Privacy Policy
Last updated: September 2026
Workino is an employee attendance system that organizations run for their staff. This policy explains what the app and the management console collect, why, who can see it and how long it is kept.
1. Who is responsible for your data
Workino is sold to organizations, not to individuals. If you are an employee using the app, your employer is the data controller: they decided to use the system, they configured it — work sites, shifts, location policy and retention periods — and they decide what happens with the data.
Drubit Raid Ltd operates the service on their behalf and processes the data only on their instructions. We do not sell personal data, we do not use it for advertising, and we do not pass it to third parties other than the sub-processors listed below.
2. What we collect
The data comes from two places: what your employer enters about you, and what is created when you report attendance.
| Category | What it includes | Source |
|---|---|---|
| Employee details | First and last name, employee number, phone number and email address as applicable, role and permissions, site, department and team, shift template, hire date and interface language. | Your employer |
| Attendance reports | Clock in, break start, break end and clock out — with a server timestamp and the device timestamp, the break type, and any note you added. | You |
| Location | Latitude, longitude and accuracy, captured at the moment of a report only, plus the computed distance from the work site and the result (inside or outside). See section 3. | You |
| Device details | A random identifier generated at install, the platform (iOS or Android), OS version, app version, and the device name at sign-in. | The app |
| IP address | Recorded alongside attendance reports for security and troubleshooting, and erased together with location data. | The app |
| Tasks and corrections | Daily tasks assigned to you, completion and notes, and correction requests you file including the reason. | You and your employer |
| Notifications | A device notification token, so we can send you reminders and messages. | The app |
| Audit log | A record of administrative actions: who changed what and when, including the value before and after. | The system |
We do not collect contacts, photos, recordings, browsing history or data from other apps on your device.
3. Location — exactly when, and what is kept
Location is the most sensitive part of any attendance system, so it is deliberately constrained. Location is read only at the moment you report — clocking in, starting or ending a break, or clocking out. Each report produces exactly one reading.
- No continuous sampling, no route. The system does not know where you were between one report and the next, and keeps no movement history.
- No background permission. The app requests foreground location only. Closed or running in the background, it has no access to your location.
- Reporting does not depend on it. If permission was denied, location services are off or no reading was obtained, the report is recorded as “location unavailable”. Only if your employer chose a blocking policy will a report from outside a site be rejected.
- Last known position. If a fresh reading does not arrive within eight seconds, the app may use the last position the device already had, provided it is less than ten minutes old.
- What is derived. The server computes the distance to the work site and stores the result. That result remains even after the coordinates themselves are erased.
The system is not a safety or location-finding tool. Do not rely on it in an emergency.
4. What we use it for
- Recording working hours, breaks, overtime, lateness and absence, and producing attendance reports for your employer.
- Verifying that a report was made at the work site, according to the policy your employer configured.
- Sending a one-time sign-in code by SMS and keeping the account secure.
- Sending reminders and alerts — for example that you have not clocked in, or forgot to clock out.
- Managing daily tasks and correction requests.
- Operating, securing, backing up and troubleshooting the service.
The basis for processing is your employer’s need to manage the employment relationship and meet its legal obligations, and for us, the performance of our contract with them. We do not profile you and we make no automated decisions with legal effect.
5. Who sees what
- You see your own reports, hours, breaks, tasks and corrections.
- Your manager sees only the employees within their scope — a team, a department or a site, as configured.
- An organization admin sees the whole organization.
- Exact coordinates are shown only to those explicitly granted that permission, and every such view is written to the audit log. Without it, a manager sees only the result: inside the site, or outside it.
- We access data only to operate, back up, secure or troubleshoot the service, and only to the narrow extent needed.
Every organization is isolated from every other. Nobody in one organization can see another organization’s data.
6. How long we keep it
Some of these periods are set by your employer in the organization settings. These are the defaults:
| What | How long |
|---|---|
| Location coordinates and IP address | Erased from the record after 90 days (your organization can change this). The result of the check — inside or outside the site — is kept. |
| Attendance reports, hours and breaks | For as long as the organization is our customer, and in line with the retention duties that apply to the employer under labour law. |
| Audit log | 730 days (your organization can change this). |
| Generated export files | 30 days (your organization can change this). |
| Notifications sent | 90 days. |
| SMS sign-in codes | Stored hashed only, and expire after five minutes. |
| Sessions and sign-ins | Deleted 30 days after they expire or are revoked. |
When our engagement with an organization ends we delete or return the data on their instruction. See also account and data deletion.
7. Sub-processors
We rely on a small number of providers to run the service:
| Provider | Purpose | What it sees |
|---|---|---|
| Our hosting provider (Vultr / The Constant Company) | Servers and database | All data, on servers in Israel |
| Cloudflare | Attack protection and traffic acceleration | Network traffic to the service, including IP address |
| SMS provider (currently Twilio) | Delivering one-time sign-in codes | The phone number and the message text |
| Expo, and behind it Apple and Google | Delivering push notifications | The notification token and the message |
We use no advertising tools, ad networks or commercial behavioural analytics.
8. Security
- All traffic is encrypted with TLS.
- Passwords are stored as argon2id hashes; SMS codes are stored hashed only.
- Sign-in tokens rotate on every use, and reuse of an old token invalidates the session.
- Permissions are enforced on the server for every request, not only in the interface.
- Administrative actions are written to an audit log with the value before and after.
- Staff access to customer data is restricted and controlled.
No system is completely immune. If we become aware of a breach we will act as the applicable law requires and notify the organizations concerned.
9. Where the data is stored
Workino’s servers and database are hosted in Israel. Some sub-processors — SMS delivery, push notifications and traffic protection — operate outside Israel, so the data those services need (phone number, notification token, IP address) may be transferred to them. Our agreements with them include data protection commitments.
10. Your rights
Under Israeli privacy law, and where relevant under European law, you have the right to access your data, to ask for it to be corrected and to ask for it to be deleted.
Because your employer is the controller, your first request should go to them — they are the only ones who can decide to change or delete attendance records. If you come to us directly, we will pass the request to your employer and help them handle it.
Inside the app you can review your own attendance history and file a correction request for a report that is wrong. For privacy enquiries: [email protected].
11. Age of users
Workino is intended for use within an employment relationship only. It is not directed at children, and we do not knowingly collect data from anyone other than employees enrolled by their employer.
12. This website
The marketing site you are reading uses no tracking cookies and loads no fonts, scripts or images from third parties — everything is served from our own server, and your language choice lives in the page URL alone. The protection network the site is served through (Cloudflare) adds a measurement script of its own, which counts page views without cookies and without identifying you personally.
The browser-based management console uses local storage to keep you signed in and to remember your display preferences. These are necessary to operate it and are not used for tracking.
13. Changes to this policy
We may update this policy from time to time. The updated version will be posted on this page with a new date, and we will notify customer organizations of any material change.
14. Contact
For questions about this policy, about your data, or to exercise your rights: [email protected].
26 Harokmim St., Holon 5885849, Israel
Phone: +972 74-703-4060
Email: [email protected]