Invite onlyRequest an invitation

Legal

Privacy Policy

At Clic Horaire, protecting your personal information is a priority. This policy clearly explains what information we collect, why, and how you can exercise your rights.

Last updated : September 5, 2026

1. Scope of this policy and everyone's role

This Privacy Policy describes how Clic Horaire inc. (« Clic Horaire », « we », « our ») collects, uses, discloses and protects the personal information of visitors to our website, of our customers and of the users of our pre-payroll and scheduling platform: the web application as well as the Clic Horaire mobile apps for iOS and Android, published by Clic Horaire inc.

It is written in accordance with the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as amended by Law 25, and with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable.

Two distinct roles, and the distinction matters when deciding who to write to:

  • For the information of our VISITORS and CUSTOMERS (demo request, account creation, billing, support), Clic Horaire is the enterprise responsible under the Act. This policy applies in full.
  • For the information of our customers' EMPLOYEES (schedules, punches, timesheets, record documents), Clic Horaire acts as a service provider on the employer's behalf: we process that information only on their instruction and to deliver the service. The employer remains the enterprise responsible. An employee who wishes to consult, correct or delete their record contacts their employer first; we assist and can redirect them.

2. Person in charge of the protection of personal information

In accordance with section 3.1 of Law 25, the person with the highest authority within Clic Horaire inc. acts as the person in charge of the protection of personal information. They ensure compliance with this policy, handle access and rectification requests, and maintain the register of confidentiality incidents.

You may reach them at any time at the address given under « Contact us » below, stating the purpose of your request. We acknowledge receipt promptly and answer within the 30 days provided by law.

3. Information we collect

We collect the following categories of information:

  • Information you provide directly: name, business email address, phone number, organization name, team size, correspondence language and the content of your communications, in particular when you fill in our demo form, create an account or write to us.
  • Technical information collected automatically: IP address, browser type, pages visited, time on site and browsing data, through cookies and analytics tools (see the cookies section).
  • Information processed on behalf of our customers: employee identity, employee number, contact details, schedules, punches, timesheets, absences, documents filed in their employment record and, where the applicable scheme requires it, sensitive information such as the social insurance number or date of birth. That information belongs to the record kept by the employer.
  • Billing information: billing contact details and payment history. Credit card numbers are handled directly by our payment processor and never transit through our servers.

4. Geolocation and punching

When an employee punches from the mobile app, their location may be read to attest that they were indeed at the workplace. That reading follows three rules, and they are technical, not merely declarative:

  • Location is read AT THE MOMENT OF THE PUNCH only: never continuously, never in the background, never when the app is closed.
  • Location permission is asked at the first punch, not when the app opens. If it is denied, the punch still goes out: no punch is ever lost or refused for lack of a location.
  • The location travels with the punch into the employer's record. It is the employer who decides to turn site geofences on, and who answers to their employees for that use.

5. Biometrics: what we do not collect

The mobile app may ask an employee to confirm their identity before punching, using their own phone's features (Face ID, Touch ID, fingerprint, or the device unlock code). This feature is optional and is set from the employee's profile.

Clic Horaire collects, transmits, processes and stores NO biometric data:

  • The check is performed by the phone's operating system, inside its secure chip (Secure Enclave on iOS, trusted execution environment or Titan chip on Android).
  • The fingerprint, the face or any biometric template never leaves that chip: neither the app, nor our servers, nor the employer has access to it.
  • The app receives a verdict only (identity confirmed, or not) and records a punch strictly identical to every other.
  • Neither Clic Horaire nor the employer therefore holds a bank of biometric data within the meaning of sections 44 and 45 of the Act to establish a legal framework for information technology (CQLR, c. C-1.1): nothing is created, and there is nothing to declare on that basis to the Commission d'accès à l'information.
  • The device unlock code fallback is always offered, and the absence of a sensor never prevents an employee from punching.

This description reflects the design of the product and is not legal advice. Each employer remains responsible for how they use this feature with their staff, in particular for the information they give them and for keeping it optional.

6. Electronic signature

When an employer has a document signed electronically, three pieces of information are collected at the moment of the act, and for one reason only: to tie the signature to the document, as section 39 of the Act to establish a legal framework for information technology requires.

  • The signature mark, as drawn with a finger or a mouse. It is an image, never a biometric measurement: nothing is extracted from it that would allow two signatures to be compared automatically.
  • The IP address of the signing request, recorded by the server and never declared by the device.
  • The server's UTC timestamp, and the browser as declared.

These three elements are drawn on the attestation page appended to the signed document. That page also shows the SHA-256 fingerprint of the original document, which lets anyone verify that nothing has changed since.

What we do NOT collect on that occasion: no geolocation, no biometric data, no device identifier. An IP address is recorded only AT THE SIGNING: not when the link is opened, and not when the signer declines, because no document is sealed then and there is nothing to tie it to.

A signer may decline to sign and must give a reason. In particular, they may ask for a PAPER VERSION: section 29 of the same Act provides that no one may be required to accept a document on a medium other than paper. The refusal is passed to the employer, whose responsibility it is to act on it.

A signed and sealed document is evidence: it is neither altered nor corrected. A correction is made by producing a new version and having it signed again, the earlier one remaining on file. Sealed documents are kept for the periods described under "Retention and destruction".

7. How we use your information

  • Provide, operate and improve the platform and its features.
  • Compute and prepare pre-payroll data, exports and the reports required by decrees and parity committees.
  • Answer your demo, information or technical support requests.
  • Send you service-related communications (security notices, material changes, invoices).
  • Keep the platform secure and prevent fraud, security incidents and unauthorized use.
  • Meet our legal, regulatory and tax obligations.

We never use our customers' employee information for advertising, commercial profiling or resale. It serves only to deliver the service to the employer who entrusted it to us.

8. Consent and withdrawal

The consent we ask for is manifest, free, enlightened and given for specific purposes. It is requested separately for every purpose that is not necessary to the service: analytics cookies, for instance, stay off until you accept them.

You may withdraw your consent at any time, free of charge, by writing to us or (for cookies) by clicking « Manage cookies » at the bottom of every page. Withdrawal is not retroactive and may, depending on the purpose, prevent the service from continuing.

The privacy settings of our products are set by default to the highest level of confidentiality, without any action on your part, in accordance with section 9.1 of Law 25.

9. Automated processing and decisions

The platform automatically computes results from the rules of decrees and agreements: paid time, overtime, premiums, holiday indemnities, eligibility for permanent status, parity committee contributions. Those computations are PROPOSALS submitted to a person: a timesheet is approved by a supervisor or an administrator before it serves any purpose, and the employer can correct any value, each correction leaving a trace in the audit trail.

Should a decision concerning you be based exclusively on automated processing, the law gives you the right to be informed of it, to know the information used, the principal factors and parameters, and to submit observations to a person able to review the decision. Address that request to your employer, who is the enterprise responsible for your record; on request we provide them with the detail of the computation and its history.

The platform also includes a conversational assistant (“Charlie”) that acts on request, in plain language. It has NO rights of its own: every action it performs replays an application operation with the rights of the signed-in person's account, and is refused exactly what that person would be refused. It therefore never consults information that the person could not consult themselves, and it widens no one's access.

Three safeguards frame its use: every write requires an explicit on-screen confirmation before it is carried out; no permanent deletion is possible by that route; and every action appears in the audit trail under the person's name, marked “via the assistant”. The client organization may restrict the data surfaces the assistant can read for a given user, require a password before each action, cap its usage, or disable it entirely.

The text of the conversation, and the portion of the record needed to answer it, are transmitted to a language-model provider acting as a service provider on our behalf, under written agreement. That processing takes place outside Québec: the section “Hosting and communication outside Québec” applies to it in full.

10. Sharing your information

We never sell your personal information. We may disclose it in the following situations:

  • To our service providers (cloud hosting, document storage, transactional email, payment processing, analytics, the assistant's language model) acting on our behalf, solely for the agreed purposes and under a written agreement carrying confidentiality and security obligations.
  • To your employer or the customer organization, when the information is processed as part of delivering the service.
  • To parity committees, the CNESST or the CCQ, when the employer files a declaration or report that the law or a decree requires of them.
  • To competent authorities where the law requires it, or to protect our rights, our safety or those of a third party.
  • As part of a commercial transaction (merger, acquisition, sale of assets), subject to an equivalent confidentiality undertaking and to the prior information required by law.

11. Cookies and similar technologies

Our site uses cookies essential to its operation as well as analytics cookies that help us understand how the site is used and improve its content. Analytics cookies are off by default and are only set after you consent, through the banner shown on your visit.

In accordance with section 8.1 of Law 25, we inform you that these technologies can identify you, locate you or build a profile, and that you can turn them off: click « Manage cookies » at the bottom of every page, or set your browser to refuse them. The platform itself only uses cookies necessary for signing in and for security.

12. Retention and destruction

We keep information for as long as necessary for the purposes described in this policy, and at least as long as the employer's legal obligations require: the Act respecting labour standards notably requires the hours register and the payroll system to be kept for three years, and some decrees require more.

Once the purposes are fulfilled and no obligation stands in the way, the information is securely destroyed, or anonymized according to generally accepted criteria where we wish to keep using it for statistical purposes (section 23 of Law 25).

At the end of a subscription, a customer has a reasonable delay to export their data. After that delay, it is destroyed in accordance with the agreement entered into.

A dedicated page, “Delete your account and your data”, sets out who may request a deletion, through which route, what is erased and what the law requires us to keep despite the request. It is reachable from the footer, without signing in.

13. Security of information

We implement administrative, technical and physical security measures suited to the sensitivity of the information processed: encryption in transit and at rest, strict partitioning between organizations, tamper-evident logging of accesses and changes, access management on a least-privilege basis, and regular backups.

As no method of transmission or storage is 100 % secure, we cannot guarantee absolute security. Our Security page describes our measures in detail.

14. Your rights

Under Québec law and, where applicable, the laws in force elsewhere in Canada, you have the following rights:

  • ACCESS: obtain confirmation that we hold information about you, obtain communication of it and know where it came from.
  • RECTIFICATION: have inaccurate, incomplete or equivocal information corrected, or have information deleted where its collection was not authorized.
  • WITHDRAWAL OF CONSENT: stop a use you had consented to, subject to the legal and contractual obligations that remain.
  • PORTABILITY: receive, in a structured, commonly used technological format, the computerized information you provided to us, or have it communicated to a third party (section 27 of Law 25).
  • DE-INDEXING AND CESSATION OF DISSEMINATION: in the cases provided by law.
  • COMPLAINT: turn to the Commission d'accès à l'information du Québec if our answer does not satisfy you.

To exercise any of these rights, write to our person in charge of the protection of personal information (see « Contact us »). We answer in writing within 30 days; a refusal is reasoned and states the available remedies. If your request concerns your employment record, we forward it to your employer, who is responsible for it, and we assist them in answering.

15. Hosting and communication outside Québec

Your information is hosted on servers located in Canada, operated by recognized cloud providers.

Before any communication of personal information outside Québec, we carry out the privacy impact assessment required by section 17 of Law 25: we make sure the information would receive adequate protection, in particular in light of generally recognized protection principles, and the communication is the subject of a written agreement that takes the assessment into account. Failing that, the communication does not take place.

16. Confidentiality incidents

We maintain a register of confidentiality incidents, in accordance with section 3.8 of Law 25. Where an incident presents a risk of serious injury, we promptly take reasonable measures to reduce its effects and prevent it from recurring, and we notify the Commission d'accès à l'information as well as the persons concerned with diligence.

Where the incident concerns information we process on behalf of a customer, we inform them without delay so they can meet their own notification obligations, and we provide them with everything they need to do so.

17. Information of minors

Our services are aimed at organizations and their staff. An employer may keep the record of a minor employee where the law allows, including the parental consent required by the Act respecting the supervision of child labour; that information is then processed on their behalf, with the same protection as any other. We do not knowingly collect information from a person under 14 through our public forms.

18. Changes to this policy

We may amend this policy to reflect changes in our practices or in the applicable legislation. Any material change is announced on this page, with the date above updated, and flagged in the app to account holders. We invite you to check this page periodically.

19. Contact us

For any questions about this policy or to exercise your rights regarding your personal information, contact:

Privacy Officer, Clic Horaire inc.info@clichoraire.comWrite to the Privacy Officer