Privacy Policy
Last updated July 17, 2026
This policy explains what data Attenzo collects, why, and how you can control it. It applies to attenzo.com and the Attenzo web and mobile applications.
1. Data we collect
We collect account data (name, work email, organization), usage data (feature interactions, device and browser metadata), and — where your organization enables it — attendance data such as check-in timestamps, GPS coordinates at time of check-in, and face-verification data used solely for identity matching and attendance review.
Face verification stores a mathematical face embedding used for matching, plus a photo captured at enrollment and at each face check-in so your organization's administrators can review attendance and confirm identity. All of it is scoped to your organization and never shared with other organizations.
2. How we use it
To provide and improve the service, secure accounts, generate the analytics your admins request, and communicate service-related updates. We never sell personal data.
3. Legal basis for processing
Where GDPR applies, we process employee data under your organization's legitimate interest or contractual necessity as the data controller; Attenzo acts as a data processor on your organization's behalf. See our GDPR page for the full breakdown.
5. Retention
Attendance and payroll records are retained per your organization's configured retention window (default 3 years) or as required by local labor law, whichever is longer. Account data is deleted within 30 days of account closure upon request.
6. Your rights
You may request access, correction, export, or deletion of your personal data by contacting privacy@attenzo.com or through your organization's admin. We respond within 30 days.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. See our Security page for details on our practices and certifications.
8. Contact
Questions about this policy can be sent to privacy@attenzo.com.