Operlix Privacy Policy
This policy explains how the Operlix mobile application ("App") processes personal data. The App is intended for employees and other authorised users of participating organisations and requires an organisation-provided account.
1. Controller and contact
Operlix is provided by Latitude Software Solutions, 27 Tvaika street, Riga, LV-1001, Latvia. Privacy, access, and deletion enquiries may be sent to info@lat-soft.com. The employer or other organisation that provides access to Operlix may act as controller for information processed in its workplace.
2. Data we process
- account and profile data, including name, work email, user identifier, organisation, role, and permissions;
- work content, including tasks, statuses, deadlines, comments, attachments, photographs, and audio recordings a user chooses to submit;
- technical data, including app version, device platform and identifiers, push notification tokens, and diagnostic and security logs;
- authentication data and securely stored session tokens. The App does not receive the password used with an external identity provider;
- files and media selected by the user. Camera, photos, microphone, and notifications are used only after the relevant device permission is granted.
3. Purposes and legal bases
Data is processed to authenticate users, provide task and attachment management, synchronise work information, deliver work-related notifications, maintain security, troubleshoot faults, and meet applicable legal requirements. Depending on the organisation and context, processing may rely on contract, legitimate interests, legal obligation, or consent where required.
4. Recipients and service providers
Information may be available to authorised personnel of the user's organisation and to technical service providers only as necessary. The App uses Google Firebase for cloud messaging and an external OpenID Connect identity service for authentication. Personal data is not sold or used for third-party advertising.
5. Retention and deletion
Information is retained for as long as needed to provide the App, meet contractual and legal requirements, or follow the retention rules of the user's organisation. Locally stored session data is removed on sign-out or removal of the App, subject to operating-system behaviour. Account or data deletion requests may be submitted to the user's organisation or to the contact address above.
6. Security and user rights
Access controls, encrypted network connections, secure authentication, and device-protected token storage are used to reduce risk. Subject to applicable law, users may request access, correction, deletion, restriction, or portability, object to processing, and complain to a supervisory authority. Some requests must be directed to the organisation that issued the account.
7. Children and changes
The App is not intended for children or directed to anyone under 18. This policy may be updated when the App or legal requirements change. The current version and effective date will remain available on this page.