Privacy Policy for SYNC HR Employee App
Last Updated: July 03, 2026
This Privacy Policy explains how the SYNC HR Employee Application
("Application" or "App"), an enterprise Human Resource and Attendance Management
system, collects, uses, stores, and protects data when used by employees,
contractors, and authorized personnel ("Users", "you", or "your") of the employer
organization ("Employer", "Company", or "Organization") that has deployed this
Application.
1. Introduction & Scope
The Application is developed and provided as an internal business tool for the
Employer to facilitate employee attendance marking, geofence verification,
facial authentication (liveness checks), profile management, and
shift/regularization request tracking.
By using the Application, you acknowledge that your personal information and
usage data are processed primarily on behalf of and under the instruction of
your Employer, who acts as the Data Controller. The Application
processes this data as a Data Processor to fulfill employment
contract and HR management requirements.
2. Information We Collect
To provide precise attendance tracking, secure login, and HR services,
the Application requests permissions to access specific device sensors
and personal data.
A. Real-Time Location Information (Geofencing)
- What We Collect: Precise geographic coordinates (GPS latitude and longitude).
- Why We Collect It: To verify that you are physically present within the designated branch coordinates (geofences) established by your Employer when you check in or check out.
- How It is Handled: Location data is accessed only while you perform attendance actions such as Check-In, Check-Out, or viewing branch coverage. The Application does not continuously track your location in the background.
B. Camera & Facial Recognition Data (Face Liveness Verification)
- What We Collect: Device camera access, temporary facial image frames, and on-device biometric face embeddings.
- Why We Collect It: To perform facial verification and liveness detection (such as blink, smile, and head movement detection) and prevent fraudulent attendance.
- How It is Handled:
- Image frames are processed locally using the
MobileFaceNet machine learning model.
- Face embeddings are compared locally to verify identity.
- The final verification image captured after successful verification is securely uploaded to your Employer's HR database as attendance proof.
C. Local Biometric Data
- What We Collect: Fingerprint or Face ID authorization status through your device's native biometric framework.
- Why We Collect It: To enable secure password-free authentication.
- How It is Handled: The application uses the native
local_auth framework. We never collect or store your fingerprint or Face ID data. The operating system only returns a success or failure result.
D. Device and Network Information
- What We Collect: Device model, operating system version, IP address, and Wi-Fi SSID.
- Why We Collect It: To verify attendance from authorized networks, ensure compatibility, and troubleshoot technical issues.
E. Account & Profile Data
- What We Collect: Employee ID, professional email address, full name, department, phone number, and shift logs.
- Why We Collect It: To associate attendance records with your HR profile. This information is provisioned by your Employer's IT administration.
F. Push Notification Tokens
- What We Collect: Firebase Cloud Messaging (FCM) device token.
- Why We Collect It: To deliver attendance updates, shift approvals, HR announcements, and other important notifications.
3. How Your Information is Used
Your Employer and the Application use collected information strictly for
operational, security, and administrative purposes.
- Attendance Auditing: Accurate clock-in and clock-out records.
- Security & Fraud Prevention: Prevent unauthorized attendance and identity fraud.
- HR Administration: Manage attendance, shifts, regularization requests, leave, and notifications.
- Application Optimization: Improve performance, resolve technical issues, and maintain secure backend communication.
4. Data Sharing & Third Parties
- Employer Access: Attendance logs, verification status, and attendance photographs are securely uploaded to your Employer's HR systems.
- No Commercial Sharing: We never sell, rent, lease, or share personal information with advertisers or marketers.
- Service Providers: Firebase (Google) is used for push notifications and cloud infrastructure services in accordance with applicable security standards.
5. Data Storage, Security & Retention
-
Local Storage:
- Application preferences and cached attendance logs are stored using
Hive.
- Authentication tokens are securely encrypted using
flutter_secure_storage.
- Data in Transit: All communication with backend servers is encrypted using HTTPS (SSL/TLS).
- Data Retention: Data is retained according to your Employer's retention policy and applicable labor laws. After employment ends, access is revoked and records are managed according to company policies.
6. Your Rights and Controls
Your rights regarding personal data are governed by your Employer's HR policies
and applicable labor laws.
- Sensor Permissions: Camera, location, and notification permissions can be granted or revoked through your device settings. Disabling required permissions may prevent attendance marking.
- Data Access & Deletion Requests: Contact your HR Department or IT Administrator to inspect, correct, or request deletion of attendance records or facial enrollment information.
7. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect operational,
legal, or regulatory changes. Any significant updates will be communicated
through the Application where appropriate. The "Last Updated" date at the
top of this document indicates the latest revision.
8. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy
or how your information is processed, please contact:
- HR / IT Support: Refer to the support contacts available in your Employee Portal.
- Application Developer / Administrator: Contact your organization's IT Infrastructure Department.