Legal
Privacy Policy
How Orgix — an enterprise HRIS, CRM, and Field Force platform — handles personal and business data.
Orgix is a multi-tenant B2B SaaS used by organizations to run people operations, sales pipelines, and field execution. Most workplace data is controlled by the customer organization that subscribes to Orgix. We process that data to provide the service under their instructions.
Scope of this policy
This Privacy Policy applies to the Orgix platform, including the web applications (People / HRIS, CRM, Field Force, authentication), the Orgix mobile app, marketing pages on orgixapp.com, and related support channels.
It covers personal information and business data processed when your organization uses Orgix modules such as attendance, leave, payroll, recruitment, CRM pipelines, field visits, conveyance claims, and reporting.
It does not replace your organization's own HR, employment, or customer-privacy policies. Employees and other end users should also review policies issued by their employer or workspace administrators.
Customer and Orgix roles
- Customer organization (controller): The company that subscribes to Orgix decides what data to put in the workspace, who gets access, which modules are enabled, and how long employment or sales records should be kept for business purposes.
- Orgix / Bracket Loop (processor / service provider): We provide the multi-tenant software, host and secure the service, and process data to deliver features the customer enables — not to sell personal data.
- End users: Employees, managers, sales reps, field staff, and admins invited into a customer workspace. Account creation is typically by invitation and role assignment from that organization.
Information we process
Depending on modules enabled and permissions configured by your organization, Orgix may process:
Account and identity
- Name, work email, password or SSO identifiers, role, and team membership
- Optional profile details (e.g. photo, job title, department, reporting structure)
- Multi-company membership when a user belongs to more than one workspace
People operations (HRIS)
- Employee directory, org chart, onboarding / offboarding records
- Attendance (including QR, selfie, or biometric check-in where configured), leave requests and balances
- Payroll-related structures, payslip access, schedules, assets, documents, training, and performance data as enabled
- Recruitment pipeline data (applications, interviews) when Talent Acquisition is used
CRM and Field Force
- Leads, customers, opportunities, activities, and pipeline stage history
- Visit plans, GPS/time-stamped check-in and check-out, territory and route data, targets
- Conveyance / expense claims linked to visits when that module is used
Device, location, and verification (when used)
- Location: Precise location may be collected during attendance or field visit check-in/out — not continuous background tracking for unrelated purposes
- Camera / images: Selfie or document capture where the customer enables identity or evidence workflows
- Device biometrics: Device biometric unlock (Face ID / fingerprint) is handled by the OS; Orgix does not store raw biometric templates
- Device model, OS version, app version, and push-notification tokens for security and reliability
Marketing and support
- Contact-form submissions, demo requests, and email/WhatsApp correspondence with Bracket Loop
- Standard website logs and diagnostics needed to operate orgixapp.com
How we use information
- Provide and operate HRIS, CRM, and Field Force features your organization enables
- Authenticate users, enforce roles/permissions, and support SSO where configured
- Generate reports, analytics, and exports available to authorized roles
- Send product notifications (approvals, visits, payroll readiness, system alerts)
- Maintain security, prevent abuse, troubleshoot incidents, and improve reliability
- Respond to sales, support, and contractual inquiries
- Comply with legal obligations applicable to us as a service provider
We do not sell personal information. We do not use customer workspace content to train public AI models.
Security and isolation
- Multi-tenant isolation so each company's workspace remains separate
- Role- and permission-based access on web and mobile
- Encrypted transport (HTTPS/TLS) for client–server communication
- Authentication via Orgix auth services, with SSO options where contracted
- Operational practices aimed at least-privilege access for platform operators
No method of transmission or storage is 100% secure. Enterprise customers should also configure roles, module access, and device policies appropriate to their risk profile.
Retention and deletion
We retain workspace data for as long as the customer subscription and account relationship require, and as needed for backups, dispute resolution, security, and legal compliance.
When a customer closes their Orgix workspace or requests deletion under contract, we delete or anonymize customer data from active systems within a commercially reasonable period, subject to legal retention and backup cycles. Individual employee or CRM record deletion is typically handled by the customer's administrators inside the product.
Your rights and choices
- Employees and end users: Update profile details in-app where permitted; manage device permissions (camera, location, notifications) in OS settings; request access or correction through your organization's HR/IT admin (they control most employment and CRM records).
- Customer admins: Manage users, roles, modules, and exports according to your subscription; contact us for account-level or contractual privacy requests.
- Marketing contacts: Ask us to stop non-essential outreach using the contact details below.
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port personal data, or to object to certain processing. Where Orgix is the processor, we will support the customer in responding as required by applicable law and our agreements.
International transfers
Orgix may be hosted and supported using infrastructure and personnel in more than one country. Where data is transferred across borders, we use appropriate contractual and technical measures consistent with our role as a B2B service provider and with customer agreements.
Children
Orgix is an enterprise workplace product. It is not directed at children under 16, and we do not knowingly collect personal information from children for consumer use of the service.
Policy updates
We may update this Privacy Policy to reflect product, legal, or operational changes. The effective date at the top of this page will be revised when we do. Material changes may also be communicated to customer administrators through the product or email.
Contact
For privacy questions, data-protection requests, or security concerns related to Orgix:
- Email: hello.bracketloop@gmail.com
- Phone: +880 1410-035667
- WhatsApp: Chat with us
- Publisher: Bracket Loop
Prefer a structured request? Use our contact form.