Evidence and notices
Choose which evidence clock-ins record (face, selfies, location), on what basis, what employees are told, and how long it's kept.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
A clock-in always records who, where, when and how. Evidence is anything more: a face match at the kiosk, a selfie, or the phone's location check. Your organisation is the data controller and decides what to record, under the Data Protection Act, 2012 (Act 843). Agoo gives you the switches and keeps the records that show what you decided and what each employee was told.
The three evidence types
| Evidence | Records | Plans |
|---|---|---|
| Face | That the kiosk matched the employee's face. The template stays on the kiosk; Agoo never receives it. See Face clock-in. | Growth and above |
| Selfie | A photo taken with a QR, PIN, NFC or phone punch. Off, optional or required. Its metadata (including any GPS location) is removed when it's stored. | Starter and above |
| Location | With phone clock-in: whether the phone was inside the site's geofence (or on its Wi-Fi), and the fix's accuracy. Optionally the coordinates, and the Wi-Fi network's name and address. | Starter and above |
All three are off until you turn them on in Console → Attendance → Settings. Sites can narrow or widen what the organisation allows.
Notices and basis
Before an evidence type can be switched on, you publish a notice: the plain explanation employees see of what is recorded, why, where it's kept and for how long. Each notice has a basis:
- Required by the organisation. You record your legal basis: the employment contract, a legal obligation, or your legitimate interests (Act 843, section 37(3)). Employees acknowledge the notice. Capture goes ahead whether or not they have acknowledged it yet, and they can't opt out. Console lists everyone who hasn't acknowledged the current version.
- Employee consent. Only employees who consent have that evidence recorded. Without consent it isn't captured, and a method that needs it isn't offered to them: they use another method, or the kiosk's fallback. They can withdraw consent at any time, and new capture stops at once.
Required is the default when you turn an evidence type on. Publishing a change makes a new version; employees then acknowledge (or consent to) that version. Notices, acknowledgements, consents and withdrawals are all kept with their dates, how they were given and who recorded them, and are written to the audit trail.
Only Owners and Admins, who hold the Data & privacy permission, can publish notices or change retention. API keys can't.
How long evidence is kept
| Evidence | Kept by default | You can choose |
|---|---|---|
| Selfies | 90 days | 1 day to 10 years, or until deleted |
| Coordinates | 90 days, then cleared from the punch | 1 day to 10 years, or until deleted |
| Location check result and accuracy, Wi-Fi match | With the punch, for your attendance retention (7 years by default) | |
| Face match result | With the punch |
Withdrawing consent stops new capture; evidence already recorded is kept until its retention date. A data subject request can still erase it. A legal hold pauses deletion for what it covers.
In the API
GET /attendance/settingsandPATCH /attendance/settingsread and change methods, evidence, notices and retention.GET /people/{person_id}/attendance-evidenceshows a person's status and the kiosks they're enrolled on;POSTrecords an acknowledgement or consent from a paper form or your HR system.GET /attendance/evidencelists everyone's status, such as who hasn't acknowledged the current notice.- Punches carry
selfie_file_id,location,wifiandface_checkonly when they have them. In consent mode, evidence for someone who hasn't consented returnsconsent_required.