Invite onlyRequest an invitation

Clic Horaire

Security & Privacy

What Clic Horaire does with your data

Who answers for what between your organisation and Clic Horaire, what is collected at the punch, what is never kept, and how long the rest is retained.

6 min readUpdated September 1, 20266 landmarks
“Legal and privacy”, at the bottom of the sidebar. The page is read-only and says the same thing to every one of your administrators.

An employee asks what you hold about them. A parity committee asks how long you keep timesheets. A worker refuses fingerprint confirmation. All three questions have an answer written into the product, on the same page.

It is there to be read before you need it: Law 25 places obligations on you that Clic Horaire does not meet on your behalf, and it is better to discover them on a quiet Tuesday than in the middle of a complaint.

Biometric data kept
None
Position recorded
At the punch only
Hours register
3 years (LNT)
Deadline to answer a request
30 days

Landmark 01

Who answers for what

For your employees' data (schedules, punches, timesheets, documents) your organisation is the enterprise responsible under Law 25: it decides what is collected and it answers its employees' requests.

Clic Horaire acts as a service provider: we process that data only to deliver the service to you, never for our own purposes. This split is not a legal footnote: it determines who an employee must write to, and who must answer.

The distinction is stated at the top of the page, before anything else: everything below follows from it.

Landmark 02

Biometrics never reach us

When an employee confirms a punch with Face ID, a fingerprint or their device passcode, the check is performed by their phone, inside its secure chip. The app receives nothing but a yes or a no.

No fingerprint, no face, no template is transmitted to us. Neither Clic Horaire nor your organisation therefore builds a biometric database, and there is nothing to declare on that basis to the Commission d'accès à l'information.

Optional, and visibly so

Biometric confirmation has to stay a choice, with the device-passcode fallback explained. Consent obtained under pressure is not consent: and it is you, not us, who must be able to show it was freely given.

The phone answers yes or no; that is all that travels.

Landmark 03

Position, only at the moment of the punch

It is read at the instant the employee punches: never continuously, never in the background, never while the app is closed. There is no trail between two punches, because there is nothing to be gained from one.

Refused, it blocks no punch: the punch goes through without a position and the server judges the zone. Nobody is left standing at the gate for having said no.

Refusing location weakens the evidence; it does not stop the work.

Landmark 04

How long it is kept

Data is retained as long as your obligations require. The Act respecting labour standards requires the hours register and the payroll system to be kept for three years, and some decrees require more.

When your subscription ends, you get a reasonable window to export everything before destruction. That is the moment to pull the pay runs and the audit trail: afterwards, they cannot be reconstructed.

Retention follows the law and your decrees, not an in-house policy.

Landmark 05

Every person's rights

Anyone, employees included, may ask for access to their information, its correction, the withdrawal of their consent, the portability of their computerised data, and may complain to the Commission d'accès à l'information if the answer does not satisfy them.

An employee sends the request to THEIR EMPLOYER, who is responsible for their file. If you need help answering it (extracting a file, tracing a calculation) write to us: we answer within the 30 days the law provides.

Five rights, portability (s. 27) among them, often forgotten.

Landmark 06

What remains yours to do

Clic Horaire equips you; it does not make you compliant on your behalf. Appointing a privacy officer and publishing their contact details, telling your employees what you collect at the moment you collect it, keeping your incident register, destroying or anonymising files whose purposes are fulfilled: those are your obligations.

The page lists them with their sections of the Act, so the list works as a reminder rather than decoration.

Five obligations, each with its section: ss. 3.1, 8, 3.5 to 3.8 and 23.

What to remember

In the event of a confidentiality incident

We keep an incident register, as section 3.8 of Law 25 requires. If an incident touches data we process for you, we tell you without delay and give you what you need to meet your own duty to notify the Commission d'accès à l'information and your employees.

This page is not legal advice

It summarises our practices and the main obligations of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1, as amended by Law 25). Your particular situation is for your own counsel to validate.

Go further

Can't find what you're looking for?

Our team can answer your technical questions and support your rollout.

Request a Demo
Clic HoraireClic Horaire

Less admin.
More time for your business.

From the first punch to pre-payroll, simplify your team's day with Clic Horaire.