1. Scope
This policy applies to the public EkamQR website, demo and support interactions, and EkamQR product deployments where EkamQR is responsible for processing personal information. A customer organization may separately determine why and how employee information is processed in its own deployment. In those cases, the customer's instructions and the applicable commercial agreement may also govern.
2. Information we may process
Depending on the modules and deployment selected, information may include:
- Contact and account information such as name, work email, phone number, username and organization details.
- Employee master data such as employee code, department, designation, team, location, reporting structure and employment dates.
- Attendance information such as punch times, shifts, attendance status, exceptions, source and audit history.
- Location information when location validation is enabled for a mobile attendance workflow.
- Device and technical information such as device identifiers, trusted-device state, browser/app information, IP-related logs and diagnostic events.
- Leave, payroll, canteen or other workforce information when the customer enables those modules.
- Information submitted through demo, support or other contact forms.
3. Biometric and device data
Biometric handling depends on the attendance method and deployment. Mobile fingerprint verification is designed to use supported device biometric capabilities rather than requiring the public website to collect a raw fingerprint image. Connected biometric attendance devices may process or store vendor-specific biometric data according to the device, integration and customer configuration.
Customers should configure biometric and location features only where they have an appropriate lawful basis, notices and employee permissions or consents required by applicable law.
4. How information is used
- Provide authentication, attendance, workforce, reporting and enabled operational features.
- Validate attendance context, apply configured shifts and rules, and maintain audit records.
- Operate demo, onboarding, support, troubleshooting, backup and security processes.
- Communicate about requested demos, service notices and customer support.
- Protect the service, investigate misuse and meet legal or contractual obligations.
6. Retention and deletion
Retention depends on the deployment, module, customer configuration, contractual requirements and legal obligations. Customer administrators may have their own retention responsibilities. Backup copies may persist for a limited period after operational data is deleted.
7. Security
EkamQR is designed with role-based access controls, audit visibility, authentication controls and secure deployment practices. Internet-facing deployments should use HTTPS/TLS. No system can promise absolute security, so customers should also protect administrator accounts, endpoints, networks and connected devices.
See the Security Overview for more information.
8. Access, correction and other choices
Requests about workforce data should normally be directed to the organization that controls the employee account. For information collected directly by EkamQR through the public website or a direct service relationship, you may contact us to request access, correction or deletion where applicable.
9. Contact
Email hello@ekamqr.com. Please include enough information for us to identify the relevant account or request without sending passwords or unnecessary sensitive data.
