Attenova
Terms & Conditions
Effective Date: August 14, 2026
Last Updated: August 14, 2026
1. Agreement to Terms
These Terms & Conditions ("Terms") constitute a legally binding agreement between you ("User," "you," "your") and DWS CODES LTD ("Company," "we," "us," "our") governing your use of the Attenova mobile application, web services, and related platforms (the "Service"). Attenova is a product and service operated by DWS CODES LTD, the registered company behind this platform.
By accessing, downloading, or using Attenova in any way, you agree to be bound by these Terms. If you do not agree to these Terms, you must not use the Service.
Your use of the Service is also governed by our Privacy Policy, which is incorporated by reference into these Terms.
2. Eligibility & Account Registration
2.1 Age Requirement
You must be at least 18 years of age to use Attenova. If you are under 18, you may only use the Service with the consent and supervision of a parent or legal guardian.
2.2 Institution Affiliation
You represent and warrant that:
- You are affiliated with an educational institution using Attenova
- The information you provide during registration is accurate and truthful
- You are authorized to access the institution's instance of Attenova
- Your institution has consented to data collection and processing for attendance tracking
2.3 Account Responsibility
You are solely responsible for:
- Maintaining the confidentiality of your login credentials
- All activities that occur under your account
- Notifying us immediately of unauthorized access or use
- Your actions and content submitted through your account
We are not liable for any loss, damage, or unauthorized access resulting from your failure to protect your credentials.
2.4 Account Termination
Your account may be terminated or suspended if you:
- Violate these Terms or any applicable laws
- Engage in fraud, abuse, or harassment
- Provide false or misleading information
- Fail to use the Service as intended
- Become unaffiliated with your institution
3. Use Licenses & Restrictions
3.1 Limited License
We grant you a non-exclusive, non-transferable, revocable license to use Attenova solely for its intended purpose: tracking attendance, managing leave requests, and communicating with your institution.
This license is personal to you and may not be shared, sold, or transferred.
3.2 Prohibited Activities
You agree NOT to:
Legal Violations:
- Use the Service for any illegal purpose or in violation of any laws
- Circumvent authentication or security measures
- Attempt unauthorized access to the Service or other users' accounts
- Hack, crack, or exploit vulnerabilities in the Service
Misuse of Data:
- Attempt to scrape, bulk download, or extract data from the Service
- Reverse-engineer or decompile the application
- Use the Service to collect data on other users without consent
- Share other users' personal information
Fraudulent Activities:
- Submit false attendance records or attendance for others
- Forge attendance with spoofed biometric data or fake GPS locations
- Manipulate offline data before syncing
- Impersonate other users or institutional staff
Abusive Behavior:
- Harass, threaten, or abuse other users
- Send spam, malware, or malicious content
- Disrupt the Service or harm other users' experience
- Engage in discrimination or hate speech
Commercial Misuse:
- Use the Service for commercial purposes without authorization
- Build competing services using Attenova data
- Resell access to the Service
- Advertise or promote products/services (except as part of institution communications)
4. Content & Intellectual Property
4.1 Company Intellectual Property
All content, features, and functionality of Attenova (including but not limited to source code, design, layout, logos, and trademarks) are the exclusive property of DWS CODES LTD or our licensors and are protected by copyright, trademark, and other intellectual property laws.
You may not:
- Copy, modify, or create derivative works
- Reproduce, distribute, or publicly display content without permission
- Remove copyright, trademark, or other IP notices
4.2 User Content
By submitting any content through Attenova (including notes, leave requests, or communications), you:
- Grant us a non-exclusive, royalty-free, perpetual license to use, reproduce, modify, and distribute that content for Service operation and improvement
- Represent that you have the right to submit that content
- Acknowledge that submitted content is not confidential
- Waive any moral rights or claims
We are not obligated to monitor, moderate, or remove user content.
4.3 Student Data Ownership
Notwithstanding the above:
- You retain ownership of your personal data and attendance records
- We act as a processor and steward of your data on behalf of your institution
- We do not claim ownership of your personal information
- Your biometric data is yours; we process it on your behalf
5. Attendance Records & Verification
5.1 Accuracy & Authenticity
You acknowledge that:
- Attendance records submitted through Attenova are official academic records
- False or fraudulent attendance submissions may result in disciplinary action by your institution
- You are responsible for the accuracy of attendance submissions
- Biometric verification (face recognition) is part of fraud prevention
5.2 Institutional Authority
Your institution has the authority to:
- Review and verify attendance records
- Investigate suspicious submissions
- Correct erroneous records
- Enforce attendance policies and consequences
- Restrict access if fraudulent activity is detected
5.3 Liability Limitation
DWS CODES LTD is not liable for:
- Institutional decisions based on attendance records
- Disputes between you and your institution regarding attendance
- Consequences (academic, disciplinary, or otherwise) resulting from attendance records
- Technical failures that prevent timely attendance submission
We act as a data processor, not as the authority on attendance policy enforcement.
6. Offline Functionality
6.1 Offline Data Storage
Attenova supports offline attendance submission. You acknowledge:
- Offline data is stored locally on your device
- We are not liable for data loss if your device is lost, stolen, or damaged
- Offline data may be lost if the app is uninstalled or device storage is cleared
- Syncing occurs when internet connectivity is restored
6.2 Sync Failure
If offline data fails to sync:
- We will attempt resubmission automatically
- You are responsible for verifying successful submission
- Contact your institution if a record does not appear after sync
- We are not liable for sync failures due to network issues or device problems
6.3 Offline Accuracy
Offline submission does not guarantee accuracy:
- Your device's GPS or biometric verification may be inaccurate offline
- Institutional verification processes will be applied after sync
- Disputes regarding offline submissions will be resolved by your institution
7. Biometric Data & Verification
7.1 Biometric Consent
By using Attenova, you explicitly consent to:
- Collection of facial biometric data for enrollment and verification
- Storage and processing of your biometric template
- Use of biometric data for attendance verification
- Continuous liveness detection to prevent fraud
7.2 Enrollment Requirements
Before using liveness-verified attendance features:
- You must complete facial enrollment
- Enrollment confirms your identity and creates a biometric template
- You authorize us to store and use this template
- You may request deletion; however, liveness verification will no longer work
7.3 Liveness Detection
Liveness detection is used to:
- Verify that a real person (not a photo/video) is submitting attendance
- Prevent account compromise
- Ensure attendance authenticity
You acknowledge that:
- False positive (rejected when you are real) or false negative (accepted when you are not real) may occur
- In case of verification failure, contact your institution
- Liveness rejection does not prevent non-verified attendance submission (if allowed by institution)
8. Payment & Subscription Terms (If Applicable)
8.1 Payment Processing
If Attenova is offered on a paid basis:
- Payments are processed by third-party payment providers
- You must provide accurate payment information
- You authorize charges to your payment method
- Failed payments may result in service suspension
8.2 Refund Policy
Refunds are not provided for:
- Voluntary service discontinuation
- Charges incurred before account deletion
- Services already provided or consumed
- Downloadable data or records
Requests for disputes must be made to your payment provider or institution.
8.3 Institutional Billing
If your institution pays for Attenova on your behalf:
- You do not have payment obligations to Attenova
- Your institution's agreement with Attenova governs billing
- Account suspension may occur if your institution's account is in default
9. Disclaimers & Limitation of Liability
9.1 "As-Is" Provision
Attenova is provided "AS-IS" and "AS AVAILABLE" without warranties of any kind. We disclaim:
- Any implied warranties of merchantability, fitness for a particular purpose, or non-infringement
- Warranty that the Service will be uninterrupted, error-free, or secure
- Warranty that defects will be corrected or that the Service meets your expectations
9.2 Accuracy Disclaimer
We do not guarantee:
- Accuracy of GPS location data (may be affected by signal quality)
- Accuracy of biometric verification (biological variation and environmental factors affect accuracy)
- Real-time synchronization of attendance records
- Complete protection against fraud or unauthorized access
9.3 Technical Issues
We are not responsible for:
- Internet connectivity problems or network failures
- Device compatibility issues or software conflicts
- Data loss due to device failure, loss, or theft
- Interruptions or delays in service
- Issues caused by third-party services (Firebase, payment processors, etc.)
9.4 Third-Party Services
Attenova integrates third-party services including:
- Firebase (analytics, notifications, authentication)
- Payment processors
- Cloud hosting providers
We are not liable for:
- Failures or unavailability of third-party services
- Data breaches by third parties
- Terms, policies, or practices of third-party providers
- Your use of third-party services
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
DWS CODES LTD, its officers, directors, employees, and agents are NOT LIABLE for:
- Any indirect, incidental, special, consequential, or punitive damages
- Loss of data, revenue, profits, business opportunity, or goodwill
- Claims arising from delay or inability to use the Service
- Claims by your institution or third parties
- Damages even if we have been advised of the possibility
MAXIMUM LIABILITY CAP: Our total liability for any claim arising from or related to these Terms or Attenova shall not exceed the amount you paid (if any) for the Service in the 12 months preceding the claim, or $100 USD, whichever is less.
This limitation applies regardless of the legal theory (contract, tort, strict liability, or otherwise) and even if we have been advised of the possibility of damages.
11. Indemnification
You agree to indemnify, defend, and hold harmless DWS CODES LTD and its officers, directors, employees, and agents from:
- Any claims, damages, losses, or expenses arising from your use of Attenova
- Violation of these Terms or applicable laws
- Infringement of any third-party intellectual property rights
- Your submission of false or defamatory content
- Fraudulent or unauthorized activities on your account
You will assume full legal responsibility and cost of defense for any such claims.
12. Termination & Suspension
12.1 Our Right to Terminate
We may terminate or suspend your account immediately, without notice or liability, if:
- You violate these Terms or our Privacy Policy
- You engage in fraud, abuse, or illegal activities
- We reasonably believe continuation poses a risk to other users or our systems
- Your institution terminates their relationship with Attenova
- We cease operations
12.2 Your Right to Terminate
You may terminate your account at any time by:
- Deleting your account through the app settings
- Sending termination request to getattenova@gmail.com
- Upon termination, we will delete your data per our retention policy
12.3 Survival
Provisions that should reasonably survive termination remain in effect, including:
- Limitation of liability and disclaimers
- Indemnification obligations
- Intellectual property rights
- Dispute resolution and governing law
13. Privacy & Data Protection
Your use of Attenova is governed by our Privacy Policy. By accepting these Terms, you also accept our Privacy Policy.
Key privacy points:
- Biometric data is collected and processed for attendance verification
- GPS location data is collected for attendance validation
- Data is shared with your institution as necessary
- Data is retained per institutional and legal requirements
- You have rights regarding your personal data (see Privacy Policy for details)
14. Third-Party Integrations & Liability
14.1 Third-Party Services We Use
Attenova integrates with the following third-party services:
1. Firebase (Google)
- Provides: Push notifications, crash reporting, analytics
- Data shared: Push tokens, crash logs, app usage analytics
- Your data: NOT shared with Firebase (Firebase analyzes our aggregate data only)
- Liability: Google is responsible for Firebase's availability and security
2. Paystack (Payment Processing)
- Provides: Credit card processing and payment authorization
- Data shared: Payment amounts and transaction references ONLY (NOT card details)
- Your data: Card details are NEVER shared with us; Paystack handles directly
- Liability: Paystack is PCI DSS Level 1 certified and responsible for payment security
3. Google Maps & Google ML Kit
- Provides: Map display and on-device facial recognition
- Data shared: Coordinates (for maps only); face images processed on-device only
- Your data: Facial images are NOT sent to Google; face recognition runs on your device
- Liability: Google is responsible for Maps service availability
4. Cloud Hosting Providers
- Provides: Data storage, backups, and database hosting
- Data shared: Encrypted attendance, account, and payment records
- Security: Encrypted in transit and at rest
- Liability: Hosting provider responsible for infrastructure security
14.2 Disclaimer of Liability for Third-Party Services
You acknowledge that:
- Attenova is not responsible for third-party service outages or failures
- We cannot control third-party security practices or data breaches
- Third-party services are subject to their own terms and privacy policies
- If third-party service is compromised, we are not liable for damages
- We use commercially reasonable efforts to select and monitor third parties
Your remedy for third-party issues:
- Contact the third-party provider directly
- Attenova will assist in communication but cannot guarantee resolution
- You waive claims against Attenova for third-party service failures
14.3 Third-Party Data Sharing Agreements
We have executed Data Processing Agreements (DPAs) with all third parties that:
- Require them to protect your data with security measures meeting industry standards
- Restrict use of your data to specified purposes only
- Prohibit sharing your data with additional third parties
- Require notification if data is breached or misused
- Permit us to audit their security practices
Copies of DPAs available upon request via getattenova@gmail.com.
15. Biometric Consent & Enrollment
15.1 What Is Biometric Data
Biometric data means:
- Facial recognition and facial patterns
- Liveness detection results (proof you're a real person)
- Face embeddings (mathematical representation of your face)
- Does NOT include raw facial images (not stored)
15.2 Your Explicit Consent to Biometric Processing
By enrolling your face in Attenova, you explicitly consent to:
- Collection of your facial image on your device
- Processing of facial image to create a mathematical embedding
- Storage of the embedding (not the image) on our servers
- Use of the embedding to verify your attendance
- Liveness testing to prevent spoofing or fraud
- Server-side re-validation of all your attendance attempts
15.3 Biometric Consent for Minors
Attenova's account age requirement is 18 (see Section 2.1), and does not currently
collect date of birth or perform automated age verification. If a student on your
account is under 18:
- Your institution and parent/legal guardian are responsible for ensuring appropriate
consent is obtained before biometric enrollment
- You (or your parent/guardian) may withdraw biometric consent at any time — see
Section 15.4 — and we will delete the associated biometric data
If your institution requires a formal, verified parental-consent workflow for
biometric enrollment, contact getattenova@gmail.com.
15.4 Withdrawal of Biometric Consent
You can withdraw your biometric consent at any time:
- In app: Settings > Biometric Data > Delete Enrollment
- Via email: getattenova@gmail.com with subject "Withdraw Biometric Consent"
- Via phone: Call your institution's admin
Consequences of withdrawal:
- Your facial embedding will be permanently deleted within 24 hours
- You cannot mark liveness-verified attendance
- Your institution may disable attendance marking if biometric is required
- You can re-enroll anytime by repeating the enrollment process
15.5 Biometric Accuracy Disclaimer
You acknowledge that:
- Biometric matching is not 100% accurate
- Biological variation and environmental factors affect accuracy
- Liveness detection can be defeated with sophisticated spoofing
- We use industry-standard thresholds (95%+ similarity) but errors can occur
- False positives and false negatives may occur
- Your institution handles attendance disputes; we provide supporting data
15.6 Biometric Data Ownership & Rights
- You retain full ownership and rights to your biometric data
- You may NOT use Attenova to collect biometric data on other users
- You may NOT share your biometric enrollment with other accounts
- You may NOT attempt to reverse-engineer face embeddings
- Violation of these restrictions results in account termination
16. Offline Functionality Limitations & Data Risk
16.1 Offline Queue Explanation
When you are offline and mark attendance, the app:
- Captures your attendance submission (class/session reference, GPS
coordinates, access code, and face verification result) locally on your
device, in a local database stored in the app's private storage area
- Attempts to sync it as soon as connection is restored
- If sync fails, keeps retrying automatically on every reconnect, and holds
the item until it either syncs successfully or you dismiss it after the
server rejects it
16.2 Data Stored in Offline Queue
The offline queue stores, per pending submission:
- The class/chapel/hostel session it belongs to, and your access code entry
- Your attendance location coordinates (exact GPS) at the moment of capture
- Your face match score and liveness result for that attempt
- A submission timestamp
It does not store your authentication token, password, or other profile
information (name, email, ID) — those are never written to the local queue;
your session token is attached fresh, from secure storage, only at the
moment a queued item is actually sent to the server.
16.3 Security Risk of Offline Data
You acknowledge the following risks:
- Device Theft: If your phone is lost or stolen while you have unsynced
offline attendance data, someone with access to the device's storage could
potentially extract your pending attendance submissions (location and
face-match data). Your authentication token is not part of this risk, since
it isn't stored in the offline queue.
- Device Compromise: If your phone is hacked, jailbroken, or rooted, the
local database is not separately encrypted beyond the operating system's
own app-storage protections, so a compromised device could expose queued
data to a malicious actor with that level of access.
- Shared Devices: To reduce the risk of one person's unsynced data being
submitted under a different person's session on a shared device, the app
blocks logging out while you have unsynced offline data or no internet
connection, until that data has had a chance to sync under your own
session.
16.4 Your Responsibilities for Offline Data Protection
To reduce risk, you agree to:
- Enable device lock (PIN, password, or biometric)
- Keep your device software updated
- Avoid jailbreaking or rooting your device
- Sync regularly rather than leaving submissions queued for long periods
- Notify us immediately if your device is lost or compromised
16.5 Attenova's Offline Data Handling
We have implemented:
- Automatic sync as soon as a connection is available, with automatic retry
- Automatic removal of an item from the local queue once it syncs
successfully
- A logout block while unsynced offline data exists, so it isn't left behind
for someone else to trigger a sync of on a shared device
We do not currently apply device-level encryption to the local queue
beyond what the operating system provides to all apps by default, and we do
not currently auto-expire queued items after a fixed time period — an item
stays queued (and retried on every reconnect) until it syncs or you dismiss
it after a rejection. If your use case needs stronger local encryption,
contact getattenova@gmail.com.
We make no guarantee that:
- The offline queue is 100% secure
- Data cannot be extracted by a sufficiently sophisticated attacker with
physical device access
- Device-level compromise can be prevented
- We can recover data if a device is lost
16.6 Liability for Offline Data Compromise
If your device is compromised and offline data is extracted, you acknowledge:
- Attenova is not liable for data loss or unauthorized access
- You are responsible for device security
- We will investigate and remediate promptly if a security control here is
found to be inadequate
- Payment of breach-related costs (credit monitoring, etc.) is not our
responsibility beyond what's legally required
17. Payment Security & PCI DSS Compliance
17.1 How Payment Processing Works
When you make a payment:
- You enter payment details in the Attenova app
- App sends payment request to Paystack (NOT to Attenova servers)
- Paystack processes payment and returns authorization status
- Attenova stores only the transaction reference and status (NOT card details)
- You receive payment confirmation
CRITICAL: Attenova NEVER touches your card details. They go directly from your app to Paystack.
17.2 Card Data Security
You acknowledge:
- Attenova does NOT store, process, or transmit credit card details
- Paystack is PCI DSS Level 1 certified (highest standard)
- Card data is encrypted on your device during transmission
- We retain only transaction reference and amount (not card details)
- Paystack is responsible for card security, not Attenova
17.3 What We Store About Your Payments
Attenova stores:
- Transaction reference ID
- Payment amount
- Timestamp
- Payment status (successful, failed, pending)
- Your institution and semester
We do NOT store:
- Card number (any digits)
- Card expiry date
- CVV/security code
- Card holder name
- Card issuer
17.4 Payment Failure & Refunds
If payment fails:
- Contact Paystack support (we cannot process refunds)
- Paystack will investigate transaction
- Attenova will update status in your account
- Refunds processed by Paystack directly to your bank
We are not responsible for:
- Paystack's processing delays
- Bank delays in issuing refunds
- Card declines or transaction failures
- Fraud disputes (Paystack handles chargeback process)
17.5 Breach Notification for Payment Data
If payment data is breached:
- Paystack is PCI DSS Level 1, extremely unlikely to be compromised
- If Paystack is breached, Paystack will notify you and financial institutions
- Attenova's role is to ensure referential integrity (transaction records match Paystack records)
- We will audit logs and notify you if unauthorized payment creation is detected
17.6 User Responsibility for Payment Security
You agree to:
- Use a secure, unique password for Attenova account
- Never share your payment details via unsecured channels
- Report suspicious transactions immediately
- Monitor your bank statements for unauthorized charges
- Notify us immediately if account is compromised
18. Data Breaches & Security Incident Response
18.1 Potential Breach Scenarios
A data breach could occur through:
- Hacking or cyberattack on Attenova systems
- Compromise of third-party services (Firebase, Paystack, hosting)
- Accidental disclosure by Attenova staff
- Loss of device containing offline queue data
- Unauthorized access to your account (phishing, password reuse)
18.2 Our Breach Response
If a breach occurs:
- We will immediately isolate affected systems
- We will investigate scope and impact within 24-48 hours
- We will notify all affected users within 30 days (or as required by law)
- Notification will include:
- What happened
- What data was affected
- What you should do (e.g., enable 2FA, monitor accounts)
- Who to contact for questions
18.3 Your Rights After a Breach
If your data is breached, you have the right to:
- Free monitoring: Complimentary credit monitoring service (if applicable)
- Account freeze: Temporary suspension of account to prevent unauthorized access
- Identity theft insurance: Coverage for identity theft losses (where legal)
- Support: Dedicated support email for breach-related questions
- Legal consultation: Free consultation with privacy lawyer (where legal)
18.4 Limitation of Liability for Breaches
Despite our security measures, you acknowledge:
- No system is 100% secure
- Sophisticated attackers may bypass security controls
- We provide security "as-is" without guarantee of unbreachability
- In event of breach, our liability is capped at $100 USD or amount paid (see Limitation of Liability section)
- We are not liable for damages unless breach resulted from gross negligence
18.5 Your Breach Prevention Responsibilities
You agree to:
- Use a strong, unique password (minimum 12 characters, mixed case, numbers, symbols)
- Enable biometric or two-factor authentication
- Never share your login credentials
- Report suspicious account activity immediately
- Keep your device and OS updated
- Use secure WiFi (not public WiFi for sensitive transactions)
- Logout after use on shared devices
19. Dispute Resolution & Arbitration
19.1 Governing Law
These Terms are governed by the laws of Nigeria, without regard to its conflict of law principles.
19.2 Informal Resolution
Before pursuing formal legal action, you agree to:
- Send a written notice describing the dispute to: getattenova@gmail.com
- Good-faith negotiation for at least 30 days
- If unresolved, proceed to arbitration or litigation
19.3 Arbitration (Optional - Jurisdiction Dependent)
For jurisdictions permitting arbitration:
- You and Attenova agree to submit disputes to binding arbitration
- Arbitration shall be conducted under applicable international arbitration rules
- Arbitration shall be conducted in Nigeria
- Each party bears its own costs; Attenova may pay arbitrator fees
- You waive the right to jury trial and class action
19.4 Small Claims Court
Notwithstanding arbitration, either party may pursue small claims in small claims court.
19.5 Equitable Relief
You acknowledge that violation of these Terms may cause irreparable harm for which monetary damages are inadequate. Attenova is entitled to seek equitable relief (injunction, specific performance) in addition to other remedies.
20. Amendments & Updates
20.1 Policy Changes
We may modify these Terms at any time. Material changes will be communicated via:
- In-app notification
- Email to your registered account email
- Updated "Last Updated" date at the top of this document
Your continued use after notification constitutes acceptance of changes.
20.2 Right to Refuse
If you do not accept updated Terms, you must discontinue use of Attenova and request account deletion.
21. Severability
If any provision of these Terms is found to be unenforceable or invalid, that provision will be modified to the minimum extent necessary to make it enforceable, or if impossible, severed. The remaining provisions remain in full force and effect.
22. Entire Agreement
These Terms, together with our Privacy Policy and any other agreements between you and Attenova, constitute the entire agreement regarding Attenova and supersede any prior agreements, understandings, or negotiations.
No employee, representative, or agent of Attenova has authority to make promises, representations, or agreements not expressly stated in these Terms.
23. Contact Information
For questions about these Terms:
- Email: getattenova@gmail.com
- Support: getattenova@gmail.com
- Mailing Address: Attenova, Nigeria
Response Time: We will respond to inquiries within 5-10 business days.
24. Non-Waiver
Failure to enforce any provision of these Terms does not constitute a waiver of that provision or the right to enforce it later.
25. Notices
All notices from Attenova may be:
- Posted on the Service
- Sent via email to your registered email address
- Delivered to your institution's administrator
- Notices are effective upon posting/sending
By using Attenova, you acknowledge that you have read, understood, and agree to these Terms & Conditions in their entirety.
Last Updated: August 14, 2026