Phino ATS

Privacy Policy

Your privacy and data security are our top priorities

Last updated: October 31, 2025

Quick Navigation:

Important Notice

This Privacy Policy explains how Phino ATS ("we," "us," or "our") collects, uses, shares, and protects your personal information, including sensitive biometric data. By using our services, you consent to the practices described in this policy.

1 Overview

Phino ATS is a biometric attendance tracking system designed for multi-tenant organizations. We are committed to protecting your privacy and handling your data with transparency and care.

This policy covers:

  • What information we collect from users and administrators
  • How we use and process biometric and attendance data
  • Our security measures and data protection practices
  • Your rights regarding your personal information

2 Information We Collect

Personal Information

We collect the following personal data:

  • Full name, email address, phone number
  • Employee ID, department, job title
  • Work schedule and shift information
  • Account credentials and authentication data

Biometric Data Sensitive

Our system processes biometric identifiers including:

  • Facial recognition templates and feature maps
  • Fingerprint patterns (if applicable)
  • Enrollment images for verification purposes

Important: Biometric data is encrypted, stored securely, and never shared with third parties. Templates are mathematical representations and cannot be reverse-engineered into original images.

Attendance & Usage Data

  • Check-in/check-out timestamps and locations
  • Device information (device ID, IP address, location)
  • Working hours, overtime, and absence records
  • System usage logs and activity history

Tenant & Organization Data

  • Company name, address, and contact information
  • Billing and payment information
  • Subscription plan and usage statistics
  • Department structures and location configurations

3 How We Use Your Information

We use the collected information for the following purposes:

Attendance Tracking

To verify employee identity and record accurate check-in/check-out times

Analytics & Reporting

To generate attendance reports, analyze trends, and provide workforce insights

Security & Fraud Prevention

To prevent unauthorized access, detect anomalies, and maintain system integrity

Customer Support

To provide technical assistance and respond to inquiries

Legal Compliance

To comply with labor laws, regulations, and legal obligations

Service Improvement

To enhance our platform, develop new features, and optimize performance

4 Biometric Data Handling

Special Protections for Biometric Information

We recognize that biometric data is highly sensitive. We implement additional safeguards and comply with biometric privacy laws including BIPA (Illinois), CCPA (California), and GDPR (Europe).

Storage & Encryption

All biometric templates are encrypted using AES-256 encryption at rest and TLS 1.3 in transit. We store mathematical representations, not actual images.

Retention Period

Biometric data is retained only while employment is active plus 3 years for legal compliance, or until deletion is requested, whichever comes first.

No Third-Party Sharing

We NEVER sell, rent, or share biometric data with third parties. It remains within our secure infrastructure and your tenant environment.

Informed Consent

Employees must provide explicit written consent before biometric enrollment. They can withdraw consent and request deletion at any time.

5 Data Sharing & Disclosure

We may share your information in the following limited circumstances:

Within Your Organization

Authorized administrators, supervisors, and HR personnel within your tenant can access relevant employee data based on their role permissions.

Service Providers

We work with trusted partners for hosting, analytics, and payment processing who are bound by strict confidentiality agreements. They never access biometric data.

Legal Requirements

We may disclose data when required by law, court order, or to protect our rights, but we will notify you unless legally prohibited.

Business Transfers

In the event of a merger or acquisition, your data may be transferred, but the new entity must honor this privacy policy.

6 Security Measures

Encryption

AES-256 encryption at rest, TLS 1.3 in transit, end-to-end encrypted biometric templates

Access Control

Multi-factor authentication, role-based permissions, audit logs for all data access

Data Isolation

Complete tenant separation, isolated databases, no cross-tenant data access

Monitoring

24/7 security monitoring, intrusion detection, regular vulnerability assessments

Backups

Encrypted daily backups, disaster recovery procedures, 99.9% uptime SLA

Compliance

SOC 2 Type II certified, GDPR compliant, regular third-party security audits

7 Your Privacy Rights

You have the following rights regarding your personal information:

Right to Access

Request a copy of your personal data we hold

Right to Rectification

Correct inaccurate or incomplete information

Right to Deletion

Request deletion of your personal and biometric data

Right to Portability

Receive your data in a machine-readable format

Right to Object

Object to certain processing of your data

Right to Restrict

Limit how we process your information

Withdraw Consent

Revoke consent for biometric data collection

Lodge Complaint

File a complaint with a supervisory authority

How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: privacy@phinoats.com

Portal: Account Settings > Privacy Requests

We will respond to your request within 30 days.

8 Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations:

Active Employment

All data is retained while you are actively employed with a tenant organization

Post-Employment

Attendance records: 7 years (for legal/tax compliance)
Biometric data: 3 years or upon request for deletion
Account data: 1 year or upon request

Secure Deletion

When data is deleted, it is permanently removed from our systems using secure deletion methods and cannot be recovered

9 International Data Transfers

Your data may be processed in countries outside your residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all service providers
  • Compliance with Privacy Shield frameworks where applicable
  • Regional data centers to minimize cross-border transfers

10 Children's Privacy

Phino ATS is designed for workplace attendance management and is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors.

If we become aware that we have collected data from someone under 18 without parental consent, we will take immediate steps to delete that information.

11 Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make material changes:

  • We will notify you via email at least 30 days before changes take effect
  • We will post a prominent notice on our website and dashboard
  • The "Last updated" date at the top of this policy will be revised

Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

12 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

privacy@phinoats.com

+1 (555) 123-4567

Mailing Address

Phino ATS, Inc.

123 Tech Boulevard, Suite 400

San Francisco, CA 94105

United States

Response Time

We aim to respond to all privacy-related inquiries within 5 business days and will resolve requests within 30 days as required by applicable law.

13 State-Specific Privacy Rights

California Residents (CCPA/CPRA)

California residents have additional rights including:

  • • Right to know what personal information is collected and sold
  • • Right to opt-out of sale of personal information (we don't sell data)
  • • Right to non-discrimination for exercising privacy rights
  • • Right to limit use of sensitive personal information

Illinois Residents (BIPA)

Illinois Biometric Information Privacy Act protections include:

  • • Written consent before biometric data collection
  • • Clear retention schedules and deletion guidelines
  • • Prohibition on selling biometric information
  • • Right to sue for violations

Other States (VA, CO, CT, UT, etc.)

Residents of states with comprehensive privacy laws have rights to access, delete, correct data, and opt-out of targeted advertising and profiling. Contact us to exercise your state-specific rights.