Skip to content
Last updated: September 1, 2026v2.0~15 min read

Privacy Policy & Workforce Data Governance Standards

Official workforce privacy standards, location data policies, and permission guidelines for the AttendKH Mobile Attendance App & Cloud Suite.

App Privacy Details
Apple App Store 5.1.1Google Play Data Safety

AttendKH Mobile App Privacy & Data Safety

The developer, AttendKH, indicated that the mobile application handles data solely for workplace attendance verification and secure employee authentication as described below.

Tracking

No Data Used to Track You

The developer does not track you across apps and websites owned by other companies.

Zero Ad Tracking • Never Sold
Linked Data

Data Linked to You

The following data may be collected and linked to your employee identity:

  • Contact Info: Phone or Email (1 required for login) • Staff ID
  • Device Model: Model & OS version bound for anti-fraud lock
  • Instant Location: Point-in-time check only (0% background GPS)
  • Selfie Photo: Watermarked clock-in photo (AES-256 encrypted)
Security

Security & Protections

Technical security measures and data subject rights:

  • Encryption: TLS 1.3 in-transit & AES-256 at rest
  • Account Deletion: Self-service & 30-day hard deletion SLA
  • Labor Compliance: MoLVT & NSSF statutory retention
* Privacy practices may vary based on the optional features enabled by your employer (such as live selfie check or QR kiosk mode).AttendKH Compliance Suite v2.2

Key Privacy & Compliance Pillars

Mobile Suite 2.0 Standards

Point-in-Time GPS Only

Zero 24/7 background tracking. GPS location is captured strictly at the instant of clocking in/out to verify geofence radius.

Encrypted Live Selfies

Live front-camera photo verifies physical presence and prevents buddy punching. Watermarked, encrypted, and never sold.

App Store & Play Store Compliant

Complete transparency for Camera, Location, Storage, and Push Notification runtime permissions.

Account & Data Deletion Rights

Employees and employers can easily request permanent account and record erasure within 30 days.

AttendKH Point-in-Time GPS Geofence Architecture vs Zero Background Tracking
Point-in-Time GPS ProtocolFigure 1.0

AttendKH Point-in-Time Geofence Radius Verification Architecture

Location coordinates are queried exclusively for 1-2 seconds during the punch event to mathematically evaluate the employer's geofence perimeter. The location sensor immediately disengages upon verification.

Multi-Layer Encryption: TLS 1.3 in Transit, AES-256 at Rest, Multi-Tenant Cloud Vault
Multi-Layer SecurityFigure 2.0

Multi-Layer Encryption & Data Vault Architecture

TLS 1.3 in-transit protocol coupled with AES-256 storage-level encryption and strict multi-tenant database partitioning.

AttendKH iOS & Android Mobile Attendance App Privacy Standards
App Store ComplianceFigure 3.0

iOS & Android Mobile Attendance Compliance

Cryptographically watermarked selfie punches meeting Apple App Store 5.1 & Google Play transparent data safety benchmarks.

Direct Comparison: Point-in-Time GPS vs Continuous 24/7 Tracking

AttendKH is engineered specifically to respect worker autonomy and prevent invasive off-duty monitoring.

What AttendKH Does (Point-in-Time)

  • Captures GPS only on punch tap: Active for 1-2 seconds to verify branch radius.
  • Sensors turn off immediately: Zero background location daemon is active.
  • 100% Off-duty privacy: Employers have zero visibility outside work hours.

What AttendKH NEVER Does (Zero Surveillance)

  • NO 24/7 background breadcrumb tracking: Never logs routes, travel history, or speed.
  • NO audio, microphone, or screen recording: Zero keystroke, screen, or microphone capture.
  • NO selling location data to brokers: Strict zero-monetization guarantee.

Mobile Device Permissions & Runtime Justifications

Compliant with Apple App Store Guideline 5.1.1 & Google Play Developer Policies.

Location Services

NSLocationWhenInUseUsageDescription
Sensitive
Operational Purpose:

Verifies that the employee is physically present within the branch geofence boundary at the active moment of clocking in.

User Control & Revocation:

Set to 'While Using App'. Background location is never requested or required.

Camera Access

NSCameraUsageDescription
Sensitive
Operational Purpose:

Captures a live front-camera selfie timestamped at clock-in to prevent proxy attendance (buddy punching).

User Control & Revocation:

Activated solely when the punch button is triggered. No background video or continuous streaming.

Encrypted Local Storage

App Sandbox & iOS Keychain
Standard
Operational Purpose:

Caches encrypted punch records and selfie metadata locally when working in remote or low-connectivity zones, syncing automatically on reconnect.

User Control & Revocation:

Strictly isolated within the operating system's protected application sandbox.

Push Notifications

UNUserNotificationCenter
Optional
Operational Purpose:

Delivers shift commencement reminders, leave approval notifications, and manager schedule updates.

User Control & Revocation:

Optional permission. Can be toggled on or off at any time in device settings.

1. Introduction & Overview#

AttendKH ("we", "our", "us", or "AttendKH") is committed to protecting the privacy, confidentiality, and fundamental data protection rights of organizations, employers, and their employees across Cambodia and international operating regions.

This Privacy Policy explains how AttendKH collects, uses, processes, stores, and safeguards personal data when you:

  • Use our mobile applications for iOS (App Store) and Android (Google Play Store);
  • Access our shared tablet QR Kiosk hardware modes;
  • Log into our web applications, manager consoles, and administrative dashboards;
  • Connect to our automated Telegram Bot notifications and webhook integrations;
  • Visit our public website and marketing resources at attendkh.com.

By downloading, accessing, or using the AttendKH Attendance mobile application or web portal, you acknowledge that you have read and understood the practices described in this policy.


2. Roles & Responsibility: Data Controller vs. Data Processor#

To ensure transparency and compliance with global data protection standards (including GDPR principles and Cambodian personal data protections under the Civil Code and E-Commerce Law):

  • Your Employer / Organization (Data Controller): The subscribing business or institution that employs you is the Data Controller. Your employer determines the personnel enrolled in AttendKH, sets authorized workplace geofences, configures shift rosters, approves attendance punches, and establishes compensation and payroll rules.
  • AttendKH (Data Processor / Service Provider): AttendKH acts strictly as a Data Processor on behalf of and under the contractual instructions of your employer. We provide secure cloud infrastructure, cryptographic check-in verification algorithms, automated Cambodian labor law payroll calculation engines, and encrypted database storage.

If you are an individual employee with questions regarding why specific attendance rules or shift requirements apply to you, please contact your employer's human resources or operations department directly.


3. Categories of Data Collected by the Attendance App & Platform#

A. Employee Profile & Authentication Identifiers

When an employer registers an employee profile on AttendKH, or when you complete your employee mobile onboarding, we process:

  • Full Legal Name & Display Name
  • Employee Identification Number (Staff ID)
  • Authentication Contact Identifiers (Phone Number or Email): At least ONE contact identifier (either a valid Phone Number for SMS/Telegram OTP verification OR a verified Email Address for magic links/OTP) is strictly required to authenticate your account and receive secure login codes. Providing both contact methods is optional.
  • Workplace Branch Assignment: Department, operational team, role/title, and reporting manager
  • Wage & Employment Structure: Base hourly or monthly salary parameters, overtime eligibility, standard shift templates, and statutory NSSF insurance classification (used exclusively for automated payslip generation)

B. Point-in-Time GPS Location Data & Geofencing

To verify that frontline staff are physically present at their assigned workplace branch (e.g. boutique store, restaurant, construction site, or office), AttendKH mobile apps query device location services under strict privacy rules:

  • Point-in-Time Capture Only: Location coordinates (latitude, longitude, horizontal accuracy radius, and server timestamp) are captured ONLY at the exact millisecond you trigger an active punch event (Clock In, Clock Out, or Break Start/End).
  • ZERO 24/7 Continuous Background Tracking: AttendKH NEVER monitors your continuous movement, travel routes, off-shift whereabouts, or location outside active clock-in events. When the mobile app is minimized or closed, GPS sensors remain completely inactive.
  • Geofence Radius Verification: The instantaneous GPS coordinate is mathematically compared against the authorized branch perimeter set by your employer (typically 50 to 300 meters). The system records whether the punch occurred "Inside Radius" or "Outside Radius" along with accuracy confidence metrics.
  • Mock Location & Anti-Spoofing Detection: The mobile app includes tamper-resistance algorithms that detect simulated GPS positions, third-party mock location apps, and developer-mode spoofing tools to maintain payroll fairness and fraud prevention.

C. Live Biometric / Selfie Photo Verification

To prevent fraudulent "buddy punching" (where one worker clocks in on behalf of an absent colleague) and verify identity at branch locations:

  • Live Selfie Photo at Punch: When enabled by your employer, the mobile app or QR Kiosk captures a live front-camera photograph at the exact moment of clock-in.
  • Watermarking & Cryptographic Binding: The photo is automatically stamped with cryptographic punch metadata (timestamp, branch ID, employee ID, and GPS coordinates) to prevent photo substitution.
  • Restricted Access: Selfie photographs are accessible only to authorized managers and HR administrators of your specific organization for audit and attendance verification purposes.
  • NO Third-Party AI Selling or Public Profiling: AttendKH does NOT sell, rent, monetize, or license your facial imagery to third parties, advertising networks, or external facial recognition training datasets.

D. Device Model, Hardware Authorization & Anti-Fraud Telemetry

To ensure mobile app security, authenticate authorized devices, and prevent multi-phone buddy punching or falsified check-ins, the mobile app collects:

  • Device Model & Manufacturer (e.g., Apple iPhone 15 Pro, Samsung Galaxy S24, Xiaomi 13): Used to bind your employee profile to your authorized workplace device and prevent ghost clock-ins across unauthorized secondary phones.
  • Operating System & Version (e.g., iOS 17.4, Android 14): Used for compatibility, security patching, and app stability.
  • Unique App Instance Identifier (UUID) and hardware installation token.
  • Network State & IP Address: Used to detect proxy evasion and ensure safe transmission.
  • Crash Reports & Diagnostics: Non-identifying error stack traces used exclusively to resolve software bugs.

E. Offline Punch Queue & Local Device Storage

When employees work at remote project sites or provincial locations with unstable cellular connectivity (e.g., construction sites, agricultural facilities, or underground parking):

  • Encrypted Local Cache: Attendance punches, timestamps, GPS coordinates, and selfie photos are stored within the mobile app's encrypted local sandbox storage (SQLite/Keychain).
  • Automatic Background Synchronization: As soon as the mobile device reconnects to a cellular or Wi-Fi network, queued punches are cryptographically verified and uploaded to AttendKH cloud servers.

F. Payroll, Overtime & Time Records

As attendance data is collected, AttendKH generates and stores statutory workforce records:

  • Clock-in and clock-out timestamps, total daily hours, and break durations
  • Grace-period late arrivals and early departures calculated against employer shift rules
  • Statutory overtime hours categorized into standard overtime (1.5× base rate) and Cambodian public holiday / weekly rest day overtime (2.0× double rate)
  • Paid annual leave, sick leave, and special leave accruals and approvals
  • Bilingual PDF payslips generated in US Dollars ($) and Khmer Riel (៛) with NSSF statutory contribution breakdowns

G. Messaging & Automated Notifications

  • Telegram Bot Integration: If your organization connects AttendKH to Telegram, we store your Telegram User ID and Chat ID to transmit real-time manager alerts (e.g., late arrivals, missed shifts, overtime warnings) and daily attendance summaries.

H. Website Visitors & Sales Inquiries

  • Marketing Inquiries: Information submitted through demo requests, pricing inquiries, or contact forms (name, company, business email, phone number, branch count).
  • Cookie Consent: User preferences saved via our Cookie Consent banner (Necessary, Analytics, Functional, and Marketing cookies).

4. Mobile Device Permissions Matrix (Apple App Store & Google Play Disclosures)#

In compliance with Apple App Store Review Guidelines and Google Play Developer Policies, the table below outlines all mobile permissions requested by the AttendKH application and their exact operational justification:

Permission (iOS / Android) Sensitivity Level Purpose & Operational Justification User Choice & Control
Location Services
(ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION)
Sensitive Used strictly at the instant of clocking in/out to confirm presence within the employer's authorized branch geofence radius. Required for GPS punches. You can set permission to "While Using the App". Background location is never requested or enabled.
Camera
(CAMERA)
Sensitive Used to capture a live selfie verification photo during clock-in to prevent buddy punching and verify worker identity. Required for selfie-verified punches. Camera is only activated when you tap the punch button.
Local Storage / Files
(READ/WRITE_EXTERNAL_STORAGE / Sandbox)
Normal Used exclusively to cache encrypted attendance punches locally when working offline in low-connectivity areas. Managed automatically by the operating system sandbox.
Push Notifications
(POST_NOTIFICATIONS)
Normal Used to send shift start reminders, schedule updates, leave request approval status, and manager emergency alerts. Optional. Can be enabled or disabled at any time in device settings.
Network & Wi-Fi State
(ACCESS_NETWORK_STATE, INTERNET)
Normal Used to check internet availability, sync attendance punches to the cloud, and securely transmit payroll data. Essential for real-time cloud attendance synchronization.

5. How We Use Information (Purposes of Processing)#

We process attendance, location, biometric photo, and payroll data strictly for lawful operational purposes:

  1. Accurate Attendance Verification: Confirming employee on-site arrival and departure within authorized geographic workplace perimeters.
  2. Fraud Prevention & Integrity: Preventing buddy punching, time theft, and clock-in falsification through selfie verification and anti-spoofing checks.
  3. Automated Cambodian Payroll Processing: Calculating exact gross wages, grace period deductions, overtime multipliers (1.5× and 2.0×), and bilingual payslip generation.
  4. Labor Compliance & Audit Readiness: Maintaining statutory attendance registers required by the Ministry of Labour and Vocational Training (MoLVT) and the National Social Security Fund (NSSF).
  5. Operational Team Communication: Delivering real-time Telegram and push notifications for shift swaps, roster schedules, and managerial approvals.
  6. Platform Reliability & Security: Monitoring system performance, preventing denial-of-service attacks, and diagnosing technical issues.

Under applicable Cambodian regulations (including the E-Commerce Law 2019 and Cambodian Labour Law) as well as international data protection principles, we process personal data under the following legal bases:

  • Contractual Necessity: Processing is necessary to fulfill the SaaS subscription contract with your employer and support the employment relationship between you and your employer.
  • Compliance with Legal Obligations: Employers must maintain accurate records of working hours, overtime premiums, and social security contributions under Cambodian labor statutes.
  • Legitimate Business Interests: Employers have a legitimate commercial interest in securing business facilities, verifying workforce presence, and ensuring payroll accuracy.
  • Explicit Consent: Where required by mobile operating systems (iOS and Android), you provide explicit permission when granting camera, location, and notification access.

7. Data Security & Storage Architecture#

AttendKH implements enterprise-grade technical and organizational security measures to protect workforce and attendance data from unauthorized access, loss, or alteration:

  • Encryption in Transit: All data transmitted between mobile devices, kiosk hardware, web browsers, and our cloud servers is encrypted using Transport Layer Security (TLS 1.3 / HTTPS) with modern cipher suites.
  • Encryption at Rest: All database tables, selfie photo storage buckets, and automated backups are encrypted using AES-256 encryption.
  • Credential Protection: User passwords are never stored in plaintext and are hashed using salted Argon2 / bcrypt algorithms.
  • Role-Based Access Control (RBAC): System access is partitioned by role (Super Admin, Organization Owner, HR Manager, Branch Supervisor, Frontline Employee). Managers can view only the branches and staff under their direct operational scope.
  • Audit Trails: All administrative modifications to punch logs, salary adjustments, and manual time overrides are permanently recorded in immutable audit logs.
  • Isolated Multi-Tenant Databases: Organizational records are logically segmented to prevent cross-tenant data exposure.

8. Data Retention & Lifecycle Management#

We retain attendance logs and personal information only for as long as necessary to serve operational purposes and fulfill legal obligations:

  • Active Organizational Subscription: Attendance logs, punch timestamps, and payroll archives are retained throughout the active duration of the employer's subscription to maintain continuity of employment records.
  • Statutory Labor Law Retention: In compliance with MoLVT guidelines, payroll calculation archives and statutory records are typically retained for up to 3 years to support official labor inspections and tax compliance.
  • Verification Selfie Photos: Verification photos are retained for an audit window determined by your employer's configuration (standard 90 to 365 days) and subsequently purged or anonymized.
  • Post-Termination Purging: Upon cancellation or termination of an organization's subscription, all associated database records, photos, and employee profiles are permanently deleted from active systems within 60 days, subject to standard encrypted rolling backup lifecycles.

9. Account & Data Deletion Policy (Google Play & Apple App Store Compliance)#

AttendKH provides clear, accessible, and transparent mechanisms for both individual employees and organizational administrators to request the deletion of their accounts and associated personal data:

For Individual Employees:

  • If you wish to delete your mobile account credentials, profile details, or personal data, you may submit a request directly to your employer's HR administrator (the Data Controller).
  • Alternatively, you can submit an individual deletion request directly to our Data Protection Officer by emailing privacy@MPG_by_ongphaly.com with the subject line "Employee Data Deletion Request". Include your registered phone number, organization name, and Staff ID.
  • Upon receiving verified confirmation from your employer or upon account deactivation, all personal authentication tokens, biometric selfie photos, and device identifiers associated with your profile will be permanently deleted from active databases within 30 calendar days.

For Organizations & Business Owners:

  • Organization administrators can request complete deletion of their enterprise account, all branch geofences, staff profiles, attendance logs, and payroll records by emailing privacy@MPG_by_ongphaly.com from the verified owner's corporate email address or via the Admin Dashboard.
  • All organizational data will be queued for permanent hard deletion across all production servers and storage buckets within 30 days.

10. Third-Party Sub-processors & Zero-Sale Guarantee#

AttendKH upholds a strict privacy standard regarding third-party disclosures:

WE DO NOT SELL, RENT, OR MONETIZE YOUR PERSONAL DATA OR VERIFICATION SELFIES TO ADVERTISERS, DATA BROKERS, OR THIRD PARTIES UNDER ANY CIRCUMSTANCES.

We engage a limited number of trusted enterprise sub-processors solely to deliver essential infrastructure and communications:

Sub-processor Category Purpose Data Transferred Security Standard
Cloud Hosting & Database Infrastructure Cloud Infrastructure Encrypted database hosting, API servers, and backup redundancy Encrypted employee records, punch timestamps SOC 2, ISO 27001, AES-256
Encrypted Object Storage Media Storage Encrypted storage of selfie verification punch images Encrypted selfie photos with punch metadata AES-256, TLS 1.3, strict IAM
SMS / OTP Gateway Provider Telecommunications Delivery of one-time password (OTP) verification codes for mobile login Employee phone number, OTP token Encrypted API, zero retention
Telegram Bot API (Optional) Messaging Automated dispatch of manager punch alerts and roster notifications Telegram chat ID, alert notification text TLS 1.3, opt-in by organization

11. Your Rights as a Data Subject#

Subject to applicable Cambodian laws and international standards, you have specific rights regarding your personal information:

  1. Right of Access & Transparency: You can view your real-time attendance history, punch timestamps, logged hours, leave balances, and generated payslips directly through the AttendKH mobile app.
  2. Right to Rectification: If an attendance record is inaccurate (for example, due to a hardware failure or forgotten punch), you have the right to submit a manual punch adjustment request to your manager for review and correction.
  3. Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data upon termination of employment or withdrawal of consent, subject to statutory labor record-keeping requirements.
  4. Right to Restrict Processing: You may request restrictions on how your data is processed if you dispute its accuracy.
  5. Right to Data Portability: Organizational administrators and employees can export attendance logs, overtime reports, and payslips in standardized formats (CSV, Excel, PDF).

To exercise any of these rights, please contact your employer's HR team or contact our privacy team at privacy@MPG_by_ongphaly.com.


12. Workplace Privacy & Anti-Surveillance Safeguards#

AttendKH is designed to balance operational workforce coordination with the fundamental privacy and dignity of frontline workers:

  • No Continuous Audio / Video Recording: The mobile app NEVER records audio through device microphones or captures continuous video feeds.
  • No Keystroke or Screen Monitoring: The app does NOT capture screenshots, monitor other installed mobile applications, or track browsing activity.
  • Off-Duty Privacy: Outside active work hours, the mobile app performs zero monitoring and does not capture any location or status information.
  • Kiosk Privacy: When using the shared tablet QR Kiosk mode, photos captured during punch-in are displayed only momentarily on-screen for user confirmation and are not publicly browsable on the physical device.

13. Children's Privacy#

AttendKH is an enterprise business-to-business workforce management platform. We do not knowingly collect, solicit, or maintain personal information from individuals under the legal employment age under the Cambodian Labour Law (under 15 years old for light work, or under 18 years old for general industrial labor). If we learn that personal data of an underage individual has been inadvertently collected without lawful parental or employer authorization, we will take immediate steps to delete the information.


14. Changes & Updates to this Privacy Policy#

We may update this Privacy Policy from time to time to reflect enhancements in our mobile applications, updates to Cambodian regulations, or evolving App Store and Google Play policies.

When material changes occur:

  • We will update the "Last updated" date and increment the policy version number at the top of this document.
  • We will notify registered employers and mobile users via an in-app notice, banner, or email notification before the updates take effect.
  • Continued use of the AttendKH mobile app or web platform after the effective date of an updated policy constitutes acceptance of the revised terms.

15. Contact Us & Data Protection Officer (DPO)#

If you have questions, concerns, feedback, or complaints regarding this Privacy Policy, your personal data, or our mobile attendance security practices, please contact our Data Protection Office:

  • Data Protection Officer (DPO): AttendKH Privacy & Security Compliance Team
  • Email: privacy@MPG_by_ongphaly.com
  • General Support: support@MPG_by_ongphaly.com
  • Official Telegram Hotline: @MPG_by_ongphaly
  • Phone Hotline: +855 23 999 888
  • Operating Hours: Monday to Saturday, 8:00 AM – 6:00 PM (ICT / UTC+7)
  • Physical Address: Phnom Penh, Kingdom of Cambodia

Self-Service Account & Personal Data Deletion Workflow

App Store Guideline 5.1.1(v) & Google Play Data Deletion Policy
30-Day SLA Hard Delete

Employees and enterprise administrators have the unconditional right to request account and personal record deletion. Follow the standardized procedure below:

Step 01

Initiate Request

Notify your HR department or email our DPO directly at privacy@attendkh.com.

Step 02

Identity Verification

Verify your registered mobile number and employee ID to prevent unauthorized tampering.

Step 03

Permanent Hard Erasure

Selfie photos, device tokens, and credentials are permanently purged within 30 days.

Ready-to-Send Deletion Email Template
Subject: Employee Account & Data Deletion Request - AttendKH

To the Data Protection Officer (AttendKH),

I am writing to formally request the permanent deletion of my mobile attendance account and associated personal data in accordance with the AttendKH Privacy Policy and App Store / Google Play guidelines.

My Account Verification Details:
- Full Legal Name: [Your Full Name]
- Registered Mobile Phone Number: [Your Phone Number]
- Organization / Company Name: [Your Employer Name]
- Staff ID Number (if applicable): [Your Staff ID]
- Reason for Deletion (Optional): [e.g. End of Employment / No longer using app]

I understand that statutory payroll calculation records may be archived by my employer in accordance with Cambodian Labor Law (MoLVT) requirements, while all mobile authentication tokens, biometric selfie images, and device identifiers will be purged from active databases within 30 days.

Thank you,
[Your Name]

Frontline Employee Privacy FAQ

Direct, transparent answers addressing the most common workforce privacy and data protection questions.

Categorically NO. AttendKH does not have 24/7 background tracking. GPS location is accessed strictly for 1-2 seconds at the exact moment you tap Clock In or Clock Out to verify branch perimeter presence. The sensor turns off completely once the punch is verified.

Data Protection Officer (DPO)

Need Privacy Assistance or Data Deletion?

Our privacy compliance desk is available to assist with data subject access requests, deletion workflows, and App Store compliance questions.