Overview
This Policy describes how TLJ Apps handles information in connection with the TLJ Locker application for Bitrix24. The Application restricts portal access according to the work schedule defined by the administrator and, optionally, logs access that occurs outside that schedule.
With respect to your employees' data, you act as the Controller and TLJ Apps acts as the Processor, handling data solely according to the instructions you configure in the Application.
Data the Application Reads from Your Bitrix24
The Application queries only the portal's user directory, through the official Bitrix24 API methods:
- Name, position, photo, email, department, and user type (employee, extranet, or guest) — to build the collaborator list in the panel.
- Identity of the signed-in user and whether they are a portal administrator — to decide who is blocked and who may configure schedules.
- Date of last activity on the portal — used only when out-of-schedule access logging is enabled.
The Application does not access CRM, tasks, messages, calendars, files, or any other portal content.
Data We Store
| Data | Purpose | Retention |
|---|---|---|
| Work schedules per collaborator (days, hours, exemptions, and temporary overrides) | Decide, on each check, whether access is allowed | Until you delete them or uninstall the Application |
| Portal settings (time zone, grace period, block screen texts, HR profiles) | Apply the rules you defined | Until uninstall |
| Portal OAuth authorization tokens | Allow the automated scan to run when nobody is signed in | Until uninstall or revocation by Bitrix24 |
| Out-of-schedule access logs (collaborator, date, first and last time, number of detections) | Reporting for the administrator and HR | 90 days, deleted automatically |
| Welcome form answers (name, email, WhatsApp, how you found us, team size, and reason) | Contact, support, and improvement of the Application | Until deletion is requested |
Welcome form answers are sent to TLJ Apps' own CRM and may be used to contact you about the Application. They are not shared with third parties and are not used for advertising.
Access Logging and Monitoring
Out-of-schedule access logging is off by default and only runs if the administrator turns it on. When active, it records that there was portal activity outside the schedule — the first and last signal of the day and how many times it was detected. It does not record pages visited, content accessed, keystrokes, location, or IP address.
This feature constitutes employee monitoring. By enabling it, you represent that you are responsible for informing your team in advance and for complying with applicable labor and data protection laws, including establishing an appropriate legal basis for the processing.
What We Do Not Do
- We do not read deals, contacts, tasks, messages, calendars, or files in your portal.
- We do not sell, rent, or share data with third parties for advertising or marketing.
- We do not use tracking cookies or advertising pixels inside the Application.
- We do not modify your collaborators' Bitrix24 records and we do not deactivate accounts.
- We do not make automated decisions with legal effects about individuals: the Application merely applies the schedule you defined.
Where Data Lives and Third-Party Services
The Application runs on Cloudflare (Workers and Workers KV), on globally distributed infrastructure, and communicates with your Bitrix24 portal. These are the only third parties involved in its operation, each subject to its own privacy policy. All communication happens exclusively over HTTPS with TLS.
Because the infrastructure is distributed, data may be processed outside the country where your company is established. International transfers rely on the contractual safeguards offered by the infrastructure provider.
Data Deletion
You can delete any collaborator's schedule directly in the Application panel. Access logs disappear on their own after 90 days. To erase all data for your portal at once, uninstall the Application or write to contato@tlj.net.br — we respond within 30 days.
Your Rights
Under applicable data protection law, including Brazil's LGPD (Law No. 13.709/2018) and, where applicable, the GDPR, data subjects may request confirmation of processing, access, correction, anonymization, portability, and deletion of their data. Because we act as Processor for your collaborators' data, data subject requests should be directed to you as Controller first; we will support you as needed. For data we control — the welcome form answers — write to contato@tlj.net.br.
Security Incidents
If a security incident occurs that may affect data processed by the Application, we will notify you without undue delay, at your registered contact email, with the available information about the incident and the measures taken.
Changes to This Policy
We may update this Policy to reflect changes in the Application or in the law. The update date at the top of the page always indicates the version in force. Material changes will be communicated through the Application's contact channels.
Contact
Questions about this Policy or about data processing can be sent to contato@tlj.net.br. Data controller entity: TLJ Tech Systems and Development, LLC.
