Clenzus — Privacy Policy
Effective date: July 13, 2026 Last updated: July 13, 2026
Plain-language summary (this is a friendly overview — the full policy below is what governs). Clenzus is software that companies use to run their field teams and the sites they service. Almost everything personal inside Clenzus is put there by, or on behalf of, your employer — your profile, your schedule, your hours, your pay information, and photos of completed work. Your employer decides what goes in, turns features on or off, and is responsible for telling you about it and getting any consent the law requires. Clenzus simply stores and protects that information so the software can do its job for your company. We are not in the business of reading your records: our platform monitoring of operational activity shows only combined, anonymous numbers, and we never see your password. Authorized security staff access an individual account only when genuinely needed to run, secure, support, or fix the Service, or when the law requires it. We do not collect your fingerprint or your face — any biometric check happens privately on your own device. Location tracking is off unless your company turns it on, and when it is on, everyone is clearly and continuously told it is on and which mode is active. This policy explains all of that in detail.
This Privacy Policy describes how Clenzus ("Clenzus," "we," "us," "our") collects, uses, stores, shares, and protects personal information in connection with the Clenzus web application, mobile applications, application programming interfaces, and related services (together, the "Service"). It forms part of, and is incorporated into, the Terms of Service. Please read both together. If there is any conflict between a short summary and the detailed terms, the detailed terms control.
1. Who Clenzus is built for
Clenzus is workforce and operations software built for companies that deliver services in the field — that is, any business whose people work across one or more customer sites, buildings, or locations rather than only at a single head office. This includes, without limitation, commercial cleaning and janitorial companies, facility-management and building-services providers, security and guarding firms, maintenance and repair businesses, landscaping and grounds companies, and other service-provider organizations that need to schedule crews, confirm attendance, track work, and keep their clients happy.
Clenzus is used by companies around the world, across many industries. Customers everywhere are responsible for using the Service in line with the laws that apply to them, their workforce, and their clients.
Because the Service is built for these organizations, most of the personal information it holds is information about a company's own workforce and its own clients, entered and controlled by that company. Understanding this is the key to understanding this policy, so we explain it next.
2. The most important thing to understand: who controls your information
Privacy law draws a line between the party that decides what personal information is collected and why (the "controller"), and the party that merely stores and processes that information on the controller's instructions (the "processor" or "service provider"). Clenzus sits on both sides of that line depending on whose information it is, and this shapes everything else in this policy.
2.1 For your company's workforce and client information, Clenzus is only the processor
For the operational and workforce information that a company (our "Customer") and its authorized users put into, or generate within, the Service — for example personnel records, schedules, hours, location signals (where enabled), pay information, photos of work, complaints, tickets, deficiencies, equipment issues, inventory and supply requests, site records, and client and contract records — the Customer is the controller and Clenzus is only the processor. In plain terms:
- Your employer decides what is entered, what features are switched on, who can see what, and how
long it is kept.
- Clenzus holds that information on your employer's behalf, so the software your employer chose
can actually run — the same way a filing cabinet or an accountant holds records for a business.
- Clenzus does not use that information for its own purposes. We do not sell it, we do not
advertise with it, and we do not mine the content of your records to build unrelated products.
If you are a worker, supervisor, or administrator using Clenzus because your employer provisioned it for you, your employer — not Clenzus — is the party that decides what is collected about you and why. For most questions or requests about your personal information, you should contact your employer first; we will help your employer respond.
2.2 For our own business information, Clenzus is the controller
For the limited information we collect directly to run Clenzus as a business — such as the details used to create and bill an account, and the security and audit records we keep to protect the platform — Clenzus is the controller, and this policy describes how we handle it. This includes the business contact details of a company's primary administrator(s) — name, work email, and phone number — which we retain so that we can reach that company about its account (for example, for provisioning, support, security, and billing matters). We use these details for account and contact purposes only; we do not use them for advertising, and we do not sell them.
3. What "Clenzus does not see your data" really means
We want to be honest and precise here, because trust matters and because vague promises help no one.
- We do not read the content of your operational records. Clenzus is designed so that the people
who operate the platform do not browse the contents of a company's individual operational records — the descriptions inside tickets and complaints, photos, notes, or site and facility details — in the ordinary course of business. Our platform-wide monitoring of that activity is deliberately limited to aggregate, de-identified numbers — for example, "how many tickets were opened across the platform this week" — and is built so it cannot surface the content inside any specific company's records.
- We never see your password. User passwords are stored only as a one-way cryptographic hash.
No one at Clenzus — including our security staff — can view, retrieve, or read your password. If a password reset is ever performed, it replaces the password with a new one; it does not reveal the existing one.
- Account and identity information is accessed only for security. A small number of authorized
security staff *can*, when there is a specific need, see account-level information — such as a user's name, email address, role, whether an account is active, and account-security details such as a verification PIN — and perform account-security actions such as forcing a password reset or disabling an account. This is not part of day-to-day operation and is never used to read your work. It is reserved strictly for genuine security and account-integrity purposes — for example investigating a suspected breach or account misuse, acting on an authorized request from the platform operator, or protecting the Service and the people who use it. Access of this kind is limited to what is needed and is logged.
- When we access anything else, it is narrow and purposeful. Like any hosted software provider, our
systems and authorized staff *can* technically access stored data when it is genuinely necessary — for example to keep the Service running, to provide support you or your employer request, to fix a defect, to make a lawful backup, or to comply with a legal obligation. We limit that access to what is needed, and we log it.
- Your data belongs to your company, not to us. As between Clenzus and the Customer, the Customer
owns its data. We keep it safe and available to the Customer; we do not treat it as ours.
In short: the reason this information lives in our database at all is so the software can do its job for your company — not so that Clenzus can read it. That is a meaningful and enforceable distinction, and it is how the platform is built.
4. Information stored in, or collected through, Clenzus
Below is the full picture of what may be present in the Service. Where an item is entered or controlled by your employer, we hold it as a processor (Section 2.1). Where an item is collected by us directly, we act as a controller (Section 2.2). We call this out for each category.
4.1 Account and identity information *(entered/controlled by your employer)*
Basic details that let the software recognize a person and give them the right access: name, work email address, phone number, an employee identifier, role, employment date and status, department or position, emergency-contact details, and profile information. Each account has a four-digit access PIN, which the Service generates automatically (users do not choose it) and stores in encrypted form, so it cannot simply be read back. A user's PIN is issued and managed by the people above them in their organization's reporting chain — a manager can regenerate and view the PIN of the users who report to them — and only the company's senior administrators may regenerate their own PIN. A user may instead turn on multi-factor authentication using an authenticator app for stronger sign-in protection; while it is on, the PIN is not required, and if the authenticator is lost an authorized administrator can remove it and re-issue a PIN. This information exists so the right person can log in and see the right things — it is provided under your employer's control, and we do not use it for our own purposes.
4.2 Human-resources and payroll information *(entered/controlled by your employer)*
Where a company chooses to run pay-related workflows in Clenzus, the software may hold pay rate, payroll file numbers and payroll identifiers, earning codes, partial tax identifiers (for example, only the last few digits of a government identification number), tax identifiers, and the codes used to line data up with an outside payroll provider (for example, ADP or Paychex identifiers). Your employer decides whether to use these fields at all and what to put in them. Clenzus stores this so your employer can prepare and reconcile pay accurately; we do not read it for any purpose of our own.
4.3 Location and attendance information *(off unless your employer turns it on — see Section 6)*
When — and only when — a company switches on a location feature, the Service may process location signals to confirm attendance. This is one of the most sensitive areas, so it has its own detailed section below (Section 6, "Location and GPS"). The short version: location is off by default, nothing is tracked or stored while it is off, and when it is on everyone is clearly and continuously notified.
4.4 Photographs and work evidence *(entered/controlled by your employer)*
Photos that users attach to complaints, tickets, inspections, deficiencies, site audits, before/after records, and similar items. These are stored as proof of work — for example, to show a site was serviced properly — and may show the interior or condition of a building. Your employer decides whether and how photos are used.
4.5 Operational records *(entered/controlled by your employer)*
The day-to-day records that make the software useful: schedules and shifts; time and attendance punches; complaints, tickets, deficiencies, equipment issues; inventory and supply requests; site and facility records; points of contact; client and contract records (including contract values and the reasons a contract ended); notifications; and site notes. These are the substance of your company's operations and are controlled by your company.
4.6 Communications *(some to us, some within your company)*
Messages you send to Clenzus (for example, a support request) are handled by us as a controller. Comments and discussion you post inside a record in the Service are operational content controlled by your employer.
4.7 Device, log, and security information *(collected by us to protect the platform)*
To keep accounts and the platform safe, we and our infrastructure providers automatically record a limited set of technical signals: the IP address a request comes from and the city, region, and country derived from it; browser/device information and the last device an account was verified on; and sign-in, session, and account-activity records that form a security audit trail. We use this strictly to protect you and your company — for example, to notice an unusual sign-in by comparing where an account is signing in from against where that person is expected to work, to power multi-factor authentication, and to investigate suspected fraud or account misuse. This is not marketing data, and we do not use it to profile you.
4.8 Usage information *(collected by us to run and improve the Service)*
General information about how the Service is used — which helps us keep it reliable, secure, and better over time. Where possible this is handled in an aggregated form (Section 8).
We do not intentionally collect special-category or "sensitive" personal information beyond the limited payroll identifiers described above, and we ask Customers not to enter sensitive information the Service is not designed to hold.
5. Biometric information — we do not collect it
Some plans offer on-device biometric verification (for example, Face ID or a fingerprint), or a passkey, as a way to confirm that the right person is clocking in. It is important to understand exactly how this works, because biometrics are heavily regulated and often misunderstood:
- The biometric check happens entirely on the user's own device, using the device's own secure
hardware (the same mechanism that unlocks the phone itself).
- Clenzus never collects, receives, stores, or has access to any fingerprint, faceprint, face
geometry, or other biometric identifier. None of it ever leaves the device or reaches our servers.
- All the device tells the Service is a simple yes/no: whether the on-device check succeeded. We
store only that result, not the biometric itself.
Because the biometric never comes to us, Clenzus is not a collector of biometric information, and using this feature does not put your fingerprint or face into our database — it stays with you, on your device, under your control.
6. Location and GPS — how it works, and how we keep it fair
Clenzus is built so companies can prove that field work actually happened — the crew arrived, at the right place, at the right time. Location features exist to serve that legitimate operational need. Because location is sensitive, we designed these features around three firm principles: it is off unless your company deliberately turns it on; you are always told when it is on; and your company chooses the least-intrusive mode that meets its needs.
6.1 Location is off by default — and off means nothing is collected
If your company does not use location — whether because it chooses not to, or because it cannot for legal, labour, or practical reasons — then GPS is simply off. When it is off, the Service does not request your location, does not track you, and does not store any location data at all. There is no hidden collection. No signal is captured "just in case."
6.2 If location is on, everyone is clearly and continuously notified
When a company enables a location feature, the people affected are notified — clearly, and on an ongoing basis while the feature is active — that location is on and which mode is running. This is not buried in fine print: the point is that no one is ever tracked without knowing it, and that your employer (the party that controls this) has told you and obtained any consent the law requires before turning it on.
6.3 The four location modes, explained
Your company selects one of the following modes per site, so tracking is never more than the situation calls for:
- Mode 1 — Off (no location). The default. Attendance is recorded by clock-in and clock-out
only. No coordinates are requested, captured, or stored, ever. This is the most private option.
- Mode 2 — Geofence / radius check. A privacy-minimal "am I at the right place?" check. When a
user clocks in, the Service confirms the device is within the site's set radius. It is used to allow or block the clock-in — it does not save the user's coordinates and does not follow the user anywhere. It answers a single yes/no question at the moment of clock-in.
- Mode 3 — Point-of-action capture (clock-in / clock-out only). The Service records the location
at the exact moment a user clocks in and clocks out — and at no other time. There is no tracking in between. Managers can later see where the clock-in and clock-out happened, as proof of presence, but no one can watch a person move during the shift, because nothing in between is collected.
- Mode 4 — Live location during a shift. For a company's highest-accountability contracts, the
Service can show a user's location on a map while a shift is active, so the team can see that people are where they should be and are safe. This mode captures the most, and is therefore the one that requires the clearest notice and, where applicable, consent — which your employer is responsible for handling before enabling it. Live location is tied to the active shift; it is not a round-the-clock tracker of your personal life.
6.4 Facility coordinates
Separately from tracking people, the Service converts the site addresses your company enters into map coordinates (geocoding), so sites can be placed on a map and used for the geofence check. This is information about places, not people.
6.5 Who is responsible
Whether any location feature is on, which mode is used, and for whom, is entirely your employer's decision, made through its administrators. Clenzus provides the tools and the notices; your employer is the controller and is responsible for the lawful basis, the notice, and any consent required by employment, labour, privacy, or electronic-monitoring law before enabling location tracking.
7. How we use information
We use personal information for the following purposes, and — where we act as a processor — only to provide the Service and only on the Customer's instructions:
- to provide, operate, maintain, and secure the Service;
- to create and manage accounts and enforce role-based access, so each person sees only what they
are permitted to see;
- to record time and attendance and, where the Customer has enabled it, to verify location at
clock-in and enforce a geofence (Section 6);
- to deliver notifications and to enable the in-app records and communications the Service
provides;
- to process pay-related information as directed by the Customer, so the Customer can prepare and
reconcile payroll accurately;
- to protect accounts and the platform — including detecting and investigating unauthorized
access, comparing sign-in location against expected work location, and enforcing multi-factor authentication;
- to provide support and respond to requests from you or your employer;
- to produce aggregated, de-identified statistics and benchmarks used to operate, analyze, and
improve the Service (Section 8); and
- to comply with law and enforce our Terms.
We do not use the content of a Customer's operational records to make decisions about you; those decisions are made by your employer using the tools the Service provides.
8. Aggregated and de-identified information
We create aggregated, de-identified information from use of the Service, and we use it to run, secure, analyze, and improve the product and to produce statistics and benchmarks. "Aggregated and de-identified" means the information has been combined across many sources and stripped of identifiers, so that it does not identify any Customer, worker, client, building, or individual and cannot reasonably be used to do so. As noted in Section 3, our platform-wide monitoring of operational activity works at this aggregate level — surfacing only numbers, never the content of any individual operational record; account-level access is separate and, as described in Section 3, is used only for security and account-integrity purposes. We will not publish aggregated information in any form that identifies anyone. Our right to use aggregated, de-identified information continues even after an account ends.
9. How we share information
We do not sell personal information. We share it only in the limited ways described here:
- Within your own company's organization, according to the roles and access your company's
administrators configure. (This is how the software is supposed to work — a supervisor sees their team, an administrator sees the company, and so on.)
- With service providers ("subprocessors") that host and support the Service under contracts
requiring them to protect the information and to use it only to provide services to us. Our current subprocessors include:
- Supabase — cloud database, authentication, and file storage / hosting;
- Cloudflare R2 (accessed via S3-compatible storage) — storage of uploaded photos and files;
- Resend — delivery of transactional email;
- A geocoding provider (for example, Google) — converting the site addresses your company
enters into map coordinates;
- A payment processor (for example, Stripe) — only if and when paid billing is enabled; Clenzus
does not store full payment-card numbers.
- For legal reasons — to comply with applicable law, to respond to a lawful request from a public
authority, or to protect the rights, property, or safety of Clenzus, our Customers, or others.
- In a business transfer — in connection with a merger, acquisition, financing, or sale of
assets, in which case this policy continues to apply to the information transferred.
A current list of subprocessors is available on request at privacy@clenzus.com.
10. How long we keep information
We keep personal information for as long as it is needed to provide the Service and as directed by the Customer, and after that only for as long as required to comply with law, resolve disputes, and enforce our agreements. A Customer may archive or request deletion of its data. Some information may persist for a limited time in secure backups, or where the law requires us to keep it, and aggregated, de-identified information (Section 8) may be kept indefinitely because it no longer identifies anyone. After an account is terminated, the Customer may request an export of its data within 30 days, after which we may delete or de-identify it, subject to any legal retention requirements.
11. How we protect information
We use technical and organizational safeguards designed to protect personal information, including:
- Encryption in transit, so information is protected as it travels between your device and the
Service, and encryption of sensitive fields at rest (such as PINs), so they cannot simply be read from storage;
- Strict tenant isolation and row-level security, so that one company's data is walled off and
another company cannot reach it;
- Role-based, least-privilege access controls, including the data-minimizing oversight design
described in Section 3, where routine oversight sees only aggregate numbers rather than record content;
- Layered verification for sensitive actions — the most sensitive functions require an additional
identity confirmation beyond an ordinary sign-in, and are available only to a small number of authorized people, never on a casual or open-ended basis;
- Accountable, tamper-resistant access records — when an authorized person accesses account
information for a support or security reason, that access is tied to a specific, recorded purpose and written to a permanent record that is designed so it cannot be altered or deleted, including by us, so every such access can be accounted for afterward;
- Continuous sign-in monitoring — we automatically watch for unusual access patterns, such as a
sign-in from an unexpected location, and flag them for prompt security review.
No method of transmission or storage can be guaranteed to be perfectly secure, and we cannot promise absolute security. You and your company share responsibility by keeping credentials, PINs, and authenticator devices confidential and by removing access promptly when someone leaves.
12. Your privacy rights
Depending on where you live and your relationship to us, you may have rights to access, correct, update, delete, or receive a copy of your personal information, to object to or limit certain processing, and to withdraw consent. Residents of Canada have rights under the federal *Personal Information Protection and Electronic Documents Act* (PIPEDA) and applicable provincial privacy laws. Depending on where you live, you may also have rights under other privacy laws — for example, U.S. state laws such as California's CCPA/CPRA, the EU/UK GDPR, and similar laws in other countries and regions. Where any such law uses terms like the "sale" or "sharing" of personal information, Clenzus does not sell or share your personal information in that sense. As stated throughout, we do not sell personal information.
Because of the controller/processor split (Section 2), where to send a request depends on the information:
- For workforce information held on your employer's behalf (most of what is in Clenzus), please
make your request to your employer (the Customer), who controls it. We will assist your employer in responding.
- For information Clenzus controls directly (account, billing, and security information), contact
us at privacy@clenzus.com. We may need to verify your identity before we act on a request, so that we do not disclose information to the wrong person.
13. International data transfers
Clenzus is based in Canada. The Service and our subprocessors may store and process personal information in Canada, the United States, and other countries where our providers operate. Because Clenzus serves companies worldwide, personal information may be stored and processed wherever our subprocessors operate. Where required, we rely on appropriate safeguards for cross-border transfers. By using the Service, you understand that your information may be processed in these locations, each of which may have data laws different from those in your home jurisdiction.
14. Children
The Service is intended for business use by adults of legal working age and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information through the Service, contact us and we will take steps to delete it.
15. Cookies and similar technologies
The Service uses cookies and local storage that are necessary to sign you in, keep your session active, remember basic preferences, and operate securely. We do not use the Service to serve third-party advertising, and we do not use advertising trackers.
16. Changes to this policy
We may update this policy from time to time as the Service, our providers, or the law evolve. If we make material changes, we will update the effective date above and provide reasonable notice — for example, in the app or by notifying account administrators. Your continued use of the Service after a change takes effect means you accept the updated policy, so we encourage you to review it periodically.
17. Contact us
Questions, requests, or complaints about privacy are welcome:
Clenzus Tel: (204) 517-1777 Email: privacy@clenzus.com