App Privacy Notice.
What the Inntally MySpace employee app collects on your phone, why it collects it, who decides what happens to it, and how to get it changed or removed.
Version 1.0 · Applies to Inntally MySpace for Android (com.inntally.myspace) · Last updated 8 September 2026
1. Who is responsible for your data
This matters more than anything else on this page, because it decides who you ask when you want something changed.
- Your employer is the data controller. The venue that employs you decides what is recorded about your work — your shifts, your attendance, your leave, your pay. They decide whether facial clock-in is switched on at all.
- Inntally Ltd. is the data processor. We build and run the software and we act on your employer's instructions. We do not decide what is collected about you, and we do not use your work data for our own purposes.
So: to correct a shift, an attendance record, your bank details or your leave, ask your employer. To ask about the software itself, or if your employer does not respond, contact us at dpo@inntally.com.
2. What the app collects, and only when
The app collects nothing in the background. Every item below is tied to something you do.
Your account and employment record
Your name, work email, job role, department and venue. This comes from your employer's HR record; the app reads it so it can show you your own shifts and pay. Required — the app cannot work without knowing who you are.
Location, when you clock in from your phone
If your employer has turned on phone clock-in and you choose to use it, the app reads your phone's location at that moment only, to confirm you are inside the venue's clock-in area. The position, its accuracy and the distance from the venue are stored on that attendance record so the decision can be explained later.
There is no background location. The app does not track your movements, does not run location when it is closed, and does not hold the "background location" permission at all. Clocking in at a wall terminal collects no location from your phone.
Facial verification, if your employer uses it
Some venues switch on facial clock-in. If yours has, a live image of your face is checked against a template held by your employer's Inntally system to confirm it is you.
- This is biometric data. Under GDPR it is a special category, and your employer must have a documented lawful basis and a Data Protection Impact Assessment before using it.
- The app shows you an explanation before the camera ever opens, and always offers another way to clock in. You are not required to use your face.
- The app does not keep a face template on your phone. The verification frame is sent for checking and is not retained by the app.
- A face match on its own never records attendance — the venue's system has to confirm the clock-in separately.
Photos you attach
When you report a problem, log maintenance, record lost property or complete a checklist that asks for evidence, the photo you take is attached to that record. The camera is only opened when you start one of those actions.
Messages and workplace posts
Messages you send colleagues, comments on the news feed, survey answers and recognition you give or receive. These are internal to your workplace. There are no public profiles and no one outside your venue can see them.
Recognising your phone
The first time you clock in from your own phone, the server issues that phone an opaque token, which the app stores. On later clock-ins the app sends it back so the system can tell it is a phone you have used before — this is what lets a QR scan know who you are without asking for your PIN again, and it is a fraud check on attendance.
Only a one-way hash of that token is stored on the server, never the token itself. You can remove it at any time by choosing "Not me" on the clock-in screen, or by signing out.
Payroll bank details
Your bank account details, so your employer can pay you. In the app they are shown masked, and revealing or changing them requires you to re-authenticate on your device. A change does not take effect until your employer's payroll team has verified it — the previously approved account stays in use until then.
What the app does not collect
No advertising identifiers. No analytics or crash-reporting SDK. No contacts, no call log, no SMS, no browsing history, no health data. There are no ads in the app and nothing in it is sold or shared for advertising.
3. Why, and on what legal basis
- Account and employment record — to show you your own work and let you act on it. Basis: contract (your employment).
- Attendance, including clock-in location — to record hours worked accurately and pay them correctly. Basis: contract, and legal obligation (working-time and pay records).
- Facial verification — to confirm identity at clock-in. The basis is set by your employer; as biometric data it also needs an Article 9 condition and a DPIA. An alternative method is always available.
- Photos on reports and checklists — evidence for safety, maintenance and compliance records. Basis: legitimate interests, and legal obligation where a record is required.
- Messages and workplace posts — running the workplace day to day. Basis: legitimate interests.
- Device recognition token — speed at clock-in, and preventing attendance fraud. Basis: legitimate interests.
- Bank details — paying you. Basis: contract, and legal obligation (payroll).
- Notifications — telling you about shift changes and decisions. Basis: consent, opt-in, and you can turn it off.
4. Who else sees it
Your data goes to your employer's Inntally system and stays there. We do not sell it, we do not share it for advertising, and there is no analytics or advertising SDK in the app.
Inntally uses infrastructure sub-processors to run the service — hosting, email and messaging delivery. They are listed in the Inntally Privacy Notice and are bound by data-processing agreements. Inntally infrastructure runs in AWS eu‑west‑1 (Dublin); your data stays in the EU.
Inside your workplace, what a manager can see is controlled by your employer's own permission settings — for example, your manager can see the shifts and attendance they are responsible for approving.
5. How long it is kept
Retention is your employer's decision as controller, within what Irish and EU law requires. In general: employment and payroll records are kept for the statutory period after your employment ends (attendance and working-time records must be kept for at least three years under the Organisation of Working Time Act); operational records such as checklists and maintenance jobs are kept for the venue's own compliance period.
The device recognition token is removed when you choose "Not me", when you sign out, or when your employer revokes the device.
6. How it is protected
- All traffic is encrypted in transit over HTTPS. Unencrypted connections are disabled in the app.
- Your sign-in tokens are held in Android's encrypted storage on your device.
- Revealing or changing bank details requires re-authentication on the device.
- Only a hash of the device token is stored on the server, so the token cannot be recovered from our records.
- Inntally is certified to ISO/IEC 27001:2022 (information security management) and ISO/IEC 27701 (privacy information management). Certificate details are available to customers under NDA.
7. Your rights
Under GDPR you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to processing, or ask us to restrict it. You can also withdraw consent where consent is the basis — for example by turning notifications off, or by declining facial verification and using another clock-in method.
Ask your employer first, because they are the controller and they hold the decision. In the app: Me → Privacy & data. If they do not respond, or you want to raise something about the software itself, contact dpo@inntally.com or privacy@inntally.com.
You also have the right to complain to the Irish Data Protection Commission at dataprotection.ie, or to your own country's supervisory authority.
8. Children
This app is for employed staff and is not directed at children. We do not knowingly collect data from anyone under 16.
9. Changes
If we change what the app collects, we update this notice and its date before the change ships. Material changes are notified in the app.
10. Contact
Inntally Ltd., Limerick, Ireland · Data Protection Officer: dpo@inntally.com · General privacy queries: privacy@inntally.com
See also the Inntally Privacy Notice, which covers the wider platform.