Privacy
Privacy Policy
Last updated 7 August 2026 · Published by CortexLabs
This policy explains what the VIX workforce pass collects about you, why it is needed, who can see it, and how you stay in control.
01Who we are
VIX — Verified Identity X-Tenant is a workforce identity platform built and operated by CortexLabs ("we", "us", "CortexLabs").
Where your employer uses VIX to manage clock-in, shifts and site access, your employer is the data controller and CortexLabs acts as a data processor on their documented instructions.
You can reach our privacy team any time at Cortexlabs.ai.app@gmail.com.
02Data we process
Identity data: your name, employee number, badge number, work email address, profile photo and pass version.
Employment data: your site or zone, shift and break records, timesheet totals, compliance signatures and asset returns.
Device and security data: NFC card identifier when you link a physical card, wallet pass issuance status, sign-in events and device integrity signals.
Optional data: location used only for geofenced clock-in when you grant permission, and messages you choose to send to colleagues.
03Why we process it
To verify your identity and issue your digital clock-in pass and wallet passes.
To record working time, breaks and payable hours accurately for your employer's payroll and legal record-keeping duties.
To keep sites safe — muster, first aid, incident reporting and access control.
To protect the platform against fraud, cloned passes and unauthorised access.
04Legal bases
Performance of your employment contract, your employer's legal obligations under working time and health and safety law, and the legitimate interests of your employer and CortexLabs in operating secure access control.
Location and biometric device unlock are used only with your explicit, revocable consent. Turning them off never blocks access to your pass.
05Encryption and security
Data is encrypted in transit with TLS and at rest by our cloud provider. Direct messages between colleagues are end-to-end encrypted on-device.
Access to your records is enforced at the database level by row-level security so only you, and managers of the sites you belong to, can read them.
Biometric checks stay on your device. We never receive or store your fingerprint or face data.
06Sharing
We share data with your employer and its authorised site managers, and with infrastructure sub-processors that host and secure the platform on our behalf.
We do not sell your data, and we do not use it for advertising or profiling.
07Retention
Working-time and timesheet records are kept for the period your employer is legally required to keep them, typically six years.
Sign-in and access logs are retained for up to 24 months. Messages are retained until deleted by you or your employer.
08Your rights
You may request access, correction, portability, restriction, objection or erasure of your personal data.
Because your employer controls your employment record, erasure requests are routed to your site manager. Email Cortexlabs.ai.app@gmail.com and we will help.
You may complain to the UK Information Commissioner's Office if you are unhappy with how your data has been handled.
09Changes
We will update this policy when the platform changes materially and will surface the new version in-app before it takes effect.