GDPR Compliance Statement
Learn how Staff Scan complies with the European Union's General Data Protection Regulation (GDPR).
1. Processing Personal Data (GDPR Scope)
The GDPR regulation ensures the protection of EU citizens' personal data. Staff Scan acts as a **Data Processor** for our clients (who are the Data Controllers). We only store employee records essential for calculating attendance logs and automated payroll sheets.
2. The Right to be Forgotten (Article 17)
Under GDPR Article 17, employees have the right to request deletion of their personal and biometric records. When an administrator removes a staff profile from the admin dashboard, their facial mapping coordinates (biometric vector points) and attendance logs are permanently deleted from our servers.
3. Right to Data Portability (Article 20)
Clients and employees have the right to access and port their personal logs. Admins can export the entire employee database, shift schedules, and attendance histories in clean **CSV** or **PDF** files with a single click.
4. Security Measures & Encryption Protocols
Our security safeguards include strict TLS encryption for data transmission and military-grade AES-256 encryption for database tables. Unauthorized access logs are monitored to prevent data leak risks.
Last Updated: July 10, 2026. For GDPR queries, contact us at info@staffscan.in.