Last updated: July 25, 2026 Version: 1.0 (Draft — Pending Legal Review)
[LEGAL REVIEW NEEDED] — This document contains template content with placeholders for jurisdiction-specific details. It must be reviewed by qualified legal counsel before publication. Sections marked [LEGAL REVIEW NEEDED] require jurisdiction-specific legal input.
1. Introduction & Scope
This Privacy Policy explains how ChronoLog ED ("we," "us," "our") collects, uses, discloses, and protects your personal information when you use our time-tracking and attendance management platform (the "Service").
[LEGAL REVIEW NEEDED — specify: jurisdiction-specific scope, definition of "personal information"/"personal data" per applicable law (GDPR, CCPA/CPRA, LGPD, etc.), territorial scope applicability]
Effective date: [LEGAL REVIEW NEEDED — specify effective date for current version] Data controller: ChronoLog ED / [LEGAL REVIEW NEEDED — specify: legal entity name, registered address, registration number, jurisdiction of incorporation] Data Protection Officer (DPO) / Privacy Contact: [LEGAL REVIEW NEEDED — specify: DPO name/contact per GDPR Art. 37, or privacy contact email/mailing address]
2. Data We Collect
We collect the following categories of personal information to provide the Service:
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Account / Identity | Name, email address, employee ID, department, role, profile photo | Account creation, authentication, access control |
| Attendance / Time Records | Check-in/out timestamps, location (area), device info, remarks | Core time-tracking functionality |
| Permissions & Requests | Leave/permission slip details, destination, purpose, dates, vehicle info | Processing permission requests |
| Overtime Slips | Purpose, section, date, time range, citizen lists | Overtime tracking & approval |
| Communications | Support tickets, feedback, correspondence | Customer support |
2.2 Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage / Telemetry | Page views, feature interactions, errors, performance metrics | Product improvement, debugging |
| Device / Network | IP address (hashed/salted), browser type, OS, device ID | Security, fraud prevention, analytics |
| Authentication Logs | Login timestamps, MFA events, session data | Security monitoring, audit trail |
| Consent Records | Consent preferences (analytics, ads, functional), timestamp, version, region | GDPR/CCPA compliance, Consent Mode v2 |
2.3 Information from Third Parties
- Identity Providers (Google, Microsoft, etc. via NextAuth): Name, email, profile picture — for authentication only
- AdSense / Google Analytics (landing page only): Pseudonymous ad/analytics identifiers — only with consent via Consent Mode v2
[LEGAL REVIEW NEEDED — specify: lawful basis for each category under GDPR Art. 6 (contract, legitimate interest, consent, legal obligation, vital interests, public task); CCPA/CPRA "sale"/"share" classification; sensitive data categories if any]
3. How We Use Your Information
We process personal information for the following purposes:
| Purpose | Lawful Basis (GDPR) | Retention |
|---|---|---|
| Provide core time-tracking & attendance features | Contract performance (Art. 6(1)(b)) | Duration of employment/contract + [LEGAL REVIEW NEEDED — specify: statutory retention period] |
| Process permission slips, overtime, vehicle logs | Contract performance / Legitimate interest | Duration of employment/contract + [LEGAL REVIEW NEEDED] |
| Authenticate users, enforce access control (RBAC) | Contract performance / Legal obligation (security) | Session duration + audit log retention [LEGAL REVIEW NEEDED] |
| Security monitoring, fraud prevention, abuse detection | Legitimate interest (Art. 6(1)(f)) | [LEGAL REVIEW NEEDED — specify: log retention period] |
| Product analytics & improvement (with consent) | Consent (Art. 6(1)(a)) | 14 months (GA4 default) / [LEGAL REVIEW NEEDED] |
| Personalized advertising (AdSense, landing page only, with consent) | Consent (Art. 6(1)(a)) | Per Google retention policies |
| Legal compliance (audit logs, consent records, DSAR fulfillment) | Legal obligation (Art. 6(1)(c)) | [LEGAL REVIEW NEEDED — specify: regulatory retention periods] |
| Respond to support requests, communicate service changes | Contract performance / Legitimate interest | Duration of relationship + [LEGAL REVIEW NEEDED] |
[LEGAL REVIEW NEEDED — specify: purpose limitation compliance, compatibility testing for secondary uses, automated decision-making/profiling disclosure per GDPR Art. 22]
4. How We Share Your Information
We do not sell personal information. We share data only as described below:
4.1 Service Providers (Data Processors)
| Category | Providers | Purpose | Safeguards |
|---|---|---|---|
| Cloud Hosting | AWS (Lambda, MongoDB Atlas) | Infrastructure | DPA, SCCs, ISO 27001 |
| Authentication | NextAuth.js (self-hosted), OAuth providers | Identity management | DPA-equivalent terms |
| Database | MongoDB Atlas | Data storage | DPA, encryption at rest/in transit |
| Analytics | Google Analytics 4 (with Consent Mode v2) | Product analytics (opt-in) | DPA, IP anonymization |
| Advertising | Google AdSense (landing page only, opt-in) | Monetization | DPA, TCF v2.2 compliance |
| Error Tracking | [Provider if any] | Monitoring | DPA |
[LEGAL REVIEW NEEDED — specify: complete processor list, DPA execution status, international transfer mechanisms (SCCs, UK IDTA, adequacy decisions), sub-processor notification obligations]
4.2 Legal & Regulatory
We may disclose information when required by law, court order, or governmental request, or to protect our rights, safety, or property.
[LEGAL REVIEW NEEDED — specify: jurisdiction-specific disclosure obligations, warrant/canary policies, user notification commitments where legally permissible]
4.3 Business Transfers
In a merger, acquisition, or asset sale, your information may be transferred as part of the transaction. We will notify you of any change in control.
[LEGAL REVIEW NEEDED — specify: asset vs. stock sale treatment, user consent/opt-out rights in transfer scenarios]
5. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account / Profile | Duration of account + [LEGAL REVIEW NEEDED] | Contract / Legal obligation |
| Attendance / Logs | [LEGAL REVIEW NEEDED — e.g., 7 years per labor law] | Legal obligation / Legitimate interest |
| Permission Slips / OT Slips | [LEGAL REVIEW NEEDED] | Legal obligation / Contract |
| Authentication / Audit Logs | [LEGAL REVIEW NEEDED — e.g., 12–24 months] | Security / Legal obligation |
| Consent Records | Duration of consent + [LEGAL REVIEW NEEDED — e.g., 5 years] | GDPR Art. 7(1) / Legal obligation |
| Analytics (GA4) | 14 months (default) | Consent |
| AdSense Data | Per Google policies | Consent |
[LEGAL REVIEW NEEDED — specify: jurisdiction-specific retention schedules (labor law, tax law, GDPR storage limitation principle), automated deletion/anonymization procedures, backup retention]
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access (GDPR Art. 15 / CCPA §1798.100) | Request copy of your personal data | Email [LEGAL REVIEW NEEDED — privacy@ email] or use in-app "Download My Data" |
| Rectification (GDPR Art. 16) | Correct inaccurate/incomplete data | Edit profile in-app or contact support |
| Erasure / Deletion (GDPR Art. 17 / CCPA §1798.105) | Request deletion (subject to exceptions) | Account settings → "Delete Account" or email privacy@ |
| Restriction (GDPR Art. 18) | Limit processing in certain cases | Contact privacy@ |
| Portability (GDPR Art. 20) | Receive data in structured, machine-readable format | In-app export or email privacy@ |
| Objection (GDPR Art. 21 / CCPA §1798.120) | Object to processing for direct marketing/legitimate interest | Cookie Preferences (/consent/manage) or email privacy@ |
| Withdraw Consent (GDPR Art. 7(3)) | Withdraw consent at any time | Cookie Preferences (/consent/manage) |
| Non-Discrimination (CCPA §1798.125) | No retaliation for exercising rights | Automatic |
[LEGAL REVIEW NEEDED — specify: jurisdiction-specific rights (GDPR, CCPA/CPRA, LGPD, PIPL, etc.), response timelines (30 days GDPR, 45 days CCPA), verification procedures, appeal process, fees if any, DPO contact for EU/UK reps]
6.1 Designated Request Channel
Email: [LEGAL REVIEW NEEDED — [email protected]] Postal Address: [LEGAL REVIEW NEEDED — Data Controller address] In-App: Settings → Privacy → "Submit Request"
7. International Data Transfers
Our infrastructure is hosted on AWS (region: [LEGAL REVIEW NEEDED — specify region, e.g., eu-central-1 / us-east-1]) and MongoDB Atlas (region: [LEGAL REVIEW NEEDED]).
[LEGAL REVIEW NEEDED — specify: transfer mechanism per GDPR Ch. V (adequacy decision, SCCs, BCRs, derogations), UK IDTA for UK transfers, China PIPL / Brazil LGPD / other local law requirements, TIAs for US transfers post-Schrems II, processor location disclosure]
8. Security Measures
We implement appropriate technical and organizational measures:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control (RBAC) with principle of least privilege
- Server-authoritative timestamps, tamper-evident audit logs
- Content Security Policy (CSP) with nonce-based script execution
- Regular security testing, dependency scanning (Renovate + pnpm overrides)
- Incident response plan with 72-hour breach notification target (GDPR Art. 33)
[LEGAL REVIEW NEEDED — specify: certifications (ISO 27001, SOC 2), penetration test frequency, data breach notification procedures per jurisdiction, cyber insurance]
9. Cookies & Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy (accessible via /consent/manage). Categories:
| Category | Purpose | Consent Required |
|---|---|---|
| Strictly Necessary | Authentication, CSRF protection, consent storage | No (legitimate interest) |
| Functional | Preferences, theme, locale | Yes (opt-in) |
| Analytics | GA4, product usage (with Consent Mode v2) | Yes (opt-in) |
| Advertising | AdSense (landing page only, with Consent Mode v2) | Yes (opt-in) |
You can manage preferences anytime at /consent/manage (footer link).
[LEGAL REVIEW NEEDED — specify: full cookie inventory table (name, domain, purpose, expiry, third-party), ePrivacy Directive compliance, TCF v2.2 compliance for AdSense, IAB vendor list]
10. Children's Privacy
The Service is not directed to children under [LEGAL REVIEW NEEDED — specify: 13 (US/COPPA), 16 (GDPR default), or lower per member state]. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us at [LEGAL REVIEW NEEDED — privacy@] to request deletion.
[LEGAL REVIEW NEEDED — specify: age threshold per applicable jurisdiction, age verification measures if any]
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via:
- Email to registered users (at least [LEGAL REVIEW NEEDED — e.g., 30 days] before effective date)
- Prominent in-app banner
- Updated "Last updated" date above
Continued use of the Service after the effective date constitutes acceptance of the revised policy.
[LEGAL REVIEW NEEDED — specify: materiality threshold, notice periods per jurisdiction, opt-out/termination rights on adverse changes]
12. Contact Us
Data Controller: ChronoLog ED / [LEGAL REVIEW NEEDED — Legal entity name, registered address] Data Protection Officer / Privacy Contact: [LEGAL REVIEW NEEDED — Name, email, phone] EU/UK Representative (if applicable): [LEGAL REVIEW NEEDED — Art. 27 GDPR representative details]
Email: [LEGAL REVIEW NEEDED — [email protected]] Postal Address: [LEGAL REVIEW NEEDED — Full mailing address]
13. Jurisdiction-Specific Addenda
[LEGAL REVIEW NEEDED — specify: attach or reference jurisdiction-specific addenda for:
- California (CCPA/CPRA): "Do Not Sell/Share My Personal Information" link, sensitive personal information categories, financial incentive notices
- EU/UK (GDPR): Representative details, DPO details, supervisory authority contact
- Brazil (LGPD): Data subject rights, ANPD contact
- Australia (ACL): Consumer guarantees, unfair contract terms
- Canada (PIPEDA/Provincial): Consent requirements, access rights
- Other applicable jurisdictions]
⚠️ COMPLIANCE FLAG — DO NOT SHIP WITHOUT LEGAL REVIEW
This document is a TEMPLATE / PLACEHOLDER ONLY. Every section marked [LEGAL REVIEW NEEDED] requires jurisdiction-specific legal counsel review and approval before this Privacy Policy can be published.
Required legal review covers at minimum:
- Data controller legal entity identification & registration details
- DPO contact details (name, email, postal address) per GDPR Art. 13(1)(b)
- Lawful basis for each processing purpose per GDPR Art. 6
- Data retention periods per category with legal basis
- International transfer mechanisms (SCCs, adequacy, BCRs, derogations)
- User rights procedures (Art. 15–22 GDPR) with response timelines
- Processor DPA execution status and sub-processor flow-down
- Cookie inventory with purposes, expiry, third-party disclosure
- AdSense/AdTech TCF v2.2 compliance for EEA/UK
- Age threshold per jurisdiction (COPPA, GDPR Art. 8, state laws)
- Contact details per GDPR Art. 13(1)(a)–(b) — identity + DPO contact
- Jurisdiction-specific addenda (CCPA/CPRA, LGPD, PIPL, etc.)
Status: ❌ NOT APPROVED FOR PRODUCTION — Legal sign-off required.