Security & compliance

Where your biometric attendance data lives, and who can touch it

Biometric attendance deserves a precise data inventory, not a trust-us page. This explains the formats AionHRMS receives from different terminals, where the data is used, what authorised users can see, how long it is retained and what to ask before deployment.

AionHRMS receives the enrolment format supplied by each supported terminal. Fingerprint terminals normally supply vendor-specific mathematical templates. Face devices may supply a face template, and some supported face-enrolment or cross-device-sync workflows also use a face photograph or an employee profile photograph. Raw templates are not displayed, included in ordinary attendance exports or exposed through the partner API; profile photos can be visible to authorised users and sent to compatible terminals. Attendance and enrolment data is hosted in India by default, access is role-scoped, and the customer organisation determines the lawful basis, notice and retention rules for its workforce. Archiving an employee retains the record; deletion is a separate request and may be limited by legal or contractual retention requirements.

Exact inventory

templates, plus face/profile photos where a terminal workflow requires them

In India

data on Indian infrastructure by default; Europe for EU/UK customers where compliance requires it

No Aadhaar

AionHRMS attendance does not require an Aadhaar number or Aadhaar authentication

Scoped

role-based access for people, hashed scoped keys for software

01

What is actually collected — and what is not

For each employee the service can hold the profile entered by the employer, device-enrolment payloads and punch records. The enrolment payload depends on the terminal model and protocol, which is why a universal 'templates only' promise would be inaccurate.

  • Fingerprint devices normally provide vendor-specific mathematical templates, not photographs of fingers
  • Face devices may provide a mathematical template; some supported face workflows also provide a JPEG face photo
  • An employee profile photo may be stored in the profile and pushed to a compatible face terminal
  • AionHRMS does not require an Aadhaar number or connect routine attendance to Aadhaar authentication
  • Punches record facts about presence, not location tracking: a person, a terminal, a moment, a method
02

How enrolment data is used and exposed

Device enrolment data exists to verify people at a terminal and, for compatible formats, synchronise enrolment between terminals. The product separates those payloads from ordinary attendance reporting.

  • Stored centrally where supported; reuse on a replacement depends on matching template formats
  • Raw fingerprint and face templates are not rendered in product screens
  • Raw templates and stored face-enrolment payloads are not included in ordinary attendance exports or exposed by the partner API
  • Profile photos can be viewed by authorised users as part of an employee record
  • Archiving or blocking retains enrolment data; a deletion request is handled separately under the agreed retention requirements
03

Access control on the data itself

The register is only as private as the weakest login that can read it, so access is scoped at every layer — human and machine.

  • Role-based access: a branch administrator sees their branch; payroll figures require the payroll permission
  • Browser and API traffic uses HTTPS; sessions are authenticated per user rather than through a shared login
  • Some legacy biometric terminals cannot use TLS and send their vendor protocol over HTTP; network controls should be agreed during deployment
  • API access via scoped keys — read and write separated, shown once, stored only as a SHA-256 hash
  • Per-key rate limits, quotas and a full request log, revocable instantly
  • Within our team, production access is limited to the people who operate and support the service
04

The company behind the data

Security claims are only as good as the organisation making them, so here are AIONDATA's credentials with their exact qualifiers — the wording matters, and we keep it precise.

  • ISO 9001:2015 — certified quality management system
  • CMMI Level 3 — appraised: a defined, documented engineering process
  • SOC 2 Type II — ready: controls prepared; stated as readiness, not an issued attestation
  • GDPR and HIPAA — ready, same precise sense
  • Engineering in Noida, headquarters in California; the people who build the system support it
05

Your obligations, our role — plainly

Whether biometric attendance is appropriate, and the legal basis and notice it requires, depends on the organisation, workforce and jurisdiction. The division of duties should be documented rather than assumed; this page is product disclosure, not legal advice.

  • The customer organisation determines its lawful basis and normally acts as data fiduciary for employee data; obtain deployment-specific legal advice
  • Give staff the notices and choices required for the specific deployment and explain the device formats in use
  • Use the data for attendance, access and payroll — the purposes stated — and nothing else; we do the same
  • Document retention, archive and deletion rules before enrolment; an archived employee is not a deleted employee
  • Attendance is exportable while your account is active and on request when ending a subscription
  • We do not sell, share or mine your data; there is no advertising business attached to your register

Questions to put to any attendance vendor — with our answers

QuestionAionHRMSCommon answer elsewhere
What biometric formats are stored?Fingerprint/face templates; some face workflows also use face or profile photos.Ask for a model-specific answer.
Who can view biometric data?Raw templates are not shown or exported; authorised users may view employee profile photos.Ask separately about templates, photos and exports.
Where is the data stored?Infrastructure in India by default; Europe for EU/UK customers where compliance requires it.An office PC, or a cloud with no stated residency.
What happens on employee exit?Block/archive retains records; deletion is a separate retention-controlled request.Ask how software and every terminal are handled.
Company certifications?ISO 9001:2015 certified; CMMI L3 appraised; SOC 2 / GDPR / HIPAA ready.Rarely published for attendance software.
Can we take our data out?Yes — exportable, and stated in writing.Ask, and get it in writing before you sign.

Frequently asked questions

Is biometric attendance safe for employees?

It can be deployed responsibly when the organisation minimises the data, documents a lawful basis, gives the required notice, restricts access, secures the device network and applies a defined retention/deletion process. Ask for model-specific disclosure because face and fingerprint terminals do not all use the same enrolment format.

Does AionHRMS store fingerprint or face photos?

Fingerprint terminals normally supply mathematical templates rather than finger photographs. Face formats vary: some devices supply templates, while some supported face-enrolment and sync workflows use a face photo. Employee profile photos may also be stored and pushed to compatible devices. These distinctions are documented here so buyers can make an informed decision.

Is employee consent required for biometric attendance in India?

The required lawful basis, notice, consent or other obligations depend on the organisation and deployment. Treat biometric and attendance information as personal data, document the purpose and retention rules, and obtain legal advice for your workforce rather than relying on a software vendor's generic statement.

Is attendance data shared with anyone?

No. Your data is processed to run the service for you — attendance, access and payroll — and for nothing else. It is not sold, not shared across customers, and not mined for any other business. Within our team, production access is limited to the people who operate and support the service.

Is AionHRMS SOC 2 certified?

Precisely: AIONDATA is SOC 2 Type II ready — controls prepared, stated as readiness rather than an issued attestation — alongside GDPR and HIPAA readiness, ISO 9001:2015 certification and a CMMI Level 3 appraisal. We keep those qualifiers exact because a security page that inflates its own certifications has told you everything about its other claims.

Security you can explain to your own employees

A precise data inventory, India residency by default, scoped access and explicit retention. Ask us for the model-specific data flow before deployment.