Privacy Policy
How svdy collects, uses, shares, and protects your personal data — written for the GDPR Article 13/14 disclosure standard and aligned with CCPA/CPRA. Plain language, concrete commitments, and links to the live mechanisms behind them.
1. What we collect
We collect three categories of personal data:
• Account data you provide: name, work email, organization name, role, phone (optional), payment billing contact. Provided by you or your organization's admin during sign-up.
• Operational data generated through use: time entries (clock-in / clock-out timestamps + GPS coordinates when geofencing is enabled), schedules, leave requests, process form submissions, in-app messages, audit logs of admin actions.
• Technical telemetry: IP address, browser/device type, session timestamps, error traces (sampled). Used for security monitoring and product reliability — never for ad targeting.
We do not buy personal data from data brokers, do not run analytics SDKs that share data with third-party ad networks, and do not sell personal information as defined under CCPA §1798.140(t).
2. How we use your data
We process personal data for these purposes only:
• Service delivery — running the attendance, scheduling, and workflow features your organization paid for. This is the contractual basis under GDPR Art. 6(1)(b).
• Service improvement — aggregated, de-identified usage statistics to identify performance bottlenecks and feature requests. Cannot be re-identified back to a worker. GDPR Art. 6(1)(f) legitimate interest.
• Security & fraud prevention — detecting unauthorized access, abuse patterns, and platform attacks. GDPR Art. 6(1)(f) legitimate interest, balanced against your privacy through data minimization and short retention.
• Legal compliance — responding to subpoenas, court orders, and lawful regulatory requests. GDPR Art. 6(1)(c).
• Communications — service announcements (always), trial onboarding (during trial only), product updates (opt-out via Notification Settings).
We do NOT use your data to train large language models, do not share with advertising networks, and do not enrich your worker data with external sources.
3. How we protect your data
Concrete security controls in place today:
• Encryption at rest: AES-256 across all stored customer data (RDS / S3 / EBS).
• Encryption in transit: TLS 1.2+ on every customer-facing endpoint and internal service-to-service hop.
• Access control: role-based access on the application layer; AWS IAM least-privilege on the infrastructure layer; multi-factor authentication required for all employee admin access.
• Audit logs: every administrative action recorded with actor, timestamp, and target. Retention 7 days (Free) / 1 year (Starter+) / 3 years (Pro+).
• Network: AWS Multi-AZ deployment in us-east-1; no public database endpoints; security-group ingress restricted to load balancers.
• Secrets: production credentials in AWS Secrets Manager; never in environment variables or source code.
For the live security architecture and SOC 2 timeline, see /trust and /trust/soc2.
4. Your rights
Regardless of where you live, you have these rights over your personal data:
• Right of access — get a copy of what we hold about you. Export available in your account settings; we'll respond to direct requests within 30 days.
• Right to rectification — correct inaccurate personal data. Self-service in account settings, or email us.
• Right to erasure ("right to be forgotten") — delete your data when there's no legitimate business reason to keep it. Note: your employer (the controller) may need to retain attendance records for labor-law compliance; our role as processor is to follow their instructions.
• Right to restrict processing — pause us from using your data while a dispute is resolved.
• Right to data portability — get your data in a machine-readable format (CSV / JSON).
• Right to object — opt out of legitimate-interest processing such as service improvement analytics.
• Right to withdraw consent — for biometric face-recognition clock-in (GDPR Art. 9(2)(a)) and any other consent-based processing.
• Right to complain — to your local data protection authority. EU residents: your national DPA. UK residents: ICO. California residents: contact California Privacy Protection Agency.
To exercise any of these, email legal@svdy.com. We respond within 5 business days; full resolution within 30 days per GDPR Art. 12(3).
5. Cookies and similar technologies
We use a minimal set of cookies. We do NOT use third-party advertising cookies, pixel trackers, or fingerprinting.
• Strictly necessary cookies (no opt-out, no tracking purpose): session ID for authentication, CSRF token for security.
• Functional cookies (you can disable in browser): your language preference, dashboard layout choices.
• Analytics cookies: NONE on customer-facing tenant subdomains (qutime.com / pureoa.com). svdy.com (this marketing site) currently runs no analytics SDK. Future analytics will be cookieless (server-side aggregation only) per our commitment to no third-party ad-tech.
Cookies are scoped to first-party (svdy.com / qutime.com / pureoa.com / id.svdy.com) only. We do not embed third-party iframes that load tracking cookies.
6. Contact, breach notification, and updates
Data protection contact: legal@svdy.com — staffed during US business hours, response within 5 business days for general inquiries and within 24 hours for urgent (subject contains "urgent" or "breach").
Breach notification: if a security incident affects your personal data, we notify your organization's designated DPO contact within 72 hours of becoming aware (GDPR Art. 33(1)) with the scope, suspected cause, remediation steps, and any actions you should take.
Sub-processors: we share data only with the third-party services listed at /trust/sub-processors (AWS, Stripe, Amazon SES, Expo, Cloudflare DNS). Each operates under its own DPA referenced on that page. We notify customers 30 days before adding or removing a sub-processor.
International transfers: customer data is stored in AWS us-east-1 (United States). EU → US transfers are covered by the EU Standard Contractual Clauses (SCCs, 2021 version) included in our DPA at /trust/dpa. UK transfers add the UK Addendum to the SCCs.
Updates to this policy: we publish material changes 30 days before they take effect, with a changelog at the top. Last updated date is shown above. The current version always lives at svdy.com/privacy.
Questions about how we handle your data, or want to exercise GDPR/CCPA rights (access, deletion, portability)? Email legal@svdy.com — we respond within 5 business days.
