Privacy notice draft
Effective date: [INSERT DATE] · Responsible organization: [INSERT LEGAL ORGANIZATION NAME] · Privacy contact: [INSERT PRIVACY EMAIL / MAILING ADDRESS]
Camera and on-device processing
Sharing and optional Google services
Your choices and requests
1. Information this app is intended to use
AKA-ONI Clock-In is intended to help an organization record attendance. Depending on the organization's configuration, the app may handle an employee's name, work role or department, clock-in and clock-out times, attendance history, and an employee reference photo or camera capture taken during a clock-in interaction.
The organization using AKA-ONI Clock-In is responsible for explaining its workplace practices and for ensuring it has an appropriate basis to collect and use employee information.
2. Camera, face and liveness processing
The app may use the device camera to compare a live camera view with an employee reference photo and to perform liveness checks intended to reduce false or fraudulent clock-ins. This processing is designed to occur on the device. [CONFIRM TECHNICAL IMPLEMENTATION AND WHETHER ANY FACE TEMPLATES, IMAGES, OR DERIVED DATA LEAVE THE DEVICE.]
Employees must have access to a reasonable non-biometric/manual alternative for recording attendance, such as [INSERT APPROVED ALTERNATIVE: manager-assisted check-in, badge, PIN, or manual timesheet].
3. Where information may go
Attendance information is intended to be visible only to authorized people at the organization, such as designated managers or administrators. AKA-ONI Clock-In is not intended to use attendance or camera information for advertising, behavioural advertising, or cross-service tracking.
If an organization enables an optional Google Sheets or Google Drive connection, configured attendance records and/or permitted files may be sent to that organization's Google account and recipients. Google's handling of information is governed by the organization's Google configuration and applicable Google terms. [CONFIRM THE EXACT DATA FIELDS AND RECIPIENT ACCESS.]
4. Access and safeguards
Access should be limited through administrator-controlled accounts, role-based permissions, device controls, and other reasonable technical and organizational safeguards. The organization should limit access to people who need it for attendance administration.
5. Retention, deletion, correction and withdrawal
The organization should set and communicate an attendance-record retention schedule: [INSERT RETENTION PERIOD AND DELETION PROCESS]. Individuals may request access to, correction of, or deletion of their personal information, or withdraw consent where consent is the applicable basis, by contacting [INSERT CONTACT]. Requests may be subject to identity verification and applicable legal requirements.
Some records may need to be retained despite a deletion or withdrawal request where required or permitted by employment, tax, accounting, legal, dispute-resolution, or other applicable obligations. The organization should explain any such exception and retain only what is necessary.
6. Updates and questions
This draft should be updated before release and whenever practices materially change. Questions or requests should be directed to [INSERT PRIVACY CONTACT].