Legal

Privacy Policy

Last updated: 3 August 2026

Punctiva is a staff-attendance platform operated by Aisjeed Technologies LTD. Because attendance involves location and biometric data, we take privacy seriously. This policy explains what we collect, why, how long we keep it, and the rights you have under the Nigeria Data Protection Act, 2023 (NDPA).

1. Who we are

Punctiva is a product of Aisjeed Technologies LTD.("Punctiva", "we", "us"). You can reach our privacy team at support@punctiva.com.

2. Controller and processor

Punctiva is sold to companies ("Customers") who use it to record their own staff's attendance. For that staff data, the Customer is the data controller and Punctiva is the data processor— we process it on the Customer's instructions to provide the service. Your employer is responsible for telling you how it uses Punctiva and for having a lawful basis to do so.

For information about the account holder directly (for example, the admin who signs up, or billing contacts), Punctiva acts as the controller.

3. Data we collect

Account & company

  • Name, work email, and a securely hashed password.
  • Company name, role (admin/employee), and office locations you configure.
  • Optional: date of birth (day and month only, for the team birthday card) and pay rates.

Attendance & location

  • GPS coordinates and distance-to-office at the moment of each check-in/out, and the timestamp.
  • Flags for suspected mock-location or poor GPS accuracy.

Biometric data

  • Face images — a reference selfie you enroll, and the selfie captured at each check-in, used only to confirm it is really you. These are matched by an automated face-recognition service and are never used for any other purpose.
  • Device biometrics — when you use fingerprint or Face ID to check in, that biometric is verified on your own phone and never reaches us. We store only a public passkey that cannot reconstruct your fingerprint or face.

Billing & technical

  • Billing contact and payment references. Card details are handled by Paystack — we never see or store them.
  • Limited technical data (IP address for rate-limiting/abuse prevention) and a tamper-evident activity log of admin actions.

4. How we use data and our lawful basis

  • Providing the service (recording and verifying attendance) — performance of the contract with your employer, and our legitimate interest in a working product.
  • Biometric verification — processed with consent, which you give at enrollment and can withdraw at any time (see §6). You can always use a non-biometric method where offered.
  • Billing — performance of the contract with the Customer.
  • Security, fraud and abuse prevention — our legitimate interest and legal obligations.

We do not sell personal data, and we do not use it for advertising.

5. Who we share data with

We share data only with service providers ("sub-processors") that help us run Punctiva, under contract and only as needed:

  • Vercel — application hosting.
  • Neon — the encrypted PostgreSQL database.
  • Vercel Blob — storage of check-in selfies.
  • A face-recognition provider (AWS Rekognition, or a self-hosted alternative) — automated face matching and liveness.
  • Paystack — payment processing.
  • Resend — transactional email (invites, receipts, alerts).
  • Upstash — rate-limiting and short-lived caching.

We may also disclose data where required by law. Some providers process data outside Nigeria; where they do, we rely on appropriate safeguards as required by the NDPA.

6. Biometric consent and how to withdraw it

Before enrolling your face, we ask for your explicit consent. You may withdraw it at any time by contacting your administrator or support@punctiva.com; we will delete your reference face and stop biometric matching for you. Withdrawing consent does not affect attendance already recorded, and your employer may offer or require an alternative check-in method.

7. How long we keep data

  • Check-in selfies are automatically deleted 90 days after capture; the attendance record (time, location, verification result) is kept without the image.
  • Attendance history is retained for the period your plan provides, or as your employer directs.
  • Account data is kept while the account is active and deleted, or anonymised, after closure, unless we must keep it to meet a legal obligation.

8. How we protect data

  • Encryption in transit (TLS) everywhere, and encryption at rest in the database.
  • Strict separation between Customers — one company can never access another's data.
  • Device biometrics never leave the employee's phone.
  • Privileged actions are recorded in a tamper-evident activity log.

9. Your rights under the NDPA

Subject to law, you have the right to access, correct, delete, or restrict your personal data, to object to certain processing, to data portability, and to withdraw consent. Because your employer is usually the controller of attendance data, please direct such requests to them first; we will assist them in fulfilling your request. You may also contact us at support@punctiva.com.

You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data has been mishandled.

10. Children

Punctiva is for workplaces and is not intended for anyone under 18.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be posted here with a new "last updated" date.

12. Contact

Aisjeed Technologies LTD. — support@punctiva.com.