Clocknet
Features How it works Pricing Use cases
Log in Get started free
Clocknet
grid_viewFeatures timelineHow it works sellPricing apartmentUse cases
EN FR AR
Log in Get started free

Legal

Privacy Notice

How Clocknet handles personal data. Draft pending legal review.

Last updated: 5 October 2026

tocOn this pageexpand_more
  1. Who is responsible for your data
  2. Data we process
  3. Location data
  4. Face verification and biometric data
  5. Why we process data
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. Security
  10. Your rights
  11. Cookies
  12. Children
  13. Changes to this notice
  14. Contact

Legal

  • Privacy Notice
  • Terms of Service
  • GDPR & Data Processing
  • Security
draft

Draft: pending legal review

This is a first draft. A lawyer has not reviewed it yet and it is not a binding policy. Text marked TO CONFIRM is still being checked.

Who is responsible for your data

link

Clocknet is a time tracking service run by [TO CONFIRM: legal entity name, registered address and company registration number]. Who is responsible for your data depends on which data it is.

  • Data in your employer's workspace, such as your time entries, location, face verification, time off, pay and approvals: your employer is the controller. We process it on your employer's behalf, as its processor.
  • Data we collect for ourselves, such as the sign-up and billing details of the person who creates a workspace, messages sent through this website, and support requests: we are the controller.

If you use Clocknet through your employer, send privacy requests to your employer first. If a request reaches us, we pass it on to your employer and help them answer it.

Data we process

link

What we process depends on the features your workspace turns on:

  • Account and profile: your name, email address, phone number, profile photo, role, team or subsidiary, and employee code.
  • Work records: clock-ins and clock-outs, breaks, timesheets, projects and tasks, shifts, time-off requests and their attachments, pay rates and calculated pay, and approvals.
  • Device data from the mobile app: platform, an install identifier, phone model, operating system and app versions, and a push notification token.
  • Sign-in and security data: a log of changes made in the workspace, single sign-on links, passkeys and two-factor authentication settings. The IP address is stored with consent records and face checks.
  • Crash reports from the app and the website, sent to Sentry. They are set up so that your name, email address and IP address are not attached.

Location data

link

Your employer decides whether Clocknet uses location. When it does:

  • When you clock in, the app reads your location once and our server checks it against your workspace's sites (geofences). If your workspace requires it and you are outside every site, the clock-in is refused, or sent to a manager for approval if your workspace allows that. Your location at clock-out may also be recorded.
  • Location sharing during a shift stays off until you turn it on in Profile, under Background location. We keep a record of when you turned it on or off.
  • With sharing on and a shift running, the app records your location at regular intervals (every 2 minutes by default) while it is open. Each record notes its accuracy and whether your phone reports it as simulated.
  • If you also allow location in the background, your phone tells the app when you enter or leave one of your sites, even when the app is closed, and the app records your location at that moment. Clocknet does not follow your location continuously in the background.
  • Recording stops when you clock out. Our server refuses location data from anyone who has not turned sharing on.
  • Managers see you on the live map only while you are clocked in with sharing on, and only if you are in the part of the organisation they manage.
  • If you turn sharing off, the app stops recording and your stored location data is deleted within 24 hours.

Face verification and biometric data

link

Face verification is optional. Your employer decides whether to turn it on for the workspace.

  • Before you set it up, the app shows you the consent text and asks you to agree. We store which version you agreed to, when, and from which IP address.
  • When you set it up, your photo is sent to AWS Rekognition, which creates a face template: a mathematical representation of your face, not the photo itself. Templates are stored in encrypted collections, one per workspace.
  • Your photo is deleted once the template is made, unless your employer sets a period for keeping photos.
  • When you clock in, and when you clock out if your workspace asks for it, a new selfie is compared with your template. We keep the time and result of each check.
  • If a check fails, your workspace settings decide whether the clock-in is refused so you can try again, or accepted and marked for review. A failed or missing check never deletes hours already recorded. A person reviews them. Clocknet does not decide anything about your pay on its own.
  • If you decline or withdraw consent, you can still clock in. Your entries are marked as not verified by face.
  • You can withdraw consent at any time in Profile. Your enrolment is retired, your face template is deleted from AWS Rekognition, and your most recent face checks are deleted within 24 hours. Deleting your account also deletes your face data.
  • We use face data only to confirm that it is you when you clock in or out. We never sell it and never use it for anything else.

Retention schedule: your face template is deleted when you withdraw consent or delete your account. When a workspace is closed, face templates are deleted with the rest of its data 30 days later. [TO CONFIRM: the deletion deadline when an employer removes a member, as laws such as the Illinois Biometric Information Privacy Act require.]

[TO CONFIRM: Morocco. CNDP deliberation 478-2013 lists tracking employees' working time and attendance among the purposes for which biometrics are not allowed, and biometric processing needs prior CNDP authorisation. Legal must decide how face verification is offered to workspaces in Morocco, and whether the company that runs Clocknet needs CNDP declarations or authorisations under Law 09-08.]

Why we process data

link

Your employer chooses the legal basis for the data in its workspace, usually the employment contract or a legal duty such as keeping working-time records. In practice:

  • Recording time, building timesheets, scheduling shifts, handling time off and approvals, and calculating pay: to perform the employment contract and meet legal duties.
  • Checking that you are at your site when you clock in: your employer's legitimate interest in accurate attendance records.
  • Face verification: your explicit consent (GDPR Article 9).
  • Location during a shift: your consent, which you can turn off in Profile at any time.
  • Our own purposes: billing the workspace owner, keeping the service secure, answering support requests, and meeting our legal obligations.

We do not use your data for advertising and we do not sell it.

Who we share data with

link
  • Your employer and the people it authorises in Clocknet, such as administrators and managers. What each person sees depends on their role and on the part of the organisation they look after.
  • Service providers who process data for us under contract (sub-processors). In the current setup these include Amazon Web Services for face matching, Sentry for crash reports, Expo for delivering push notifications to the app, and Cloudflare for network traffic to this website. [TO CONFIRM: the full list and each provider's region, including the server host, file storage, email provider, map providers (Google Maps on the sign-up page, OpenStreetMap in the geofence editor, maps in the mobile app), and whether the optional AI summary on the dashboard (Anthropic) is switched on in production.] The full list will be published on our GDPR page.
  • Public authorities, when the law requires it.

International transfers

link

[TO CONFIRM: the country where Clocknet's servers and file storage are hosted.] Face matching with AWS Rekognition happens in the eu-west-1 region (Ireland), in the European Union.

When personal data from the European Economic Area goes to a country without an adequacy decision, we use the European Commission's standard contractual clauses or another safeguard the GDPR allows. [TO CONFIRM: the safeguard in place with each sub-processor.]

For workspaces in Morocco, transfers abroad follow Law 09-08 and the rules of the CNDP, the national data protection authority. [TO CONFIRM: whether each destination country is on the CNDP's list or needs its authorisation.]

How long we keep data

link

Default retention periods:

  • Location data recorded during shifts: 90 days. Your employer can change this. If you turn sharing off, your location data is deleted within 24 hours.
  • Face photos: deleted once the face template is made, unless your employer sets a period for keeping them.
  • Face template: kept until you withdraw consent, set up face verification again, or delete your account.
  • Log of changes made in the workspace: 2 years.
  • Backups: [TO CONFIRM: how long backups are kept in production].
  • Work records such as time entries and timesheets: your employer decides how long to keep them, within the limits set by employment law.
  • After you delete your own account: your name, email address, phone number, photo and face data are erased straight away. Your employer keeps your time, timesheet, pay and time-off records, linked to your employee code instead of your name, as employment law requires.
  • After a workspace is closed: the workspace owners have 30 days to export its data, then we delete it. Copies in backups are deleted when those backups expire.

Security

link

Traffic to Clocknet is encrypted with HTTPS. All workspaces share one database, and every query for workspace data is limited to the workspace it belongs to. Access depends on each person's role, and changes are recorded in a log. Face templates are kept in encrypted AWS Rekognition collections, one per workspace.

Our Security page explains how we protect the service in more detail.

Your rights

link

Depending on the law that applies to you, you can ask to:

  • see the data we hold about you and get a copy
  • correct data that is wrong
  • delete your data
  • limit how your data is used, or object to a use
  • get your data in a format you can move to another service
  • withdraw a consent you gave, such as for face verification or background location. This does not affect what was done before.
  • complain to a data protection authority, such as the one in your EU country or the CNDP in Morocco

Some of this you can do yourself:

  • Download my data, in Privacy & data in the app or on your profile page on the web, gives you a copy of your profile, devices, time entries and breaks, face consent and check records, notifications, and the changes you made.
  • Delete account, in the app, erases your account straight away. If you don't have the app, follow the steps at /account/delete on this website.
  • Face verification and Background location, in Profile, let you withdraw those consents.

We answer requests within one month. If you use Clocknet through your employer, we pass your request to your employer, as explained above.

Cookies

link

This website uses essential cookies to keep you signed in, protect forms and remember your language. The site needs them to work, so they can't be turned off.

When you close the cookie banner or switch between light and dark mode, that choice is saved in your browser, not in a cookie, and is not sent to us.

We don't use analytics or advertising cookies. If we add any, we will update this notice and ask for your consent before setting them.

Children

link

Clocknet is a workplace tool and is not meant for children. [TO CONFIRM: the minimum age, for example 16.] If you think a child's data is in Clocknet, contact their employer or us and we will help delete it.

Changes to this notice

link

We may update this notice when Clocknet or the law changes. The date at the top shows when it last changed. [TO CONFIRM: how significant changes are announced, for example by email to workspace owners or a notice in the app.]

Contact

link

Privacy questions and requests: [TO CONFIRM: privacy contact email, and whether a data protection officer is appointed].

Postal address: [TO CONFIRM: registered address of the company that runs Clocknet].

EU representative: [TO CONFIRM: whether an EU representative is needed under GDPR Article 27, and their contact details].

Clocknet

A simple way for teams to track work time: verified, ready for offline use, and fair to everyone who clocks in.

Coming soon toApp Store Coming soon toGoogle Play

Product

  • Features
  • How it works
  • Pricing
  • Use cases
  • Get started

Company

  • About
  • Trust & security
  • Book a demo
  • Contact

Resources

  • Help center
  • Log in

Legal

  • Privacy
  • Terms
  • GDPR
  • Security
  • Delete your account
© 2026 Clocknet Privacy Terms GDPR
EN FR AR
cookie
Cookies on this site

This site only uses essential cookies. They keep you signed in, protect forms and remember your language. We don't use analytics or advertising cookies.

Cookie details