If your team clocks in and out, you are collecting personal data about your employees. That is true whether the records live in a spreadsheet, on a paper sheet by the door, or in a system like ours.
Here is the part that matters and that a lot of vendor marketing gets wrong: no software makes your company compliant. Compliance is your responsibility. You decide what to collect, why, who can see it and how long to keep it. What a system can do is make those decisions easy to implement and easy to evidence — or make them nearly impossible.
This guide is about telling those two apart.
What to check before you choose a system
These are practical questions to put to any vendor, including us. They are not a legal checklist — for that you want your own advisors — but they are the questions whose answers determine how much work compliance will cost you day to day.
Where does the data live, and who else touches it? Ask for the hosting location and for the list of sub-processors. A vendor should be able to name them without hesitating, and they should appear in the contract rather than in a blog post.
Is there a Data Processing Agreement, and how do you get it? If your vendor processes personal data on your behalf, you need a written agreement with them. Ask when you get it and whether you have to chase it.
Does it collect biometric data? Fingerprint and face-recognition clock-ins bring a category of data with heavier obligations attached. The simplest way to avoid that weight is to choose a system that never collects it.
Can employees access their own data without asking anyone? People have rights over their own records. Whether exercising those rights means a self-service button or an email to HR changes how much work lands on your team.
Is every change traceable? A record that can be edited silently is worth very little as evidence. Ask whether modifications store who made them, when, and what changed.
Can you get your data out? Export matters twice: for the day-to-day, and for the day you leave. Ask what the export contains and who can trigger it.
What Kinmu actually does
Concrete answers to the questions above, limited to what the product does today.
European infrastructure. Kinmu’s application servers and database run in the European Economic Area — specifically in Frankfurt, Germany. Some functions rely on sub-processors; those are named in the Data Processing Agreement, which is the authoritative source on this, not this page.
A Data Processing Agreement from day one. The DPA is presented and accepted as part of setting up your company account, alongside the terms of service. You do not have to request it after the fact.
No biometric data. Kinmu does not collect fingerprints or facial recognition data. Clock-ins are identified by account, PIN or QR code. There is no biometric option to disable, because there is none to enable.
Employee self-service. Each person can sign in and export their own data from their own account, without going through HR.
Traceable corrections. By default employees correct their own records and a manager approves or rejects. Companies can also grant specific managers a check-in modification permission. In both cases the change is stored with author, timestamp and what was modified.
Role-based access. Managers see the records of the people in their assigned locations or units, with granular permissions per role, rather than the whole company by default.
Location only at the clock-in. If your company enables the location feature, the position is read at the moment of the clock-in to confirm the work zone — and by default what is stored is the zone, not the exact point. There is no background tracking, and no continuous location history, because the product does not have that capability.
The honest summary
A well-built system removes a lot of friction: it stops records being edited invisibly, it lets people reach their own data without an email chain, it keeps data where you expect it, and it avoids collecting things you would rather not hold. That is real value and it is worth choosing carefully.
What it does not do is transfer the responsibility. Your company remains the controller. The decisions — and the accountability for them — stay with you, and the specific rules that apply depend on your country, your sector and your circumstances, which is a conversation for your own advisors rather than for a software vendor’s blog.
We would rather say that plainly than sell you a badge.
If you want to see how the pieces above work in practice, start a free 15-day trial.