Who We Are

This policy explains how personal data is collected, used, shared, secured and retained across the websites, platform and mobile applications listed above (together, the "Service").
  • FieldTrace is a product of: CodeLogicX Technologies Private Limited
  • Corporate Identity Number: U72300WB2013PTC191145
  • Registered Office: 6th Floor Webel IT Park, BN-9 Sector V, Sech Bhawan, North 24 Parganas, Saltlake, West Bengal, India, 700091
In this policy, "CodeLogicX", "we", "us" and "our" mean CodeLogicX Technologies Private Limited, a private limited company incorporated in India under the Companies Act and registered with the Registrar of Companies, Kolkata.

The Structure

CodeLogicX Technologies Private Limited (the company) → TeamTrace (the platform) → FieldTrace (the field-workforce modules of that platform, marketed and sold as a product)
FieldTrace is presented and sold as a product, but technically it is the field-workforce module set of TeamTrace, which is itself

a CodeLogicX product. Neither TeamTrace nor FieldTrace is a separate company. Wherever you see either name — website, app store listing, invoice, this policy — the legal person behind it is CodeLogicX.

CodeLogicX writes the software, operates the cloud infrastructure, administers the databases, provides support, holds the security certifications, signs your contract and issues your invoice. There is no gap between the entity you contract with and the entity that holds your data, and no ambiguity about who answers if something goes wrong.
Because FieldTrace sits inside TeamTrace, you should also expect that:
  • Sign-up, authentication, user administration and billing run through platform.teamtrace.app, so the TeamTrace name will appear in the interface, in system emails, in card statements and in app store listings even though you bought FieldTrace.
  • FieldTrace and TeamTrace data share one production environment, separated per customer workspace as described in Section 12.
  • The FieldTrace and TeamTrace privacy policies describe the same underlying operations. This one governs the FieldTrace modules.
If you are an employee of an organization that uses FieldTrace, read this alongside your employer's own monitoring, IT, and privacy policies. Those govern what your employer chooses to collect about you.

The Legal Framework We Operate Under

We are an Indian company with customers in India and abroad, so more than one regime can apply to the same processing.
  • India — our home jurisdiction. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, notified on 13 November 2025 and phasing in until substantive obligations become enforceable on 13 May 2027. We are building to those obligations now rather than waiting. Until Section 44(2) of that Act takes effect, Section 43A of the Information Technology Act, 2000 and the SPDI Rules, 2011 also remain in force, so both regimes currently apply to us in parallel. The SPDI Rules treat passwords, financial information, health information and biometric information as sensitive personal data, and require a published privacy policy and a designated Grievance Officer — this document and Section 16 discharge those requirements. Separately, the CERT-In Directions of 28 April 2022 impose incident-reporting and log-retention duties that apply today, independently of the DPDP timetable (Sections 13 and 17).
  • European Union and United Kingdom. Where we offer the Service to organizations or individuals in the EEA or the UK, or process data in connection with monitoring behavior there, the GDPR applies to us extraterritorially under Article 3(2). We act as a processor for EEA and UK customers under Article 28 and have appointed representatives under Article 27 (Section 23).
  • Canada. Where we collect, use or disclose personal information in the course of commercial activity connected with Canada, PIPEDA applies, along with provincial private-sector laws where relevant — Quebec's Law 25 and the Alberta and British Columbia Personal Information Protection Acts.
  • Employment law. Worker monitoring is regulated by employment law as well as privacy law, and those rules vary. Section 19 sets out what that means for organizations deploying FieldTrace.
If we are designated a Significant Data Fiduciary under Section 10 of the DPDP Act, we will appoint an India-based Data Protection Officer, carry out annual impact assessments and independent data audits, and publish the DPO's details here.

Definitions

  • You — the individual using or affected by the Service: an account administrator, a manager, a field employee, a website visitor or a prospective customer. Also called the Data Principal (DPDP Act) or Data Subject (GDPR).
  • Customer / Organization / Employer — the body that subscribes to FieldTrace and creates a workspace for its workforce. If you use FieldTrace because your employer told you to, your employer is the Customer.
  • Workforce Data — personal data about a Customer's employees, contractors or field agents held in that Customer's workspace: location trails, attendance records, visit and call logs, tasks, orders, leads, expenses, form submissions, photographs and biometric verification data.
  • Account Data — data we process to run our own business: administrator and billing contacts, subscription and invoicing records, support correspondence, website and marketing enquiries.
  • Usage Data — technical and behavioral data generated automatically in use: logs, IP address, device and operating-system details, crash reports, interaction events, performance metrics.
  • Data Fiduciary / Data Controller — the entity that decides why and how personal data is processed.
  • Data Processor — a processor engaged by a processor.
  • Sub-processor — an entity that processes it on a Fiduciary's instructions.
  • Sensitive Personal Data — the categories treated as sensitive under the SPDI Rules, and special-category data under Article 9 of the GDPR.

Our Two Roles

FieldTrace is a business software, and we handle two categories of data in two different capacities. Which one applies determines where you send a request.
  • For Workforce Data, the Customer is the Data Fiduciary, and we are only the Data Processor. The organization deploying FieldTrace decides whether to use it, which modules to switch on, who is tracked and when, what is retained and for how long, who internally can see whose records, and what employment consequences follow. We process that data to provide, secure, support and maintain the Service under our agreement with that Customer, and for no independent purpose of our own. We do not decide what an employer monitors, and we do not evaluate employees. The Customer's own legal duties are set out in Section 19. Where to send an employee request is covered in Section 15.4.
  • For Account Data, Usage Data and website data we are the Data Fiduciary. That covers administrator and billing records, subscription, invoicing and tax records, support tickets and feedback, website enquiries, demo requests, trial sign-ups and marketing contacts, the security and audit logs we generate to keep the Service safe, and aggregated, de-identified telemetry we use to diagnose faults and improve the product.
  • When our personnel can access a workspace. Only on a Customer's request (for example a support ticket that cannot be resolved without reproducing the issue), for fault diagnosis or platform-integrity investigation that cannot be done from logs and metadata alone or where required by law under Section 11.3. Such access is role-based, limited to named authorized personnel, granted for the minimum period necessary, and logged for audit. We do not browse Customer data.

What FieldTrace Does, and What It Collects

FieldTrace manages field workforces — sales teams, distributors' field forces, service and installation technicians, delivery staff, surveyors. Its modules cover GPS location tracking and route recording, geo-fenced and optionally face-verified attendance, shifts and leave, customer visit and call logging, task, order and lead management, beat planning and route optimization, configurable alerts and geo-fencing, and expense capture and custom forms. Not every module is enabled for every Customer, so what is collected and given individual depends on what that person's employer has switched on.
These are categories, not an exhaustive field inventory; Customers can build custom forms whose contents we do not control.
  • Identity and account. Name, work email and phone, employee identifier, job title, role and reporting line, department, team, branch or territory, profile photograph, skill sets and, where the HR module is used, employment history recorded by the Customer, credentials in hashed form, authentication and session records, language and notification preferences.
  • Location. GPS coordinates with timestamps and accuracy radius, derived route trails, distance, stop and idle detection, geofence entry and exit, check-in and check-out locations, location-tagging of visits, orders, expenses and forms, and device-integrity signals used to detect location spoofing. Collected only for individuals whose employer has enabled location features, and only during configured periods — see Section 7.
  • Attendance, biometrics, and photograph. Clock-in and clock-out times, break and idle duration, shift and roster assignment, leave and absence records, attendance selfies where photo- verified attendance is enabled, and, where face-verified attendance is enabled, a mathematical facial template — see Section 8.
  • Work activity. Tasks with timestamps and progress, visits with arrival, departure and outcome, calls and dispositions, orders and leads with pipeline stage, beat plans and adherence, expense and receipt images, custom form submissions.
  • Files and documents. Reports, PDFs, receipts, site or delivery photographs, signed proofs of delivery and similar work documents that users upload. Customers control what is uploaded, and we ask them not to put sensitive or special-category data into general-purpose fields or attachments unless it is necessary and lawful.
  • Device and technical. IP address, device make, model and identifiers (Android ID, Apple identifier for vendors), OS version, app version and build, mobile network and connection type, battery and charging state where relevant to location reliability, time zone and locale, permission states, website referrer and campaign data.
  • Diagnostics and usage. Crash reports and stack traces, error logs, API request logs, load times, feature-usage events, session duration. Used for debugging, capacity planning, security monitoring and product improvement, in aggregated or de-identified form where feasible.
  • Communications. Support tickets, chat transcripts, emails and call notes, onboarding and training records, feedback and survey responses, correspondence with our privacy and security teams.
  • Commercial and billing. Company details, billing contact and address, tax identifiers including GSTIN where applicable, plan, seat count and renewal dates, invoices and payment status. We do not store full payment-card numbers — card data goes directly to our payment gateways.
  • Website and marketing. Contact, demo, pricing and trial request form submissions, newsletter subscriptions, event registrations, cookie data as described in Section 18.
What we do not collect. Aadhaar or other national identity numbers, PANs except where required for tax invoicing of a business, health records, biometric data other than the facial templates described above, bank or card numbers, anything about your personal social media or private messaging. FieldTrace does not log keystrokes, capture screenshots, record screens, or record call audio. Where a Customer's custom fields or uploads introduce data of these kinds, the Customer is responsible for ensuring that is lawful.

Why We Process Your Data, and Our Legal Basis

PurposeOur roleLegal basis
Providing the Service to a Customer's workforce: tracking, attendance, tasks, visits, orders, expenses, reportingProcessorThe Customer's lawful basis, as the Customer determines — see Section 9.2
Creating, administering and securing accountsFiduciaryPerformance of contract; legitimate interests in securing the Service
Billing, invoicing, GST and statutory accountingFiduciaryPerformance of contract; legal obligation
Customer support and incident responseProcessor or Fiduciary as applicablePerformance of contract; legitimate interests
Platform security, fraud prevention, abuse detection, audit loggingFiduciaryLegitimate interests; our security obligations under the instruments in Section 2
Diagnosing faults and improving the productFiduciaryLegitimate interests
Marketing to businesses and prospectsFiduciaryConsent where required, including for electronic messages under the DPDP Act, Indian telecom regulations and Canadian anti-spam law; otherwise legitimate interests, with an opt-out in every message
Responding to lawful requests, exercising or defending legal claimsFiduciaryLegal obligation; legitimate interests
We do not sell or rent personal data, we do not use it for behavioral advertising, and we do not share Workforce Data with data brokers. Our position on AI training is in Section 10.

Location data

Location is the most sensitive thing the FieldTrace handles day to day.
  • Before collection starts. The app shows a prominent in-app disclosure explaining what location data is collected, why and how it is used, immediately before the operating system permission prompt — in normal use of the app. The permission prompt then requires an affirmative action. Where background or "always" location is used, that is disclosed separately and specifically: FieldTrace collects location data to enable field tracking, geo-fenced attendance, visit verification and route recording even when the app is closed or not in use, for users whose employer has enabled these features. You can withdraw these permissions at any time in device settings. Doing so stops collection and disables location-dependent features, and your employer will be able to see that location data is unavailable. Declining is a valid choice at the app level. What it means for your employment is between you and your employer.
  • Working hours and off-duty time. FieldTrace supports shift-bound tracking: collection can be restricted to configured working hours, roster windows or an explicit on-duty toggle, and suspended outside them. Whether that restriction is applied is the Customer's decision. We recommend shift-bound configuration as the default, and our documentation says so.
  • Visible while active. Whenever field tracking is running, the app shows a persistent indicator, and on Android a persistent foreground-service notification, so the person being tracked can see it is active. FieldTrace has no covert or invisible field-location mode.
  • Integrity signals. To make records reliable, the app detects mock-location apps, developer settings, emulator characteristics, and device root or jailbreak status. These relate to the device, are used only for data integrity and fraud prevention, and surface to the Customer as exceptions.
  • Precision and derived data. Location is sampled at intervals and accuracy levels, balancing usefulness against battery and data consumption. Route trails, distances, stop durations and geofence events are derived from raw points. Retention is covered in Section 14.
  • Quebec (Canada). FieldTrace uses technology that can identify, locate and profile you within the meaning of Law 25. This section and the in-app disclosures constitute notice of that use. The functions can be deactivated by withdrawing the device's permissions.

Face Verification and Biometric Data

Where a Customer enables face-verified attendance, we generate a mathematical template from a facial image at enrollment and compare later check-in images against it. The template confirms only that the enrolled person is present. It is not matched against any external database, not shared with other Customers, and not used for emotion, demographic or behavioral inference. Templates are stored encrypted and logically separated from other profile data, with access restricted to the systems performing the comparison.
Facial-recognition data is sensitive personal data under the SPDI Rules — which require consent in writing, including by electronic means, before collection — and special-category data under Article 9 of the GDPR, where the Customer must establish a valid Article 9 condition, normally explicit consent or an authorizing provision of employment law. Our platform records an affirmative in-app enrollment acknowledgement to support this.
A meaningful alternative must be offered. Attendance can be verified without face recognition — geofenced check-in with a selfie, or supervisor confirmation — and we require Customers to make a non-biometric route available, without detriment, to any employee who does not agree to biometric verification.
In Quebec (Canada), the Customer must declare the biometric database to the Commission d'accès à l'information before bringing it into service (Section 19). We will supply the technical detail needed for that.
Templates and enrollment images are deleted as set out in Section 14.

Consent

9.1 Consent We Obtain

Where we rely on consent as Data Fiduciary — marketing email, non-essential cookies, optional product research — we ask through a clear, specific, informed and unambiguous affirmative action: a tick box, a toggle, an "I agree" button. Silence, inactivity, pre-ticked boxes, and continued browsing are not consent for those purposes. As the DPDP Act requires, we will make the notice available in English and in the other languages of the Eighth Schedule to the Constitution of India on request.
You can withdraw consent at any time — via the unsubscribe link in any marketing email, the cookie preference control on our website, your device settings for app permissions, or by writing to support@teamtrace.app. Withdrawal takes effect prospectively. It does not make earlier lawful processing unlawful, and it does not affect processing carried out on another basis, such as retaining invoices for tax.

9.2 The Basis for Processing Workforce Data

The employer, not CodeLogicX, is responsible for establishing a lawful basis for monitoring its workforce, and for obtaining consent where consent is the basis it relies on. We supply the notices, disclosures, configuration controls and audit records that let an employer do this properly, and our contracts require it.
In India, Section 7(i) of the DPDP Act permits an employer to process employee data for purposes of employment, or to safeguard itself from loss or liability, as a "legitimate use" — that is, without separate consent. Whether a given monitoring activity falls within that provision, and whether consent would nonetheless be more appropriate, is the employer's determination as Data Fiduciary. Where a Customer relies on consent instead, our platform supports a recorded, affirmative in-app acknowledgement at first log-in and on material change.
More broadly, consent given by an employee to an employer is often not freely given in the way data-protection law requires. That is why our contracts require Customers to assess necessity and proportionality rather than treat a tick box as sufficient.

Automated Processing, Analytics and AI

FieldTrace produces scores, rankings, exception flags, route suggestions and productivity analytics. These are decision-support outputs shown to the Customer's managers. FieldTrace takes no employment decisions, and we make no decisions about you. We do not carry out solely automated decision-making producing legal or similarly significant effects. Where a Customer uses FieldTrace outputs to inform decisions about pay, discipline, promotion or termination, that Customer is responsible for meaningful human review and for its own obligations under Article 22 of the GDPR, the Law 25 automated-decision notice requirements and equivalent laws. On request we will tell a Customer what inputs a score or flag derives from, so it can explain the output to its workforce.
AI and machine-learning features — route optimization, receipt OCR, anomaly detection — operate on the data in the Customer's own workspace to produce results for that Customer. We do not use Customer workspace content to train general-purpose AI or large language models, and we do not make it available to third parties to do so. Where a third-party AI or OCR service delivers a specific feature as a sub-processor, it is contractually barred from retaining or training on the data.
We may use aggregated, de-identified statistics derived from usage to improve performance and publish benchmarks. These identify no individual, Customer or workspace data cannot be reversed to do so.

Disclosure

11.1 Sub-Processors

We share personal data with a limited set of vendors that help us operate the Service. Each is bound by a written agreement imposing confidentiality, security, purpose limitation, breach notification and deletion obligations — and, where the SPDI Rules apply to the transfer, a requirement to maintain the same level of protection required of us.
CategoryPurposePrimary location
Cloud infrastructure — Amazon Web ServicesCompute, storage, database, backup, content deliveryIndia (primary)
Email, SMS and push notification providersService notifications, alerts, password resetsIndia, US, EU
Payment gatewaysSubscription billing and collectionIndia; varies by method
Product analytics, crash and error monitoringStability and performance diagnosticsIndia, US, EU
Support desk and ticketingHandling support requestsIndia, US
Mapping and geocodingMaps, address lookup, route calculationVaries
Optical character recognitionReading receipts and forms where enabledIndia, US
Professional advisers and auditorsLegal, accounting, tax, certification and audit, under professional confidentialityIndia
An itemized register naming each vendor is available to Customers from support@teamtrace.app and forms an annex to our Data Processing Agreement. Customers on that agreement get advance notice of new or replacement sub-processors and may object on reasonable grounds.

11.2 Within the Customer's Organization

Workforce Data is visible to the users the Customer authorizes — typically the reporting manager, field-operations administrators, HR and workspace administrators — under role-based permissions the Customer configures, not us.

11.3 Legal and Regulatory Disclosure

We may disclose personal data where legally required: a court order, warrant, summons, statutory demand or binding request from a competent law-enforcement, tax or regulatory authority, compliance with a legal obligation, or establishing, exercising or defending legal claims. Our practice is to require that requests be in writing under valid legal authority and served on our designated contact, to challenge or narrow requests that are overbroad, defective or unlawful, to disclose only the minimum within scope, and to notify the affected Customer so it can protect its own interests, unless legally prohibited or there is an imminent risk to life or safety.

11.4 Corporate Transactions

In a merger, acquisition, financing, reorganization or sale of assets, personal data may be disclosed to the counterparty and its advisers under confidentiality obligations, and where required, through a de-identified or restricted-access diligence process. If such a transaction completes and the handling of your data would materially change, we will notify affected Customers, and affected individuals where required, before any change takes effect.

Where Data is Stored, and Cross-Border Transfers

The Service is hosted primarily in the AWS Asia Pacific (Mumbai) region (ap-south-1) in India, and accessed for engineering, operations and support from India. Customer workspaces share that production environment and are separated logically by tenant-scoped authorization at the application layer, as described in Section 13. A limited number of ancillary services in Section 11.1 process data elsewhere, including the United States and the European Union. Enterprise Customers with specific residency requirements should contact sales@teamtrace.app.
Because we are an Indian company hosting in India, most personal data we process is not transferred out of India at all.
  • Transfers into India If your organization is outside India, your data will be transferred to India where you use the Service. While personal data sits in or is accessed from a country, it is subject to that country's laws, including laws that let courts, law enforcement and regulators there compel disclosure — true of India, and equally of Canada, the United States and the EU. Safeguards reduce risk and no contract excludes local law.
  • EEA and UK. India has no European Commission adequacy decision, so transfers rely on the Standard Contractual Clauses (Module Two for controller-to-processor, Module Three where we act for another processor) and the UK International Data Transfer Addendum, supported by a transfer impact assessment we will share on request. Our Data Processing Agreement incorporates these.
  • Canada. Under PIPEDA's accountability principle, an organization stays responsible for personal information transferred for processing and must use contractual means to secure comparable protection. We process to that standard, and this is our disclosure that personal information will be processed outside Canada, in India, where Indian authorities may compel access under Indian law.
  • Quebec. A privacy impact assessment is required before communicating personal information outside of Quebec. We conduct our own where we act as Data Fiduciary, and supply Customers with what they need for theirs.
  • Transfers out of India are made in accordance with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, and we transfer to no country restricted by Central Government notification — if such a restriction is notified for a jurisdiction we use, we will re-route the affected processing. Under Rule 7 of the SPDI Rules, sensitive personal data goes to another body corporate, in India or abroad, only where that recipient maintains the level of protection required of us and the transfer is necessary for a lawful contract or has been consented to.

Security

Security accountability and security operations sit in the same company.

13.1 Certifications

CodeLogicX holds ISO/IEC 27001 for information security management and ISO 9001 for quality management, with a certified scope covering the software development, product engineering and managed-operations activities in which FieldTrace is built, deployed, hosted and supported.
This carries statutory weight in India. Rule 8 of the SPDI Rules names IS/ISO/IEC 27001 as a standard satisfying the "reasonable security practices and procedures" required under Section 43A of the IT Act, where the implementation is certified by an independent auditor. Certification is nonetheless an assurance about a management system, not a guarantee that no incident can occur, and we do not present it as one.
Certificate numbers, the accredited certification body, the scope statement and validity dates are available from support@teamtrace.app and accompany our security questionnaire responses as standard.

13.2 Controls

  • Encryption — TLS 1.2 or above with strong cipher suites in transit, AES-256 at rest, passwords stored only as salted one-way hashes, additional application-layer protection for facial templates and other sensitive fields.
  • Access control — need-to-know and least privilege, tied to a named individual, approved through a documented process, reviewed periodically and revoked promptly on role change or departure. Multi-factor authentication for administrative access. Customers control access inside their workspace through role-based permissions, enforced password policies and session controls.
  • Segregation — tenant-scoped authorization at the application layer separates Customer workspaces; production, staging and development environments are separated, and personal data is not used in development or test except masked or synthetic.
  • Logging and monitoring — access to and modification of personal data is logged and monitored for anomalies. Security logs are retained at least twelve months per Rule 6 of the DPDP Rules. ICT system logs are maintained for a rolling 180 days within Indian jurisdiction as the CERT-In Directions require. It is kept longer where an investigation demands it.
  • Secure development — change management, peer review, dependency and vulnerability scanning, separation of duties for production deployment, within the certified ISMS.
  • Testing and assurance — periodic vulnerability assessment and penetration testing with remediation tracked to closure, internal audit and management review under ISO/IEC 27001. Summary results are available under the NDA.
  • Resilience — encrypted automated backups, defined recovery objectives, periodic restoration testing.
  • People — background verification where lawful, confidentiality agreements surviving employment, and mandatory security and privacy training for everyone with access to personal data.
  • Incident response — a documented plan with named roles, escalation paths, forensic preservation and notification workflows covering the CERT-In and DPDP Board channels separately, exercised periodically.
We do not claim the Service cannot be breached. But we do claim that we take reasonable and appropriate measures, review them, and will tell you promptly if something goes wrong. Report suspected vulnerabilities to support@teamtrace.app. We will acknowledge and will not pursue action against good-faith research within the scope of our responsible disclosure guidance.

Retention and Deletion

We keep personal data only as long as the purpose requires or the law demands. Rule 8 of the DPDP Rules requires erasure once the purpose is no longer served. Customers configure retention within the ranges we support, and these defaults apply where they have not.
DataDefault retention
Raw GPS points and route trails12 months, configurable 3 – 24 months
Aggregated location summariesDuration of subscription
Attendance, timesheet and leave records36 months, or longer where payroll, labour or tax law requires
Facial templates and enrollment imagesWhile the employee is active, then deleted within 90 days of deactivation or the feature being switched off
Attendance selfies and check-in photographs12 months
Tasks, visits, calls, orders, leads, expenses, form submissionsDuration of subscription
Uploaded files and documentsDuration of subscription, unless deleted earlier by the Customer
ICT system logs180 days
Security and access audit logs12 months minimum, up to 24
Support tickets and correspondence24 months from closure
Books of account, invoices, tax recordsUp to 8 years, per Indian company and tax law
Records of personal data breachesAt least 24 months from confirmation
Website enquiry and marketing contacts24 months from last interaction, or until you unsubscribe
On termination, a Customer may export its data during a 30-day grace period. Workspace data is then deleted from production within 90 days and purged from encrypted backups within a further 35 days, except where law requires retention.
When a worker leaves. Deactivating a user stops all collection about that person immediately. Their existing records stay in the Customer's workspace under the retention periods above until the Customer deletes them or those periods expire, because an employer commonly needs attendance and expense history for payroll, statutory or audit purposes after someone leaves. Facial templates are the exception and are deleted on the timetable above.
Inactive trial and unpaid accounts are flagged for deletion after 12 consecutive months, with 30 days' notice to the registered email address.
Deletion requests. Where we hold the data as Data Fiduciary, we will delete it unless we must keep it for a legal obligation, a dispute or enforcement of an agreement — in which case we will say which exception applies. Requests concerning Workforce Data go to your employer (Section 15.4). Deletion removes data from live systems and revokes access. Because backups are encrypted, immutable and rotated on a schedule, residual copies may persist for the periods above before being overwritten. Aggregated data no longer linkable to an individual may be retained indefinitely.

Your Rights

15.1 What You Can Ask For

Subject to applicable law and identity verification: access to confirmation and a summary of your data, purposes, categories, recipients and retention; correction of inaccurate or incomplete data; erasure where no lawful basis or overriding obligation to retain applies, including de-indexation under Law 25; restriction or objection where processing rests on legitimate interests, or while an objection or accuracy dispute is resolved; portability of computerized data you provided, in a structured commonly used format; withdrawal of consent (Section 9.1); not to be subject to solely automated decision with legal or similarly significant effects; nomination of another individual to exercise your rights on your death or incapacity, under Section 14 of the DPDP Act; and to complain to us or to a regulator (Section 16.2).

15.2 How to Ask

Write to support@teamtrace.app with enough detail to identify the account or workspace and describe what you want. We will verify your identity, normally by confirming control of the registered email address, before acting — disclosing data to the wrong person is itself a breach. No fee applies unless a request is manifestly unfounded, excessive or repetitive, and we will tell you before charging one.

15.3 How Long We Take

FrameworkOur commitment
Acknowledgement of any request or grievance48 hours
DPDP Act, 2023 (India)15 business days, or less if the Rules prescribe
SPDI Rules, 2011 (India)Grievances within one month of receipt, per Rule 5(9) — we aim to be considerably faster
GDPR (EU / UK)One month, extendable by two for complex requests, with notice
PIPEDA (Canada)30 days, with any permitted extension and its reason notified to you
Quebec Law 2530 days

15.4 If You Are an Employee

Where your request concerns Workforce Data, we hold it as a processor and cannot grant access, correction or deletion without the employer's instruction. Doing so would override the Data Fiduciary's decisions about its own records.
  • Send the request to your employer through its internal privacy, HR or grievance channel.
  • If you cannot find the right channel of your employer does not respond, write to grievance@teamtrace.app. We will forward it to the workspace administrator within 5 business days, confirm to you that we have, and help the employer fulfil it.
  • If you believe the monitoring itself is unlawful, complain directly to the regulator in Section 16.2 or, in Ontario, to the Ministry of Labour about the policy requirement in Section 19. You do not need our permission, and we will not restrict your account for complaining.

Grievances and Escalation

16.1 Our Grievance Officer

Designated under the SPDI Rules and required in the DPDP Act:
Grievance Officer / Privacy Compliance Officer —
  • Name: Anjishnu Pramanick
  • Email: grievance@teamtrace.app
  • Registered Office: 6th Floor Webel IT Park, BN-9 Sector V, Sech Bhawan, North 24 Parganas, Saltlake, West Bengal, India, 700091.
Timelines are in Section 15.3. If we need longer than stated, we will tell you why and give you a date.

16.2 Regulators

  • India: the Data Protection Board of India under the DPDP Act, once its complaint mechanisms are operational — escalate there if we do not resolve your complaint to your satisfaction or you believe your rights have been contravened. We will cooperate fully with any inquiry. Complaints concerning sensitive personal data may also be pursued under Section 43A of the IT Act through the Adjudicating Officer of the relevant State.
  • EU: the data protection authority of your country of residence or work, or our Article 27 representative (Section 23).
  • UK: the Information Commissioner's Office.
  • Canada: the Office of the Privacy Commissioner of Canada.
  • Quebec: the Commission d'accès à l'information.
  • Alberta and British Columbia: the respective Offices of the Information and Privacy Commissioner.

Personal Data Breaches

On detection, we contain the incident and assess its nature, the categories and volume of data involved, who is affected, and the likely consequences.
Where we act as processor, we notify the affected Customer without undue delay and in any event within 24 hours of becoming aware and support that Customer's notifications to regulators and its workforce. The Customer, as Data Fiduciary, decides on and issues those notifications.
Where we act as Data Fiduciary, we notify the applicable law requires. A single incident can trigger several clocks at once, on separate channels:
RegimeObligation
CERT-In (India)Qualifying cyber incidents reported within 6 hours of being noticed
DPDP Act and Rules (India)The Data Protection Board informed without delay, prescribed detailed report within 72 hours (or longer if the Board allows), and every affected Data Principal notified in plain language. No severity threshold.
GDPR (EU / UK)Supervisory authority within 72 hours where the breach is likely to risk individuals' rights and freedoms; affected individuals without undue delay where the risk is high
PIPEDA (Canada)Privacy Commissioner and affected individuals as soon as feasible once a real risk of significant harm is determined, plus any organization that could reduce the harm. Records of every breach kept at least 24 months regardless of threshold
Quebec Law 25Commission d'accès à l'information and affected individuals where a confidentiality incident presents a risk of serious injury; incident register maintained
Notifications describe what happened and when, what data was involved, likely consequences, what we have done and are doing, what you can do to protect yourself, and how to reach us. Afterwards we conduct a root-cause analysis and remediate. We will not use legal or contractual mechanisms to stop you being told about an incident that affects you.

Cookies

  • Strictly necessary — session and authentication cookies, security tokens, load balancing, CSRF protection. Required for the Service to work and cannot be switched off; session cookies expire when you close your browser or log out.
  • Functional — language, region, time zone and interface preferences.
  • Analytics and performance — which features and pages are used, and error diagnosis. Aggregated where feasible.
  • Marketing — campaign effectiveness on our public website. We see no advertising or behavioral-tracking cookies inside the authenticated platform or the mobile apps.
Non-essential cookies are set only after you consent through our banner, and you can change or withdraw that at any time through the cookie preference control. Browser-level blocking also works, though it may affect functionality. We honor Global Privacy Control signals where our website receives them. Our Cookie Notice lists each cookie, its purpose, provider and duration.

Responsibilities of Organizations that Deploy FieldTrace

We provide powerful monitoring tools. Using them lawfully is the Customer's responsibility, and our agreements require it.
  • Everywhere: document a lawful basis for each monitoring activity and assess whether it is necessary and proportionate, collecting the least data that achieves the purpose. Tell your workforce what is monitored, how, when, why, who sees it and how long it is kept — before monitoring starts, and again when practices change. Configure working hours limits, retention and role-based access to match your policy. Offer and honor a non-biometric alternative where face verification is enabled. Handle your employees' rights requests and give them an internal route to raise concerns. Complete a data protection impact assessment where required — under the GDPR this will usually be required for systematic location monitoring and for biometric processing — and a Law 25 privacy impact assessment for the system and for any communication outside Quebec. Do not use FieldTrace to monitor anyone under 18, or anyone who is not your worker.
  • India: decide whether you rely on consent or on the Section 7(i) legitimate use, publish the required notice, obtain consent in writing for sensitive personal data while the SPDI Rules remain in force, designate someone to answer data-principal queries, and meet your own breach-notification duties.
  • Ontario: employers with 25 or more employees on 1 January must have a written electronic-monitoring policy in place before 1 March of that year — stating whether, how and in what circumstances employees are monitored electronically and the purposes the information may be used for — and must give every employee a copy. A transparency obligation under Part XI.1 of the Employment Standards Act, 2000, enforced by the Ministry of Labor.
  • Quebec: inform individuals of technology that identifies, locates or profiles them and of how to deactivate those functions; declare any biometric database to the Commission d'accès à l'information before use; and designate a person responsible for the protection of personal information.
  • Alberta and British Columbia: meet the notice and reasonableness requirements for employee personal information under the applicable Personal Information Protection Act.
  • EU / UK: establish an Article 6 basis and an Article 9 condition for biometric data; complete a DPIA; consult works councils or employee representatives where required, and maintain records of processing.
We supply the documentation, configuration options, notices and audit records you need, and will sign a Data Processing Agreement incorporating the Standard Contractual Clauses where applicable. What we cannot do is make those judgements for you.

Children's Data

FieldTrace is a business software for adults in employment, intended solely for individuals aged 18 or over. It is not directed at children, and we do not knowingly collect data from anyone under 18. Because the Service performs location tracking and behavioural monitoring, we take it from position: it must not be used to track or monitor a minor. Section 9(3) of the DPDP Act prohibits tracking, behavioural monitoring and targeted advertising directed at children, and comparable restrictions exist elsewhere. Our Terms and Conditions for Customers strictly require them to not in law use it is not permitted for monitoring.
If we learn we hold data of a person under 18 we will delete it promptly, and where it sits in a Customer workspace, require the Customer to remove the user. Report concerns to grievance@teamtrace.app.

Third-Party Integrations and Links

Where a Customer connects FieldTrace to another system — CRM, HR or payroll, ERP, messaging — data flows between the two under the Customer's instruction, and on the third party's own privacy terms govern what it does with that data. We are not responsible for third-party systems a Customer chooses to connect, and recommend reviewing those terms first. Our website and emails may link to third-party sites with their own policies, which we do not control.

Changes to this Policy

We review this policy at least annually and update it when our practices, our vendors or the law change — and Indian data protection law is changing on a known timetable through May 2027, so expect updates. The current version is always published at www.fieldtrace.ai, linked from our app store listings and available inside the mobile applications. When we update it, we revise the "Last updated" date and keep the previous version available on request. For material changes — a new purpose, a new category of data, a new class of recipient, a change of hosting jurisdiction, or any reduction in your rights — we notify account administrators by email and in-product at least 30 days before the change takes effect and obtain consent first where the new processing requires it.
Continued use after a non-material update signifies acceptance. We will not treat continued use as consent where the law requires an affirmative act.

Contact

ForContact
Privacy matters and rights requestssupport@teamtrace.app
Grievances (see Section 16.1)grievance@teamtrace.app
Security and vulnerability reportssupport@teamtrace.app
Product supportsupport@teamtrace.app
Sales and data-residency enquiriessales@teamtrace.app
CodeLogicX Technologies Private Limited · CIN U72300WB2013PTC191145
Registered Office: 6th Floor Webel IT Park, BN-9 Sector V, Sech Bhawan, North 24 Parganas, Saltlake, West Bengal, India, 700091