Clenzus - Privacy Policy
Effective date: July 13, 2026 Last updated: August 28, 2026
Plain-language summary (this is a friendly overview - the full policy below is what governs). Clenzus is software that companies use to run their field teams and the sites they service. Almost everything personal inside Clenzus is put there by, or on behalf of, your employer - your profile, your schedule, your hours, your pay information, and photos of completed work. Your employer decides what goes in, turns features on or off, and is responsible for telling you about it and getting any consent the law requires. Clenzus simply stores and protects that information so the software can do its job for your company. We are not in the business of reading your records: our platform-wide reporting of operational activity shows only combined, de-identified numbers, and we never see your password. Authorized security staff access an individual account only when genuinely needed to run, secure, support, or fix the Service, or when the law requires it. We do not collect your fingerprint or your face - any biometric check happens privately on your own device. Location tracking is off unless your company turns it on, and when it is on, you are asked to agree first and shown a clear indicator on your profile that it is on and which mode is active. This policy explains all of that in detail.
This Privacy Policy describes how Clenzus ("Clenzus," "we," "us," "our") - operated by Clenzus Inc., a corporation governed by the laws of the Province of Manitoba, Canada - collects, uses, stores, shares, and protects personal information in connection with the Clenzus web application, mobile applications, application programming interfaces, and related services (together, the "Service"). It forms part of, and is incorporated into, the Terms of Service. Please read both together. If there is any conflict between a short summary and the detailed terms, the detailed terms control.
1. Who Clenzus is built for
Clenzus is workforce and operations software built for companies that deliver services in the field - that is, any business whose people work across one or more customer sites, buildings, or locations rather than only at a single head office. This includes, without limitation, commercial cleaning and janitorial companies, facility-management and building-services providers, security and guarding firms, maintenance and repair businesses, landscaping and grounds companies, and other service-provider organizations that need to schedule crews, confirm attendance, track work, and keep their clients happy.
Clenzus is used by companies in most countries, across many industries. The Service is not yet available in the EU/EEA, the United Kingdom, India, the United Arab Emirates, or Saudi Arabia (coming soon - see Section 12.3), where we are still completing local data-protection requirements. Customers everywhere are responsible for using the Service in line with the laws that apply to them, their workforce, and their clients.
Because the Service is built for these organizations, most of the personal information it holds is information about a company's own workforce and its own clients, entered and controlled by that company. Understanding this is the key to understanding this policy, so we explain it next.
2. The most important thing to understand: who controls your information
Privacy law draws a line between the party that decides what personal information is collected and why (the "controller"), and the party that merely stores and processes that information on the controller's instructions (the "processor" or "service provider"). Clenzus sits on both sides of that line depending on whose information it is, and this shapes everything else in this policy.
2.1 For your company's workforce and client information, Clenzus is only the processor
For the operational and workforce information that a company (our "Customer") and its authorized users put into, or generate within, the Service - for example personnel records, schedules, hours, location signals (where enabled), pay information, photos of work, complaints, tickets, deficiencies, equipment issues, inventory and supply requests, site records, and client and contract records - the Customer is the controller and Clenzus is only the processor. In plain terms:
- Your employer decides what is entered, what features are switched on, who can see what, and how
long it is kept.
- Clenzus holds that information on your employer's behalf, so the software your employer chose
can actually run - the same way a filing cabinet or an accountant holds records for a business.
- Clenzus does not use that information for its own purposes. We do not sell it, we do not
advertise with it, and we do not mine the content of your records to build unrelated products.
If you are a worker, supervisor, or administrator using Clenzus because your employer provisioned it for you, your employer - not Clenzus - is the party that decides what is collected about you and why. For most questions or requests about your personal information, you should contact your employer first; we will help your employer respond.
2.2 For our own business information, Clenzus is the controller
For the limited information we collect directly to run Clenzus as a business - such as the details used to create and bill an account, and the security and audit records we keep to protect the platform - Clenzus is the controller, and this policy describes how we handle it. This includes the business contact details of a company's primary administrator(s) - name, work email, and phone number - which we retain so that we can reach that company about its account (for example, for provisioning, support, security, and billing matters). We use these details for account and contact purposes only; we do not use them for advertising, and we do not sell them. It also includes business-verification information you provide when we ask you to confirm you operate a legitimate business (see Section 4.9), which we collect and review as a controller and then delete.
2.3 A Data Processing Addendum is available to business Customers
Because Clenzus is a processor of the Customer's workforce and client data, business Customers - and, should the Service open to Customers subject to the EU or UK GDPR, those Customers - are covered by the Data Processing Addendum (DPA), which is incorporated into the Terms of Service and takes effect when the Customer accepts the Terms (no separate signature required). The DPA sets out, under Article 28 of the GDPR (and equivalent UK rules), how Clenzus processes personal data on the Customer's instructions, the security and confidentiality commitments, the rules for engaging subprocessors, how Clenzus assists with data-subject requests and breach notification, the international-transfer safeguards, and how data is returned or deleted at the end of the relationship. A Customer that needs a signed copy may request one at legal@clenzus.com.
3. What "Clenzus does not see your data" really means
We want to be honest and precise here, because trust matters and because vague promises help no one.
- We do not read the content of your operational records. Clenzus is designed so that the people
who operate the platform do not browse the contents of a company's individual operational records
- the descriptions inside tickets and complaints, photos, notes, or site and facility details - in the
ordinary course of business. Our platform-wide monitoring of that activity is deliberately limited to aggregate, de-identified numbers - for example, "how many tickets were opened across the platform this week" - and is built so it does not surface the content inside any specific company's records.
- We never see your password. User passwords are stored only as a one-way cryptographic hash.
No one at Clenzus - including our security staff - can view, retrieve, or read your password. If a password reset is ever performed, it replaces the password with a new one; it does not reveal the existing one.
- Account and identity information is accessed only for security. A small number of authorized
security staff *can*, when there is a specific need, see account-level information - such as a user's name, email address, role, whether an account is active, and account-security details such as a verification PIN - and perform account-security actions such as forcing a password reset or disabling an account. This is not part of day-to-day operation and is never used to read your work. It is reserved strictly for genuine security and account-integrity purposes - for example investigating a suspected breach or account misuse, acting on an authorized request from the platform operator, or protecting the Service and the people who use it. Access of this kind is limited to what is needed and is logged.
- When we access anything else, it is narrow and purposeful. Like any hosted software provider, our
systems and authorized staff *can* technically access stored data when it is genuinely necessary - for example to keep the Service running, to provide support you or your employer request, to fix a defect, to make a lawful backup, or to comply with a legal obligation. We limit that access to what is needed, and we log it.
- Your data belongs to your company, not to us. As between Clenzus and the Customer, the Customer
owns its data. We keep it safe and available to the Customer; we do not treat it as ours.
In short: the reason this information lives in our database at all is so the software can do its job for your company - not so that Clenzus can read it. That is a meaningful and enforceable distinction, and it is how the platform is built.
4. Information stored in, or collected through, Clenzus
Below is the full picture of what may be present in the Service. Where an item is entered or controlled by your employer, we hold it as a processor (Section 2.1). Where an item is collected by us directly, we act as a controller (Section 2.2). We call this out for each category.
4.1 Account and identity information *(entered/controlled by your employer)*
Basic details that let the software recognize a person and give them the right access: name, work email address, phone number, an employee identifier, role, employment date and status, department or position, emergency-contact details, and profile information. Each account has a four-digit access PIN, which the Service generates automatically (users do not choose it) and stores in encrypted form, so it cannot simply be read back. A user's PIN is issued and managed by the people above them in their organization's reporting chain - a manager can regenerate and view the PIN of the users who report to them - and only the company's senior administrators may regenerate their own PIN. A user may instead turn on multi-factor authentication using an authenticator app for stronger sign-in protection; while it is on, the PIN is not required, and if the authenticator is lost an authorized administrator can remove it and re-issue a PIN. This information exists so the right person can log in and see the right things - it is provided under your employer's control, and we do not use it for our own purposes.
4.2 Human-resources and payroll information *(entered/controlled by your employer)*
Where a company chooses to run pay-related workflows in Clenzus, the software may hold pay rate, payroll file numbers and payroll identifiers, earning codes, partial tax identifiers (for example, only the last few digits of a government identification number), tax identifiers, and the codes used to line data up with an outside payroll provider (for example, ADP or Paychex identifiers). Your employer decides whether to use these fields at all and what to put in them. Clenzus stores this so your employer can prepare and reconcile pay accurately; we do not read it for any purpose of our own.
4.3 Location and attendance information *(off unless your employer turns it on - see Section 6)*
When - and only when - a company switches on a location feature, the Service may process location signals to confirm attendance. This is one of the most sensitive areas, so it has its own detailed section below (Section 6, "Location and GPS"). The short version: location is off by default, nothing is tracked or stored while it is off, and when it is on everyone is clearly and continuously notified.
4.4 Photographs and work evidence *(entered/controlled by your employer)*
Photos that users attach to complaints, tickets, inspections, deficiencies, site audits, before/after records, and similar items. These are stored as proof of work - for example, to show a site was serviced properly - and may show the interior or condition of a building. Your employer decides whether and how photos are used.
4.5 Operational records *(entered/controlled by your employer)*
The day-to-day records that make the software useful: schedules and shifts; time and attendance punches; complaints, tickets, deficiencies, equipment issues; inventory and supply requests; site and facility records; points of contact; client and contract records (including contract values and the reasons a contract ended); notifications; and site notes. These are the substance of your company's operations and are controlled by your company.
4.6 Communications *(some to us, some within your company)*
Messages you send to Clenzus (for example, a support request) are handled by us as a controller. Comments and discussion you post inside a record in the Service are operational content controlled by your employer.
4.7 Device, log, and security information *(collected by us to protect the platform)*
To keep accounts and the platform safe, we and our infrastructure providers automatically record a limited set of technical signals: the IP address a request comes from and the city, region, and country derived from it; browser/device information and the last device an account was verified on; and sign-in, session, and account-activity records that form a security audit trail. We use this strictly to protect you and your company - for example, to notice an unusual sign-in by comparing where an account is signing in from against where that person is expected to work, to power multi-factor authentication, and to investigate suspected fraud or account misuse. This is not marketing data, and we do not use it to profile you.
4.8 Usage information *(collected by us to run and improve the Service)*
General information about how the Service is used - which helps us keep it reliable, secure, and better over time. Where possible this is handled in an aggregated form (Section 8).
4.9 Business-verification information *(collected by us as controller)*
If you register with a free or personal email address, we may ask you to provide a document that shows you operate a real, registered business (for example a business licence, a registration or incorporation certificate, or a tax registration). We collect this only to confirm you are a legitimate business, we hold it only for as long as it takes to review it, and we delete the document once verification is complete - keeping only a minimal record that verification occurred (its date, method, and the type of document reviewed - see Section 10). It is stored with heightened protection (Section 11) and is accessible only to the small number of people authorized to perform verification.
We do not intentionally collect special-category or "sensitive" personal information beyond the limited payroll identifiers described above, and we ask Customers not to enter sensitive information the Service is not designed to hold.
5. Biometric information - we do not collect it
Some plans may offer, as a planned per-plan capability, on-device biometric verification (for example, Face ID or a fingerprint), or a passkey, as a way to confirm that the right person is clocking in. This is an optional feature that a plan may make available; it is not enabled platform-wide, and today most sign-in confirmation relies on a device PIN or an authenticator app. Whether or not this feature is offered, the design principle below never changes - and it is important to understand exactly how it works, because biometrics are heavily regulated and often misunderstood:
- The biometric check happens entirely on the user's own device, using the device's own secure
hardware (the same mechanism that unlocks the phone itself).
- Clenzus never collects, receives, stores, or has access to any fingerprint, faceprint, face
geometry, or other biometric identifier. None of it ever leaves the device or reaches our servers.
- All the device tells the Service is a simple yes/no: whether the on-device check succeeded. We
store only that result, not the biometric itself.
Because the biometric never comes to us, Clenzus is not a collector of biometric information, and using this feature does not put your fingerprint or face into our database - it stays with you, on your device, under your control.
To be precise: the pass/fail result is not a biometric identifier or biometric information. It is not derived from, does not contain, and cannot be used to reconstruct any fingerprint, faceprint, face geometry, or other biometric. Clenzus performs no server-side biometric matching, does not compare photographs to identify or verify anyone, and does not store any biometric template in its database. Biometric verification results are never sold, disclosed, or included in aggregated or de-identified information. Because no biometric identifier or biometric information is ever collected, received, stored, or possessed by Clenzus, the laws that regulate the collection or possession of biometrics - such as the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric law (RCW 19.375) - do not impose their collection, retention, or destruction duties on Clenzus. Where a Customer enables this feature, the Customer is responsible for any notice or consent those laws require of the employer.
6. Location and GPS - how it works, and how we keep it fair
Clenzus is built so companies can prove that field work actually happened - the crew arrived, at the right place, at the right time. Location features exist to serve that legitimate operational need. Because location is sensitive, we designed these features around three firm principles: it is off unless your company deliberately turns it on; you are always told when it is on; and your company chooses the least-intrusive mode that meets its needs.
6.1 Location is off by default - and off means nothing is collected
If your company does not use location - whether because it chooses not to, or because it cannot for legal, labour, or practical reasons - then GPS is simply off. When it is off, the Service does not request your location, does not track you, and does not store any location data at all. There is no hidden collection. No signal is captured "just in case."
6.2 If location is on, you are asked first and shown a clear indicator
When a company enables a location feature, the Service asks the affected user to agree before location is used, and shows a clear "location is on" indicator - including which mode is running - on the user's profile. The point is that no one is tracked without being asked and being able to see that it is on, and that your employer (the party that controls this) has provided any notice and obtained any consent the law requires before turning it on.
6.3 The four location modes, explained
Your company selects one of the following modes per site, so tracking is never more than the situation calls for:
- Mode 1 - Off (no location). The default. Attendance is recorded by clock-in and clock-out
only. No coordinates are requested, captured, or stored, ever. This is the most private option.
- Mode 2 - Geofence / radius check. A privacy-minimal "am I at the right place?" check. When a
user clocks in, the Service confirms the device is within the site's set radius. It is used to allow or block the clock-in - it does not save the user's coordinates and does not follow the user anywhere. It answers a single yes/no question at the moment of clock-in.
- Mode 3 - Point-of-action capture (clock-in / clock-out only). The Service records the location
at the exact moment a user clocks in and clocks out - and at no other time. There is no tracking in between. Managers can later see where the clock-in and clock-out happened, as proof of presence, but no one can watch a person move during the shift, because nothing in between is collected.
- Mode 4 - Live location during a shift. For a company's highest-accountability contracts, the
Service can show a user's location on a map while a shift is active, so the team can see that people are where they should be and are safe. This mode captures the most, and is therefore the one that requires the clearest notice and, where applicable, consent - which your employer is responsible for handling before enabling it. Live location is tied to the active shift; it is not a round-the-clock tracker of your personal life.
6.4 Facility coordinates
Separately from tracking people, the Service converts the site addresses your company enters into map coordinates (geocoding), so sites can be placed on a map and used for the geofence check. This is information about places, not people.
6.5 Who is responsible
Whether any location feature is on, which mode is used, and for whom, is entirely your employer's decision, made through its administrators. Clenzus provides the tools and the notices; your employer is the controller and is responsible for the lawful basis, the notice, and any consent required by employment, labour, privacy, or electronic-monitoring law before enabling location tracking.
7. How we use information
We use personal information for the following purposes, and - where we act as a processor - only to provide the Service and only on the Customer's instructions:
- to provide, operate, maintain, and secure the Service;
- to create and manage accounts and enforce role-based access, so each person sees only what they
are permitted to see;
- to record time and attendance and, where the Customer has enabled it, to verify location at
clock-in and enforce a geofence (Section 6);
- to deliver notifications and to enable the in-app records and communications the Service
provides;
- to process pay-related information as directed by the Customer, so the Customer can prepare and
reconcile payroll accurately;
- to protect accounts and the platform - including detecting and investigating unauthorized
access, comparing sign-in location against expected work location, and enforcing multi-factor authentication;
- to provide support and respond to requests from you or your employer;
- to produce aggregated, de-identified statistics and benchmarks used to operate, analyze, and
improve the Service (Section 8); and
- to comply with law and enforce our Terms.
We do not use the content of a Customer's operational records to make decisions about you; those decisions are made by your employer using the tools the Service provides.
8. Aggregated and de-identified information
We create aggregated, de-identified information from use of the Service, and we use it to run, secure, analyze, and improve the product and to produce statistics and benchmarks. "Aggregated and de-identified" means the information has been combined across many sources and stripped of identifiers, so that it does not identify any Customer, worker, client, building, or individual and cannot reasonably be used to do so. As noted in Section 3, our platform-wide monitoring of operational activity works at this aggregate level - surfacing only numbers, never the content of any individual operational record; account-level access is separate and, as described in Section 3, is used only for security and account-integrity purposes. We will not publish aggregated information in any form that identifies anyone. We commit to maintain and use aggregated and de-identified information only in that form, and we will not attempt to re-identify it. Our right to use aggregated, de-identified information continues even after an account ends.
9. How we share information
We do not sell personal information. We share it only in the limited ways described here:
- Within your own company's organization, according to the roles and access your company's
administrators configure. (This is how the software is supposed to work - a supervisor sees their team, an administrator sees the company, and so on.)
- With service providers ("subprocessors") that host and support the Service under contracts
requiring them to protect the information and to use it only to provide services to us. These providers fall into the following categories:
- Cloud hosting, database & authentication - running the application and securely storing its data;
- File & media storage - storing uploaded photos and documents;
- Transactional email delivery - sending account, security, and notification emails;
- Address geocoding - converting the site addresses your company enters into map coordinates.
A current, named list of these subprocessors is available on request (see below).
- For legal reasons - to comply with applicable law, to respond to a lawful request from a public
authority, or to protect the rights, property, or safety of Clenzus, our Customers, or others.
- In a business transfer - in connection with a merger, acquisition, financing, or sale of
assets, in which case this policy continues to apply to the information transferred.
Payments (Stripe). Paid subscriptions are processed by Stripe, Inc. ("Stripe"), our payment subprocessor. Card and bank details are entered directly into Stripe's secure, hosted payment pages - Clenzus never sees, receives, transmits, or stores your full card number, bank-account number, CVC/security code, or other sensitive payment credentials. We receive back from Stripe only limited, non-sensitive billing details (for example the card brand, the last four digits, the expiry, the billing country, and the payment status) to manage your subscription. Stripe processes your payment information as its own controller under the Stripe Privacy Policy and the Stripe Services Agreement. All billing is conducted exclusively in United States Dollars (USD) (see the Terms of Service for payment terms). Free and complimentary provisioning involves no charge and no payment details.
A current list of subprocessors is available on request at privacy@clenzus.com. Where required by the privacy laws that apply to a Customer, we will give affected Customers advance notice before a new subprocessor begins processing their personal information, together with a reasonable opportunity to object.
10. How long we keep information
We keep personal information for as long as it is needed to provide the Service and as directed by the Customer, and after that only for as long as required to comply with law, resolve disputes, and enforce our agreements. A Customer may archive or request deletion of its data. Some information may persist for a limited time in secure backups, or where the law requires us to keep it, and aggregated, de-identified information (Section 8) may be kept indefinitely because it no longer identifies anyone. After an account is terminated, the Customer may request an export of its data within 30 days, after which we may delete or de-identify it, subject to any legal retention requirements.
Security and audit-log retention (tiered). The security and audit-activity records described in Sections 4.7 and 11 are retained for a limited period that depends on the Customer's subscription tier and are then automatically and permanently purged by a scheduled retention process. Higher tiers retain this history longer than lower tiers; entry-level and free accounts are retained for the shortest period. The applicable retention window for a given tier is set out in the plan's feature details, and audit records with no associated company are purged at the shortest window.
Business-verification documents. Any document you submit to verify your business (Section 4.9) is kept only until verification is complete and is then deleted. We retain only a minimal record that verification took place - its date, method, and the type of document reviewed - not the document itself.
When a Customer removes, resets, or archives a record within the Service - for example a site, a contract, or its operational history - that record is generally hidden from the Customer's day-to-day users but may be retained in the underlying system for the Customer's own recordkeeping, audit, security, and legal purposes, and to support the Customer's authorized administrators. Retained records remain subject to the Customer's instructions and to this policy.
Responding to individual deletion requests. Where an individual asks for their personal information to be deleted (see Section 12), the Customer - acting through the Service - will erase the information that directly identifies that individual, such as name, contact details, emergency-contact details, and government or payroll identifiers, from that individual's profile. Certain records are, however, retained notwithstanding such a request to the extent retention is necessary to comply with a legal obligation to which the Customer is subject, or for the establishment, exercise, or defence of legal claims - including the Customer's tax, payroll, and employment-law recordkeeping duties. Records retained on this basis - which include time and attendance records (such as clock-in and clock-out entries), submitted and approved working hours, and payroll and wage records - are kept in a de-identified form, associated with a non-identifying reference rather than the individual's name, and are held only for the period, and for the purposes, that the applicable law permits, after which they are deleted or further anonymized. This reflects the limitations that data-protection laws place on the right to erasure where continued retention is legally required or necessary for legal claims.
11. How we protect information
We use technical and organizational safeguards designed to protect personal information, including:
- Encryption in transit, so information is protected as it travels between your device and the
Service, and field-level encryption at rest (AES-256) of the most sensitive stored identifiers - including the access PIN, partial tax identifiers (such as the last four digits of a Social Security or equivalent national ID number), and payroll file numbers - so they cannot simply be read from storage. These fields are additionally protected by strict tenant isolation and role-based access controls (described below), and are decrypted only when an authorized payroll/HR/administrator role reads them;
- Strict tenant isolation and row-level security, so that one company's data is walled off and
is not accessible to another company;
- Role-based, least-privilege access controls, including the data-minimizing oversight design
described in Section 3, where routine oversight sees only aggregate numbers rather than record content;
- Layered verification for sensitive actions - the most sensitive functions require an additional
identity confirmation beyond an ordinary sign-in, and are available only to a small number of authorized people, never on a casual or open-ended basis;
- Accountable, tamper-resistant access records - when an authorized person accesses account
information for a support or security reason, that access is tied to a specific, recorded purpose and written to a tamper-resistant record engineered so that these access entries cannot be altered or deleted in the ordinary course of operating the Service, so every such access can be accounted for afterward;
- Sign-in anomaly detection - the Service is designed to flag unusual sign-ins (for example, from
an unexpected location, by comparing where an account signs in from against where that person is expected to work) and to raise them for prompt security review.
Data-breach notification. No method of transmission or storage can be guaranteed to be perfectly secure. If we become aware of a personal-data breach affecting Customer Data, we will notify the affected Customer(s) without undue delay and cooperate with their breach-response and notification obligations, consistent with applicable law (including, as applicable, PIPEDA, Québec Law 25, the GDPR, the Australian Notifiable Data Breaches scheme, and the New Zealand notifiable-privacy-breach scheme). Where Clenzus is the processor, the Customer (as controller) remains responsible for notifying affected individuals and any regulator; where Clenzus is the controller of information it collects directly (Section 2.2), it will make any notification the law requires to the relevant regulator (including, as applicable, the Office of the Privacy Commissioner of Canada, the OAIC, or the New Zealand Privacy Commissioner) and to affected individuals.
No method of transmission or storage can be guaranteed to be perfectly secure, and we cannot promise absolute security. You and your company share responsibility by keeping credentials, PINs, and authenticator devices confidential and by removing access promptly when someone leaves.
12. Your privacy rights
Depending on where you live and your relationship to us, you may have rights to access, correct, update, delete, or receive a copy of your personal information, to object to or limit certain processing, to data portability, and to withdraw consent. Where any privacy law uses terms like the "sale" or "sharing" of personal information, Clenzus does not sell or share your personal information in that sense. As stated throughout, we do not sell personal information.
Because Clenzus does not sell personal information or use it for targeted advertising, opt-out preference signals (such as Global Privacy Control) do not apply to our processing, and Clenzus is not a data broker and is not required to register as one. Some information the Service can process - such as precise location (where a Customer enables it) and government or payroll identifiers - is treated as "sensitive" under some privacy laws; where Clenzus is the processor, it handles this only on the Customer's instructions, and the Customer, as controller, is responsible for any opt-in consent those laws require.
12.1 How to route a request (the controller/processor split)
Because of the controller/processor split (Section 2), where to send a request depends on whose information it is:
- For workforce and client information held on your employer's behalf (most of what is in
Clenzus), Clenzus is only the processor. The Service does not currently offer self-service export or erasure directly to individual workforce members, because your employer (the Customer) is the controller that decides what is collected and kept. Please make your request to your employer; we will assist the employer in identifying, exporting, correcting, or deleting the relevant records as their processor.
- For information Clenzus controls directly (account, billing, and security information - Section
2.2), contact us at privacy@clenzus.com. We may need to verify your identity before we act, so that we do not disclose information to the wrong person. We will respond within the timeframe the applicable law requires.
You will not be discriminated against for exercising any of these rights.
12.2 Canada - PIPEDA and Québec Law 25
Residents of Canada have rights under the federal *Personal Information Protection and Electronic Documents Act* (PIPEDA) and applicable provincial laws, including Québec's Law 25 and the Personal Information Protection Acts (PIPA) of Alberta and British Columbia. These include the right to access and correct your personal information and to complain to the Office of the Privacy Commissioner of Canada (or the applicable provincial regulator). Our lawful basis in Canada is consent (express or implied) and the other bases PIPEDA and Law 25 permit.
12.3 European Union / EEA and United Kingdom - GDPR and UK GDPR
If you are in the EEA or the UK, the EU GDPR and UK GDPR apply.
- Roles. For workforce and client data, the Customer (your employer) is the controller and
Clenzus is the processor, processing only on the Customer's documented instructions. For the account, billing, and platform-security data Clenzus collects directly, Clenzus is the controller.
- Lawful bases (for data Clenzus controls directly). We rely on performance of a contract
(to create, run, and bill accounts), our legitimate interests (to secure the platform, prevent fraud, and improve the Service in ways that do not override your rights), consent where we ask for it, and compliance with a legal obligation. Where Clenzus acts as processor, the lawful basis is the Customer's to establish and document.
- Your rights. You have the rights of access, rectification, erasure, restriction, objection,
portability, and the right to lodge a complaint with your local supervisory authority. For data held on your employer's behalf, route the request through your employer as described in 12.1. These rights are not absolute: in particular, the right to erasure does not extend to information that must be retained to comply with a legal obligation or for the establishment, exercise, or defence of legal claims, which is retained in de-identified form as described in Section 10.
- Data Processing Addendum. Business Customers may execute Clenzus's Article 28 DPA (Section
2.3) to govern this processing.
- International transfers. See Section 13 - Clenzus relies on the Standard Contractual Clauses
(and the UK Addendum) where personal data leaves the EEA/UK.
- EU / UK availability and representative. Clenzus is **not yet available to companies or
individuals located in the EU/EEA or the United Kingdom, and we do not currently accept account sign-ups from those regions (including sign-ups originating from EU/EEA/UK IP addresses). While the Service is closed to these regions, we do not intentionally process the personal data of individuals located there. We are completing the local data-protection steps - including appointing an EU representative under GDPR Article 27 and a UK representative - and will publish the representative's name and contact details here before opening the Service to these regions. In the meantime, if you believe we hold personal data about you, you may contact us at privacy@clenzus.com**.
12.4 California - CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, applies.
- Service-provider role. For workforce and client data, Clenzus acts as a service provider to
the Customer (the business) and processes personal information only to perform the Service under our contract. Clenzus does not "sell" or "share" personal information (as those terms are defined by the CCPA/CPRA), does not retain, use, or disclose it for any purpose other than providing the Service, and does not combine it with data from other sources except as permitted.
- Your rights. Subject to the routing in 12.1, you may have the right to know/access,
delete, correct, and opt out of sale/sharing (which Clenzus does not do), and to non-discrimination for exercising these rights. Requests about data Clenzus controls directly can be sent to privacy@clenzus.com.
12.5 Australia - Privacy Act 1988
Where the Australian Privacy Principles (APPs) apply, we handle personal information consistently with them, including openness about our practices (APP 1), notice of collection (APP 5), use and disclosure (APP 6), cross-border disclosure (APP 8 - see Section 13), security (APP 11), and access and correction (APPs 12 and 13). For workforce and client information held on your employer's behalf, route your request through your employer as described in 12.1; for information Clenzus controls directly, contact privacy@clenzus.com. You may also raise a concern with the Office of the Australian Information Commissioner (OAIC).
12.6 New Zealand - Privacy Act 2020
Where the Information Privacy Principles (IPPs) apply, we handle personal information consistently with them, including access and correction (IPPs 6 and 7) and cross-border disclosure (IPP 12 - see Section 13). Route workforce and client requests through your employer (12.1); for information Clenzus controls directly, contact privacy@clenzus.com. You may also raise a concern with the Office of the Privacy Commissioner.
12.7 Other jurisdictions
Individuals in other U.S. states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect) and in other countries and regions (for example Brazil's LGPD, Singapore's PDPA, Japan's APPI, South Africa's POPIA, India's Digital Personal Data Protection Act, and similar data-protection laws) may have comparable rights. We honour the rights that apply to you under the law of your jurisdiction. Where Clenzus is a processor/service provider, route your request through your employer (12.1); where Clenzus is the controller, contact privacy@clenzus.com.
13. International data transfers and data residency
Clenzus is based in Canada. Because Clenzus serves companies worldwide, personal information may be stored and processed in Canada, the United States, the European Union, and other countries where our infrastructure providers and subprocessors operate.
Where your data is processed. The core of the Service runs on a small set of subprocessors:
- Cloud database, authentication, and hosting - the primary backend that stores Customer Data;
- Object/file storage - for uploaded photos and documents;
- Transactional email delivery - for account, security, and notification emails;
- Address geocoding - to turn the site addresses a Customer enters into map coordinates; and
- IP geolocation - to derive the approximate city, region, and country from a request's IP address for the security checks described in Section 4.7 (for example, unusual-sign-in detection).
These providers may process data in the United States and other regions in addition to Canada; international transfers are governed by the safeguards described below in this Section and the security measures in Section 11. A current, named list of subprocessors is available on request at privacy@clenzus.com (see Section 9), and we commit to giving affected Customers advance notice of a new subprocessor with an opportunity to object, as described in Section 9.
Transfer mechanism. The Service is not currently offered in the EEA, the UK, or Switzerland. To the extent any personal data originating in the EEA, the UK, or Switzerland is nonetheless processed under the Agreement and transferred to a country that has not received an adequacy decision, we rely on an approved safeguard - principally the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum - together with the security measures described in Section 11. For transfers subject to Canadian and other laws, we rely on comparable contractual and organizational safeguards.
For personal information subject to Australian or New Zealand law that is processed in Canada, the United States, or elsewhere, Clenzus imposes contractual data-protection obligations on its subprocessors that are designed to secure handling consistent with the Australian Privacy Principles (APP 8) and the New Zealand Information Privacy Principles (IPP 12), and remains accountable for its subprocessors' handling of that information.
By using the Service, you understand that your information may be processed in these locations, each of which may have data-protection laws different from those in your home jurisdiction.
14. Children
The Service is intended for business use by individuals who are at least the age of majority in their jurisdiction and of legal working age, and is not directed to individuals below that age. We do not knowingly collect personal information from anyone who is not of the age of majority and legal working age. If you believe such a person has provided personal information through the Service, contact us and we will take steps to delete it.
15. Cookies, and communications you receive
The Service uses cookies and local storage that are necessary to sign you in, keep your session active, remember basic preferences, and operate securely. We do not use the Service to serve third-party advertising, and we do not use advertising trackers.
We send two kinds of email: service and security messages about your account, which are part of the Service; and, if we ever send them, optional product or marketing messages, which you can opt out of at any time using the unsubscribe link they contain or by emailing privacy@clenzus.com. Where we send commercial electronic messages, we comply with applicable anti-spam law (including Canada's CASL and, for United States recipients, CAN-SPAM): we identify ourselves and provide a working unsubscribe mechanism. We do not send text messages or automated calls; if we introduce them, we will first obtain any consent the law requires and provide a clear opt-out.
16. Changes to this policy
We may update this policy at any time as the Service, our providers, or the law evolve. When you accept this policy - which you do once, when you first use the Service - you agree to the policy as it exists then and as we may update it in the future under this section; you do not need to re-accept it each time it changes.
When we make changes, we will update the "Last updated" date above and make the current version available in the app. If the changes are material, we will also provide reasonable notice - for example, an in-app notice or an email to your account address. Your continued use of the Service after a change takes effect means you accept the updated policy, so please keep your email address current and review the policy periodically. The version posted in the app is always the current one and supersedes prior versions.
17. Contact us
Questions, requests, or complaints about privacy are welcome. Clenzus has designated a Privacy Officer responsible for compliance with applicable privacy law (including PIPEDA, Québec's Law 25, Singapore's PDPA, and Brazil's LGPD), reachable at the address below and monitored on an ongoing basis.
Clenzus Inc. Canada Email: privacy@clenzus.com