Privacy Policy
Effective Date: 24 August 2026
1. Introduction
Fiable Technologies (“we”, “us”, “our”) operates Trizelo, a cloud‑based workforce‑management SaaS platform. This Privacy Policy explains how we collect, use, disclose, store, protect, and retain personal data of our customers, their employees, and any other individuals (“you”, “your”) who interact with Trizelo. By using Trizelo you acknowledge that you have read, understood, and consent to the practices described herein.
2. Legal Framework
| Jurisdiction | Governing Law(s) | Key Provisions |
|---|---|---|
| Canada | Personal Information Protection and Electronic Documents Act (PIPEDA) | Consent, purpose limitation, access, correction, retention, safeguards, breach reporting |
| European Union | General Data Protection Regulation (GDPR) | Lawful bases, data‑subject rights, breach notification, DPIA, transfer mechanisms |
| United States (California) | California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA) | Right to know, delete, opt‑out of sale, non‑discrimination |
| Other jurisdictions | Applicable local data‑protection statutes | As required by local law |
We rely on one or more of the following lawful bases (GDPR Art. 6):
- Contractual necessity – to deliver Trizelo and fulfill our service agreement with you.
- Legitimate interests – for security, fraud prevention, platform improvement (balanced against your rights).
- Consent – where we ask for explicit opt‑in (e.g., marketing communications, optional analytics).
- Legal obligation – to comply with statutory or regulatory duties (tax, labor, court orders).
3. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identification & Contact | Full name, email address, phone number, job title, employee ID, company name, postal address | Account registration, onboarding forms, HR CSV imports |
| Authentication & Security | Username, password hash, authentication tokens, MFA data, IP address, device fingerprint | Login flow, Laravel Sanctum token issuance, security logs |
| Employment & Payroll | Pay rate, bank account (last 4 digits), tax identifiers, work schedules, timesheet entries, attendance records | HR onboarding, schedule imports, timesheet submission |
| Communications | In‑app messages, notifications, support tickets, email correspondence | Messaging module, support portal |
| Device & Usage | Browser/user‑agent, cookies, session IDs, log data, error reports | Web UI, API calls, analytics |
| Optional & Derived | Profile photo, custom fields, feature‑usage analytics | User‑uploaded files, optional settings |
4. How We Use Your Data
- Service Delivery – account creation, authentication, role‑based access control, scheduling, timesheet & payroll processing, reporting.
- Customer Support – respond to support tickets, troubleshoot issues, improve reliability.
- Security & Fraud Prevention – detect unauthorized access, maintain audit logs, enforce MFA, monitor anomalous activity.
- Legal & Regulatory Compliance – retain records for tax, labor‑law, audit requirements; respond to lawful requests.
- Product Improvement – aggregate, anonymized usage analytics to prioritize features and fix bugs (no personal identifiers).
- Communications – send transactional emails (password resets, alerts) and, where you have opted‑in, marketing or product‑update newsletters.
5. Data Sharing & Disclosure
| Recipient | Purpose | Safeguards |
|---|---|---|
| Your Organization’s Administrators | HR/management functions | Role‑based access controls (RBAC) enforced via config/permissions.php |
| Third‑Party Service Providers | Perform services on our behalf (e.g., email delivery, payment gateways, backup storage) | Data Processing Agreements (DPAs) requiring equivalent data‑protection standards |
| Regulatory Authorities | Legal compliance, tax reporting, court orders | Disclosure limited to the specific data requested; we provide notice when permissible |
| Aggregated, Anonymized Analytics Vendors | Product usage analysis | Personal identifiers removed; data is fully aggregated |
We do not sell personal data to any third party.
6. International Data Transfers
Trizelo is hosted on cloud infrastructure located in Canada, the United States, and the European Union. When transferring personal data outside the European Economic Area (EEA) we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, or
- Adequacy decisions (e.g., for transfers to Canada).
All transfers are recorded in our internal data‑flow register and protected by encryption in transit (TLS 1.2+).
7. Data Security
- Encryption at Rest – Sensitive columns (e.g., SSN, banking details) are encrypted using PostgreSQL `pgcrypto`.
- Encryption in Transit – All API and UI traffic uses TLS 1.2+ with strong cipher suites (`DB_SSLMODE=verify-full` in production).
- Access Controls – RBAC enforced via `config/permissions.php` and Laravel policies; least‑privilege principle applied.
- Audit Logging – Every create, update, or delete operation on personal data is recorded in the `audit_logs` table.
- Incident Response – 24/7 monitoring; security incidents are reported to affected individuals within 72 hours (GDPR Art. 33).
8. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| User account & authentication data | Until account deletion or legal requirement | Contractual & security purposes |
| Payroll & timesheet records | Minimum 7 years (or longer per local labor law) | Tax & labor‑law compliance |
| Support tickets & communications | 2 years | Service quality & dispute resolution |
| Audit logs | 1 year (configurable up to 3 years) | Security monitoring & compliance |
| Marketing preferences | Until you withdraw consent | Consent‑based processing |
We perform periodic reviews and securely delete data that is no longer needed.
9. Your Rights
Depending on your jurisdiction, you may exercise the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Obtain a copy of your personal data. | Submit a request via the Data‑Subject Request form in the app or email privacy@trizelo.app. |
| Rectification | Correct inaccurate or incomplete data. | Update via the UI or request via email. |
| Erasure | Delete personal data (subject to legal limits). | Request through the Data‑Subject Request form; we’ll confirm deletion or explain lawful retention. |
| Restriction | Limit processing pending verification. | Email request; we’ll suspend non‑essential processing. |
| Portability | Receive data in a structured, commonly used format. | Email request; we’ll deliver CSV/JSON within 30 days. |
| Objection | Object to processing based on legitimate interests or direct marketing. | Email privacy@trizelo.app. |
| Withdraw Consent | Stop processing that relies on consent. | Use the in‑app “Privacy Settings” page or email notice. |
We aim to respond to all lawful requests within 30 days (extendable to 90 days for complex cases as allowed by GDPR).
10. Cookies & Tracking Technologies
| Type | Purpose | User Control |
|---|---|---|
| Essential Cookies | Session ID, CSRF token, authentication cookie (secure, HttpOnly) | Managed automatically; cannot be disabled without breaking the service. |
| Analytics Cookies | Optional usage insights (if admin enables “Usage Analytics”) | Opt‑in/opt‑out via admin UI; no personal identifiers stored. |
| Third‑Party Cookies | Services such as email delivery (e.g., SendGrid) | Controlled by the third‑party’s privacy policy; can be disabled in browsers. |
Manage preferences via your browser settings or the Privacy Settings page in Trizelo.
11. Children & Minors
Trizelo is not directed to children under 13 years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has provided personal data, please contact us to have it removed.
12. Changes to This Privacy Policy
We may update this policy to reflect changes in law, technology, or business practices.
- Notification: Significant changes (affecting your rights) will be communicated via email and posted on the Privacy Policy page with a revised effective date.
- Version History: Each revision includes a short summary of changes.
13. Contact Information
Fiable Technologies
Privacy Officer – Data Protection
- Email: privacy@trizelo.app
- Phone: +1 (639) 590-5105
If you have any questions, concerns, or wish to exercise any of your data‑subject rights, please contact us using the details above.