GetsDay · Time Attendance Service

Privacy Policy

Effective date: 25 August 2026

Summary. GetsDay processes personal data to provide time attendance functions, verify attendance at approved work locations, support payroll and HR administration, protect the service, and meet legal obligations. Location access is intended for attendance-related actions and should not be used for continuous tracking unless a customer has separately configured and lawfully disclosed such use.

This policy applies to the GetsDay mobile application, website, and related services provided by Micware Asia Pacific Co., Ltd.

1. About this Privacy Policy

Micware Asia Pacific Co., Ltd. ("Micware", “the company” "we", "us", or "our") provides GetsDay, a time attendance service that enables organizations to manage employee attendance, working hours, breaks, absences, approved work locations, and related reports. This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected when an individual uses the GetsDay application, website, or related support services.

The company places great importance on the protection of personal data. In accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), the Company has established this Privacy Policy describing how personal data is collected, used, and disclosed in connection with the use of the GetsDay application and related services.

By using GetsDay, you acknowledge that you have read this Privacy Policy. Where consent is required by applicable law, we will request consent separately and provide a genuine choice. This Privacy Policy is not intended to replace any employee privacy notice issued by your employer or organization.

2. Our Role and Your Organization’s Role

In most workforce deployments, the customer organization or employer decides why and how employee data is processed through GetsDay. That organization generally acts as the personal data controller, while Micware processes the data on its instructions as a personal data processor and service provider. Micware may act as a controller for limited activities that it determines independently, such as account administration, service security, billing, legal compliance, and direct support communications.

Important for users. Questions about attendance rules, required data, workplace monitoring, payroll decisions, or correction of employment records should normally be directed first to your employer or organization. We will assist the organization with valid privacy requests where appropriate.

3. Scope

This Privacy Policy applies to:

A customer organization may configure GetsDay differently. Therefore, not every data category or feature described below will apply to every user.

4. Data We May Collect

Data categoryExamplesPrimary purpose
Identity and account dataName, employee or user ID, username, profile image, organization, account role, and authentication information.Account creation, identity verification, access control, and administration.
Contact dataWork or personal email address, telephone number, address, and designated contact information, where configured.Account communications, support, and organization administration.
Employment and attendance dataJob title, department, work schedule, shift, check-in and check-out times, breaks, absences, leave, overtime, assigned workplace, and attendance status.Attendance management, reporting, payroll support, and workforce administration.
Location dataDevice-derived geographic coordinates or location accuracy information captured in connection with an attendance action, where enabled and permitted.Verify attendance at an approved location, apply geofencing rules, prevent fraudulent records, and support audits or attendance disputes.
Biometric or image dataFacial image, face template, fingerprint, or other biometric identifier, only where the customer enables the feature and applicable legal requirements are met.Identity verification and prevention of attendance impersonation.
Device and technical dataDevice type, operating system, application version, language, IP address, device or application identifiers, and network information.Operate, secure, troubleshoot, and improve the service.
Usage and log dataLogin history, timestamps, feature interactions, error logs, diagnostic data, and security events.Service delivery, security monitoring, auditing, support, and performance improvement.
Support and communication dataMessages, support requests, attachments, feedback, and records of service communications.Respond to requests, resolve issues, and maintain service quality.
Billing and business contact dataCustomer contact, subscription, invoice, payment status, and tax-related information.Customer administration, billing, accounting, and legal compliance.

GetsDay does not require every item listed above in every deployment. The customer organization determines which configured fields are required for its workforce processes. We ask customers not to upload unrelated or excessive personal data.

5. Location Data

If location verification is enabled by your organization, GetsDay may request access to your device location when you perform an attendance-related action, such as check-in or check-out. The location may be compared with an approved workplace, customer site, project site, or geofence and may be stored with the attendance record.

Location data may be used to:

Location control. GetsDay should request location access only to support configured attendance functions. Users can manage location permission through device settings. If permission is denied, a location-dependent attendance function may not work, and the user should contact the customer organization for an alternative attendance method. The organization must separately inform users if it enables any location use beyond attendance-related actions.

6. How We Use Personal Data and Our Legal Bases

Micware and the customer organization must have an appropriate legal basis before processing personal data. The applicable basis depends on the purpose, the relationship with the user, the customer’s configuration, and applicable law. Processing may be based on:

PurposeWhat this includesPossible legal basis
Service delivery and contract performanceProvide accounts, record attendance, generate reports, support configured workflows, and maintain the service.Performance of a contract or steps requested before entering a contract; processing under the customer’s instructions.
Legal and employment obligationsSupport statutory recordkeeping, payroll, tax, labor, accounting, or regulatory requirements.Compliance with legal obligations.
Security and legitimate operationsPrevent misuse, investigate incidents, maintain logs, troubleshoot, and improve reliability.Legitimate interests, where those interests are not overridden by user rights, or legal obligations.
Optional features and sensitive dataEnable optional biometric, facial recognition, or other sensitive-data functions.Explicit consent or another lawful exception permitted by applicable law.
Service communicationsSend operational notices, security information, support responses, and material policy updates.Contract performance, legal obligation, or legitimate interests.
Marketing communicationsSend product information or recommendations where legally permitted.Consent or another lawful basis, with an opt-out where required.

We will not use personal data for a new purpose that is incompatible with the purpose originally communicated unless we provide further notice and obtain consent where required.

7. Sensitive Personal Data

Certain data, including biometric data used for unique identification, may be treated as sensitive personal data. Sensitive personal data will be processed only when the relevant feature is enabled, the processing is necessary, suitable safeguards are applied, and a lawful condition exists. Where explicit consent is relied upon, users will receive a separate consent request explaining the relevant purpose and may withdraw consent as permitted by law. User/Customer Data will be used solely to provide the Service and will not be used for any unrelated purpose. Access is restricted to authorized personnel and protected by appropriate access controls.

GetsDay should not be used to collect religious beliefs, ethnicity, health information, criminal records, or other sensitive personal data unless the customer organization has a documented lawful need and has implemented the required notices, permissions, and safeguards.

8. How We Obtain Personal Data

We may obtain personal data:

9. Disclosure of Personal Data

Personal data may be disclosed only as necessary and subject to appropriate safeguards to:

We do not sell personal data. We do not permit service providers to use personal data for their own unrelated purposes.

10. International Transfers

Personal data may be processed or stored in Thailand or in another country where Micware, the customer organization, or an authorized service provider operates. Where personal data is transferred internationally, the responsible party will apply safeguards required by applicable law, which may include an adequacy decision, contractual protections, consent where appropriate, or another legally recognized transfer mechanism. Users may contact us for more information about applicable safeguards.

11. Data Retention

Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy, the customer’s documented instructions, contractual requirements, dispute resolution, security, and applicable legal obligations. Retention periods may vary by data category and customer configuration. When personal data is no longer required, it will be deleted, destroyed, anonymized, or isolated from further use, unless retention is required by law.

Customer organizations control the retention of workforce records held in their GetsDay tenant. Users should contact their organization for the specific retention period applicable to attendance and employment records.

12. Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal data against loss, unauthorized access, use, alteration, disclosure, or destruction. Measures may include access controls, authentication, encryption where appropriate, logging, monitoring, personnel controls, backup, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Users are responsible for protecting their credentials and devices and should promptly report suspected unauthorized access to their customer organization or Micware.

13. Personal Data Breaches

If a personal data breach occurs, Micware will investigate and take reasonable steps to contain and remediate the incident. Where Micware acts as a processor, it will notify the relevant customer organization in accordance with contractual and legal requirements. The responsible controller will notify regulators and affected individuals where required by applicable law.

14. Your Privacy Rights

Subject to applicable law and relevant exceptions, individuals may have the right to:

For employment and attendance records controlled by a customer organization, submit your request to that organization first. Micware may forward a request to the relevant organization or ask for information necessary to verify identity and authority. Rights may be limited where an exception applies, including where data must be retained by law or is needed for legal claims.

15. Device Permissions and Choices

Depending on the features enabled, GetsDay may request device permission for location, camera, photos, notifications, or biometric functions. The permission request should explain why access is needed. Users may grant or revoke permission through device settings. Revoking permission may prevent the related feature from working but should not affect unrelated features.

Operational and security messages may be necessary to provide the service. Users may opt out of non-essential marketing communications by using the unsubscribe method provided or by contacting us.

16. Cookies and Similar Technologies

The GetsDay website or web application may use cookies, local storage, session identifiers, or similar technologies to maintain sessions, remember preferences, protect accounts, measure performance, and support service functionality. Where required, users will be given information and choices through an appropriate cookie notice or consent mechanism.

17. Children’s privacy

GetsDay is intended for workforce and organizational use and is not directed to children. Customer organizations must not create accounts for individuals who cannot lawfully use the service without authorization unless they have established an appropriate legal basis and obtained any required consent from a parent or legal guardian.

18. Third-Party Links and Integrations

GetsDay may contain links to third-party websites or connect with systems selected by the customer organization. Third parties process data under their own terms and privacy notices unless they act solely as a contracted processor. We encourage users and customer organizations to review the privacy practices of each relevant third party.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in the service, technology, legal requirements, or business practices. We will post the updated version through an appropriate service channel and revise the effective date. Where required, we will provide additional notice or obtain consent before a material change takes effect.

20. Contact Us

For questions about this Privacy Policy, Micware’s privacy practices, or a request relating to data for which Micware acts as controller, contact:

Micware Asia Pacific Co., Ltd.
No. 8, T-One Building, Sukhumvit 40, Phra Khanong, Khlong Toei, Bangkok 10110, Thailand

Tel : 02-085-8580
E-mail : contact@micware-ap.com
support@getsday.com
Web : www.getsday.com

Note - If your request concerns attendance, leave, payroll, workplace rules, or employee data controlled by your employer or organization, please contact that organization’s HR department, privacy contact, or system administrator first.