In short: CEMIS is an official staff application of the College Education Department, Government of Sindh. It is used by authorised government employees to mark attendance and access work-related services. To verify attendance, the app uses your precise location and a facial image (selfie) captured at the time you mark attendance. We do not sell your data, and we do not use it for advertising.
1. Introduction
This Privacy Policy describes how the College Education Department, Government of Sindh (“CED”, “we”, “us” or “our”) handles personal information collected through the CEMIS mobile application (the “App”, package name pk.gov.sindh.ced.cemis_mobile). By downloading, installing or using the App, you acknowledge the practices described in this policy.
The App is intended solely for officials, faculty and staff of the College Education Department and its colleges. It is not a public consumer application.
2. Who we are
The data controller is the College Education Department, Government of Sindh, Tughlaq House, Sindh Secretariat, Karachi, Sindh, Pakistan. The App and its supporting systems (CEMIS) are operated on behalf of the Department. For privacy queries, contact [email protected].
3. Information we collect
We collect only the information needed to operate the App and verify staff attendance:
Account & identity information
- Your name, personnel/employee number and, at registration, your CNIC used to confirm you are a genuine employee on record.
- Your designation, grade/BPS, subject, and posting/office as held in departmental records.
- Contact details associated with your service record, where applicable.
Attendance & activity data
- Attendance events (check-in / check-out), including the date, time and status (present, late, half-day, etc.).
- Field-visit records and any leave, NOC or transfer requests you submit through the App.
Location information
- Your precise (GPS) location at the moment you mark attendance or record a field visit, used to confirm you are within the approved geofence of your posting.
Camera & facial image
- A selfie / facial image captured by the camera when you mark attendance, used to verify your identity (1:1 face match).
Device & technical information
- A device identifier used to bind your account to a single trusted device.
- Integrity signals (whether the device is rooted, an emulator, or reporting a mock/fake location) used to prevent attendance fraud.
- Network state, app version, and a push-notification token (Firebase Cloud Messaging).
4. How we use your information
- To authenticate you and confirm you are an authorised employee.
- To record and verify staff attendance, including geofence and identity checks.
- To process work requests you submit (e.g. leave, NOC, transfer, field visits).
- To protect the integrity of attendance by detecting spoofing, mock locations and unauthorised devices.
- To send you service notifications relevant to your account.
- To meet the administrative, record-keeping and audit obligations of the Department.
We do not sell your personal information, and we do not use it for third-party advertising or profiling.
5. Location data
The App requests precise location access to verify that attendance is marked at your approved place of posting. Location is read only at the moment you take an attendance or field-visit action; the App does not track your location continuously in the background. You may decline the location permission, but attendance marking that depends on a geofence will not function without it.
6. Camera & facial verification
The App uses the camera to capture a selfie for facial verification when you mark attendance. Face matching is performed on your device (using an on-device model) to compare your live selfie against your enrolled face template. The captured selfie may be transmitted to and stored on the Department's secure servers as an attendance record and for review of mismatches by authorised administrators. Facial images are used strictly for identity verification of attendance and are not used for any unrelated purpose.
7. Device & security data
To keep attendance trustworthy, the App binds your account to a single device and checks for signs of tampering — such as rooted/jailbroken devices, emulators, or mock-location tools. These checks may block attendance from a compromised device. This information is used only for security and fraud prevention.
8. How your information is shared
Your information is handled within the Government of Sindh and shared only as follows:
- Within the Department: with authorised administrators and reporting officers for attendance, HR and audit purposes.
- Service providers: Google Firebase Cloud Messaging is used to deliver push notifications. Push tokens are processed by Google solely to route notifications.
- Legal requirements: where disclosure is required by applicable law or lawful government process.
We do not share your personal information with advertisers or data brokers.
9. Data storage & security
- Data in transit is protected using encrypted (HTTPS/TLS) connections.
- Authentication tokens are held in the device's encrypted secure storage.
- Attendance captured while offline is queued in a local, app-private database and synced to the server when connectivity returns.
- Server data is held on infrastructure managed for the Department with access restricted to authorised personnel.
No system can be guaranteed perfectly secure, but we apply reasonable technical and organisational measures to protect your information.
10. Data retention
Attendance, activity and identity records are retained for as long as necessary to serve the administrative and audit purposes of the Department and as required by applicable government record-keeping rules. Locally cached data on your device is removed when you log out or uninstall the App.
11. Your rights
Subject to applicable law and departmental policy, you may request access to, correction of, or clarification about the personal information the Department holds about you through the App. Because records here are tied to your official government service record, such requests are handled through the Department. Contact [email protected].
12. Children's privacy
The App is a workforce application for government employees and is not directed to, or intended for use by, children. We do not knowingly collect information from children.
13. App permissions we request
- Location (precise): to verify attendance within your posting's geofence.
- Camera: to capture the selfie used for facial verification.
- Notifications: to deliver service and attendance notifications.
- Network access: to communicate with the Department's servers.
You control these permissions in your device settings and may revoke them at any time, though some features will stop working.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be communicated through the App or the Department where appropriate.
15. Contact us
College Education Department, Government of Sindh
Tughlaq House, Sindh Secretariat, Karachi, Sindh, Pakistan
Email: [email protected]
Questions about this document? Contact the College Education Department at [email protected].