Legal & Compliance

Privacy Policy

Effective Date: 24 August 2026

1. Introduction

Fiable Technologies (“we”, “us”, “our”) operates Trizelo, a cloud‑based workforce‑management SaaS platform. This Privacy Policy explains how we collect, use, disclose, store, protect, and retain personal data of our customers, their employees, and any other individuals (“you”, “your”) who interact with Trizelo. By using Trizelo you acknowledge that you have read, understood, and consent to the practices described herein.


2. Legal Framework

Jurisdiction Governing Law(s) Key Provisions
Canada Personal Information Protection and Electronic Documents Act (PIPEDA) Consent, purpose limitation, access, correction, retention, safeguards, breach reporting
European Union General Data Protection Regulation (GDPR) Lawful bases, data‑subject rights, breach notification, DPIA, transfer mechanisms
United States (California) California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA) Right to know, delete, opt‑out of sale, non‑discrimination
Other jurisdictions Applicable local data‑protection statutes As required by local law

We rely on one or more of the following lawful bases (GDPR Art. 6):

  • Contractual necessity – to deliver Trizelo and fulfill our service agreement with you.
  • Legitimate interests – for security, fraud prevention, platform improvement (balanced against your rights).
  • Consent – where we ask for explicit opt‑in (e.g., marketing communications, optional analytics).
  • Legal obligation – to comply with statutory or regulatory duties (tax, labor, court orders).

3. Personal Data We Collect

Category Examples Source
Identification & Contact Full name, email address, phone number, job title, employee ID, company name, postal address Account registration, onboarding forms, HR CSV imports
Authentication & Security Username, password hash, authentication tokens, MFA data, IP address, device fingerprint Login flow, Laravel Sanctum token issuance, security logs
Employment & Payroll Pay rate, bank account (last 4 digits), tax identifiers, work schedules, timesheet entries, attendance records HR onboarding, schedule imports, timesheet submission
Communications In‑app messages, notifications, support tickets, email correspondence Messaging module, support portal
Device & Usage Browser/user‑agent, cookies, session IDs, log data, error reports Web UI, API calls, analytics
Optional & Derived Profile photo, custom fields, feature‑usage analytics User‑uploaded files, optional settings
Sensitive Personal Data (e.g., social‑insurance numbers, health information) is only stored when strictly required for payroll processing and is encrypted at the column level (see § 7).

4. How We Use Your Data

  • Service Delivery – account creation, authentication, role‑based access control, scheduling, timesheet & payroll processing, reporting.
  • Customer Support – respond to support tickets, troubleshoot issues, improve reliability.
  • Security & Fraud Prevention – detect unauthorized access, maintain audit logs, enforce MFA, monitor anomalous activity.
  • Legal & Regulatory Compliance – retain records for tax, labor‑law, audit requirements; respond to lawful requests.
  • Product Improvement – aggregate, anonymized usage analytics to prioritize features and fix bugs (no personal identifiers).
  • Communications – send transactional emails (password resets, alerts) and, where you have opted‑in, marketing or product‑update newsletters.

5. Data Sharing & Disclosure

Recipient Purpose Safeguards
Your Organization’s Administrators HR/management functions Role‑based access controls (RBAC) enforced via config/permissions.php
Third‑Party Service Providers Perform services on our behalf (e.g., email delivery, payment gateways, backup storage) Data Processing Agreements (DPAs) requiring equivalent data‑protection standards
Regulatory Authorities Legal compliance, tax reporting, court orders Disclosure limited to the specific data requested; we provide notice when permissible
Aggregated, Anonymized Analytics Vendors Product usage analysis Personal identifiers removed; data is fully aggregated

We do not sell personal data to any third party.


6. International Data Transfers

Trizelo is hosted on cloud infrastructure located in Canada, the United States, and the European Union. When transferring personal data outside the European Economic Area (EEA) we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • Adequacy decisions (e.g., for transfers to Canada).

All transfers are recorded in our internal data‑flow register and protected by encryption in transit (TLS 1.2+).


7. Data Security

  • Encryption at Rest – Sensitive columns (e.g., SSN, banking details) are encrypted using PostgreSQL `pgcrypto`.
  • Encryption in Transit – All API and UI traffic uses TLS 1.2+ with strong cipher suites (`DB_SSLMODE=verify-full` in production).
  • Access Controls – RBAC enforced via `config/permissions.php` and Laravel policies; least‑privilege principle applied.
  • Audit Logging – Every create, update, or delete operation on personal data is recorded in the `audit_logs` table.
  • Incident Response – 24/7 monitoring; security incidents are reported to affected individuals within 72 hours (GDPR Art. 33).

8. Data Retention

Data Type Retention Period Reason
User account & authentication data Until account deletion or legal requirement Contractual & security purposes
Payroll & timesheet records Minimum 7 years (or longer per local labor law) Tax & labor‑law compliance
Support tickets & communications 2 years Service quality & dispute resolution
Audit logs 1 year (configurable up to 3 years) Security monitoring & compliance
Marketing preferences Until you withdraw consent Consent‑based processing

We perform periodic reviews and securely delete data that is no longer needed.


9. Your Rights

Depending on your jurisdiction, you may exercise the following rights:

Right Description How to Exercise
Access Obtain a copy of your personal data. Submit a request via the Data‑Subject Request form in the app or email privacy@trizelo.app.
Rectification Correct inaccurate or incomplete data. Update via the UI or request via email.
Erasure Delete personal data (subject to legal limits). Request through the Data‑Subject Request form; we’ll confirm deletion or explain lawful retention.
Restriction Limit processing pending verification. Email request; we’ll suspend non‑essential processing.
Portability Receive data in a structured, commonly used format. Email request; we’ll deliver CSV/JSON within 30 days.
Objection Object to processing based on legitimate interests or direct marketing. Email privacy@trizelo.app.
Withdraw Consent Stop processing that relies on consent. Use the in‑app “Privacy Settings” page or email notice.

We aim to respond to all lawful requests within 30 days (extendable to 90 days for complex cases as allowed by GDPR).


10. Cookies & Tracking Technologies

Type Purpose User Control
Essential Cookies Session ID, CSRF token, authentication cookie (secure, HttpOnly) Managed automatically; cannot be disabled without breaking the service.
Analytics Cookies Optional usage insights (if admin enables “Usage Analytics”) Opt‑in/opt‑out via admin UI; no personal identifiers stored.
Third‑Party Cookies Services such as email delivery (e.g., SendGrid) Controlled by the third‑party’s privacy policy; can be disabled in browsers.

Manage preferences via your browser settings or the Privacy Settings page in Trizelo.


11. Children & Minors

Trizelo is not directed to children under 13 years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has provided personal data, please contact us to have it removed.


12. Changes to This Privacy Policy

We may update this policy to reflect changes in law, technology, or business practices.

  • Notification: Significant changes (affecting your rights) will be communicated via email and posted on the Privacy Policy page with a revised effective date.
  • Version History: Each revision includes a short summary of changes.

13. Contact Information

Fiable Technologies

Privacy Officer – Data Protection

If you have any questions, concerns, or wish to exercise any of your data‑subject rights, please contact us using the details above.