Cloud data and retention
This page sets out the data boundary for cloud reporting: what leaves the computer, what the cloud service accepts, and how long it keeps it. It is for administrators, data protection contacts and anyone reviewing BioTrack before turning cloud reporting on.
A fixed list of fields
Section titled “A fixed list of fields”BioTrack does not upload its database. For each record, the sender builds a new message containing only the fields on a fixed list, and refuses to send a record that does not match it.
| Record type | Fields sent |
|---|---|
| Attendance event | Event identity, the employee’s ID on the terminal, employee name, employee type, event type, time of the scan, time BioTrack received it, terminal name (if known) |
| Calendar override | Date, working or non-working day, name, the local ID of the user who made the change |
| Leave | The employee, the leave dates and details, the local ID of the user who entered it |
| Leave revocation | The leave withdrawn, when, the reason, the local ID of the user who withdrew it |
| Attendance correction | The employee, the business date, the reason, the day’s result before and after, the local ID of the user who made it |
Every record also carries a unique operation ID and the time it was created, so the cloud can recognise repeats.
Corrections never change the original scans. A correction record contains only the day’s result before and after the change.
Never sent
Section titled “Never sent”- Biometric templates, face images or other biometric media
- BioTrack passwords, password hashes and sign-in sessions
- Terminal user names and passwords
- Recovery passphrases and other recovery secrets
- Raw requests from the terminal
- The installation’s private signing key
What the cloud service checks
Section titled “What the cloud service checks”The cloud service does not trust the computer to get this right. Before it stores anything, it:
- checks the request’s signature against the key registered for this installation, and refuses requests with a clock more than five minutes out or a reused one-time value;
- rejects any record with fields it does not expect;
- rejects any record containing field names that suggest passwords, credentials, sessions, biometric data, templates, images or raw event data;
- accepts a batch only as a whole. A rejected batch is not partly stored.
Organisations are kept apart
Section titled “Organisations are kept apart”The computer never tells the cloud which organisation it belongs to. When your commissioner creates the activation code, it is tied to one organisation (tenant) and one site. On activation, the cloud records that link against the installation’s key. From then on, the cloud decides where each batch belongs from the installation that signed it.
Two organisations whose terminals happen to use the same employee IDs remain separate.
Retention
Section titled “Retention”Each organisation’s cloud data is kept for a period chosen when it is commissioned: 1, 3, 5 or 7 years. There are no other options.
- Automatic deletion. Once a day, the cloud service deletes that organisation’s attendance events, calendar overrides, leave, corrections, delivery records, health history and audit history that are older than the retention period.
- Deletion counts only. The cloud keeps a record of each deletion run with the number of items removed, but not the removed data itself.
- Late records are refused. If a batch contains a record whose date or creation time is already outside the retention period, the cloud rejects it. An old backlog or a replayed request cannot bring expired data back.
- Changing retention. Only your commissioner can change the period, and only between the same four values. Reducing it deletes older cloud data at the next daily run, so it needs your organisation’s approval first. See Commissioning the cloud service.
Retention in the cloud does not affect the data on this computer. The local database keeps its own history.
Keys and backups
Section titled “Keys and backups”- The private signing key is created on the computer, encrypted with Windows protection, and never shown in the app, sent to the cloud, or included in support bundles.
- Portable backups leave out the cloud address, the signing keys and the cloud registration details. A restored backup starts with cloud reporting off. See Backup and recovery.