Sertoga
WorkContactPrivacy
Control Clock

Control Clock Privacy Policy

How the workplace attendance application handles information.

This policy covers Control Clock and customer-branded versions of the application.

Provider: Sertoga Corp.  ·  Effective: September 28, 2026

Your employer controls its workforce records. The employer or other workplace organization using Control Clock (the “Organization”) decides why workplace information is processed, who may access it, how it is used for employment and payroll purposes, and how long it is retained. Sertoga owns and provides the application and handles information for application support, security, distribution, and legal purposes. Sertoga has no continuing access to an Organization's workforce data unless the Organization grants bounded support access.
On this pageInformation processed
Photos and on-device checks
Storage, access, and optional Google Sheets
Retention
Choices and requests

1. Information processed

Control Clock processes employee and administrator names and identifiers, roles, workplace location, schedules, clock-in and clock-out times, attendance history, corrections, review status, device and security records, and information used to prepare payroll records.

Before an employee's first photo under a notice version, the application records the employee's acknowledgment of the current photo notice. During reference enrollment, a manager may instead record delivery of the notice to the selected employee; that record documents delivery only and does not verify comprehension. The receipt may include a receipt identifier, the notice version and text hash, employee, time, device, and location, plus administrative provenance when a manager records delivery. The local receipt can be saved offline and synchronized to the Organization's private backend later. A notice receipt is an acknowledgment, not consent, and it does not determine the Organization's lawful authority for workplace processing.

2. Photos and on-device checks

The application uploads ordinary clock photos, separate flagged review photos, and reference/enrollment photos to the Organization-controlled private backend. Authorized managers use the applicable photos for attendance administration, reference enrollment, and review.

The device performs photo-quality, face-consistency, and liveness checks. Face embeddings are created and used on the device and are not uploaded. These checks support human review; they are not a guarantee of identity and are not the sole basis for an employment or payroll decision.

An employee who cancels the photo notice or cannot use the camera workflow is directed to the Organization's manager-assisted manual attendance process.

3. Storage, access, and optional Google Sheets

Workforce records and uploaded photos are stored on an Organization-operated private Raspberry Pi using PostgreSQL and protected file storage. Production access uses the Organization's private NetBird network and trusted HTTPS. Administrator roles, paired-device credentials, and location-based access limit who can view or change information.

The isolated App Review environment contains fictional data only. It uses separate credentials, database, file storage, and network boundaries from production and is reachable for Apple's review without exposing the production system.

If the Organization enables the optional connection, authorized managers may import schedules from an Organization-owned Google Sheets workbook or export attendance times for payroll processing to an Organization-owned Google Sheets workbook. Google handles that information under the Organization's Google account, sharing settings, and applicable Google terms. The Organization's private backend remains the system of record.

Sertoga does not use employee, attendance, or photo information for advertising, sale, or cross-company tracking.

4. Retention

  • Ordinary local and private-backend clock-photo files are deleted after the next 4 a.m. Toronto-time business-day rollover.
  • Each flagged review photo is handled separately and is deleted 28 days after that photo's review is resolved.
  • Active reference/enrollment photo generations remain while operationally required. Replacement and deletion records prevent stale offline copies from returning.
  • Deleting a photo does not delete its attendance timestamps. Attendance, schedules, corrections, payroll records, access records, and other non-photo information follow the Organization's approved retention schedule. Backups and legal holds follow separate approved processes.
  • Append-only notice-receipt and audit records follow a separately approved retention process. They are not removed by attendance limits or employee removal.

5. Choices, requests, and contact

For workplace-monitoring questions, the reason information is processed, access, correction, deletion, retention, complaints, or a camera-free attendance path, contact the manager or privacy contact identified in the employee notice supplied by your Organization. A request may be limited where records must be kept under employment, payroll, tax, legal, or dispute-resolution obligations.

For application, accessibility, or security support, email contact@sertoga.com. Do not include employee photos, attendance records, pairing codes, administrator PINs, credentials, or device tokens in email.

Sertoga© 2026 Sertoga.
WorkContactPrivacyTermsSupport