Privacy Policy
Last updated 18 August 2026
This Privacy Policy explains what personal data is processed in connection with Timenox 360, why it is processed, and the rights that may be available to you. Timenox 360 is field workforce management software. It is distinct from Timenox, the office attendance and workforce-management product.
This document is a professional draft for legal review. It is not a substitute for advice from qualified counsel.
1. Who we are
Timenox 360 is operated by VYQDA Technologies Pvt. Ltd. (“we”, “us”, “our”), a company incorporated in India. The public contact address for this product family is support@timenox.com.
This policy applies to employer administrators who create or manage a Timenox 360 organization; field employees provisioned by that organization; and visitors to the Timenox 360 marketing website.
2. Data roles
Employer — controller
The organization that subscribes to Timenox 360 is the data controller for employee personal data processed in the Service. The Employer decides which people to provision, which operational features to use, and how field-work records are used inside the organization.
The Employer is responsible for informing employees, establishing a lawful basis, and obtaining consent where applicable law requires it (including, where relevant, GDPR, India’s Digital Personal Data Protection Act, 2023, and other local employment or privacy laws).
Timenox 360 operator — processor
We process employee personal data to provide the Service on the Employer’s instructions. We do not sell employee data and do not use it for advertising unrelated to providing the Service.
Employees who have questions about how their employer uses attendance, visit, or location-related records should contact the Employer first. We will assist as processor where we are able, via support@timenox.com.
3. Account and organization data
When an administrator creates or manages an organization we may process name, work email, organization name, account credentials (stored in hashed form), support correspondence, and billing details as presented in the application or an order form. We do not claim a specific payment-card storage practice on this marketing website; card handling, if any, is performed by the processor shown at checkout.
4. Employee profile data
Employees do not create a public self-signup on the marketing website. The Employer provisions access. Profile data typically includes name, internal identifiers, role or team assignment, and employment status as configured by the Employer.
5. Field attendance data
Where used, Timenox 360 records GPS-enabled field attendance events such as check-in, check-out, working hours, and optional selfie attendance on the mobile application. Associated timestamps and the attendance state are stored as operational records for the Employer.
Selfie images, where the Employer enables that feature, are used for employer-side verification. This policy does not claim that we perform facial recognition or extract biometric templates from those images.
6. Location data
Location is not collected merely because the Timenox 360 application is installed. Where the Employer enables location-based field attendance, an active attendance session begins when the employee checks in. During that session, Timenox 360 may collect location updates, including while the application is backgrounded, to provide field-work visibility. The session ends when the employee checks out, at which point location collection for that attendance session stops. Whether updates continue in the background depends on device permissions, operating-system behavior, connectivity, and other technical conditions. This policy does not claim 24/7, always-on, or permanent tracking, and it does not assert a specific sampling frequency or route-history store.
GPS accuracy varies by device and environment. Employers should not rely solely on location data for disciplinary decisions. Employees are asked for device location permission before the device provides location to the application, subject to the operating system’s permission model.
Until unpublished implementation details (for example exact sampling intervals) are independently documented, those details must not be inferred from this policy.
7. Visits, tasks, calendar, orders, and reporting
Depending on configuration, the Service may store customer and site visits, assigned tasks, calendar entries, and—where used—orders and collections recorded during field work. Operational reporting presents recorded activity to authorized administrators. These records are workplace operations data, not a public tracking feed.
8. Device data
The mobile and web applications may process device identifiers, operating-system and app-version information, IP address, and diagnostic logs needed to operate, secure, and support the Service. This policy does not copy Timenox office-product WebAuthn or browser-fingerprinting descriptions unless those mechanisms are separately documented for Timenox 360.
9. Marketing website and contact form
If you email support@timenox.com or submit the contact form, we process the name, organization, work email, optional phone number, optional team size, and message you provide so we can respond. Submissions may be delivered to an automation endpoint configured for that deployment.
The marketing website uses Google Analytics 4 to measure traffic, engagement, and successful contact-form submissions. Analytics events do not include the contents of the contact form. Google LLC processes this analytics data as a service provider. This site does not use advertising pixels or session replay. See the Cookie Policy for cookies used on this site.
10. How data is used
- Providing field workforce operations: attendance, visits, tasks, calendar, optional orders/collections, and reporting.
- Administering Employer accounts, trials, and support.
- Securing the Service and investigating abuse.
- Complying with applicable law.
- Improving the Service using aggregated or diagnostic information where appropriate.
- Understanding how the public marketing website is used, including whether a contact enquiry was submitted.
11. Legal basis (where GDPR or similar laws apply)
For Employer account data, processing is typically necessary to perform a contract or take steps at the Employer’s request. Employee data is processed on the Employer’s documented instructions; the Employer is responsible for its own legal basis, which may include legitimate interests or consent where required. Security and fraud prevention may rely on legitimate interests. Marketing-website analytics may rely on legitimate interests in understanding public-site usage where that basis is available. Legal obligations may require retention or disclosure.
12. Sharing
We do not sell personal data. Authorized Employer administrators can see the operational records the Service is designed to show them. Infrastructure and cloud providers process data as sub-processors to host the Service. Google LLC processes marketing-website analytics as described in the Cookie Policy. Payment providers may process billing data when a paid plan is purchased. We may disclose data if required by valid legal process. A business transfer may include data subject to equivalent protections where required.
This policy does not invent a public sub-processor list, encryption-standard inventory, or certification set.
13. Retention
We retain personal data only as long as needed to provide the Service, as configured by the Employer, or as required by applicable law. Specific retention windows that are not published here should be treated as unspecified—not as infinite storage and not as a guaranteed deletion SLA.
14. Security
We implement technical and organizational measures appropriate to the nature of the Service, including encryption in transit (TLS) for the public websites and applications as commonly deployed. No system is completely immune to attack. This policy does not claim “100% secure,” unpublished certifications, or that a breach has never occurred.
15. Your rights
Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability, and objection. Employees should usually exercise those rights through the Employer. You may also contact support@timenox.com. We will respond within the time required by applicable law, often within 30 days where that period applies.
16. International transfers
The operator is established in India. Data may be stored or processed on infrastructure in India and in other countries where providers operate. Where transfer rules apply (for example EEA or UK), we use appropriate safeguards such as standard contractual clauses where required. Employers that need a DPA should contact support@timenox.com.
17. Children's privacy
Timenox 360 is intended for workplace use by adults. It is not directed at children under 18. If you believe a minor has been provisioned, contact support@timenox.com.
18. Changes
We may update this policy. Material changes will be indicated by the “Last updated” date and, where appropriate, notice to Employer administrators. Continued use after the effective date constitutes acceptance where permitted by law.
19. Account deletion
Employer administrators may request deletion of an organization account via support@timenox.com. Employees should request deletion through the Employer. We will take reasonable steps to delete or anonymize data unless retention is required for legal, tax, security, or dispute-resolution purposes.
20. Contact
Privacy questions: support@timenox.com. Company: VYQDA Technologies Pvt. Ltd., Agra, Uttar Pradesh, India. Related pages: Terms of Service, Cookie Policy, and Security.
Questions: support@timenox.com. Related:Privacy,Terms,Cookies,Security.