ATTENDANCE.CY · LEMORANGE LTD

Privacy at work, explained.

This notice is specifically about the Attendance.cy employee app and workspaces. It is separate from Lemorange's client-portal privacy policy.

Updated 16 September 2026

Who is responsible?

The employer or organisation that creates an Attendance.cy workspace normally decides why employee data is used, which features are enabled, who may access the records and how long they are retained. It is the controller of that workforce data.

Lemorange Ltd, based in Nicosia, Cyprus, provides and secures Attendance.cy as a processor under the customer's instructions and agreement. Lemorange is separately responsible for its own website enquiries, support and business records. We do not make employment or pay decisions about workers.

What the app and workspace may hold

  • Work identity and access: name, employee code, contact details, site, department, role and employer-created sign-in credentials.
  • Working time: schedules, shift changes, attendance attempts and corrections, leave, approvals, calculated hours, messages and audit history.
  • Mobile operation: device type and identifier, app version, notification token, and information required to diagnose sign-in or delivery problems.
  • Optional attendance checks, only when the organisation enables them: location and accuracy, distance from an authorised site, approved Wi-Fi identifiers and connection information at the time of an attempt. The app does not need continuous location tracking for this check.
  • Content you choose to send, such as a profile photo, document or in-app message, where the relevant feature is available.

A customer may also use compatible physical terminals with QR, card, PIN or, where lawful and enabled, biometric identification. Those terminal choices are not required for every mobile-app user.

Why it is used and who receives it

Attendance.cy uses the data to provide secure sign-in, schedules, attendance, shift-cover messages, hours and approvals selected by the customer; to protect the service; and to support a documented request or correction. The employer must identify the lawful basis for its workforce processing and inform its workers.

Access is limited to authorised people in the customer's workspace and Lemorange personnel who need it for service delivery, security or support. Hosting, notification and technical providers process only what is needed for their role. An HR, payroll or access-control integration receives data only when authorised by the customer. We do not sell workforce data or use it for advertising profiles.

If processing outside the European Economic Area is required, Lemorange and the customer use the applicable legal transfer safeguards. The customer agreement may describe a particular deployment and provider arrangement.

Security and retention

Production communications are encrypted in transit. Attendance.cy separates customer workspaces, restricts access by role and records relevant changes in an audit history. No online system is completely risk-free; organisations must protect their own accounts, devices and networks too.

Workforce records follow the customer's documented retention settings and instructions. On termination, data is returned or deleted as agreed. Attendance, payroll, tax, security or dispute records may need restricted retention for a legal obligation or claim. Limited protected backup copies can remain until the normal backup cycle overwrites them. There is no single fixed period for every customer or record type.

Your rights and deletion

Depending on the circumstances, you may request access, correction, erasure, restriction or portability, or object to processing. Some rights are subject to legal obligations. For workforce data, contact the employer controlling your workspace; Lemorange cannot erase it on a worker's direct instruction without involving that customer unless law requires otherwise.

Signed-in employees can open Your data rights in the Attendance.cy app's Settings, submit an account-and-data deletion request, and follow its status and response. If you cannot sign in, contact your employer or email [email protected] so we can direct the request appropriately. Do not email a password, PIN or QR code.

Requests are reviewed without undue delay and normally within one month after identity and authority are confirmed. We explain any data that cannot be removed and why. The steps and retention limits are set out on the Attendance.cy data-deletion page.

You may complain to the Cyprus Office of the Commissioner for Personal Data Protection or the authority where you live or work.

Contact

Lemorange Ltd · Nicosia, Cyprus · [email protected] · 80012900. For information your employer controls, it remains your first point of contact.