LEGAL

Privacy Policy

Last updated:

This privacy policy explains how your data is collected, used and protected when you use the Point PDKS service and this website.

1. Data We Collect

Within the service we collect only the data required for employee time and attendance: identity and contact details, clock-in/out and leave/shift records, location verification at the moment of clock-in, and device/IP information for account security.

We do not collect biometric data and do not perform continuous location tracking.

2. Why We Use Data

We use data only to provide the service, ensure the accuracy of attendance records, maintain security and fulfil legal obligations. We do not sell your data for advertising purposes.

3. Multi-Tenant Data Isolation

Point PDKS runs on a multi-tenant architecture. Every query is automatically isolated by organization; one business's data cannot be viewed by another. This isolation is a core part of the application infrastructure.

4. Security Measures

Your data is encrypted in transit with SSL/TLS. Passwords are stored in an irreversibly hashed form. Critical actions are recorded in an audit log together with IP, device and change information. Access is restricted through role-based authorization.

5. Third-Party Processors

We work with a limited number of infrastructure providers to operate the service:

  • Vercel — website hosting.
  • NetGSM — sending one-time SMS codes solely for password reset.

6. Your Control Over Your Data

You may request a copy of your data to be exported or have it deleted. Your account deletion request, outside of legal retention obligations, is processed within a reasonable time. For your requests, you may write to info@cnutlabs.com.