Orgix

Legal

Privacy Policy

How Orgix — an enterprise HRIS, CRM, and Field Force platform — handles personal and business data.

Effective July 12, 2026Product of Bracket Loop

Orgix is a multi-tenant B2B SaaS used by organizations to run people operations, sales pipelines, and field execution. Most workplace data is controlled by the customer organization that subscribes to Orgix. We process that data to provide the service under their instructions.

01

Scope of this policy

This Privacy Policy applies to the Orgix platform, including the web applications (People / HRIS, CRM, Field Force, authentication), the Orgix mobile app, marketing pages on orgixapp.com, and related support channels.

It covers personal information and business data processed when your organization uses Orgix modules such as attendance, leave, payroll, recruitment, CRM pipelines, field visits, conveyance claims, and reporting.

It does not replace your organization's own HR, employment, or customer-privacy policies. Employees and other end users should also review policies issued by their employer or workspace administrators.

02

Customer and Orgix roles

  • Customer organization (controller): The company that subscribes to Orgix decides what data to put in the workspace, who gets access, which modules are enabled, and how long employment or sales records should be kept for business purposes.
  • Orgix / Bracket Loop (processor / service provider): We provide the multi-tenant software, host and secure the service, and process data to deliver features the customer enables — not to sell personal data.
  • End users: Employees, managers, sales reps, field staff, and admins invited into a customer workspace. Account creation is typically by invitation and role assignment from that organization.
03

Information we process

Depending on modules enabled and permissions configured by your organization, Orgix may process:

Account and identity

  • Name, work email, password or SSO identifiers, role, and team membership
  • Optional profile details (e.g. photo, job title, department, reporting structure)
  • Multi-company membership when a user belongs to more than one workspace

People operations (HRIS)

  • Employee directory, org chart, onboarding / offboarding records
  • Attendance (including QR, selfie, or biometric check-in where configured), leave requests and balances
  • Payroll-related structures, payslip access, schedules, assets, documents, training, and performance data as enabled
  • Recruitment pipeline data (applications, interviews) when Talent Acquisition is used

CRM and Field Force

  • Leads, customers, opportunities, activities, and pipeline stage history
  • Visit plans, GPS/time-stamped check-in and check-out, territory and route data, targets
  • Conveyance / expense claims linked to visits when that module is used

Device, location, and verification (when used)

  • Location: Precise location may be collected during attendance or field visit check-in/out — not continuous background tracking for unrelated purposes
  • Camera / images: Selfie or document capture where the customer enables identity or evidence workflows
  • Device biometrics: Device biometric unlock (Face ID / fingerprint) is handled by the OS; Orgix does not store raw biometric templates
  • Device model, OS version, app version, and push-notification tokens for security and reliability

Marketing and support

  • Contact-form submissions, demo requests, and email/WhatsApp correspondence with Bracket Loop
  • Standard website logs and diagnostics needed to operate orgixapp.com
04

How we use information

  • Provide and operate HRIS, CRM, and Field Force features your organization enables
  • Authenticate users, enforce roles/permissions, and support SSO where configured
  • Generate reports, analytics, and exports available to authorized roles
  • Send product notifications (approvals, visits, payroll readiness, system alerts)
  • Maintain security, prevent abuse, troubleshoot incidents, and improve reliability
  • Respond to sales, support, and contractual inquiries
  • Comply with legal obligations applicable to us as a service provider

We do not sell personal information. We do not use customer workspace content to train public AI models.

05

Sharing and disclosure

  • Within your organization: Admins and other authorized roles can access data according to module permissions (e.g. managers approving leave, sales leadership viewing pipeline).
  • Service providers: Infrastructure, email delivery, authentication, and similar vendors that process data only to run Orgix — under contractual confidentiality and security obligations.
  • Integrations: If the customer enables webhooks or third-party connections, data may flow to systems the customer chooses.
  • Legal: When required by law, court order, or to protect rights, safety, and the integrity of the service.
  • Business transfers: In connection with a merger, acquisition, or asset sale, subject to appropriate safeguards.

Customer tenants are isolated: data from one organization is not shared with another organization's workspace.

06

Security and isolation

  • Multi-tenant isolation so each company's workspace remains separate
  • Role- and permission-based access on web and mobile
  • Encrypted transport (HTTPS/TLS) for client–server communication
  • Authentication via Orgix auth services, with SSO options where contracted
  • Operational practices aimed at least-privilege access for platform operators

No method of transmission or storage is 100% secure. Enterprise customers should also configure roles, module access, and device policies appropriate to their risk profile.

07

Retention and deletion

We retain workspace data for as long as the customer subscription and account relationship require, and as needed for backups, dispute resolution, security, and legal compliance.

When a customer closes their Orgix workspace or requests deletion under contract, we delete or anonymize customer data from active systems within a commercially reasonable period, subject to legal retention and backup cycles. Individual employee or CRM record deletion is typically handled by the customer's administrators inside the product.

08

Your rights and choices

  • Employees and end users: Update profile details in-app where permitted; manage device permissions (camera, location, notifications) in OS settings; request access or correction through your organization's HR/IT admin (they control most employment and CRM records).
  • Customer admins: Manage users, roles, modules, and exports according to your subscription; contact us for account-level or contractual privacy requests.
  • Marketing contacts: Ask us to stop non-essential outreach using the contact details below.

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port personal data, or to object to certain processing. Where Orgix is the processor, we will support the customer in responding as required by applicable law and our agreements.

09

International transfers

Orgix may be hosted and supported using infrastructure and personnel in more than one country. Where data is transferred across borders, we use appropriate contractual and technical measures consistent with our role as a B2B service provider and with customer agreements.

10

Children

Orgix is an enterprise workplace product. It is not directed at children under 16, and we do not knowingly collect personal information from children for consumer use of the service.

11

Policy updates

We may update this Privacy Policy to reflect product, legal, or operational changes. The effective date at the top of this page will be revised when we do. Material changes may also be communicated to customer administrators through the product or email.

12

Contact

For privacy questions, data-protection requests, or security concerns related to Orgix:

Prefer a structured request? Use our contact form.