Privacy Policy

Construct Manager — Attendance & Performance Management

1. Who we are and what this policy covers

This policy explains what personal data we collect through the platform, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to meet the requirements of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Roles. Where you are our employee or a worker engaged directly by us, we act as the Data Fiduciary. Where the platform is deployed for a client organisation (a builder, principal employer or contractor), that organisation is the Data Fiduciary for its own workforce data and we act as a Data Processor on its written instructions. In that case, this policy describes our practices; your employer's own notice governs the purposes for which your data is used.


2. Personal data we collect

2.1 Identity and contact details

Name, worker or employee code, date of birth, gender, father's or husband's name, photograph, phone number, email address, permanent and local address (state, city, area, pincode), and emergency contact name and phone number.

2.2 Employment and engagement details

Contractor or department, assigned project and site, job category, skills, date of joining, employment type, employment status, and the history of changes to those assignments.

2.3 Financial and statutory details

Wage rate (daily, monthly or hourly), overtime rate, salary, PF and other deductions, salary advances, payroll records and payslips, ESI/PF identification number, and the history of wage changes and approvals.

2.4 Government identifiers

Aadhaar number, collected only with your separate, explicit and recorded consent. We store the timestamp at which consent was given. The Aadhaar number is stored in encrypted form and is never displayed in full in reports or exports. You may refuse to provide it; where Aadhaar is legally required for a statutory filing, we will tell you before collecting it.

2.5 Biometric and authentication data

Biometric data is treated as sensitive personal data. We collect it only for attendance verification and payroll accuracy, and never for surveillance, emotion analysis, performance profiling or any purpose not listed in Section 3.

2.6 Attendance and location data

Check-in and check-out date and time; the method used (face, PIN, QR, RFID, device punch or manual entry); GPS latitude and longitude captured at the moment you check in or check out; whether that location fell inside the site's geofence; the attendance photograph captured at the punch, where your site has enabled photo capture; the device that recorded the punch; working hours, overtime hours and their approval status; and leave, time-off and attendance correction requests.

We capture location only at the moment of a check-in or check-out. We do not track your location continuously, in the background, or after working hours.

2.7 Site operations content

Daily task and progress entries, activity photographs and media you upload, incident and safety reports, training records, permits, safety checklists and performance reviews.

2.8 Technical and security data

Login history (username, IP address, device description, success or failure and timestamp); audit logs recording who created, updated or deleted a record, what changed, and from which IP address; mobile push notification tokens; and app preference settings.

2.9 Data stored on your phone

The mobile app stores attendance records, your face template and reference data in a local database on your device so that you can mark attendance when the site has no network coverage. This data is synchronised to our servers when connectivity returns, and is deleted when you log out or uninstall the app.


3. Why we process your data, and on what basis

Purpose

Data used

Lawful basis under the DPDP Act

Recording attendance and verifying identity at the site

Biometric template, PIN, attendance timestamps, location, photo

Consent; and employment-related legitimate use

Calculating wages, overtime, advances and payroll

Employment, attendance and financial data

Performance of the employment relationship

Statutory compliance — PF, ESI, labour and welfare board filings, muster rolls, wage registers

Identity, Aadhaar, employment and payroll data

Compliance with law

Site safety, incident management and access control

Identity, attendance, incident, training and permit records

Legitimate use for employment purposes and safety of persons

Workforce planning, supervision and reporting to the principal employer

Attendance and project assignment data

Legitimate use for employment purposes

Preventing proxy attendance ("buddy punching") and fraud

Biometric template, location, geofence result, audit logs

Legitimate use for employment purposes

Securing the platform and investigating misuse

Login history, audit logs, IP address

Legitimate use; compliance with law

Sending you operational notifications

Push token, phone number

Consent

We do not sell your personal data, and we do not use it for advertising, credit scoring, or automated decisions that produce legal effects on you without human review.


4. Consent

Where we rely on your consent — in particular for face registration, biometric attendance and Aadhaar collection — we will:

Withdrawing consent for biometric attendance does not affect your employment. Your site will provide an alternative method — PIN, card or supervisor-marked manual attendance. Withdrawal does not undo processing that already happened lawfully, and we may continue to retain records we are legally required to keep (for example, wage registers).


5. Who we share your data with

We do not share your data with anyone else without your consent, unless required by law.


6. Where your data is stored

Your personal data is stored on servers located in [India / specify region]. Where any processing occurs outside India, it will be limited to countries not restricted by the Central Government under Section 16 of the DPDP Act, and will be covered by contractual safeguards.


7. How long we keep your data

Category

Retention period

Face templates and PIN hashes

Deleted within [30] days of your exit, or immediately on withdrawal of consent

Attendance records, muster rolls and wage registers

[3] years after the relevant financial year, or as required under applicable labour legislation, whichever is longer

Payroll, PF and ESI records

[8] years, as required by tax and statutory rules

Aadhaar number (encrypted)

Only while required for a statutory filing; deleted thereafter

Attendance photographs and site media

[12] months, unless attached to an open incident or dispute

Login history and audit logs

[24] months

Local data on your phone

Until you log out or uninstall the app

When a retention period ends, we delete the data or irreversibly anonymise it so it can no longer identify you. Records under an active legal claim, audit or investigation are retained until that matter closes.


8. How we protect your data

No system is perfectly secure. In the event of a personal data breach, we will notify the Data Protection Board of India and every affected person, in the form and within the time required by the DPDP Act and its rules.


9. Your rights

Under the DPDP Act, you have the right to:

To exercise any of these rights, contact the Grievance Officer below, or ask your site supervisor to raise the request on your behalf. We may ask you to verify your identity before we act. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

11. Children and persons with disabilities

The platform is not intended for anyone under 18 years of age, and we do not knowingly register minors as workers. Where the law requires it, processing of a child's data, or the data of a person with a lawful guardian, will be carried out only with verifiable consent from the parent or guardian, and never for tracking, behavioural monitoring or advertising. If you believe a minor has been registered, contact the Grievance Officer and we will remove the record.


12. Permissions the mobile app requests

Permission

Why it is needed

Camera

To capture your face for registration and attendance verification, and to attach photographs to site activity and incident reports

Location (precise)

To record where a check-in or check-out took place and confirm it is within the site boundary. Captured only at the moment of a punch, never in the background

Storage

To save photographs and offline attendance records on your device until they sync

Internet / network access

To sync data with our servers

Notifications

To alert you about approvals, shifts and requests

You can refuse or revoke any of these in your phone's settings. Refusing camera or location permission will prevent face-based or geofenced attendance; your site will provide an alternative method.


13. Changes to this policy

We may update this policy as the platform or the law changes. We will post the revised version in the app and on [website URL], update the "Last updated" date, and where the change is significant, notify you in the app before it takes effect. Where a change requires it, we will ask for fresh consent.


This document reflects how the Construct Manager platform actually handles data, based on its database schema, API and mobile app permissions. It is not legal advice. Have it reviewed by qualified legal counsel, and complete every field marked in [brackets], before publishing it.