People get paid based on what Attendify records.
We treat it that way.
Attendance data decides salaries, overtime, and disputes. This page explains, plainly, how we protect it, how we verify it, and how it stays yours.
ISO
ISO 27001 certified hosting provider, EU region
TLS
Encrypted in transit (TLS 1.2+)
Daily backups today; encrypted off-site copies and at-rest volume encryption are planned
OTP + JWT
Phone-verified authentication
Logged
Administrative actions written to an audit log · viewer on Advanced & Enterprise
1:1
Per-company isolation enforced in the API
Aligned with Bahrain's PDPL, Kuwait's CITRA rules and GCC data-protection law
React Wave Labs is registered in Bahrain and operates under Bahrain's Personal Data Protection Law (Law No. 30 of 2018). Most of our customers are in Kuwait, so Attendify is also designed in line with Kuwait's CITRA data-privacy regulation, and with comparable laws in Saudi Arabia, the UAE, Qatar and Oman. We say aligned because that is the honest word: we follow the rules, and we do not claim certifications we do not hold.
Bahrain, Kuwait and GCC alignment
Operates under Bahrain's PDPL; built in line with Kuwait's CITRA data-privacy rules and comparable GCC laws.
Data processing terms
How we process your data on your behalf is set out in our Terms and Privacy Policy. If procurement needs something specific, contact us.
The data stays yours
Your attendance records belong to your company. We process them on your behalf, nothing more.
Export anytime
Pull your data out in bulk whenever you want. No tickets, no waiting, no lock-in.
Access is narrow by design
Fewer people seeing less data, verified more often. That is the whole idea.
Role-based access control
Five roles: super admin, admin, HR, supervisor, and employee. Each role sees what it needs for the job, nothing more.
Per-company tenant isolation
Every request is scoped to your company in the API, so your records are never returned with another customer's.
Device binding
One employee, one registered device. A check-in from an unrecognized phone is refused until an admin approves the change.
Rate-limited OTP login
Login codes are sent to the employee's phone and rate-limited against brute-force attempts. Employees sign in with a phone OTP; admins can add an optional password.
Who sees what
Super admin
Platform administration
Admin
Company-wide settings & reports
HR
Attendance, leave & payroll data
Supervisor
Their team only
Employee
Their own records only
Five checks between a tap and a payroll record
Every check-in is validated on the server before it counts. Fail a check, and the record is rejected or flagged for review.
-
Server-side timestamp validation
The server clock decides the time, not the phone. If a device clock drifts more than 10 minutes from the server, the check-in is rejected.
-
GPS-spoof detection
Mock-location apps, emulators and impossible travel are detected. The check-in is flagged for review, or blocked if your company chooses.
-
Geofence validation
The reported location is checked against your branch geofence. Outside the zone means no check-in.
-
Photo capture at check-in
When your company enables it, a photo is taken at check-in, so every name on a report has a face behind it.
-
Face images kept on our servers
Check-in photos and face images are stored behind authentication, used only to verify your own employees, and passed to our AI screening provider only for that purpose. They are never sold.
Your records, on your terms
The data was always yours. These are the controls that keep it that way.
Retention that follows your policy
Attendance history is kept for as long as you need it and your policy requires, not a day longer than you want.
Deletion on request
Ask us to delete your company's data and we delete it, completely.
Bulk export
Download your records in bulk at any time, for your accountant, your auditor, or your archive.
Minimal subprocessors
We keep third parties to the minimum the service needs: SMS delivery and cloud hosting. Nobody else touches your data.
The questions procurement asks
On ISO 27001 certified cloud infrastructure in the EU (Amsterdam). Data is encrypted in transit (TLS 1.2+). Daily backups run today; encrypted off-site copies and at-rest volume encryption are planned.
Only the roles you authorize, such as admins and HR. Location is captured at check-in and check-out, and during active work sessions according to your company policy. It is not continuous personal tracking, and nothing is recorded outside of that.
Our Terms and Privacy Policy set out how we process data on your behalf. If your procurement requires a separate signed agreement, contact us and we will work through it with you.
You export everything in bulk, then we delete your company's data on request. No lock-in, and no copies kept against your wishes.
Have a security questionnaire?
Send it over. We answer procurement and IT security reviews quickly and honestly. And if you are still comparing us with wall-mounted machines, we wrote that up too.