Privacy Policy
Last updated: 23 September 2026
This Privacy Policy explains how Attendi (“Attendi”, “we”, “us” or “our”) — a workforce attendance, management and payroll platform operated by Nexify Infotech LLP, a limited liability partnership incorporated in India — collects, uses, shares, stores and protects personal data when you use our mobile applications (iOS and Android), our website at attendi.in, and our related services and APIs (together, the “Services”).
Attendi is built to be consistent with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and other applicable law. Because Attendi is provided to employers to manage their own workforce, the way we handle employee data depends on the role we play in a given situation. Please read Scope and our roles to understand who is responsible for your data.
1. Introduction — who we are
Attendi is a centralized attendance, workforce-management and payroll product for organizations in India. It helps companies record employee attendance through QR codes, face-verification and field check-ins, manage working hours and leave, generate attendance reports, and support payroll.
The Services are operated by Nexify Infotech LLP (“Nexify”), whose corporate website is nexify.co.in. We are committed to processing personal data lawfully, fairly and only for the purposes described in this policy.
Controller vs. processor. When an employer subscribes to Attendi and uses it to record and manage information about its employees, that employer decides why and how the employee data is processed. In that relationship the employer is the Data Fiduciary (equivalent to a “controller”) and Attendi/Nexify acts as a Data Processor that processes the data on the employer’s documented instructions. Separately, for our own business contacts, prospective customers and visitors to our marketing website, Nexify acts as a Data Fiduciary in its own right. This policy explains both situations.
2. Scope and our roles
This policy applies to personal data processed through the Attendi mobile applications, the Attendi backend and APIs (including api.attendi.in), and the Attendi marketing website at attendi.in. Using the terminology of the DPDP Act, the parties involved are:
| Role (DPDP Act) | Who this is | Responsibility |
|---|---|---|
| Data Fiduciary (controller) | The employer / company that subscribes to and uses Attendi. | Determines the purpose and means of processing employee data, obtains any required consent from its employees, and is the primary point of contact for employee rights requests. |
| Data Processor | Nexify Infotech LLP, operating the Attendi platform. | Processes employee personal data only on the documented instructions of the employer, and secures it as described in this policy. |
| Data Principal | The employee or end-user whose personal data is processed. | Holds the rights described in “Your rights as a Data Principal” below. |
Where we act as a Data Processor, this policy describes our practices for transparency, but the employer’s own privacy notice governs its collection and use of your data. Where an employee right must be exercised against the Data Fiduciary, we will support the employer in responding and, where appropriate, direct you to them.
3. Information we collect
We collect only the categories of data needed to operate the Services. What is actually collected for you depends on the plan your employer uses (Basic, Standard or Pro) and the features they enable.
Account and employee profile data
Name, employee identifier or code, work email address, phone number, job title / designation, department, assigned workplace or site, manager, and the login credentials used to access the app.
Attendance and working-hours data
Check-in and check-out events, timestamps, the workplace or QR code used, computed working hours, shift and break information, and the daily attendance status (for example present, late, half-day or absent).
Location, GPS and geofence data
For field-workforce features, we collect device location (GPS coordinates and accuracy) to validate that a field check-in happens inside the geofence of an assigned site, and to show approximate live location to authorized managers. Location is collected only while an employee is on an active, started field visit — it is never continuous or 24/7 tracking. Location capture stops when the field visit is completed or submitted. Office-based attendance (for example QR check-in) uses a location reading only at the moment of check-in to confirm the workplace.
Selfies and face-verification (biometric) data
Where an employer enables selfie or face check-in, we capture a selfie image at the time of check-in and, for face verification, a mathematical face template derived from a reference enrollment image. We treat this as sensitive personal data. It is used only to verify the identity of the person checking in — it is not used for surveillance, profiling, advertising or any unrelated purpose. Face verification and liveness checks run against server-side thresholds and, by design, fail closed (access is denied) if identity cannot be confirmed. Because of its sensitivity, this data is processed only with explicit, informed consent (see Legal basis and consent).
Leave records
Leave requests and balances, leave type, dates, reason (where provided), and approval or rejection status.
Payroll data
For plans that include payroll, we process salary and pay figures (in Indian Rupees, ₹), pay-period calculations, deductions and net-pay amounts, and payroll run records generated from attendance and leave data. Payroll amounts are handled only to the extent needed to support the employer’s payroll process.
Device, technical and notification data
Device model and operating-system version, app version, language, a device identifier, and a push notification token issued by Firebase Cloud Messaging (FCM) so that we can deliver notifications such as check-in reminders, leave approvals and announcements.
Phone number and one-time passwords (OTP)
We use your phone number to send a one-time password (OTP) by SMS for sign-in and verification. SMS delivery is handled through our SMS provider, 2Factor (2factor.in). We generate and verify the OTP ourselves; the OTP is short-lived and stored only in a hashed form.
Usage and log data
Technical logs generated when you use the Services, such as request timestamps, IP address, error and diagnostic information, and actions taken in the app. This data helps us keep the Services secure, reliable and working correctly.
We do not intentionally collect special categories of data beyond the biometric data described above, and we ask that you do not submit unnecessary sensitive information through free-text fields.
4. How we use the information
We use the personal data described above to:
- Record and calculate attendance, working hours, and leave for the employer.
- Verify the identity of the person checking in, using selfie or face verification where enabled.
- Validate field check-ins against a site geofence and show authorized managers approximate live location during an active visit.
- Support the employer’s payroll process and generate attendance, leave and payroll reports.
- Deliver notifications and reminders through Firebase Cloud Messaging.
- Authenticate you and secure your account, including sending SMS OTPs.
- Detect, prevent and investigate fraud, spoofing, mock-location and other misuse of the Services.
- Provide customer and technical support, and respond to your requests.
- Maintain, troubleshoot and improve the reliability, safety and performance of the Services.
- Comply with applicable legal, tax and regulatory obligations, and enforce our terms.
We do not use employee attendance, location, biometric or payroll data for advertising, and we do not sell it.
5. Legal basis and consent under the DPDP Act
Under the DPDP Act, personal data is processed on the basis of the consent of the Data Principal or for certain legitimate uses permitted by law (which can include purposes connected with employment). Because Attendi is used by employers to manage their staff:
- The employer (Data Fiduciary) is responsible for obtaining consent from its employees, and for giving each employee a clear notice of what is collected and why, before the relevant features are used.
- Face / biometric verification and location tracking require explicit, informed consent. These features are optional and are only activated where the employer has enabled them and the necessary consent has been obtained.
- Basic attendance functions may be processed as a legitimate use connected with your employment, in line with your employer’s policies and applicable law.
Withdrawing consent. Where processing relies on your consent, you may withdraw it at any time. Because your employer is the Data Fiduciary, consent is normally withdrawn through your employer (for example, by contacting your HR or admin), and it can also be raised with us at privacy@attendi.in. Withdrawing consent is as easy as giving it. Please note that withdrawing consent for a feature (for example, face verification or field-visit location) may mean you can no longer use that feature, and your employer may then require an alternative method of recording attendance. Withdrawal does not affect processing already carried out lawfully before the withdrawal.
6. Sharing, disclosure and sub-processors
We do not sell your personal data, and we do not share it for third-party advertising. We share data only in the following circumstances:
- With your employer (the Data Fiduciary) and the managers or administrators it authorizes, which is the core purpose of the Services.
- With sub-processors that help us operate the Services, under contractual confidentiality and security obligations, and only for the purposes below.
- For legal reasons — where disclosure is required to comply with applicable law, a valid legal request, or a regulatory or governmental order, or to protect the rights, safety and security of users, the public, or Attendi.
- In a business transfer — if Nexify is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this policy and applicable law.
The principal sub-processors we currently use are:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Google Firebase Cloud Messaging (Google LLC) | Delivery of push notifications to your device. | Device push token and notification content. |
| 2Factor (2factor.in) | Delivery of one-time passwords (OTP) by SMS. | Phone number and the OTP message. |
| Cloud hosting / VPS provider | Hosting of the Attendi servers, database and stored files. | All data processed by the Services, at rest on secured infrastructure. |
We keep this list current and will update it when our sub-processors change. Where a sub-processor processes data outside India, we do so only as described in Cross-border transfers.
7. Data storage, location and retention
Personal data is stored in a PostgreSQL database and file storage running on secured cloud (VPS) infrastructure managed by us and our hosting provider. We aim to host data in a region appropriate for Indian customers; where any processing occurs outside India, it is subject to Cross-border transfers below.
Retention. We retain personal data for as long as needed to provide the Services to your employer and to meet legal, tax, accounting and record-keeping obligations. In general:
- Attendance, leave and payroll records are retained for the duration of your engagement with the employer and for a period afterwards as required by law or the employer’s retention policy.
- Biometric face templates and selfies are retained only for as long as needed to provide face verification, are minimized wherever possible, and are deleted when face verification is disabled for you, when your account is de-provisioned, or on a valid erasure request (subject to any overriding legal obligation).
- Location and geofence data captured during field visits is retained only as long as needed for attendance records and reporting, and is not used to build continuous location history.
- OTPs are stored only briefly and in hashed form, and expire within minutes.
When data is no longer required, we delete it or irreversibly anonymize it. Because your employer is the Data Fiduciary, specific retention periods may also be governed by the employer’s own policies.
8. Security measures
We apply technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse or alteration, including:
- Encryption in transit using TLS/HTTPS for all communication between the apps and our servers.
- Multi-tenant isolation so that each organization’s data is segregated, enforced at the database level through row-level security (RLS).
- Access controls based on least privilege, so administrators, managers and employees can access only the data appropriate to their role, and biometric data is restricted to the data owner and authorized in-organization administrators.
- Authentication safeguards including SMS OTP, hashed one-time passwords, rate limiting and protections against replay and mock-location.
- Secured, access-controlled hosting infrastructure, along with logging and monitoring.
No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security. If we become aware of a personal data breach, we will act in accordance with the DPDP Act and notify the affected parties and authorities as required.
9. Your rights as a Data Principal
The DPDP Act grants you, as a Data Principal, the following rights in respect of your personal data:
- Right to access — to obtain a summary of the personal data we process about you and the processing activities.
- Right to correction and completion — to have inaccurate or incomplete data corrected, completed or updated.
- Right to erasure — to request deletion of personal data that is no longer necessary for the purpose it was collected, subject to legal retention requirements.
- Right of grievance redressal — to raise a grievance with us and receive a response (see Grievance Officer).
- Right to nominate — to nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent — where processing is based on consent, as described in Legal basis and consent.
How to exercise your rights. Because your employer is the Data Fiduciary for your workplace data, the quickest route is usually to contact your employer’s HR or Attendi administrator, who can action most requests directly in the platform. You may also contact us at privacy@attendi.in or our Grievance Officer below, and we will assist and, where we act as a processor, coordinate with your employer. We may need to verify your identity before acting on a request. You also have the right to make a complaint to the Data Protection Board of India.
10. Grievance Officer
In accordance with the DPDP Act, we have designated a Grievance Officer to address questions and complaints about this policy and our handling of personal data. You can reach the Grievance Officer using the details below, and we will respond within the timeframes required by applicable law.
- Grievance Officer: [Name of Grievance Officer]
- Designation: Grievance Officer, Nexify Infotech LLP
- Email: grievance@attendi.in
- Address: Nexify Infotech LLP, [Registered office address, City, State, PIN, India]
11. Children’s data
Attendi is a workplace tool intended for use by employees and organizations. It is not directed at, or intended for, children, and it should only be used by individuals who are at least 18 years of age (or the applicable minimum working age). We do not knowingly collect personal data from children. If you believe a child’s data has been provided to us, please contact us so we can take appropriate action, including deletion where required.
12. Cross-border transfers
We aim to process and store personal data within India. However, some of our sub-processors — for example Google Firebase Cloud Messaging — may process limited data (such as push notification tokens and message content) on infrastructure located outside India. Where personal data is transferred outside India, we do so only as permitted by the DPDP Act and applicable law, and only to countries that are not restricted by the Government of India for such transfers. We take reasonable steps to ensure that any recipient protects the data to a standard consistent with this policy.
13. Cookies and website analytics
This section relates to the Attendi marketing website at attendi.in. The marketing site uses minimal cookies — primarily those needed for the site to function. We keep any analytics limited and privacy-respecting, and we do not use the marketing site for cross-site advertising or profiling. The Attendi mobile apps themselves do not use advertising cookies. You can control cookies through your browser settings.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, sub-processors or legal requirements. When we make changes, we will revise the “Last updated” date at the top of this page. If the changes are material, we will provide a more prominent notice, for example within the app or by another appropriate means. We encourage you to review this policy periodically.
15. Contact us
If you have any questions, requests or concerns about this Privacy Policy or how your personal data is handled, please contact us:
- Email: privacy@attendi.in
- Grievance Officer: grievance@attendi.in
- Company: Nexify Infotech LLP — nexify.co.in
- Registered address: [Registered office address, City, State, PIN, India]