is immune to a determined, well-resourced attack. This system is not certified to ISO/IEC 30107-3. We say this plainly rather than claiming the system is impossible to defeat.
This system does not use Aadhaar, Aadhaar Face RD or any UIDAI authentication service. No Aadhaar number, Aadhaar biometric data, PID block or OTP is collected or stored. If optional Aadhaar-based identity verification is introduced in future, it will be voluntary, will use offline verification only, and this notice will be updated before it is enabled.
If we change what we collect or why, this notice will be updated and you will be informed through the app before the change takes effect.
[Your Company Name]
[Your registered office address]
[privacy@yourcompany.com]
Highlighted items are placeholders that must be replaced with your organisation's real details before this notice is published.