Privacy Policy
Last updated 2026. This describes how Fronx OS actually handles your data today; it is not a substitute for independent legal advice.
01
Information we collect
When you register, we collect your name, email, company details, and any content you submit through the platform — project files, chat messages, contracts, and payment records. Company-side accounts also have a role, and employee accounts additionally hold HR data (attendance, leave, salary structure) entered by HR.
02
How we use it
Your data is used to deliver the service you signed up for — project management, invoicing, communication, notifications, and support. We do not sell client or employee data to third parties, and we do not use your project content to train any external system.
03
Data security
All files are served via expiring, pre-signed URLs — there is no direct, permanent link to a stored file. Credentials, bank details, and other sensitive records are encrypted at rest (AES-256) with keys isolated per subsystem. Access to your data is scoped strictly by role and by account, and every access to the credentials vault is logged.
04
Two-factor authentication & sessions
Company-side accounts require TOTP two-factor authentication. Sessions are managed with short-lived access tokens and rotating refresh tokens stored in httpOnly cookies, never accessible to page scripts.
05
Audit logging
Security-relevant actions (logins, role changes, payment confirmations, credential access, permanent deletions) are recorded in an immutable audit log. Audit entries are never deleted and are visible only to the CEO/Super Admin.
06
Retention & deletion
Deleted records are soft-deleted first and recoverable; permanent deletion is a Super-Admin-only action that always leaves a surviving log entry (what, who, when, why). We retain project and financial records for as long as your account is active and as needed to meet legal/accounting obligations.
07
Your rights
You can request a copy of your data or ask us to close your account at any time by contacting us. Company-side employee data is managed by HR on your employer’s behalf.
08
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated in-app or by email before they take effect.