Belagavi District Central Co-Operative Bank LTD.
Telephone : 0831-2466896
Deaf Accounts Details:    

CORE 154609   |   RBI CIRCULAR   |

 

Privacy Policy — BDCC Mobile Attendance

Last updated: 24 June 2026

Document Control

Policy Version Numberversion 1.0
Effective Date08-06-2026
Last Updated24 June 2026
Next Review DateYearly
Approval AuthorityBoard of Directors
Policy Owner Planning & Development Department

This Privacy Policy explains how the BDCC Mobile Attendance application (the "App") collects, uses, stores, and protects personal data. The App is provided for the employees of The Belagavi District Central Co-operative Bank Limited ("BDCC", "the Bank", "we", "us") to record and verify staff attendance. The Bank is the data controller (Data Fiduciary) responsible for the personal data processed through the App. The App is developed and maintained on the Bank's behalf by Integrity Techno Solutions acting as the Bank's technology service provider (data processor / Data Processor).

The App is intended only for authorised BDCC employees. It is not intended for, and does not knowingly collect data from, the general public or children.

1. Personal Data We Collect

CategoryWhat we collectWhy
Facial / biometric data When you register your face and each time you mark attendance, the App captures one or more photographs of your face using the device camera and derives a facial recognition template from them. This biometric template is used to confirm that the person marking attendance is the enrolled employee (and to perform a blink "liveness" check to prevent spoofing with a photo). To verify employee identity when recording attendance and prevent fraudulent or proxy attendance.
Account / login data Your employee email address, password (stored only in a hashed, non-reversible form on the Bank's server), employee role, and a per-installation device identifier generated by the App. To authenticate you, secure your account, and tie a registration to your device.
Location data Your device's geographic location (latitude/longitude) captured only at the exact moment you mark attendance, used to confirm you are within the Bank's permitted premises (geofence). See Section 5 for details. To verify attendance is marked from an authorised location.
Attendance & device records Date, time, and status of each attendance event, and basic technical information needed to operate the App. To maintain accurate attendance records for the Bank.

2. How Your Data Is Used

We use the data described above solely to: authenticate employees; register and verify faces for attendance; confirm attendance is marked from a permitted location; and create and maintain official attendance records for the Bank. We do not use your facial data, location, or login information for advertising, marketing, profiling, or any purpose unrelated to attendance.

3. Employee Consent

Enrolment in the App's facial recognition feature and the collection of location data are carried out on the basis of your informed consent, obtained before any biometric enrolment takes place.

  • Before you enrol your facial data, the App presents a consent notice describing what biometric data is collected, the purpose of collection, how long it is retained, and your right to withdraw consent. Enrolment proceeds only after you affirmatively accept.
  • Location access is requested through your device's operating system permission prompt, which you may grant or decline. The App cannot access your location unless you grant this permission.
  • Your consent is free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, in accordance with the Digital Personal Data Protection Act, 2023.
  • You may withdraw your consent at any time by contacting the Grievance Officer named in Section 12. Withdrawal is as easy as giving consent. On withdrawal, the Bank will cease biometric processing and delete your enrolled face data within the period stated in Section 8, unless retention is required by law. Please note that withdrawing consent to facial recognition or location access will prevent you from marking attendance through the App, and the Bank will record your attendance through an alternative manual process.

4. Biometric Data — Specific Notice

Your facial image and the biometric template derived from it are sensitive personal data. We collect and process them only with your informed consent and your participation in the attendance process. The biometric template is used exclusively for identity verification within the App and is stored securely on the Bank's server. We do not sell, license, or disclose your biometric data to any third party, except as required to operate the App or by law. You may request deletion of your enrolled face data as described in Section 9; on cessation of employment your biometric data is deleted in accordance with the retention period stated in Section 8.

5. Location Data — Scope and Limits

To remove any ambiguity about how location is used:

  • The App collects your location only at the exact moment you tap to mark attendance (check-in and check-out). A single latitude/longitude reading is taken at that instant.
  • The App does not track your location continuously, does not collect location in the background, and does not collect location when the App is closed or when you are not marking attendance.
  • The App does not build any location history, movement trail, or travel profile of employees. Only the point reading attached to each attendance event is retained.
  • The reading is used solely to confirm that the attendance event occurred inside the Bank's authorised geofence, and is never used to monitor employees outside working attendance events.

6. How Data Is Stored and Transmitted

Personal data is transmitted over an encrypted (HTTPS/TLS) connection to servers operated for the Bank and is stored on those servers with access restricted to authorised personnel. Passwords are stored only as salted hashes. We apply reasonable technical and organisational safeguards — including access controls, role-based authorisation, encryption in transit, and audit logging — to protect data against unauthorised access, alteration, disclosure, or loss. All personal data collected through the App is stored on servers located in India.

7. Sharing and Disclosure

We do not sell your personal data. Data is accessible to authorised Bank personnel for attendance administration and to Integrity Techno Solutions strictly for operating and maintaining the App on the Bank's behalf. We may disclose data where required by law, regulation, or a valid legal request.

7.1 Responsibilities of the Technology Provider (Data Processor)

Integrity Techno Solutions processes personal data strictly on behalf of and under the documented instructions of the Bank, and for no independent purpose of its own. Under a binding written agreement with the Bank, the provider is contractually obligated to:

  • process personal data only for the purposes of operating and maintaining the App, and not for its own commercial, analytical, marketing, or model-training purposes;
  • maintain strict confidentiality of all personal data, including biometric data, and bind its personnel to equivalent confidentiality obligations;
  • implement and maintain reasonable security safeguards appropriate to the sensitivity of the data, including access control, encryption, and logging;
  • not engage any sub-processor without the Bank's prior written authorisation, and to impose equivalent obligations on any authorised sub-processor;
  • notify the Bank without undue delay upon becoming aware of any personal data breach or security incident, and assist the Bank in its investigation, remediation, and regulatory notification obligations;
  • assist the Bank in responding to data principal requests for access, correction, or erasure;
  • permit audits or security assessments by the Bank or its appointed auditors; and
  • securely delete or return all personal data on termination of the agreement, retaining no copies except where required by law.

The Bank remains the Data Fiduciary and stays accountable for personal data processed by the provider on its behalf.

8. Data Retention

The Bank retains personal data only for as long as necessary for the purposes described in this Policy, in accordance with the periods below:

Data categoryRetention periodBasis
Facial / biometric data (face images and derived templates) Retained for the duration of your employment, and deleted within 30 days of the earlier of: (a) cessation of employment, (b) withdrawal of consent, or (c) a valid deletion request. Consent; purpose limitation under the DPDP Act, 2023.
Attendance records (date, time, status, geofence result) Retained for 8 years from the date of the attendance event. The Bank's record-keeping, payroll, audit, and applicable regulatory obligations.
Account / login data Retained for the duration of your employment and deleted within 90 days of cessation of employment. Authentication and access administration.

On expiry of the applicable period, data is securely deleted or irreversibly anonymised, unless a longer period is required by law, regulation, or an ongoing legal or disciplinary proceeding.

9. Your Rights

Subject to applicable law (including India's Digital Personal Data Protection Act, 2023), you may:

  • request access to a summary of the personal data the Bank processes about you;
  • request correction of inaccurate or incomplete data, and completion or updating of your data;
  • request erasure of your personal data, including your enrolled face data, where retention is no longer required;
  • withdraw consent to biometric processing or location access at any time (see Section 3);
  • nominate another individual to exercise your rights in the event of your death or incapacity; and
  • raise a grievance with the Grievance Officer named in Section 12, and, if unsatisfied with the resolution, escalate to the Data Protection Board of India.

To exercise these rights, contact us using the details in Section 12. The Bank will respond within the timelines prescribed under applicable law. Withdrawing consent to facial recognition may prevent you from marking attendance through the App.

10. Data Breach and Security Incident Handling

The Bank maintains a documented incident response procedure for personal data breaches and security incidents affecting the App:

  • Detection and reporting. Any suspected breach — whether identified by Bank personnel, by Integrity Techno Solutions, or reported by an employee — must be reported immediately to the Grievance Officer and the Bank's IT Department. Employees who suspect an incident should report it using the contact details in Section 12.
  • Containment and assessment. On becoming aware of an incident, the Bank will act promptly to contain it, assess the nature, scope, categories of data, and the individuals affected, and preserve evidence for investigation.
  • Notification to the regulator. The Bank will notify the Data Protection Board of India of any personal data breach in the form and within the timelines prescribed under the Digital Personal Data Protection Act, 2023 and the rules made thereunder.
  • Notification to affected employees. The Bank will notify each affected Data Principal without undue delay, describing the nature and extent of the breach, its likely consequences, the measures taken to mitigate risk, and the contact point for further information.
  • Other regulatory reporting. Where applicable, the Bank will also report the incident to CERT-In within the timelines prescribed under the Information Technology Act, 2000 and CERT-In directions, and to the Reserve Bank of India and NABARD in accordance with applicable cyber security and incident reporting guidelines for co-operative banks.
  • Processor obligations. Integrity Techno Solutions is contractually required to notify the Bank without undue delay of any breach affecting data processed on the Bank's behalf, and to cooperate fully in investigation and remediation (see Section 7.1).
  • Remediation and review. Following any incident, the Bank will conduct a root-cause review, implement corrective measures, and record the incident, its effects, and the remedial action taken in its incident register.

11. Governing Law and Applicable Regulations

This Policy is governed by and construed in accordance with the laws of India. In particular, the collection, processing, storage, and protection of personal data through the App is carried out in accordance with:

  • the Digital Personal Data Protection Act, 2023 and the rules made thereunder;
  • the Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable;
  • CERT-In directions on information security practices and incident reporting;
  • applicable Reserve Bank of India and NABARD circulars, master directions, and cyber security guidelines applicable to co-operative banks;
  • the Banking Regulation Act, 1949 and the Karnataka Co-operative Societies Act, 1959, to the extent applicable to the Bank's record-keeping obligations; and
  • any other statutory, regulatory, or supervisory guidelines applicable to the Bank from time to time.

Where any provision of this Policy conflicts with applicable law or regulatory direction, the law or direction shall prevail. Disputes arising under this Policy are subject to the exclusive jurisdiction of the courts at Belagavi, Karnataka.

12. Grievance Redressal and Contact

For privacy questions, to exercise your rights, to report a suspected security incident, or to raise a grievance, contact the Bank's Grievance Officer:

The Belagavi District Central Co-operative Bank Limited
Data Protection / Grievance Officer: Arunkumar C Kalmath
Designation: Deputy General Manager
Address: The Belagavi DCC Bank Ltd, Belagavi, TQ/Dist: Belagavi, Karnataka, India
Email: dgm.branchcontrol@belagavidccb.bank.in
Phone: 6366820377
Response timeline: The Grievance Officer will acknowledge your request and respond within 30 days of receipt.

If you are not satisfied with the resolution provided by the Grievance Officer, you may escalate your complaint to the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023.

Technology provider (processor): Integrity Techno Solutions — support@integritysolutions.co.in

13. Children

The App is for the Bank's employees only and is not directed to children under 18.

14. Changes to This Policy

The Bank may amend or update this Policy from time to time to reflect changes in applicable laws, regulations, business requirements, or the App's data processing activities. This Policy shall be reviewed at least annually (once every 12 months) or earlier whenever there is a significant change in legal, regulatory, operational, or technological requirements. Any material changes to this Policy shall be communicated to employees through the App, the Bank's internal communication channels, or other appropriate means. The version number and "Last Updated" date in the Document Control section shall be revised accordingly. Where required under the Digital Personal Data Protection Act, 2023 or any other applicable law, the Bank shall obtain fresh consent before processing personal data for any new purpose requiring such consent..



©2021. All Rights Reserved.     Website updated: 27-10-2021

     Privacy Policy   |  Terms and Conditions