Privacy Policy
Effective Date · February 24, 2026
IRONCLOCK
Privacy Policy
Effective Date: February 24, 2026
Kevadia LLC, doing business as IronClock ("Company", "we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and protect information when you access or use the IronClock platform, including the web application, mobile application (iOS and Android), application programming interfaces (APIs), and all related services (collectively, the "Service").
This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given to them in the Terms of Service.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you are a Subscriber using the Service on behalf of an organization, you agree to this Privacy Policy on behalf of that organization and its Authorized Users.
1. INFORMATION WE COLLECT
We collect information in the following categories:
1.1 Account and Registration Information
When you create an Account, we collect:
- Full name
- Email address
- Password (stored in hashed form)
- Organization name and details (for organizational Accounts)
- Role and position within the organization
- Phone number (if provided)
1.2 Employee and Workforce Information
Subscribers and administrators may input information about their workforce, including:
- Employee names, email addresses, and contact information
- Job titles, roles, departments, and organizational hierarchy
- Employment type and classification (employee, contractor)
- Pay rates and compensation details (hourly rate, overtime rate, daily rate)
- Work schedules and shift assignments
- Emergency contact information (if provided)
1.3 Time and Attendance Data
The Service collects time and attendance records, including:
- Clock-in and clock-out timestamps
- Timesheet entries and hours worked
- Overtime records
- Break times and break type (lunch, rest, other)
- Timesheet approval and rejection records
- Project, client, and task time allocations
- Clock method used
- Clock-in and clock-out photos (where photo capture features are enabled by the Subscriber)
- Personal protective equipment (PPE) confirmation status
- Injury reports submitted at clock-out (injury type and description)
- Edit history (who edited, when, and reason for edit)
1.4 Location Data
When location features are enabled, the Service collects:
- Clock event location: GPS coordinates captured at each clock-in and clock-out event
- Background location tracking: Continuous GPS coordinates during active shifts for geofence monitoring, collected at regular intervals while a shift is active. Background location data is used for real-time geofence checking and is not persistently stored beyond the clock-in and clock-out coordinates recorded on the time entry.
- Geofence entry and exit events: Records of when an Authorized User enters or exits a designated work site boundary
Background location tracking may be disabled by revoking location permissions in your mobile device settings. This may limit the availability of certain features such as geofencing and automated clock-out.
1.5 Biometric Data
Where facial recognition features are enabled by the Subscriber, the mobile application collects and processes biometric data, including:
- Facial images captured during clock-in and clock-out events
- Facial geometry identifiers derived from those images
Biometric Data is collected only with the informed, written consent of the Authorized User, obtained prior to initial collection. For more details, see Section 8 (Biometric Data).
1.6 Device and Technical Information
We automatically collect certain technical information when you use the Service, including:
- Device identifiers and device type
- Device name and device model
- Operating system and version
- App version installed
- Platform type (iOS, Android, web)
- Browser type and version (web application)
- Push notification tokens
- IP address
- User agent string
1.7 NFC Tag Data
When NFC features are used, we collect:
- NFC tag identifiers scanned during clock events
- Timestamp and location of NFC scans
- Associated site and work location information
1.8 Uploaded Documents
Subscribers and Authorized Users may upload documents to the Service, including:
- Identification cards and government-issued identification
- Safety certification cards and training certificates
- Other work-related documents as required by the Subscriber
1.9 Usage and Analytics Data
We collect information about how you interact with the Service, including:
- Feature usage and screen views
- Clock events and workflow actions
- Search queries within the Service
- Clicks, navigation patterns, and session duration
- Error encounters and feature interactions
1.10 Communication Data
We collect information from communications related to the Service, including:
- Invitation emails and responses
- Notification preferences and delivery records
- Support requests and correspondence
2. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes:
2.1 Providing and Operating the Service
- Processing clock-in and clock-out events
- Managing timesheets, schedules, and attendance records
- Verifying employee identity through facial recognition (where enabled)
- Monitoring geofence compliance and generating location-based alerts
- Automated clock-out when an Authorized User exits a geofence boundary (where enabled)
- Automated clock-out after exceeding maximum shift duration (where enabled)
- Automated time entry review and approval based on configurable rules (see Section 9)
- Automated overtime and break calculations
- Verifying site presence through NFC tag scans
- Processing payroll integrations and exports
- Managing organizational hierarchy and role-based access
- Delivering push notifications and in-app notifications
- Supporting offline clock-in/out with automatic synchronization
- Tracking worker document (ID card, safety certification) expiration and compliance status
2.2 Account Management
- Creating and maintaining user Accounts
- Authenticating users and maintaining session security
- Processing subscription billing and payments
- Sending transactional communications (invitations, notifications, billing correspondence)
2.3 Improving the Service
- Analyzing usage patterns to improve features and user experience
- Identifying and fixing bugs, errors, and performance issues
- Developing new features and functionality
- Conducting internal research and analytics
2.4 Security and Compliance
- Detecting and preventing fraud, unauthorized access, and abuse
- Maintaining audit logs of administrative and significant user actions
- Enforcing our Terms of Service and Acceptable Use Policy
- Complying with legal obligations and responding to legal process
2.5 Aggregated and Anonymized Analysis
- Creating aggregated, de-identified datasets for industry benchmarking, research, and analytics
- Improving the Service based on aggregate usage patterns
- Generating anonymized workforce analytics and reports
3. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information as that term is defined under applicable law. However, we may share or license aggregated and anonymized datasets — which do not identify you or any individual — with third parties for research, industry benchmarking, and other lawful business purposes (see Section 7.2 of our Terms of Service). We share identifiable information only in the following circumstances:
3.1 Within Your Organization
- Subscribers and administrators can access information about their Authorized Users as necessary for workforce management
- Supervisors and managers may access time records, location data, and attendance information for their team members based on role-based access controls configured by the Subscriber
3.2 Third-Party Service Providers
We share information with third-party service providers who assist us in operating and delivering the Service. These providers are contractually obligated to use the information only for the purposes of providing services to us and in accordance with this Privacy Policy. The categories of service providers we use include:
- Cloud Infrastructure and Storage — encrypted storage of Customer Data, documents, and biometric images
- Payment Processing — subscription billing and invoice management
- Email Delivery — transactional communications such as invitations, notifications, and billing correspondence
- Web and Mobile Analytics — usage analytics, event tracking, and page views within the web and mobile applications
- Mapping Services — displaying site locations, geofence boundaries, and address search within the web application
- Push Notification Services — delivering notifications to mobile devices via platform-native notification channels
- Error Tracking and Performance Monitoring — identifying and resolving software issues and monitoring application performance
- Accounting Integrations — payroll synchronization with third-party accounting software, where enabled by the Subscriber
We may update the specific service providers from time to time. A current list of sub-processors is available upon request for Subscribers who require it under applicable data protection laws.
3.3 Legal Requirements
We may disclose information if required to do so by law, regulation, legal process, or governmental request, including:
- Responding to subpoenas, court orders, or other legal process
- Cooperating with law enforcement investigations
- Protecting the rights, property, or safety of IronClock, our users, or the public
- Enforcing our Terms of Service
3.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice within the Service of any change in ownership or uses of your personal information.
3.5 With Your Consent
We may share your information for purposes not described in this Privacy Policy with your explicit consent.
4. DATA RETENTION
We retain information for the following periods:
| Data Type | Retention Period |
|---|---|
| General Customer Data (timesheet entries, employee records, schedules, documents) | During the subscription term and for 30 days following termination or expiration |
| Biometric Data (facial recognition images and identifiers) | Maximum of 6 months from the date of collection, then permanently deleted regardless of subscription status |
| Clock-In/Clock-Out Photos (photos captured at clock events) | 90 days from the date of capture, then permanently deleted. May vary by subscription plan. |
| Audit Logs (administrative actions, IP addresses, user agents) | During the subscription term and for up to 12 months following termination. Retention period may vary by subscription plan. |
| Location Data (GPS coordinates from clock events) | During the subscription term and for 30 days following termination (retained as part of time entry records). Background location data used for real-time geofence monitoring is not persistently stored. |
| Account Information | During the subscription term and for 30 days following termination |
| Device Tokens (push notification tokens) | Automatically deactivated after 90 days of inactivity |
| Session and Authentication Data (session cookies, access tokens) | Session data expires automatically after a defined period of inactivity or upon logout. Token lifetimes vary by platform. |
| Aggregated and Anonymized Data | Retained indefinitely (this data does not identify any individual) |
After the applicable retention period, we permanently delete the corresponding data. It is your responsibility to export your data prior to the expiration of the retention period. Data export features may be available within the Service, subject to your plan tier.
5. DATA SECURITY
We implement commercially reasonable administrative, technical, and physical security measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- AES-256 encryption for biometric data storage
- Role-based access controls and authentication
- Regular security assessments and monitoring
- Audit logging of administrative actions
- Secure cloud infrastructure with industry-standard certifications
However, no method of electronic storage or internet transmission is completely secure. We cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your Account credentials and for all activity that occurs under your Account.
6. DATA BREACH NOTIFICATION
In the event of a security incident involving unauthorized access to, acquisition of, or disclosure of your personal information, we will:
- Investigate the incident promptly and take steps to contain and mitigate any harm;
- Notify affected individuals without undue delay, and in any event within the timeframes required by applicable law, including within seventy-two (72) hours to the relevant supervisory authority where required by the GDPR;
- Provide details of the incident, including the types of data involved, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects;
- Cooperate with applicable regulatory authorities as required by law.
For Subscribers with a Data Processing Agreement (DPA), breach notification procedures specified in the DPA shall apply. We maintain an internal incident response plan and will provide updates to affected parties as additional information becomes available.
7. YOUR RIGHTS AND CHOICES
7.1 Account Information
You may access, update, or correct your Account information at any time through the Service. Subscribers may manage Authorized User information through the administrative interface.
7.2 Data Export
Depending on your plan tier, you may be able to export your data through the Service, including payroll reports (CSV and PDF), attendance and hours reports (CSV), compliance reports (CSV), and audit logs (CSV and JSON). You may also contact us at [email protected] to request a copy of your personal data.
7.3 Account Deletion
You may request deletion of your Account by contacting us at [email protected]. Upon Account deletion, we will delete your information in accordance with the retention periods set forth in Section 4. Certain information may be retained as required by law or for legitimate business purposes (such as audit logs for compliance).
7.4 Location Permissions
You may disable background location tracking by revoking location permissions in your mobile device settings. This may limit the availability of certain features such as geofencing and automated clock-out.
7.5 Push Notifications
You may opt out of push notifications by adjusting your device settings or notification preferences within the Service.
7.6 Biometric Data
Where biometric features are enabled, you have the right to:
- Receive written notice before biometric data collection begins
- Provide or withhold informed, written consent prior to collection
- Request information about the storage and use of your biometric data
- Request deletion of your biometric data
For more details, see Section 8 (Biometric Data).
7.7 Response Timeframes
We will acknowledge receipt of your request within five (5) business days and respond substantively within thirty (30) days of receiving a verifiable request. If we require additional time (up to an additional sixty (60) days), we will notify you of the extension and the reason for the delay. For California residents, response timeframes are governed by Section 13 (California Privacy Rights).
8. BIOMETRIC DATA
This section applies where facial recognition features are enabled by the Subscriber.
8.1 What We Collect
We collect facial images and facial geometry identifiers ("Biometric Data") for the purpose of verifying Authorized User identity during clock-in and clock-out events.
8.2 Consent
Biometric Data is collected only with the informed, written consent of the Authorized User, obtained prior to initial collection. We provide tools to facilitate consent collection within the Service.
8.3 Storage and Security
Biometric Data is:
- Stored in encrypted form using AES-256 encryption on secure servers
- Accessible only to authorized systems for the purpose of identity verification
- Not stored on end-user devices
8.4 Retention and Destruction
Biometric Data is retained for a maximum of six (6) months from the date of collection, after which it is permanently and irrevocably deleted. This retention period applies regardless of subscription status.
8.5 No Disclosure
Biometric Data is not sold, leased, traded, or otherwise disclosed to third parties, except:
- As required by law, regulation, or valid legal process
- With the Authorized User's explicit consent
8.6 Subscriber Responsibilities
The Subscriber is solely responsible for:
- Determining whether applicable biometric data laws apply to its use of facial recognition features, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington Biometric Identifiers statute, and similar state, federal, or international laws
- Obtaining all required consents from Authorized Users prior to enabling facial recognition
- Maintaining and making available to Authorized Users a written biometric data retention and destruction policy as required by applicable law
- Refraining from selling, leasing, or profiting from biometric data
9. AUTOMATED DECISION-MAKING
The Service includes features that involve automated processing which may produce effects on Authorized Users. The Subscriber is responsible for configuring these features and informing Authorized Users of their use.
9.1 Automated Clock-Out
Where enabled by the Subscriber, the Service may automatically clock out an Authorized User in the following circumstances:
- Geofence exit: If the Authorized User's GPS location exits a designated work site geofence boundary and remains outside for a configurable grace period, the Service will automatically record a clock-out event. These entries are always flagged for supervisor review.
- Maximum shift duration: If an active shift exceeds the organization's configured maximum shift duration, the Service will automatically record a clock-out event. These entries are always flagged for supervisor review.
9.2 Time Entry Auto-Approval
The Service may automatically approve or flag time entries for manual review based on configurable rules, including:
- Whether the entry was created manually (flagged for review)
- Whether clock-in or clock-out occurred outside a geofence boundary (flagged for review)
- Whether the shift duration falls below a minimum threshold or exceeds a maximum threshold (flagged for review)
- Whether overtime exceeds a configured threshold (flagged for review)
- Whether facial verification failed (where enabled; flagged for review)
- Whether an injury was reported during clock-out (flagged for review)
9.3 Overtime and Break Calculations
The Service automatically calculates overtime based on configurable daily and weekly thresholds, and may automatically apply break deductions based on shift duration and organizational settings.
9.4 Document Compliance
The Service automatically checks the expiration status of worker documents (identification cards, safety certifications). Workers with expired required documents may be prevented from clocking in until their documents are renewed and verified.
9.5 Your Rights Regarding Automated Decisions
Where required by applicable law, you have the right to request human review of automated decisions, express your point of view, and contest such decisions. Contact your organization's administrator or email [email protected].
10. COOKIES AND TRACKING TECHNOLOGIES
For detailed information about the cookies and similar technologies used by the Service, including local storage, mobile device storage, and analytics technologies, please refer to our Cookie Policy. The following is a summary.
10.1 Cookies
The web application uses a single essential first-party cookie to maintain your authenticated session. This cookie is set with security flags (httpOnly, secure) and expires automatically after 14 days or upon logout.
The web application does not use analytics cookies or third-party tracking cookies.
10.2 Web and Mobile Analytics
The web application may use third-party analytics services to collect page views and usage data. The specific analytics provider may vary and can be changed by the Company at any time.
The mobile application uses third-party analytics services to collect event-level analytics, including authentication events, clock events, geofence events, and screen views. Analytics services associate events with a user identifier to provide usage insights. Error tracking services collect crash reports and performance metrics. These services are configured to minimize the collection of personally identifiable information.
10.3 Do Not Track
Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no common industry standard for interpreting DNT signals, the Service does not currently respond to DNT signals. We will update this Privacy Policy if a uniform standard is adopted.
10.4 Cookie Consent for EU Users
For users in the European Economic Area, the United Kingdom, or other jurisdictions requiring prior consent for non-essential cookies or tracking technologies, we will present a consent mechanism before activating any non-essential tracking. As the web application currently uses only a single essential session cookie, no consent is required for cookie placement. If we introduce non-essential cookies in the future, we will implement appropriate consent mechanisms.
10.5 Your Choices
You may manage cookies through your browser settings. Blocking the essential session cookie will prevent you from authenticating with the web application. On mobile devices, you may limit analytics collection by adjusting your device's privacy settings or opting out of analytics tracking where supported by your operating system.
11. CHILDREN'S PRIVACY
The Service is not directed to individuals under the age of 18 (or the age of legal majority in the applicable jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to promptly delete that information. If you believe that a child has provided us with personal information, please contact us at [email protected].
12. INTERNATIONAL DATA TRANSFERS
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities. These countries may have data protection laws that differ from those in your jurisdiction.
Where required by applicable law, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) as the legal basis for cross-border data transfers, supplemented by appropriate technical and organizational measures as determined by a transfer impact assessment. These safeguards ensure that your personal data receives an adequate level of protection regardless of the country in which it is processed. You may request a copy of the applicable transfer safeguards by contacting us at [email protected].
13. CALIFORNIA PRIVACY RIGHTS
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected the information, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information as defined under the CCPA. We do not share your personal information for cross-context behavioral advertising purposes.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of your sensitive personal information to that which is necessary to perform the Service (see Sensitive Personal Information below).
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
How to Exercise Your Rights
To exercise your California privacy rights, contact us at [email protected]. You may also designate an authorized agent to submit a request on your behalf, provided the agent presents your written authorization and we can verify your identity. We will respond to verifiable requests within forty-five (45) days. If additional time is needed (up to an additional forty-five (45) days), we will notify you of the extension and the reason for the delay.
Categories of Personal Information Collected
Under the CCPA, we collect the following categories of personal information:
| CCPA Category | Examples | Sources | Business Purpose | Third Parties Receiving |
|---|---|---|---|---|
| Identifiers | Name, email, IP address, device identifiers, employee ID | Directly from you; automatically from devices | Providing the Service, account management, security | Cloud infrastructure providers, email delivery providers, error tracking providers |
| Personal information under Cal. Civ. Code § 1798.80 | Name, phone number, employment information, pay rates | Directly from you or your employer (Subscriber) | Workforce management, payroll processing | Cloud infrastructure providers, accounting integration providers |
| Biometric information | Facial images, facial geometry identifiers | Directly from you via mobile camera (where enabled) | Identity verification at clock events | Cloud infrastructure providers for encrypted storage only |
| Internet or electronic network activity | Usage data, feature interactions, device information, app version | Automatically from devices | Service improvement, error resolution, security | Analytics providers, error tracking and performance monitoring providers |
| Geolocation data | GPS coordinates, geofence compliance data | Automatically from mobile devices (where enabled) | Attendance verification, geofence monitoring | Cloud infrastructure providers |
| Professional or employment-related information | Job title, department, pay rates, work schedules, document verification status | Directly from you or your employer (Subscriber) | Workforce management, compliance tracking | Cloud infrastructure providers, accounting integration providers |
| Inferences | Workforce analytics, attendance patterns, overtime calculations | Derived from data above | Reporting, payroll, compliance | None (generated and used internally) |
Sensitive Personal Information
Under the CPRA, we collect the following categories of sensitive personal information:
| Category | Examples | Purpose |
|---|---|---|
| Precise geolocation | GPS coordinates during active shifts | Geofence monitoring and attendance verification |
| Biometric information | Facial images and geometry identifiers | Identity verification at clock-in/out (where enabled) |
| Government-issued identification | Uploaded ID cards and documents | Worker document management and compliance verification |
You have the right to limit our use of your sensitive personal information to that which is necessary to perform the Service. To exercise this right, contact us at [email protected].
14. EUROPEAN DATA PROTECTION RIGHTS
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR), the UK GDPR, or equivalent legislation, including:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data, subject to certain exceptions
- Right to Restrict Processing: Request that we restrict the processing of your personal data
- Right to Data Portability: Request a copy of your personal data in a structured, machine-readable format
- Right to Object: Object to the processing of your personal data for certain purposes, including processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal
- Right Regarding Automated Decision-Making: Where automated processing produces legal or similarly significant effects, request human review of such decisions, express your point of view, and contest the decision (see Section 9)
Legal Bases for Processing
We process personal data on the following legal bases:
- Contract Performance: Processing necessary to perform our contract with you (providing the Service, managing your Account, processing clock events and timesheets)
- Legitimate Interests: Processing necessary for our legitimate business interests (security, fraud prevention, service improvement, error resolution), where those interests are not overridden by your rights
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent (biometric data collection, optional analytics)
- Legal Obligation: Processing necessary to comply with legal obligations (tax records, regulatory requirements)
Data Processing Agreement
For Subscribers who require a Data Processing Agreement (DPA) under applicable data protection laws, we offer a standard DPA available upon request. Contact us at [email protected].
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority in the EU or UK member state of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available at the European Data Protection Board website.
Automated Decision-Making
Certain features of the Service involve automated processing that may produce effects on Authorized Users, including automated clock-out, time entry auto-approval, and document compliance checks. For details on these features, see Section 9 (Automated Decision-Making). Where required by applicable law, you have the right to request human review of automated decisions.
Data Controller and Processor Roles
For the purposes of applicable data protection laws:
- The Subscriber is the data controller with respect to Customer Data, including employee information, timesheet records, location data, and biometric data processed through the Service. The Subscriber determines the purposes and means of processing Customer Data.
- Kevadia LLC (d/b/a IronClock) acts as a data processor, processing Customer Data on behalf of the Subscriber in accordance with the Subscriber's instructions and the terms of any applicable Data Processing Agreement (DPA).
- Kevadia LLC (d/b/a IronClock) is an independent data controller with respect to: (a) Account registration information provided directly by users; (b) Service Data (usage patterns, performance metrics, system logs, metadata); (c) usage analytics collected for service improvement and error resolution; and (d) data processed for IronClock's own legitimate business purposes, including security, billing, and fraud prevention. Where IronClock acts as a data controller, it processes personal data in accordance with this Privacy Policy.
To exercise your European data protection rights, contact us at [email protected].
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days' prior notice by email to the address associated with your Account or by prominent notice within the Service. For non-material changes, we will use reasonable efforts to provide notice. Your continued use of the Service following the effective date of any modification constitutes acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
16. CONTACT INFORMATION
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Kevadia LLC (d/b/a IronClock)
Email: [email protected]
Website: www.ironclock.app
For data protection inquiries or to exercise your privacy rights, email: [email protected]
Last Updated: February 24, 2026