Latitude Software Solutions Home

BPMS Privacy Policy

Effective date: 22 July 2026

This policy explains how the BPMS mobile application ("App") processes personal data. BPMS is a business process management service for employees and other authorised users of participating organisations. Access requires an account issued or approved by the user's organisation; users cannot create an account in the App.

1. Controller and contact

BPMS is provided by Latitude Software Solutions, 27 Tvaika street, Riga, LV-1001, Latvia. Privacy, access, correction, and deletion enquiries may be sent to info@lat-soft.com. The employer or other organisation that provides a BPMS account generally determines which workplace information is processed and may act as the controller for that information. Some requests must therefore be handled by that organisation.

2. Data processed by BPMS

Depending on the user's role and the modules enabled by their organisation, BPMS may process:

The App does not collect precise or approximate location, device contacts, health data, payment information, advertising identifiers, or data for behavioural advertising. Camera or photo-library access is used only when the user chooses to add or replace a profile photograph. Notification permission is used to deliver work-related alerts.

3. Why data is processed

Data is processed to authenticate and manage authorised users; display and update business information; support comments, approvals, and other workflows; personalise account settings; deliver work-related push notifications; understand App-version adoption and usage; protect the service; troubleshoot faults; and comply with contractual or legal obligations.

Depending on the organisation and context, the legal basis may be performance of a contract, legitimate interests in operating and securing business processes, compliance with a legal obligation, or consent where applicable.

4. Recipients and service providers

Information is available only to authorised users and administrators according to organisation-defined permissions. Latitude Software Solutions may use contracted hosting, maintenance, security, email, and identity providers where necessary to operate BPMS. Google Firebase Cloud Messaging processes App installation and notification identifiers to deliver push notifications. Service providers act under applicable contractual and confidentiality obligations.

Personal data is not sold, used for third-party advertising, or shared with independent third parties for their own marketing purposes. Data may be disclosed when required by law or to protect users, the service, or legal rights.

5. International processing

Some technical service providers may process data in countries other than the user's country. Where required, appropriate safeguards are used for international transfers in accordance with applicable data protection law.

6. Retention and security

Information is retained for as long as necessary to provide BPMS, maintain business and audit records, follow the retention instructions of the user's organisation, resolve disputes, and meet contractual or legal obligations. Retention periods therefore depend on the type of record and the organisation using BPMS.

BPMS uses encrypted network connections, access controls, secure authentication, device-protected token storage, backups, and other appropriate technical and organisational safeguards. No system can guarantee absolute security.

7. How to request account or data deletion

  1. Contact the administrator of the organisation that issued your BPMS account, or email info@lat-soft.com with the subject BPMS account or data deletion request.
  2. Include your organisation name and the username or work email address associated with the account. Do not send your password.
  3. Complete any reasonable identity and authority verification requested to prevent unauthorised deletion.

Where legally and technically permitted, an approved request may delete or anonymise the BPMS account, profile information, optional profile photograph, comments attributable to the user, App installation identifier, and push notification token. Access may instead be disabled when the organisation must preserve the account's relationship to business records.

Business documents, approvals, audit trails, security records, backups, and information required for contractual or legal compliance may be retained for the applicable period. Data that cannot be deleted will be restricted where appropriate. Requests are handled within the time limits required by applicable law.

8. User rights

Subject to applicable law, users may request access to, correction of, deletion of, restriction of, or portability of personal data, object to processing, and lodge a complaint with a competent supervisory authority. Requests concerning workplace records should normally be directed first to the organisation that issued the BPMS account.

9. Children and policy changes

BPMS is intended for authorised workplace users aged 18 or older and is not directed to children. This policy may be updated when the App, service providers, or legal requirements change. The current version and effective date will remain available on this page.