Attenova logo
Attenova

Privacy Policy

Effective Date: August 14, 2026

Last Updated: August 14, 2026

1. Introduction

Attenova is a product and service operated by DWS CODES LTD ("Company," "we," "us," "our"). DWS CODES LTD is the registered company behind the Attenova platform and is responsible for the operation, processing, and governance of the Service described in this Privacy Policy.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, web services, and related platforms (collectively, the "Service").

This Privacy Policy applies to all users, including students, lecturers, administrators, hostel managers, and portal users ("Users," "you," "your").

Please read this Privacy Policy carefully. By accessing or using Attenova, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.


2. Information We Collect

2.1 Information You Provide Directly

Account Registration Data:

Authentication & Verification:

Attendance & Marking Data:

Communication & Requests:

Payment Information:

2.2 Information Collected Automatically

Device & App Usage:

Location Data:

Connectivity & Offline Data:


3. How We Use Your Information

3.1 Primary Uses

  1. Service Delivery & Attendance Management
  1. Communication
  1. Authentication & Security
  1. Analytics & Improvement
  1. Compliance & Legal

3.2 Legitimate Interests

We process your information based on legitimate interests including:


4. Sharing Your Information

4.1 Information We Do NOT Share

We do NOT sell, rent, or trade your personal information to third parties for marketing purposes. We maintain strict policies against unauthorized disclosure.

4.2 Information We MAY Share

Your information may be shared with:

Educational Institution Staff

Third-Party Service Providers

We share specific data with carefully selected providers:

  1. Firebase (Google)
  1. Paystack (Payment Processor)
  1. Google Maps & Google ML Kit
  1. Cloud Hosting Providers
  1. Email Service Providers

All Service Providers are contractually required to:

Legal Requirements

Business Transfers

4.3 Public Information

Information you choose to make public (e.g., profile picture, display name) may be visible to other users on the platform.


5. Biometric Data & Facial Recognition

5.1 What Facial Biometric Data Is Collected

Attenova collects and processes facial biometric data for:

5.2 How We Process Facial Biometric Data

On Your Device (Client-Side Processing):

On Our Server (Server-Side Validation):

Data Minimization:

5.3 Your Rights Regarding Biometric Data

5.4 Biometric Data Retention & Deletion Schedule

Student Facial Enrollment Data:

Hostel Manager Identity Photos (Special Case):

5.5 Your Consent to Biometric Processing

By enrolling your face in Attenova, you explicitly consent to:

You can withdraw this consent at any time by:

Consequences of Withdrawal:


6. GPS Location Data

6.1 Location Collection & Purpose

Why Precise Coordinates?

6.2 Location Privacy & Access Controls

What Lecturers Can See:

What Admins Can See:

What Superadmins Can See:

You Can Always See:

6.3 Location Data Retention

Retention Timeline:

6.4 Location Permissions

On Android and iOS, the app requests "Precise Location" permission. You may:


7. Data Security

7.1 Security Measures

We implement comprehensive security safeguards:

In Transit:

At Rest:

Access Control:

Application Security:

7.2 Limitations

While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of your data. You are responsible for:


8. Data Retention

8.1 Retention Periods

Active Users:

record are anonymized (cleared) at the end of the academic year — see Section 11.1

Inactive Users:

starting once your institution approves the request) — see Section 12.2 for the full

deletion request process

Event Data:

are formalizing specific retention periods for these as part of the audit-logging

work described in Section 11.7

8.2 Backup & Archive


9. Your Privacy Rights

9.1 GDPR Rights (EU/UK Users)

If you are located in the European Union or United Kingdom, you have:

Right of Access: Request access to your personal data

Right to Rectification: Correct inaccurate data

Right to Erasure: Request deletion of your data ("Right to be Forgotten")

Right to Restrict Processing: Limit how we use your data

Right to Data Portability: Receive your data in structured, machine-readable format

Right to Object: Object to certain processing activities

Right to Withdraw Consent: Withdraw previously given consent

To exercise these rights, contact us at: getattenova@gmail.com

Response Timeline: We will respond to requests within 30 days (extendable to 60-90 days for complex requests)

9.2 CCPA Rights (California Users)

California residents have additional rights under the California Consumer Privacy Act:

9.3 Other Jurisdictions

Depending on your location, you may have additional privacy rights. Contact us for jurisdiction-specific information.


10. Children's Privacy

10.1 Age Requirement

Attenova is intended for use by students 18 years of age or older. If you are under 18, you may only use Attenova with parental/guardian consent.

10.2 Parent/Guardian Rights

If we discover a child under 18 is using the Service without parental consent, we will:

Parents/guardians may contact us to request deletion of a child's account.

10.3 Biometric Data Consent for Minors

Attenova's account age requirement is 18 (Section 10.1). Because the Service does not

currently collect date of birth or perform automated age verification, biometric

enrollment does not go through a separate, automated parental-consent workflow at this

time.

If a student on your account is under 18:

is obtained before biometric enrollment, consistent with Section 10.1's general

parental-consent requirement for users under 18

requesting deletion of biometric data — see Section 5.3 and Section 5.5

Withdrawing Consent:

time via Settings in the app, or by emailing getattenova@gmail.com

If your institution requires a formal, verified parental-consent workflow for

biometric enrollment, contact getattenova@gmail.com — this is a feature we can prioritize

building for institutions that need it.


11. Data Retention & Deletion Schedule

This section outlines how long we retain each category of data and when it is automatically deleted:

11.1 Attendance Records

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
Attendance records (date, time, face score)Retained as an institutional record (see Section 8.1)NoYes, anytime (subject to institutional record-keeping needs)
Location coordinatesUntil end of academic year (Sept 30)Yes — anonymized (coordinates cleared, record kept)Yes, anytime
Liveness verification resultsRetained as part of the attendance recordNoYes, anytime
Leave/permission request records2 academic yearsYesYes, anytime
Leave/permission request supporting documents2 academic yearsYesYes, anytime

11.2 Biometric Data

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
Facial enrollment embeddings (active)While account is activeNoYes, anytime
Facial enrollment embeddings (inactive/old)30 days after deactivationYes, auto-delete after 30 daysYes, anytime
Hostel manager identity photos12 months after role terminationYes, after 12 monthsYes, anytime

11.3 Account Data

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
Email, name, phoneUntil account deletionNoYes (deletes account)
Password (hashed)Until account deletionNoYes (deletes account)
Profile pictureUntil account deletionNoYes (can change anytime)
Access token15 minutes, refreshed automatically while you're activeYes, auto-expiresN/A (automatic)
Refresh token (keeps you signed in between sessions)Up to 30 days, or until logoutYes, auto-expires or on logoutYes, by logging out
Session dataDuring active sessionYes, on logoutN/A (automatic)

11.4 Payment Data

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
Payment transaction records7 years (tax/legal requirement)NoNo (legal requirement)
Payment reference IDs7 yearsNoNo (audit trail)
Payment status history7 yearsNoNo (audit trail)
Card details (processed by Paystack)0 days (NOT stored by us)N/AN/A (Paystack handles)

11.5 Offline Data

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
Offline submissions pending sync (held on your device)Until synced to the serverCleared from your device once syncedYes, by clearing the app's local storage
Synced offline submissionsSame as the equivalent attendance/chapel/hostel record (see 11.1)Same as aboveYes, via main records

Offline attendance capture works by recording your submission on-device with a unique

request ID, then syncing it to the same tables used for regular attendance once you're

back online — there is no separate server-side "offline queue" table or retention

schedule distinct from the attendance record itself.

Offline Queue Security Note: If your device is lost or stolen while you have unsynced

offline attendance data, the local queue may contain pending submissions (session

reference, GPS location, face match/liveness result). It does not contain your

authentication token or other profile data — those are never written to local storage;

your session token is attached only at the moment a queued item is actually sent. The

local queue is not separately encrypted beyond the operating system's standard

app-storage protections.

Risk Mitigation: We recommend enabling device lock. To reduce the risk of your

unsynced data being submitted under someone else's session on a shared device, the app

blocks logging out while you have unsynced offline data or no internet connection.

11.6 Notification & Analytics Data

Data TypeRetention PeriodAutomatic DeletionUser Can Request Deletion
In-app notification history (class/attendance/permission notices)Until account deletionNoYes (deletes with your account)
Push delivery tokens (FCM)Until you log out, revoke notification permission, or your token expiresYes, stale/invalid tokens are removed automaticallyYes, anytime (disables notifications)
Firebase crash logsPer Google Firebase policyPer GoogleContact us; may limit debugging
App usage analytics (anonymized)13 monthsYesContact us (may impact analytics)
Device identifiers (IDFA, Android ID)Until app uninstallVaries by deviceManage in device settings

11.7 Institutional Audit Logs

Current status: structured, queryable audit logging (who accessed whose data, permission changes, attendance modifications, security events) is planned but not yet implemented as a standalone system. Administrative actions that change data (permission reviews, attendance corrections, account approvals) are recorded as part of the relevant record itself (e.g. who reviewed a request and when), but there is not yet a separate, centralized audit-log retention/deletion schedule to report here. This section will be updated with specific retention periods once that system is built.


12. Your Data Subject Rights

12.1 Right to Access (Subject Access Request - SAR)

You have the right to know what personal data we hold about you.

How to Request:

  1. Email getattenova@gmail.com with subject line "Data Subject Access Request"
  2. Include your full name, student/lecturer ID, and email address
  3. Include proof of identity (national ID, passport, or student ID photo)
  4. Include statement: "I request access to all personal data held about me"

Our Response:

What Happens to Your Request:

12.2 Right to Deletion (Right to Be Forgotten)

You have the right to request deletion of your personal data under certain circumstances.

When You Can Request Deletion:

What WILL Be Deleted:

What WILL NOT Be Deleted (Legal/Contractual Requirements):

How to Request:

  1. Email getattenova@gmail.com with subject "Data Deletion Request"
  2. Specify what data: "Delete entire account" or "Delete only [specific data]"
  3. Include your ID for verification
  4. Type or voice: "I request deletion of my personal data"

Our Response:

12.3 Right to Data Portability

You have the right to receive your data in a machine-readable format and transfer it to another service.

What We'll Export:

How to Request:

  1. Email getattenova@gmail.com: "I request data portability"
  2. Specify format: CSV, JSON, or XML
  3. Include your student/lecturer ID

Our Response:

12.4 Right to Correct (Right to Rectification)

You have the right to correct inaccurate personal data.

How to Request:

Our Response:

12.5 Right to Restrict Processing

You have the right to request we stop processing your data temporarily.

When This Applies:

How to Request:

Our Response:

12.6 Right to Object

You have the right to object to certain processing.

You Can Object to:

How to Request:

Our Response:

12.7 Right to Not Be Subject to Automated Decision-Making

You have the right to not be subject to automated decisions that produce legal effects about you.

Current Status:


13. Breach Notification & Security Incident Response

13.1 What Is a Data Breach?

A data breach occurs when unauthorized parties gain access to your personal data through:

13.2 Our Breach Response Procedure

Immediate Action (Within 24 hours of discovery):

  1. Isolate affected systems
  2. Assess scope (how much data? which users?)
  3. Preserve evidence for investigation
  4. Notify our legal and security teams
  5. Engage cybersecurity experts

Investigation (Within 3-7 days):

  1. Determine root cause
  2. Identify all affected data and users
  3. Assess risk level to users
  4. Implement fixes to prevent recurrence

Notification to Users (Within 30 days of discovery):

13.3 Notification to Authorities

We will notify authorities if required by law:

Notification includes:

13.4 Your Rights After a Breach

If your data is breached, you have the right to:

Contact getattenova@gmail.com immediately if breach-related and we'll provide these services at no cost.


14. Contact Us

For Privacy Concerns or Requests:

Quick Help:


15. Policy Updates

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

The "Last Updated" date at the top indicates when this policy was last modified.

16. International Data Transfers

If you access Attenova from outside the country where our servers are located, your data will be transferred to and processed in the country where our servers operate. By using Attenova, you consent to such transfers.

We implement appropriate safeguards for international data transfers, including:


17. Third-Party Links & Services

Attenova may contain links to third-party websites and services. We are not responsible for their privacy practices. Please review their privacy policies before providing your information.


18. Dispute Resolution

Any disputes regarding this Privacy Policy or our privacy practices will be governed by the laws of Nigeria. You agree to submit to the exclusive jurisdiction of courts in Nigeria.


By using Attenova, you acknowledge that you have read, understood, and agree to this Privacy Policy.