Privacy Policy
Last updated: [publication date]
1. Who processes your data
The itrackflow.com website and the iTrackFlow app (app.itrackflow.com) are operated by info2K, Lda, [registered office], tax number [NIPC] ("info2K", "we"). You can contact us about privacy at info@itrackflow.com.
info2K acts in two different roles:
- Controller of the website data, contact requests and the account data needed to provide and manage the service (sign-up, authentication, security, the business relationship with the customer).
- Processor, under Article 28 GDPR, of the data each customer organisation enters in its workspace (tracked time, projects, clients, time off, expenses and their attachments). For that data the controller is the customer organisation, which decides what is recorded and about whom. Requests about that data should first be addressed to the organisation you work for.
[State whether a data protection officer has been appointed; in principle not mandatory for info2K's activity, to be confirmed.]
2. What data we process
On the itrackflow.com website
- Web server technical logs: IP address, date and time, requested page, response code and browser identification, generated automatically by the server on every visit.
- Messages you send us by email: your address and the content of the message.
The website uses no cookies, analytics, advertising or third-party content. Fonts and images are served by the website itself.
In the iTrackFlow app
- Account data: name, email address, password (stored only as an Argon2id hash), time zone, preferred language and, if you turn on two-factor authentication, the TOTP key (stored encrypted).
- Security data: authentication events (successful or failed sign-ins, lockouts, password changes) with the source IP address, and the audit log of relevant changes (approvals, access, roles).
- Workspace content, entered by the organisation and its members: time entries and descriptions, projects, tasks, clients, tags, time-off requests, expenses and attached receipts.
Time-off requests may have the type "sick". Recording an absence as sick leave may count as health data. The app neither asks for nor needs any medical information, and we recommend not entering it in the notes. [Confirm the legal treatment with the lawyer.]
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing the account, providing the contracted service and sending the emails it needs (confirmation code, invitations, password recovery, approval notifications) | Performance of a contract — Art. 6(1)(b) |
| Protecting the service and accounts (attempt limits, lockout, audit log, server logs) | Legitimate interest in security — Art. 6(1)(f) |
| Answering contact and sales enquiries | Pre-contractual steps or legitimate interest — Art. 6(1)(b) and (f) |
| Complying with legal obligations, namely tax and accounting ones, once there is invoicing | Legal obligation — Art. 6(1)(c) |
| Processing workspace content on behalf of customer organisations | Customer instructions, under the processing agreement — Art. 28 |
We do not use the data for advertising, we do not sell it and we do not make automated decisions with legal effects on people.
4. How long we keep it
- Account: for as long as the account exists. A sign-up awaiting confirmation is deleted 24 hours after the last code was sent.
- Workspace: while the contract is in force. A disabled workspace is permanently deleted [15] days later. The organisation can also set a period after which data from earlier years is proposed for deletion.
- Audit log and security events: 90 days by default; the organisation can set another limit for its workspace.
- Single-use codes and links: email confirmation code, 15 minutes; password recovery, 1 hour; invitations, 7 days.
- Web server logs: [period to be set; IIS does not delete them automatically today].
- Backups: configuration files, 14 days; database, [period to be set]. Deleted data disappears from backups as they expire.
- Contact emails: for as long as needed to answer and follow up the request, [maximum period to be set].
5. Who we share it with
The data is only accessible to info2K staff who need it to provide the service and to the following providers, acting as our processors:
- Hosting: a server managed by info2K, located in [place/country].
- Email delivery: GoDaddy [contracting entity and server location to be confirmed; if this involves a transfer outside the EEA, state the applicable mechanism].
- Off-site backups: [provider and location].
- Payments: once paid subscriptions are available, payments will be processed by Stripe; info2K neither receives nor stores card data. [Review when invoicing is turned on.]
Within a workspace, the data you record is visible to other people in the same organisation according to their role (for example, approvers see the hours submitted to them).
6. Security
Among other measures, we use encrypted connections (HTTPS), passwords stored with Argon2id, optional two-factor authentication, lockout after failed attempts, sessions with a maximum length that are revoked when the password changes, secrets encrypted at rest, data separated by workspace, database accounts with least privilege, an audit log and verified backups.
7. Your rights
You have the right to ask for access to your data, its rectification or erasure, restriction of processing, portability, and to object to processing based on legitimate interest. For account data, write to info@itrackflow.com; we reply within one month. Much of the data can be corrected directly in the app profile.
For workspace data, address the request to the organisation you work for, which is the controller of that data. If you contact us directly, we forward the request to that organisation.
You also have the right to lodge a complaint with the Portuguese data protection authority, CNPD (www.cnpd.pt), or with the authority of your EU country of residence.
8. Cookies and browser storage
The website uses no cookies. The app keeps in the browser's local storage only what it strictly needs to work: the signed-in session, the chosen language and a few display preferences (for example, the last entry mode or favourite projects). This information is not used to track your activity; the session is removed when you sign out, and everything is removed when you clear the browser's data.
9. Changes to this policy
We may update this policy when the service or the law changes. The date of the last update is at the top of the page, and relevant changes will be announced to customers by email or in the app.
