Privacy policy
Effective and last updated: 27 August 2026
This policy explains how Trakium AI handles information from public-site visitors, business contacts, product administrators, and the workforce records customers choose to process through the service.
1. Information we receive
- Website and enquiry information: name, work email, company, team size, use case, message, and basic request-security data.
- Account information: name, email, organisation, role, authentication and session records, support requests, and administrative audit events.
- Workforce data submitted by a customer: employee profile and work context, attendance, shifts, breaks, devices, activity events, applications, websites, window titles, idle time, screenshots, alerts, reports, and customer-configured notes.
- Technical information required to operate and secure the service, such as IP address, user agent, request time, error, agent version, and device-health data.
2. Why we use information
- Respond to demonstrations, security reviews, pricing requests, and support enquiries.
- Provide, secure, troubleshoot, and improve the contracted service.
- Authenticate users, enforce access roles, investigate abuse, and keep an audit trail.
- Process workforce records only on the customer’s documented instructions and product configuration.
- Meet legal obligations and establish, exercise, or defend legal claims.
3. Roles and lawful basis
For public-site enquiries and direct business administration, Trakium determines the purpose of processing and acts as controller. Processing is based on steps requested before a contract, legitimate business interests, consent where required, and legal obligations.
For employee and workforce monitoring records, the customer determines the purpose, scope, users, and retention. The customer is responsible for an appropriate lawful basis, notice, consultation, policy, access rules, and response to data-subject requests.
4. AI-assisted processing
Trakium may use configured AI services to classify work context and produce summaries. The product is designed to use extracted text and operational context for automated analysis rather than automatically sending screenshot images to the AI service. A customer should still avoid collecting unnecessary sensitive information and should review output before using it in a people decision.
5. Service providers and disclosures
Trakium uses service providers only where needed to deliver the website, communications, security, hosting, storage, and AI-assisted features. The current deployment or order form identifies material product subprocessors and hosting location. Cloudflare provides public-site delivery, DNS, security, forms, and email routing. Google provides configured Gemini AI services for applicable product features.
We may disclose information where required by law, to protect the service or users, during a business reorganisation subject to appropriate safeguards, or on the customer’s documented instruction.
6. Retention
Public enquiries are kept only as long as needed for the business conversation, security, and legal record. Customer workforce data follows the contracted retention configuration and deletion process. Customers should choose the shortest period that meets their documented purpose and legal obligations.
7. Security
We use access controls, revocable sessions, organisation scoping, protected object links, auditability, and deployment security controls appropriate to the service. No internet service can guarantee absolute security. Customers remain responsible for user administration, endpoint security, monitoring policy, and protecting exported data.
8. International transfers
The service and its providers may process data outside the customer’s country. Where transfer restrictions apply, the parties will use an appropriate contractual or legal mechanism identified in the data processing agreement or order form.
9. Individual rights
A workforce member should normally submit an access, correction, objection, restriction, or deletion request to their employer, which is the controller. Trakium will support the customer as required by the DPA. Public-site contacts may write to us directly using the address below.
10. Changes
We may update this policy when the product, providers, or legal requirements change. The current version and effective date are published on this page. Material changes affecting contracted processing will be handled under the customer agreement.
Contact
Questions about this document or Trakium’s data practices can be sent to info@trakiumai.com.