AttendFlow

Delete your account

Ask us to remove your AttendFlow account and the personal data we hold about you. You do not need to be signed in.

This form sends a deletion request to Infi-Tech Inc, the provider of AttendFlow. A person reads it. Nothing is erased the instant you press the button, because an irreversible action taken on an unverified email address would be its own kind of breach.

The two lists below are worth reading before you send it rather than after: what we remove, and what stays behind whatever anybody asks. Both are already in our Privacy Policy — they are repeated here so that they are in front of you while you are deciding.

What we remove

  • Your sign-in credentials — the password hash, and any Google or Apple identity linked to the account.
  • Your profile: name, email address, phone number, job title, avatar and signature.
  • Your sessions, refresh tokens, trusted devices and push notification tokens, so that no device stays signed in.
  • Any face template held for you, and the consent record that permitted it.
  • Your notification history and your saved preferences.
  • Your membership of every organization you belong to, which ends your access to them.

What stays, and why

Your employer's records about you
Your employee record, your attendance and your leave belong to your employer, who is their controller. Retention is their decision and deletion inside their workspace is theirs to perform. Send that part of the request to them — we will help them answer it, but we may not act on their data without their instruction.
Invoices, payments, ledger entries and commission records
Financial records are kept for as long as the law requires and are not deleted on request. A ledger that can be edited is not a ledger.
The audit trail
Security-relevant actions are recorded so that an organization can answer what happened to a record and who did it. The trail is append-only and cannot be rewritten through any path, including this one.
Encrypted backups, until they age out
Data erased from the live system may persist in encrypted backups until those backups expire on their ordinary cycle. We do not restore a backup in order to reinstate data somebody asked us to erase.

What happens after you send it

  1. We acknowledge it

    The address you give receives a confirmation carrying a reference as soon as the request is accepted. If that email does not arrive, the request did not reach us — write to us directly rather than assume it did.

  2. We check who you are

    We may need to verify that the request comes from the person the data is about. That is not an obstacle put in your way: acting on an unverified request is how one person deletes another person's account.

  3. We tell you what we can do

    Where part of what you asked for is your employer's to decide, we say so and name what we have passed on, rather than reporting a deletion we did not perform.

  4. We act, and we answer

    We respond within the period the Malawi Data Protection Act, 2024 allows. You do not have to come to us before complaining to the authority designated under the Act — we would simply rather you told us first, so that we can put it right.

Send your request

Which of these describes you?*

Where your confirmation goes.

Optional. Only used to help confirm it is you.

Optional. Helps us find the right account.

Optional. What you would like removed, or anything that helps us identify your account.

This sends a request. It does not delete anything by itself — a person reads it and may need to verify who you are first.

Prefer to write to us? Email info@infi-tech.net. Our Privacy Policy sets out the rest of your rights and how to exercise them. Last updated: 1 September 2026.