Danti > Privacy Policy


Effective Date: October 23, 2025
Last Updated: October 23, 2025
Version: 2.0

1. Introduction

This Privacy Policy describes how Danti ("we," "us," or "our") collects, uses, and protects information provided by users when using our mobile application. We are committed to protecting your privacy and security. This policy may be updated periodically, and we recommend reviewing it regularly.

Important Notice: This application collects biometric data (facial recognition) and location data. Please read this policy carefully before using our services.

2. Information We Collect

2.1 Personal Information

2.2 Biometric Data

What We Collect:

Processing Details:

  1. Profile Photo: One photograph of your face is captured and stored on our secure servers. This photo is used as your profile image and for generating facial embeddings when needed.
  2. Facial Embeddings: When you clock in/out:
    • Your live facial image is captured
    • A temporary facial embedding (encrypted numerical representation) is generated
    • This embedding is compared against the embedding generated from your stored profile photo
    • Both embeddings are permanently deleted immediately after the face matching process is complete
    • No facial embeddings are stored long-term on our servers
  3. Original Live Photos: Any live photos captured during clock-in/out are never stored and are discarded immediately after embedding generation.

2.3 Location Data

What We Collect:

When We Collect:

Retention:

Purpose:

2.4 Technical Data

3. How We Use Your Information

We use collected data to:

3.1 Legal Basis for Processing

We process your data based on:

4. Facial Recognition and Biometric Data

4.1 Purpose and Processing

Our app uses facial recognition technology exclusively for employee identification, attendance tracking, and payroll purposes within the same organization.

Detailed Processing Flow:

  1. Initial Registration:
    • You provide explicit consent for biometric data collection
    • One profile photograph is captured
    • Photo is encrypted and stored on secure cloud servers
    • This photo serves as your reference image
  2. Clock-In/Clock-Out Process:
    • Live facial image is captured through your device camera
    • Temporary facial embedding is generated from live image
    • Temporary facial embedding is generated from your stored profile photo
    • Both embeddings are compared for identity verification
    • Both temporary embeddings are immediately and permanently deleted after comparison
    • Result (match/no match) is recorded for attendance
  3. Data Storage:
    • Only your profile photograph remains stored
    • No facial embeddings are stored
    • All embeddings are ephemeral (temporary) and deleted within seconds

4.2 Apple TrueDepth API

For iOS devices, Danti uses Apple's TrueDepth API solely for facial verification during clock-in/clock-out. This data is:

4.3 Consent and Rights

Consent Requirements:

Your Rights:

4.4 Data Retention

Profile Photograph:

Facial Embeddings:

4.5 Compliance

Our biometric data practices comply with:

  • Illinois Biometric Information Privacy Act (BIPA)
    • ✓ Written policy publicly available
    • ✓ Informed written consent obtained
    • ✓ Specific purpose and retention disclosed
    • ✓ Data deleted within 3 years or upon request
    • ✓ No sale or profit from biometric data
  • Texas Capture or Use of Biometric Identifier Act (CUBI)
  • Washington State Biometric Privacy Laws (HB 1493)
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Colombian Law 1581 of 2012 (Personal Data Protection)
  • Mexican LFPDPPP (Federal Law on Protection of Personal Data)
  • General Data Protection Regulation (GDPR) principles

4.6 Security Measures for Biometric Data

5. Location Data Collection and Use

5.1 When and Why We Collect Location

Purpose:

Collection Timing:

5.2 Background Location Collection

Important Notice: Danti collects location data in the background while you are on shift, even when the app is not actively open or in use.

Why Background Collection:

Your Control:

5.3 Location Data Retention

Automatic Deletion:

Storage:

5.4 Location Permissions

To use Danti's attendance features, you must grant:

You can revoke these permissions at any time through device settings, but this will disable attendance tracking features.

6. Data Sharing and Third Parties

6.1 Third-Party Services

We integrate with trusted third-party providers:

Link to the privacy policy of the external service providers used by the app:

These third parties may access limited personal information only to perform specific tasks on our behalf and are contractually bound not to disclose or use it for other purposes.

Important: Third parties never have access to:

6.2 Data We Do NOT Share

6.3 Data Controller vs Processor

Important Legal Distinction:

Employers using Danti are the data controllers for employee information. Danti acts as a data processor.

This means:

7. International Data Transfers

Your data may be transferred to and stored on servers located outside your country of residence, including in the United States. We ensure appropriate safeguards through:

8. Data Security

We employ industry-standard security measures to protect your information:

Technical Measures:

Organizational Measures:

Limitations:

However, no transmission or storage method is 100% secure. We cannot guarantee absolute security. You use the service at your own risk.

9. Data Retention

We retain personal data only as long as necessary for:

Specific Retention Periods:

Data Type Retention Period
Profile photograph (biometric) Duration of employment + 30 days (max 3 years)
Facial embeddings Seconds (deleted immediately after matching)
Location data Duration of shift only (deleted when shift ends)
Attendance records As required by labor laws (typically 3-7 years)
Account data Until account deletion requested
Technical logs 90 days
Payment information As required by tax laws

10. Your Rights

You have the right to:

To exercise these rights, contact us at: soporte@dantiapp.com

Response Time: We will respond to requests within 30 days (45 days for complex requests).

10.1 California Residents (CCPA/CPRA)

Under CCPA and CPRA, California residents have additional rights including:

10.2 Illinois Residents (BIPA)

Under BIPA, Illinois residents have specific rights:

11. Breach Notification

In the event of a data breach affecting your personal information, we will:

12. Cookies and Tracking

Danti does not explicitly use cookies in the mobile application but may integrate third-party libraries that do.

Third-Party Cookies:

You can configure your device to limit ad tracking. Rejecting tracking may affect some app functionality.

13. Log Data

In case of app errors, we may collect diagnostic data including:

Purpose: This data is used exclusively for debugging and service improvement.

Retention: Log data is retained for 90 days then automatically deleted.

Privacy: Log data does not contain biometric or location information.

14. Links to Third-Party Sites

Our app may contain links to third-party websites or services not operated by us. We have no control over their content or privacy practices. Please review their privacy policies independently before providing any information.

15. Children's Privacy

Our services are not directed to individuals under 13 years of age. We do not knowingly collect personal information from children.

If we discover we have collected data from a child under 13, we will:

If you believe a child has provided us with personal information, please contact us immediately at soporte@dantiapp.com.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect:

Notification:

17. Contact Us

If you have questions, concerns, or wish to exercise your data rights, please contact us:

Email: soporte@dantiapp.com
Subject Line: "Privacy Request" or "Data Rights Request"
Response Time: We will respond to requests within 30 days (45 days for complex requests)

18. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of Colombia and complies with applicable international and U.S. federal and state data protection regulations including:

International:

United States - Federal:

United States - State Laws:


Acknowledgment and Consent

By using Danti, you acknowledge that you have:

  • Read and understood this Privacy Policy in its entirety
  • Been informed about the collection of biometric data (facial recognition)
  • Been informed about the collection of location data during work shifts
  • Been informed about your rights and how to exercise them
  • Provided your explicit, informed, voluntary consent for the collection and use of your biometric and location data
  • Agreed to be bound by this Privacy Policy

Special Acknowledgment for Biometric Data:

  • I understand that Danti collects my facial photograph and creates temporary facial embeddings
  • I understand that my profile photo is stored but embeddings are deleted after each use
  • I understand the specific purpose is employee identification and attendance tracking
  • I understand my data will be retained for the duration of employment plus 30 days (maximum 3 years)
  • I understand I can request deletion at any time
  • I understand I can use a PIN instead of facial recognition
  • I voluntarily consent to this collection and use

Special Acknowledgment for Location Data:

  • I understand that Danti collects my location in the background during my work shifts
  • I understand this location data is deleted when my shift ends
  • I understand the purpose is to verify my presence at work locations
  • I voluntarily consent to this collection and use

Last Updated: October 23, 2025
Version: 2.0

For questions or concerns, contact us at:
soporte@dantiapp.com