Weplanifyweplanify
30-day free trial

Legal information

Privacy policy

What Weplanify does with personal data, on this site and in the application: who decides, what is collected, why, for how long, who has access, and how to exercise your rights.

Version of

Who is responsible for your data

Weplanify acts in two capacities, and you exercise your rights with whoever decides how your data is used.

  • On the weplanify.io website, Weplanify is the data controller

    For trial requests, conversations with our team and browsing the site, Weplanify decides why and how the data is processed.

  • In the application, the client company is the data controller, and Weplanify its processor

    The subscribing employer decides which employees it tracks, what it enters and how its teams clock in. Weplanify processes this data on its behalf and on its instructions.

  • Are you an employee of a client company?

    Your employer is your first point of contact: it chose Weplanify and decides how your data is used. If you write to us, we pass your request on to it.

Data controller for the website

Company
WEPLANIFY SARL (Senegal) and XIPINA LLC (Wyoming, United States)

Data collected by the website

  • The trial request

    The form on the Request a trial page collects your name, your company’s name, your email, your WhatsApp phone number and the company’s headcount range, with the date sent. Nothing else. The request is stored in Firebase (Google), where only the Weplanify team can read it. It is used to call you back or message you on WhatsApp, then to prepare your account.

  • WhatsApp and phone

    If you message us on WhatsApp or call us, we receive your number and the content of our exchanges. On WhatsApp, they also go through that service, run by Meta, under its own rules.

  • Browsing

    The site contains no audience measurement or advertising tools, and sets no cookies. It keeps your language choice in your browser (see the Cookies page). As with any website, the server and Cloudflare receive the IP address, the page requested and the browser type of each visit: this is needed to serve pages and block attacks.

  • Fonts

    The site’s fonts are loaded from Google Fonts: your browser then contacts Google’s servers, which receive your IP address.

Data processed in the application

What an account contains depends on the modules the client company uses and what it enters. The application may process:

  • Identity and position

    Name, phone number (used to sign in to the mobile app, without a password), email, employee number, job, site, team, working hours, profile photo, and any custom fields the employer adds.

  • Personal details used for payroll

    Sex, date of birth, ID number, marital status, number of children and wives, spouse without income, tax residence, bank and account number. They are used to calculate pay (tax allowances, contributions) and to transfer the salary.

  • Contract and payroll

    Contract, salary and pay items (bonuses, benefits, advances and loans, expense claims), payslips, payroll reports and accounting entries. Contracts are visible only to people with payroll access.

  • Schedules and clock-ins

    Planned shifts, arrival and departure times, lateness, overtime, and every correction with its reason and author. Each clock-in also records the phone’s position at that moment, which is used to flag a clock-in made away from the site. With face recognition, a photo is taken (see below).

  • Leave, requests and forms

    Leave and absence requests with supporting documents, approval chains, completed forms (reports, checklists, surveys), expense claims with a photo of the receipt.

  • Documents and signatures

    Contracts, ID documents, certificates and other files uploaded by the employer or the employee. An electronically signed document ends with a proof page: the signature, the date and time, the IP address and the digital fingerprint of the original document.

  • Day labourers

    Name, phone, photo if the employer requires it, days worked and payments.

  • Locations

    The application records the phone’s position at the moment of a clock-in and, depending on settings, when a form is filled in or a job is carried out. These are one-off positions: the application does not track movements continuously.

  • Messages and notifications

    Messages exchanged in the application, and the phone’s notification identifier, used to send it reminders.

  • Management accounts and subscription

    Name and email of administrators and managers, a record of their actions (who created or changed what, and when), subscription and billing history.

Face recognition

  • It is used only if the employer chooses it for an employee, on that employee’s record.
  • The photo taken at clock-in is compared with the employee’s profile photo, on Weplanify’s server, by a recognition model installed on that server. No image is sent to a third-party service for this comparison.
  • No biometric template is stored: the comparison is redone at every clock-in, from the two photos.
  • If the check succeeds, the clock-in photo is deleted at once. If it fails, the photo is kept with that day’s record, so a manager can check who clocked in.
  • Face recognition processes biometric data. The employer, as data controller, informs its employees and completes the formalities required in its country; in Senegal, with the CDP.

Why, and on what legal basis

Each processing operation has a specific purpose and a basis provided for by Senegalese Law No. 2008-12 of 25 January 2008 on the protection of personal data.

Answering a trial request, calling you back, preparing your account
Pre-contractual steps taken at your request.
Providing the application to client companies, onboarding and support
Performance of the subscription contract. For employee data, the basis is the one the employer relies on: most often the employment contract and the legal obligations that follow from it (payroll, social and tax filings).
Billing the subscription and keeping accounts
Performance of the contract and legal accounting and tax obligations.
Protecting the site and application against attacks and abuse
The security obligation that applies to every data controller.
Remembering your display language
The service you ask for by choosing a language. Nothing is sent.

The website and the web application contain no advertising tools: your data is not used to target you.

How long

Application data
For the whole subscription. When the contract ends, the client exports them; they are then deleted.
Face clock-in photo
Deleted at once if the check succeeds; kept with that day’s record if it fails.

Who has access

In the application, data is visible only to the users the client company authorises, module by module. At Weplanify, the team that handles onboarding and support accesses it to configure the account and answer the client’s requests.

Weplanify uses the following providers, which process data on its behalf:

  • Server host

    Runs the website, the application and its API.

    Provider:
    Amazon Web Services (AWS): Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, United States
  • Cloudflare (United States)

    Protects and speeds up weplanify.io, app.weplanify.io and the application’s API: all traffic goes through this service.

  • Amazon Web Services, S3 (United States)

    Stores the application’s files: documents, PDF payslips, photos. They open only through signed links, valid for one hour.

    Storage country:
  • Google Firebase (United States)

    User sign-in (by phone number or email), phone notifications and in-app messaging; on the website, trial requests, articles and documentation.

    Hosting country:
  • Google Cloud Document AI (United States)

    Reads photographed receipts automatically, only if the company turns it on for an expense type. The employee always confirms or corrects what was read.

  • Stripe (United States)

    Subscription payment by bank card.

  • PayDunya

    Subscription payment by mobile money.

  • Email delivery

    Sends the application’s emails.

    Provider:

WhatsApp (Meta) is involved only if you choose to message us that way.

Transfers outside the country

Cloudflare, Google, Amazon Web Services and Stripe are American companies: data may therefore be processed outside Senegal and outside Africa. The application server and its files are hosted by Amazon Web Services.

Law No. 2008-12 allows personal data to be transferred to another State only if it ensures an adequate level of protection, or in the cases the law provides for, under the CDP’s oversight.

Security

  • All connections to the website, the application and its API are encrypted (HTTPS).
  • Each client company is isolated from the others: a user sees only their own company’s data and, within it, only the modules they have access to.
  • Files open only through signed links, which expire after one hour.
  • Creations and changes keep their author and date; a clock-in correction also keeps its reason.
  • A signed document carries a proof page that makes it possible to check it has not been altered since.

Your rights

Law No. 2008-12 gives you the following rights over your personal data:

Access
Find out whether data about you is processed, and obtain a copy.
Rectification
Have inaccurate or incomplete data corrected or completed.
Objection
Object, on legitimate grounds, to processing, and without giving grounds to any marketing use.
Deletion
Have data erased that is inaccurate, incomplete, out of date, or no longer lawfully kept.

To exercise them over the website’s data, write to us on WhatsApp at +221 78 661 00 53. Say what you are asking for; we may ask you to prove your identity.

For application data, contact your employer first, as the data controller. If you write to us, we pass your request on to it.

Complaints to the CDP

If you believe your rights are not being respected, you may complain to the Commission de protection des données personnelles (CDP), the Senegalese authority set up by Law No. 2008-12: www.cdp.sn. If you live in another country, you may also contact that country’s data protection authority.

Minors

The website and the application are aimed at companies and their teams. They are not intended for children, and the trial form is not meant to be filled in by a minor. When a client company employs a minor, it is up to it to make sure the processing of their data complies with applicable law.

Changes

This policy changes when the service changes: a new provider, a new feature. The date of the current version is shown at the top of the page.