Legal

Security Policy

The technical and organisational measures that protect your data.

Last updated 04/Oct/202628 sections5 min read
1

Introduction

Teamital is committed to protecting the confidentiality, integrity and availability of the information entrusted to our platform.

This Security Policy outlines the technical and organisational measures we use to protect customer and employee information while providing our workforce management platform.

Our security practices are designed to support compliance with:

  • EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)
  • Irish Data Protection Act 2018

Security is integrated into the design, development and operation of Teamital to help reduce risk, protect customer data and support secure business operations.

2

Company Information

Teamital

Kandoy House, 2 Fairview Strand

Clontarf West, Dublin, D03 R8P3

Ireland

Privacy & Security Contact

contact@teamital.com

3

Scope

This Security Policy applies to:

  • Teamital website
  • Web application
  • Mobile applications
  • APIs
  • Cloud infrastructure
  • Customer data
  • Employee data
  • Internal administrative systems
  • Third-party services supporting the platform
4

Security Principles

Teamital follows these core security principles:

  • Confidentiality
  • Integrity
  • Availability
  • Least Privilege Access
  • Security by Design
  • Privacy by Design
  • Continuous Improvement

These principles guide how we build, maintain and operate our platform.

5

Hosting Infrastructure

Teamital is hosted on Amazon Web Services (AWS).

Primary hosting infrastructure is located within Ireland (Europe) to support secure and reliable service delivery.

AWS provides enterprise-grade infrastructure including physical security, redundancy and availability features.

6

Database Security

Teamital uses Supabase as its database platform.

Our database environment is protected through:

  • Secure authentication
  • Encrypted communications
  • Controlled access permissions
  • Role-based access
  • Secure backups
  • Infrastructure monitoring

Access to production databases is restricted to authorised personnel with a legitimate business need.

7

Encryption

Teamital protects information using industry-standard encryption.

This includes:

Encryption in Transit

All communication between users, mobile applications, browsers and our servers is protected using HTTPS with TLS encryption.

This helps protect information from interception while transmitted over public networks.

Encryption at Rest

Where supported by our infrastructure, stored information is protected using encryption technologies designed to reduce the risk of unauthorised access.

8

Password Security

Passwords are never stored in plain text.

Teamital uses secure password hashing mechanisms designed to protect authentication credentials.

Users are encouraged to:

  • Create strong passwords.
  • Avoid password reuse.
  • Keep credentials confidential.
  • Change passwords if compromise is suspected.
9

Authentication

The platform currently supports:

  • Email and Password authentication

Administrative access is additionally protected through internal security controls and multi-factor authentication where applicable.

10

Access Control

Teamital follows the principle of least privilege.

Users are granted access only to the information and functionality required for their role.

Role-based permissions may include:

  • Organisation Owner
  • Administrator
  • Manager
  • Supervisor
  • Employee

Customers are responsible for configuring user permissions within their organisation.

11

Multi-Factor Authentication

Administrative accounts are protected using Multi-Factor Authentication (MFA) wherever applicable.

MFA provides an additional layer of security beyond passwords to reduce the risk of unauthorised administrative access.

12

Network Security

Teamital uses multiple security measures to protect network infrastructure, including:

  • HTTPS
  • Secure API communication
  • Firewall protection
  • Network monitoring
  • Secure cloud infrastructure
  • Traffic filtering
  • DDoS mitigation through Cloudflare
13

Cloudflare Protection

Teamital uses Cloudflare to improve both security and performance.

Cloudflare assists with:

  • DDoS protection
  • Traffic filtering
  • Bot mitigation
  • Content delivery optimisation
  • Website performance
  • Network resilience
14

GPS and Location Data Security

Location information is handled securely and only processed where enabled by the customer.

GPS information may include:

  • Live location
  • Route history
  • Geofence events
  • Attendance verification
  • Site visit information

Location information is processed only for legitimate workforce management purposes configured by the customer.

15

Biometric and Attendance Security

Where enabled by customers, Teamital supports:

  • Face Recognition
  • Fingerprint Authentication
  • PIN Authentication

Customers remain responsible for ensuring lawful use of biometric-related attendance features in accordance with applicable laws.

Teamital recommends restricting access to attendance information to authorised personnel only.

16

File Upload Security

Teamital supports secure upload of:

  • Employee selfies
  • Site photographs
  • Documents
  • Work reports
  • Project files

Uploaded content is protected using platform access controls.

Customers are responsible for ensuring uploaded content complies with applicable laws and organisational policies.

17

Logging and Audit Trails

Teamital maintains audit logs to support security, operational monitoring and troubleshooting.

Audit records may include:

  • User logins
  • Administrative actions
  • Configuration changes
  • Attendance activity
  • Security events
  • System errors

Audit logs are accessible only to authorised personnel where necessary.

18

Monitoring and Incident Detection

Teamital continuously monitors platform health and security.

Monitoring may include:

  • Infrastructure monitoring
  • Service availability
  • Error detection
  • Authentication events
  • Suspicious activity
  • Application performance

Potential security incidents are investigated promptly.

19

Crash Reporting

Teamital uses Firebase Crashlytics to identify technical issues affecting application stability.

Crash reports may include:

  • Device model
  • Operating system
  • App version
  • Error logs
  • Technical diagnostic information

Crash reporting data is used solely to improve platform reliability and performance.

20

Analytics

Teamital uses Google Analytics to better understand website usage and improve customer experience.

Analytics information may include:

  • Device information
  • Browser information
  • Website interactions
  • Traffic sources
  • Anonymous usage statistics

Analytics data is not used to make employment decisions.

21

Data Backups

Regular backups are maintained to support business continuity and disaster recovery.

Backup procedures are designed to:

  • Reduce data loss
  • Support restoration
  • Improve resilience
  • Protect customer information

Backups are protected using appropriate security controls.

22

Business Continuity

Teamital maintains procedures intended to support continued service during unexpected events.

These procedures may include:

  • Infrastructure redundancy
  • Cloud resilience
  • Backup restoration
  • Incident response processes
  • Operational recovery planning
23

Security Incident Response

If a security incident is identified, Teamital will:

  • Investigate the incident.
  • Contain the issue.
  • Assess potential impact.
  • Restore affected systems.
  • Notify affected customers where required by applicable law.
  • Review security controls to reduce future risk.

Where GDPR applies, breach notifications will be handled in accordance with applicable legal requirements.

24

Customer Responsibilities

Customers also play an important role in maintaining security.

Customers should:

  • Use strong passwords.
  • Restrict administrator accounts.
  • Remove inactive users promptly.
  • Configure permissions appropriately.
  • Inform employees about platform usage.
  • Protect devices used to access the platform.
  • Keep operating systems and browsers updated.
  • Report suspected security issues immediately.
25

Third-Party Service Providers

Teamital relies on carefully selected service providers including:

  • Amazon Web Services (AWS)
  • Supabase
  • Cloudflare
  • Firebase
  • Firebase Crashlytics
  • Google Analytics
  • Google Maps
  • Stripe
  • Revolut
  • Resend

These providers maintain their own security controls and privacy obligations.

Teamital reviews third-party services as part of ongoing security management.

26

Security Reviews

Our security practices are reviewed periodically to improve protection against evolving threats.

Reviews may include:

  • Infrastructure assessments
  • Configuration reviews
  • Access reviews
  • Software updates
  • Dependency updates
  • Security improvements
27

Policy Updates

This Security Policy may be updated from time to time to reflect changes in technology, legal requirements or our security practices.

The latest version will always be available on our website.

28

Contact Us

If you have questions regarding security or wish to report a potential security issue, please contact:

Teamital

Kandoy House, 2 Fairview Strand

Clontarf West, Dublin, D03 R8P3

Ireland

Email: contact@teamital.com

Questions about this policy?

Our team is happy to help. Reach us at contact@teamital.com.

Contact us