LEGAL
Privacy Policy
This policy explains how CSO Staff processes information for authorized employees, managers and administrators.
Who controls the data
The employer or participating organization that issues an account controls its workforce and HR records. CSO Staff processes those records to provide the authorized workplace service.
Information processed
- Account and HR information, including name, staff identifier, role, branch, contact details and documents supplied for employment administration.
- Roster and attendance information, including planned shifts, check-in, break and check-out times, and whether QR, NFC or an authorized correction was used.
- Operational content such as tickets, messages, training progress, performance records and payroll-related work summaries or salary-cut units.
- A privacy-safe technical device report after login: per-install random identifier, platform, app/build and OS version, manufacturer/model, device family, storage and memory information when available, camera/NFC capability and a short safe login-error code.
- Security and connection metadata needed to prevent abuse, diagnose failures and keep accounts safe.
Information not collected by device telemetry
Device telemetry does not request IMEI, hardware serial number, UDID, GPS location, contacts or a full crash dump. Camera access is used for QR scanning; NFC access is used for approved workplace tags.
Purposes and legal basis
Information is used to provide workforce operations, keep accurate attendance and HR records, secure accounts, diagnose the service, comply with employment obligations and support legitimate workplace administration. The employer determines the applicable legal basis under local law.
Service providers and international processing
Authorized infrastructure, mobile-platform, email, security and approved AI providers may process limited information necessary to operate the service. Access is limited by role and contractual or technical safeguards.
Retention
Records are retained only for the operational, employment, audit and legal periods determined by the participating organization and applicable law. Security logs and technical diagnostics are retained only as long as reasonably necessary.
Your choices and rights
Employees may ask their manager or HR representative to access or correct their information. Requests to remove an account or eligible data follow the process described on the Account Deletion page. Some employment or audit records may need to be retained where required by law.
Security
CSO Staff uses authenticated access, role controls, encrypted transport, protected storage, audit records and recovery procedures. No internet service can promise absolute security; suspected incidents should be reported immediately through the support process.
Contact
Use the in-app Tickets module, contact the manager or HR representative who issued the CSO Staff account, or email info@csosystem.com. Public support instructions are available at csosystem.com/support.