This Privacy Policy explains how CodeLogicX Technologies Pvt. Ltd. ("CodeLogicX", "TeamTrace", "we", "us", "our") collects, uses, shares, stores and protects personal data in connection with the TeamTrace workforce productivity platform.
It applies to:
- the website www.teamtrace.app and its subdomains,
- the TeamTrace web application at platform.teamtrace.app,
- the TeamTrace mobile applications for Android and iOS,
- the TeamTrace desktop application and monitoring agent, and
- related support, onboarding, sales, and marketing activities.
Collectively, these are referred to as the "Services".
Registered entity details:
| Legal entity | CodeLogicX Technologies Pvt. Ltd. |
| Registered office | 6th Floor Webel IT Park, BN-9 Sector V, Sech Bhawan, North 24 Parganas, Saltlake, West Bengal, India, 700091 |
| CIN | U72300WB2013PTC191145 |
| Incorporated | Under the Companies Act, 2013 |
| Privacy contact | grievance@teamtrace.app |
If you do not agree with this Policy, please do not use the Services.
- You / User – any individual who uses the Services, whether as an individual, or as an employee, contractor or representative of an organization. Also referred to as the Data Principal (DPDP Act) or Data Subject (GDPR).
- Customer – the organization that subscribes to TeamTrace and deploys it to its workforce.
- Personal data – any information that identifies, or can reasonably be used to identify, an individual.
- Usage data – technical and behavioral data generated automatically when the Services are used.
- Processing – any operation performed on personal data, including collection, storage, use, disclosure and deletion.
- Sub-processor – a third party engaged by us to process personal data on our behalf in order to deliver the Services.
Our Two Roles:
TeamTrace processes personal data in two distinct capacities. Which one applies determines who is accountable for a given decision.
We act as a Data Controller (Data Fiduciary) when we decide why and how data is processed — e.g., for website visitors, prospects, trial sign-ups, billing contacts, support requesters and marketing subscribers.
We act as a Data Processor (Data Processor under the DPDP Act) when a Customer deploys TeamTrace to its workforce. In that case, the Customer is the Controller for its employees' work, activity, attendance, location, and monitoring data. The Customer decides what to enable, what to collect and how long to keep it. We process that data only on the Customer's documented instructions, under a Data Processing Agreement.
If you are an employee with questions about why your organization monitors particular activity, please contact your employer in the first instance. We will assist your employer in responding to you.
Information We
We collect only what is needed to operate, secure and improve the Services.
Account and
Name, work email address, phone number, job role, profile photo, organization name, department, employee ID, username and authentication credentials, time zone and language preference.
HR and Workforce
Where enabled by the Customer: reporting structure, skill sets, availability, capacity, leave records, employment history and other resource-management fields entered by the Customer or its administrators.
Work Activity and
Task and project identifiers, task descriptions and deadlines, progress updates, start and end times, time logged against tasks, timesheets, application and website usage during tracked work hours, idle time, activity levels, availability status and work patterns.
Screen Capture
Screenshots and screen recordings, only where the Customer has enabled this feature, at the frequency and scope the Customer configures.
Attendance and
Clock-in and clock-out records, break duration, GPS coordinates, geo-fence entry and exit events, and geo-tagged check-ins, where attendance or field-work features are enabled. Location collection is preceded by an in-app disclosure and an operating-system runtime permission request.
Camera and
Photographs and videos used for profile creation and identity or attendance verification, captured only after an explicit in-app permission prompt.
Content and
Documents, project briefs, reports, PDFs, attachments, comments, wiki entries and other content uploaded to or created within the Services.
Device and
IP address, device model, operating system and version, device identifiers (for example Android ID, Apple IDFA), app version, browser type, mobile network information and referrer data.
Usage and
Feature usage, in-app interactions, page and screen views, load times, crash reports, error logs, and audit logs.
Subscription plan, billing contact details, billing address, GSTIN or tax identifiers, invoices and transaction records. Card and bank details are collected and stored by our payment processors, not by us. We receive only a payment token and limited transaction metadata.
Records of your correspondence with our sales, support and success teams, including email, chat, WhatsApp, demo requests, contact-form submissions, and call notes.
We do not intentionally collect special categories or sensitive personal data. Please do not upload such data into free-text or file fields unless your organization has a lawful basis to do so.
How We
- Directly from you — when you register, create a profile, book a demo, contact support, subscribe to communications or upload content.
- From your organization — when a Customer creates accounts, imports employee records or configures monitoring settings on your behalf.
- Automatically — through the applications, desktop agent, cookies and similar technologies, as described in Section 12.
- From third parties — integration partners you or your organization connect (for example project management, payroll, calendar or communication tools), single sign-on providers, payment processors, and lawful business-data sources used for sales outreach.
Why We Use Your Data, and On What Legal
| Purpose | Categories used | Legal basis |
|---|---|---|
| Create and administer accounts; authenticate users | 4.1 | Performance of contract; consent (DPDP) |
| Deliver core platform functionality — projects, time tracking, attendance, resource management | 4.1 – 4.7 | Performance of contract; Customer's instructions as Controller |
| Enable workforce visibility and productivity reporting for the Customer | 4.3 – 4.5 | Customer's legitimate interest / applicable employment law basis; Customer's instructions |
| Process subscriptions, invoicing and taxes | 4.1, 4.10 | Performance of contract; legal obligation |
| Provide customer support and service communications | 4.1, 4.9, 4.11 | Performance of contract; legitimate interest |
| Maintain security, prevent fraud and abuse, investigate incidents | 4.8, 4.9 | Legitimate interest; legal obligation |
| Diagnose faults and improve platform stability and usability (aggregated and de-identified wherever possible) | 4.8, 4.9 | Legitimate interest; consent for non-essential analytics |
| Send marketing communications about TeamTrace | 4.1, 4.11 | Consent; legitimate interest for existing business contacts, subject to opt-out |
| Comply with law and respond to lawful requests | Any relevant | Legal obligation |
We do not sell personal data, and we do not use it for third-party targeted advertising.
Consent and How to
Where we rely on consent, we obtain it through a clear, specific, informed and unambiguous affirmative action. An explicit checkbox or "I Agree" action at sign-up, or an in-app permission prompt when a feature such as location, camera or notifications is activated. Continued use of the Services alone is not treated as consent for any new or additional purpose.
If a required consent is not given, the associated feature or data collection is not activated. Refusing non-essential processing does not affect your access to core functionality.
You may withdraw consent at any time through your account settings, your device's operating-system permission controls, the unsubscribe link in our emails, or by writing to the contacts in Section 17. Withdrawal takes effect prospectively and does not affect the lawfulness of processing carried out before it. Where a Customer deploys TeamTrace, consent and notice obligations towards employees rest with that Customer.
Workforce Monitoring and
TeamTrace is a monitoring-capable platform. We design it to be used transparently.
What may be collected when a Customer deploys TeamTrace: work activity logs, application and website usage during tracked hours, attendance and idle-time records, GPS and geo-fence data for field staff, and screenshots or screen recordings where enabled.
Discreet / stealth monitoring mode (Silent App). TeamTrace offers a configurable mode that runs without a visible on-device indicator. This capability is available only to Customer organizations and may be activated only with prior written disclosure to affected employees and, where required by law, their explicit consent. Monitoring without notification may be unlawful in certain jurisdictions. The Customer is solely responsible for lawful, proportionate, and policy-compliant use of this feature. We do not endorse its use without appropriate transparency to employees.
Customer obligations. The Customer must issue employee-facing notices, obtain any consents required under applicable employment and data protection law, limit monitoring to what is necessary and proportionate, and restrict access to monitoring data to authorised personnel.
Our commitment. Within the application, we surface clear indicators of what is being collected while a user is logged in, subject to the Customer's configuration.
Sharing and
We disclose personal data only in the circumstances below.
- Your organization. If you use TeamTrace through an employer or client organization, that organization's administrators can access your account, activity, and monitoring data in line with its own policies.
- Affiliates and group entities. Our overseas offices and affiliated entities may access personal data to provide sales, support, engineering and administrative services, under the same protections set out in this Policy.
- Sub-processors. We engage vetted service providers for cloud hosting, email and notification delivery, payment processing, analytics, error monitoring, and CRM and support tooling. Each is bound by contract to confidentiality, purpose limitation and security standards no less protective than this Policy. A current list of sub-processors is available on request at grievance@teamtrace.app.
- Integrations you enable. Where you or your administrator connect a third-party tool, data flows to that tool as configured. Those tools operate under their own privacy policies.
- Legal and regulatory. Where required by law, court order, or a valid request from a government or regulatory authority, and to establish, exercise or defend legal claims. We assess each request and disclose only what is legally required.
- Business transfers. In a merger, acquisition, financing or sale of assets, personal data may be transferred as part of the transaction. Any acquirer will remain bound by this Policy or provide notice before materially changing it.
- Aggregated or de-identified data. We may publish or share statistics that cannot reasonably be used to identify any individual or Customer.
Data Location and
Production data is hosted on Amazon Web Services in the Mumbai region (ap-south-1), within India.
Certain ancillary providers, integrations and affiliated offices may process limited data in other jurisdictions, including the United States, the European Union and the Kingdom of Saudi Arabia. Where personal data is transferred across borders, we rely on appropriate safeguards — including data processing agreements incorporating Standard Contractual Clauses or equivalent contractual protections — that require the recipient to maintain protection consistent with this Policy and applicable law.
CodeLogicX operates a certified ISO/IEC 27001:2022 Information Security Management System and a certified ISO 9001:2015 Quality Management System. Our information security programme is built on the former and reviewed periodically while the latter governs the documented processes, change control and continual-improvement discipline applied across the delivery and operation of the Services. Key controls:
- Encryption. Personal data is encrypted at rest using AES-256, and all traffic between clients and our servers is encrypted using 256-bit TLS.
- Access control. Access is role-based, authenticated, granted on a need-to-know basis, and reviewed periodically.
- Logging and monitoring. Access to and modification of personal data is logged. Logs are retained for audit and incident investigation.
- Infrastructure protection. Hardened cloud infrastructure with network firewalls, segmentation, and managed backups.
- Assurance testing. Regular vulnerability assessments, security scans, and penetration testing, with tracked remediation.
- People and process. Confidentiality obligations for personnel, security awareness training, and documented incident response procedures.
Certifications and compliance posture. TeamTrace is operated in alignment with the Digital Personal Data Protection Act, 2023 (India) and the EU General Data Protection Regulation. CodeLogicX Technologies Pvt. Ltd. additionally holds the ISO/IEC 27001:2022 Information Security Management System certificate and a ISO 9001:2015 Quality Management System certificate.
Certification applies only within the scope stated on each certificate and does not by itself constitute a warranty of the security of any individual feature. Copies of current certificates are available to customers and prospective customers on request at grievance@teamtrace.app.
No system can be guaranteed completely secure. You are responsible for keeping your credentials confidential and for notifying us promptly of any suspected unauthorized access.
Cookies and
We use the following categories on our website and platform:
- Strictly necessary cookies — maintain your session, keep you logged in and protect against fraudulent requests. These cannot be disabled without breaking core functionality.
- Analytics cookies — help us understand how the site and platform are used so we can improve them. These include third-party tools deployed via our tag manager.
- Marketing cookies — used on our public website to measure campaign performance and to reach relevant business audiences.
Non-essential cookies are set only where you have accepted them via our cookie banner, and you can change your choice at any time through the banner controls or your browser settings. Disabling certain cookies may affect functionality.
| Data type | Retention period |
|---|---|
| Account and profile data | For the life of the account, then deleted or anonymized within 90 days of closure |
| Project, task and historical work records | Retained only for the duration of the Customer's active subscription. |
| Screenshots and screen recordings | Retained for a period of 3 months. |
| Location and attendance records | Retained subject to applicable statutory record-keeping requirements. |
| Usage, diagnostic and log data | Up to 12 months, unless retained longer for security or legal reasons |
| Billing, tax and contractual records | As required by applicable Indian tax and company law |
| Marketing contact data | Until you unsubscribe or after 24 months of no engagement |
Accounts inactive for 12 consecutive months are flagged for deletion. We notify the registered email address 30 days in advance so that the account can be reactivated. On expiry of a retention period, data is securely deleted or irreversibly anonymized. Customers may request export or deletion of their workspace data in accordance with their agreement with us.
Subject to applicable law and to verification of your identity, you may:
- Access the personal data we hold about you and obtain information about how it is processed.
- Correct inaccurate, misleading, or incomplete data.
- Erase your personal data, subject to legal and contractual retention obligations.
- Withdraw consent for any processing based on consent.
- Port data you provided to us in a structured, machine-readable format.
- Object to or restrict processing based on legitimate interests, or object to direct marketing at any time.
- Nominate another individual to exercise your rights in the event of death or incapacity, under Section 14 of the DPDP Act, 2023. Send the nominee's name and contact details to grievance@teamtrace.app.
- Complain to a supervisory authority — the Data Protection Board of India, or your local supervisory authority in the EEA or UK.
How to exercise them. Write to the contacts in Section 17. We will acknowledge your request within 48 hours and respond substantively within 15 business days, or within any shorter period required by applicable law. We may ask for information to verify your identity, and we may decline requests that are manifestly unfounded, excessive, or that would infringe the rights of others.
If your data is held on behalf of your employer, we will forward your request to that organization and support it in response, as our agreement requires.
TeamTrace is a professional platform intended solely for individuals aged 18 or over. We do not knowingly collect or process the personal data of minors. If we learn that a minor's data has been collected, we will delete it promptly. If you believe this has occurred, contact us at the address in Section 17.
Personal Data Breach
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected users and, where we act as Processor, the relevant Customer, without undue delay and, where feasible, within 72 hours of becoming aware of it. The notification will describe the nature of the breach, the categories of data affected, the likely consequences, and the remedial measures taken or proposed. We will report the breach to the competent authority — including the Data Protection Board of India or the relevant GDPR supervisory authority — as applicable law requires.
Grievance Officer and
For any privacy question, request or complaint:
| Grievance Officer / Privacy Compliance Officer | Anjishnu Pramanik |
| grievance@teamtrace.app | |
| General support | support@teamtrace.app |
| Postal address | The Grievance Officer, CodeLogicX Technologies Pvt. Ltd., 6th Floor Webel IT Park, BN-9 Sector V, Sech Bhawan, North 24 Parganas, Saltlake, West Bengal, India, 700091 |
| Acknowledgement | Within 48 hours |
| Resolution target | Within 15 business days |
Escalation. If your grievance is not resolved to your satisfaction within the stated timeline, or if you believe your rights under the Digital Personal Data Protection Act, 2023 have been infringed, you may escalate to the Data Protection Board of India. Users in the EEA or UK may lodge a complaint with their local supervisory authority. We will cooperate fully with any such inquiry.
Changes to this
We may update this Policy from time to time. When we do, we will publish the revised version on this page, update the "Last updated" date, and — for material changes — notify you by email or through a prominent in-app notice before the changes take effect. We encourage you to review this page periodically. Continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.
This Policy is governed by the laws of India. Subject to any mandatory rights you hold under the data protection law of your own country, and to the escalation route in Section 17, the courts at Kolkata, West Bengal shall have exclusive jurisdiction over any dispute arising from it. This Policy should be read together with our Terms & Conditions, Refund Policy and DPDP Compliance pages.
