Skip to main content

Privacy policy

Skoola Employee Attendance

This policy applies only to the Android employee-attendance administration app (package com.skooladmission.employeeattendance) and its school-scoped service.

Last reviewed: 6 August 2026

Effective date: 6 August 2026.

1. Who is responsible for employee data

The school or employer chooses whether to use the app, enrolls authorized employees, sets its attendance and employment-record rules, controls administrator access, and handles employee requests. Depending on applicable law and the parties' agreement, the school or employer may be the data controller or equivalent responsible organization. Skooladmission provides the school-scoped attendance service and processes data to operate it under the school's instructions and applicable agreements.

Employees should contact their school or employer first about enrollment, attendance corrections, or whether use of facial matching is required. Schools must provide any notices, lawful basis, consultation, or alternative process required in their location and must not use this employee product for student facial attendance.

2. Data the service processes

  • Transient camera photos: the app captures four guided images during enrollment or one image for an attendance scan. It is designed not to upload those photos. It deletes each local file after processing and blocks further scans if cleanup cannot be confirmed.
  • Live face-derived descriptor: on-device processing converts the photo into 128 numeric values. The descriptor is sent over an authenticated HTTPS connection for request-time comparison with the school's existing employee enrollment templates. Enrollment templates remain server-side and are not downloaded to the app.
  • Employee enrollment descriptors: after explicit employee consent, the four face-derived descriptors are sent over authenticated HTTPS and stored as that employee's school-scoped enrollment. Authorized administrators can replace or remove the enrollment.
  • Attendance and identity: after a server-confirmed match, the service processes the employee's display identity, punch-in or confirmed punch-out time, attendance classification, worked duration, applicable deduction information, and a request identifier used to prevent duplicate writes.
  • Administrator account and school profile: a Main Admin or School Admin signs in and selects an active school profile. Authenticated requests carry protected session information and the active profile; the service independently checks role and school scope.

3. Why data is processed

Data is used to authenticate authorized administrators, register or remove employee face enrollments, verify an enrolled employee for attendance, prevent duplicate or unauthorized entries, show scan and report results, maintain attendance records, configure school attendance rules, support authorized corrections, and apply the school's configured attendance inputs to payroll processing.

4. Retention and deletion

  • Temporary camera photos are designed to be deleted immediately after descriptor extraction.
  • Live descriptors are designed to remain only for the active scan in app and server request memory. They are not intended to become a new enrollment template or part of the attendance record.
  • Attendance records are kept under the school or employer's employment-record schedule and applicable legal duties. The exact period, backup expiry, and deletion timetable are determined by the responsible school and its service agreement; this page does not invent a universal period.
  • Enrollment descriptors remain until authorized replacement or removal, employee or school deletion, or the applicable approved retention period. Backup expiry and deletion propagation follow the school's service agreement.

Deletion may be limited where an attendance or employment record must be retained. Employees can ask their school for the schedule that applies to them and for the status of a request.

5. Sharing, sale, advertising, and tracking

The employee-attendance app contains no advertising, does not sell personal data, and does not use face-derived or attendance data for advertising or cross-app tracking. Service providers that host or secure the service may process data only to provide those functions under the applicable organizational arrangements. The responsible school can provide the processor information applicable to its deployment.

6. Security

Controls include authenticated HTTPS requests, school-scoped role and active-profile checks, Android protected credential storage, server-side enrollment templates, duplicate-request protection, no offline attendance-write queue, and scan blocking when temporary-photo cleanup is unresolved. Access to settings, monitoring, corrections, and payroll functions is restricted to authorized administrators. No security measure can eliminate every risk; schools must physically secure attendance devices and promptly sign out or remove devices that are lost or no longer trusted.

7. Employee choices and requests

Subject to applicable law, employees may ask their school or employer for access to attendance information, correction of an inaccurate record, information about retention or recipients, or consideration of an objection, restriction, or deletion request. A request is not guaranteed to result in deletion where lawful retention is required. Start with the school administrator or HR contact that manages attendance. For product-level privacy questions, use the contact route below.

8. Changes to this policy

When this policy changes, the revised text and review date will appear at this public path. Material operational changes may also require notice from the school or employer. See the Employee Attendance Support page for troubleshooting and request guidance.