NO AADHAAR

A Non-Aadhaar Attendance App for Private Employers

Attendance without Aadhaar numbers, AEBAS devices or biometric templates. Each work session runs under a personal login, carries its project, and is approved by a manager — which is the record an inspector, an auditor or a client actually asks for.

What replaces the reader

Four steps on a phone your team already owns, ending in an attendance record that names the manager who approved it.

09:41
Workclave

Sign in

Use your work account.

Work emailpriya.sharma@company.in
Password
Sign in

Your account is the identity. Workclave stores no biometric data.

Nowhere in those four steps

  • Aadhaar number
  • Fingerprint or face template
  • AEBAS device registration
  • Screenshots or keystroke logs

Drawn from the product, not screenshotted — the screens move between releases, the four steps do not.

Why private employers are looking for a non-Aadhaar option

The Aadhaar Enabled Biometric Attendance System was built for government offices and public-sector bodies, and it is the reason many Indian buyers now assume attendance means Aadhaar. For a private company it is a poor fit. You inherit a device estate, an authentication dependency and a category of personal data you had no business reason to hold — all to prove a fact that a login and an approval already prove.

The legal position is narrower than the market assumes. Section 7 of the Aadhaar Act, 2016 ties mandatory Aadhaar authentication to subsidies, benefits and services funded from the Consolidated Fund of India. That is not a private employer paying salaries out of its own revenue. Puttaswamy (2018) struck down Section 57, which had been read as permitting private bodies to demand Aadhaar authentication under a contract. Private-sector Aadhaar use has been treated as voluntary and constrained ever since, which is precisely the ground on which an employee can decline.

What this app does not collect

The clearest way to describe a non-Aadhaar attendance app is by what is absent. None of the following is captured, stored, hashed or sent anywhere, because none of it is needed to know that someone worked.

  • No Aadhaar number, virtual ID or last four digits.
  • No Aadhaar authentication, eKYC or AUA/KUA integration.
  • No fingerprint, iris or face template — the underlying biometric is never captured, so there is nothing stored and nothing to breach.
  • No AEBAS device registration or dependency on UIDAI availability.
  • No screenshots, keystroke logging or covert background agent.

What proves attendance instead

Attendance is a claim about a person and a period, and it needs evidence. Workclave's evidence is a session: a block of work started and stopped under a personal login, attached to a project, with a manager's approval recorded against it afterwards. The manager is a named human who knows what work happened that day, and their approval is kept with the session permanently.

That structure is harder to game than a shared badge or a colleague's finger on a reader, because falsifying it requires a manager to approve work they know did not occur, on a record that keeps their name. It is also a richer record: a biometric punch tells you a body touched a scanner at 09:42, while an approved session tells you who worked, for how long, on which client's project, and who signed it off.

The DPDP position, stated accurately

It is worth being precise here, because the market copy on this is frequently wrong. The Digital Personal Data Protection Act, 2023 does not create a separate 'sensitive personal data' tier for biometrics — that categorisation came from the SPDI Rules, 2011, which the DPDP framework moves away from. The DPDP Act applies one standard to all personal data: notice, consent or a listed legitimate use, purpose limitation, data minimisation, and deletion when the purpose ends.

Minimisation is what makes the Aadhaar-and-biometrics route hard to defend for attendance. If a login plus a manager approval establishes the same fact, then collecting an Aadhaar number or a fingerprint template collects more personal data than the purpose requires. Not collecting it is the shortest compliance story available: there is no consent artefact to maintain for data you never took, no retention schedule for a template that does not exist, and no breach-notification exposure for a database you never built.

No Indian labour law requires Aadhaar or biometrics for attendance

The state Shops and Establishments Acts and the labour codes require an employer to maintain an accurate attendance register and produce it on inspection. They specify the record, not the capture mechanism. No provision names Aadhaar, fingerprints or face recognition as the required method, and an inspector's question is whether the register is accurate and contemporaneous — not which device produced it.

So the practical test is evidentiary rather than technological: can you show who worked, on which day, for how long, and can you show it was not reconstructed after the fact? Timestamped sessions with a recorded approval and a preserved edit history answer that. That is what the register needs to be, whatever collected it.

  • Attendance registers required; the capture method left to the employer.
  • Timestamped start and end times per session, not a daily guess.
  • Manager approval recorded against each session, with the approver named.
  • Corrections kept as an audit trail rather than silently overwriting the original.

When employees decline, and why that matters

Because private-sector Aadhaar use is voluntary, a policy built on it has a failure mode built in: a single employee declining leaves you running a parallel manual process for them, which is the process you bought software to eliminate. The same applies to biometric refusal on religious, medical or privacy grounds, and to contractors and consultants whose Aadhaar you have no standing to ask for at all.

A login-based record has no such branch. Permanent staff, contractors, remote engineers and on-site teams all produce the same session record in the same system, and the attendance report has one shape. Removing the opt-out removes the exception handling.

What it costs to switch off the hardware

There is no attendance hardware in this model, which changes the arithmetic. No readers per site, no annual maintenance on devices, no replacement units, no field visit when a scanner fails at a branch office. Workclave is free for up to 3 users and ₹199 per user per month after that, with no base platform fee and no seat minimum.

Retiring the readers is not a prerequisite. Plenty of teams keep a gate device for physical access to the building and use Workclave for the attendance and billing record — the part an inspector or a client asks to see. The access-control decision and the attendance-record decision are genuinely separate, and treating them as one is what usually locks a company into biometric attendance it never explicitly chose.

Frequently asked questions

Can a private company legally require Aadhaar for attendance?

The ground is narrow. Section 7 of the Aadhaar Act, 2016 links mandatory authentication to subsidies, benefits and services drawn from the Consolidated Fund of India, which does not describe a private employer paying salaries from its own revenue. Puttaswamy (2018) struck down Section 57, the provision read as allowing private bodies to demand Aadhaar under a contract. Private-sector use has been treated as voluntary since, so an employee can decline — which is why a policy built on it needs a fallback anyway. Take your own legal advice on your specific facts.

Is AEBAS mandatory for private employers?

No. AEBAS was built for government offices and public-sector bodies. There is no requirement for a private company to register devices with it or to route attendance through Aadhaar authentication.

Without Aadhaar or biometrics, what stops proxy attendance?

Sessions run under a personal login and are approved by a manager who knows what work happened that day. Marking someone falsely present means that manager approving work they know was not done, on a record that keeps their name against the approval. That is a harder thing to do quietly than handing a colleague your badge or your finger.

Does the DPDP Act ban Aadhaar-based attendance?

No, and it does not treat biometrics as a separate sensitive tier the way the SPDI Rules, 2011 did. It applies one standard to all personal data: notice, consent or a listed legitimate use, purpose limitation, minimisation and deletion. Minimisation is the hurdle for attendance specifically — if a login and an approval prove the same fact, collecting an Aadhaar number or a biometric template collects more than the purpose needs.

We already run an AEBAS or biometric setup. Is this rip-and-replace?

Not necessarily. Keeping a reader for physical access to the building while moving the attendance and billing record into Workclave is a common arrangement. If you do retire the devices, retiring the template store with them is the point rather than a side effect.

Do you store Aadhaar numbers anywhere, even hashed?

No. There is no Aadhaar field in the product, hashed or otherwise, and no UIDAI integration. A user is identified by their account, not by a national ID.

Start free — up to 3 users, no base fee.

Session-based attendance built for Indian IT teams and agencies. ₹199/user/month after the free tier, priced in ₹, DPDP-aligned and India Labour Code ready.