Privacy notice
Privacy and personal data.
Lemorange Ltd handles information you send through attendance.cy. When an organisation uses Attendance, that organisation decides how its workforce data is used. Lemorange Ltd processes the data on its behalf and under its instructions.
Last updated: 26 August 2026
1. Who we are and who this notice covers
Lemorange Ltd is a company registered in Cyprus and based in Nicosia. It operates attendance.cy and provides Lemorange Attendance. For any privacy matter, email support@lemorange.com or call 80012900.
This notice covers people who visit attendance.cy or contact Lemorange Ltd, customer administrators and authorised users, and people whose details are entered into Attendance by their employer or another organisation.
A customer agreement and data-processing agreement may give additional information for a particular deployment. Where such an agreement differs on processing performed by Lemorange Ltd for a customer, the relevant signed agreement takes priority.
2. When Lemorange Ltd is responsible and when the customer is responsible
Lemorange Ltd is the controller when it uses personal data for its own purposes. Examples include website enquiries, customer and billing administration, service security, support records and website analytics enabled with consent.
For workforce data entered into an Attendance workspace, the customer is normally the controller. The customer decides why it uses the system, whose data is included, which attendance methods are permitted, who may see the data and how long the data is kept.
In that situation, Lemorange Ltd acts as processor. It uses the data only to provide, protect and support Attendance under the customer agreement and documented instructions, unless applicable law requires otherwise.
Lemorange Ltd is not the employer and does not decide how a worker is assessed, paid or treated.
3. Where the data comes from
- Directly from you when you submit a form, contact us, create an account or ask for technical support.
- From your organisation when it adds users, workers, departments, sites, schedules and rules to Attendance.
- From terminals and mobile devices when an attendance attempt, synchronisation or permitted-method check takes place.
- From an HR, payroll, access-control or other integration authorised by the customer.
- Automatically from technical service logs where needed for sign-in, security, diagnosis and abuse prevention.
Lemorange Ltd does not buy personal-data lists or build advertising profiles from Attendance workforce data.
4. What we collect through attendance.cy
- Contact and enquiry information: name, organisation, role, email address, optional telephone number, employee and site counts, current attendance method and your message.
- Security information: submission time, source page and technical information needed to limit unwanted or malicious requests. The contact form stores a non-reversible hash of the source IP address rather than the address itself.
- Website analytics: pages visited, referral source, device and browser type and approximate region through Google Analytics, but only after you allow it.
- Business records: account, contract, billing and support information if your organisation becomes a customer. Full card details may be sent directly to the payment provider and not stored by Lemorange Ltd.
5. What Attendance may hold
The data depends on the functions selected by the customer. Not every customer uses every category below:
- Work and contact information such as name, employee code, telephone number, job title, department, site and user permissions.
- Rosters, shift changes, availability, leave requests, messages, approvals, calculated hours, payroll codes and audit history.
- Attendance records such as date and time, entrance or site, terminal, method, result and any later correction or approval.
- Credentials selected by the customer, such as a PIN, RFID card number and QR code.
- For mobile use, device identifier and type, operating system, app version and notification token. If the customer enables the relevant checks, Attendance may also record location, accuracy, distance from the workplace, Wi-Fi identifiers and IP address at the time of an attempt.
- Terminal and integration information such as device identifiers, connection status, synchronisation logs and identifiers exchanged with an authorised HR or payroll system.
For a private deployment on customer servers, the data may remain entirely within the customer environment. The customer agreement defines the deployment model.
6. Biometrics and location data
Where the customer enables it and the law permits its use, compatible terminals may use a face image, facial template or fingerprint template. Storage and synchronisation depend on the terminal model and the contracted deployment.
Mobile attendance may check whether a device is within an authorised area or connected to an approved network. Attendance does not need to track a worker continuously to perform that check. The customer decides which checks are enabled.
Biometric data and precise location require particular care. Before enabling them, the customer must have a specific lawful purpose, consider a less intrusive method, document its legal basis and complete any required data-protection impact assessment or consultation.
Availability in Attendance does not mean a function is lawful in every workplace.
8. Why we use data and the legal basis
When Lemorange Ltd is controller, it uses data to answer enquiries, prepare a requested quotation or demonstration, provide the contracted service, administer accounts and billing, deliver support, secure its systems, prevent misuse and meet legal obligations.
The legal basis depends on the context. It may be steps requested before entering a contract, performance of a contract, a legal obligation, your consent or Lemorange Ltd’s legitimate interests in operating, supporting and protecting its business and services.
Google Analytics is based on consent. You can withdraw that consent at any time through the controls at the end of this page without affecting the website’s operation.
When processing is based on legitimate interests, we consider the purpose, necessity and impact on individuals. You may object on grounds relating to your particular situation.
9. Which information is required
Required fields are marked on the contact form. Without basic contact information and enough detail about the enquiry, we may be unable to reply or prepare a relevant quotation. A telephone number and Google Analytics are optional.
Inside Attendance, the customer decides which information is needed for the selected functions. If a required identifier, schedule, attendance event or permission is missing, a function or calculation may not complete correctly. The customer is responsible for checking completeness and accuracy.
10. What the customer must do
- Give workers clear information before collection begins.
- Use only the data and attendance methods genuinely needed for the stated purpose.
- Identify and document the legal basis, retention period and people with access.
- Keep employee, site, terminal and integration information accurate.
- Handle worker requests and ask Lemorange Ltd for the assistance provided by the data-processing agreement.
- Complete any required data-protection impact assessment, consultation or approval before using biometrics, location, monitoring or another intrusive method.
- Give Lemorange Ltd lawful, clear and documented instructions and have the right to send data to every connected system.
11. Who may have access
Access inside Lemorange Ltd is restricted to authorised people who need the data for service delivery, security, billing or technical support.
Lemorange Ltd may use providers for hosting and technical infrastructure, transactional messages, website analytics, payments and support. Those providers are contractually required to use the data only for the relevant service and to apply appropriate safeguards.
Data may be sent to HR, payroll, access-control or another system only when the customer activates or requests that integration. It may also be disclosed to professional advisers, insurers, authorities or courts where required by law or needed for a legal claim.
If Lemorange Ltd is reorganised, merged, acquired or transfers a business, relevant information may be disclosed to advisers and the successor under confidentiality duties and applicable law.
Lemorange Ltd does not sell personal data and does not use customer workforce data for advertising.
12. Transfers outside the European Economic Area
If data must be transferred outside the European Economic Area, Lemorange Ltd uses a mechanism recognised by data-protection law, such as an adequacy decision or standard contractual clauses, and considers whether additional safeguards are required.
The hosting location, deployment model and relevant providers may be described more specifically in the customer agreement and data-processing agreement.
13. Security and personal-data breaches
Lemorange Ltd applies technical and organisational measures appropriate to the service and risk. They include access controls, separation between customer workspaces, encryption of production communications, audit history, controls against malicious or repeated requests and managed support access.
No online system is completely secure. Customers must protect their administrator accounts, networks, servers, terminals, mobile devices and integrations and notify Lemorange Ltd promptly if they suspect a compromise.
When Lemorange Ltd acts as processor and confirms a personal-data breach involving customer data, it informs the affected customer without undue delay. It provides the information available so the customer can assess the incident and meet its own legal duties.
An initial notification may be supplemented as the investigation progresses. Notification does not by itself amount to an admission of fault or liability.
14. How long we keep data
There is no single period for every category. We consider the purpose, the duration of the relationship, customer instructions, security and support needs, legal limitation periods and the possibility of a legal claim.
Website enquiries are kept for as long as needed to answer, continue a genuine business discussion and address misuse. Contract, billing and support records are kept for the periods required by the relationship, accounting rules and law.
Workforce data follows the settings and documented instructions of the relevant customer. On termination, it is returned or deleted as agreed. Limited backup copies may remain protected until overwritten in the normal backup cycle.
Lemorange Ltd may keep specific information longer when required by law, court or administrative proceedings, or to establish, exercise or defend a legal claim. Access is restricted to that purpose.
15. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability. You may also object to processing based on legitimate interests and withdraw consent for future processing.
These rights are not absolute. For example, information may need to be retained for a legal obligation, active dispute or compelling lawful reason. We will explain if a request cannot be met in full.
To protect the data, we may request information needed to confirm identity or authority. We respond without undue delay and normally within one month. A complex request or multiple requests may permit the extension provided by the General Data Protection Regulation.
16. If your data is in your employer’s workspace
In the Attendance.cy mobile app, open Settings and choose Your data rights to submit and track an access, correction, erasure, restriction, portability or objection request. The request goes to the employer or organisation that controls the relevant workspace and is responsible for assessing it.
Lemorange Ltd does not delete or change workforce data on a worker’s direct instruction without involving the responsible customer, unless the law requires otherwise. It will pass on the request and assist the customer as required by the data-processing agreement.
For information controlled directly by Lemorange Ltd, such as an enquiry you submitted on attendance.cy, email support@lemorange.com.
17. Attendance calculations and recommendations
Attendance may calculate hours, flag records that need review and suggest available workers for shift cover. These functions assist the customer’s authorised managers.
Lemorange Ltd does not use those outputs to make employment decisions about an individual. The customer must review the data, correct possible errors and decide whether and how to act.
18. Questions and complaints
For a question, request or complaint about information controlled by Lemorange Ltd, email support@lemorange.com or call 80012900. We will review the matter and provide our response.
You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus or the data-protection authority where you live or work.
Office of the Commissioner for Personal Data Protection19. Changes to this notice
We update this notice when the service, processing, a significant provider or legal requirements change. The date at the top shows the latest revision.
If a change is material, we will provide additional notice where required. A customer agreement or data-processing agreement may specify how a customer is notified.
Google Analytics
Google Analytics settings
Choose whether Google Analytics may run in this browser. Attendance.cy works without it.