1.Who this policy is for
This policy is published by The Reciprocal Solutions, the developer of Fusion HRM (Employee Self-Service (ESS) mobile app), distributed on Google Play as com.thereciprocalsolutions.ess_portal. In this policy, “we”, “us” and “our” mean The Reciprocal Solutions; “you” means the person using the app.
Fusion HRM is workplace software. You will normally be using it because your employer has licensed the Fusion HRM platform and has issued you an account. The app is the phone companion to that platform: it shows you your own employment record and lets you record attendance, file requests and, if your employer has given you that responsibility, decide other people’s requests.
Accounts are created by your employer
You cannot sign up for Fusion HRM yourself. Accounts are created by your organisation’s HR or IT administrators, and are closed by them.
2.Your employer’s role, and ours
Under data-protection law there is a difference between the organisation that decides what is collected and why, and the organisation that handles it on their behalf.
- Your employer is the data controller. They decide which modules are switched on, whether face verification and geofencing are required, what your employment record contains, who may see it, and how long it is retained. Their own employee privacy notice governs that.
- We are the data processor. We host and operate the software and act on your employer’s documented instructions. We do not decide what to do with your employment data on our own account.
The practical consequence: if you want your record corrected, restricted or erased, the request is usually one your employer must action, and we will help them do it. Section §14 Your privacy rights explains how to reach either of us.
3.What data the app collects
The table below lists every category of personal data the app accesses, collects or transmits, and why. It is written to correspond directly to the Data safety disclosure on our Google Play listing.
| Category | What it includes | Why it is needed | Required? |
|---|---|---|---|
| Account and identity | Name, work email address, employee code, job title, department, branch, role, profile photo, preferred language. | To sign you in, show your own record, and decide which screens and approvals you may see. | Required |
| Employment records | Attendance and shift history, leave balances and requests, overtime, reimbursements, advances and loans, projects, documents, appraisals, notifications. | These are the records the app exists to show you and let you act on. | Required |
| Face data (biometric) | A numeric face template derived from your photo, a quality score, and — where your employer keeps punch evidence — the photo itself. | To confirm that the person recording a punch is you, where your employer has switched face verification on. | Only if your employer enables face verification — see §5 |
| Precise location | The GPS coordinates of your device at the moment you record an attendance punch. | To confirm a punch was made inside your branch’s permitted area, where your employer has switched geofencing on. | Only if your employer enables geofencing — see §6 |
| Photos and files you submit | Photos taken in the app, and documents you attach to a request — payslip queries, claim receipts, ID or visa copies, bank letters. | To carry the evidence your employer’s process asks for alongside the request it belongs to. | Only when you choose to attach something |
| Financial information | Payslip amounts, salary components, bank account details you submit through a bank-change request, loan and advance balances. | To show you your own pay records and to route a bank-detail change for approval. | Required for payroll features |
| Device and diagnostic data | App version, operating-system version, device model, timezone, IP address, and server-side logs of requests the app makes. | To keep the service secure, diagnose faults, and detect misuse of an account. | Required |
Some categories are sensitive personal data — in particular face data, precise location, bank and salary details, and any identity or immigration documents you upload. They are treated accordingly: collected only for the purpose named above, visible only to the people your employer authorises, and never disclosed publicly.
4.Device permissions the app requests
The app asks for a permission at the moment it is first needed, with an explanation on screen, and it works without the optional ones — a refused camera or location permission stops the feature that needs it, not the app.
Camera
To take the photo that accompanies a check-in, check-out or lunch punch, and to photograph a document you are uploading. The camera is opened only by your own tap and never runs in the background.
Location (precise and approximate)
To attach a GPS fix to an attendance punch when your branch has geofencing switched on. Location is read at the moment of a punch only — the app does no background or continuous location tracking.
Photos and files
To let you pick an existing photo or document to attach to a request. The app reads only the file you select.
Internet and network state
To reach your employer’s Fusion HRM server. The app is a client for that server and does nothing offline beyond caching what it has already shown you.
What the app does not access
The app does not read your contacts, your call logs, your SMS messages, your calendar, your microphone, your installed-app list, or any file you have not explicitly chosen. It does not track you across other apps or websites, and it contains no advertising identifier.
5.Face data and attendance photos
Face verification is off unless your employer switches it on. Where it is on, this is exactly what happens.
- Enrolment. You are asked once to register your face. The photo is sent over an encrypted connection to your employer’s Fusion HRM server, which converts it into a numeric face template — a mathematical vector. The template cannot be turned back into a photograph of you.
- Each punch. The app opens the camera, you take the photo, and the server compares a template derived from it against your enrolled template. The result is a match or no match. Where your employer keeps punch evidence, the photo is also stored against that attendance record so that a disputed punch can be reviewed.
- Where it lives. The template and any stored photos are held in your employer’s Fusion HRM database and file storage. They are linked to your employee record and to nothing else.
- What it is never used for. Face data is used only to confirm attendance. It is not used for surveillance, emotion or demographic inference, advertising, or training any machine-learning model, and it is never shared with a third party for those or any other purposes.
- Deletion. Your face template and photos are deleted when your employee record is deleted, and can be deleted on request at any time — see §13 Deleting your account and your data. Deleting them stops face-verified punching until you enrol again.
If you do not want to provide face data
Whether face verification is mandatory for your role is your employer’s decision, not ours. Raise it with your HR team; the platform supports attendance without it, and your employer can switch you to a non-biometric method.
6.Location data
Location is collected only at the instant you record an attendance punch, and only where your employer has enabled geofencing for your branch. The coordinates are stored on that single attendance row so it can be shown that the punch was made inside the permitted area.
The app does not collect location in the background, does not collect it while it is closed, and does not build any history of your movements beyond the punches you yourself make. Your phone’s operating system shows an indicator whenever location is read, and you can withdraw the permission at any time in the system settings — a punch will then be refused if your employer requires a location fix for it.
7.How the data is used
Data in the app is used for these purposes and no others:
- Authenticating you and keeping your session secure.
- Showing you your own attendance, leave, payroll, reimbursement and loan records.
- Submitting your requests and routing them to the right approvers.
- Letting you decide other people’s requests, where your employer has authorised it.
- Verifying attendance punches, where face verification or geofencing is switched on.
- Sending you notifications about your own requests and records.
- Keeping the service available, diagnosing faults, and investigating misuse or fraud.
- Meeting your employer’s legal obligations, such as payroll and statutory records.
We do not use your data for automated decision-making that produces a legal or similarly significant effect on you without a human being in the loop; approvals in Fusion HRM are made by people.
8.Legal basis for processing
Where data-protection law requires a legal basis to be identified, the bases relied on by your employer, and by us acting on their behalf, are typically:
| Basis | Where it applies |
|---|---|
| Performance of your employment contract | Attendance, leave, payroll and related records. |
| Legal obligation | Statutory payroll, tax, wage-protection and employment records. |
| Legitimate interests | Keeping the service secure, preventing attendance fraud, and diagnosing faults — balanced against your rights. |
| Consent | Optional features such as face enrolment, where your employer offers it as a choice. Consent can be withdrawn. |
For users in India this policy is intended to operate consistently with the Digital Personal Data Protection Act, 2023; for users in Oman, with the Personal Data Protection Law (Royal Decree 6/2022); and where the GDPR applies, with that Regulation. Your employer’s own notice identifies the basis applicable to you.
10.What we never do
We do not sell your personal data to anyone, for any price.
We do not share your data with advertisers or data brokers.
The app contains no advertising SDK and no cross-app tracking.
We do not publicly disclose financial, payroll or bank information.
We do not use your employment data, photos or face templates to train AI models.
We do not read data on your device other than what you choose to submit.
11.How the data is protected
- All traffic between the app and the server uses HTTPS with modern TLS.
- Your session token is stored in the device’s hardware-backed secure storage (Android Keystore / iOS Keychain), not in plain preferences.
- Passwords are stored only as salted one-way hashes; nobody at The Reciprocal Solutions can read them.
- Access inside the app is enforced server-side by role, branch and department scope — the app never draws a control the server would refuse.
- Uploaded files are held in access-controlled object storage, not on a public URL.
- Administrative actions on employment records are logged for audit.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify your employer without undue delay so that they, as controller, can meet their notification duties — and we will support that notification.
12.How long data is kept
Retention is set by your employer, because employment records carry statutory minimum retention periods that differ by country. As a general rule:
| Data | Kept for |
|---|---|
| Employment, attendance and payroll records | As long as your employer’s policy and local law require, typically for a period after you leave. |
| Face templates and punch photos | While face verification is active for you; deleted with your employee record, or earlier on request. |
| Attendance location coordinates | With the attendance record they belong to. |
| Documents you upload | Until you or your employer delete them, or the record they attach to is deleted. |
| Session tokens on your device | Until you sign out, the session expires, or you uninstall the app. |
| Server logs and diagnostics | A short rolling window, then deleted or anonymised. |
13.Deleting your account and your data
Because your account belongs to your employer, deletion requests are actioned through them. There are two routes, and both work:
Through your employer
Ask your HR or IT administrator to close your account or delete specific data. They can do this from the Fusion HRM web portal, including deleting your face enrolment on its own.
Directly to us
Email privacy@thefusionapps.com from your work address with the subject “Account deletion request”, naming your employer. We acknowledge within 7 days and act within 30, after confirming the request with your employer as controller.
What deletion covers. Your login, profile, face template and enrolment photos, uploaded documents and app notifications are erased. What it does not. Records your employer must keep by law — payroll registers, statutory attendance and wage records, and anything under legal hold — are retained by them for the required period, and financial records already posted to an accounting system cannot be unwound. Backups age out on their own schedule, within 90 days.
Uninstalling the app removes the copy of data cached on your phone, but does not by itself delete your record on your employer’s server.
14.Your privacy rights
Subject to the law that applies to you, you have the right to ask for access to your personal data, correction of what is inaccurate, erasure, restriction of or objection to certain processing, a portable copy, and withdrawal of any consent you gave — withdrawal does not affect processing already carried out.
Start with your employer. They hold the record and are the controller, so they can usually answer faster. If they do not respond, or your request concerns how we operate the platform itself, write to privacy@thefusionapps.com. We will not charge you, and we will not discriminate against you for exercising a right.
You may also complain to your local data-protection authority — in India the Data Protection Board, in Oman the Ministry of Transport, Communications and Information Technology, or in the EEA/UK your national supervisory authority.
15.International transfers
Your data is hosted in the region your employer’s deployment is provisioned in. Where support, maintenance or hosting involves a transfer to another country, it is made under appropriate safeguards — contractual data-protection terms with every provider, and standard contractual clauses or the equivalent local mechanism where required. Your employer can tell you which region their deployment sits in.
16.Children
Fusion HRM is workplace software intended only for employed adults. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child’s data has reached us, write to privacy@thefusionapps.com and we will delete it.
17.Third-party services
The app itself embeds no analytics, advertising or social SDK. The third-party services it touches are:
| Service | What it is for | What it receives |
|---|---|---|
| Google Play services | Distribution, and checking whether a newer version of the app exists. | A version query from your device. No account or employment data. |
| Your employer’s Fusion HRM server | Everything the app does. | The data described in §3, over an encrypted connection. |
| Cloud object storage | Holding photos and documents you upload. | The files themselves, access-controlled. |
Links or attachments inside the app may lead to content your employer controls. This policy does not cover their sites or systems.
18.Changes to this policy
We update this policy when the app’s data practices change. The “Last updated” date at the top always reflects the current version, and the Google Play listing links to this same page, so the version you can read here is the version in force. Where a change is material — a new category of data, or a new recipient — we will tell your employer in advance so they can pass it on, and, where the law requires it, seek fresh consent.
19.Contact us
Privacy questions about Fusion HRM
- Developer
- The Reciprocal Solutions — The Reciprocal Solutions — [street, city, postcode, country]
- Privacy contact
- privacy@thefusionapps.com
- Support
- support@thefusionapps.com
- Your employer
- For anything about your own employment record, contact your organisation’s HR or IT administrator first — they are the controller of that data.