Skip to content

Privacy Policy

abbas0444 edited this page Sep 9, 2026 · 1 revision

Privacy Policy

Nexus ZKT Integration — last updated 10 September 2026.

The short version

This app collects nothing, sends nothing, and phones nobody. It runs entirely inside your own Frappe site and your own network. The author has no access to your data and no way to obtain it.

There is no telemetry, no analytics, no usage reporting, no licence check, no update ping and no external API of any kind.

What data the app touches

All of it stays on your server, in your own database.

Data Where it comes from Where it goes
Punch records — a user ID and a timestamp Read from your ZKTeco devices Turned into Employee Checkin records in your site
Attendance Device ID Your own Employee records Used to match a punch to a person. Never modified.
Device address, port and communication key Typed into Nexus ZKT Settings by you Stored in your database. The key is stored in Frappe's encrypted password field.
A log of what each run did Written by the app The Nexus Attendance Log in your site, emptied weekly

Personal data

Attendance data is personal data about your staff in most jurisdictions, including under the GDPR. You are the data controller for it, not the author of this app. This app is a tool you run; it processes that data on your instruction, inside your own systems.

Your obligations — telling staff their attendance is recorded, keeping it only as long as needed, honouring access and deletion requests — are yours, and are the same as they were before you installed this.

Two things worth knowing:

  • The Nexus Attendance Log records device user IDs (numbers such as 101), not names. It empties itself weekly, and has a Clear Logs button.
  • Employee Checkin records are HRMS records and are governed by your existing ERPNext retention policy. Uninstalling this app does not delete them.

Network connections

The app opens exactly one kind of connection: from your server to the IP address and port you typed into Nexus ZKT Settings, over the ZK protocol.

It makes no other outbound connection. If you forward a device to the public internet so your server can reach it, please read the warning in Networking — ZK devices have very weak authentication.

Third parties

The app depends on the open-source Python package pyzk to speak the ZK protocol. pyzk also makes no external connections. No other third-party service is involved.

Children

The app is a business tool and is not directed at children.

Changes

This policy may be updated. The date at the top of this page is the date of the last change.

Contact

Questions about this policy: Abbas Raza — abbasraza0444@gmail.com

Clone this wiki locally