Privacy Notice — FaceINOUT Attendance

Last updated: 18 September 2026

This notice explains what the FaceINOUT attendance app collects from employees of [Your Company Name], why it is collected, how it is protected, and what rights you have over it. It covers the Android app and the server it communicates with.

In one paragraph: the app converts your face into a mathematical template on your own phone and sends only that template — not your photograph — to your employer's server, where it is stored encrypted and used for one purpose: confirming it is really you when you mark attendance. Your face images are not stored, not shared, and not used to identify you anywhere else.

1. Who is responsible for your data

[Your Company Name] is the data fiduciary for this system. Contact: [privacy@yourcompany.com], [Your registered office address].

2. What we collect

DataWhyWhen
Face template
(a numeric vector, not an image)
To verify that the person marking attendance is you Once, at enrolment; replaced if you re-enrol
Employment details
name, employee code, mobile, email, department, designation
To identify your account and produce attendance records Entered by HR when your account is created
Attendance records
check-in/out times, working hours, status
Payroll, leave and statutory record-keeping Each time you mark attendance
Location
latitude and longitude
To record where attendance was marked, where your employer requires it Only at the moment you mark attendance. You are not tracked at any other time.
Device details
model, Android version, app version, a device identifier and a device security key
To bind your account to your own phone and block attendance from an unauthorised device At sign-in and device registration
Verification records
match score, liveness result, time, IP address
Security audit trail and accuracy monitoring Every verification attempt, successful or not
Occasional face image
a small cropped image of your face
Spot-checking that the system is working correctly and has not been tampered with On a small, randomly selected percentage of check-ins

3. What we do not collect

4. How your face data works

It is converted on your phone

When you enrol, the app looks at your face through the camera and converts it into a list of numbers — a face template. This happens entirely on your phone. The camera images used to produce it are discarded immediately and are never uploaded.

The template cannot be turned back into your photograph

A template is a one-way numeric summary. It cannot be reversed into a recognisable image of you. It is, however, still biometric data about you, so it is treated as sensitive throughout.

It is only ever compared against your own template

Because you sign in first, the system only ever asks "is this the same person as employee X?" It does not search a database of faces, and it cannot identify you from a photograph taken elsewhere.

Liveness checks

You will be asked to perform a random action such as blinking or turning your head. This is to stop someone marking your attendance using a photograph or a video of you. The app also analyses the camera frames for signs of a screen or printed photo. These checks happen on your phone; only the result is sent to the server.

5. Where it is stored and how it is protected

6. Who can see your data

WhoWhat they can see
YouYour profile, your attendance, your enrolment status, your registered devices
HR and authorised administratorsYour employment details, attendance records, enrolment status, device list, and verification outcomes — never your face template itself, and audit face images only where spot-checking is required
System administratorsTechnical access to the server for maintenance, under the same audit logging
Third partiesNothing. Your data is not shared, sold or transferred, except where your employer is legally required to disclose it

7. How long it is kept

DataRetention
Face templateUntil you leave employment, ask for it to be deleted, or re-enrol (which replaces it). Deleted within 30 days of leaving.
Attendance recordsAs required by employment and statutory record-keeping obligations.
Verification score logs12 months
Audit face images90 days, then deleted automatically
Session tokensExpire automatically; removed within 7 days
Administrative audit logsRetained for the life of the system, as a security record

8. Your rights

9. Permissions the app asks for

PermissionWhyOptional?
CameraTo capture your face for enrolment and verificationNo — the app cannot work without it
LocationTo record where attendance was markedYes, unless your employer has made it mandatory. Asked for only when you mark attendance.
InternetTo communicate with your employer's serverNo
NotificationsReminders and sync resultsYes

10. Honest limitations

Face recognition is not perfect. It can occasionally fail to recognise you in poor lighting or after a significant change in appearance — when that happens you can retry or contact HR, and no attendance is recorded from a failed attempt. The liveness checks defeat printed photos and simple video replays, but no software-only system is immune to a determined, well-resourced attack. This system is not certified to ISO/IEC 30107-3. We say this plainly rather than claiming the system is impossible to defeat.

11. Aadhaar

This system does not use Aadhaar, Aadhaar Face RD or any UIDAI authentication service. No Aadhaar number, Aadhaar biometric data, PID block or OTP is collected or stored. If optional Aadhaar-based identity verification is introduced in future, it will be voluntary, will use offline verification only, and this notice will be updated before it is enabled.

12. Changes to this notice

If we change what we collect or why, this notice will be updated and you will be informed through the app before the change takes effect.

13. Contact

[Your Company Name]
[Your registered office address]
[privacy@yourcompany.com]

Highlighted items are placeholders that must be replaced with your organisation's real details before this notice is published.