Home Pricing Privacy Policy
Privacy & Data Protection

Your identity data deserves clear and responsible protection.

This Privacy Policy explains how Identra Pro collects, uses, stores, shares, and protects information across Smart ID Cards, AI Face Attendance, GPS punching, leave management, reports, web dashboards, and mobile applications.

Effective: July 30, 2026 privacy@identra.online

Privacy at a glance

Identra Pro processes identity, attendance, and workspace information only to operate, secure, support, and improve the services selected by an organization.

Organization control

Your organization controls its employee or student records

Feature based

Face and location features depend on workspace configuration

No data sale

We do not sell uploaded identity or attendance records

Payment security

Payment card details are handled by payment providers

Role based access

Workspace administrators manage access and permissions

User requests

Deletion and access requests can be submitted to support

1. Who We Are and Our Privacy Role

Identra Pro is an identity and smart attendance platform operated through identra.online. The platform allows organizations to create ID cards, maintain employee or student records, configure attendance rules, verify punches, manage leave, and generate operational reports.

For information supplied directly by a workspace owner—such as account, subscription, support, and billing-contact information—Identra Pro generally decides why and how that information is processed.

For employee, staff, student, member, visitor, face-enrollment, location, and attendance information uploaded or collected under an organization’s workspace, the organization normally determines the purpose and rules of processing. Identra Pro processes that information to provide the configured service. Your employer, school, agency, or organization may therefore have its own privacy notice that also applies to you.

2. Information We Collect

The information collected depends on the services enabled and how the platform is used.

Account and workspace data

Name, email address, phone number, organization name, workspace details, role, branch, login credentials, communication preferences, and account settings.

Identity-card records

Employee or student ID, name, photograph, designation, department, class, branch, validity date, blood group, contact details, signature, QR or barcode values, and custom fields configured by the organization.

Attendance records

Punch In and Punch Out timestamps, breaks, attendance status, shift, working hours, overtime, late or early status, regularization, approval history, and attendance notes.

Device and technical data

IP address, browser or app version, operating system, device identifiers where available, session information, security events, crash details, and diagnostic logs.

Support and communications

Messages, attachments, feedback, support requests, and records of communications with the Identra Pro team.

Billing information

Plan, subscription status, transaction identifiers, invoices, tax or billing address, and limited payment metadata received from the payment provider.

3. Face Images and Biometric-Related Processing

When an organization enables AI Face Attendance, the platform may process an enrollment photograph, a live punch photograph, face-detection results, face-match measurements or confidence information, verification status, and related audit details.

Important: Face-related information can be highly sensitive and may be treated as biometric or specially protected data in some jurisdictions. The organization using Identra Pro is responsible for establishing an appropriate legal basis, providing required notices, obtaining valid consent where required, limiting access, and ensuring that face verification is lawful for its workforce, students, or members.

Face verification is intended to confirm whether the live person attempting an attendance action matches the approved enrollment. It should not be used as the sole basis for significant employment, disciplinary, educational, or legal decisions without appropriate human review.

4. Location and Geofencing Data

When GPS attendance or location verification is enabled, the mobile application may request the device’s current latitude, longitude, accuracy, timestamp, configured office or branch, distance from the approved location, geofence result, and whether an employee-specific Work From Home rule applies.

Location is processed when necessary for the requested attendance workflow, such as Punch In, Punch Out, field attendance, branch attendance, or an authorized remote-work action. Identra Pro does not require continuous background tracking unless a separate feature clearly states otherwise and the organization lawfully enables it.

5. How We Use Information

  • Create, operate, authenticate, and secure accounts and workspaces.
  • Import and manage identity records and generate ID cards, QR codes, barcodes, and print-ready files.
  • Process Face ID enrollment, live verification, GPS geofencing, Punch In and Punch Out, leave, regularization, and approval workflows.
  • Generate dashboards, attendance history, branch summaries, audit logs, Excel exports, and operational reports.
  • Send service messages, security notices, approval updates, punch reminders, and support communications.
  • Detect misuse, unauthorized access, suspicious activity, duplicate or proxy attendance attempts, and technical failures.
  • Maintain backups, troubleshoot problems, improve reliability, and develop new product functionality.
  • Process subscriptions, invoices, refunds, taxes, and customer-support requests.
  • Comply with applicable law, enforce agreements, and protect users, organizations, and the platform.

7. How Information Is Shared

We do not sell workspace identity, face, location, or attendance records. Information may be disclosed only where reasonably necessary to operate or protect the service:

  • Workspace users: Authorized owners, administrators, HR users, managers, supervisors, employees, teachers, or other roles according to configured permissions.
  • Service providers: Hosting, storage, database, email, notification, analytics, monitoring, customer-support, face-verification, mapping, and security providers acting under contractual restrictions.
  • Payment providers: Payment processors or Merchant of Record providers that process subscription transactions and maintain payment details under their own policies.
  • Legal and safety disclosures: Government authorities, courts, regulators, professional advisers, or other parties when disclosure is required by law or reasonably necessary to protect rights, security, and users.
  • Business transactions: A buyer, successor, investor, or adviser during a merger, acquisition, financing, reorganization, or sale, subject to appropriate confidentiality and privacy protections.

8. Data Retention, Export, and Deletion

Information is retained only for as long as reasonably necessary for the purposes described in this Policy, the organization’s instructions, active subscription requirements, backup cycles, dispute resolution, security, tax, accounting, and legal obligations.

Workspace owners and authorized administrators may be able to update, export, archive, or delete records through available product controls. Some deleted information may remain temporarily in encrypted backups or security logs until normal backup rotation or legal-retention periods expire.

Before terminating a workspace or subscription, the organization should export any records it is required to retain. Requests for account or workspace deletion can be sent to privacy@identra.online.

9. Security and Access Controls

We use reasonable administrative, technical, and organizational safeguards designed to protect information. These may include encrypted connections, access controls, password protections, role-based permissions, secure hosting, logging, backups, monitoring, and restricted administrative access.

No internet service can guarantee absolute security. Workspace owners are responsible for assigning appropriate roles, removing inactive users, protecting login credentials, configuring attendance rules lawfully, securing exported files, and promptly reporting suspected unauthorized access.

10. Your Privacy Rights

Depending on applicable law, you may have rights to request access, correction, completion, deletion, restriction, objection, portability, withdrawal of consent, information about processing, or review of certain automated outcomes.

When your information belongs to an employer, school, agency, or another workspace customer, submit the request to that organization first because it controls the underlying record and may need to verify and action the request. Identra Pro will provide reasonable assistance where required.

To submit a request directly to Identra Pro, email privacy@identra.online. We may request information to verify identity and authority before responding. Some requests may be limited where retention or processing is required by law or necessary to protect other individuals’ rights.

11. Children, Students, and Educational Records

Identra Pro may be used by schools, colleges, coaching organizations, and other institutions to manage student identity cards or attendance. The institution is responsible for determining whether parental or guardian authorization, student notice, age verification, or another legal safeguard is required.

Children should not independently create commercial workspaces or submit sensitive information unless permitted by the applicable organization and law. Institutions should collect only the information needed for their legitimate educational and administrative purposes.

12. International Data Transfers

Identra Pro and its service providers may process information in countries other than the country where the user or organization is located. Where required, appropriate contractual, organizational, or legal safeguards will be used for international transfers.

Organizations with data-residency or cross-border-transfer requirements should contact us before enabling the service so available hosting and contractual options can be reviewed.

13. Cookies, Analytics, and Similar Technologies

Our website and web application may use essential cookies for authentication, security, session continuity, preferences, and core functionality. We may also use analytics and performance technologies to understand page usage, diagnose errors, and improve the service.

Where required by law, non-essential cookies or similar technologies will be used only after an appropriate choice or consent is obtained. Browser settings may allow you to block cookies, although essential platform functions may not work correctly without them.

14. Service and Marketing Communications

We may send transactional messages needed to operate the service, including login, security, subscription, support, attendance, approval, and account notices.

Promotional messages may be sent where permitted by law. You can use the unsubscribe option in the message or contact support. Unsubscribing from marketing does not stop essential service or security communications.

15. Third-Party Links and Integrations

The service may link to or integrate with payment providers, cloud platforms, mapping services, notification providers, app stores, or other external services. Their privacy practices are governed by their own notices. Organizations should review third-party terms before enabling optional integrations.

16. Changes to This Privacy Policy

We may update this Policy when the platform, legal requirements, service providers, or processing practices change. The effective date at the top will be updated, and material changes may also be communicated through the website, application, email, or workspace notice.

17. Contact Us

Questions, complaints, privacy requests, or suspected data-security incidents can be sent to:

Identra Pro Privacy Team

Email: privacy@identra.online

General support: info@identra.online

Website: identra.online

This template should be reviewed and adapted to Identra Pro’s actual hosting locations, subprocessors, retention periods, payment providers, company registration details, and launch jurisdictions before production use.