Operator (data processing) agreement
Effective 14 July 2026, as amended 19 August 2026 (clauses 3, 4 and 8 — proof-photograph retention and encryption scope); encryption-field and optional AI descriptions clarified 6 September 2026. Between Werktyd (“Operator”) and the registered business using it (“Responsible Party”).
- Roles. The Responsible Party determines the purpose; the Operator processes employee attendance data only on the Responsible Party’s documented instructions (POPIA ss.20–21).
- Purpose limitation. Processing is limited to time-and-attendance. No secondary use; no sale of data.
- Security. The Operator applies reasonable safeguards (POPIA s.19): encryption in transit, access control and audit logging. The identifying worker fields — SA ID number, phone number and pay — are AES-256-GCM encrypted at rest. The Responsible Party’s company registration number, VAT number, physical address, company contact email and phone number, and information officer email are also AES-256-GCM encrypted at rest. Fields stored unencrypted include numeric face templates, worker names and worker numbers, company and information officer names, account names and sign-in email addresses, and the company’s Telegram chat identifier used to route messages. These readable fields are protected by access control, role separation and audit logging. Biometric enrolment produces a numeric template and the enrolment photograph is discarded; a clock-in that cannot be verified automatically retains the photograph taken at that moment as proof for manager review — see clause 8.
- Sub-operators. Hosting is in Germany (EU/GDPR). Where the Responsible Party enables Telegram clock-in, worker selfies are transmitted via Telegram (a third-party messaging service), which may process them outside South Africa. Where the scan identifies the worker on its own, the Operator converts the selfie to a numeric template and does not store the image. Where the worker sends the selfie with a worker number as the caption — the fallback used when the face check cannot identify them — the clock-in is unverified and the full-resolution photograph is stored on the Operator’s server and shown to the Responsible Party’s manager for acceptance or rejection. When optional owner chat assistance is enabled, commands requiring AI interpretation are sent through OpenRouter to its configured language-model providers; the default chain includes Google Gemini, Anthropic Claude and DeepSeek. For voice notes, Groq receives the voice-note audio for transcription, and the transcript may then be sent through the same language-model chain. These requests may include worker names, numbers or other personal information the owner includes. They do not append the stored worker roster, face templates or clock photographs. The Operator stays responsible for its sub-operators.
- Cross-border transfer. The Responsible Party authorises EU processing (GDPR adequacy, POPIA s.72) and, if Telegram clock-in is enabled, the incidental transfer of selfies via Telegram — both disclosed in the worker notice. The Responsible Party is responsible for obtaining worker consent to the Telegram channel.
- Breach. The Operator notifies the Responsible Party without undue delay of any security compromise so it can meet its POPIA s.22 duties.
- Data-subject rights. The Operator assists the Responsible Party with access, correction, deletion and objection requests.
- Retention & deletion. Biometric templates are deleted on a worker’s termination (after a short buffer); time records are kept per the BCEA (3 years) then deleted. A proof photograph retained under clause 4 is deleted as soon as the Responsible Party’s manager accepts or rejects that clock-in, and in any case automatically after 30 days, at which point the clock-in is accepted. On termination of this agreement, data is returned or deleted.
© 2026 Werktyd.