Time tracking and data protection: what to look for in a system

If your team clocks in and out, you are collecting personal data about your employees. That is true whether the records live in a spreadsheet, on a paper sheet by the door, or in a system like ours.

Here is the part that matters and that a lot of vendor marketing gets wrong: no software makes your company compliant. Compliance is your responsibility. You decide what to collect, why, who can see it and how long to keep it. What a system can do is make those decisions easy to implement and easy to evidence — or make them nearly impossible.

This guide is about telling those two apart.

What to check before you choose a system

These are practical questions to put to any vendor, including us. They are not a legal checklist — for that you want your own advisors — but they are the questions whose answers determine how much work compliance will cost you day to day.

Where does the data live, and who else touches it? Ask for the hosting location and for the list of sub-processors. A vendor should be able to name them without hesitating, and they should appear in the contract rather than in a blog post.

Is there a Data Processing Agreement, and how do you get it? If your vendor processes personal data on your behalf, you need a written agreement with them. Ask when you get it and whether you have to chase it.

Does it collect biometric data? Fingerprint and face-recognition clock-ins bring a category of data with heavier obligations attached. The simplest way to avoid that weight is to choose a system that never collects it.

Can employees access their own data without asking anyone? People have rights over their own records. Whether exercising those rights means a self-service button or an email to HR changes how much work lands on your team.

Is every change traceable? A record that can be edited silently is worth very little as evidence. Ask whether modifications store who made them, when, and what changed.

Can you get your data out? Export matters twice: for the day-to-day, and for the day you leave. Ask what the export contains and who can trigger it.

What Kinmu actually does

Concrete answers to the questions above, limited to what the product does today.

European infrastructure. Kinmu’s application servers and database run in the European Economic Area — specifically in Frankfurt, Germany. Some functions rely on sub-processors; those are named in the Data Processing Agreement, which is the authoritative source on this, not this page.

A Data Processing Agreement from day one. The DPA is presented and accepted as part of setting up your company account, alongside the terms of service. You do not have to request it after the fact.

No biometric data. Kinmu does not collect fingerprints or facial recognition data. Clock-ins are identified by account, PIN or QR code. There is no biometric option to disable, because there is none to enable.

Employee self-service. Each person can sign in and export their own data from their own account, without going through HR.

Traceable corrections. By default employees correct their own records and a manager approves or rejects. Companies can also grant specific managers a check-in modification permission. In both cases the change is stored with author, timestamp and what was modified.

Role-based access. Managers see the records of the people in their assigned locations or units, with granular permissions per role, rather than the whole company by default.

Location only at the clock-in. If your company enables the location feature, the position is read at the moment of the clock-in to confirm the work zone — and by default what is stored is the zone, not the exact point. There is no background tracking, and no continuous location history, because the product does not have that capability.

The honest summary

A well-built system removes a lot of friction: it stops records being edited invisibly, it lets people reach their own data without an email chain, it keeps data where you expect it, and it avoids collecting things you would rather not hold. That is real value and it is worth choosing carefully.

What it does not do is transfer the responsibility. Your company remains the controller. The decisions — and the accountability for them — stay with you, and the specific rules that apply depend on your country, your sector and your circumstances, which is a conversation for your own advisors rather than for a software vendor’s blog.

We would rather say that plainly than sell you a badge.

If you want to see how the pieces above work in practice, start a free 15-day trial.

Frequently Asked Questions

Does using Kinmu make my company GDPR compliant?

No software can do that, and any vendor who says otherwise is overselling. Compliance is your company's responsibility: you decide what you collect, why, who sees it and how long you keep it. What a system can do is make those decisions easier to implement and to evidence. That is the role Kinmu is built for.

Who is the controller and who is the processor?

Your company is the data controller — it decides the purposes and means of processing. Kinmu acts as the processor, handling the data on your instructions. That split is set out in the Data Processing Agreement you accept when you set up your company account.

Where is our data stored?

Kinmu's core infrastructure runs in the European Economic Area — the application servers and database are hosted in Frankfurt, Germany. Certain functions rely on sub-processors; those are identified in the Data Processing Agreement, which is the authoritative source rather than this page.

Does Kinmu use fingerprints or facial recognition?

No. Kinmu does not collect biometric data of any kind. Clock-ins are identified by account login, PIN or QR code. If avoiding biometric processing matters to you, this is a design decision rather than a setting you have to remember to switch off.

Can employees see and export their own records?

Yes. Each person can sign in and export their own data from their account. It is a self-service function, so it does not depend on someone in HR finding the time to respond.

Who can change a time record, and is the change visible?

By default the employee corrects their own record and a manager approves or rejects it. Companies can additionally grant specific managers a check-in modification permission. Either way, every modification is stored with who made it, when, and what changed.

Is location tracked?

Only if your company enables the location feature, and only at the moment of a clock-in — to confirm it happened inside a defined work zone. There is no background or continuous location tracking in Kinmu; it is not a setting, it is absent from the product.

How long are records kept?

Retention requirements vary by country and by the type of record, so the period that applies to you is a decision for your company and its advisors. What Kinmu provides is the ability to export your data at any time and to request deletion in line with the Data Processing Agreement.

Kinmu

The app that simplifies attendance tracking

Track your team's working hours and centralize the management of vacations and absences in one easy-to-use tool that adapts to your business needs.

List of team requests in Kinmu

Clock in your way: web, app, QR, or digital kiosk

Absence approval notification in Kinmu

Manage vacations and absences from one place

Editing a clock-in with entry, exit and breaks

Always know where everyone is. No questions asked

Kinmu AI suggestion to approve a request

Your records, always available whenever you need them

Try it free for 15 days

No credit card required