Privacy Policy
1. Scope and Who We Are
This Privacy Policy explains how Phoenix Software Inc. (“Phoenix”, “we”, “us” or “our”) collects, uses, shares, stores and protects personal data through our public websites, hosted payroll and human-resources services, Phoenix Portal, GPHC Mobile when provided by Phoenix, and any other Phoenix application or service that links to this Policy (collectively, the “Platform”).
Phoenix Software Inc. is located at 73 Hadfield Street, Stabroek, Georgetown, Guyana. Phoenix Portal and GPHC Mobile are workforce applications, not general consumer social networks. This Policy should be read together with our Terms of Use and any privacy notice supplied by your employer or other organization.
This Policy does not govern an employer’s independent privacy practices or a third-party website, application or service that Phoenix does not control.
2. Customer and Phoenix Roles
An employer, public body, business or other organization using the Platform is a “Customer”. An employee, officer, contractor, manager, administrator or other person permitted to use a Customer account is an “Authorized User”.
For payroll, employment and workforce records, the Customer generally decides why the data is processed, which records are entered, who may access them, how long they must be kept, and what employment action is taken. Phoenix generally processes that data to provide the Platform under the Customer’s instructions and agreement.
Phoenix makes its own decisions about limited data needed to operate its business and protect the Platform, such as public-website inquiries, account security records, support communications, service logs and product diagnostics. Questions about the substance or accuracy of an employment record should usually be directed first to the Customer’s human-resources, payroll or Platform administrator.
3. Information We Collect
Account and identity information. We may collect names, work or personal email addresses, employee or badge identifiers, date of birth used to verify registration, department, job title, profile photograph, account roles, and authentication or verification information.
Payroll, HR and workforce information. Depending on the modules a Customer enables, the Platform may process compensation and payslip information, deductions and statutory payroll information, leave and time-off records, attendance-related information, appraisal and peer-review information, job-letter requests, workflow approvals, personal documents and other employment records supplied or approved by the Customer or Authorized User.
Content you provide. We collect information you enter, upload or submit, such as registration details, profile photos, supporting documents, leave requests, appraisal responses, acknowledgements, notes and messages to Phoenix support. When you contact us, we may retain your contact details and the content of the communication.
Device, application and network information. The Platform may collect an internet protocol address, browser type, operating system and version, device type, app version, build number, package identifier, a device or vendor identifier supplied by the operating system, a Phoenix-generated per-install identifier, sign-in dates and times, requested endpoints, response codes and related security or service logs.
Push-notification information. If notifications are enabled, the App obtains a Firebase Cloud Messaging registration token and associates it with the account and device identifier so that Phoenix can deliver service and workflow notifications.
Crash and diagnostic information. Release versions of the App use Firebase Crashlytics. When the App crashes or experiences a serious error, Crashlytics may automatically receive an installation identifier, crash or exception stack trace, timestamp, app version, operating-system details, device model and technical application state needed to identify and correct the problem. Phoenix does not use Google Analytics, advertising SDKs or targeted-advertising trackers in the current App.
Information from Customers and other users. Customers, administrators and authorized workflow participants may provide or generate information about another Authorized User, including employment records, assigned permissions, requests, approvals, comments and appraisal information.
4. Mobile Permissions and Device Features
The App requests access only when a related feature needs it or the operating system requires permission. Depending on the device, App and enabled features:
- Camera: used when you choose to take a profile photo or photograph a supporting document.
- Photos and files: used when you choose a profile image or supporting document to upload.
- Notifications: used to deliver account, security, workflow and service updates.
- Biometric authentication: used to unlock an existing local session after you enable the feature. The biometric comparison is performed by the device operating system. Phoenix does not receive or store a fingerprint, facial image or biometric template.
Current versions of Phoenix Portal and GPHC Mobile do not request access to precise location, contacts or the microphone. You can grant or revoke operating-system permissions in device settings, although disabling a permission may prevent the related feature from working.
5. How We Use Information
Phoenix uses personal data as reasonably necessary to:
- register, authenticate, secure and administer accounts and devices;
- provide payroll, HR, employee self-service, leave, appraisal, document, notification and related Platform features;
- process requests, uploads, approvals and instructions from you or the Customer;
- deliver push notifications and service-related email or in-app communications;
- provide support, answer inquiries and resolve technical issues;
- monitor availability, investigate crashes, maintain compatibility and improve reliability and usability;
- detect, prevent and investigate fraud, misuse, unauthorized access and security incidents;
- maintain business, audit and compliance records and meet legal obligations; and
- enforce agreements and protect the rights, safety and property of Phoenix, Customers, users and others.
Depending on the context and applicable law, this processing is performed to provide contracted services, follow the Customer’s lawful instructions, comply with legal obligations, protect legitimate operational and security interests, or act with consent where consent is required. Phoenix does not sell or rent personal data and does not use Customer workforce data for targeted advertising.
6. When We Share Information
Phoenix may disclose personal data only as reasonably necessary:
- To the Customer and Authorized Users: according to roles, permissions and workflows configured by the Customer. For example, an approver may see information needed to review a leave request.
- To Phoenix personnel and contractors: when they require access to operate, secure or support the Platform and are subject to confidentiality obligations.
- To service providers: for infrastructure hosting, push delivery, crash diagnostics, communications and other technical services described below.
- At your direction: when you choose to export, download or share content with a destination or application you select.
- For legal and safety reasons: when reasonably necessary to comply with law or lawful process, protect rights and safety, investigate misuse, or establish, exercise or defend legal claims.
- For a business transaction: in connection with a proposed or completed merger, financing, reorganization, acquisition or sale of assets, subject to appropriate confidentiality and legal safeguards.
Phoenix requires service providers that process personal data on its behalf to protect it consistently with this Policy, their contractual obligations and applicable law. Phoenix does not permit them to use Customer workforce data for their own advertising.
7. Service Providers and International Processing
Phoenix’s core hosted services use Amazon Web Services infrastructure in Virginia, United States. The Apps use Google Firebase Cloud Messaging for push delivery and Firebase Crashlytics for crash diagnostics. Apple or Google may also process device, store and notification-delivery information when you obtain or use an App through their platforms.
These providers may process information in the United States and other countries where they or their service providers operate. When Phoenix appoints a provider, Phoenix uses contractual, organizational and technical measures appropriate to the information and applicable requirements. Provider practices are described in the AWS Privacy Notice, Firebase Privacy and Security information, Apple Privacy Policy and Google Privacy Policy.
8. Data Retention
Phoenix retains personal data only for as long as reasonably necessary for the purposes described in this Policy, the Customer Agreement, the Customer’s lawful instructions, account administration, security, dispute resolution and applicable payroll, employment, tax, audit or other legal requirements.
Customer-controlled employment records are generally retained for the Customer’s subscription and then handled according to the Customer Agreement, Phoenix’s operational retention procedures and the Customer’s instructions, subject to law. Security and support records are kept for a limited period appropriate to their purpose. Operational backups are overwritten or deleted on a scheduled cycle, although a deleted item may remain in a protected backup until that cycle completes.
Google applies its documented retention periods to Firebase data. Firebase currently states that Crashlytics retains crash stack traces and associated installation identifiers for 90 days before beginning removal from live and backup systems. Current provider retention details are available in the Firebase privacy information linked above.
Phoenix may retain limited information after an account-deletion request when necessary for security, fraud prevention, compliance with law, the establishment or defence of legal claims, or enforcement of agreements. When possible, information no longer requiring identification may be aggregated or de-identified.
9. Account Deletion
Delete from the App. A signed-in Phoenix Portal or GPHC Mobile user can initiate permanent app-account deletion from Account → Security → Delete account. The App requires the current password and two confirmations before submitting the request, then signs the user out.
Request deletion from the web. If you cannot access the App, email support@phoenixsoftgy.com with the subject “Phoenix Portal account deletion”. Include the account email address, the Customer or employer name, and enough information for Phoenix to locate and verify the account. Never send your password or a security code by email.
Phoenix will verify the request and delete or de-identify the app account and associated personal data that Phoenix is responsible for, except information that must be retained for one of the legitimate reasons described in Section 8. Merely disabling or freezing an account is not treated as completion of a valid deletion request.
Deleting an app account does not automatically erase payroll, tax, employment, appraisal, leave, audit or other underlying workforce records controlled by the Customer. Those records may be independent of the app account and may need to be retained by the Customer or Phoenix under the Customer’s instructions or applicable law. Contact the Customer’s human-resources or payroll administrator to request access, correction or deletion of an underlying employment record.
Uninstalling the App, signing out, or revoking a device permission does not by itself submit an account-deletion request or delete server records.
10. Your Privacy Choices and Requests
Depending on applicable law and the nature of the data, you may be able to request access to, correction of, export of or deletion of personal data, or object to or restrict certain processing. Phoenix may need to verify your identity and may direct a workforce-data request to the Customer that controls the record.
You may disable notifications, camera, photo-library and biometric permissions through the App or device settings. You may also stop using the Platform, subject to the Customer’s workplace requirements. Where processing relies on consent, you may withdraw that consent, but withdrawal does not affect processing already performed lawfully and may make the related feature unavailable.
Service and security communications are part of operating the Platform and may not offer an unsubscribe option while an account remains active. Phoenix does not send targeted advertising through the Platform.
11. Security
Phoenix uses commercially reasonable administrative, technical and organizational safeguards designed to protect personal data. These include encrypted transport using protocols such as Transport Layer Security, authentication and access controls, restricted administrative access, operational backups, monitoring and personnel confidentiality obligations.
Authentication tokens are stored using operating-system protected storage where supported. Non-sensitive app preferences may be stored locally on the device. No internet transmission or storage system can be guaranteed completely secure, so you should protect your credentials and device, use available device security, and promptly report suspected unauthorized access.
12. Cookies, Local Storage and Caches
Phoenix websites and hosted web applications may use essential cookies or similar storage for authentication, security, traffic management and user preferences. Phoenix does not use targeted-advertising cookies on the Platform.
The Apps use protected device storage for the authentication token and ordinary local storage for settings such as the remembered email choice, theme, biometric preference, notification prompts and display preferences. They may temporarily cache images and documents to display requested content. Signing out clears the active Phoenix session, while uninstalling or clearing app storage may remove local information but does not necessarily delete server data.
Browser controls can block or delete cookies, and device settings can clear App storage. Disabling necessary storage may prevent authentication or other Platform features from working correctly.
13. Children
The Platform is intended for Customers and their authorized workforce users and is not directed to children as a general consumer service. If a Customer authorizes a person below the legal age of majority to use the Platform in a lawful employment or similar context, the Customer is responsible for providing required notices and obtaining any consent required by applicable law.
14. Changes to This Policy
Phoenix may update this Policy to reflect changes to the Platform, data practices, providers or applicable requirements. Phoenix will post the revised Policy here and update the date above. For a material change, Phoenix will provide additional notice through the Platform, by email or through the Customer where reasonably appropriate or legally required.
15. Contact Information
For privacy questions, requests or complaints, contact:
- Phoenix Software Inc.
- 73 Hadfield Street, Stabroek
- Georgetown, Guyana
- Telephone: +592 223 4696
- Email: support@phoenixsoftgy.com
To help us respond, describe the service and Customer involved and the nature of your request. Do not send passwords, verification codes, payroll documents or identity documents by ordinary email unless Phoenix specifically provides a secure method.