Privacy Policy

App: Fixwork (PT. Lalu Lintas Lancar, operating under the brand “Treffix.id”)
Effective date: 31 July 2026
Last updated: 31 July 2026

Contents
  1. Overview
  2. Information We Collect
  3. Facial Recognition & Biometric Data
  4. How We Use Information
  5. Sharing & Third-Party Service Providers
  6. Data Retention
  7. Data Security
  8. Your Rights & Choices
  9. Children's Privacy
  10. International Data Transfers
  11. Changes to This Policy
  12. Contact Us

1. Overview

Fixwork ("the App", "we", "us") is a human resource management (HRMS) mobile application developed by PT. Lalu Lintas Lancar (operating under the brand "Treffix.id"), provided as a business-to-business (B2B) service to client companies and organizations ("Client Organizations"). Employees of a Client Organization use the App — after being registered/invited by their employer — to manage attendance, leave, permission, reimbursement, overtime, and related HR workflows.

This Privacy Policy explains what information we collect through the App, how we use it, who we share it with, and the choices available to you. It applies to all users of the Fixwork mobile application on iOS and Android.

2. Information We Collect

2.1 Account & Employment Data

When your employer (a Client Organization) registers you as a user, or when you log in, we collect: full name, email address and/or employee ID/NIP, phone number, position/job title, department, employment status, and profile photo. This data originates from your employer's HR records, not from you directly, except where you update it yourself in the App.

2.2 Facial Recognition & Biometric Data

See the dedicated section “Facial Recognition & Biometric Data” below for a complete explanation, including what is collected, why, who it is shared with, where it is stored, and how long it is retained.

2.3 Location Data

With your permission, the App collects your device's GPS location at the moment you clock in/out or submit a field-visit ("kunjungan") record, in order to verify that attendance is submitted from an authorized location (e.g. office geofence) or to log field-visit locations requested by your employer. Location is not tracked continuously or in the background outside of these specific actions.

2.4 Documents & Attachments

Files and photos you upload when submitting leave, permission, reimbursement, or overtime requests (e.g. medical certificates, receipts), accessed via your device's camera or photo library with your permission.

2.5 Device & Usage Data

Device model, operating system version, app version, IP address, and a push-notification subscription identifier (see Section 5 regarding our push notification provider, OneSignal), used to deliver notifications and diagnose technical issues.

3. Facial Recognition & Biometric Data

This section specifically addresses how the App collects and uses face-related data, and is written to directly answer the questions raised under App Store Review Guideline 2.1.

3.1 There are two distinct, unrelated uses of "face" in this App

Feature What happens Where the data goes
Face ID / fingerprint login (optional, device biometric unlock) Uses the operating system's built-in biometric authentication (Apple Face ID / Touch ID, or Android biometric unlock) to unlock a login credential that is stored securely on your device. Never leaves your device. The App never receives, sees, or stores your biometric template — the OS handles matching entirely on-device inside the secure enclave/hardware-backed keystore. We do not have a copy of this data.
Attendance face verification ("absen wajah") When you clock in/out, the App opens your device camera, performs an on-device liveness check (e.g. confirming a real person is present, not a photo), and captures a photo of your face at that moment. The captured photo is transmitted securely (HTTPS) to our attendance verification server to confirm that the person clocking in/out matches the employee's enrolled profile photo, in order to prevent attendance fraud (e.g. one employee clocking in for another — "titip absen").

The remainder of this section concerns only the second row — attendance face verification — since that is the feature that transmits and stores face data off the device.

3.2 What face data does the App collect?

A single photo of your face, captured via the device camera at the moment you submit an attendance clock-in or clock-out. No video is recorded and retained; the on-device liveness check is performed transiently during capture and is not itself stored.

3.3 What is the face data used for?

Solely to verify that the individual submitting an attendance record is the enrolled employee, by comparing the captured photo against the employee's reference profile photo on file. This is used exclusively for internal attendance-fraud prevention on behalf of the Client Organization that employs you. Face data is never used for advertising, analytics, profiling, or any purpose unrelated to attendance verification.

3.4 Is face data shared with third parties?

The attendance photo is processed using Google Cloud Vision API, a third-party facial recognition/comparison service provided by Google, solely to compare the captured photo against the employee's enrolled reference photo. Google processes this image only to perform the comparison requested by our system and does not use it for advertising or any other purpose, in accordance with the Google Cloud Privacy Notice. Face data is not sold, and is not shared with any party other than Google Cloud Vision (as our processor) for the attendance verification purpose described above.

3.5 Where is face data stored?

Face data is stored on Google Cloud Platform (GCP) servers located in Singapore (Southeast Asia region).

3.6 How long is face data retained?

Attendance face data (and other personal data associated with a user's account) is retained for as long as the employee remains active in the system, and is deleted within 7 (seven) days after the employee is deactivated from the system by their employer (the Client Organization).

3.7 Legal basis / consent

Attendance face verification is enabled by your employer (the Client Organization) as part of your employment's attendance policy. Under the service agreement between Treffix.id and each Client Organization, the Client Organization agrees to provide its employees' data for use within the App and accepts the associated risks and responsibilities as set out in that agreement, including obtaining any consent required from its employees before providing their data to us. By using this feature, you also consent to the collection and processing of your facial image for the purpose described above.

4. How We Use Information

5. Sharing & Third-Party Service Providers

We share limited information with the following categories of service providers, solely to operate the App:

We do not sell personal data to third parties, and we do not share data across different Client Organizations.

6. Data Retention

We retain your personal data for as long as your account remains active in the App. When your employer deactivates your account (e.g. upon resignation or termination), your personal data — including attendance face data (see Section 3.6) — is automatically deleted within 7 (seven) days of deactivation, except where we are required to retain certain records for a longer period to comply with applicable law.

7. Data Security

We use industry-standard measures, including encrypted transmission (HTTPS/TLS) and access controls, to protect your information. Our infrastructure and data handling practices are certified to the ISO/IEC 27001 information security management standard. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights & Choices

You may request access to, correction of, or deletion of your personal data by contacting your employer's HR administrator, or by contacting us directly at the email in Section 12. Note that some data (e.g. attendance records) is owned and controlled by your employer (the Client Organization) as the data controller, and requests may need to be directed to them first, in accordance with applicable law.

9. Children's Privacy

The App is intended for use by employees of Client Organizations and is not directed at, nor knowingly used by, children. We do not knowingly collect data from individuals under the minimum working age applicable in their jurisdiction.

10. International Data Transfers

Fixwork is currently offered only to Client Organizations within Indonesia; we do not operate internationally. However, as described in Sections 3.5 and 5, our backend and face-verification data processing are hosted on Google Cloud Platform servers located in Singapore. This means your personal data is transferred to and processed in Singapore even though our service itself is offered on a national (Indonesia-only) basis.

This transfer is safeguarded under Google Cloud's standard Cloud Data Processing Addendum (which incorporates Standard Contractual Clauses), entered into as part of our Google Cloud service agreement, together with the consent obtained under Section 3.7 and the security measures described in Section 7.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified within the App or via email prior to taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at:

PT. Lalu Lintas Lancar (Treffix.id)
Email: marketing@treffix.id
Address: Permata Regency D/37, Jl. H. Kelik, Srengseng, Kembangan, Jakarta Barat