HRIS Logo HRIS Logo

HRIS Mobile App Privacy Policy

This Privacy Policy explains how the HRIS Mobile App collects, uses, stores, and shares information when employees and authorized users sign in to the app and use its HR, attendance, profile, and account request features.

Last updated: June 26, 2026

1. Scope

The HRIS Mobile App is intended for use by employees and authorized personnel of the Kuwait Oil Company (KOC) that provides access to the app. This Privacy Policy applies to information processed through the mobile application, including Microsoft account sign-in, employee profile access, attendance actions, mobile account requests, and related support features.

2. Information We Collect

The following categories of information are collected and processed:

  • Identity and account information. When you sign in, the app uses Microsoft authentication to process your work account identifier, work email address, access tokens, and related account details required to authenticate you and connect your account to the HRIS system.
  • Employee and profile information. The app retrieves employee-related HRIS records such as your name, employee information, assigned work locations or buildings, account approval status, and other profile data made available by the organization through its backend services.
  • Attendance and request information. When you submit attendance actions or mobile account requests, the app processes sign-in time, sign-out time, attendance identifiers, on-site or not-on-site status, permission request details, reason fields, selected dates, and time ranges.
  • Location data. The app collects precise or approximate location data, including latitude and longitude, to support attendance verification, location-based worksite checks, profile map features, and mobile account requests.
  • Camera, Image, and Face Data. To support identity-verified attendance features, the app uses your device camera to capture facial images (“Face Data”). During initial registration, a baseline facial image is captured for approval. During daily attendance actions (clock-in or clock-out), a live facial image is temporarily captured for real-time verification.
  • Biometric and device authentication data. The app can request device-level biometric or credential authentication, such as fingerprint, face recognition, PIN, password, or passcode, to re-authenticate access within the app. The app relies on your device operating system for this process and does not collect or store your raw fingerprint or facial biometric template.
  • App security and diagnostic data. The app may process technical information related to network requests, service errors, response codes, and operational diagnostics to maintain app reliability, investigate failures, and protect the service.
  • Local storage data. The app may store limited data on your device, such as secure authentication state, biometric re-authentication timestamps, temporary app preferences, and locally cached session-related values needed for app operation.

3. How We Use Information

We use the information processed through the app to:

  • Authenticate users and provide secure access to the HRIS Mobile App.
  • Display employee profile and employment-related information available in the HRIS system.
  • Record and manage attendance actions, including sign-in and sign-out events.
  • Verify worksite presence or support attendance exception handling using location information.
  • Process Face Data to prevent identity fraud: During daily attendance, the temporarily captured Face Data is vectorized and compared against the employee’s pre-approved registration image using a neural network running on our internal servers. Once this real-time comparison is complete, the daily capture is immediately discarded.
  • Support permission requests, account requests, and other employee self-service features.
  • Maintain session security through secure storage and optional biometric re-authentication.
  • Monitor reliability, troubleshoot issues, and protect the app and backend services from misuse.

4. Permissions and Device Features

The app may request access to the following device capabilities:

  • Location: to determine whether you are within an approved worksite area and to support attendance or account request workflows.
  • Camera: to capture images and Face Data for initial registration and daily attendance verification.
  • Biometric or device credentials: to re-authenticate access to the app using device-supported security methods.
  • Network access: to communicate with the organization’s HRIS backend and Microsoft authentication services.

If you deny certain permissions, some features of the app may not function correctly or may be unavailable.

5. Sharing and Storage of Information

Information processed by the app, including collected Face Data, may be shared with:

  • The KOC team operating the HRIS backend and its authorized administrators.
  • The Team Leader and/or supervisor of the employee.

Storage and Third-Party Disclosure: Only the approved baseline registration image is stored securely on internal KOC server infrastructure. The facial images captured during daily attendance are not stored anywhere; they are processed in real-time and immediately discarded. Face Data is never shared with, sold to, or disclosed to any third parties or external entities.

6. Data Retention

Information is retained for as long as necessary to provide the app’s functionality, manage employment-related processes, and comply with internal corporate policies.

Face Data Retention: The approved baseline facial image captured during initial registration is retained only for the duration of the employee’s active employment with KOC. As soon as the employee leaves the company, the account is deactivated and the registration image is permanently deleted. Face Data captured during daily clock-in/clock-out events is never stored or retained; it is immediately discarded after the real-time neural network comparison.

7. Data Security

The app uses administrative, technical, and organizational measures intended to protect personal information against unauthorized access, loss, misuse, or alteration. These measures may include secure authentication, secure local storage, session controls, and protected communication with backend services. No method of electronic storage or transmission is completely secure, and absolute security cannot be guaranteed.

8. Children’s Privacy

The app is intended for employee and authorized workplace use and is not directed to children. It is not intended to, and cannot be, used to collect information from minors.

9. Changes to This Privacy Policy

This Privacy Policy may be updated from time to time to reflect changes in legal requirements, operational practices, backend services, or app functionality. Any updated version will be posted on the page where this policy is made available, and the revision date will be updated.

10. Contact

For questions about this Privacy Policy or privacy-related requests connected to the HRIS Mobile App, please contact the HRIS team that provided your access to the app.