Privacy Policy

What Navbat7 collects, why, where it is kept, who sees it, and what you can do about it.

Last updated: 14.09.2026

1. Who is responsible

1.1The Service is operated by ООО "PT TECHNOLOGIES" (“we”), a company registered in the Republic of Uzbekistan. You can reach us at contact@techatpt.com.

1.2This policy covers personal data handled when you use Navbat7 — the website, the web application, the mobile web app and the Telegram mini app.

1.3This policy is designed to comply with the EU General Data Protection Regulation (EU GDPR), the UK GDPR, the UK Data Protection Act 2018, applicable US state privacy legislation, and the Law of the Republic of Uzbekistan No. ZRU-547 “On Personal Data”.

2. Two roles: your employer and us

2.1The business that uses Navbat7 decides which of its staff to add, what to record about them and for how long. For its staff’s data the business is the controller; it decides the purposes.

2.2We process that data on the business’s instructions and only as needed to run the Service. We do not sell personal data, share it with advertisers, or use it for profiling or automated decisions with legal effect.

2.3If you are a member of staff and want to know what is held about you, or want it changed or deleted, ask your employer first — it controls those records. You can also write to us; we will help, acting together with your employer.

2.4For the data of the account owner — the person who signed the business up — we are the controller.

3. What we collect

3.1About the owner or manager who creates the account:

  • name;
  • email address, and a password stored as a one-way hash;
  • phone number, if given;
  • the business’s name, address and map coordinates, time zone, country and currency.

3.2About a member of staff:

  • name, and the name shown on the schedule;
  • phone number and email address, whichever were given;
  • Telegram account — identifier, username and profile photo — if the person linked Telegram;
  • position, start date and pay rate;
  • shifts: scheduled, worked, swapped, time off and requests;
  • clock-in and clock-out times, and the distance in metres between the person and the venue at the moment of clocking in;
  • where the employer has switched it on for a venue, a small photograph taken by the time-clock tablet at the moment of clocking in or out, kept for 30 days and then deleted.

3.3We also keep the notes managers and staff write themselves (a note on a shift, the reason for time off), the activity log of the Service, and a record of which notifications were sent and when.

3.4We do not collect health data, ethnicity, religion, political opinions or other special categories, and ask you not to enter them in free-text fields.

4. Location: a distance, not a place

4.1When a member of staff clocks in from a phone, the browser asks permission to read its location. The coordinates go to our server, which computes a single number — the distance in metres to the venue — and then discards them.

4.2We do not store staff coordinates. No screen, report or export contains them, because they are not in the database. Only the distance is kept, which shows the person was on site and says nothing about where they were at any other time.

4.3If permission is refused, the clock-in is still recorded — without a distance.

5. Photographs at the time clock

5.1An employer may switch on, per venue, a photograph at the wall-mounted time clock: the tablet takes one small picture at the moment a person clocks in or out and shows it beside that record on the timesheet, so that one person cannot clock in for another. The camera is visible on screen while the picture is taken.

5.2The picture is kept for 30 days in private storage that nothing outside the Service can read, and is then deleted automatically. It is not used for anything else — not for recognition, not for matching against other pictures — and it is not shared. If the camera is unavailable, the clock-in is still recorded, without a picture.

5.3This is the employer’s decision and the employer’s responsibility to announce to its staff before switching on; in most countries it must. Off by default.

6. Why we process data, and on what basis

  • Staff scheduling, time recording and workplace communication — processed on the employer’s instructions, as its data processor. Where we act as a controller of the employer’s operational data, processing relies on our legitimate interest in providing efficient workforce tools (GDPR Article 6(1)(f)).
  • Account owner registration and administration — necessary for the performance of our contract with your business (GDPR Article 6(1)(b)).
  • Billing and financial records — necessary for compliance with our legal and tax accounting obligations (GDPR Article 6(1)(c)).
  • Location data at clock-in — the member of staff’s explicit device-level consent, given through the browser’s or app’s location permission (GDPR Article 6(1)(a)), which can be refused or revoked at any time.
  • Photographs at the time clock — on the employer’s instructions, as its processor, in the employer’s legitimate interest in an honest record of working time (GDPR Article 6(1)(f)); the employer decides whether to switch it on and informs its staff.
  • System integrity and security monitoring — our legitimate interest in securing our infrastructure against fraud and cyber threats (GDPR Article 6(1)(f)).

7. Where data is kept, and international transfers

7.1Our database runs on Supabase’s managed infrastructure in the European Union (Warsaw). The application runs on Vercel, whose edge network serves requests from the region nearest the reader, with functions in the United States and the EU.

7.2Our core database is located within the European Union (Warsaw, Poland). However, as our operational headquarters are in Uzbekistan and certain technical service providers operate in the United States, personal data may be accessed from or transferred to locations outside the EEA and the UK. All international transfers are safeguarded under our Data Processing Agreement, which executes the European Commission’s Standard Contractual Clauses (Module Two) and the UK International Data Transfer Addendum with the relevant parties.

7.3We protect data in transit with TLS, separate every business’s data at the database row level, and encrypt stored third-party tokens.

8. Who we share data with

8.1Sub-processors that help us run the Service, each bound by a contract and used only for the purpose named:

  • Supabase (EU) — database and authentication;
  • Vercel (US) — hosting of the application;
  • Resend (US) — sending email: sign-in links, invitations and notifications;
  • Twilio (US) — sending SMS, only to people who have neither Telegram nor an email and only where the business has enabled it;
  • Telegram — the chat identifier and the text of a notification, to deliver it to a person who linked Telegram;
  • Paddle (UK/US) — payment for the Service, as merchant of record; Paddle receives the account owner’s name, email and billing country. We never receive card details;
  • Poster — only if the business itself connected its point-of-sale system, from which staff names, phone numbers and positions are read;
  • xAI (US) — only when a manager uses the assistant in the Telegram bot: the text of the manager’s message is sent to interpret the command, with staff names replaced by placeholder labels before sending; names, phone numbers, pay rates and schedules are not sent to xAI and are not kept there.

8.2We disclose data to public authorities only on a lawful and properly served request, and we tell the affected business unless the law forbids it.

8.3We do not share data with advertising networks and do not use third-party analytics that track users.

9. Who inside can see what

9.1Access is limited at the database level, not only in the interface. A member of one business cannot see another’s data; a member of staff sees their own shifts and requests; pay rates, the activity log and the timesheet are visible only to managing roles.

9.2On our side, only the people who need access to operate and support the Service have it.

10. How long we keep data

  • Sent notifications — 90 days, then deleted.
  • Team chat messages — 180 days, then deleted.
  • The activity log — 2 years, then deleted.
  • Expired invitation links — 7 days, then deleted.
  • Shifts, hours worked, pay rates, invoices and team membership — for as long as the business uses the Service. These are the employer’s payroll and working-time records, and deleting them would take from both employer and employee the evidence they would need in a dispute.
  • After a business closes its account, its data is kept for 90 days, then deleted.

11. Your rights

11.1You have the right to know what personal data we hold about you and to receive a copy; to have it corrected; to have it deleted; to restrict or object to its processing; to receive it in a portable form; and to withdraw consent where processing is based on consent. You will not be treated differently for exercising these rights.

11.2Write to contact@techatpt.com from the address on your account. We reply within 30 days, and within 15 where we can. A member of staff can also export everything held about them from the profile screen without asking anyone.

11.3If your request concerns staff data, we will tell the employer, as controller: some records we cannot delete unilaterally, because they are the employer’s records of working time.

11.4If you are in the EU or the UK you can complain to your data protection authority — in the UK, the Information Commissioner’s Office. We would rather you wrote to us first.

12. Security incidents

12.1If a breach of security affects personal data, we tell the affected businesses without undue delay and within 72 hours of becoming aware of it, with what we know and what we are doing, so that they can meet their own obligations to their staff and their regulator.

13. Cookies

13.1We use only the cookies the Service cannot work without: keeping you signed in, and remembering your language and which business you were looking at. There are no advertising or tracking cookies, so there is nothing to consent to and no banner.

14. Children

14.1The Service is for employers and their staff and is not directed at anyone below the age at which they may be employed in their country.

15. Changes

15.1We may update this policy. The date of the last change is at the top of the page. We tell account owners about material changes by email or in the product.

Company details

Name
ООО "PT TECHNOLOGIES"
Tax ID
313308723
Address
Toshkent shahri, Chilonzor tumani, Katta Navbahor MFY, S mavze
Director
Parpiyev Xasanboy Dilshodovich
Business activity
62.01.0
Certificate of registration
3339849
Registered on
05.09.2026
Email
contact@techatpt.com
Website
https://navbat7.techatpt.com

The full registered address appears on invoices and contracts and is available on request.