Taqniva product
Staff Lock Privacy Policy
Effective and last updated: 16 July 2026
Staff Lock is an enterprise device-control product for organization-owned or explicitly organization-managed devices. A customer organization determines its staff accounts, approved apps, duty schedule, location radius, and device-release decisions. Taqniva supplies and operates the Staff Lock service.
Information processed
- Organization and administrator information: organization name and code, administrator account identifier and email, plan and subscription status, policy configuration, approved app package identifiers, and administrator actions.
- Staff account information: staff name, email address or mobile number supplied by the organization, an internal member identifier, login aliases, account status, and protected credential records.
- Device and compliance information: Android installation or device identifier, assigned member, battery level, last-seen time, app version, restriction state, Device Owner and lock-task state, Accessibility status, local VPN status, call-screening role, location-permission status, and notification-policy status.
- Location-radius mode: the administrator device location and configured radius are sent to the service during an active location session. The staff device uses its location to calculate distance and enforcement state. Staff Lock reports the resulting status; it is not designed to store a continuous staff-location history.
- Duty-hours mode: start time, end time, time-zone offset, target devices, release state, and schedule status.
- Security and audit information: authentication events, rate-limit records, Firebase App Check information, policy-change logs, device-release logs, timestamps, and technical diagnostics.
Accessibility and app activity
During an active restriction, the Android Accessibility service observes the package identifier of the foreground app so the device can return to Staff Lock when an unapproved app is opened. Staff Lock does not use this service to read typed text, passwords, messages, contacts, or screen content. Foreground package checks are processed on the device and are not designed to create an app-usage history.
Local VPN and network control
Staff Lock uses Android VpnService as an on-device firewall during an active restriction. Approved apps are excluded from the local blocking interface and continue to use their normal network connection. The Staff Lock firewall does not route traffic through a Taqniva VPN server and is not designed to inspect or retain browsing content.
Call and interruption controls
If the organization enables the Android call-screening role and notification-policy access, Staff Lock may reject calls and suppress interruptions during an active restriction. Phone numbers are not written to Staff Lock application logs. The operating system or phone app may retain its normal call log.
Purposes and legal responsibilities
Information is used to authenticate authorized users, apply and verify organization policy, make approved work apps available, release devices, display compliance status, prevent abuse, maintain audit records, provide support, enforce subscriptions, and protect the service. The customer organization is the controller or equivalent decision-maker for staff-management data and instructions. Taqniva acts as a service provider or processor where applicable and also processes limited service, security, billing, and account information for its own legitimate operational purposes.
Service providers and sharing
Staff Lock uses Google Firebase services, including Authentication, Cloud Firestore, Cloud Functions, and App Check, and uses Android platform services for device policy, Accessibility, location, call screening, notifications, and local VPN control. Information may be processed by these providers to supply those functions. We do not sell Staff Lock personal information and do not use it for advertising profiling.
Retention
Organization, member, device, and audit records are retained while the customer account is active and afterwards only as needed for security, dispute resolution, legal obligations, backup cycles, and documented service-retention requirements. Temporary login rate-limit records are designed to expire. Customer administrators should remove staff access promptly during offboarding.
Security
Controls include authenticated administrator roles, protected credential hashing, Firebase App Check, server-side authorization, subscription checks, restricted database rules, upload signing, and server-generated audit records. No system guarantees absolute security. Customer organizations remain responsible for administrator account security, device inventory, enrollment custody, and timely removal of former staff access.
Staff choices, access, correction, and deletion
Staff members should first contact their organization administrator to correct account information, request a device release, or complete offboarding. Privacy requests may also be sent to hello@taqniva.com with the organization name and enough information to route the request. We may ask the customer organization to verify and authorize a request where it controls the relevant record.
Children and school deployments
Staff Lock is designed to manage staff devices, not student accounts or student surveillance. A school using the service must assess applicable education, employment, child-privacy, labour, and data-protection requirements before deployment. Student-device management requires a separately reviewed product configuration, contract, notice, and age-appropriate safeguards.
Changes and contact
We may update this policy when the product, providers, or legal requirements change. Material changes will be reflected by the date above and, where appropriate, an updated in-app acknowledgement. Contact hello@taqniva.com.