Legal
Privacy Policy
Last updated: 28 July 2026Introduction
This Privacy Policy explains how TimeChart, a product of Al Hutaib Computers & Network Solutions LLC ("TimeChart", "we", "us"), collects, uses and protects personal data when you visit our website, use our attendance software and mobile app, or when we supply biometric hardware. We process personal data in line with applicable UAE law, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL").
Who we are
TimeChart is a Dubai-based provider of time-attendance and workforce-management solutions. For privacy questions, contact us at info@alhutaib.com.
Our role: controller and processor
Our role depends on the data:
- As a controller — for data about website visitors and the business contacts of our customers (for example, enquiries you submit to us).
- As a processor — for data about our customers' employees that is processed through the Services (attendance, biometric and location data). Here the customer (the employer) is the controller and decides why and how the data is used; we process it on their instructions.
Data we collect
Website & enquiries
- Name, company, email and phone when you contact us or request a demo;
- Usage and device data collected through cookies and analytics.
Customer & account data
- Account, billing and contact details for administrators.
Employee data processed through the Services (as processor)
- Identity and role details entered by the employer;
- Attendance records: clock-in/out times, shifts, breaks, leave and overtime;
- Biometric data used to verify identity (see below);
- Location and GPS/geofencing data where enabled;
- Device and log data associated with check-ins.
Biometric data
Where an employer enables biometric attendance, our hardware and software use fingerprint, facial or similar features to verify identity. Biometric data is sensitive, and we handle it with particular care:
- Devices generally convert a fingerprint or face into an encrypted mathematical template used for matching, rather than storing raw images, wherever the device supports it;
- Biometric templates are stored securely and access is restricted to authorized personnel;
- Employers are responsible for informing employees and obtaining any consent required by law, and for offering a reasonable non-biometric alternative where appropriate;
- Biometric data is used only to verify attendance and access, not for any unrelated purpose.
- Where TimeChart Vision is used, faces may be recognised from CCTV or camera feeds; these are processed as encrypted templates solely for attendance and access monitoring, and for children this requires appropriate notice and consent.
Location & GPS data
When geofencing or mobile check-in is enabled, the app records the location of a check-in to confirm the employee is within an approved work area. Location is captured at the point of clock-in/out for attendance verification and is not used for continuous background tracking. Employers configure these features and are responsible for informing their employees.
How we use data
- To provide, operate and support the Services;
- To verify attendance and prevent time fraud;
- To generate reports and integrate with payroll/HRMS at the employer's direction;
- To respond to enquiries and provide demos;
- To secure our systems, comply with law and improve the Services.
Legal bases
Depending on the context, we rely on: performance of a contract; consent (including for biometric processing where required); our legitimate interests in running and securing the Services; and compliance with legal obligations such as record-keeping under UAE labour law.
International transfers
Data is primarily processed in the UAE. Where data is transferred outside the UAE (for example to a cloud region), we take steps to ensure an adequate level of protection consistent with the PDPL.
Data retention
We retain personal data for as long as needed to provide the Services and to meet legal, tax and labour-law obligations. Employee data processed on behalf of a customer is retained per that customer's instructions; on termination we delete or anonymize it after a reasonable window unless the law requires otherwise.
Security
We use appropriate technical and organizational measures — including encryption, access controls, secure hosting and, where supported, on-device biometric templating — to protect personal data against unauthorized access, loss or misuse. No system is perfectly secure, but we work continuously to protect your data.
Your rights
Subject to applicable law, individuals may request to access, correct, delete or restrict their personal data, object to certain processing, withdraw consent, or request portability. For employee data processed through the Services, please contact your employer (the controller) first; we will support them in responding. To exercise rights relating to data we control, contact info@alhutaib.com. You may also lodge a complaint with the UAE Data Office.
Children
The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect data from children.
Changes to this policy
We may update this Privacy Policy to reflect changes in our Services or the law. We will post the updated version here with a new "last updated" date.
Contact
For any privacy question or request, contact TimeChart at info@alhutaib.com, call +971 55 602 4245, or message us on WhatsApp.