Iterative AI Solutions (“we”, “us”, “our”) builds the Attendance Management System (“AMS”, the “App”), a geofenced attendance platform for institutes and offices. This policy explains what information the App collects, why we collect it, how it is used and protected, and the choices you have.
1. Information we collect
We collect only the data needed to operate a workplace attendance system. Your employer/institute is the owner (“controller”) of this data; we process it on their behalf.
| Category | Data | Why |
|---|---|---|
| Account & profile | Full name, email address, phone number, work role, and a securely hashed password. | To create your account, verify your email, and let you sign in. |
| Location | Approximate and precise GPS coordinates (latitude, longitude, accuracy) captured at the moment you tap Check-In / Check-Out. | To verify you are physically inside your assigned office premises (geofence). |
| Device | A device identifier (for device binding), device model, and operating-system version. On Android we also read the “mock location” flag. | To bind your account to one device and to detect fake/spoofed GPS. |
| Attendance records | Check-in / check-out times, computed status (on-time, late, absent, on-leave), and any correction or leave requests you submit. | To record and manage your attendance. |
| Technical logs | Basic request metadata (e.g. IP address, timestamps) and audit logs of key actions. | Security, troubleshooting, and an audit trail. |
We do not collect your contacts, photos, messages, microphone, browsing history, or advertising identifiers. The App contains no third-party advertising or analytics trackers.
2. Location data — important disclosure
The App accesses location only in the foreground, only when you actively mark attendance. It does not track your location in the background, and it does not record your location at any other time. A single GPS reading is taken when you tap Check-In or Check-Out, sent securely to the server to confirm you are within the allowed radius of your office, and stored as part of that attendance record.
- Permissions requested:
ACCESS_FINE_LOCATIONandACCESS_COARSE_LOCATION(foreground only). No background-location permission is requested or used. - The location check runs server-side (PostGIS distance calculation). If you are outside the permitted radius, the check-in is rejected and the reading is not retained as a successful punch.
- You can revoke location permission at any time in your device settings; the attendance feature will not function without it, but you can still use the rest of the App.
3. How we use your information
- Authenticate you and secure your account (email OTP verification, sign-in, device binding).
- Verify on-site presence and record attendance, lateness, leave and corrections.
- Provide administrators of your organisation with attendance dashboards and reports for their own company only.
- Detect and prevent fraud, GPS spoofing, and abuse.
- Maintain security, diagnose problems, and comply with legal obligations.
We do not sell your personal data and we do not use it for advertising.
4. Sharing & disclosure
Your data is visible to the administrators of your own organisation (company/HR/manager roles) and is not shared with other organisations. We may share limited data with:
- Email delivery provider — to send your one-time verification codes and notifications.
- Hosting/infrastructure provider — the servers where the application and database run on our behalf.
- Legal authorities — only where required by law, or to protect rights, safety and security.
These providers act as our processors under appropriate confidentiality obligations.
5. Data retention
We retain your account and attendance data for as long as your organisation uses the service and as needed to provide it. When your organisation’s account is closed, or on a valid deletion request, we delete or anonymise personal data unless we are required to keep it for legal or legitimate business reasons.
6. How we protect your data
- Passwords are stored using strong one-way hashing (argon2id) — never in plain text.
- Data in transit is protected with HTTPS/TLS encryption.
- Access is controlled by role-based permissions and short-lived authentication tokens; each organisation’s data is isolated.
- Key actions are written to an append-only audit log.
No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures.
7. Your rights & choices
- Access & correction — request a copy of your data or ask us to correct it.
- Deletion — request deletion of your account and associated personal data.
- Withdraw permission — revoke location or other permissions in your device settings at any time.
To exercise these rights, contact us (below) or your organisation’s administrator. We respond within a reasonable time.
8. Children’s privacy
The App is intended for employees and authorised staff of organisations and is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Effective date” above and, where appropriate, by notice in the App. Continued use after an update constitutes acceptance of the revised policy.
10. Contact us
If you have questions or requests about this Privacy Policy or your data, contact:
Iterative AI Solutions
Email: [email protected]
Phone: +92 334 5414404
Website: https://ams.iterativeaisolutions.com/