Legal
Privacy policy
KoreKonnect records the moment a signed-in member of staff taps a registered KonnectReader, and nothing more. No location, no biometrics, no background monitoring. This notice explains exactly what we hold, why we hold it, who else sees it and what you can ask us to do about it.
- Last updated
- 8 August 2026
- Version
- 1.0
- Applies to
- korekonnect.co.uk
The short version
We hold the name, work email and attendance record of staff at organisations that use KoreKonnect. We do not track anyone's location, we do not use biometrics, and we never see or store card or bank details. We do not sell data, run advertising, or use analytics or tracking cookies. If your employer uses KoreKonnect, they decide what is recorded about you and you should speak to them first; we will help them respond.
1.Who we are
KoreKonnect is a workforce attendance service operated by Kore Digital Ltd (“we”, “us”), a company registered in England and Wales under company number 17202130, with its registered office at 82 James Carter Road, Suite A, Mildenhall, Suffolk, IP28 7DE, United Kingdom.
| Purpose | Contact |
|---|---|
| Privacy and data protection | privacy@korekonnect.co.uk |
| General enquiries | hello@korekonnect.co.uk |
| Person accountable for data protection | Muhammad Rehmani |
| By phone | Naeem Kothdiwala, +44 7533 331973Muhammad Rehmani, +44 7775 277891 |
We are not required to appoint a statutory Data Protection Officer under Article 37 of the UK GDPR. Responsibility for data protection sits with Muhammad Rehmani, who can be reached at the address above.
2.Who this notice is for
This notice covers four groups of people.
- Visitors to our website at korekonnect.co.uk, including anyone who sends us an enquiry.
- Customer administrators and billing contacts at organisations that subscribe to KoreKonnect.
- Members of staff at those organisations, whose attendance, shifts and leave are recorded in the service.
- People who buy KonnectReaders from our shop.
If your employer uses KoreKonnect
Your employer decides what is recorded about you and why. They are legally responsible for that decision, and they should have told you separately that they use this system. If you want to see your records, correct them or object to them, ask your employer first. If they do not respond, you can contact us at privacy@korekonnect.co.uk and we will do what we can to help, though we usually have to act on your employer's instructions.
3.Controller or processor
Data protection law distinguishes between the organisation that decides why personal information is used (the controller) and the organisation that acts on its instructions (the processor). We are both, depending on the information.
| Information | Our role | Controller |
|---|---|---|
| Website visits and enquiries | Controller | Kore Digital Ltd |
| Customer accounts, subscriptions and billing | Controller | Kore Digital Ltd |
| KonnectReader orders and delivery | Controller | Kore Digital Ltd |
| Staff records, attendance, shifts, leave and corrections | Processor | The customer organisation (the employer) |
Where we act as a processor, we only use the information to run the service for that customer and to meet our own legal obligations. We do not use it for our own purposes, we do not sell it, and we do not use it to train models. The processing terms we agree with customers are set out in Annex A of our terms of service.
4.What we collect
This is the complete list. If a field is not named here, the system does not store it.
Staff and account records
- Full name.
- Work email address. Where a member of staff has no work email, employers may assign a placeholder address that does not receive mail.
- A password, stored only as a cryptographic hash by our authentication provider. Nobody at KoreKonnect can see or recover it.
- Role in the system, for example employee, team manager or department lead.
- Optional staff or payroll reference set by the employer.
- Team, department and the sites the person is assigned to.
- Annual leave entitlement in days, and whether the account is active.
Attendance
- The date and time of each tap, and whether it was a sign in or a sign out.
- The name of the door or reader that was tapped, and the site it belongs to.
- The chip identifier of the reader and its internal read counter, which together prevent a tap being copied or replayed.
- Whether the record came from a tap or was entered manually by a manager, and which manager entered it.
- Any note a manager adds to a record.
Working time, leave and corrections
- Contracted working pattern: day of the week, start and end times, and whether it is a working day.
- Published shifts and who is assigned to them, including break minutes.
- Leave requests: type, start and end dates, number of days, the reason given, the decision, who decided it and any comment they added.
- Leave balances: days allocated and days used for each year.
- Correction requests: the date, time and direction being corrected, the reason given, the outcome and any decision comment.
Customer, billing and order records
- Organisation name, time zone, subscription status and trial end date.
- Identifiers issued by Stripe for the customer and subscription, so we can match a payment to an account.
- For hardware orders: the buyer's email address, the delivery recipient's name and address, the order reference from Stripe, and what was ordered.
Enquiries
- Your name, organisation if you give one, email address and the message you send us. Enquiries arrive as email; they are not stored in the product database.
Technical information
- Your IP address, recorded briefly against a counter when you submit an enquiry, start a checkout or complete signup. We use it only to stop the same source flooding those endpoints.
- Our hosting and database providers also see the IP address and basic request details of everyone who uses the service, as any web host does.
5.What we never collect
These are deliberate design decisions, not omissions. The product has no way to gather any of the following.
- No biometric data. No fingerprints, facial recognition, iris or voice. We never process the special category data that biometric clocking systems rely on.
- No location tracking. No GPS, no geofencing, no Wi-Fi or Bluetooth positioning. We know which door was tapped because the reader is fixed to it, and nothing else about where anyone is.
- No background or continuous monitoring. Nothing is recorded between taps. There is no always-on app, no screen monitoring, no keystroke logging and no productivity scoring.
- No card or bank details. Payments are taken on Stripe's own hosted pages. Card numbers, security codes and bank details never reach our servers and are never stored by us in any form, not even the last four digits.
- No sensitive personnel data. No date of birth, home address, national insurance number, salary or pay rate, photograph, or right to work documents.
- No tracking, advertising or analytics. We run no analytics package, no advertising pixels, no session recording and no third party trackers of any kind. Our web fonts are served from our own domain, so your browser does not contact a font provider.
6.Where it comes from
- From the customer organisation, when an administrator creates staff accounts and sets working patterns, teams and leave entitlements.
- From the individual, each time they tap in or out, request leave or ask for a correction.
- From Stripe, when a subscription or hardware order completes, including the delivery address the buyer typed into Stripe's checkout.
- Automatically, in the limited technical form described above.
7.Why we use it, and our lawful basis
Where we are the controller, we rely on the following bases under Article 6 of the UK GDPR.
| What we do | Information used | Lawful basis |
|---|---|---|
| Provide the service to a subscribing organisation | Account, organisation and subscription records | Performance of a contract |
| Take payment and manage subscriptions | Billing identifiers and order records | Performance of a contract |
| Keep accounting and tax records | Order and payment records | Legal obligation |
| Fulfil and deliver hardware orders | Buyer email, recipient name and delivery address | Performance of a contract |
| Answer enquiries | Name, organisation, email, message | Legitimate interests, and steps taken at your request before entering a contract |
| Keep the service secure and prevent abuse | IP address, request counters, sign-in activity | Legitimate interests in protecting the service and the people whose records it holds |
| Diagnose faults and keep the service working | Technical records | Legitimate interests in providing a reliable service |
| Comply with the law and defend legal claims | Whatever is relevant | Legal obligation, and legitimate interests |
Where we rely on legitimate interests we have considered the effect on you and are satisfied that our interests do not override your rights. You can ask us for that assessment at any time.
Where we act as a processor for an employer, the lawful basis for recording attendance is the employer's to choose and to document. It is commonly the employer's legitimate interests in managing the workforce, their legal obligation to keep working time and pay records, or performance of the contract of employment.
We do not send marketing
We do not operate a mailing list, do not send marketing emails and do not pass anyone's details to third parties for marketing. The only emails the system sends are internal notifications to us when someone submits an enquiry or completes an order.
8.Health and other sensitive details
KoreKonnect is not designed to hold special category data, and no field asks for it. There is one place it could arrive by accident: the free text boxes used for a leave reason, a correction reason or a manager's note. If someone types “hospital appointment” or names a medical condition, that text becomes health information.
- We ask employers to tell staff to keep these boxes brief and factual, and not to record health, religious or other sensitive details in them.
- We treat anything that does appear in them as confidential and apply the same access controls as to every other record.
- Employers remain responsible for identifying an Article 9 condition if their own use of the service involves special category data, for example recording sickness absence.
11.International transfers
Staff records, attendance and everything else in our database are stored in Ireland (AWS eu-west-1). Ireland is in the European Economic Area, which the UK Government has formally recognised as providing an adequate level of protection for personal data. No further safeguard is needed for information to be held there, and your records do not routinely leave the EEA.
Some of our other suppliers are headquartered in the United States and may process limited personal information there, principally our hosting and email providers, and Stripe for payments. Where personal information is transferred outside the UK and the EEA we rely on one of the safeguards UK law allows: a finding of adequacy by the UK Government, the UK International Data Transfer Agreement, or the UK Addendum to the European Commission Standard Contractual Clauses, in each case supported by a transfer risk assessment.
You can ask us for a copy of the safeguard that applies to a particular supplier by writing to privacy@korekonnect.co.uk.
12.How long we keep it
We keep personal information only as long as we need it. Where we act as a processor, the customer organisation decides how long its staff records are kept and can delete them at any time.
| Records | How long |
|---|---|
| Staff accounts and attendance, shift, leave and correction records | For as long as the customer's account is open. After the account closes we keep them for 30 days so the customer can export them, then delete them. |
| A member of staff removed by their employer | Their account and personal records are deleted when the employer removes them, subject to any retention the employer is legally required to apply. |
| Billing, order and delivery records | 6 years from the end of the financial year they relate to, to meet company and tax law. |
| Enquiries | 24 months from your last contact with us, unless the enquiry becomes a customer relationship. |
| Technical records used to prevent abuse, including IP addresses | No longer than 90 days. |
| Backups | Overwritten on our providers' normal cycle. Information deleted from the live service persists in backups only until that cycle completes. |
| The public demonstration organisation | Wiped and rebuilt with fictional data every night at 03:00. |
Employers have their own retention duties
Working time records must generally be kept for two years under the Working Time Regulations 1998, and payroll records for three years under HMRC rules. Employers should set their retention to meet those duties rather than assume the service does it for them.
13.How we protect it
Attendance data says where somebody was and when, so we treat it carefully. These are the measures actually in place.
- All traffic is encrypted in transit with HTTPS, and information is encrypted at rest by our hosting and database providers.
- Passwords are hashed by our authentication provider. They are never stored in readable form and nobody at KoreKonnect can see them.
- Every table enforces row level security, so one organisation's records are inaccessible to another even if a request is malformed. Staff can read only their own attendance, leave and correction records.
- A tap cannot be forged. Each reader carries its own cryptographic key and signs every read; we verify that signature before recording anything, and comparisons are made in constant time.
- A tap cannot be replayed. Each read carries a counter that only ever increases, and a tap whose counter has already been used is rejected.
- A reader on its own can never create a record. Recording a tap also requires the member of staff's own signed-in session, so a lost or copied tag alone is not enough.
- Card and bank details never reach our systems, so they cannot be exposed by us.
- Sensitive endpoints are rate limited, and payment notifications from Stripe are cryptographically verified before we act on them.
- Access to production systems is limited to the people who need it to run the service.
No system is perfectly secure. If a breach happens that is likely to put people at risk, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it and tell affected customers without undue delay, so that they can tell their staff.
14.Your rights
Under UK data protection law you have the right to:
- Be told how your information is used, which is what this notice does.
- Ask for a copy of the information held about you.
- Have inaccurate information corrected, and incomplete information completed.
- Ask for information to be deleted, where there is no good reason for us to keep it.
- Ask us to restrict how information is used while a concern is resolved.
- Receive information you gave us in a portable, machine readable form, or have it sent to another provider.
- Object to processing based on legitimate interests, including a right to object at any time to direct marketing, which we do not carry out.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, write to privacy@korekonnect.co.uk. We will respond within one month. If a request is complex we may extend that by two further months and will tell you why. There is no charge unless a request is manifestly unfounded or excessive.
We may need to confirm who you are before we release information, so that we do not disclose one person's records to another.
If your request concerns records your employer holds in KoreKonnect, ask them first. As their processor we must normally refer the request to them rather than act on it ourselves, and we will tell you when we have done so.
15.Automated decisions
We do not make decisions about anyone by automated means alone that produce legal effects or similarly significant effects.
The service does compare taps against a working pattern and mark a day as late, absent or needing review. That is a calculation presented to a manager, not a decision. A person always reviews it, and employers must not use these flags as the sole basis for disciplinary action, pay deductions or dismissal. If you believe an automated flag has been treated as a decision, raise it with your employer, and tell us if it is not resolved.
16.Children
KoreKonnect is a workplace tool sold to organisations and is not directed at children. Where an employer records the attendance of a worker under 18, such as an apprentice, that employer is responsible for making sure the information given to that worker is clear and age appropriate. We do not knowingly collect information about anyone under 13.
17.Changes to this notice
We may update this notice as the service changes or the law does. The version number and date at the top always tell you which version you are reading. If a change materially affects how we use personal information, we will tell customer administrators by email before it takes effect.
18.Contact and complaints
If you have a question or are unhappy with how we have handled your information, please tell us first at privacy@korekonnect.co.uk. We would rather put something right than have you go elsewhere unheard.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at any time.
| Information Commissioner's Office | Details |
|---|---|
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
| Helpline | 0303 123 1113 |
| Online | ico.org.uk/make-a-complaint |
See also our terms of service, which include the data processing terms that apply between us and customer organisations.