1. Introduction & Overview
Welcome to Liqaa(“Liqaa,” “we,” “us,” or “our”), a cloud-native business operating system providing enterprise software including Liqaa Platform Control Tower, Liqaa HRMS, Liqaa POS, and related mobile applications (the “Services”).
This Privacy Policy explains in transparent detail how we collect, process, store, protect, and share data when your organization (“Tenant” or “Employer”) and its employees (“Users,” “Employees,” or “you”) interact with our web platforms, APIs, and mobile applications (iOS and Android).
2. Data Controller vs. Data Processor Roles
Employer / Tenant as Data Controller: In the context of employment records, attendance schedules, leave records, salary details, and on-duty tracking, your Employer (the Tenant who provisions your account) acts as the Data Controller. The Employer decides what policies, geofences, and tracking features are enabled.
Liqaa as Data Processor: Liqaa acts strictly as a Data Processor / Service Provider processing employee information under the written instruction of the Tenant, in compliance with GDPR (Art. 28), CCPA/CPRA, and the Digital Personal Data Protection (DPDP) regulations.
3. Geolocation & Location Tracking (Foreground & Background)
Liqaa HRMS provides precise workplace verification and on-duty mobility tracking. We require specific device location permissions which operate under strict operational boundaries:
A. Office Geofence Verification (Foreground Location)
Permission: ACCESS_FINE_LOCATION (Android) / NSLocationWhenInUseUsageDescription (iOS).
Purpose:When an employee taps “Check In” or “Check Out,” the app accesses the device’s GPS coordinates solely to verify whether the employee is physically present within the Employer’s authorized office geofence radius.
Frequency: Ephemeral check performed only at the precise instant the punch button is pressed. Continuous tracking is NOT active during standard office shifts.
B. Active Field Shift Tracking (Background Location)
Permission: ACCESS_BACKGROUND_LOCATION, FOREGROUND_SERVICE_LOCATION (Android) / NSLocationAlwaysAndWhenInUseUsageDescription (iOS).
Operational Rule: Background location tracking is STRICTLY LIMITED to active on-duty field shifts.
- Tracking begins only when an employee explicitly marks attendance for an authorized field/mobile shift.
- During the shift, periodic GPS breadcrumbs (coordinates, timestamp, battery state) are captured to generate verifiable travel routes and client visit logs.
- Hard Termination on Punch-Out: The moment the employee taps “Check Out” or the scheduled shift expires, all background location listeners are immediately terminated. Liqaa never captures location data during off-duty hours, breaks, or personal time.
4. Camera & Facial Biometric Verification
To eliminate buddy-punching and identity fraud, Liqaa HRMS mobile applications utilize camera hardware for facial verification:
Permission: CAMERA (Android) / NSCameraUsageDescription (iOS).
Facial Liveness & Match:When enabled by the Tenant, the employee presents their face during check-in. The app performs client-side liveness detection (blink/head motion) to verify a live human presence and compares facial feature vectors against the employee’s enrolled biometric template.
Automated Raw Image Purging:Biometric evidence is encrypted with AES-256 in transit and at rest. Raw captured selfie images are retained only for the Tenant’s configured audit window (e.g., 30 to 90 days) and are subsequently permanently purged from object storage.
5. Device Integrity, Anti-Spoofing & Security Verification
To ensure platform trustworthiness, Liqaa collects hardware and system telemetry:
- Mock Location / GPS Spoofing Detection: We inspect system flags to detect virtual location providers or mock GPS apps.
- Device Binding & UUID: Cryptographically generated device tokens ensure attendance punches originate from registered, employer-approved physical hardware.
- Tamper & Root/Jailbreak Detection: We verify operating system integrity via Apple DeviceCheck / Google Play Integrity APIs to block compromised environments.
6. Information We Collect & Categories of Data
| Category | Data Collected | Purpose |
|---|---|---|
| Tenant Account Data | Company name, business email, billing address, tax ID, phone. | Workspace setup, invoicing, enterprise license governance. |
| Employee Profile Data | Full name, official email, employee ID, department, designation. | Authentication, permissions allocation, organizational chart. |
| Attendance & Leaves | Punch-in/out timestamps, shift rosters, regularization notes, leave balances. | Payroll calculation, statutory overtime tracking, timesheets. |
| Payroll & Financials | Bank account details, salary components, statutory deductions (PF, Tax). | Automated payslip distribution and direct payout reconciliation. |
7. Data Retention & Deletion
We retain customer data for as long as the Tenant maintains an active subscription. Upon workspace termination or written tenant request:
- All transactional attendance, payroll, and shift records are preserved for a 30-day grace period to allow data export.
- After 30 days, tenant database records and associated object storage buckets are permanently and securely destroyed.
- Employees wishing to delete biometric profiles may submit requests to their Employer Administrator or directly to
privacy@liqaahq.com.
8. Security Measures & Subprocessors
Liqaa enforces enterprise-grade defense-in-depth security:
- Encryption: TLS 1.3 for all data in transit; AES-256 encryption for database volumes and S3 object storage at rest.
- Multi-Tenant Isolation: Logical and schema-level isolation ensures no tenant can access cross-workspace records.
- Subprocessors: We host infrastructure in ISO 27001 / SOC 2 certified AWS facilities (EU/Stockholm region) with automated disaster recovery backups.
9. Contact Our Data Protection Officer
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your legal rights under GDPR, CCPA, or DPDP, please contact our Data Protection Officer: