Legal

Privacy policy

KoreKonnect records the moment a signed-in member of staff taps a registered KonnectReader, and nothing more. No location, no biometrics, no background monitoring. This notice explains exactly what we hold, why we hold it, who else sees it and what you can ask us to do about it.

Last updated
8 August 2026
Version
1.0
Applies to
korekonnect.co.uk

The short version

We hold the name, work email and attendance record of staff at organisations that use KoreKonnect. We do not track anyone's location, we do not use biometrics, and we never see or store card or bank details. We do not sell data, run advertising, or use analytics or tracking cookies. If your employer uses KoreKonnect, they decide what is recorded about you and you should speak to them first; we will help them respond.

1.Who we are

KoreKonnect is a workforce attendance service operated by Kore Digital Ltd (“we”, “us”), a company registered in England and Wales under company number 17202130, with its registered office at 82 James Carter Road, Suite A, Mildenhall, Suffolk, IP28 7DE, United Kingdom.

How to contact us about privacy
PurposeContact
Privacy and data protectionprivacy@korekonnect.co.uk
General enquirieshello@korekonnect.co.uk
Person accountable for data protectionMuhammad Rehmani
By phoneNaeem Kothdiwala, +44 7533 331973Muhammad Rehmani, +44 7775 277891

We are not required to appoint a statutory Data Protection Officer under Article 37 of the UK GDPR. Responsibility for data protection sits with Muhammad Rehmani, who can be reached at the address above.

2.Who this notice is for

This notice covers four groups of people.

  • Visitors to our website at korekonnect.co.uk, including anyone who sends us an enquiry.
  • Customer administrators and billing contacts at organisations that subscribe to KoreKonnect.
  • Members of staff at those organisations, whose attendance, shifts and leave are recorded in the service.
  • People who buy KonnectReaders from our shop.

If your employer uses KoreKonnect

Your employer decides what is recorded about you and why. They are legally responsible for that decision, and they should have told you separately that they use this system. If you want to see your records, correct them or object to them, ask your employer first. If they do not respond, you can contact us at privacy@korekonnect.co.uk and we will do what we can to help, though we usually have to act on your employer's instructions.

3.Controller or processor

Data protection law distinguishes between the organisation that decides why personal information is used (the controller) and the organisation that acts on its instructions (the processor). We are both, depending on the information.

Our role for each category of information
InformationOur roleController
Website visits and enquiriesControllerKore Digital Ltd
Customer accounts, subscriptions and billingControllerKore Digital Ltd
KonnectReader orders and deliveryControllerKore Digital Ltd
Staff records, attendance, shifts, leave and correctionsProcessorThe customer organisation (the employer)

Where we act as a processor, we only use the information to run the service for that customer and to meet our own legal obligations. We do not use it for our own purposes, we do not sell it, and we do not use it to train models. The processing terms we agree with customers are set out in Annex A of our terms of service.

4.What we collect

This is the complete list. If a field is not named here, the system does not store it.

Staff and account records

  • Full name.
  • Work email address. Where a member of staff has no work email, employers may assign a placeholder address that does not receive mail.
  • A password, stored only as a cryptographic hash by our authentication provider. Nobody at KoreKonnect can see or recover it.
  • Role in the system, for example employee, team manager or department lead.
  • Optional staff or payroll reference set by the employer.
  • Team, department and the sites the person is assigned to.
  • Annual leave entitlement in days, and whether the account is active.

Attendance

  • The date and time of each tap, and whether it was a sign in or a sign out.
  • The name of the door or reader that was tapped, and the site it belongs to.
  • The chip identifier of the reader and its internal read counter, which together prevent a tap being copied or replayed.
  • Whether the record came from a tap or was entered manually by a manager, and which manager entered it.
  • Any note a manager adds to a record.

Working time, leave and corrections

  • Contracted working pattern: day of the week, start and end times, and whether it is a working day.
  • Published shifts and who is assigned to them, including break minutes.
  • Leave requests: type, start and end dates, number of days, the reason given, the decision, who decided it and any comment they added.
  • Leave balances: days allocated and days used for each year.
  • Correction requests: the date, time and direction being corrected, the reason given, the outcome and any decision comment.

Customer, billing and order records

  • Organisation name, time zone, subscription status and trial end date.
  • Identifiers issued by Stripe for the customer and subscription, so we can match a payment to an account.
  • For hardware orders: the buyer's email address, the delivery recipient's name and address, the order reference from Stripe, and what was ordered.

Enquiries

  • Your name, organisation if you give one, email address and the message you send us. Enquiries arrive as email; they are not stored in the product database.

Technical information

  • Your IP address, recorded briefly against a counter when you submit an enquiry, start a checkout or complete signup. We use it only to stop the same source flooding those endpoints.
  • Our hosting and database providers also see the IP address and basic request details of everyone who uses the service, as any web host does.

5.What we never collect

These are deliberate design decisions, not omissions. The product has no way to gather any of the following.

  • No biometric data. No fingerprints, facial recognition, iris or voice. We never process the special category data that biometric clocking systems rely on.
  • No location tracking. No GPS, no geofencing, no Wi-Fi or Bluetooth positioning. We know which door was tapped because the reader is fixed to it, and nothing else about where anyone is.
  • No background or continuous monitoring. Nothing is recorded between taps. There is no always-on app, no screen monitoring, no keystroke logging and no productivity scoring.
  • No card or bank details. Payments are taken on Stripe's own hosted pages. Card numbers, security codes and bank details never reach our servers and are never stored by us in any form, not even the last four digits.
  • No sensitive personnel data. No date of birth, home address, national insurance number, salary or pay rate, photograph, or right to work documents.
  • No tracking, advertising or analytics. We run no analytics package, no advertising pixels, no session recording and no third party trackers of any kind. Our web fonts are served from our own domain, so your browser does not contact a font provider.

6.Where it comes from

  • From the customer organisation, when an administrator creates staff accounts and sets working patterns, teams and leave entitlements.
  • From the individual, each time they tap in or out, request leave or ask for a correction.
  • From Stripe, when a subscription or hardware order completes, including the delivery address the buyer typed into Stripe's checkout.
  • Automatically, in the limited technical form described above.

7.Why we use it, and our lawful basis

Where we are the controller, we rely on the following bases under Article 6 of the UK GDPR.

Purposes and lawful bases
What we doInformation usedLawful basis
Provide the service to a subscribing organisationAccount, organisation and subscription recordsPerformance of a contract
Take payment and manage subscriptionsBilling identifiers and order recordsPerformance of a contract
Keep accounting and tax recordsOrder and payment recordsLegal obligation
Fulfil and deliver hardware ordersBuyer email, recipient name and delivery addressPerformance of a contract
Answer enquiriesName, organisation, email, messageLegitimate interests, and steps taken at your request before entering a contract
Keep the service secure and prevent abuseIP address, request counters, sign-in activityLegitimate interests in protecting the service and the people whose records it holds
Diagnose faults and keep the service workingTechnical recordsLegitimate interests in providing a reliable service
Comply with the law and defend legal claimsWhatever is relevantLegal obligation, and legitimate interests

Where we rely on legitimate interests we have considered the effect on you and are satisfied that our interests do not override your rights. You can ask us for that assessment at any time.

Where we act as a processor for an employer, the lawful basis for recording attendance is the employer's to choose and to document. It is commonly the employer's legitimate interests in managing the workforce, their legal obligation to keep working time and pay records, or performance of the contract of employment.

We do not send marketing

We do not operate a mailing list, do not send marketing emails and do not pass anyone's details to third parties for marketing. The only emails the system sends are internal notifications to us when someone submits an enquiry or completes an order.

8.Health and other sensitive details

KoreKonnect is not designed to hold special category data, and no field asks for it. There is one place it could arrive by accident: the free text boxes used for a leave reason, a correction reason or a manager's note. If someone types “hospital appointment” or names a medical condition, that text becomes health information.

  • We ask employers to tell staff to keep these boxes brief and factual, and not to record health, religious or other sensitive details in them.
  • We treat anything that does appear in them as confidential and apply the same access controls as to every other record.
  • Employers remain responsible for identifying an Article 9 condition if their own use of the service involves special category data, for example recording sickness absence.

9.Cookies and local storage

We use a small number of cookies, all of which are strictly necessary to deliver a service you have asked for. Because of that, UK cookie rules do not require a consent banner and we do not show one. We set no advertising, analytics or tracking cookies.

Cookies and browser storage
NamePurposeType and duration
kk_tapCarries the encrypted reader message from the moment you tap to the moment you confirm, because installed apps drop the web address it arrives in. Cleared as soon as the tap is recorded.Cookie, 3 minutes, not readable by scripts
kk_tap_pendingTells the installed app that a tap is waiting to be confirmed, so it can take you to the right screen.Cookie, 3 minutes
sb-…-auth-tokenKeeps you signed in. Set by our authentication provider and may be split across several numbered cookies. Removed when you sign out.Cookie, up to 400 days unless you sign out
kk_install_dismissedRemembers that you closed the prompt to install the app, so it does not reappear.Local storage, until you clear it
kk-hardware-basket-v1Holds your shop basket while you browse.Session storage, cleared when the tab closes
kk-launch-promo-home-dismissedRemembers that you closed the launch offer notice.Session storage, cleared when the tab closes

You can block or delete cookies in your browser settings. Blocking the two tap cookies or the sign-in cookie will stop the service working, because there is no other way to keep you signed in or to complete a tap.

10.Who we share it with

We do not sell personal information and we do not share it for advertising. We use a small number of suppliers to run the service. Each acts on our instructions under a written contract, except Stripe, which is also a controller in its own right for payment, fraud prevention and financial regulation.

Our sub-processors
SupplierWhat they doWhat they handleWhere
SupabaseDatabase and sign-inAll service records: staff accounts, attendance, shifts, leave and ordersData stored in Ireland. Supplier headquartered in the United States.
VercelWebsite and application hostingRequests to the service, including IP addressesUnited States, with a global edge network
StripePayments, subscriptions and checkoutPayment details you enter directly with Stripe, buyer email, delivery addressIreland and the United States
ResendSends our notification emailsThe contents of enquiry and order notificationsUnited States

We may also share information:

  • With the customer organisation whose records they are, which is the point of the service.
  • With our professional advisers, such as accountants and lawyers, where they need it and are bound by confidentiality.
  • Where the law requires it, or to establish, exercise or defend legal claims.
  • With a buyer or successor if the business is sold or reorganised, subject to the protections in this notice.

We keep the list of suppliers above current. Customers are told before we add a new one that handles their staff records, as set out in Annex A of the terms.

11.International transfers

Staff records, attendance and everything else in our database are stored in Ireland (AWS eu-west-1). Ireland is in the European Economic Area, which the UK Government has formally recognised as providing an adequate level of protection for personal data. No further safeguard is needed for information to be held there, and your records do not routinely leave the EEA.

Some of our other suppliers are headquartered in the United States and may process limited personal information there, principally our hosting and email providers, and Stripe for payments. Where personal information is transferred outside the UK and the EEA we rely on one of the safeguards UK law allows: a finding of adequacy by the UK Government, the UK International Data Transfer Agreement, or the UK Addendum to the European Commission Standard Contractual Clauses, in each case supported by a transfer risk assessment.

You can ask us for a copy of the safeguard that applies to a particular supplier by writing to privacy@korekonnect.co.uk.

12.How long we keep it

We keep personal information only as long as we need it. Where we act as a processor, the customer organisation decides how long its staff records are kept and can delete them at any time.

Retention periods
RecordsHow long
Staff accounts and attendance, shift, leave and correction recordsFor as long as the customer's account is open. After the account closes we keep them for 30 days so the customer can export them, then delete them.
A member of staff removed by their employerTheir account and personal records are deleted when the employer removes them, subject to any retention the employer is legally required to apply.
Billing, order and delivery records6 years from the end of the financial year they relate to, to meet company and tax law.
Enquiries24 months from your last contact with us, unless the enquiry becomes a customer relationship.
Technical records used to prevent abuse, including IP addressesNo longer than 90 days.
BackupsOverwritten on our providers' normal cycle. Information deleted from the live service persists in backups only until that cycle completes.
The public demonstration organisationWiped and rebuilt with fictional data every night at 03:00.

Employers have their own retention duties

Working time records must generally be kept for two years under the Working Time Regulations 1998, and payroll records for three years under HMRC rules. Employers should set their retention to meet those duties rather than assume the service does it for them.

13.How we protect it

Attendance data says where somebody was and when, so we treat it carefully. These are the measures actually in place.

  • All traffic is encrypted in transit with HTTPS, and information is encrypted at rest by our hosting and database providers.
  • Passwords are hashed by our authentication provider. They are never stored in readable form and nobody at KoreKonnect can see them.
  • Every table enforces row level security, so one organisation's records are inaccessible to another even if a request is malformed. Staff can read only their own attendance, leave and correction records.
  • A tap cannot be forged. Each reader carries its own cryptographic key and signs every read; we verify that signature before recording anything, and comparisons are made in constant time.
  • A tap cannot be replayed. Each read carries a counter that only ever increases, and a tap whose counter has already been used is rejected.
  • A reader on its own can never create a record. Recording a tap also requires the member of staff's own signed-in session, so a lost or copied tag alone is not enough.
  • Card and bank details never reach our systems, so they cannot be exposed by us.
  • Sensitive endpoints are rate limited, and payment notifications from Stripe are cryptographically verified before we act on them.
  • Access to production systems is limited to the people who need it to run the service.

No system is perfectly secure. If a breach happens that is likely to put people at risk, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it and tell affected customers without undue delay, so that they can tell their staff.

14.Your rights

Under UK data protection law you have the right to:

  • Be told how your information is used, which is what this notice does.
  • Ask for a copy of the information held about you.
  • Have inaccurate information corrected, and incomplete information completed.
  • Ask for information to be deleted, where there is no good reason for us to keep it.
  • Ask us to restrict how information is used while a concern is resolved.
  • Receive information you gave us in a portable, machine readable form, or have it sent to another provider.
  • Object to processing based on legitimate interests, including a right to object at any time to direct marketing, which we do not carry out.
  • Withdraw consent at any time, where we rely on consent.
14.1

To exercise any of these, write to privacy@korekonnect.co.uk. We will respond within one month. If a request is complex we may extend that by two further months and will tell you why. There is no charge unless a request is manifestly unfounded or excessive.

14.2

We may need to confirm who you are before we release information, so that we do not disclose one person's records to another.

14.3

If your request concerns records your employer holds in KoreKonnect, ask them first. As their processor we must normally refer the request to them rather than act on it ourselves, and we will tell you when we have done so.

15.Automated decisions

We do not make decisions about anyone by automated means alone that produce legal effects or similarly significant effects.

The service does compare taps against a working pattern and mark a day as late, absent or needing review. That is a calculation presented to a manager, not a decision. A person always reviews it, and employers must not use these flags as the sole basis for disciplinary action, pay deductions or dismissal. If you believe an automated flag has been treated as a decision, raise it with your employer, and tell us if it is not resolved.

16.Children

KoreKonnect is a workplace tool sold to organisations and is not directed at children. Where an employer records the attendance of a worker under 18, such as an apprentice, that employer is responsible for making sure the information given to that worker is clear and age appropriate. We do not knowingly collect information about anyone under 13.

17.Changes to this notice

We may update this notice as the service changes or the law does. The version number and date at the top always tell you which version you are reading. If a change materially affects how we use personal information, we will tell customer administrators by email before it takes effect.

18.Contact and complaints

If you have a question or are unhappy with how we have handled your information, please tell us first at privacy@korekonnect.co.uk. We would rather put something right than have you go elsewhere unheard.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at any time.

Information Commissioner's Office contact details
Information Commissioner's OfficeDetails
AddressWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline0303 123 1113
Onlineico.org.uk/make-a-complaint

See also our terms of service, which include the data processing terms that apply between us and customer organisations.