Privacy policy
Last updated: 30 September 2026
DeskAttend is provided by Aidesknova ("we"). This page explains what personal data the DeskAttend service handles, why, and for how long.
Who is responsible
Each organization that uses DeskAttend (the "workspace") decides what data it collects about its people and why — it is the data controller. We process that data on the organization's behalf to provide the service. If you are an employee or student, contact your organization's administrator first; you can also contact us.
What we collect
- Account details: name, work email, and optionally a mobile number, employee ID, department and role.
- Attendance: clock-in and clock-out times, shifts, leave and requests, class attendance marks, and the reasons given for changes.
- Location — only at the moment of clocking in or out. DeskAttend does not track location in the background. The server uses the location to decide whether the clock-in was on-site.
- Security records: sign-in history (time, IP address, browser), active sessions, and an audit log of changes made in the workspace.
- Workspace information such as the organization's name, logo, time zone and settings.
Why we use it
To record attendance, calculate hours, leave and payroll inputs, produce the reports the organization asks for, send the notifications it turns on, keep accounts secure, and support the service. We do not sell personal data or use it for advertising.
How long we keep it
- Exact location coordinates are erased after the period the organization chooses — one year by default (90 days to three years, or kept if the organization decides). Whether a clock-in was on-site or off-site is kept, because attendance records depend on it.
- Other workspace data is kept while the organization uses DeskAttend, and deleted or returned when it asks us to close the workspace, except where the law requires us to keep it longer.
Who else processes data
Only the providers needed to run the service: our hosting provider (servers and backups), an email delivery provider for notifications, and — only if the organization turns it on — WhatsApp (Meta) for alerts. Each organization's data is kept separate from every other organization's.
Security
Encrypted connections (HTTPS), encryption of sensitive settings at rest, hashed passwords, optional two-step verification, sign-in protection against automated attacks, role-based permissions enforced on the server, and an audit trail of changes.
Your choices and rights
You can ask your organization's administrator to access, correct or export your data, or delete it where the organization's obligations allow. We support organizations in meeting their obligations under applicable law, including India's Digital Personal Data Protection Act, 2023.
Contact
Questions about this policy: hello@desknova.in · +91 93092 41404 · Aidesknova, Akola, Maharashtra, India.