NoahFace Privacy Policy

This is the Privacy Policy for Noah Facial Recognition Pty Ltd (NoahFace), and Auckland Time Systems Ltd (TimeLab).

Noah Facial Recognition Pty hosts and supplies NoahFace as a service. TimeLab is a NoahFace Partner (“Partner”). TimeLab is the New Zealand reseller and support provider for the NoahFace service.

This Privacy Policy was last updated: 6th July 2022 and is effective from 6th July 2022.

This Privacy Policy details:

  • What information we collect.
  • How we use information.
  • How we protect information
  • When we destroy information.
  • How we comply with local legislation.
  • How we update this privacy policy.
  • How to contact NoahFace regarding privacy.
  • How to contact Government regarding privacy.

This Privacy Policy refers to:

  • The NoahFace public Web site (noahface.com)
  • The NoahFace Platform, which runs in the Cloud and can be accessed using a Web Browser.
  • The NoahFace App, which runs on permanently mounted iPads.
  • The NoahFace Go App, which runs in iPhone and Android mobile phones.

Collectively these are referred to as the "NoahFace Service".

1. What Information we Collect

Business Information

We collect information about organisations that use the NoahFace Service ("Customers"). This includes information such as the organisation's:

  • Name
  • Location
  • Industry
  • Size
  • Contact details (eg: Primary Contact, Email, Phone, etc.).
  • Technology (eg: Payroll Platform, Access Control Platform).

Collecting this information is essential to us doing business.

Customer Information

The NoahFace Platform allows Partners to manage their Customers, and to allow Partners and Customers to manage how each Customer uses the NoahFace Service. This includes information such as the Customer's:

  • Sites.
  • Devices.
  • Access Rules.
  • Subscriptions.

Collecting this information is essential to the operation of the NoahFace Service and to Partners and Customers doing business.

User Information

The NoahFace Platform allows Customers to manage information about their employees/members/students/customers/etc ("Users"). This includes information such as the User's:

  • Unique identifier (eg: employee number, member number, student number, etc).
  • Name
  • Contact details (ie: email and mobile phone number).

The NoahFace App allows each User to register - a process which allows Users to submit their:

  • Profile picture
  • Biometric data (ie: key facial features)

The NoahFace Go App allows users to submit their:

  • Profile picture.

Collecting this information is essential to the operation of the NoahFace Apps and to Customers doing business.

Biometric Information

The NoahFace Service uses facial recognition technology. With the consent of Users, whenever they use the NoahFace App their photo is taken and their biometric information (ie: their unique facial characteristics) is extracted. The use of facial recognition allows Users to be automatically identified on subsequent uses. The NoahFace Service provides important capabilities to support the responsible collection and use of biometric information, including:

  • Requiring Users to acknowledge a simple privacy statement and to actively consent to the capture of biometric data.
  • Allowing non-consenters to use an alternative means of identification, such as passcodes.
  • Allowing Users to remove their consent at any time, at which time biometric data is destroyed.

Collecting this information is essential to the operation of the NoahFace App.

Usage Information

The NoahFace Platform allows Customers to collect information about each activity (or event) performed using the NoahFace Apps. This includes information such as:

  • The date and time.
  • The identifier of the User.
  • The type of activity (eg: clock in, access, start job, etc.)
  • Details of the activity (eg: an entered job number or selected task type).

The NoahFace App also allows Customers to collect:

  • The User's photo.
  • The User's temperature (if an optional temperature sensor is deployed).

The NoahFace Go App also allows Customers to collect:

  • The User's location (this requires the User's explicit consent).

Collecting this information is essential to the operation of the NoahFace Apps and to Customers doing business (eg: so you can pay staff for the hours they work).

2. How we Use Information

Business Information

We collect information on organisations that use or may use the NoahFace Service so we can keep them informed about relevant and important changes. For example, this allows us to notify organisations of updates to:

  • The NoahFace Service.
  • Pricing.
  • This Privacy Policy

We may also contact organisations regarding other related products or services offered by us. If we do contact you, we will provide a mechanism for you to opt out of receiving future communications.

NoahFace does not share or sell your business information, including your contact details. TimeLab also does not share or sell your business information, including your contact details.

Customer Information

The NoahFace Platform allows Partners to manage their Customers, and to allows Partners and Customers to manage how each Customer uses the NoahFace Service. For example, you can configure:

  • The list of sites and devices.
  • The behaviour of each device when a User interacts with it.

NoahFace does not use your customer information for its own purposes, nor do they share it with or sell it to others. TimeLab also does not use your customer information for our own purposes, nor do we share it with or sell it to others.

User Information

The NoahFace Platform allows Customers to manage information on Users so that you can control which Users can make use of the NoahFace Apps, and how they can use it. For example, to control which employees:

  • Need to record their time and attendance.

NoahFace does not use your user information for it's own purposes, nor do they share it with or sell it to others. TimeLab also does not use your user information for its own purposes, nor do we share it with or sell it to others.

Biometric Information

The biometric information collected by the NoahFace App allows Users to be recognised automatically.

NoahFace does not use your biometric information for our own purposes, nor do we share it with or sell it to others.

TimeLab does not use your biometric information for our own purposes, nor do we share it with or sell it to others.

Usage Information

The NoahFace Apps allow Customers to collect information about each activity (or event). If you use the NoahFace Apps stand-alone, the usage information is only retained on your device. If you choose to connect the NoahFace Apps to the NoahFace Platform, then this information is retained in the NoahFace Platform so that you can perform queries and reports on it.

Customers can configure the NoahFace Platform to send a subset of the usage information to 3rd party systems. For example to:

  • A Payroll System, to automatically populate timesheets, so that employees can be paid.

NoahFace does not use usage information for its own purposes, nor do they share it with or sell it to others. TimeLab does not use usage information for our own purposes, nor do we share it with or sell it to others.

3. How we Protect Information

Business Information

Information on businesses that use or may use the NoahFace Service is stored in our IT systems. We take responsible measures to protect this information. For example:

  • Access to business information is limited to authorised employees.
  • Access to business information is password protected.
  • Business information is backed up.

Customer Information

Information on the Customers that use the NoahFace Service may be stored in the NoahFace Platform. We take responsible measures to protect this information. For example:

  • Access to customer information is limited to authorised employees.
  • Access to customer information is password protected.
  • Customer information is backed up.
  • Customer information is encrypted both in transit and at rest.

User Information

Information on the Users of the NoahFace Apps may be stored in the NoahFace Platform. We take responsible measures to protect this information. For example:

  • Access to user information is limited to authorised employees.
  • Access to user information is password protected.
  • User information is backed up.
  • User information is encrypted both in transit and at rest.

Biometric Information

Biometric information is a special form of information for which additional privacy protections are offered. We take responsible measures to protect this information. For example:

  • Biometric Information is NOT viewable.
  • Biometric Information is NOT exportable.
  • Biometric information is backed up.
  • Biometric information is encrypted both in transit and at rest.

Usage Information

Information on the usage of the NoahFace Apps may be stored in the NoahFace Platform. We take responsible measures to protect this information. For example:

  • Access to usage information is limited to authorised employees.
  • Access to usage information is password protected.
  • Usage information is backed up.
  • Usage information is encrypted both in transit and at rest.

4. When we Destroy Information

NoahFace actively destroys information after its useful purpose has passed.

Customer Information

Customer information is destroyed when a Customer leaves the NoahFace Service. At this time, all associated User, Biometric, and Usage information for that Customer is also destroyed.

User Information

User information is automatically destroyed a Customer configurable retention period after a User is removed from the NoahFace Service (eg: when the employer / employee relationship is terminated). This retention period is 90 days by default.

Biometric Information

When a User is removed from the NoahFace Service (eg: when the employer / employee relationship is terminated), Customers can configure whether the associated biometric information is either destroyed immediately or when the user information is destroyed (ie: after the configured retention period).

Biometric information is also destroyed immediately that a User removes their consent to the use of their biometrics. In this case, the User can continue to use the NoahFace App by manually identifying themselves using non-biometric methods (eg: passcodes).

Usage Information

Usage information is automatically destroyed after a Customer configurable retention period. This retention period is 90 days by default.

5. How we Comply with Local Legislation

We respect your right to privacy and are committed to safeguarding the privacy of our customers and users. We adhere to all Information Privacy Principles contained in the New Zealand Privacy Act 2020.

Using a provider such as NoahFace that has a strong commitment to privacy does not absolve your legal obligations around privacy. You should seek your own professional legal opinion on privacy legislation prior to implementing any new process that involves the collection, storage, and processing of information, and prior to using the NoahFace service.

The pages below explain how NoahFace complies with, and/or helps you comply with, specific local legislation:

6. Changes to this Policy

We reserve the right, at our sole discretion, to modify or replace these Terms at any time. If a revision is material we will try to provide at least 30 days' notice prior to any new terms taking effect. What constitutes a material change will be determined at our sole discretion.

This version was last updated on 6th July 2022 and is effective from 6th July 2022.

Contact Us

Should you have any concerns about your privacy or have any questions about this privacy policy, you can contact us at:

noahface@timelab.co.nz

Your local Time and Attendance specialists. Because timing is everything.
Proudly New Zealand owned, operated and supported.
© 2023 TimeLab. All rights reserved.