Invite onlyRequest an invitation

Legal

Security

The security of your data is at the core of how Clic Horaire is built. This page describes the technical and organizational measures we put in place to protect the information you entrust to us.

Last updated : August 30, 2026

1. Our approach to security

Security isn't bolted on after the fact at Clic Horaire: it's built into the design of our pre-payroll engine, given the sensitivity of the attendance, schedule and pay data we process on behalf of our customers.

2. Hosting and infrastructure

  • Your data is hosted on servers located in Canada, operated by recognized cloud providers offering high availability and geographic redundancy.
  • Our customers' environments are logically isolated from one another to prevent any cross-access to data.
  • Our infrastructure is monitored continuously to quickly detect any anomaly.

3. Data encryption

All data in transit between your browser and our servers is encrypted using TLS. Data at rest is encrypted using industry-recognized algorithms. Access to encryption keys is strictly limited and logged.

4. Tamper-evident forensic audit trail

Every action taken on the platform (a schedule change, a time-tracking adjustment, a decree change) is recorded in a cryptographically chained audit trail (hashing), making any after-the-fact modification detectable. This design protects the integrity of your data during a CCQ, CPEEP, LNT or CNESST inspection.

5. Access management and authentication

  • Internal access is granted on the principle of least privilege and reviewed periodically.
  • Roles and permissions for client users are configurable to limit access to only the data required for their duties.
  • Every administrative access to sensitive data is logged.

6. Identity verification never leaves the device

A punch can be confirmed by Face ID, Touch ID, a fingerprint or the phone's unlock code. That check is performed by the device's operating system, inside its secure chip (Secure Enclave, trusted execution environment, Titan chip).

  • No biometric data is collected, transmitted or stored by Clic Horaire. Our app receives a boolean only: identity confirmed, or not.
  • No template, no image and no fingerprint transits through our servers: there is therefore no bank of biometric measurements to protect, to encrypt, or to leak.
  • The device-passcode fallback is offered by default: gloves, wet fingers or a missing sensor never block an employee.
  • The feature is optional and is set from the employee's profile, on their own phone.

The best protection for sensitive data remains never holding it. That is the principle chosen here.

7. The AI assistant widens no access

The conversational assistant “Charlie” has no rights of its own, and that is not a policy: it is a design constraint. Every action it performs replays an application request using the SESSION TOKEN of the signed-in person. It passes through the same access controls, the same fine-grained permissions and the same partitioning between organizations. A refusal issued to the person is issued to the assistant, without any additional guard having to be written: and therefore without one that could be forgotten.

It follows that no conversation can open information the person could not display on screen themselves. The assistant is not a service account, it holds no master key, and there is no path by which it would read the file of an organization the person does not belong to.

Three barriers frame writing. Every change suspends the conversation until it is explicitly confirmed on screen. No permanent deletion is possible by that route: destruction requests are refused before they are even issued, only deactivation, the trash bin and archiving being allowed. Finally, every action is recorded in the tamper-evident audit trail under the person's name, marked “via the assistant”: a conversation creates no blind spot in the register.

The client organization keeps control of the assistant's reach: individual authorization, readable data surfaces set one by one, a monthly cap per person, and an optional password requirement when the assistant opens or before each write. These settings restrict the assistant without ever widening the person's rights.

The text of conversations and the portion of the record needed to answer them are transmitted to a language-model provider, acting as a processor on our behalf under written agreement, outside Québec. The assistant does not repeat the most sensitive information in a file (social insurance number, date of birth, home address) until the account holder has allowed it on that person's record. The “Subcontractors and suppliers” section and the Privacy Policy describe this processing.

8. Document uploads: caps and server-side verification

An employee can file documents into their own record from their phone. That door, open to tens of thousands of devices, is framed by guardrails that live entirely on the server:

  • The cap is checked BEFORE the upload URL is signed as well as at confirmation: signing a presigned URL already grants a write.
  • The file size is READ BACK from storage after the upload, never taken from the device; an oversized object is deleted and refused.
  • The object key is verified against the employee's own record: an upload can never point at a co-worker's document.
  • Accepted file types are restricted (PDF and images), and the document types an employee may file exclude, in particular, the employment contract and the pension enrolment form.
  • Removed documents still count towards the caps: « upload, delete, repeat » resets no counter.

9. Service continuity and backups

We perform regular encrypted backups of your data and maintain a disaster recovery plan to limit service interruptions and data loss in the event of a major incident.

10. Security testing and responsible disclosure

Our platform undergoes continuous security updates and periodic testing. If you believe you have found a vulnerability, we invite you to report it responsibly to the address in the "Contact us" section below; we commit to acknowledging it promptly and addressing it with diligence.

11. Subprocessors and vendors

Our vendors (hosting, transactional email, analytics) are selected against rigorous security criteria and are bound by confidentiality agreements. A list of our main subprocessors is available upon request.

12. Incident response

In the event of a privacy incident presenting a risk of serious harm, we apply our incident response plan and notify affected individuals and the competent authorities, within the timelines required by law, including Quebec's Law 25.

13. Regulatory compliance

Our security practices are designed to comply with Quebec's Act respecting the protection of personal information in the private sector (Law 25), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the record-retention requirements set by CNESST for schedule and attendance data.

14. Contact us

For any question about the security of our services, or to responsibly report a vulnerability, contact:

Security Team, Clic Horaire inc.info@clichoraire.comWrite to the Security Team