Security & Privacy
What Clic Horaire does with your data
Who answers for what between your organisation and Clic Horaire, what is collected at the punch, what is never kept, and how long the rest is retained.
An employee asks what you hold about them. A parity committee asks how long you keep timesheets. A worker refuses fingerprint confirmation. All three questions have an answer written into the product, on the same page.
It is there to be read before you need it: Law 25 places obligations on you that Clic Horaire does not meet on your behalf, and it is better to discover them on a quiet Tuesday than in the middle of a complaint.
- Biometric data kept
- None
- Position recorded
- At the punch only
- Hours register
- 3 years (LNT)
- Deadline to answer a request
- 30 days
Landmark 01
Who answers for what
For your employees' data (schedules, punches, timesheets, documents) your organisation is the enterprise responsible under Law 25: it decides what is collected and it answers its employees' requests.
Clic Horaire acts as a service provider: we process that data only to deliver the service to you, never for our own purposes. This split is not a legal footnote: it determines who an employee must write to, and who must answer.
Landmark 02
Biometrics never reach us
When an employee confirms a punch with Face ID, a fingerprint or their device passcode, the check is performed by their phone, inside its secure chip. The app receives nothing but a yes or a no.
No fingerprint, no face, no template is transmitted to us. Neither Clic Horaire nor your organisation therefore builds a biometric database, and there is nothing to declare on that basis to the Commission d'accès à l'information.
Optional, and visibly so
Biometric confirmation has to stay a choice, with the device-passcode fallback explained. Consent obtained under pressure is not consent: and it is you, not us, who must be able to show it was freely given.
Landmark 03
Position, only at the moment of the punch
It is read at the instant the employee punches: never continuously, never in the background, never while the app is closed. There is no trail between two punches, because there is nothing to be gained from one.
Refused, it blocks no punch: the punch goes through without a position and the server judges the zone. Nobody is left standing at the gate for having said no.
Landmark 04
How long it is kept
Data is retained as long as your obligations require. The Act respecting labour standards requires the hours register and the payroll system to be kept for three years, and some decrees require more.
When your subscription ends, you get a reasonable window to export everything before destruction. That is the moment to pull the pay runs and the audit trail: afterwards, they cannot be reconstructed.
Landmark 05
Every person's rights
Anyone, employees included, may ask for access to their information, its correction, the withdrawal of their consent, the portability of their computerised data, and may complain to the Commission d'accès à l'information if the answer does not satisfy them.
An employee sends the request to THEIR EMPLOYER, who is responsible for their file. If you need help answering it (extracting a file, tracing a calculation) write to us: we answer within the 30 days the law provides.
Landmark 06
What remains yours to do
Clic Horaire equips you; it does not make you compliant on your behalf. Appointing a privacy officer and publishing their contact details, telling your employees what you collect at the moment you collect it, keeping your incident register, destroying or anonymising files whose purposes are fulfilled: those are your obligations.
The page lists them with their sections of the Act, so the list works as a reminder rather than decoration.
What to remember
In the event of a confidentiality incident
We keep an incident register, as section 3.8 of Law 25 requires. If an incident touches data we process for you, we tell you without delay and give you what you need to meet your own duty to notify the Commission d'accès à l'information and your employees.
This page is not legal advice
It summarises our practices and the main obligations of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1, as amended by Law 25). Your particular situation is for your own counsel to validate.
Go further
Answering an employee's access request
An employee asks for a copy of what you hold about them. Where to find their file, how to export it, what to check before sending, and what the law lets you keep.
LireReading and exporting the audit trail
Find who did what and when, narrow the search to one person, one action or one record, then pull the log out for an inspection.
LireCan't find what you're looking for?
Our team can answer your technical questions and support your rollout.

