CGGC Site AttendancePrivacy policy

PRIVACY & DATA USE

Privacy Policy

This policy explains how CGGC Site Attendance handles employee, device, attendance, equipment-report, and location data.

Effective: 23 August 2026 Package: com.siteattendance.app No advertising or background location

ENGLISH

How your information is handled

1. Who operates the service

CGGC Site Attendance is an internal workforce system operated by Liang Ye (the “Operator”) for the CGGC Kuwait project. The Operator determines why attendance information is processed and which authorized administrators may access it. Public privacy and support contact: y172198402@gmail.com.

2. Information we process

  • Employee and work profile: employee code, name, department, team, job title, role, and assigned shift supplied by the Operator or authorized project administrator.
  • Precise foreground location: latitude, longitude, accuracy, matched work zone, and location time when you actively clock in, clock out, locate yourself on the work-zone map, or submit a location-enabled equipment report.
  • Attendance and report details: clock type, trusted server time, attendance date, upload status, equipment number, report type, and any note you choose to enter.
  • Device and security information: an app-specific identifier derived from the Android device ID, activation and device-binding status, app version, integrity verdicts, indicators of location manipulation, and whether a known mock-location application is detected. The app records the detection result, not a general list of your installed apps.
  • Service logs: request time, network address, authentication, replay-prevention, rate-limit, synchronization, and administrative audit events needed to operate and protect the service.

3. When location is used

Location is requested only after you choose a feature that needs it and after an in-app disclosure. The app does not request background location permission and does not collect location while running in the background. Precise location is required to validate that an attendance event occurred inside an approved polygonal work zone and to help prevent fraudulent clocking.

4. Why we use the information

We process the information to activate and bind an assigned phone, authenticate requests, show and synchronize shift information, validate and record attendance, display your work-zone position, manage equipment fault and repair reports, detect replay or location manipulation, investigate exceptions, support users, and maintain an auditable employment record.

5. Sharing and service providers

Information is available only to project administrators authorized by the Operator within their assigned permission scope and to infrastructure providers acting for the Operator. The service uses Google Cloud hosting and Google Play services. Play Integrity sends app, device, and account-related signals to Google so that Google can return an integrity verdict. We do not sell personal data and do not use it for advertising or third-party marketing. There are no advertising, analytics, or third-party crash-reporting SDKs in the Android app.

6. Storage, offline use, and security

Pending attendance and report events are protected by Android application storage on the assigned phone until synchronization. Pending attendance remains available for retry while it is within the approved 24-hour offline window; expired local location-bearing events are removed no later than 90 days. Android cloud backup is disabled. Server data is protected with HTTPS, device binding, HMAC signatures, nonce replay prevention, trusted server time, access controls, and audit logging. No system can guarantee absolute security.

7. Retention

The active system applies the following retention schedule:

  • Employee profile: while the account is active and for two years after it is disabled, then deleted or anonymized.
  • Attendance records: five years from creation, then deleted or anonymized.
  • Device and security records: two years, then automatically deleted; device credentials and tokens are invalidated immediately after unbinding, disabling, or revocation.
  • Administrative audit logs: two years, then automatically deleted.
  • Precise GPS latitude and longitude: 90 days, then deleted. Work zone, location-validation result, accuracy, integrity and attendance-validity results remain with the attendance record for five years.

Deletion may be suspended when required by law, an employment dispute, a security incident, an audit investigation, or fraud prevention, and resumes when that matter ends. Deleted active data may remain in access-controlled backups until their scheduled expiry; current backup retention is up to 14 days in testing and 30 days in production.

8. Access, correction, and deletion requests

Email y172198402@gmail.com or contact the CGGC Kuwait project HR/Site Administration Office to request access, correction, deactivation, or deletion where applicable. Some records may remain subject to the legal-hold exceptions above. The Operator will assess each request under applicable law and policy.

9. Children, changes, and contact

This internal workforce service is not directed to children. We may update this policy when the app, infrastructure, or legal requirements change; the effective date above will be revised. Privacy questions should be sent to y172198402@gmail.com.

العربية

كيفية التعامل مع معلوماتك

1. الجهة المشغلة للخدمة

تطبيق حضور مواقع CGGC هو نظام داخلي للقوى العاملة تديره Liang Ye («المشغّل») لمشروع CGGC في الكويت. يحدد المشغّل أغراض معالجة بيانات الحضور والمسؤولين المصرح لهم بالوصول إليها. جهة التواصل العامة للخصوصية والدعم: y172198402@gmail.com.

2. المعلومات التي نعالجها

  • ملف الموظف والعمل: رقم الموظف والاسم والإدارة والفريق والمسمى الوظيفي والدور والوردية، كما يزودنا بها المشغّل أو مسؤول المشروع المصرح له.
  • الموقع الدقيق أثناء استخدام التطبيق: خط العرض وخط الطول والدقة ومنطقة العمل المطابقة ووقت الموقع عند اختيار تسجيل الحضور أو الانصراف أو تحديد موقعك على خريطة المناطق أو إرسال تقرير معدات يتضمن الموقع.
  • بيانات الحضور والتقارير: نوع الحركة ووقت الخادم الموثوق وتاريخ الحضور وحالة الرفع ورقم المعدة ونوع التقرير وأي ملاحظة تختار إدخالها.
  • بيانات الجهاز والأمان: معرف خاص بالتطبيق مشتق من معرف جهاز Android، وحالة التفعيل وربط الجهاز، وإصدار التطبيق، ونتائج سلامة الجهاز، ومؤشرات التلاعب بالموقع، وما إذا تم اكتشاف تطبيق معروف للموقع الوهمي. يسجل التطبيق نتيجة الاكتشاف ولا يجمع قائمة عامة بالتطبيقات المثبتة.
  • سجلات الخدمة: وقت الطلب وعنوان الشبكة والمصادقة ومنع إعادة الإرسال وحدود الطلبات والمزامنة وسجل إجراءات الإدارة اللازمة لتشغيل الخدمة وحمايتها.

3. متى يُستخدم الموقع

يُطلب الموقع فقط بعد اختيارك ميزة تحتاج إليه وبعد ظهور إفصاح داخل التطبيق. لا يطلب التطبيق إذن الموقع في الخلفية ولا يجمع الموقع أثناء عمله في الخلفية. الموقع الدقيق مطلوب للتحقق من وقوع حركة الحضور داخل منطقة عمل متعددة الأضلاع معتمدة وللمساعدة في منع التسجيل الاحتيالي.

4. أسباب استخدام المعلومات

نستخدم المعلومات لتفعيل الهاتف المخصص وربطه، ومصادقة الطلبات، وعرض معلومات الوردية ومزامنتها، والتحقق من الحضور وتسجيله، وعرض موقعك في منطقة العمل، وإدارة بلاغات أعطال المعدات وإتمام الإصلاح، وكشف إعادة الإرسال أو التلاعب بالموقع، والتحقيق في الحالات الاستثنائية، ودعم المستخدمين، والاحتفاظ بسجل وظيفي قابل للتدقيق.

5. المشاركة ومقدمو الخدمة

تتاح المعلومات فقط لمسؤولي الجهة المصرح لهم ضمن نطاق صلاحياتهم ولمقدمي البنية التحتية العاملين لصالح الجهة. تستخدم الخدمة استضافة Google Cloud وخدمات Google Play. ترسل Play Integrity إشارات متعلقة بالتطبيق والجهاز والحساب إلى Google لإرجاع نتيجة السلامة. لا نبيع البيانات الشخصية ولا نستخدمها للإعلانات أو التسويق الخارجي. ولا يحتوي تطبيق Android على حزم إعلانية أو تحليلات أو تقارير أعطال خارجية.

6. التخزين والعمل دون اتصال والأمان

تبقى حركات الحضور والتقارير المعلقة داخل مساحة تطبيق Android المحمية حتى المزامنة. تبقى حركة الحضور قابلة لإعادة المحاولة خلال نافذة العمل دون اتصال المعتمدة ومدتها 24 ساعة، وتُحذف الأحداث المحلية التي تتضمن الموقع عند انتهاء مدة أقصاها 90 يوماً. النسخ الاحتياطي السحابي لنظام Android معطل، وتُحمى بيانات الخادم بواسطة HTTPS وربط الجهاز وتوقيعات HMAC ومنع إعادة استخدام Nonce ووقت الخادم الموثوق والتحكم بالصلاحيات وسجل التدقيق. لا يمكن لأي نظام ضمان الأمان بصورة مطلقة.

7. مدة الاحتفاظ

يطبق النظام النشط مدد الاحتفاظ التالية:

  • ملف الموظف: طوال مدة تفعيل الحساب ولسنتين بعد تعطيله، ثم يُحذف أو تُزال هويته.
  • سجلات الحضور: خمس سنوات من تاريخ إنشائها، ثم تُحذف أو تُزال هويتها.
  • سجلات الجهاز والأمان: سنتان ثم تُحذف تلقائياً؛ وتُبطل بيانات اعتماد الجهاز والرموز فور فك الربط أو التعطيل أو الإلغاء.
  • سجلات تدقيق الإدارة: سنتان ثم تُحذف تلقائياً.
  • إحداثيات GPS الدقيقة: 90 يوماً ثم يُحذف خط العرض وخط الطول. وتبقى منطقة العمل ونتيجة التحقق من الموقع والدقة والسلامة وصحة الحضور مع سجل الحضور لمدة خمس سنوات.

يجوز تعليق الحذف عند الحاجة للوفاء بالتزام قانوني أو نزاع عمالي أو حادث أمني أو تحقيق تدقيق أو منع الاحتيال، ويستأنف بعد انتهاء السبب. وقد تبقى البيانات المحذوفة من النظام النشط في النسخ الاحتياطية المحمية حتى انتهاء مدتها؛ وهي حالياً حتى 14 يوماً في الاختبار و30 يوماً في الإنتاج.

8. طلبات الوصول والتصحيح والحذف

راسل y172198402@gmail.com أو تواصل مع الموارد البشرية/إدارة الموقع لمشروع CGGC في الكويت لطلب الوصول أو التصحيح أو التعطيل أو الحذف حيث ينطبق. قد تخضع بعض السجلات لاستثناءات الحفظ القانوني أعلاه، ويقيّم المشغّل كل طلب وفق القانون والسياسة المعمول بهما.

9. الأطفال والتغييرات والتواصل

هذه الخدمة الداخلية للقوى العاملة غير موجهة للأطفال. قد نحدّث هذه السياسة عند تغير التطبيق أو البنية التحتية أو المتطلبات القانونية، وسيتم تعديل تاريخ السريان أعلاه. تُرسل أسئلة الخصوصية إلى y172198402@gmail.com.