Last updated 19 August 2026·SPM Technologies (Private) Limited
1. Who we are, and the two different roles we play
VEYQON is workforce management software published by SPM Technologies (Private) Limited ("SPM Technologies", "VEYQON", "we", "us"), a company incorporated in Sri Lanka:
SPM Technologies (Private) Limited No. 57, Lloyd's Avenue Batticaloa 30000 Sri Lanka Company registration number: PV 00245366
VEYQON is not a consumer product. There is no public sign-up. You can only use it if your employer — or an organisation you work with — has a VEYQON workspace and has issued you an account.
That structure determines who is legally answerable for your data, and it is the most important thing in this document.
1.1 Your employer is the controller
For everything you do inside VEYQON as an employee — signing in, checking in and out, running task timers, requesting leave, submitting expenses, viewing your payslips — your employing organisation is the data controller under Art. 4(7) GDPR, and under the equivalent concepts in UK GDPR, Canada's PIPEDA, India's DPDP Act 2023 and Sri Lanka's Personal Data Protection Act No. 9 of 2022.
Your employer decides:
- whether to use VEYQON at all;
- which features are switched on, including whether location is recorded;
- who inside the organisation can see which records;
- which fields of your employee profile are filled in;
- how long records are kept, within the limits we support;
- the lawful basis on which your data is processed.
SPM Technologies acts as a processor (Art. 4(8) / Art. 28 GDPR) on your employer's documented instructions. We do not decide the purposes of processing your employment data, and we do not use it for our own purposes.
What this means for you in practice: if you want to access, correct, or delete your employment records, or object to how they are used, your first point of contact is your employer's HR or data protection contact, not us. Section 10 explains what happens if you contact us directly.
1.2 Where we are the controller
We are a controller for a narrow, separate set of data that is not your employment record:
- account and billing contacts at customer organisations;
- people who contact our sales or support channels;
- visitors to our public website;
- server and security logs we keep to run the service safely.
Section 8 covers that data.
1.3 Scope
This policy covers the VEYQON mobile app for iOS and Android (bundle identifier
com.veyqon.mobile), the VEYQON web application, and the backend service behind both.
It does not override any privacy notice your own employer gives you. Where the two differ on a question your employer controls — legal basis, retention, internal access — your employer's notice governs.
2. What the apps collect, in detail
2.1 Account and sign-in data
| Data | When it is collected | Where it comes from |
|---|---|---|
| Your company's VEYQON workspace address | The first time you open the app | You type it on the sign-in screen |
| Email address / username | Each sign-in | You |
| Password | Each sign-in — transmitted to your employer's workspace for authentication, never stored on the device | You |
| Session cookie | On successful sign-in | Issued by your employer's workspace, held in the device's native cookie store |
| Name, employee record, job title, department, reporting line | After sign-in | Your employer's workspace |
2.2 Location data — the most sensitive thing we handle
We want to be precise about this rather than reassuring, because precise location is a special-care category in an employment context.
What is collected: your device's latitude and longitude, at precise (GPS) accuracy.
When it is collected — only these moments:
- when you record an attendance check-in or check-out; and
- when you start or stop a task timer.
When it is not collected:
- Never in the background. The iOS app requests When In Use permission only and declares no background location capability. The app cannot read your location while it is closed or backgrounded.
- No continuous tracking. No location history is built between the discrete events above. There is no route, no trail, and no geofence monitoring.
- Not at all, if your employer has switched it off. Location capture at check-in is governed by a workspace-level setting. Where your employer has disabled it, no coordinates are captured or transmitted at check-in.
- Not, if you decline. If you refuse or later revoke location permission in your device settings, check-in and the task timer still work — the event is simply recorded without coordinates.
You are told before it happens. On first launch the app takes you through a flow that presents the terms, requests notification permission, requests location permission, and then shows a specific notice that starting or stopping a task timer records your location at that moment. You must acknowledge that notice before you can reach the app.
Coordinates are shown back to you. After a check-in with location enabled, the app displays the recorded coordinates and a map of that point, so you can see exactly what was recorded. The map is rendered from OpenStreetMap, which means the map area around your coordinates and your IP address reach the OpenStreetMap Foundation's tile servers when the map is displayed. The map is not requested at all where no coordinate was recorded.
Retention. Our policy is that coordinates are kept no longer than 90 days after the event, separately from the attendance or timesheet record they are attached to, which is kept for the period your employer's statutory obligations require. Automated deletion of coordinates after 90 days is not yet in operation; until it is, coordinates persist alongside the underlying record. We state this rather than describe a control we have not built.
2.3 HR and employment records
Through the apps you access records held in your employer's VEYQON workspace:
- attendance and check-in/check-out history, including timestamps and, where enabled, coordinates;
- shift assignments and shift change requests;
- leave requests, approvals, rejections and leave balances;
- expense claims, expense line items, taxes and any files you attach;
- employee advance requests and balances;
- task assignments, task timers and the time logged against them;
- salary slips and the compensation figures they contain;
- in-app notifications relating to the above.
Attachments. When you attach a file to an expense claim, the app accepts images and documents of any type from your device's file picker and uploads them to your employer's workspace. Whatever is inside that file — a receipt, an invoice, an itinerary — is uploaded with it. We do not scan, index, or analyse attachment contents.
We do not create these records independently of your employer's system. The app is a window onto data your employer holds.
2.4 Your employee profile — including health and financial data
The Profile screen displays the employee record your employer holds about you. Depending on what your employer has filled in, this can include:
| Group | Fields shown |
|---|---|
| Identity | Name, employee number, gender, date of birth, date of joining, blood group |
| Organisation | Company, department, designation, branch, grade, reporting line, employment type |
| Contact | Mobile number, personal email, company email, preferred email |
| Salary and banking | Cost to company (CTC), payroll cost centre, tax identification number (e.g. PAN), provident fund account, salary mode, bank name, bank account number, IFSC, MICR and IBAN |
Two entries deserve to be named rather than buried:
- Blood group is health data. Under Art. 9 GDPR it is a special category of personal data, and processing it needs a specific Art. 9(2) condition — most commonly Art. 9(2)(b), obligations in the field of employment and social security law (in Germany read with §26(3) BDSG). Employers who do not need blood group should leave the field empty. VEYQON does not require it to function.
- Bank account details and tax identifiers (IBAN, account number, PAN or equivalent) are payroll data held by your employer. VEYQON does not initiate payments and does not transmit these to any payment processor.
Whether a given field is populated at all is your employer's decision.
2.5 Notifications and device tokens
If you allow notifications, your device is issued a push token by Apple (APNs) on iOS or Google (Firebase Cloud Messaging) on Android. That token is:
- stored locally on your device;
- registered against your user account on your employer's workspace, so notifications about your approvals and rejections reach the right handset;
- deleted, and de-registered from the backend, when you sign out — so the next person to use the handset does not receive your HR notifications.
Push delivery is not yet switched on. Notifications currently appear only inside the app, on the Notifications screen. The token is registered so that push can be enabled without a further app update. When it is enabled, the content of a notification (for example "your leave request was approved") will pass through Apple's or Google's push infrastructure to reach your device; we will update this page at that point.
You can decline notifications at first launch and change your mind later in your device settings.
2.6 Technical and connection data
When the app or the web application makes a request, the server processes standard connection data: IP address, request time, the endpoint requested, and a user-agent string. This is used to operate, secure and troubleshoot the service. Server logs are rotated on the hosting platform's schedule and are not retained for analysis beyond troubleshooting.
2.7 What is stored locally on your device
The mobile app stores a small amount of data in the operating system's own preference store and cookie jar:
- your first-launch consent choices (terms accepted, notification asked, location asked, timer notice acknowledged);
- your company workspace address;
- your theme preference (light/dark);
- your push device token;
- your session cookie.
None of it is transmitted anywhere except the session cookie, which authenticates you to your employer's workspace, and the push token, which is registered as described above. Signing out clears the session and the push token.
2.8 What we do not collect
Stated as verified facts about the mobile application source, not as marketing claims:
- No third-party analytics SDK. No Google Analytics, Firebase Analytics, Sentry, Mixpanel, Amplitude, PostHog or comparable telemetry library is used in the app.
- No advertising SDK, no advertising identifier (IDFA/AAID), and no App Tracking Transparency prompt — because we do not track you across other companies' apps or websites.
- No access to your device's contacts, photo library, microphone, camera, calendar, or health/fitness data (Apple HealthKit, Google Fit), and no access to your file system beyond the single file you explicitly pick for an attachment. The Android app declares only internet and location permissions; the iOS app declares no camera, photo library, microphone, contacts or calendar usage. (This concerns data on your device. Health information your employer has recorded in your employee profile — §2.4 — is a separate matter and is covered there.)
- No sale of personal data. We do not sell, rent or share personal data with data brokers, and we do not "sell" or "share" it as those terms are defined under the California Consumer Privacy Act.
- No use of your employment data to train machine learning models.
3. Why the data is processed, and on what legal basis
Because your employer is the controller, your employer determines the legal basis. The table below sets out the bases we would normally expect a customer to rely on. It describes the processing; it does not replace your employer's own notice.
| Purpose | Data involved | Legal basis typically relied on by the employer |
|---|---|---|
| Authenticate you and maintain your session | Credentials, session cookie, workspace URL | Art. 6(1)(b) GDPR — necessary for the employment contract |
| Record attendance and working time | Check-in/out events, timestamps | Art. 6(1)(c) GDPR — legal obligation to record working time; in Germany §26(1) BDSG |
| Verify where attendance or field work occurred | Precise coordinates at those events | §26(1) BDSG / Art. 6(1)(f) GDPR — the employer must document its necessity and balancing test |
| Administer leave, expenses and advances | The relevant records and attachments | Art. 6(1)(b) GDPR |
| Maintain and display your employee profile | Identity, contact, banking and payroll fields | Art. 6(1)(b) and 6(1)(c) GDPR |
| Hold health data recorded in your profile (blood group) | Special-category data | Art. 9(2)(b) GDPR — employment and social security law; in Germany §26(3) BDSG. The employer must be able to point to this condition, or leave the field empty. |
| Make payroll documents available to you | Salary slips | Art. 6(1)(b) and 6(1)(c) GDPR |
| Notify you of approvals and rejections | Push token, notification content | Art. 6(1)(b) / 6(1)(f) GDPR |
| Keep the service secure, available and debuggable | Technical and log data | Art. 6(1)(f) GDPR — our and the employer's legitimate interests |
Note for employers and their counsel. Consent under Art. 6(1)(a) is a weak basis in an employment relationship because of the imbalance of power — in Germany expressly so under §26(2) BDSG. The first-launch acknowledgement inside the app should be treated as a transparency measure, not as the lawful basis for location processing.
Works councils. In Germany, recording employee location at check-in and at task timer start/stop is a technical facility capable of monitoring employee conduct or performance. That engages co-determination under §87(1) No. 6 BetrVG, and a works agreement (Betriebsvereinbarung) may be required before the feature is switched on. Comparable employee-representation rules exist in other jurisdictions. This is the employer's obligation, and no wording in a privacy policy substitutes for it.
4. Who else is involved — sub-processors and third parties
We use a deliberately small number of third parties. As a processor we engage sub-processors under Art. 28(2)–(4) GDPR, on the written terms each provider makes available. Two of the entries below are not conventional sub-processors and we would rather be precise than tidy: Apple and Google issue the push token to your own device under their own terms with you and with us as a developer, and the OpenStreetMap Foundation operates a public map service that your device requests directly — we have no contract with it, and we list it because your IP address reaches it.
| Party | What they receive | Why | Location |
|---|---|---|---|
| Hostinger International, Ltd. | All workspace data, at rest and in transit | Hosting the VEYQON backend and database | Server in Germany; company registered in Cyprus |
| Apple Inc. (APNs) | Push device token, iOS devices only, and the notification content where notification delivery is in use | Issuing the device token and delivering notifications to iPhones and iPads | United States and global edge infrastructure |
| Google LLC (Firebase Cloud Messaging) | Push device token, Android devices only, and the notification content where notification delivery is in use | Issuing the device token and delivering notifications to Android devices | United States and global infrastructure |
| OpenStreetMap Foundation | The map area around your coordinates, and your IP address, at the moment the check-in map is drawn on your device | Rendering the map on the check-in screen | United Kingdom |
Support, billing and email are handled by SPM Technologies' own staff. We do not use a third-party helpdesk, CRM, email marketing or billing platform for customer data.
Notification content. Notification payloads travelling through Apple or Google infrastructure do not contain salary figures or comparable detail — they carry the fact and the destination ("Your leave request was approved"), not the substance.
Inside your organisation. Your records are visible to colleagues according to the role-based permissions your employer configures — typically your manager, HR, and finance for expense-related records. Ask your employer how access to check-in coordinates is configured in your workspace.
We do not disclose your data to anyone else, except where we are legally compelled to by a binding order from a competent authority, in which case we notify the controlling employer unless the law forbids it.
A current sub-processor list is maintained at veyqon.de/subprocessors, and customers are notified 30 days before a new sub-processor is engaged.
5. Where your data is stored, and international transfers
5.1 One server, in Germany
VEYQON runs on a single server located in Germany, operated for us by Hostinger International, Ltd. Every customer workspace is hosted on that server, whatever the customer's own country. There is no per-region or in-country hosting today, and we do not claim otherwise.
For people in the EEA this means the data itself rests inside the European Union. It does not mean that no one outside the EU can reach it — see §5.2, which describes access from Sri Lanka.
Hostinger is engaged as a sub-processor and its data processing addendum, which incorporates the Standard Contractual Clauses, applies to this relationship.
5.2 Access from Sri Lanka — stated plainly
SPM Technologies is established in Sri Lanka. Our engineering and support staff are based there. When we provide support, investigate an incident, or maintain the service, our personnel in Sri Lanka may access data held on our server in Germany. That is a transfer to a third country, and we would rather state it than let you discover it.
Sri Lanka does not have an adequacy decision from the European Commission or the UK Government. Transfers of personal data from the EEA or the UK to us are therefore made under:
- the European Commission's Standard Contractual Clauses (Decision 2021/914), module three (processor to sub-processor) or module two as applicable, supplemented by a transfer impact assessment; and
- for transfers out of the UK, the UK International Data Transfer Addendum to those Clauses.
These are incorporated into our Data Processing Agreement with each customer.
5.3 Other applicable law
Depending on where you work and where your employer is established, the following may apply, and we contract to support them:
- EU GDPR and, for German employers, the BDSG (in particular §26 on employment data);
- UK GDPR and the Data Protection Act 2018;
- Canada's PIPEDA and applicable provincial legislation;
- India's Digital Personal Data Protection Act 2023;
- US state privacy laws including the CCPA/CPRA, under which we act as a "service provider" and not a "third party";
- Sri Lanka's Personal Data Protection Act No. 9 of 2022, which governs us as a company domiciled in Sri Lanka. As at the date of this policy the Act's substantive provisions have not yet been brought into force by Ministerial Order, although the Data Protection Authority is operational. We will comply with those provisions when they commence.
6. How long data is kept
| Data | Retention |
|---|---|
| Location coordinates (check-in, check-out, task timer) | Target: no more than 90 days from the event. Automated deletion is not yet in operation — see §2.2. The attendance or timesheet record is retained separately and for longer. |
| Attendance, leave, expense, advance and payroll records | Set by your employer, and largely fixed by law. Statutory periods for payroll and attendance documentation are commonly 6 or 10 years depending on the country. |
| Server and connection logs | Rotated on the hosting platform's schedule; not retained for analysis. |
| Push device token | Until you sign out, or until the token is invalidated by Apple or Google. |
| Device-local data (consent flags, workspace URL, theme) | Until you sign out, clear app data, or uninstall. |
| Workspace data after a customer leaves | Deleted or returned in accordance with our Data Processing Agreement with that customer. |
7. Security
- Encryption in transit. All traffic between the apps and the backend uses HTTPS/TLS. The production mobile build does not permit unencrypted connections.
- Where data rests. Workspace data is stored on our server in Germany, on storage provided by Hostinger. We do not claim encryption at rest across every component of the deployment. Database access is restricted to the application and to named administrators.
- Session handling. Sessions are held in the operating system's native cookie store, rather than in web storage accessible to page scripts.
- Access control. Access to HR records is governed by role-based permissions configured by your employer in their workspace.
- Our staff access. SPM Technologies personnel access customer workspace data only where necessary for support, maintenance or incident response. Access is limited to named personnel who require it for those purposes and is subject to written confidentiality obligations.
- Breach notification. Where we become aware of a personal data breach affecting a customer workspace, we notify the controlling employer without undue delay, as Art. 33(2) GDPR requires, so they can meet their own 72-hour duty. Notifying a supervisory authority and, where required, affected employees, is the employer's responsibility as controller.
No system is perfectly secure, and we do not claim otherwise.
8. Data we control ourselves
Separately from employment data, we process a limited set of data as controller:
| Category | Purpose | Legal basis |
|---|---|---|
| Business contact details of customer administrators and prospects | Managing the customer relationship, support, billing | Art. 6(1)(b) and 6(1)(f) GDPR |
| Support correspondence | Answering and resolving your request | Art. 6(1)(b) / 6(1)(f) GDPR |
| Website visit data | Operating and securing our website | Art. 6(1)(f) GDPR |
| Billing and invoicing records | Contract performance and statutory accounting retention | Art. 6(1)(b) and 6(1)(c) GDPR |
This data is handled by SPM Technologies staff directly. For it, you may exercise your rights against us using the contact details in §11.
Our marketing website sets no non-essential cookies. It runs no analytics, no advertising or tracking scripts, and no third-party embeds that profile visitors. The only storage used is what is strictly necessary to serve the pages you request.
9. Automated decision-making
VEYQON does not make automated decisions producing legal or similarly significant effects about you within the meaning of Art. 22 GDPR. Approvals of leave, expenses and advances are made by people in your organisation. Workflow rules may route a request to a particular approver, but the decision itself is human.
10. Your rights, and how to use them
Under the GDPR — and in substance under UK GDPR, PIPEDA, the DPDP Act, the CCPA/CPRA and the Sri Lankan PDPA once in force — you have the right to:
- access the personal data held about you (Art. 15);
- rectify inaccurate data (Art. 16);
- erasure in defined circumstances (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21);
- withdraw consent where consent is the basis, without affecting prior lawfulness;
- not be discriminated against for exercising your rights, where local law provides that protection.
Statutory retention obligations — payroll and tax records in particular — will often override an erasure request. That is a legal limit, not a refusal of your right.
Where to send the request. Because your employer is the controller of your employment data, send your request to your employer's HR or data protection contact. If you send it to us, we will forward it to the controlling employer and assist them in responding, as Art. 28(3)(e) GDPR requires. We cannot act on your employment records without your employer's instruction, and we will not delete an employer's records on an employee's request alone.
Complaints. You may lodge a complaint with the supervisory authority where you live, where you work, or where the alleged infringement took place. In Sri Lanka, the competent authority is the Data Protection Authority of Sri Lanka (dpa.gov.lk).
11. Contact
Data protection contact: support@veyqon.de
Support: veyqon.de/support
Postal: SPM Technologies (Private) Limited, No. 57, Lloyd's Avenue, Batticaloa 30000, Sri Lanka
Telephone: +94 76 664 6404
Data Protection Officer. SPM Technologies has not appointed a Data Protection Officer. We have assessed that our processing does not meet the thresholds in Art. 37(1) GDPR requiring mandatory appointment. Data protection enquiries should be sent to the address above.
12. Children
VEYQON is a workplace application intended for people in employment. It is not directed at children, we do not knowingly collect data from children, and there is no route for a child to obtain an account — access requires an employer-issued credential.
13. Changes to this policy
We will publish any change on this page and update the "Last updated" date. Where a change materially affects how personal data is handled — a new sub-processor, a new category of data — we will notify customer organisations in advance in accordance with our Data Processing Agreement, and they will inform their employees.