← Back to Home
Privacy Policy
Last Updated: July 2026
1. Introduction
FaceAuth ("we", "our", "us") is a biometric attendance management system. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our application.
2. Data We Collect
We collect the minimum personal data necessary for the application to function:
- Identity Data: First name, last name, email address, employee ID
- Biometric Data: Facial recognition encoding (a mathematical representation of your facial features, not a photograph)
- Attendance Data: Login/logout times, dates, and attendance status
- Location Data: GPS coordinates at the time of login/logout (when enabled by your administrator)
- Device Data: Browser user agent, screen dimensions, and touch capability (for device-type detection only)
3. How We Use Your Data
Your personal data is used exclusively for:
- Verifying your identity through facial recognition during attendance logging
- Recording attendance (login/logout times and status)
- Security monitoring (location verification, device restrictions)
- Account management (password resets, notifications)
4. Data Storage & Security
Your data is stored securely in Microsoft Dataverse with the following protections:
- Passwords are hashed using industry-standard PBKDF2 with SHA-256
- All data transmission uses TLS encryption
- Session cookies are secured with HttpOnly, Secure, and SameSite attributes
- Administrative access is restricted to authorized personnel only
5. Data Retention
Your personal data is retained for the duration of your employment or account activity. When your account is deleted by an administrator, all associated attendance records and personal data are permanently removed from the system.
6. Your Rights
You have the right to:
- Request access to your personal data held by the system
- Request correction of inaccurate personal data
- Request deletion of your personal data (via your administrator)
- Object to specific uses of your personal data
To exercise any of these rights, please contact your system administrator or email the data controller at the address provided by your organization.
7. Third-Party Services
We use the following third-party services to operate:
- Microsoft Dataverse: Secure data storage
- Brevo (Sendinblue): Transactional email delivery (password resets, notifications)
- OpenStreetMap Nominatim: Reverse geocoding for location display (no personal data is sent)
8. Cookies
We use essential cookies only for session management and security. No analytics or marketing cookies are used. By using the application, you consent to the use of these essential cookies required for the system to function.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Users will be notified of significant changes through the application.
10. Contact
For privacy-related inquiries, please contact your system administrator or the designated data protection contact within your organization.