Privacy Policy for To-Clock
Effective Date: April 7, 2026
Privacy Policy
This Privacy Policy is intended to inform you about how we collect, use, store, and protect your personal data in accordance with the Indonesian Personal Data Protection Law (UU PDP). By accessing and using our services, you agree to the collection and processing of your personal data as outlined in this Privacy Policy.
1. Information We Collect
We may collect the following types of personal data:
- Personal identification information (name, email address, phone number)
- Demographic information (age, gender, etc.)
- Payment and transaction details (credit card information, billing address, etc.)
- Usage data (IP address, browser type, operating system, access times, etc.)
- Location data (To-Clock collects precise location data during clock-in/out to verify presence within the designated office geofence.)
- Biometric Data: To-Clock collects facial images and geometry data for identity verification.
2. How We Use Your Information
Your personal data may be used for the following purposes:
Providing services (Attendance and Geospatial mapping).
Identity Verification: Using face data and liveness detection (blink detection) to ensure secure and valid attendance records.
Improving services and ensuring organizational security.
3. Data Sharing and Disclosure
We may share your personal data with trusted third parties in the following situations:
- To service providers and partners who assist in the delivery of our services
- For legal or regulatory compliance purposes, as required by Indonesian law
- In case of a merger, acquisition, or business transfer, provided your data is handled in accordance with this Privacy Policy
We ensure that any third parties we share data with have adequate security measures in place to protect your personal data.
4. Data Retention
We will retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy and to comply with applicable legal requirements.
5. Data Security
We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
6. Your Rights
Under the Personal Data Protection Law (UU PDP), you have the following rights regarding your personal data:
- The right to access your personal data
- The right to correct or update inaccurate data
- The right to request the deletion of your data (under certain conditions)
- The right to object to or restrict the processing of your data
To exercise these rights, please contact us using the details provided below.
7. Changes to This Privacy Policy
We reserve the right to update or change this Privacy Policy at any time. Any updates will be posted on this page, and the date of the latest revision will be indicated at the top of the page.
8. Biometric Data Protection (Face Data)
We implement strict measures for handling facial data:
Collection: We capture facial images and landmark points during the "Enrollment" and "Check-in" processes.
Purpose: The data is used solely for biometric matching to verify the user's identity and for liveness detection (detecting eye blinking) to prevent fraudulent attendance attempts.
Storage & Security: Facial data is processed locally using on-device machine learning (Google ML Kit & TensorFlow) and stored securely on our private, encrypted organization servers. We do not use third-party cloud biometric providers.
No Sharing: We do not share, sell, or disclose your biometric/face data to any third parties.
Retention: Biometric data is retained only as long as the user remains an active employee. Upon account deletion or employment termination, all facial templates and associated biometric records are permanently purged from our system within 30 days.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or the handling of your personal data, please contact us at:
mobilegeocollector@gmail.com
dev@rmlabs.id