Privacy policy
Last updated:
1. Who this covers
Klock is operated by [LEGAL ENTITY NAME], registration number [REG NUMBER], of [REGISTERED ADDRESS] ("we", "us").
There are two different relationships in this product, and the difference matters:
- Our customers — the businesses who sign up. For their account data we are the responsible party (controller).
- Our customers' employees — the people who clock in. For their data, including face templates, the employer is the responsible party and we are the operator (processor). We process that data only on the employer's instructions.
If you clock in using Klock at work and want to know why your face is being processed, or want it erased, your employer is the right first point of contact. They can erase your template immediately from within the product.
2. What we collect
| Data | Why | Basis |
|---|---|---|
| Account details — name, work email, company name, hashed password | To create and secure your workspace | Performance of a contract |
| Billing details — handled by Stripe; we store only a customer reference and subscription state | To take payment | Performance of a contract |
| Employee names and codes | To identify who a punch belongs to | Employer's instruction; employment administration |
| Face templates — 128 numeric values per capture | To recognise an employee at the kiosk | Explicit consent, recorded per person by the employer |
| Punch records — time, in/out, method, device, match distance | To calculate hours worked | Employer's legal obligation to keep time records |
| Audit log — who did what, when | Security and payroll accountability | Legitimate interest |
| Server logs — IP address, request path, timestamp | Security, debugging, abuse prevention | Legitimate interest |
3. What we do not collect
- No photographs or video. Face recognition runs in the browser. The image is converted to a numeric template on the device and discarded there. No image is transmitted to us or stored by us at any point.
- No advertising or cross-site tracking cookies. The only cookies we set are the ones that keep you signed in.
- We do not use customer data to train machine-learning models. The face recognition model is a fixed, pre-trained, third-party model that we do not modify.
4. Biometric data specifically
Under POPIA a face template is special personal information; under the GDPR it is a special category of personal data. Both require a higher bar. In this product:
- A template cannot be stored for anyone until consent is recorded against their name, with the date and who recorded it.
- Consent can be withdrawn at any time, and withdrawal erases the templates.
- A person whose template is erased can still clock in with a PIN, so withdrawing consent does not cost them the ability to work or be paid.
- Templates are never shared between workspaces or used to identify anyone outside the employer that recorded them.
Employers: obtaining valid consent from your staff is your responsibility, and consent obtained under pressure of employment is not always considered freely given. Offering the PIN alternative is a meaningful part of making it genuine.
5. Who we share data with
We do not sell personal information. We use these operators:
| Who | What for | Where |
|---|---|---|
| Microsoft Azure | Hosting and storage | Western Europe |
| Stripe | Payment processing | EU / US, under standard contractual clauses |
Card details are entered on Stripe's own pages and never touch our servers. We may also disclose data where legally compelled, and will tell the affected customer unless the law forbids it.
6. Cross-border transfers
Data is hosted in Western Europe. For South African customers this is a transfer outside the Republic under section 72 of POPIA, made on the basis of contractual safeguards with our hosting provider that give effect to comparable protection. Customers who require data residency in South Africa should contact us before signing up.
7. How long we keep it
- Face templates — until consent is withdrawn, the person is erased, or the workspace is deleted.
- Punch and timesheet records — for as long as the workspace exists. Employers can set an automatic retention limit. Note that South African law requires employment time records to be kept for at least three years.
- Cancelled workspaces — kept readable for 90 days so records can be exported, then deleted on request or after 12 months.
- Audit logs — for the life of the workspace.
- Server logs — 30 days.
8. Your rights
You may request access to your personal information, correction of it, deletion, or object to processing. Employees should raise these with their employer, who can act immediately within the product; we will assist where the employer cannot. Contact us at [PRIVACY CONTACT EMAIL].
If you are unhappy with our response you may complain to the Information Regulator (South Africa) at inforegulator.org.za, or to your local supervisory authority in the EU/UK.
9. Security
Described in detail on our security page, including what is not yet in place.
10. Breach notification
If personal information is compromised we will notify the affected customers and the Information Regulator as soon as reasonably possible after establishing the scope, in line with section 22 of POPIA.
11. Changes
We will tell account holders by email at least 14 days before any change that materially reduces protection.
12. Contact
Information Officer: [NAME] · [PRIVACY CONTACT EMAIL] · [POSTAL ADDRESS]