Draft for review. This policy is a working draft prepared alongside the product. It describes what the software actually does, but it has not been reviewed by a lawyer and must be before the service is offered commercially. Company details marked [SQUARE BRACKETS] still need completing.

Privacy policy

Last updated:

1. Who this covers

Klock is operated by [LEGAL ENTITY NAME], registration number [REG NUMBER], of [REGISTERED ADDRESS] ("we", "us").

There are two different relationships in this product, and the difference matters:

If you clock in using Klock at work and want to know why your face is being processed, or want it erased, your employer is the right first point of contact. They can erase your template immediately from within the product.

2. What we collect

DataWhyBasis
Account details — name, work email, company name, hashed password To create and secure your workspace Performance of a contract
Billing details — handled by Stripe; we store only a customer reference and subscription state To take payment Performance of a contract
Employee names and codes To identify who a punch belongs to Employer's instruction; employment administration
Face templates — 128 numeric values per capture To recognise an employee at the kiosk Explicit consent, recorded per person by the employer
Punch records — time, in/out, method, device, match distance To calculate hours worked Employer's legal obligation to keep time records
Audit log — who did what, when Security and payroll accountability Legitimate interest
Server logs — IP address, request path, timestamp Security, debugging, abuse prevention Legitimate interest

3. What we do not collect

4. Biometric data specifically

Under POPIA a face template is special personal information; under the GDPR it is a special category of personal data. Both require a higher bar. In this product:

Employers: obtaining valid consent from your staff is your responsibility, and consent obtained under pressure of employment is not always considered freely given. Offering the PIN alternative is a meaningful part of making it genuine.

5. Who we share data with

We do not sell personal information. We use these operators:

WhoWhat forWhere
Microsoft AzureHosting and storageWestern Europe
StripePayment processingEU / US, under standard contractual clauses

Card details are entered on Stripe's own pages and never touch our servers. We may also disclose data where legally compelled, and will tell the affected customer unless the law forbids it.

6. Cross-border transfers

Data is hosted in Western Europe. For South African customers this is a transfer outside the Republic under section 72 of POPIA, made on the basis of contractual safeguards with our hosting provider that give effect to comparable protection. Customers who require data residency in South Africa should contact us before signing up.

7. How long we keep it

8. Your rights

You may request access to your personal information, correction of it, deletion, or object to processing. Employees should raise these with their employer, who can act immediately within the product; we will assist where the employer cannot. Contact us at [PRIVACY CONTACT EMAIL].

If you are unhappy with our response you may complain to the Information Regulator (South Africa) at inforegulator.org.za, or to your local supervisory authority in the EU/UK.

9. Security

Described in detail on our security page, including what is not yet in place.

10. Breach notification

If personal information is compromised we will notify the affected customers and the Information Regulator as soon as reasonably possible after establishing the scope, in line with section 22 of POPIA.

11. Changes

We will tell account holders by email at least 14 days before any change that materially reduces protection.

12. Contact

Information Officer: [NAME] · [PRIVACY CONTACT EMAIL] · [POSTAL ADDRESS]