Privacy Policy
GDPR Summary Notice: TimeLogic Attendance Station is an on-premises enterprise terminal operated on behalf of your employing organization (the Data Controller). We collect strictly necessary identity, biometric verification, and timestamp data exclusively for workplace attendance logging, fraud prevention, and statutory payroll verification.
1. Who We Are (Data Controller & Data Processor)
Your employing organization acts as the Data Controller responsible for determining employee scheduling and attendance policies. TimeLogic Enterprise Systems operates as the Data Processor providing secure biometric kiosk terminal software, edge encryption, and synchronized attendance telemetry.
2. Personal Data We Collect
When you interact with the TimeLogic Attendance Station Kiosk, the following categories of data may be processed:
- Identity & Employment Information: Full name, employee identification code, organization email address, department, job role, and shift assignment.
- Biometric Verification Data: Mathematical vector embeddings generated from your facial landmarks during clock-in. Important: TimeLogic does not sell, market, or share biometric templates. All biometric processing is strictly utilized for authenticating workplace check-ins and eliminating buddy-punching.
- Time & Attendance Logs: Precise timestamp records of clock-in, clock-out, break intervals, overstay durations, total hours worked, and punctuality status (Present, Late, Half-Day).
- Hardware & Kiosk Telemetry: Bound kiosk terminal device ID, local IP address, browser user-agent, and synchronization health status.
3. Legal Basis for Processing (GDPR Articles 6 & 9)
We process personal data under the following legal bases:
- Performance of Employment Contract (GDPR Art. 6(1)(b)): To calculate time worked, overtime, leave days, and monthly payroll compensation.
- Compliance with Legal Obligations (GDPR Art. 6(1)(c)): To maintain statutory workplace labor records, tax verification documents, and audit trails required by employment authorities.
- Legitimate Interests (GDPR Art. 6(1)(f)): To maintain organizational facility security, prevent unauthorized clock-ins, and ensure operational accountability.
- Special Category Data (GDPR Art. 9(2)(b) & 9(2)(a)): Biometric verification is conducted under employment law obligations and explicit organizational workplace consent frameworks.
4. Data Storage, Security & Offline Operation
TimeLogic implements enterprise-grade technical and organizational safeguards:
- Transit Encryption: All communication between this kiosk station and the enterprise backend occurs over TLS 1.3 with HTTP Strict Transport Security (HSTS) enforced.
- Self-Contained Offline Outbox: In offline kiosk mode, punch events are encrypted locally in IndexedDB outbox storage and synchronously re-verified with the central database once network connectivity is re-established.
- Strict-Origin Content Security Policy: Web requests and scripts are restricted to authorized endpoints, preventing clickjacking, code injection, and unauthorized third-party tracking.
- Zero Third-Party Ad Trackers: No third-party marketing pixels, analytics beacons, or external ad networks are loaded or permitted on this kiosk terminal. All typography and assets are self-hosted locally on our secure domain.
5. Data Retention & Erasure
Attendance records are retained for the duration of the employee's active engagement and the mandatory statutory payroll audit window specified by applicable labor laws. Upon employee departure or verified deletion request by the Data Controller, biometric templates and profile images are permanently purged from database records.
6. Your Rights Under GDPR
As a data subject, you have the following rights under the General Data Protection Regulation:
- Right of Access (Art. 15): You may request an itemized transcript of your attendance punches, timestamps, and payroll deductions.
- Right to Rectification (Art. 16): You may request correction of inaccurate clock-in records or personal details via your designated HR administrator.
- Right to Erasure (Art. 17): You may request removal of biometric templates where processing is no longer necessary or consent has been withdrawn.
- Right to Restriction of Processing (Art. 18): You may dispute punch calculations pending administrative review.
- Right to Data Portability (Art. 20): You may request your attendance history in structured, machine-readable format.
- Right to Lodge a Complaint: You have the right to lodge a formal complaint with your national data protection supervisory authority.
7. Contact & Data Protection Officer
For questions regarding your attendance data or to exercise your GDPR rights, please contact your organization's internal HR Data Administrator or reach TimeLogic Data Protection at:
Email: privacy@timelogic.internal · dpo@timelogic.com