Privacy Policy
Effective date: [[Effective date — e.g. 1 September 2026]] · Last updated: [[Effective date — e.g. 1 September 2026]]
This Privacy Policy explains how [[Legal business name — e.g. Ezaris Software]] ("Ezaris", "we", "us") collects, uses, discloses and protects personal information through the Ezaris suite — Ezaris ExpensesClaim and Ezaris Time & Attendance — including our mobile app and web dashboards (the "Services"). We follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Ezaris is a tool used by employers to manage their own workforce. When your employer uses Ezaris, your employer is the party that decides what information is collected and why (the "controller"); we process that information on their behalf. Questions about your own data should first go to your employer.
1. Information we collect
Account & profile
- Name, work email, phone number, employee code, job details (branch, department, manager, shift, employment type).
- Login credentials (passwords are stored only as a secure one-way hash — never in plain text).
Attendance & expense data
- Clock-in / clock-out times, breaks, leave requests, timesheets.
- Expense claims, amounts, receipts you upload, and reimbursement records.
Location (GPS)
- When you clock in or out, the app records the device's GPS coordinates (and, where available, a readable address) as proof of where the punch happened. Location is captured only at the moment of a punch — Ezaris does not track your location continuously or in the background.
Biometric (facial) information
- To prevent "buddy punching", your employer may require a face check at clock-in. You (or your administrator) enrol a reference photo, and at each punch you take a selfie.
- Face matching is performed by Amazon Web Services (AWS) Rekognition. AWS stores a mathematical face template (a numeric vector), not a viewable image, in a collection dedicated to your company. The reference photo and punch selfies are stored by us in private storage and are used only to verify identity and as an attendance record.
- Facial data is sensitive personal information. It is collected and used only for attendance verification, only where your employer has enabled the feature, and with consent as described in Section 3.
Device & usage
- Device type, app version, IP address, and basic technical logs needed to operate and secure the Services.
2. How we use information
- To provide the Services: recording attendance, verifying identity and location of punches, managing leave, processing expense claims and reimbursements, and producing reports for your employer.
- To secure the Services, prevent fraud (including buddy punching), and troubleshoot problems.
- To comply with legal obligations.
We do not sell personal information, and we do not use your face or location data for advertising.
3. Consent
Where required, we and your employer rely on your consent to collect and use personal information, especially biometric (facial) and location data. The app asks your permission for the camera and location before they are used, and you may decline. If you do not consent to face or location capture, your employer may offer an alternative way to record attendance, or these features may be unavailable to you — please discuss options with your employer. You may withdraw consent at any time (see Section 8), subject to legal and contractual limits.
4. Sharing & service providers
- Your employer and the administrators/managers they designate can see your attendance, location of punches, selfies, leave and expense information.
- Service providers that help us run the Services, under confidentiality obligations — including Amazon Web Services (face matching and hosting) and our email provider.
- Where required by law, or to protect rights and safety.
5. Where your data is processed
The Services are hosted on servers and use AWS in the United States. By using the Services your information may be processed outside your province or country, where it may be subject to lawful access by authorities in that jurisdiction. We take steps to protect it as described here.
6. Retention
- We keep personal information for as long as your employer's account is active and as needed to provide the Services and meet legal, tax and employment-record requirements.
- Punch selfies and enrolled face data are deleted when your employer removes your enrolment or closes their account, or on request where we are able to do so. [[Confirm your retention periods — e.g. selfies retained 90 days.]]
7. Security
We protect information with encryption in transit (HTTPS), one-way password hashing, access controls, private (non-public) storage for photos, and multi-tenant isolation so each company's data is kept separate. No system is perfectly secure, but we work to safeguard your information.
8. Your rights
- You may request access to, or correction of, your personal information, and may withdraw consent or request deletion (subject to legal limits).
- Because your employer controls your workplace data, please make these requests to your employer first; we will support them in responding.
- You may contact us using the details below, and you have the right to complain to the Office of the Privacy Commissioner of Canada.
9. Children
The Services are for workplace use by adults and are not directed to children under 16.
10. Changes to this policy
We may update this policy; we will post the new version here and update the "Last updated" date. Material changes will be communicated as required by law.
11. Contact us
[[Legal business name — e.g. Ezaris Software]]
[[Business address, City, Province, Country]]
Email: privacy@ezaris.co
© 2026 [[Legal business name — e.g. Ezaris Software]]. This document is a starting draft and should be reviewed by a qualified lawyer before you rely on it.