Privacy & Data Processing Policy
1. Introduction
This policy explains how FIXALL GENERAL CONSTRUCTION LT ("we", "us", "the Company") collects, uses, stores and protects personal data through the Work Activity Tracker system used to record the start and end of working shifts. By creating an account, logging in and using the check-in functionality, employees agree to the processing of their data as described in this document.
2. Data we collect
When you use the Work Activity Tracker we may collect the following categories of personal data:
- Identity data: first name, last name, username, email address, phone number and job position.
- Authentication data: encrypted password, session cookies, and timestamps of successful logins.
- Work-activity data: date and exact time of each check-in and check-out, duration of shifts, work site, client, and any description or notes you provide.
- Geolocation data: latitude and longitude captured by your device at the moment you press Check-in and Check-out. Location is obtained exclusively with your explicit browser authorization.
- Digital signature: if requested by your administrator, an image of your signature captured via canvas or file upload.
- Technical data: IP address, browser type and version, operating system, and internal identifiers required for security and auditing.
3. Purpose and legal basis
We process your personal data for the following purposes:
- Recording attendance and working hours for payroll, billing and operational purposes.
- Verifying that work is performed at the agreed locations (through optional geolocation).
- Complying with labour-law obligations that require employers to keep reliable records of working hours.
- Auditing security incidents and preventing fraudulent use of the platform.
The legal bases on which we rely are (a) the performance of the employment contract between us and the employee, (b) compliance with legal obligations, and (c) the legitimate interest of the Company in operating the tool safely and efficiently.
4. Storage and retention
Data is stored on the servers where this website is hosted. We retain attendance records for the period required by applicable labour and tax regulations (typically between 5 and 10 years, depending on jurisdiction). Access credentials remain active while your employment relationship is in force.
5. Sharing with third parties
We do not sell, rent or transfer your personal data to third parties for commercial purposes. Data may be shared with:
- Internal supervisors, leads and the human-resources team, strictly on a need-to-know basis.
- Technical providers that host the website (e.g. hosting, backup services) under confidentiality obligations.
- Authorities or courts when required by law or by a binding judicial order.
The map tiles displayed on administrative views are served by OpenStreetMap (© OpenStreetMap contributors). Only the coordinates needed to render a map are sent to their tile servers, and never your personal identity.
6. Security measures
We apply reasonable technical and organizational measures to protect your data: encrypted passwords (hashed with WordPress secure algorithms), capability-based access control, nonce protection on every write action, sanitization/validation of all inputs, and audit trails for administrative edits of working-time records.
7. Your rights
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data — via your profile page or by contacting your supervisor.
- Object to or limit certain processing, where permitted by law.
- Request deletion of your data once the statutory retention periods have elapsed.
- Withdraw your consent to geolocation at any time. Once withdrawn, check-ins without location will be accepted (if permitted by the administrator) or you will need to record them manually with your supervisor.
- Lodge a complaint with the competent data-protection authority.
8. Cookies and session tokens
Authentication cookies are strictly necessary to keep you logged in. We do not use tracking or advertising cookies as part of this plugin. Your browser may store the "remember me" cookie if you tick that option at login.
9. Contact
To exercise your rights or ask any question about this policy, please write to mario@fixallgc.com. We will reply within the period established by applicable regulations.

