Legal
Privacy Policy
How CatalystGen handles personal data in HereIQ, written to be read rather than survived
Effective 18 August 2026CatalystGen
This replaces the AttendanceGM Privacy Policy dated 25 April 2026. Same company, same platform, new name.
1Who we are, and what this covers
HereIQ is a workforce platform — attendance, payroll, leave, employee records, documents and performance — provided by CatalystGen. This policy covers the platform and this website.
HereIQ was previously called AttendanceGM. The company, the platform and your data are unchanged; the name is not. This policy replaces the AttendanceGM Privacy Policy dated 25 April 2026.
HereIQ is sold to organisations, not to individuals. If you are an employee reading this, your employer decided to use HereIQ and decides what is recorded in it. That distinction runs through the whole document, and the next section explains why it matters.
2Who is responsible for what
In data protection law two roles are separate, and in a workplace platform they sit with different people:
- Your organisation — the controller
- Your employer decides to use HereIQ, decides what is recorded, who can see it, and whether optional features like location or biometric check-in are switched on. It is responsible for the lawfulness of all of that.
- CatalystGen — the processor
- We run the platform and process data on your organisation's instructions. We do not use employee data for our own purposes, and we do not decide what your employer collects.
Where we act as a controller in our own right — our own security logs, our own business records, this website — the same standards in this policy apply.
In practice this means most requests about your own data are answered fastest by your employer's HR or admin team, because they control the settings. If they will not act, you can come to us directly. Section 11 explains how.
3What we collect
3.1 About you as a person
- Name, email address, phone number and home address
- Date of birth, gender and marital status, where your organisation records them
- Emergency contact details
- Tax and social-security identifiers, where payroll is used
- A username and password — passwords are stored hashed and are never readable by us
3.2 About your work
- Position, department, manager, office location and contract dates
- Salary, allowances, deductions and payslips, where payroll is used
- Check-in and check-out times, hours worked, lateness, breaks and absences
- Leave requests, approvals and balances
- Documents your organisation uploads against your record, and their expiry dates
- Performance goals, reviews and feedback, where those features are used
3.3 Location
Where your organisation has configured office locations, HereIQ records coordinates at check-in and at check-out, and the distance between you and the office. It also records coordinates once at registration. In that configuration, location is required — a check-in without it is refused.
HereIQ does not track you between those moments. There is no background location, no movement history and no tracking outside working actions you take yourself.
3.4 Technical
We record the IP address a check-in came from, as part of verifying that attendance record, and again in security logs for sign-ins and administrative actions. We also use session identifiers, device identifiers for the mobile scanner, and counters for failed sign-in attempts.
4Why we are allowed to process it
- To perform the contract — everything needed to deliver attendance, leave, payroll, records and reporting to your organisation.
- To meet legal obligations — tax, employment and record-keeping duties that apply to your organisation or to us.
- For our legitimate interests — keeping the platform secure, available and free from abuse, where that does not override your rights.
- With explicit consent — where a law requires consent for a specific feature. Biometric check-in is the clearest example, and section 5 covers it.
Which of these applies to you can depend on where you work, because employment and data protection law differ by country. Where a stricter rule applies in your jurisdiction, that rule applies.
5Biometric check-in
Some organisations use fingerprint hardware for attendance. If yours does not, none of this applies to you.
Fingerprint templates are created and stored on the device itself. They are never transmitted to HereIQ and are never stored on our servers.
What HereIQ holds is an identifier — a number that links an enrolment on a device to a person in your organisation. On its own it is not a fingerprint and cannot be turned back into one.
Biometric data is treated as sensitive almost everywhere, and the conditions for using it at work differ sharply between countries. Your organisation is responsible for meeting them before enrolling anyone.
HereIQ does not currently offer biometric check-in to organisations in Illinois, United States.
6What we use it for
- Recording attendance, and producing the hours that payroll reads
- Generating payslips, leave balances and reports
- Letting you see your own records, payslips, leave and documents
- Sending account and system notifications
- Keeping the platform secure, and investigating misuse
- Meeting legal and regulatory obligations
We do not profile people for marketing, we do not run advertising, and we do not sell, rent or trade personal data. Not to anyone, at any price.
7Who else sees it
- Your organisation — administrators, HR and managers, limited by the roles your organisation configures.
- Service providers we use to run the platform, under written contract. By category: hosting, email delivery, error monitoring, payment processing and document storage.
- Authorities, where we are legally required to disclose.
- A future owner, if the business is sold or restructured, with the same protections and notice to affected organisations.
We name our service providers to customer organisations under their agreement, and to anyone who asks us in writing, and we give notice before adding a new one. We do not publish the list, because a public inventory of the systems behind a platform is more useful to an attacker than to a reader.
8Where it is kept
HereIQ application data — your records, attendance, payroll and documents — is stored in the European Union.
A small number of the service providers in section 7 process limited data outside the EU in the course of delivering their part, for example sending an email or recording an error. Those transfers are covered by contractual safeguards.
We describe where data is held rather than which companies hold it, for the reason given in section 7.
9How long we keep it
While your organisation's account is active, its records are kept — that is the point of an HR system, and a payroll history with gaps in it is worse than useless.
- People who leave are archived rather than erased, so the records they generated stay attached to the right person and payroll history stays intact.
- Deleted payroll records can be restored, because deleting one by mistake should not be permanent.
- Your organisation can export attendance, payroll, contract and leave data at any time, in Excel, CSV or PDF.
- Before closing an account, exporting what you need is your organisation's responsibility. We will say so again at the time.
- Where a law requires something to be retained, it is retained for as long as the law requires, whatever anyone would prefer.
- Retention and deletion apply to backups on the same terms, allowing for the time it takes backups to cycle.
If you need a retention schedule with specific periods for a procurement process, ask us and we will provide one.
10How we protect it
- Data is encrypted in transit between your device and the platform.
- Sensitive personal fields — names, contact details, addresses, dates of birth, salaries, tax identifiers and more — are encrypted individually in the database, not only at the disk level.
- Access is limited by role. An employee reaches their own record; supervisors and administrators see what their organisation grants them; organisations stay separate from one another.
- Records carry their origin. Attendance shows its method and location, a break shows whether the employee logged it or HR added it, and edits leave a history.
- Data is backed up daily.
- Staff with access are subject to confidentiality obligations.
No system is perfectly secure, and any policy claiming otherwise is not worth reading. Section 12 says what happens when something goes wrong.
11Your rights
- See your data
- Your own attendance, payslips, leave and documents are visible to you in the platform at any time. No request needed.
- Correct it
- Ask your HR or admin team to fix anything wrong. If they do not act, contact us.
- Have it deleted
- Requests go through your employer, because they control the record. Some data must be kept where the law requires it.
- Take it with you
- Ask for a copy in a common, machine-readable format — through your organisation, or from us directly.
- Object, or ask us to pause
- You can object to particular processing, or ask that it be limited while a disagreement is being resolved.
- Complain
- You can complain to the data protection authority where you live or work. In The Gambia that is the Data Protection Commission.
These apply wherever you are. Some countries give you more, and where they do, you get more.
12If there is a breach
- We notify the relevant authority within the time the law allows, once a breach is confirmed and poses a risk.
- We notify affected organisations as soon as we practically can, not once the story is tidy.
- We notify individuals directly where the risk to them is high.
- We contain it, investigate it, fix it, and say what we found.
- We keep records of what happened and what we did.
13Automated decisions
HereIQ does not make automated decisions about you that have legal or similarly significant effects, and it does not profile employees. Attendance statuses like late or absent are calculated from the times recorded and the schedule your organisation set — arithmetic, not judgement, and a person can change them.
Nothing in HereIQ uses artificial intelligence today. If that changes, this section changes first, and we will tell organisations before it does.
14Cookies
One essential cookie, set when you sign in, holding an encrypted session identifier. It is deleted when you sign out or the session expires.
This website and the platform use no advertising cookies, no cross-site tracking, and no third-party analytics. You can clear cookies in your browser at any time; doing so signs you out.
15Children
HereIQ is built for workplaces and is not intended for anyone under 18. We do not knowingly collect data from under-18s without verified parental or guardian consent, and where an organisation registers someone under 18 it is responsible for obtaining that consent.
If you believe a minor's data has been collected without consent, contact us and we will act on it.
16Changes to this policy
We update this policy when the product, the law or our practices change. The effective date at the top always reflects the current version.
For changes that materially affect you, we notify organisation administrators in advance by email and in the platform. Continuing to use HereIQ after the effective date means the updated policy applies.
17Contact us
For privacy questions, requests about your data, or to report a concern:
+220 4010971
If you have raised something with us and are not satisfied with how it was handled, you can take it to the data protection authority where you live or work.
We would rather write a policy you can check than one that sounds impressive. If something here does not match what the product does, tell us and we will fix the product or fix the policy.
Uptime and incident history are published on our status page.