Privacy notice
What Negarit records about owners, administrators, and employees, why, and who can see it.
Who is responsible
Each business that uses Negarit (the “employer”) decides which employees to add and how attendance records are used, and is responsible for that data. Negarit Digitals runs the service for the employer and uses the data only to provide it.
What we record
- Owner and administrator accounts: name, email address, a one-way protected form of the password (never the password itself), role, which companies you manage, and sign-in times.
- Employee records: name, employee number, work email and phone if the employer adds them, job, department, workplace, employment dates and status, and work schedule.
- Attendance: each check-in, check-out, and break, timed by our server. The phone’s own clock reading is kept alongside it so mistakes can be reviewed, but it does not change recorded hours.
- Correction requests: the time an employee proposes, their explanation, and the reviewer’s decision and reason.
- Staff app devices: a random installation ID created by the app, the phone platform and app version, and the device name if the phone provides one. This lets the employer see and sign out connected phones.
- Security records: an audit log of important actions (such as sign-ins, access codes, and approvals) and counts of failed sign-in attempts, used to block guessing.
The staff app does not collect location, photos, contacts, or anything else from the phone.
Why
To record working time, show schedules, let employers review attendance and prepare pay, keep accounts secure, and fix problems with the service. We do not sell data or use it for advertising.
Who can see it
- An employee sees their own schedule, time records, and requests in the staff app.
- Administrators see records only for the companies they are allowed to manage; Super administrators see the whole organization.
- Negarit Digitals staff access data only to operate or support the service.
- Hosting providers store and process it on our behalf: the database and API run in Frankfurt, Germany (Neon and Render), and the web app on Vercel.
How long we keep it
Attendance and employment records are kept while the employer uses Negarit, because they may be needed for pay and employment records. Failed sign-in counts are deleted after a day. When an employer stops using Negarit, we delete or return its data on request, except where the law requires us to keep it.
Your choices
Employees can ask their employer to see or correct their records, and can request a time correction in the app. Owners and administrators can ask us for a copy of their organization’s data or its deletion.
Security
Connections are encrypted, passwords and access codes are stored only in protected form, sign-in attempts are rate limited, and access is limited by role and company.