1. Scope and responsibility
Clynova E-HR is an HR and attendance platform provided by Codebxo Technologies. This policy explains how the mobile application and web portal process personal data. Your employer or contracting organization controls which HR features are enabled and normally acts as the organization responsible for employee records. Codebxo Technologies operates the platform and processes data to provide those configured services.
2. Data we process
- Account and employment data: name, email address, profile details, organization, department, role and account identifiers.
- Attendance data: punch-in and punch-out times, attendance status, work arrangement and attendance photos where your organization enables photo verification.
- On-shift location data: precise latitude and longitude, GPS accuracy, capture and receipt times, location provider, workplace-boundary state and distance from the configured boundary.
- Tracking safety metadata: session and sequence identifiers, a protected device-identifier hash, permission state, application lifecycle, battery/network availability, queue status and signals that may indicate mock location, timestamp replay or impossible movement.
- Violation records: policy type, evidence references, timestamps, severity, review status, return-to-boundary information and disputes or corrections submitted by employees and reviewers.
3. On-shift background location
Clynova E-HR may collect precise location in the background, including while the app is minimized, closed, or not actively in use, only for an active authorized shift. This supports workplace-boundary verification, attendance coverage and investigation of configured attendance exceptions.
- Policy limited: collection is available only when the organization subscription and the effective organization, department, role and, where configured, employee policy permit it.
- Shift limited: the employee must start the attendance flow, review the disclosure and grant the required location permission. A time-limited server session must then be issued.
- Off-shift protection: without a valid active shift and server session, the native collector is not authorized to collect or upload location. Collection is stopped on punch-out, logout, session expiry, policy disablement, permission loss or account deactivation.
- Visible operation: Android displays an ongoing notification while its location foreground service is active. Both platforms show current tracking state and recent location activity inside the app.
4. Violation and exception processing
Tracking observations do not automatically prove misconduct. When enabled by the applicable organization policies, the system can create reviewable cases for workplace-boundary exits, missing updates, device or network unavailability, disabled permissions or location services, suspected mock location, impossible travel, timestamp replay, device mismatch or unexpected tracking stoppage. Accuracy thresholds, grace periods and minimum evidence rules are applied before eligible cases are created. Authorized reviewers can acknowledge, excuse, uphold or correct a case, and employees can view and dispute cases available to them.
5. Purposes and access
- Verify attendance, work hours and presence within an assigned workplace boundary.
- Show employees their active tracking state, coverage status and reviewable violation history.
- Detect technical coverage gaps and potential attendance-data manipulation.
- Support authorized HR review, correction, dispute handling, security and audit requirements.
Location and violation details are restricted by organization and role. They are available only to the employee and authorized organization reviewers as required by the configured workflow. We do not sell location data or use it for advertising.
6. Retention and deletion
The organization configures a retention period for raw tracking observations, currently limited by the platform to between 1 and 365 days. Each observation and related evidence record is assigned a retention-expiry timestamp, and automated cleanup removes expired primary-database records in bounded batches. Short-lived latest-location cache entries expire separately according to organization policy. Violation cases may be retained longer for review, dispute, audit or legal obligations, and a legal hold prevents automated case deletion. Backup copies may remain for a limited recovery period before being overwritten.
This automated tracking and violation cleanup does not delete attendance punches, attendance photos, user or employee accounts, organization or department records, payroll, leave, asset, document or other primary HR records. Those records follow their own business, contractual and legal retention requirements.
Contact your organization administrator or the address below to request access, correction, restriction or deletion where applicable. Some attendance or employment records may need to be retained when required by employment, tax, security or other law; when deletion is not permitted, access will be restricted and the reason will be explained.
7. Security and service providers
Tracking uploads use authenticated HTTPS endpoints and short-lived, device-bound tracking-session credentials. Organization and user identity are validated by the server. Pending mobile observations are stored in a bounded encrypted local queue until upload or session sealing. The platform uses access controls, tenant separation, audit records, replay protection, accuracy checks and limited cache lifetimes. Infrastructure, hosting, messaging, notification and media-storage providers may process only the data needed to operate the service under their applicable contractual and security obligations.
8. Employee choices and platform controls
The app explains on-shift background collection before requesting elevated location access. If a required permission is declined, location sharing does not start. Depending on your organization policy and whether attendance has already been created, the punch may be cancelled or attendance may continue without tracking for administrative review. You can revoke location permission in device settings; doing so prevents further location collection but may create a coverage exception during an already active policy-controlled shift.
9. Contact and policy changes
For privacy questions, requests or complaints, first contact your organization administrator. You may also contact Codebxo Technologies at info@codebxo.com. Material changes to location collection require updated disclosures and policy/version review before the changed behavior is released.