This is an interim privacy policy. It reflects how enwitness is designed to handle personal information and applies while our pre-launch legal review is completed. It will be replaced by a final policy before commercial launch.
1. About this policy
This privacy policy explains how enwitness collects, holds, uses and discloses personal information, and how you can access and correct that information or make a complaint.
enwitness is a proof-of-presence platform. Small Bluetooth beacons, NFC tags or scan codes are placed at checkpoints in buildings, and a worker’s phone confirms they were present at those checkpoints while working. We provide the platform; the companies and buildings that use it decide how it is deployed.
For our New Zealand operations we act consistently with the Privacy Act 2020 (NZ) and its information privacy principles.
2. A witness, not a tracker
Three commitments shape everything below.
- Presence is only recorded at checkpoints. The system records that a worker’s phone was near a specific beacon, tag or code at a specific time. It does not use GPS and does not follow anyone between checkpoints or outside work.
- Recording only happens on shift. Presence detection operates only while a worker is logged in and marked available. When a worker is off shift or logged out, no presence is recorded.
- Workers can always see their own record. Every worker can view their own visit history in the app at any time.
3. What personal information we collect
- Account details - name, email address, phone number, role, employer or building association, and login records.
- Presence records (workers) - the checkpoint, date, time, duration and detection method (beacon, NFC or scan) of visits recorded while on shift. We treat presence records as our most sensitive data class and apply our strongest protections to them.
- Issue reports - descriptions, severity, optional photos and the checkpoint location, where a worker reports an issue through the app. Photos may incidentally include people or worksites.
- Consent records - the timestamped acknowledgement of the privacy notice shown to workers on first login, including the version acknowledged.
- Support and contact data - messages, attachments and contact details when you contact us, request a demo through our website, or use in-app support.
- Billing details - business contact and payment information for customers. Card payments are processed by our payment provider; we do not hold full card numbers.
- Website data - standard technical information such as IP address, browser type and pages visited when you use our website.
We do not knowingly collect sensitive information such as health or biometric information, and our platform is not designed to record it.
4. How we collect it
- Directly from you - when you create an account, use the app, submit a form on our website, or contact us.
- From your employer or the company you work for - which sets up worker accounts and site assignments.
- Automatically through the app - presence records generated when your phone detects a checkpoint while you are on shift.
Workers are shown a plain-language privacy notice, in their own language, before presence recording begins, explaining exactly what is recorded and when. The notice must be acknowledged, and any updated notice must be re-acknowledged.
5. Why we collect, hold and use it
- To operate the platform - recording and reporting verified presence, schedules, compliance and issue reports for the buildings and companies that use enwitness.
- To provide an audit trail - the core purpose of the platform is a reliable record that work occurred, available to the parties entitled to see it.
- To administer accounts, billing and support.
- To keep the platform secure - detecting misuse, fraud and anomalies.
- To meet our legal obligations.
We do not sell personal information. We do not use worker presence records for advertising or marketing, and we never will.
6. Artificial intelligence
We may use artificial intelligence (AI) and machine-learning technologies, including automated processing and generative tools, across our business, and we may use personal information to do so. This may include using AI to develop, provide, operate, improve, personalise, secure and support our products, services and websites; to understand and analyse how they are used; to detect and prevent fraud, misuse and security incidents; to assist our team and operations; and to generate or help generate responses to enquiries and communications. These technologies may be operated by us or by third-party providers acting on our behalf, in Australia or overseas.
Any personal information processed using AI is handled in accordance with this policy and applicable laws, and we take reasonable steps to use AI systems safely and responsibly. Consistent with the rest of this policy, we do not sell personal information, and worker presence records are not provided to third parties to train their AI models.
7. Who can see worker presence records
A worker’s presence records are visible to their own company and, where configured, to the building or building manager for the sites they service.
A worker’s identity is not linkable across unrelated companies. If a worker works for two different companies on the platform, each company sees only its own records.
Access to presence records by our own staff is restricted and logged at the record level - we audit who looked at whose movements.
8. Our role: platform provider, not employer
For worker data, the company that engages the worker is responsible for how the data is used. enwitness provides the platform and processes data on that company’s behalf.
Companies must inform their workers about the use of enwitness and comply with privacy and workplace law, and they accept this obligation as a condition of using the platform.
If you are a worker and want access to, correction of, or deletion of your information, your employer handles the request and we provide the tools - including a full export of your account details, visit log, issue reports, photos, consent record and company access history.
If you contact us directly, we will help route your request to the right company, and we remain responsible for the information we hold in our own right, such as website and support data.
9. Disclosure to third parties
We disclose personal information only where needed to run the service, and only the minimum each provider requires. This includes service providers for hosting, payment processing, email delivery, SMS delivery and support tooling, and professional advisers, regulators and law enforcement where required or authorised by law.
Worker presence records are never sent to third parties beyond the minimum a specific platform feature requires, and are never used to train third-party AI models.
Some of our service providers are located overseas, including in the United States. Where personal information is disclosed overseas, we take reasonable steps to protect it, including data-processing agreements with those providers.
10. Storage and security
We hold personal information in secure, access-controlled systems. Measures include encryption of data in transit and at rest, application-level encryption of the most sensitive records, tenant isolation so each customer’s data is segregated, multi-factor authentication for administrative access, record-level audit of access to presence data, and vulnerability management of our software supply chain.
No system is perfectly secure, but if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the relevant regulator in accordance with applicable law.
11. How long we keep it
We keep personal information only as long as needed for the purposes above, including the platform’s audit-trail purpose and our legal obligations. Presence records carry the shortest retention that the audit and dispute-resolution purpose can justify. Specific retention periods are being finalised as part of our legal review and will be published in the final version of this policy.
When a worker leaves a company, their app access for that company ends immediately. Historical records are retained read-only as part of the building’s audit trail, and a company can de-identify a departed worker so that records remain but the personal link - name, email, phone, photo - is permanently removed.
Where records must be kept for legal or evidentiary reasons, we anonymise rather than delete.
12. Access, correction and deletion
You may request access to or correction of the personal information we hold about you, or ask us to delete it. We verify requests, for example by a one-time code to your registered email, and aim to respond within 30 days. Worker requests about presence records are handled through your employer as described in section 8.
There is no charge for making a request. If we refuse a request, we will tell you why and how to complain.
13. Marketing
We may send customers and prospective customers information about enwitness where permitted by law. Every marketing message includes a working unsubscribe, and opting out never affects use of the platform. Worker data is never used for marketing.
14. Cookies and website analytics
Our website uses cookies. Some are essential to make the site work. We also use Google Analytics, a service provided by Google, to understand how the site is used - such as which pages are visited and how visitors move through the site - so we can improve it. Google Analytics sets its own cookies.
Analytics data is used in aggregate and is not used to identify you personally. Where local rules require it, such as in the United Kingdom, analytics load only after you accept our cookie banner, and you can reopen that banner from the footer to change your choice. You can also control or delete cookies through your browser settings; blocking essential cookies may affect how the site works.
15. Complaints
If you have a concern about how we have handled your personal information, contact us using the details on our contact page. We will acknowledge your complaint, investigate, and respond.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
16. Changes to this policy
We may update this policy from time to time. The current version is always available on this page, with the date last updated shown at the top. Material changes affecting workers trigger a fresh in-app notice and re-acknowledgement.