AttenIP

Privacy Policy

Last updated: August 18, 2026

This is a draft prepared for launch planning. It has not been reviewed by a lawyer. Have qualified legal counsel review this document before relying on it in production.

This Privacy Policy explains what information AttenIP collects when a company and its employees use our attendance management service, and how that information is used, stored, and protected.

1. Who this applies to

AttenIP is a business-to-business (B2B) product. Company administrators register on behalf of their organization, and employees are added to the system by their employer's administrator — not by signing up directly.

This policy applies to company administrators, HR/managers, and employees using the AttenIP website and mobile app.

2. Information we collect

Company and administrator details provided at registration: company name, company code, business address and contact details, and the admin's name, email, mobile number, and password (stored as a salted hash, never in plain text).

Employee records added by a company administrator: name, employee code, department, designation, contact details, and any other fields the administrator chooses to enter (including via bulk CSV import).

Location data captured at check-in and check-out: GPS coordinates and accuracy, used to verify the employee was within an approved office radius.

WiFi network identifiers captured at check-in and check-out on the Android app: the connected network's name (SSID) and, where available, its access point hardware address (BSSID) — used to verify the employee was connected to an approved office network.

Attendance, leave, and shift records generated through normal use of the product.

Billing information processed through our payment partner, Razorpay (see "Payments" below) — AttenIP does not receive or store card or UPI account numbers.

Payroll figures computed from attendance and the salary structure a company administrator enters: basic pay, overtime pay, and statutory PF/ESI/TDS deductions, used to generate payslips.

Security audit records: for every login and every admin or HR edit to an attendance record, we keep who performed it and when, as a durable security log.

If you sign in with Google or Microsoft instead of an AttenIP password, we receive the name and email address that account shares during sign-in — never your Google or Microsoft password.

3. Optional integrations (Slack & Microsoft Teams)

A company administrator can optionally connect AttenIP to Slack or Microsoft Teams, authorized directly through Slack's or Microsoft's own sign-in screen — AttenIP never sees your Slack or Microsoft password.

Once connected, AttenIP uses the connected workspace only to deliver notifications the product already generates (for example, a new employee joining) as a direct message or chat message to your company's own admins and HR — never as a public channel post, and never to anyone outside your company.

The access token Slack or Microsoft issues is stored encrypted and used only for this purpose. A company administrator can disconnect an integration at any time from Settings, which stops further notifications and revokes AttenIP's access.

4. Biometric authentication

The AttenIP Android app supports fingerprint sign-in as a convenience for returning users. This authentication is performed entirely by the Android operating system's own biometric hardware and APIs, on the employee's device.

AttenIP does not receive, transmit, or store raw fingerprint data or biometric templates. The device only tells the app whether the biometric check succeeded or failed, and that pass/fail result is used to unlock a securely stored session credential on the same device.

5. How we use this information

To provide the core service: verifying check-in/check-out location, calculating attendance and working hours, managing leave and shift schedules, and generating the reports company administrators request.

To compute payroll figures and generate payslips from attendance and the salary structure a company administrator enters — AttenIP computes these figures but does not itself disburse salary payments.

To operate billing and subscriptions, including trial periods and plan upgrades.

To detect and investigate suspected misuse, such as attempts to spoof location or WiFi network data (see "Anti-spoofing" in our Terms of Service).

We do not sell employee or company data to third parties, and we do not use attendance or location data for advertising.

6. AI features

AttenIP includes AI-generated features for admins, HR, managers, and employees: an "Ask" assistant, plain-language attendance insights, security risk summaries, security incident triage, and shift roster suggestions.

To generate these, AttenIP sends a request to a third-party AI language model provider (currently Groq). What's sent is limited to data already computed by AttenIP's own systems for that specific request — for example, attendance analytics and percentages, security incident records, device metadata (device type/OS, approval status, risk score), or leave/shift/holiday records for the relevant employees — never raw GPS coordinates, WiFi BSSIDs, passwords, or biometric data.

This data is sent solely to generate the text response shown to you. AttenIP does not use it to train any AI model, and access to each AI feature is restricted by the same role-based permissions (admin/HR/manager/employee) that apply everywhere else in the product. The AI provider's own privacy policy governs how they handle API requests on their end.

AI features degrade gracefully when unavailable or unconfigured — the rest of the product continues to work normally without them.

7. Payments

Subscription payments are processed by Razorpay, a licensed third-party payment gateway. When you pay for a plan, your card or UPI details are entered directly into Razorpay's checkout and are not transmitted to or stored by AttenIP. AttenIP retains only the payment amount, plan, status, and Razorpay's own transaction/order identifiers, for billing records.

8. Data retention

Company and employee data is retained for as long as the company maintains an active account, and for a reasonable period afterward to comply with accounting and legal obligations. A company administrator can request deletion of their company's data by contacting support.

9. Your rights

Employees: your attendance, leave, and personal records are managed by your employer's administrator. To access, correct, or request deletion of your data, contact your company's HR or admin team, or reach us at support@attenip.com and we will route your request appropriately.

Company administrators: you can request an export or deletion of your company's data at any time by contacting support@attenip.com.

10. Children's privacy

AttenIP is a workplace product intended for use by employed adults and is not directed at children. We do not knowingly collect data from individuals under the age of 18.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above, and where appropriate, by notifying company administrators directly.

12. Contact

Questions about this policy can be sent to support@attenip.com.