Skip to content

Privacy policy

Effective 18 September 2026. Applies to inoroff.com and the InOrOff application.

Who we are

InOrOff (“we”) operates inoroff.com, a leave and attendance service for employers. For the records an employer keeps about its people, the employer is the controller and we process them on the employer's instructions. For your account (name, email, sign-in details) we are the controller. Questions: contact@inoroff.com.

What we collect

  • Account: name, email address, password hash, whether two-factor authentication is on, session records (token, creation and expiry, the address and browser a session was created from).
  • Employer records entered by your administrator: employee code, name, location, department, schedule, reporting line, employment dates, leave types and balances, holidays.
  • Attendance: check-in, check-out and break events with server timestamps, the schedule and policy in force, and the public network address the event came from (used only to apply an office-network rule).
  • Leave and corrections: requests, dates, optional reasons, decisions, and — if your administrator enables attachments — files you choose to upload as evidence.
  • Notifications and mail: in-app notices and the emails we send you (verification, reset, invitations, reminders) and their delivery status.
  • Audit history: who did what and when, with a redacted summary that never contains passwords, tokens or medical content.

We do not collect photos, biometrics, keystrokes or browsing activity. We set no advertising or analytics cookies; the only cookies are the session cookie and a preference for which workspace you last opened.

Location is the one exception, and only if your employer turns it on. If a site has been given coordinates, checking in from a phone may ask your browser for its position. You can refuse, and the check-in still works. Your coordinates are never stored or sent to us: the position is compared with the site on our server and all that is kept is one word — whether you were at the site, away from it, or that it is unknown — together with which site it was. That word is deleted with the rest of the check-in evidence under your employer’s retention setting.

Why

To provide the service: record attendance, manage leave, route approvals, prepare monthly time data, notify you, secure your account, and keep an audit history employers can rely on. We do not sell data and do not use it for advertising.

Who can see what

Inside an employer: employees see their own records; managers see their reports' attendance and requests, without reasons or evidence; HR reviewers see reasons and evidence; administrators manage settings and exports. Between employers, nothing is shared: isolation is enforced in the database. Our own staff see service health and limited tenant metadata; access to an employer's records requires a time-bounded grant made by that employer's administrator, is read-only, and is written to the employer's audit history.

Where and with whom

Data is stored on servers we operate. Emails are sent from our own mail server. We use no third-party analytics or processors for your records. If you sign in with Google, Google processes your sign-in under its own policy; we keep only the account identity, never Google tokens.

How long

  • Account and employer records: for as long as the workspace exists.
  • Network addresses recorded at check-in: 90 days by default; each employer can set this.
  • Monthly export files: 400 days by default; configurable.
  • Audit history: 7 years by default; configurable. An employer can place a legal hold that stops all automatic removal.
  • When an employer erases a former employee — at that person’s request, or automatically once the keeping period has run — the record’s name, addresses and phone number are replaced, the files attached to their requests are deleted, and their name is taken out of the notices colleagues were sent and out of the record of what was done. Their sign-in is closed unless they still work for another employer here. Dates, leave balances and attendance figures stay, under a replacement name, because the employer still has to account for the months that person worked; and something another person typed about them, such as a note on a request, is that person’s own record and stays.
  • After a deletion request: a 30-day grace period, then removal of all workspace data. The fact of the deletion is kept so that any restored copy is deleted again.

Your rights

You can see and download your own leave, attendance and account data in the application. An employer's administrator can export everything their organisation entered and everything computed for it at any time, and request deletion. For access, correction or deletion requests about records your employer holds, contact your employer first; we will assist them. For your account, contact us. We answer within 30 days.

Security

Described in detail on our security page: database-enforced isolation, two-factor authentication, step-up for privileged changes, scanned private files, audited access.

Changes

We will post changes here with a new effective date and, for material changes, notify workspace administrators by email.