Updated 6 Oct 2026

Privacy policy

This page explains what Never Late stores when you clock in, who can see it, and how you stay in control.

DRAFT by Victoria (legal): dashed boxes are placeholders still to fill (legal entity, address, server region, mailbox…). Fill them and remove this notice before publishing.

Summary

  • Selfie + GPS attendance: only at check-in/out or on the check screen; no background tracking, no movement trail.
  • Managers can see all employees' attendance photos and coordinates; photos are in a private bucket.
  • Data on Supabase (outside Vietnam); no sale, no ads; delete your account in the Me tab or by email.

1. Who is responsible for your data

Never Late is an attendance app: employees check in/out with a selfie and GPS location, log breaks and submit leave requests; managers review timesheets and approve requests. The app currently serves the staff of DBR Group ([full legal name, registration no., address — fill in before publishing]) ("DBR", "we"), which is also the employer and the controller and processor of your data in the app. If another organisation later deploys Never Late for its staff, that organisation is the controller and DBR the processor under a separate data-processing agreement; that organisation must notify its own employees.

This policy is prepared under: Law on Personal Data Protection No. 91/2025/QH15 (effective 1 January 2026) and Decree 356/2025/ND-CP implementing it (which replaced Decree 13/2023/ND-CP), and Law on Cybersecurity No. 116/2025/QH15 (effective 1 July 2026), and also serves as notice to employees about attendance by photo and location.

2. Data we collect

CategoryDetailsNotes
Check-in selfieA front-camera photo taken at the moment you check in/out. The app stamps time, date, name, address and note on the photo. Live capture only, no library upload.Facial image — sensitive data. Stored in a private bucket; only you and managers can view it.
GPS locationHigh accuracy, only while the app is open on the Today or Check screen. On check-in/out the app stores the coordinates and the distance to the nearest office.No background tracking, no movement trail. The street address stamped on the photo is looked up through the operating system's map service (Apple/Google).
Working timeIn/out times, minutes late/early/worked, shift, note; time zone derived from location.
BreaksStart/end time, labels, notes, reason for skipping.
Leave requests & timesheet edit requestsType, date, reason (text you write), status, approver; content before/after an edit.
Employee profileFull name, employee code, title, department, manager name, annual leave days, sign-in email.Password stored as a hash by the authentication provider.
Notifications & deviceIn-app notification content; push token and operating system (iOS/Android).No advertising ID or IMEI.
Biometric unlock (Face ID/fingerprint)Handled by the operating system. The app receives only a yes/no result and does not receive or store face or fingerprint templates.

A cache (most recent 90 days), your session and the Face ID option are stored on your device.

3. Purposes and legal basis

We process data to: verify that you check in as the right person, at the right place and time; compute working hours, lateness/early leave and leave balance; handle leave and timesheet-edit requests; produce timesheet reports (Excel) for labour management and payroll; send work-related notifications; and secure the service and prevent attendance fraud. Our basis is your consent (the notice-and-consent screen on first launch, at sign-up, and when you grant camera, location and notification permissions), together with labour-management needs under your employment contract and the employer's internal work rules. We do not sell data, use it for advertising, or use it to train facial-recognition models.

4. Who can see your data

5. Processors and sharing

PartyRoleData
Supabase Inc.Cloud infrastructure: authentication, database, photo storage (private bucket, viewing links expire after 1 hour).All data in §2.
Expo (Expo Push Service) → Apple APNs / Google FCMDeliver push notifications.Push token, notification title and body.
Apple / Google (OS map services)Turn coordinates into a street address.Coordinates at check time, per their policies.
Expo / EASApp build and distribution tooling.Does not receive attendance data.

6. Storage outside Vietnam

Supabase servers are located outside Vietnam ([exact server region — confirm in Supabase dashboard]). Sending data abroad to provide the service is based on your consent and the rules on cross-border transfer of personal data, including a transfer impact assessment dossier where required. We require recipients to apply appropriate security.

7. Retention

Attendance data is kept while you work here and afterwards for as long as needed for labour management, payroll, accounting and handling complaints, as required by labour, accounting and tax law. After that it is deleted or anonymised. Selfies are sensitive data; we keep them only as needed for attendance purposes [proposal: selfie + coordinates kept 12 months then deleted; working-time figures (anonymised when an employee deletes their account) kept per Accounting Law 2015 Art. 41 — lawyer to confirm].

8. Your rights and deletion requests

Under the Law on Personal Data Protection you have the right to: be informed; consent or refuse (and withdraw consent); access, view and correct your data; obtain a copy; request deletion; request restriction of processing; object to processing; and complain, report, bring a claim and seek compensation as provided by law.

To exercise these rights, write to contact@dbr.business [xác nhận hộp thư]. We acknowledge your request and handle it within the statutory time limits; we may ask you to verify your identity to prevent impersonation. Withdrawing consent does not affect processing already carried out, but some features may stop working.

Deleting your account and data: in the app go to the "Me" tab → "Delete account" (two-step confirmation); or send a request to contact@dbr.business [xác nhận hộp thư] or tell your manager. We delete or anonymise your data except what the law requires us to keep (e.g. labour or accounting records) and will tell you what is kept and for how long. The last remaining administrator cannot delete their account until a replacement exists. Managers may hide former employees from lists; hiding is not deletion.

Copy of your data: you can export your own timesheet to Excel under Reports; for a fuller copy (photos, coordinates, requests) email us.

9. Employee rights and our commitments

10. Security and breach notification

We use encrypted connections, role-based access (employee/manager), a private photo bucket with time-limited viewing links, session storage in the device's secure store, and Face ID/fingerprint before check-in (if enabled). No system is perfectly secure.

If a personal-data breach occurs that may harm your lawful rights and interests, we will notify the competent data protection authority within 72 hours of discovery, take remedial measures, and notify you where the law requires.

11. Age

Never Late is not intended for people under 16. Under Vietnamese law a child is a person under 16 and processing a child's personal data requires the consent of a parent or guardian. If you are a parent/guardian and believe your child has given us data, contact us and we will delete it.

12. EU/EEA/UK users

If you use Never Late from the European Economic Area (EEA) or the United Kingdom, the GDPR / UK GDPR may apply alongside Vietnamese law. Our legal bases are then consent (Art. 6(1)(a)) and performance of a contract (Art. 6(1)(b)); for special-category data (e.g. health) it is explicit consent (Art. 9(2)(a)). You additionally have the right to data portability and to lodge a complaint with your local supervisory authority. For transfers outside the EEA we rely on Standard Contractual Clauses (SCCs) or another valid mechanism offered by the recipient.

13. Changes to this policy

We may update this document when the product or the law changes. Material changes will be announced in the app or by email before they apply; the update date is shown at the top. Continuing to use the service after the effective date means you accept the new version, unless the law requires us to obtain your consent again.

14. Contact

DBR Group ([full legal name, registration no., address — fill in before publishing]) · Email: contact@dbr.business [xác nhận hộp thư]. You may also complain to Vietnam's competent personal data protection authority (under the Ministry of Public Security).