Privacy Policy – TERMINAL by Jurist Soft
Effective date: 25.08.2026
Application name: TERMINAL BY JURIST SOFT
Platforms: Android and iOS
Company: Jurist Soft doo Niš, Republic of Serbia
Contact: contact form at juristsoft.com
Privacy Policy URL: https://juristbiro.com/terminal/politika-privatnosti
1. Introduction
TERMINAL BY JURIST SOFT ("Terminal" or the "Application") is a business-to-business (B2B) application intended for use on a device (tablet or phone) that the employer permanently installs at a work location, operating in kiosk mode.
Terminal provides technical support for recording employee attendance by displaying a continuously changing QR code and emitting a Bluetooth Low Energy (BLE) beacon signal that the TEMPUS mobile application can detect.
The user of the Terminal is exclusively the employer, or an administrator authorized by the employer to configure the device at the workplace. Terminal is NOT intended for individual employees — employees never interact directly with the Terminal via its screen or keyboard; they only scan the QR code displayed by the Terminal using their own phone and the TEMPUS application, or are automatically recognized via the Bluetooth signal.
The login account for the Terminal (the employer's email and password) is created administratively by JURIST SOFT, as part of the employer's B2B onboarding process — the Application does not have a form for self-registration or account creation.
2. Roles in Data Processing
The employer determines the purposes and manner of use of the Terminal device and related attendance-recording functions, and in that respect has the status of Controller of its employees' data.
Jurist Soft provides the application and the technical infrastructure of the system and may process data on behalf of the employer, in accordance with its instructions, the contractual relationship, and applicable regulations, acting as a Processor.
3. Administrator Account Data
Terminal processes the data required for the login of the authorized administrator/employer, such as e-mail address, account identifier, authentication token (JWT), and other technical data necessary to maintain the user session. Terminal does not include an account registration form.
Sensitive authentication data (JWT token) is stored in the device operating system's secure, encrypted storage (FlutterSecureStorage — Android Keystore on Android devices, or the iOS Keychain on iOS devices).
Data on the selected work location, employer name, QR-display identifier, and the cache of the last server response are stored locally on the device in standard (unencrypted) storage (SharedPreferences on Android / UserDefaults on iOS); this local cache does not contain employees' personal data.
4. QR Code
Terminal generates and displays a QR code that changes periodically for security purposes, which the employee scans via the TEMPUS application on their own phone.
Terminal does not have a camera or any scanning function — it only displays the QR code on its screen. Terminal does not collect or store photographs or video.
5. Bluetooth Low Energy (BLE) Beacon
Terminal may emit a short Bluetooth Low Energy (BLE) signal (beacon) containing a technical identifier of the work location, to enable the TEMPUS application on the employee's phone to automatically recognize proximity to the Terminal.
This transmission is one-directional — the signal travels exclusively from the Terminal outward. Terminal does not scan for or receive Bluetooth signals from nearby devices, does not recognize which phones are nearby, and does not collect or store any data about employees who receive that signal.
6. Location of the Terminal Device
Terminal may use the device's precise GPS location exclusively when the authorized user (employer/administrator) manually triggers the "Send location" function. In that case, the location of the TERMINAL ITSELF (a fixed device), not of individual employees, is read once and sent to the backend server, to confirm the physical location where the Terminal has been installed.
Terminal does not collect GPS location automatically or in the background, and does not track movement — Terminal is a fixed device that remains in one place, so location is sent only at the user's explicit request, for a one-time confirmation of the device's position.
7. Kiosk Mode
Terminal uses a function that prevents the screen from turning off (wakelock) to ensure continuous operation in kiosk mode at the workplace. This function does not, in itself, constitute the processing of personal data.
8. Data Not Collected by Terminal
Terminal does not use the camera, microphone, or biometric functions. Terminal does not access contacts, photos, or SMS messages. Terminal does not collect the personal data of individual employees (names, phone numbers, photographs) — such data, where processed, remains exclusively within the TEMPUS application on the employee's phone and its corresponding Privacy Policy. Terminal does not use an advertising identifier and does not share data with advertising networks.
9. Third-Party Services
Terminal uses Firebase Analytics and Firebase Crashlytics for application usage analysis and technical error diagnostics. These services process technical data (application version, error type, screen usage patterns) and do not process employees' personal data or the content of attendance records.
Terminal may also use the Sentry service for error diagnostics, once that function is activated by the Service Provider. In that case, the same protective measures (masking of sensitive content) apply as with the TEMPUS application.
10. Backend Infrastructure and Data Transfers
Communication between the Terminal application and the backend system takes place over HTTPS. The backend infrastructure of the JuristBiro/TEMPUS system is hosted on Amazon Web Services (AWS) infrastructure in Frankfurt, Federal Republic of Germany. Germany is a member state of the European Union, and accordingly, pursuant to Article 65 of the Law on Personal Data Protection of the Republic of Serbia, an adequate level of data protection is deemed to be ensured.
11. Data Retention
Data is retained only for as long as necessary for the purpose of its processing, in accordance with the contractual relationship with the employer and applicable regulations. Local authentication and technical data is stored in the device's secure storage while the Terminal is logged in and active, and is removed upon logout or reset of the Application.
12. User Rights
The authorized user (administrator/employer) may, in accordance with applicable regulations, have the right to access, rectify, erase, restrict processing, object, and contact the competent data protection authority with respect to their administrator account data. With respect to employee data processed via the TEMPUS application, the rights described in the TEMPUS Privacy Policy shall apply.
13. Security
Jurist Soft applies technical and organizational measures designed to protect data and the Terminal system from unauthorized access, alteration, loss, or misuse, including encrypted communication (HTTPS), secure storage of sensitive local data, and access control to the backend system.
14. Minors
Terminal is not intended for minors and is not used as a personal application of natural persons. The Application is used exclusively by the employer's authorized administrators.
15. Changes to This Policy
This Privacy Policy may be updated when the functions of the Terminal application, the manner of data processing, the services used, or legal requirements change. The date of the last amendment is stated at the top of this document.
16. Contact
JURIST SOFT DOO NIŠ
Aleksandra Medvedeva bb
18000 Niš
Republic of Serbia
Contact form: juristsoft.com/contact
Web: www.juristsoft.com
Privacy Policy URL: https://juristbiro.com/terminal/politika-privatnosti