Attendance data decides salaries, overtime, and disputes. This page explains, plainly, how we protect it, how we verify it, and how it stays yours.
Data hosted in-region
Encrypted in transit and at rest
Phone-verified authentication
Sensitive actions audit-logged
One isolated tenant per company
Data protection
Attendify is designed to operate in line with Kuwait's CITRA Resolution No. 26 of 2024 and comparable data-protection regulations across the GCC. We say aligned because that is the honest word: we follow the rules, and we do not claim certifications we do not hold.
Built in line with CITRA Resolution No. 26 of 2024 on data privacy protection, and comparable GCC regulations.
Need a Data Processing Agreement for procurement or legal review? Ask, and we will send it.
Your attendance records belong to your company. We process them on your behalf, nothing more.
Pull your data out in bulk whenever you want. No tickets, no waiting, no lock-in.
Security architecture
Fewer people seeing less data, verified more often. That is the whole idea.
Five roles: super admin, admin, HR, supervisor, and employee. Each role sees what it needs for the job, nothing more.
Every company runs in its own isolated tenant. Your records are never mixed with another customer's.
One employee, one registered device. A check-in from an unrecognized phone is refused until an admin approves the change.
Login codes are sent to the employee's phone and rate-limited against brute-force attempts. No passwords to leak or reuse.
Who sees what
Super admin
Platform administration
Admin
Company-wide settings & reports
HR
Attendance, leave & payroll data
Supervisor
Their team only
Employee
Their own records only
Record integrity
Every check-in is validated on the server before it counts. Fail a check, and the record is rejected or flagged for review.
The server clock decides the time, not the phone. If a device clock drifts more than 10 minutes from the server, the check-in is rejected.
Mock-location apps and GPS spoofing are detected, and the check-in is blocked before a fake location is accepted.
The reported location is checked against your branch geofence. Outside the zone means no check-in.
A photo is taken at check-in, so every name on a report has a face behind it.
Face verification templates are stored privately, used only to verify your own employees, and never shared or sold.
Your data, your control
The data was always yours. These are the controls that keep it that way.
Attendance history is kept for as long as you need it and your policy requires, not a day longer than you want.
Ask us to delete your company's data and we delete it, completely.
Download your records in bulk at any time, for your accountant, your auditor, or your archive.
We keep third parties to the minimum the service needs: SMS delivery and cloud hosting. Nobody else touches your data.
Security FAQ
On cloud infrastructure in the GCC region. Your attendance data stays close to home, inside a legal environment your lawyers already know.
Only the roles you authorize, such as admins and HR. Location is captured at check-in and check-out, and during active work sessions according to your company policy. It is not continuous personal tracking, and nothing is recorded outside of that.
Yes. A DPA is available on request for procurement and legal review. Contact us and we will send the current version.
You export everything in bulk, then we delete your company's data on request. No lock-in, and no copies kept against your wishes.
Send it over. We answer procurement and IT security reviews quickly and honestly. And if you are still comparing us with wall-mounted machines, we wrote that up too.