This policy explains how TempoHR uses product data. It supplements the Privacy Policy.
1.Product Data
[PLACEHOLDER — TempoHR-specific content to be added. Contact legal@brightstack.us]
2.AI Features
[PLACEHOLDER — TempoHR-specific content to be added. Contact legal@brightstack.us]
3.Data Isolation and Security
Every query scoped by tenant_id using row-level security — one organization cannot access another's data.
All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
Staff access requires MFA and is audit-logged.
SOC-2-aligned controls reviewed annually.
4.Data Export and Deletion
Export: account data available from Settings → Data.
Deletion: account deletion removes all data within 90 days.
5.Third-Party Processors
[PLACEHOLDER — TempoHR-specific content to be added. Contact legal@brightstack.us] — full subprocessor list. Each subprocessor operates under a Data Processing Agreement. Contact privacy@brightstack.us for the current list.
6.Contact
privacy@brightstack.us · 30 days (GDPR), 45 days (CCPA)
Michell + Marteen LLC / Brightstack, Houston, Texas