Privacy Policy — WorkLabs
Effective date: 22 September 2026 · Last updated: 22 September 2026
This Privacy Policy explains how WorkLabs (“we”, “our”, “us”) collects, uses, stores, and shares information when you use the WorkLabs mobile application for Android (the “App”).
The App is a business HR / workforce tool provided only to organisations that subscribe to WorkLabs (each a “Customer” / employer). It is not a consumer social, dating, gaming, or advertising app. We do not show ads in the App, and we do not sell personal information.
Employees use the App under their employer’s WorkLabs account. Your employer determines which HR features are enabled and is responsible for the HR records in that account. WorkLabs processes that data as a service provider / processor to operate the App for the Customer.
1. Who we are
WorkLabs
Privacy contact:
info@worklab.co.in
Address: India. For postal correspondence, email the contact above and
we will provide mailing details.
2. Permissions the App may request
On Android, the App may ask for the following runtime permissions. Each permission is used only for the stated workplace purpose. You can deny or revoke a permission in Android Settings → Apps → WorkLabs → Permissions. Denying a permission disables the related feature; other parts of the App may still work.
- Location (approximate and precise) — to confirm you are inside an authorised office geofence when you check in or check out. Location is requested while you use the App (foreground). We do not use background location tracking for advertising or marketing.
- Camera — to capture a face photo / liveness check when your employer requires face-verified attendance punch.
- Photos / media (or storage on older Android versions) — only so you can choose an existing image to update your profile photo. We do not scan your full gallery in the background.
- Notifications — to show work alerts (for example leave / regularization updates and your own check-in or check-out confirmation).
- Internet — to connect securely to WorkLabs servers.
3. Information we collect
Account and login
- Work email address
- Password (sent securely to our servers to sign you in; we do not store your password in plain text on the phone)
- After login: name, employee code, role, branch, department, designation, and profile photo URL if present in your employer’s HR record. These fields belong to your employer’s WorkLabs account.
Location
- Approximate and precise location (GPS / network)
- Used only to confirm you are at an authorised office geofence when you check in or check out
- Location is collected at the time of the punch (while the App is in use). We do not continuously track you in the background for ads or marketing
- If you deny location permission, you cannot mark attendance from the App using geofence punch; other HR screens may still work
Camera and face attendance photos
- When face attendance is enabled by your employer, the App uses the camera to detect a face and capture a punch selfie / liveness image
- That image is uploaded over HTTPS to WorkLabs servers and stored with the attendance punch (for example as a photo URL) so your employer can verify the punch
- Face photos are used only for attendance verification and related HR audit. We do not sell face images, use them for advertising, or use them to train public AI models for third parties
- If you deny camera permission, face-verified punch from the App will not work; other features may still work
Profile photos and media
- If you update your profile photo, you may pick an image from your device gallery. The selected image is uploaded to secure cloud storage used by WorkLabs and linked to your employer’s employee profile
- Profile photos may appear in the App (for example Home, Profile, Virtual ID card, Directory, or Team attendance) to authorised users in your organisation
Attendance and HR data
- Check-in / check-out time, GPS coordinates of a mobile punch, matched office / geofence, and optional face punch photo
- Attendance punches may also come from authorised workplace biometric / time-attendance machines connected to your employer’s WorkLabs account (when configured by the Customer)
- Leave requests and approvals, attendance history, regularization, payroll summary (if enabled), and team / company attendance views (if your role allows)
- In-app notification inbox items related to leave, regularization, and your own attendance alerts
Push notifications and device tokens
- After login (and if you allow notifications), the App registers a Firebase Cloud Messaging (FCM) device token with WorkLabs servers
- We use that token only to deliver work-related push notifications to your signed-in device (for example leave / regularization status and your own check-in or check-out alerts)
- On logout, the App requests removal of that device token for your account on that platform so push delivery to that session stops
- We do not use push tokens for advertising or marketing campaigns
On the device
- Login / session tokens so the App can stay signed in securely
- Limited local data such as a short session log and identifiers of notifications already shown (to avoid duplicate alerts)
- This local data stays on your phone until you log out, clear App data, or uninstall the App
What we do not collect
- We do not collect contacts, SMS, call logs, or microphone audio for our features
- We do not sell personal data or share it with advertisers or data brokers
- We do not use the App to show third-party ads
4. How we use information
- Authenticate you and keep your session secure
- Record and verify attendance (including geofence and, where enabled, face punch)
- Show your profile, leave, payroll, notifications, and (for managers / authorised roles) team information
- Deliver work-related push and in-app notifications
- Store and display profile and punch photos for HR verification
- Operate, secure, and troubleshoot the App and related services
- Comply with legal obligations where applicable
We do not sell your data. We do not use location, camera, photos, email, or push tokens for advertising or marketing profiling.
5. Legal basis (where applicable)
Depending on your location and your employer’s arrangements, processing may rely on: (a) performance of an employment / workplace relationship and legitimate interests to run attendance and HR systems for the Customer; (b) your employer’s instructions as controller of HR data; and (c) your consent on the device for permissions such as location, camera, photos/media, and notifications.
6. Sharing and service providers
Data is processed on WorkLabs servers and infrastructure used to run the App for your employer. Your employer’s authorised HR / IT users can access records for their organisation according to their roles.
We may use trusted service providers who process data only under our instructions, including:
- Cloud hosting / database providers — to host the WorkLabs application and store Customer account data
- Microsoft Azure (or equivalent object storage) — to store uploaded files such as profile photos and attendance punch photos
- Google Firebase Cloud Messaging — to deliver push notifications to your device
We do not share personal information with advertisers. We may disclose information if required by law, regulation, legal process, or to protect the rights, safety, and security of users, Customers, or WorkLabs.
7. Data retention
- Login / session tokens on device: until logout, expiry, or uninstall
- FCM device tokens on our servers: until logout / unregister, token replacement, or account deactivation as applicable
- Attendance punches (including coordinates and face punch photos) and other HR records: retained as required by your employer’s company / labour / audit policy
- Profile photos: while linked to the employee record in the Customer’s account, or until replaced / removed by authorised users
- In-app notification records: according to product / Customer retention settings
- Local session / shown-notification helpers: limited recent data on the phone
8. Security
Access to WorkLabs services uses HTTPS. Session tokens are stored on the device. Uploaded photos are stored in secured cloud storage used by the service. Access to server records is limited to authorised WorkLabs personnel and your employer’s authorised HR / IT users. No method of transmission or storage is 100% secure.
9. Your choices and controls
- Deny or revoke Location, Camera, Photos / media, or Notifications in Android Settings → Apps → WorkLabs → Permissions
- Change your password in the App (where available)
- Log out to clear session tokens on the device and unregister the push device token for that session
- Uninstall the App to remove local App data from the phone
- For correction, export, or deletion of HR / attendance records (including punch photos held in your employer’s account), contact your employer’s HR department — they control that Customer account
- For App or privacy questions about WorkLabs as the service provider, email info@worklab.co.in
10. Children’s privacy
The App is intended only for employees and authorised workplace users of Customer organisations. It is not directed to children under 13 (or under 16 where a higher age is required by law). We do not knowingly collect personal information from children.
11. International users
WorkLabs may process data in India and/or other countries where our hosting or service providers operate. If you use the App from the EEA, UK, or another region with data-transfer rules, your employer’s agreement with WorkLabs and applicable law govern those transfers.
12. Changes to this policy
We may update this Privacy Policy when the App’s features or practices change. The “Effective date” / “Last updated” line at the top will change when we do. Continued use of the App after an update means you acknowledge the revised policy. Material changes may also be communicated through the App or your employer where appropriate.
13. Contact
WorkLabs privacy:
info@worklab.co.in
HR / employment records: your employer’s HR department.
Google Play users in the EEA/UK may also contact their local data
protection authority.