Important Notice
This Privacy Policy explains how Phino ATS ("we," "us," or "our") collects, uses, shares, and protects your personal information, including sensitive biometric data. By using our services, you consent to the practices described in this policy.
1 Overview
Phino ATS is a biometric attendance tracking system designed for multi-tenant organizations. We are committed to protecting your privacy and handling your data with transparency and care.
This policy covers:
- What information we collect from users and administrators
- How we use and process biometric and attendance data
- Our security measures and data protection practices
- Your rights regarding your personal information
2 Information We Collect
Personal Information
We collect the following personal data:
- • Full name, email address, phone number
- • Employee ID, department, job title
- • Work schedule and shift information
- • Account credentials and authentication data
Biometric Data Sensitive
Our system processes biometric identifiers including:
- • Facial recognition templates and feature maps
- • Fingerprint patterns (if applicable)
- • Enrollment images for verification purposes
Important: Biometric data is encrypted, stored securely, and never shared with third parties. Templates are mathematical representations and cannot be reverse-engineered into original images.
Attendance & Usage Data
- • Check-in/check-out timestamps and locations
- • Device information (device ID, IP address, location)
- • Working hours, overtime, and absence records
- • System usage logs and activity history
Tenant & Organization Data
- • Company name, address, and contact information
- • Billing and payment information
- • Subscription plan and usage statistics
- • Department structures and location configurations
3 How We Use Your Information
We use the collected information for the following purposes:
Attendance Tracking
To verify employee identity and record accurate check-in/check-out times
Analytics & Reporting
To generate attendance reports, analyze trends, and provide workforce insights
Security & Fraud Prevention
To prevent unauthorized access, detect anomalies, and maintain system integrity
Customer Support
To provide technical assistance and respond to inquiries
Legal Compliance
To comply with labor laws, regulations, and legal obligations
Service Improvement
To enhance our platform, develop new features, and optimize performance
4 Biometric Data Handling
Special Protections for Biometric Information
We recognize that biometric data is highly sensitive. We implement additional safeguards and comply with biometric privacy laws including BIPA (Illinois), CCPA (California), and GDPR (Europe).
Storage & Encryption
All biometric templates are encrypted using AES-256 encryption at rest and TLS 1.3 in transit. We store mathematical representations, not actual images.
Retention Period
Biometric data is retained only while employment is active plus 3 years for legal compliance, or until deletion is requested, whichever comes first.
No Third-Party Sharing
We NEVER sell, rent, or share biometric data with third parties. It remains within our secure infrastructure and your tenant environment.
Informed Consent
Employees must provide explicit written consent before biometric enrollment. They can withdraw consent and request deletion at any time.
5 Data Sharing & Disclosure
We may share your information in the following limited circumstances:
Within Your Organization
Authorized administrators, supervisors, and HR personnel within your tenant can access relevant employee data based on their role permissions.
Service Providers
We work with trusted partners for hosting, analytics, and payment processing who are bound by strict confidentiality agreements. They never access biometric data.
Legal Requirements
We may disclose data when required by law, court order, or to protect our rights, but we will notify you unless legally prohibited.
Business Transfers
In the event of a merger or acquisition, your data may be transferred, but the new entity must honor this privacy policy.
6 Security Measures
Encryption
AES-256 encryption at rest, TLS 1.3 in transit, end-to-end encrypted biometric templates
Access Control
Multi-factor authentication, role-based permissions, audit logs for all data access
Data Isolation
Complete tenant separation, isolated databases, no cross-tenant data access
Monitoring
24/7 security monitoring, intrusion detection, regular vulnerability assessments
Backups
Encrypted daily backups, disaster recovery procedures, 99.9% uptime SLA
Compliance
SOC 2 Type II certified, GDPR compliant, regular third-party security audits
7 Your Privacy Rights
You have the following rights regarding your personal information:
Right to Access
Request a copy of your personal data we hold
Right to Rectification
Correct inaccurate or incomplete information
Right to Deletion
Request deletion of your personal and biometric data
Right to Portability
Receive your data in a machine-readable format
Right to Object
Object to certain processing of your data
Right to Restrict
Limit how we process your information
Withdraw Consent
Revoke consent for biometric data collection
Lodge Complaint
File a complaint with a supervisory authority
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: privacy@phinoats.com
Portal: Account Settings > Privacy Requests
We will respond to your request within 30 days.
8 Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
Active Employment
All data is retained while you are actively employed with a tenant organization
Post-Employment
Attendance records: 7 years (for legal/tax compliance)
Biometric data: 3 years or upon request for deletion
Account data: 1 year or upon request
Secure Deletion
When data is deleted, it is permanently removed from our systems using secure deletion methods and cannot be recovered
9 International Data Transfers
Your data may be processed in countries outside your residence. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with all service providers
- Compliance with Privacy Shield frameworks where applicable
- Regional data centers to minimize cross-border transfers
10 Children's Privacy
Phino ATS is designed for workplace attendance management and is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors.
If we become aware that we have collected data from someone under 18 without parental consent, we will take immediate steps to delete that information.
11 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make material changes:
- We will notify you via email at least 30 days before changes take effect
- We will post a prominent notice on our website and dashboard
- The "Last updated" date at the top of this policy will be revised
Your continued use of our services after changes take effect constitutes acceptance of the updated policy.
12 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
privacy@phinoats.com
+1 (555) 123-4567
Mailing Address
Phino ATS, Inc.
123 Tech Boulevard, Suite 400
San Francisco, CA 94105
United States
Response Time
We aim to respond to all privacy-related inquiries within 5 business days and will resolve requests within 30 days as required by applicable law.
13 State-Specific Privacy Rights
California Residents (CCPA/CPRA)
California residents have additional rights including:
- • Right to know what personal information is collected and sold
- • Right to opt-out of sale of personal information (we don't sell data)
- • Right to non-discrimination for exercising privacy rights
- • Right to limit use of sensitive personal information
Illinois Residents (BIPA)
Illinois Biometric Information Privacy Act protections include:
- • Written consent before biometric data collection
- • Clear retention schedules and deletion guidelines
- • Prohibition on selling biometric information
- • Right to sue for violations
Other States (VA, CO, CT, UT, etc.)
Residents of states with comprehensive privacy laws have rights to access, delete, correct data, and opt-out of targeted advertising and profiling. Contact us to exercise your state-specific rights.