We use analytics to understand how visitors use this site. No personal or workforce data is collected. See our Privacy Policy.
ForceLytics is committed to uncompromised workforce data privacy, strict regulatory compliance, and transparent fiduciary stewardship. This policy details our data protection standards, processor responsibilities, and zero-model-training guarantees.
We contractually guarantee that customer workforce data is never used to train, retrain, or fine-tune public, foundational, or third-party AI models.
Your organization remains the exclusive Data Controller of your employee data. ForceLytics acts strictly as a Data Processor under GDPR Art. 28.
Government IDs (SSNs, National IDs) and personal bank account numbers are actively filtered or hashed at ingestion gateways before analytical storage.
Upon contract termination, you receive a 30-day export window, followed by a complete cryptographic wipe across all volumes within 60 days.
ForceLytics Inc. (“ForceLytics,” “we,” “us,” or “our”) provides an enterprise-grade cloud workforce intelligence, analytics, and scenario planning platform. We empower organizational leaders to harmonize disparate Human Resources Information Systems (HRIS), payroll, applicant tracking, and operational telemetry into clear, defensible workforce decisions.
Because workforce records represent an organization’s most sensitive human capital and strategic assets, we adhere to strict privacy-by-design principles. This Privacy Policy applies to all interactions with the ForceLytics website (forcelytics.co), our cloud software services, and enterprise customer engagements.
To ensure complete clarity under the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act, and the California Consumer Privacy Act (CCPA/CPRA), we distinguish between two separate categories of data processing:
When an enterprise customer ingests, synchronizes, or uploads employee telemetry (such as headcount rosters, compensation bands, tenure, supervisory org charts, and performance scores) into the ForceLytics platform, the Customer acts as the sole Data Controller (or Business under CCPA). ForceLytics acts exclusively as a Data Processor (or Service Provider). We process Customer Workforce Data strictly in accordance with the Customer’s documented instructions, our Master Services Agreement (MSA), and our signed Data Processing Addendum (DPA).
ForceLytics acts as a Data Controller for business contact information voluntarily submitted by visitors (e.g., booking a demonstration, contacting sales, or signing up for enterprise events), customer administrator account credentials, and anonymous website diagnostic telemetry.
We recognize the profound intellectual property and confidential risks associated with uncontrolled generative AI systems in the enterprise. ForceLytics maintains an uncompromising, contractually binding commitment:
Contractual Guarantee on Customer Workforce Telemetry:
ForceLytics will NEVER use, disclose, or transfer Customer Workforce Data, organizational structures, compensation figures, or confidential planning scenarios to train, retrain, fine-tune, or benchmark public, foundational, or third-party Artificial Intelligence (AI) or Large Language Models (LLMs). All statistical and machine-learning transformations run in isolated, tenant-scoped memory runtimes and produce outputs owned solely by the customer tenant.
Depending on how you interact with our platform and marketing properties, we process the following data categories:
| Data Category | Data Elements Included | Collection Mechanism |
|---|---|---|
| Customer Workforce Telemetry | Employee IDs, job profiles, department assignments, cost centers, salary ranges, hire dates, tenure, attrition codes, and project velocity. | Read-only Direct API (Workday, BambooHR, ADP) or automated PGP-encrypted SFTP batch. |
| Filtered / Excluded PII | Social Security Numbers, national identity cards, passport numbers, personal banking details. | Strictly blocked, filtered, or hashed client-side before analytical ingest. |
| Business Lead & Account Data | Full name, corporate email address, company name, job role, and inquiry notes. | Demo booking forms, direct contact inquiries, and authenticated customer logins. |
| Website Telemetry | Anonymized IP hashes, browser user-agent, referring URLs, and page session metrics. | Strictly gated on user consent via our Cookie Preferences Banner. |
Under European data protection laws, ForceLytics processes personal information only where an established lawful basis applies:
We retain information only as long as necessary to fulfill the operational purposes for which it was collected:
Retained exclusively during the active customer contract term. Upon contract termination, customers have a 30-day export window to extract all raw data and analytical aggregates. Upon expiration of the export window, all customer data partitions and KMS encryption keys are cryptographically revoked and permanently erased across all databases and rolling backups within 60 days.
Retained for up to 24 months from the last substantive communication, or immediately purged upon receipt of an opt-out or erasure request.
Retained for 12 months for forensic analysis, intrusion detection, and SOC 2 Type II audit verification, after which they are automatically rotated and deleted.
ForceLytics employs defense-in-depth safeguards engineered to prevent unauthorized access or disclosure:
For deeper architectural details, inspect our Enterprise Security & Trust Center.
We engage carefully vetted third-party infrastructure sub-processors subject to rigorous vendor security risk assessments and signed Data Processing Addenda:
Where cross-border data transfers occur from the European Economic Area (EEA), UK, or Switzerland, ForceLytics relies on standard contractual clauses (SCCs) approved by the European Commission, supplemented by technical safeguards and encryption.
Applicable privacy laws afford individuals rights concerning their personal data, including:
Request confirmation and a machine-readable export of personal records.
Correct inaccurate, outdated, or incomplete personal data.
Request deletion of personal data where no overriding legal obligation exists.
Restrict processing or withdraw consent for non-essential analytics at any time.
Submitting Requests: For Customer Workforce Data, employees must submit requests directly to their employer (the Data Controller). For marketing contacts or website visitors, email our Data Protection Office at privacy@forcelytics.co. We respond within statutory timelines without charge.
ForceLytics has designated a dedicated Data Protection Officer (DPO) to oversee privacy compliance, handle regulatory audits, and resolve data subject requests.
ForceLytics Inc. — Data Protection Office
Email: privacy@forcelytics.co
Online Inquiries: Contact Inquiry Gateway
This document is published at /privacy-policy. ForceLytics reserves the right to update this policy periodically in accordance with applicable laws and material notification provisions.