Attendance data is sensitive: it shows where people are and when. This page describes how Punctual protects it and what we ask of organisations. It is written to be accurate, so it also lists what we do not claim.
1. Infrastructure
Punctual runs on Google Cloud / Firebase (Hosting, Cloud Firestore, Authentication and Cloud Functions). All traffic uses HTTPS/TLS, and Google encrypts stored data at rest. Our web hosts send security headers including a strict Content Security Policy, X-Frame-Options and X-Content-Type-Options.
2. Organisation isolation and access control
- Every organisation's staff, attendance and settings are isolated by database security rules enforced on the server, so one organisation cannot read another's staff or attendance records.
- Role-based access: staff, co-admin and admin roles; co-admins only get the permissions an admin grants.
- Sensitive controls (plan, staff caps, workplace-radius and device-binding safeguards) can be changed only from our Punctual Admin console, not by an organisation.
3. Attendance integrity
- GPS radius check at clock-in/out; an optional IP-address lock.
- Device binding: an account is tied to one registered device so credentials cannot be shared to clock in for someone else.
- Database rules also stop deactivated or removed accounts from writing attendance.
- Remote clock-in requires admin approval with a selfie and a best-effort face check.
4. Account security
Passwords are handled by Firebase Authentication and are never stored by us in readable form. Two-factor authentication and biometric login (fingerprint/face unlock on the user's own device) are available on supported plans. Admins can reset a staff password or device registration.
5. Incidents and responsible disclosure
If personal data is affected by a breach we will notify affected organisations without undue delay and, where required, the Nigeria Data Protection Commission within 72 hours. To report a vulnerability, email support@afrisalespro.com with details; please do not access other people's data, and give us reasonable time to fix the issue before disclosing it.
6. What we do not claim
- We do not currently hold our own ISO 27001 or SOC 2 certification. Our underlying provider, Google Cloud, does hold such certifications for its infrastructure.
- GPS and face checks reflect what a user's device reports and can be defeated by a determined person; they deter and log, they are not unbreakable.
7. Your part
Use strong unique passwords, keep devices locked, remove or deactivate staff who leave, review admin and co-admin access regularly, and tell staff what is collected. See also our Privacy Policy.