ITN-Zeiterfassung — every function in detail
From clocking in on any device through to the finished payroll export: ITN-Zeiterfassung in detail — every function with screenshots from the running application, in the order in which you meet them in the program itself. The interface of ITN-Zeiterfassung is currently available in German.
New: messages to a person, a department or everyone — with read receipts — on a desktop and in the mobile app. Alongside them the request workflow — leave, special leave, business travel, flexitime compensation, time corrections and cancellations are submitted by staff themselves, at a desk or on a phone, and decided with a single click — with the department head role, a deputy per group, the management status and a line manager named for each person — as well as the log, which makes every change traceable.
Version 1.0.34
Overview & ways in
ITN-Zeiterfassung is a multi-tenant web application. Arrival, departure and break entries are worked out per user against the working time model assigned to them; targets, actual hours, breaks, premiums and balances arise automatically. Clocking happens on whichever device is to hand.
Desktop browser
At a desk you clock in straight from the dashboard in the browser — nothing installed, with large buttons for arriving, leaving and taking a break.
Mobile PWA
On an employee's own phone the app runs as an installable PWA at …/app — with mandatory location and an offline buffer, and no app store.
Tablet kiosk
A shared tablet at …/kiosk becomes the time clock: tap the action, enter your personal PIN, done.
Datafox terminal
Fixed RFID hardware reads the chip or the fingerprint and reports every entry straight to the server — offline too.
Which menu entries are visible depends on the role: employees clock in and see their own account, editors may change hours (possibly only for the groups assigned to them), and administrators manage users, models and settings and approve leave.
Dashboard — the admin cockpit
The dashboard is both the home screen for clocking in and an overview of the business. Employees see their figures for the day; administrators additionally see outstanding tasks and the status of the whole workforce.
Figures & clocking
At the top are the tiles for the current day: hours worked today, the day's target and the balance, plus a remaining-leave tile with the days left. On public holidays the target is 0. Clocking happens through the large buttons, with only the currently permitted actions active — after arriving, for instance, leaving and taking a break. Reasons of your own (such as „going to the doctor“) appear as additional buttons; below them are today's entries with their source.

Outstanding tasks for administrators
For administrators the dashboard adds an overview of the business. Open requests appear as a figure and a card and can be approved or rejected directly; planned leave becomes real leave with one click. Anyone who has forgotten to clock out shows up, as do incomplete days (arrival without departure) and anything odd in the balances. The status of the terminals (online or offline) and any upcoming dates round the picture off.
The two error lists are clickable: clicking „forgot to clock out“ or an incomplete daily row opens the time tracking view with the employee selected, the month set and the day highlighted — so the error is one click away rather than something to hunt for.

Attendance by group
An overview shows, per group, who is currently in. That makes it possible to see at a glance whether a department is complete.

Approved leave only disappears from the list after a short while, once the overview reloads.
Time tracking — the monthly view
In the time tracking view, editors check and correct an employee's hours month by month. Once a group and a user have been chosen, the current month loads; the arrows or the field at the top switch months. The principle of the page is a calculation you can follow: beside every daily row it says how a figure came about.

The account card in the month header
The account card summarises the time account. The monthly balance shows flexitime including the carry-over from the previous month, counting only the days up to today — future targets do not appear as a deficit. Remaining leave is what is available (entitlement + carry-over from last year + corrections) minus the days taken; a link leads to the working time model assigned.

„Leave planned/future“ and the amount still free to plan follow from the remainder minus any planned leave not yet approved. Planned leave is only deducted from the account when it is approved.
The calendar bar — painting absences
A calendar bar sits above the list of days. After choosing a tool (leave planned, leave, sick, released from duty, or the eraser) you drag across the days with the mouse and enter absences as an area. Days with no model are skipped while dragging; „link“ jumps from the day you clicked down to the matching daily row.

A daily calculation you can follow
Every daily row shows the clocking entries and their source on the left, the calculation in the middle — the break deducted under the model's rule, the day's target, the actual hours and the difference — and corrections and reasons for absence on the right. Nothing is hidden: you can see which break rule applied and how the balance arose. The source of each entry is shown by an icon (🌐 web, 🖥️ kiosk, 📍 phone, ✍️ manual, ✏️ changed afterwards); incomplete entries are marked as clocking errors.

Adding and correcting entries
For each day, entries can be corrected, deleted or added with „+ entry“. „+ reason“ enters a genuine absence — all day, or with a time from–to (= half a day). A forgotten day of leave belongs in as „+ reason → leave“, not as a balance correction.

Balance corrections
„+ balance correction“ offers three kinds. Time posts ± hours and minutes, either for the day or for the month, and affects the actual hours and the balance. Leave posts ± days to the leave account (a payout, say, or additional special leave); such postings do not count as a day taken and do not appear in the payroll export. Sick posts ± counted sick days and does appear in reports and the export.
A recycle bin for deleted entries
The ✕ on an entry does not delete it for good but moves it to the recycle bin. Days with deleted entries show a yellow bar at the left of the daily row; clicking it opens the window for restoring them — individually or with „restore all“.

Deleted entries are only removed for good after the recycle bin period set in the settings (0 = never).
Leave & absences
Leave, sickness and release from duty are planned graphically in the calendar — for individual employees and for whole groups — and act directly on the account and the calculation. A leave account per employee records entitlement, carry-over and the remainder.
Entered graphically: just draw the absences
Entering them needs no forms: in the calendar bar you choose the tool you want — leave (planned), leave, sick, release from duty paid or unpaid, or the eraser — and then drag across the days with the mouse. The span colours in immediately (leave green, planned hatched, sick red, release from duty yellow) and the account recalculates at once; the eraser removes a marking just as quickly.

The whole group at a glance: planning

The planning page shows the calendar for a whole group — one row per person, one column per day. Leave, planned requests and days of sickness for everyone lie side by side in colour, so that overlaps and gaps (two sales staff in the same week, say) stand out immediately. Here too, planning happens directly in the view rather than in lists.

Requesting rather than shouting across the room
Staff can request leave and the other absences themselves — at a desk or on a phone. Nothing about the hours changes until a decision is made; requested leave merely appears as „planned“ in the grid. The whole process is in the chapter on requests.
Approving with one click
Planned leave appears as an open request on the dashboard. Whoever is responsible sees the employee, the group, the period and the number of days, and approves with one click — the provisional entry becomes counted leave.

Exchanging leave data with your mail server
If the calendar connection to the company mail server is switched on, the application enters every all-day absence automatically as an appointment in the employee's personal calendar. Planned leave appears there as a tentative appointment; on approval the same appointment is automatically set to confirmed — and when the absence is removed it is deleted from the calendar again. Employees see their leave directly in their mail program, on their phone or in webmail, with nothing maintained twice. The connection is optional and is set up per employee with an app password of their own, stored encrypted.
- mailcow / SOGo — the well-established open-source mail server; set up and in use with this.
- Open-Xchange — behind many hosting offerings, IONOS and mailbox.org among them.
- Kerio Connect, Zimbra, IceWarp — commercial groupware servers with CalDAV support.
- Nextcloud / ownCloud, Synology Calendar — calendars on your own cloud or NAS.
- Apple iCloud, Fastmail — cloud calendars with an app-specific password.
Microsoft Exchange and Microsoft 365 use a protocol of their own without CalDAV — the exchange is currently not available there. Get in touch if you need it.
Types of absence
- Leave planned: a provisional entry with no effect on the account, which becomes real leave only on approval.
- Leave: an approved, counted day of leave; half days in steps of 0.5.
- Sick: a day of sickness, all day or with a time from–to.
- Release from duty, paid or unpaid: paid covers the day's target (balance 0), unpaid does not cover it and is merely documented.
- Business travel / training: paid, covers the day's target.
- Special leave: paid, covers the target — but does not count as a day of leave taken.
- Unpaid leave: the target remains, and the day is documented.
- Flexitime compensation: time off in lieu — the day's deficit draws down the flexitime built up.
- Vocational school: generated from the apprentice's school timetable (its own chapter).
With a paid all-day absence and no clocking entries, the day counts as covered: actual = target, balance 0, no break. If work was nevertheless done on such a day (leave entered afterwards on a day with entries, say), the time worked counts in addition, and the day of leave stays used up in the account.
The leave account
The leave account shows entitlement, carry-over from the previous year and the remainder. The remainder is the entitlement plus the carry-over minus the days taken; the carry-over runs recursively into the following year, and nothing expires automatically. Real days of leave are counted as taken, half days as 0.5.

A dated history of entitlement
If the entitlement changes — three days more from a particular year, say — the entitlement history is maintained instead of the simple annual figure („from year X: N days“). Each year then calculates with the value that applied at the time; previous years and carry-overs stay correct. Where a history is maintained, only it applies and the simple field has no effect. Individual days can be credited or deducted through balance corrections (special leave or a payout, for instance).
Requests — leave, corrections, approval
Leave, special leave, business travel, flexitime compensation, a forgotten clocking time or a cancellation: staff submit these themselves — at a desk or on the move with a phone. Nothing about the hours changes until a decision is made; once management approves, the program enters the change and records who decided it. The note on the desk and the question shouted across the room both disappear.
Submitting
A submission consists of a type, a period and a reason. For the reason the common cases are offered (forgot to clock, wrong time, clocked twice, terminal unreachable, doctor's appointment, business errand); free text remains possible. For a time correction the form shows the entries for the day chosen: an entry made in error is struck out, and a missing time is added by type and time. Requested leave appears in the grid as „planned“ straight away — so the department sees early who would like time off, without anything being booked yet.




Deciding
Responsibility lies with the person's named line manager; where none is stored, management decides, and otherwise the administrators. Open submissions appear as a figure and a card on the dashboard and can be approved there directly, or rejected with a reason. Nobody may approve their own submission — not even a department head; the button is simply not there.
Before an approved time correction is applied, the server checks whether the day has changed since the request was made. If it has, the approval is refused rather than pasting a stale correction over a newer change.
Who is responsible
The department head role maintains the hours of its groups and decides their submissions, but reaches no administration page. A deputy can additionally be stored per group so that nothing is left lying during a holiday. The management status — which any number of people may hold — decides every submission without a line manager of its own and grants no other rights: no administration, no other people's hours. Anyone who is only an employee cannot approve leave; so only those entitled to decide can be selected as a line manager.
On request the system sends emails in both directions: to those responsible when a submission comes in, and to the employee once it has been decided. If no notification address is stored, the message simply appears in the web and mobile app — nobody needs a mailbox for it.
On a phone
In the mobile app the submissions have a tile of their own: make them, follow their status, withdraw them. Decisions are deliberately made only at a desk. Every correction requested this way stays recognisable afterwards — in the time tracking view the entry carries the note „requested by phone“ along with the name of whoever approved it.



Messages to the workforce
„The delivery will not arrive until 7 tomorrow“ — messages like that used to travel by phone chains and private messengers, past the time tracking system and with no record. Messages reach the same people in the same program: one person, a whole department or everyone. The recipient confirms with „read“, and the sender can see who has taken note. Deliberately one-way — no chat, no discussion; requests go through the request workflow.
Writing is for those who carry responsibility
Administrators and management reach everyone, department heads their own departments (with any stored deputy counted in), and a named line manager additionally the people assigned to them. Only the people and groups you are allowed to reach appear in the recipient selector. Everyone else has a mailbox but no write access.

Normal or important
A normal message waits in the mailbox; the bell in the header and the tile in the mobile app show how many are unread. A message marked important opens as a window at the next start, which can only be closed with „read“ — for when a message really does have to reach everyone.


A record instead of asking around
Under „sent“, each message shows how many recipients have read it — with names and times, if you want. That makes it demonstrable who had the information. A message can be withdrawn; it then disappears from every mailbox. Every send appears in the log with the sender, the subject and the number of recipients.

On a phone
The mobile app has a tile of its own with a counter of unread messages. There is nothing to set up and nothing to switch on: the messages arrive in the app along with the rest of the data. Operating system notifications are deliberately not used — so there is no permission anyone could refuse, and nothing appears on the lock screen. The messages last loaded stay readable without a connection.


Working time models
A working time model sets the target hours, the break deduction, the premiums and the public holiday rule — it is the backbone of every evaluation. Models are maintained under Time tracking → Models.

Target types
- Per weekday: a target of its own for each weekday (Mon–Thu 8.0 / Fri 6.0, say).
- Weekly target: a number of hours per week plus a choice of working days; optionally a daily target of its own, with the remainder distributed evenly across the other working days.
- Monthly flexitime: a monthly target, with the distribution across days left open.
- Free: no target — all the time recorded counts.

Break rules per weekday
The break deduction is chosen per day:
- Free / as clocked: only the break actually clocked is deducted.
- Statutory (German Working Hours Act): more than 6 h ⇒ 30 min, more than 9 h ⇒ 45 min.
- Flat rate: a fixed deduction per day.
- Tiered: a graded deduction depending on how long the day was.
The deduction actually applied is always the greater of the break clocked and the break prescribed; with „as clocked“ only the break actually clocked counts.
Public holiday rule, core hours & clocking window
The public holiday card settles how public holidays are calculated — usually a target of 0 plus the public holiday premiums. In addition, core hours, a clocking window (arrival–departure, limiting the attendance counted) and a grace period on the first entry can be defined.
Overnight shifts
Where a shift runs past midnight (22:00→06:00, say), a model setting determines which calendar day carries the shift — by default the day of departure, or optionally the day of arrival. The working time and the break of that shift lie entirely on that one carrying day; double counting is ruled out. If the carrying day is a non-working day under the model, the work still counts there as a credit (with a Sunday or public holiday premium where applicable).

The flexitime account & capping
The flexitime account can be switched on or off per model. When it is off, there is no carry-over: every month starts at 0 and a monthly surplus is shown as „for payout“. When it is on, the balance of every previous month moves into the new month as a carry-over. A cap can optionally limit the flexitime balance at the turn of the month — capping only works downwards from above.
Balance at month end 160 h, limit 100 h → 100 h are carried into the following month, 60 h are capped.
Assignment per employee
A model is assigned per user and with a date: it applies from a given day, and earlier periods keep their old model. The history is in the personnel record.

If no model is assigned to a user, no target hours are calculated for them. Deleting a model takes effect retrospectively on every period evaluated with it — which is why deleting one requires the administrator password.
Vocational school for apprentices
School days, block weeks and school holidays are stored once per school year against the person — not against the working time model. From that the system generates the school days automatically, eight months ahead on a rolling basis, and enters them in the calendar too where one is set up.
A whole school day counts as meeting the daily target, leaving the balance at 0. For a half school day the class time is credited; work done afterwards is added on top as normal. Public holidays, days with no model and days already occupied are skipped. In the planning view school days are recognisable by a colour and symbol of their own — half days only half filled.
If a class is cancelled, the day is simply erased and does not come back by itself; an additional school day can be set by hand at any time. At the turn of the school year a new entry from a date is enough: the pre-calculated days of the old rhythm disappear from that day onwards, calendar appointments included, and are rebuilt to the new timetable — with no duplicates. The working time model is untouched by all this, so no separate model is needed per year of training.

Premiums
Premiums are a company-wide catalogue of allowances in time or money — night, Sunday, public holiday, overtime or types of your own — which are then assigned within the working time models. The catalogue is maintained under Time tracking → Models → Premiums.

Types & eligibility windows
- Night / Sunday / public holiday: apply within a from–to window; a window may run past midnight (22:00–06:00, for instance), and several separate windows are possible.
- Overtime: daily as max(0, actual − target); weekly on a cumulative basis.
- Premiums of your own: freely created for cases particular to your business.
Paid out or credited as time
For each premium the effect is set — paid out as money or credited as time to the time account — along with the percentage. A premium only takes effect once it is assigned to a day card in a working time model; that way different weekdays can carry different premiums.
The number stored on a premium corresponds to the DATEV wage type and takes precedence over the general wage type mapping under Settings → DATEV.
Reports
Reports evaluate hours per person or group — for a month or a free from–to span, as a table, a PDF and a CSV file. The choice between „month“ and „period“ at the top governs every report on the page.
Monthly overview
The individual report in its monthly overview form shows daily rows with totals, plus the figures for carry-over, actual, target, difference and flexitime balance. Premiums are also shown as a bonus, along with days of absence (half days as 0.5, sickness including sickness corrections). The flexitime balance applies to date; any capping is shown where it exists.

Daily overview
The daily overview form lists the individual entries along with the calculation. In the daily PDF, the arrival of a shift running past midnight is attributed to the day of departure.

Premium report
The premium form shows arrival, departure, target and actual per day, and then a column for each premium with the time eligible for it (not the bonus). The column header gives the name and rate, „night 25 %“ for instance; a legend at the top lists every premium in the period, and the totals are at the bottom. Arrival and departure are the first and last entry of the shift; where the departure of a night shift falls on the following day, it is marked with „*“. The CSV export contains the same columns.

Group report
The group report sets every employee in a group side by side with their actual, target, difference, carry-over and absences. „PDF overview“ summarises the group; „PDF full report“ bundles everyone's individual reports together.

System groups (inactive / former employees) allow individual reports only, not a group report.
Payroll & DATEV
At the end of the month the export page produces a DATEV import file for payroll — either as Lohn & Gehalt (LuG, ASCII/CSV) or as LODAS. The month, the scope (everyone, one group or one person), the format and the level are chosen before downloading.

What gets exported
- Actual hours, overtime and premiums.
- Leave, sickness and release from duty as days (half days 0.5).
- The level either as monthly values only, or monthly plus daily values.
Wage types & personnel numbers
The wage type numbers come from the settings under DATEV (along with the adviser and client numbers); a number stored on a premium takes precedence. Personnel numbers are maintained per user. If wage types or a personnel number are missing, a warning appears and the employees affected are skipped.

Members of the system groups (inactive / former employees) are not exported. Corrections to the leave account do not appear in the export — only real days of leave; sickness corrections, by contrast, do.
Mobile app
The mobile app runs as an installable PWA in the browser at …/app — without an app store and without a rollout by IT. It is aimed at staff who clock in where the work happens.


Installation & pairing the device
The app is opened in the browser and added to the home screen. After the first sign-in the device registers itself and shows a device number. The employee gives that to an administrator, who assigns the phone to a user under Administration → Devices and approves it. Only after approval do the tiles the person is entitled to — for clocking and for reports — appear.
GPS required
Location is mandatory when clocking; the first time, „precise location“ has to be permitted. If the positioning is too imprecise, the entry is rejected with a note — wait a moment and try again.
On an iPhone, location has to be set to „allow“ in the settings for Safari or for the website, otherwise every attempt to clock will fail.
The offline queue
Without a connection, entries are stored locally and transmitted with their original time once a connection returns. That works even if the app was closed before the location fix arrived — it catches up by itself. Every entry shows its status: transmitted ✓ or waiting ⏳.

Requests on the move
A tile of its own leads to the requests: applying for leave and other absences, adding a forgotten clocking time for a single day, or cancelling an absence already entered. The status of every submission is visible there, open ones can be withdrawn, and the month selector reaches older ones. Decisions are deliberately made only at a desk.
The account card & your own reports
The home screen shows hours worked, target, balance, remaining leave, leave planned or upcoming, and the amount still free to plan. Through „reports“ an employee calls up their own monthly report straight on the phone.


For buffered entries to arrive, the app should occasionally be opened with an internet connection and location active.
Time clock / kiosk
The kiosk turns a tablet into a fixed time clock for the whole team. It is opened in the browser at …/kiosk: tap the action, enter your personal PIN, done — the PIN identifies the person clocking and takes the place of signing in.


Operation & confirmation
After clocking, a confirmation appears briefly with the person's name and their current time account (flexitime balance, actual/target). The company logo is shown in the branding corner. The display size scales the whole kiosk display, from small to extra large, and takes effect immediately — „standard“ is tuned for 8- to 9-inch tablets.
Your own reports by PIN
Through the reports icon and their own PIN, each person sees their own monthly or daily report; only their own hours are shown.

The offline buffer & settings
If the network drops, clocking carries on working: the entry is stored on the device with its original time, and the confirmation says „saved · no connection“. Once the connection returns, the kiosk transmits every entry by itself; a line on the home screen shows how many are still waiting. On first start the terminal ID and secret from the administration are entered; the cog opens the settings after the administrator PIN, including the full-screen lock.

For unattended continuous operation there is additionally an Android kiosk app of our own with autostart, which locks the tablet straight into the time clock after switching on.
Datafox hardware terminals
For entrances, production floors and outdoor areas, robust RFID terminals of the Datafox EVO series are available. They read RFID chips — and, depending on the model, fingerprints — and report every entry directly and encrypted to the server; the browser is not involved, and no server of your own is needed on site.
Chips, biometrics & assignment
Chips are stored per employee as transponders in the personnel record (the number being the chip's UID); several chips per person are possible, and „active“ controls whether they may be used for clocking. On models with a fingerprint sensor the biometric mapping stays in the device — no fingerprint leaves the terminal. If the network drops, the device buffers the entries and sends them on later with their original time.

EVO 2.8
The compact classic for arriving and leaving: a 2.8-inch colour display, robust keys and an RFID reader — the slim option beside the door.

EVO 3.5 Pure Fingerprint
A 3.5-inch touch display with RFID plus biometric identification by fingerprint — clocking with no chip and no PIN.

EVO 5.0 Pure
A generous 5-inch touch display with freely configurable buttons — plenty of room for clear labelling, and glove operation on request.
Setup
Setup happens in two steps: the terminal is created in the application under Administration → Settings → Terminals and is given an ID and a secret. On the device, HTTP(S) with basic authentication is set as the access method — the username being the terminal ID and the password the secret — and /terminal/datafox with the tenant ID is entered as the send path. The serial number appears automatically in the terminal list as soon as the device has reported in for the first time.
Live attendance
The attendance board shows in real time who is currently in. It suits attendance terminals and refreshes itself.

The board is divided into three columns:
- Present: currently clocked in, with the time since when.
- Missing (should be here): a target above 0 today, but not present.
- Away (no target): no daily target today — a day off, leave or sickness.
„Group“ narrows the display down. The visibility of individual people can be switched off per user.
Location checking / geofencing
Locations define permitted places (a geofence) at which clocking by phone or desktop widget is allowed. The check is opt-in and off by default; without it being switched on, locations serve only as information.

Creating permitted places
A location consists of a name, coordinates and a radius. The coordinates can be derived from an address or taken from a real entry made on a phone (➕📍 in the time tracking view). The tolerance is the radius plus the current GPS accuracy (capped at the top), so that imprecise positioning is not rejected out of hand.
Levels & assignment
The check is switched on under Settings → Location check, separately for the phone and the desktop widget. For each channel there are three levels: off (no check), mark only (the entry is allowed but flagged with ⚠️) and block (an entry outside is prevented). For each device it can be set whether it is exempt from the check (field service, say) and which permitted locations it is restricted to.

Entries captured offline and submitted later are never blocked, only flagged. Ordinary clocking through the dashboard is not checked at all.
Log — who changed what
Every change to hours, absences, master data and settings is written down. The log shows the time, the person responsible, the operation and the employee affected — and, on a click, the details, which for a corrected entry includes the value it had before.
It can be filtered by period, by area (clocking entries, absences, requests, users, settings …) and by person; the filtered list can be exported as CSV. Operations with no person named come from automatic runs, such as emptying the recycle bin once its period has expired.
Who sees what is narrowly drawn: administrators see every operation in their company, department heads only those of their own groups, and employees nothing at all. The log is a record view — entries can be neither changed nor deleted. Deleted clocking entries are brought back through the recycle bin in the time tracking view.

Administration & security
Administration brings together users, groups, devices, terminals, public holidays, settings and licences. The application runs as a hosted cloud service accessed over HTTPS in Germany.
Roles & responsibilities
There are four roles: employee (clock in, see your own hours, make submissions), department head (additionally maintain the hours of their own groups and decide their submissions, with no access to administration), administrator and super administrator. Additional rights come on top, such as „edit hours“ (which can be limited to particular groups), „see the duty roster“ or visibility of the project costing.
For requests, the management status can be granted independently of all that — to any number of people. It decides the submissions of everyone for whom no line manager of their own is stored, and grants no other rights. A line manager can be named per person; only those entitled to decide can be selected.
The personnel record
Clicking a name opens the personnel record. Above everything sits a row of core data (active, role, group, working time model, remaining leave, responsibility), and below it five tabs: master data (address, the start and end of time recording, leave entitlement including its history, the internal hourly rate), account & access (role, rights, password, kiosk PIN), requests & school (responsibility, school timetables), recording (locations, transponders, calendar) and documents (a memo, a file store). Every card carries an (i) with an explanation of its fields.


Groups & editor rights
Groups bundle staff for viewing and evaluation; every user belongs to exactly one group and is moved by drag and drop. Two system groups — „inactive employees“ and „former employees“ — always come last and cannot be deleted or renamed. Anyone moved there has their account deactivated (no sign-in, no clocking, no changes, no export) and no longer counts towards the licence.

Devices & terminals
Under Devices, phones are approved, assigned to an employee and set up in their rights (clocking on or off, maximum GPS imprecision, location exemptions). Terminals — kiosk time clocks, attendance boards or Datafox hardware — each receive an ID and a secret for setting them up on the device.


Public holidays & settings
Public holidays are imported per region and supplemented with your own one-off or annually recurring dates (a company shutdown, for instance); on a public holiday the target follows the model's public holiday rule. The settings bring together the time zone and date format, the global clocking buttons, the recycle bin period, the location check and the interfaces (DATEV, email/SMTP).


Licences & the peak overview
The licence page shows how many accounts are active at once. What counts is the highest number of simultaneously active accounts within a month (the peak), not the number at month end. It shows the current figure, the highest so far this month, the inactive accounts, a monthly history and a free period query.

Multi-tenancy & operation
The application is multi-tenant; every data query is bound to a tenant. It runs as a hosted cloud service accessed over HTTPS in Germany. Employees and administrators need only a current browser, the mobile app needs an iPhone or Android device as a PWA, and the kiosk any tablet. Anyone holding the same login in several tenants chooses at sign-in which one they want.
Protection against attacks from outside
Delivery is hardened: strict browser rules (a content security policy, no embedding in other people's pages, enforced HTTPS), a session cookie that is invisible to scripts and additionally marked „secure“ behind HTTPS, and blocked foreign origins. Against credential guessing there are brakes: at sign-in per origin, on setup links, and on the kiosk PIN per terminal — the last of these locks for a short while after several failed attempts and releases immediately on a correct PIN.
Every change to hours, absences, master data and settings ends up in the log. Deleting a clocking entry is a recycle bin operation with a period, not immediate removal — so a slip of the hand stays curable.
Questions about introducing it, about terminals or about the payroll export? We are happy to show the application against your own processes.
