Enkept Privacy Policy

Last Updated: 27-Jul-2026

Enkept, a product of Fastcurve Services Private Limited, Bengaluru, India ("Enkept," "we," "our," or "us"), is committed to protecting the privacy of its users. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services, mobile applications, and website.

  1. Information We Collect

    We collect different types of data to enhance our service delivery, ensure compliance, and improve the user experience. The data may be collected from in the process of using Enkept web, apps, APIs or other platforms.

    1. Personal Information

      We may collect the following personally identifiable information (PII) such as Full name, Email address, Phone number, Employer details, Designation and Payment details (for subscription-based services)

    2. Usage and Device Data

      We may collect technical and analytical data to improve our services, such as IP address, Browser type and version, Device information, Operating system details and Application logs.

    3. Location Data

      For attendance and field-tracking features, Enkept may collect location data when explicitly allowed by the user, including while the app is in use and, where permitted, in the background to support employer-configured attendance and workforce management workflows.

    4. Face Data (Biometric Data)

      When you use Enkept HRMS features that involve facial recognition—such as mobile face attendance, kiosk-based face registration, or visitor face check-in—the app may collect facial images and derived face recognition data (such as facial feature templates or embeddings) used solely to verify identity for attendance, access, and visitor management. Face data is collected only after you or your organization administrator enables the feature and you provide consent through in-app prompts and device permissions (e.g., camera access).

    5. Cookies and Tracking Technologies

      We use cookies and similar technologies to personalize content and analyze traffic. Users may disable cookies through their browser settings.

  2. How We Use Your Information

    The collected data is used for the following purposes:

    1. To provide and maintain Enkept services
    2. To authenticate user access
    3. To improve our platform based on usage trends
    4. To send service-related notifications
    5. To ensure compliance with legal and regulatory requirements
    6. To handle customer support requests
    7. To prevent fraud and unauthorized access
    8. To verify employee and visitor identity through face recognition for attendance marking, clock-in/clock-out, kiosk registration, and visitor check-in
    9. To detect and log suspected face spoofing or unauthorized attendance attempts
  3. Face Data: Collection, Use, Sharing, Retention, and Deletion

    This section describes how Enkept HRMS handles face data, as required for apps that use facial recognition or other face-based features.

    1. What We Collect

      We may collect facial photographs captured through the Enkept mobile app or kiosk, and mathematical face recognition data derived from those images. We do not use face data for advertising, marketing, or sale to data brokers.

    2. Intended Uses and Disclosures

      Face data is used only to:

      • Register and authenticate employees for touchless attendance (clock-in and clock-out)
      • Register and recognize returning visitors at organization-managed entry points
      • Support anti-spoofing checks and maintain attendance audit logs for the employer
      • Enable organization administrators and authorized HR personnel to view attendance records associated with face verification

      Face data and related attendance records are disclosed only to your employer or organization that provisioned your Enkept account, and to Enkept personnel who need access to provide support or maintain the service under strict access controls.

    3. Sharing with Third Parties

      Enkept does not sell face data. Face data may be processed or stored by third-party infrastructure providers (such as cloud hosting partners with servers located in India) that help us operate the service. Any third party that processes face data on our behalf is contractually required to provide the same or equal protection of face data as described in this Privacy Policy, including restrictions on use, disclosure, retention, and security. Face data is not shared with third parties for their independent marketing or profiling purposes.

    4. Retention

      Face data is retained for as long as your organization maintains an active Enkept HRMS subscription and your employee or visitor profile remains active, or as needed to fulfill attendance and audit requirements configured by your employer. When an account is deactivated or your organization requests removal, face data is deleted or anonymized in accordance with our retention schedules and applicable legal obligations, typically within 90 days unless a longer period is required by law or legitimate business record-keeping needs.

    5. Deletion and Consent Revocation

      You may revoke consent for face data collection and use at any time by:

      • Disabling camera permissions for the Enkept app in your device settings
      • Requesting deletion through your organization’s HR or system administrator, who can remove your face registration from the Enkept admin portal
      • Contacting us directly at support@enkept.com with your name, employer, and request to delete face data

      Upon verified request, we will delete or anonymize your stored face data and associated face templates, except where retention is required by law or where your employer must retain attendance records for compliance. Revoking consent may limit or prevent use of face-based attendance features.

    6. Security

      Face data is protected using encryption in transit and at rest, role-based access controls, and secure authentication. Access is limited to authorized users and systems required to deliver the service.

  4. Data Sharing and Transfers
    1. Third-Party Service Providers

      Enkept may engage third-party service providers to assist with feature and system implementations but not limited to:

      1. Cloud hosting and storage (servers are located in India)
      2. Payment processing
      3. Customer support
      4. AI services
      We ensure that such vendors adhere to privacy standards in compliance with Indian laws.
    2. Legal Requirements

      We may disclose personal data when required to:

      1. Comply with legal obligations
      2. Protect Enkept’s legal rights
      3. Prevent security threats or fraud
    3. Business Transfers

      In case of a merger, acquisition, or sale, user information may be transferred to a successor entity.

  5. Data Security

    We employ security measures to protect user data from unauthorized access, including:

    • Data encryption in transit and at rest
    • Secure authentication protocols
    • Role-based access control

    Users are responsible for maintaining the confidentiality of their login credentials.

  6. User Rights

    Users have rights concerning their data, including:

    • Access and Correction: Users may request access to their personal data and correct inaccuracies.
    • Data Deletion: Users may request deletion of their accounts, subject to legal and business obligations.
    • Consent Management: Users can update their consent preferences for marketing, data tracking, and face data collection as described in the Face Data section above.
    • Face Data Deletion: Users may request deletion of stored face images and face recognition templates as outlined in Section 3 (Face Data: Collection, Use, Sharing, Retention, and Deletion).
  7. Retention of Data

    We retain user data as long as required to:

    • Fulfill contractual and legal obligations
    • Maintain records for auditing purposes
    • Prevent fraudulent activities
  8. International Access and Compliance

    Although Enkept is based in India and complies with Indian data protection laws, users from other countries may access our services. By using Enkept, users acknowledge and agree that their data will be processed and stored in India. We strive to align our practices with recognized global data protection standards where applicable but do not claim compliance with non-Indian laws.

    Users from jurisdictions with specific privacy laws (such as the GDPR in the European Union) should note that Enkept currently operates under Indian legal frameworks, and any requests regarding data protection will be addressed based on Indian regulations.

  9. Governing Law and Dispute Resolution

    This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Bengaluru, India.

  10. Contact Us

    For any privacy-related concerns, you may reach us at:

    Fastcurve Services Private Limited
    Bengaluru, India
    Email: support@enkept.com