Last updated: 24 June 2026
| Policy Version Number | version 1.0 |
|---|---|
| Effective Date | 08-06-2026 |
| Last Updated | 24 June 2026 |
| Next Review Date | Yearly |
| Approval Authority | Board of Directors |
| Policy Owner | Planning & Development Department |
This Privacy Policy explains how the BDCC Mobile Attendance application (the "App") collects, uses, stores, and protects personal data. The App is provided for the employees of The Belagavi District Central Co-operative Bank Limited ("BDCC", "the Bank", "we", "us") to record and verify staff attendance. The Bank is the data controller (Data Fiduciary) responsible for the personal data processed through the App. The App is developed and maintained on the Bank's behalf by Integrity Techno Solutions acting as the Bank's technology service provider (data processor / Data Processor).
The App is intended only for authorised BDCC employees. It is not intended for, and does not knowingly collect data from, the general public or children.
| Category | What we collect | Why |
|---|---|---|
| Facial / biometric data | When you register your face and each time you mark attendance, the App captures one or more photographs of your face using the device camera and derives a facial recognition template from them. This biometric template is used to confirm that the person marking attendance is the enrolled employee (and to perform a blink "liveness" check to prevent spoofing with a photo). | To verify employee identity when recording attendance and prevent fraudulent or proxy attendance. |
| Account / login data | Your employee email address, password (stored only in a hashed, non-reversible form on the Bank's server), employee role, and a per-installation device identifier generated by the App. | To authenticate you, secure your account, and tie a registration to your device. |
| Location data | Your device's geographic location (latitude/longitude) captured only at the exact moment you mark attendance, used to confirm you are within the Bank's permitted premises (geofence). See Section 5 for details. | To verify attendance is marked from an authorised location. |
| Attendance & device records | Date, time, and status of each attendance event, and basic technical information needed to operate the App. | To maintain accurate attendance records for the Bank. |
We use the data described above solely to: authenticate employees; register and verify faces for attendance; confirm attendance is marked from a permitted location; and create and maintain official attendance records for the Bank. We do not use your facial data, location, or login information for advertising, marketing, profiling, or any purpose unrelated to attendance.
Enrolment in the App's facial recognition feature and the collection of location data are carried out on the basis of your informed consent, obtained before any biometric enrolment takes place.
Your facial image and the biometric template derived from it are sensitive personal data. We collect and process them only with your informed consent and your participation in the attendance process. The biometric template is used exclusively for identity verification within the App and is stored securely on the Bank's server. We do not sell, license, or disclose your biometric data to any third party, except as required to operate the App or by law. You may request deletion of your enrolled face data as described in Section 9; on cessation of employment your biometric data is deleted in accordance with the retention period stated in Section 8.
To remove any ambiguity about how location is used:
Personal data is transmitted over an encrypted (HTTPS/TLS) connection to servers operated for the Bank and is stored on those servers with access restricted to authorised personnel. Passwords are stored only as salted hashes. We apply reasonable technical and organisational safeguards — including access controls, role-based authorisation, encryption in transit, and audit logging — to protect data against unauthorised access, alteration, disclosure, or loss. All personal data collected through the App is stored on servers located in India.
We do not sell your personal data. Data is accessible to authorised Bank personnel for attendance administration and to Integrity Techno Solutions strictly for operating and maintaining the App on the Bank's behalf. We may disclose data where required by law, regulation, or a valid legal request.
Integrity Techno Solutions processes personal data strictly on behalf of and under the documented instructions of the Bank, and for no independent purpose of its own. Under a binding written agreement with the Bank, the provider is contractually obligated to:
The Bank remains the Data Fiduciary and stays accountable for personal data processed by the provider on its behalf.
The Bank retains personal data only for as long as necessary for the purposes described in this Policy, in accordance with the periods below:
| Data category | Retention period | Basis |
|---|---|---|
| Facial / biometric data (face images and derived templates) | Retained for the duration of your employment, and deleted within 30 days of the earlier of: (a) cessation of employment, (b) withdrawal of consent, or (c) a valid deletion request. | Consent; purpose limitation under the DPDP Act, 2023. |
| Attendance records (date, time, status, geofence result) | Retained for 8 years from the date of the attendance event. | The Bank's record-keeping, payroll, audit, and applicable regulatory obligations. |
| Account / login data | Retained for the duration of your employment and deleted within 90 days of cessation of employment. | Authentication and access administration. |
On expiry of the applicable period, data is securely deleted or irreversibly anonymised, unless a longer period is required by law, regulation, or an ongoing legal or disciplinary proceeding.
Subject to applicable law (including India's Digital Personal Data Protection Act, 2023), you may:
To exercise these rights, contact us using the details in Section 12. The Bank will respond within the timelines prescribed under applicable law. Withdrawing consent to facial recognition may prevent you from marking attendance through the App.
The Bank maintains a documented incident response procedure for personal data breaches and security incidents affecting the App:
This Policy is governed by and construed in accordance with the laws of India. In particular, the collection, processing, storage, and protection of personal data through the App is carried out in accordance with:
Where any provision of this Policy conflicts with applicable law or regulatory direction, the law or direction shall prevail. Disputes arising under this Policy are subject to the exclusive jurisdiction of the courts at Belagavi, Karnataka.
For privacy questions, to exercise your rights, to report a suspected security incident, or to raise a grievance, contact the Bank's Grievance Officer:
The Belagavi District Central Co-operative Bank Limited
Data Protection / Grievance Officer: Arunkumar C Kalmath
Designation: Deputy General Manager
Address: The Belagavi DCC Bank Ltd, Belagavi, TQ/Dist: Belagavi, Karnataka, India
Email: dgm.branchcontrol@belagavidccb.bank.in
Phone: 6366820377
Response timeline: The Grievance Officer will acknowledge your request and respond within
30 days of receipt.
If you are not satisfied with the resolution provided by the Grievance Officer, you may escalate your complaint to the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023.
Technology provider (processor): Integrity Techno Solutions — support@integritysolutions.co.in
The App is for the Bank's employees only and is not directed to children under 18.
The Bank may amend or update this Policy from time to time to reflect changes in applicable laws, regulations, business requirements, or the App's data processing activities. This Policy shall be reviewed at least annually (once every 12 months) or earlier whenever there is a significant change in legal, regulatory, operational, or technological requirements. Any material changes to this Policy shall be communicated to employees through the App, the Bank's internal communication channels, or other appropriate means. The version number and "Last Updated" date in the Document Control section shall be revised accordingly. Where required under the Digital Personal Data Protection Act, 2023 or any other applicable law, the Bank shall obtain fresh consent before processing personal data for any new purpose requiring such consent..
Near Central Bus Stand,
Old P B Road,
Belagavi, Karnataka 590016
0831-2466896