HomePrivacy Policy

Privacy Policy

 

Effective Date: Aug 3, 2026

WorkClock HQ (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal and business data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application, web platform, and related services (collectively, the “Service”).

By using WorkClock HQ, you agree to the terms of this Privacy Policy.


1. Information We Collect

We collect information to provide and improve our services. This includes:

a. Personal Information
  • Name
  • Email address
  • Phone number (if applicable)
  • Login credentials
b. Business Information
  • Company name
  • Business structure (locations, departments, roles)
  • Staff records and organizational data
c. Location Data
  • GPS location for clock-in verification
  • Geofence-based location validation
  • Approximate location (used during offline mode)
d. Device Information
  • Device type
  • Device name
  • IP address
  • Operating system and browser
e. Usage Data
  • Clock-in and clock-out activity
  • Attendance records
  • System interactions and logs
f. Usage Data

Where enabled by an organization, WorkClock HQ may collect facial photographs during enrollment and attendance verification. The application temporarily processes live camera images to perform liveness verification (such as blinking, smiling, or head movement) and to verify that the person clocking in or out is physically present.

WorkClock HQ does not collect or access Apple Face ID data, TrueDepth camera data, ARKit facial geometry, infrared images, or any biometric information stored by Apple. Facial photographs are used solely for attendance verification, fraud prevention, and workforce management.

 


2. How We Use Your Information

We use your data to:

  • Provide workforce management and attendance tracking services
  • Verify clock-in locations using GPS and geofencing
  • Enable offline clock-in and data synchronization
  • Improve system performance and user experience
  • Generate reports and analytics
  • Communicate updates, invoices, and important notifications
  • Verify facial identity during enrollment and attendance events where facial verification is enabled.
  • Detect liveness to prevent impersonation, spoofing, or fraudulent attendance.

3. Location Tracking

WorkClock HQ uses location services only for workforce management features enabled by an organization.

Location may be collected:

  • During clock-in
  • During clock-out
  • During Presence Verification (Heartbeat), where enabled
  • While the app is running in the foreground or background during scheduled working hours when Presence Verification has been enabled by the organization and the user has granted the required permissions.

Background location is not enabled by default. It is only used after:

  • the organization enables Presence Verification,
  • the user grants Always Allow location permission,
  • and the user has clocked in or is within an active work session.

Location information is used only for attendance verification and workforce management.


4. Data Sharing

We do not sell your personal data.

We may share data only:

  • With your organization (employer/admin)
  • With trusted service providers (e.g., hosting, analytics)
  • When required by law or legal process

Any third-party service provider that processes or stores facial data on behalf of WorkClock HQ is required by contract to provide the same or a higher level of protection for facial data as described in this Privacy Policy and may not use facial data for any purpose other than providing services to WorkClock HQ.


5. Data Storage and Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Secure servers and encrypted communication
  • Access control and role-based permissions
  • Regular system monitoring

However, no system is 100% secure, and we cannot guarantee absolute security.


6. Data Retention

We retain your data:

  • As long as your account or organization is active
  • As required for legal, operational, or compliance purposes

Organizations may manage or permanently delete employee records, including facial photographs, through the platform or by contacting WorkClock HQ Support, subject to any applicable legal retention requirements.


7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Request corrections
  • Request deletion of your data
  • Withdraw consent (where applicable)

Requests should be directed to your organization or our support team.


8. Responsibility of Organizations

Organizations using WorkClock HQ are responsible for:

  • Informing employees about data collection
  • Obtaining necessary consent
  • Using the system in compliance with local laws

WorkClock HQ acts as a service provider and is not responsible for how organizations use collected data.


9. Third-Party Services

WorkClock HQ may integrate with third-party services. We are not responsible for the privacy practices of those external services.


10. Children’s Privacy

WorkClock HQ is not intended for individuals under the age of 18. We do not knowingly collect data from minors.


11. Presence Verification (Heartbeat)

Where enabled by an organization, WorkClock HQ periodically verifies an employee’s location during scheduled working hours after the employee has clocked in.

Presence Verification is designed to:

• Confirm employee presence during working hours.

• Verify attendance beyond the initial clock-in.

• Prevent attendance fraud.

• Support workforce reporting.

Presence Verification only operates:

  • when enabled by the organization,
  • after the user grants the required location permissions,
  • during active work sessions,
  • and may continue while the application is in the background during scheduled work hours.

 

Where enabled by an organization, WorkClock HQ may periodically collect location data during working hours through a feature known as Heartbeat Tracking.

Heartbeat Tracking is designed to:

• Verify employee presence during assigned work hours
• Confirm attendance beyond initial clock-in activities
• Support workforce accountability and operational monitoring
• Generate location verification records for reporting purposes

Heartbeat Tracking is only active when enabled by the organization and where the user has granted the necessary device permissions.

 


12. Facial Data and Attendance Verification

Where enabled by an organization, WorkClock HQ provides an optional Facial Attendance Verification feature to verify employee identity during attendance events.

Information We Collect

When facial attendance verification is enabled, WorkClock HQ may collect:

  • Four (4) standard two-dimensional facial photographs during employee enrollment.
  • One (1) standard two-dimensional facial photograph during each facial clock-in or clock-out verification.
  • Temporary live camera frames solely to perform liveness verification, including actions such as blinking, smiling, or turning the head.

Temporary camera frames used for liveness detection are processed only during the verification session and are never stored.


How We Use Facial Data

Facial photographs are collected and used only for the following purposes:

  • Enrolling employees for facial attendance verification.
  • Verifying employee identity during clock-in and clock-out.
  • Performing liveness verification to confirm the presence of a real person.
  • Preventing attendance fraud, impersonation, and unauthorized access.
  • Supporting attendance records and workforce management.

Facial data is never used for:

  • Advertising
  • Marketing
  • User profiling
  • Artificial intelligence model training
  • Facial recognition databases
  • Analytics unrelated to attendance
  • Sale or commercialization of facial information

Face Data Sharing

WorkClock HQ does not sell, rent, license, or trade facial data.

Facial photographs may only be shared with:

  • The employee’s organization (employer) for attendance management.
  • Authorized WorkClock HQ personnel where necessary to provide technical support or maintain the service.
  • Service providers that securely host WorkClock HQ infrastructure.

Where facial data is processed or stored by a third-party service provider, such provider is contractually required to maintain the same or a higher level of protection for facial data as described in this Privacy Policy and may not use facial data for any other purpose.

Facial data is never shared with advertisers, data brokers, marketing companies, or third parties for commercial purposes.


Storage and Security

Facial photographs are encrypted during transmission using HTTPS/TLS and stored using industry-standard security measures on secure servers.

Access is restricted through role-based permissions and limited to authorized personnel who require access to perform legitimate operational or technical support functions.


Face Data Retention

Facial photographs are retained only for as long as necessary to provide facial attendance verification services.

Unless otherwise required by applicable law or the organization’s employment record retention policy, facial photographs are retained:

  • While the employee remains active within the organization.
  • Until the organization removes the employee.
  • Until facial attendance verification is disabled for the employee.
  • Until deletion is requested by the organization or employee.

Temporary camera frames used for liveness detection are not retained after verification completes.


Face Data Deletion

Employees may request deletion of their facial data by contacting their organization administrator.

Organizations may permanently delete employee facial data directly through WorkClock HQ or by contacting WorkClock HQ Support.

When a valid deletion request is received, facial photographs are permanently removed from WorkClock HQ systems, except where retention is required by law.

Employees may also revoke consent for facial attendance verification at any time by:

  • Contacting their organization administrator.
  • Requesting removal of facial attendance verification from their account.
  • Revoking camera permissions through their device settings.

Please note that disabling or deleting facial data may prevent the employee from using facial attendance verification features.


Apple Face ID

WorkClock HQ does not access, collect, or store:

  • Apple Face ID information
  • TrueDepth camera data
  • Depth maps
  • Infrared facial images
  • ARKit facial geometry
  • Biometric identifiers generated by Apple

WorkClock HQ uses only standard camera photographs captured through the device camera.


13. User Consent 

Facial attendance verification and location tracking require the user’s explicit permission before these features can operate.

Users may revoke consent at any time by:

  • Disabling camera or location permissions in their device settings.
  • Requesting removal of facial attendance verification through their organization administrator.
  • Requesting deletion of their facial photographs as described in this Privacy Policy.

Revoking consent may prevent the user from accessing attendance features that rely on facial verification.x


14. Changes to This Policy

We may update this Privacy Policy from time to time. Continued use of the Service after changes means you accept the updated policy.


15. Contact Us

If you have any questions about this Privacy Policy, please contact:

Email: support@workclockhq.com
Company: WorkClock HQ (P&K Smart Rise Solutions)